File name:

TradingView (Premium) Desktop (2).zip

Full analysis: https://app.any.run/tasks/88895a14-d904-4fd2-b247-7dd7bb57b61c
Verdict: Malicious activity
Threats:

Remote access trojans (RATs) are a type of malware that enables attackers to establish complete to partial control over infected computers. Such malicious programs often have a modular design, offering a wide range of functionalities for conducting illicit activities on compromised systems. Some of the most common features of RATs include access to the users’ data, webcam, and keystrokes. This malware is often distributed through phishing emails and links.

Analysis date: March 15, 2022, 20:45:44
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
trojan
rat
redline
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

AB52F5C8352021B813A45D776905BE00

SHA1:

1DAD184486CA79369BE94C783AD9D6941B301582

SHA256:

BD2D879294335D3BCFE628D84474E2742D4B251C7A01F7F25661EB318A1E7E14

SSDEEP:

98304:XudRRh46aKRozbBR4FshBR6INLyb9CDg4GfopyUk:e3XuThBRHGZC01gpyUk

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • REDLINE was detected

      • TradingView (Premium) Desktop.exe (PID: 1996)
    • Connects to CnC server

      • TradingView (Premium) Desktop.exe (PID: 1996)
    • Actions looks like stealing of personal data

      • TradingView (Premium) Desktop.exe (PID: 1996)
    • Steals credentials from Web Browsers

      • TradingView (Premium) Desktop.exe (PID: 1996)
  • SUSPICIOUS

    • Reads the computer name

      • WinRAR.exe (PID: 2368)
      • TradingView (Premium) Desktop.exe (PID: 1996)
    • Checks supported languages

      • WinRAR.exe (PID: 2368)
      • TradingView (Premium) Desktop.exe (PID: 1996)
    • Reads Environment values

      • TradingView (Premium) Desktop.exe (PID: 1996)
    • Searches for installed software

      • TradingView (Premium) Desktop.exe (PID: 1996)
    • Reads the cookies of Mozilla Firefox

      • TradingView (Premium) Desktop.exe (PID: 1996)
    • Reads the cookies of Google Chrome

      • TradingView (Premium) Desktop.exe (PID: 1996)
  • INFO

    • Reads settings of System Certificates

      • TradingView (Premium) Desktop.exe (PID: 1996)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipFileName: TradingView (Premium) Desktop.exe
ZipUncompressedSize: 377027680
ZipCompressedSize: 4334482
ZipCRC: 0x241b9044
ZipModifyDate: 2022:03:14 15:07:10
ZipCompression: Deflated
ZipBitFlag: -
ZipRequiredVersion: 20
No data.
screenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
36
Monitored processes
2
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe no specs #REDLINE tradingview (premium) desktop.exe

Process information

PID
CMD
Path
Indicators
Parent process
1996"C:\Users\admin\AppData\Local\Temp\Rar$EXa2368.33339\TradingView (Premium) Desktop.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa2368.33339\TradingView (Premium) Desktop.exe
WinRAR.exe
User:
admin
Company:
mmediaapp_v211beta_win64 (Microsoft Corporation)
Integrity Level:
MEDIUM
Description:
mmediaapp_v211beta_win64 SQL Server Compact
Exit code:
0
Version:
4.0.8876.1
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2368.33339\tradingview (premium) desktop.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2368"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\TradingView (Premium) Desktop (2).zip"C:\Program Files\WinRAR\WinRAR.exeExplorer.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
Total events
5 255
Read events
5 211
Write events
44
Delete events
0

Modification events

(PID) Process:(2368) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2368) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2368) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2368) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(2368) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(2368) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\TradingView (Premium) Desktop (2).zip
(PID) Process:(2368) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2368) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2368) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2368) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
Executable files
0
Suspicious files
0
Text files
28
Unknown types
0

Dropped files

PID
Process
Filename
Type
2368WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2368.33339\TradingView (Premium) Desktop.exe
MD5:
SHA256:
2368WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2368.33339\Privacy Policy\UBT_bg.rtftext
MD5:8CAAC7F6437F587142CDA210000CADBC
SHA256:4926FAC821460A82D333D5C5D3ADD490DD3B620D18EEB3689F5EEE4E6729F2AC
2368WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2368.33339\Privacy Policy\UBT_fi.rtftext
MD5:1D713CD1758AAF01F4E39C8E514843E5
SHA256:9EE64A38F94533592B2012039491ED0969FDB8C595A176BD0805531B0E8161F4
2368WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2368.33339\Privacy Policy\UBT_hu.rtftext
MD5:7A78D0ED6EE46E885942FFC7164F6218
SHA256:2110D58C50D59996B769DEC02764FE8F3009DF8D6924469FE688B4882C8EB8E6
2368WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2368.33339\Privacy Policy\UBT_it.rtftext
MD5:1078DBC19F8BFBB2C11B1CC4772296BE
SHA256:9B72BE935D74636B9F311570D38F75F6D7D0CAEDEB00EC1A0051C668AD4785A3
2368WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2368.33339\Privacy Policy\UBT_el.rtftext
MD5:F78578A8F622DAEB9B93BE08CE78C2D1
SHA256:EE295BE2F795D871A524ECEEC9E49563F4D24E0EDCC95317616E530E9F88F7B5
2368WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2368.33339\Privacy Policy\UBT_en-us.rtftext
MD5:61C77F963F5ED65DFC13A9EBD5AD820E
SHA256:9E35D0A96499BB811E99ABCAD801F217BAD15D6748CAB036B398C9AA6656D01F
2368WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2368.33339\Privacy Policy\UBT_da.rtftext
MD5:2FFDB0BB667EC42B624D6934055DDE9C
SHA256:E182177BCBC5296F335E04A90DE522153C9680B87FBE9EA049495AB5AD8111A7
2368WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2368.33339\Privacy Policy\UBT_ar.rtftext
MD5:9B5B6B6C14FDEFBB3D67AB8425666CEA
SHA256:6CEE95EDFB044E5DE674B49C816EC074CF1FD99B58E50B90101BA0ADE80D7AF4
2368WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2368.33339\Privacy Policy\UBT_ja.rtftext
MD5:BB1FD966B0F5F6916708878AEF1B4DBF
SHA256:E8567F8AB8BA40798B861AC825FE826CEBBBC53A488D74878E868FAA4C44A32C
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
2
DNS requests
2
Threats
29

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1996
TradingView (Premium) Desktop.exe
45.83.122.135:80
xardelitty.xyz
malicious
1996
TradingView (Premium) Desktop.exe
172.67.75.172:443
api.ip.sb
US
suspicious

DNS requests

Domain
IP
Reputation
xardelitty.xyz
  • 45.83.122.135
malicious
api.ip.sb
  • 172.67.75.172
  • 104.26.12.31
  • 104.26.13.31
whitelisted

Threats

Found threats are available for the paid subscriptions
29 ETPRO signatures available at the full report
No debug info