File name:

TradingView (Premium) Desktop (2).zip

Full analysis: https://app.any.run/tasks/88895a14-d904-4fd2-b247-7dd7bb57b61c
Verdict: Malicious activity
Threats:

Remote access trojans (RATs) are a type of malware that enables attackers to establish complete to partial control over infected computers. Such malicious programs often have a modular design, offering a wide range of functionalities for conducting illicit activities on compromised systems. Some of the most common features of RATs include access to the users’ data, webcam, and keystrokes. This malware is often distributed through phishing emails and links.

Analysis date: March 15, 2022, 20:45:44
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
trojan
rat
redline
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

AB52F5C8352021B813A45D776905BE00

SHA1:

1DAD184486CA79369BE94C783AD9D6941B301582

SHA256:

BD2D879294335D3BCFE628D84474E2742D4B251C7A01F7F25661EB318A1E7E14

SSDEEP:

98304:XudRRh46aKRozbBR4FshBR6INLyb9CDg4GfopyUk:e3XuThBRHGZC01gpyUk

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Connects to CnC server

      • TradingView (Premium) Desktop.exe (PID: 1996)
    • REDLINE was detected

      • TradingView (Premium) Desktop.exe (PID: 1996)
    • Actions looks like stealing of personal data

      • TradingView (Premium) Desktop.exe (PID: 1996)
    • Steals credentials from Web Browsers

      • TradingView (Premium) Desktop.exe (PID: 1996)
  • SUSPICIOUS

    • Reads the computer name

      • TradingView (Premium) Desktop.exe (PID: 1996)
      • WinRAR.exe (PID: 2368)
    • Checks supported languages

      • WinRAR.exe (PID: 2368)
      • TradingView (Premium) Desktop.exe (PID: 1996)
    • Reads Environment values

      • TradingView (Premium) Desktop.exe (PID: 1996)
    • Searches for installed software

      • TradingView (Premium) Desktop.exe (PID: 1996)
    • Reads the cookies of Mozilla Firefox

      • TradingView (Premium) Desktop.exe (PID: 1996)
    • Reads the cookies of Google Chrome

      • TradingView (Premium) Desktop.exe (PID: 1996)
  • INFO

    • Reads settings of System Certificates

      • TradingView (Premium) Desktop.exe (PID: 1996)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipFileName: TradingView (Premium) Desktop.exe
ZipUncompressedSize: 377027680
ZipCompressedSize: 4334482
ZipCRC: 0x241b9044
ZipModifyDate: 2022:03:14 15:07:10
ZipCompression: Deflated
ZipBitFlag: -
ZipRequiredVersion: 20
No data.
screenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
36
Monitored processes
2
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe no specs #REDLINE tradingview (premium) desktop.exe

Process information

PID
CMD
Path
Indicators
Parent process
1996"C:\Users\admin\AppData\Local\Temp\Rar$EXa2368.33339\TradingView (Premium) Desktop.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa2368.33339\TradingView (Premium) Desktop.exe
WinRAR.exe
User:
admin
Company:
mmediaapp_v211beta_win64 (Microsoft Corporation)
Integrity Level:
MEDIUM
Description:
mmediaapp_v211beta_win64 SQL Server Compact
Exit code:
0
Version:
4.0.8876.1
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2368.33339\tradingview (premium) desktop.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2368"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\TradingView (Premium) Desktop (2).zip"C:\Program Files\WinRAR\WinRAR.exeExplorer.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
Total events
5 255
Read events
5 211
Write events
44
Delete events
0

Modification events

(PID) Process:(2368) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2368) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2368) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2368) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(2368) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(2368) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\TradingView (Premium) Desktop (2).zip
(PID) Process:(2368) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2368) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2368) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2368) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
Executable files
0
Suspicious files
0
Text files
28
Unknown types
0

Dropped files

PID
Process
Filename
Type
2368WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2368.33339\TradingView (Premium) Desktop.exe
MD5:
SHA256:
2368WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2368.33339\Privacy Policy\UBT_bg.rtftext
MD5:8CAAC7F6437F587142CDA210000CADBC
SHA256:4926FAC821460A82D333D5C5D3ADD490DD3B620D18EEB3689F5EEE4E6729F2AC
2368WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2368.33339\Privacy Policy\UBT_cs.rtftext
MD5:99112078FA44DC65D231A074539DCD9E
SHA256:4576C09B432ACC5933AB0CDCDE451D329E4AADDEBCC232D93E754B7CF151EF6A
2368WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2368.33339\Privacy Policy\UBT_el.rtftext
MD5:F78578A8F622DAEB9B93BE08CE78C2D1
SHA256:EE295BE2F795D871A524ECEEC9E49563F4D24E0EDCC95317616E530E9F88F7B5
2368WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2368.33339\Privacy Policy\UBT_de.rtftext
MD5:4CFA2DA298B95EFA55B19D51C81A3C66
SHA256:D62B3089300FE942D491EE3D18BAB07B59AAAA5410B72181C267A694A2692F8D
2368WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2368.33339\Privacy Policy\UBT_en.rtftext
MD5:1AEC177B22E45F99FC812D5BFEDD2F07
SHA256:6B45386A52901170D24DB77537044197450BF3412590B694DE589596C5F68839
2368WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2368.33339\Privacy Policy\UBT_fi.rtftext
MD5:1D713CD1758AAF01F4E39C8E514843E5
SHA256:9EE64A38F94533592B2012039491ED0969FDB8C595A176BD0805531B0E8161F4
2368WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2368.33339\Privacy Policy\UBT_es.rtftext
MD5:FE54231534BD4D28879C7BD9E30B2AEA
SHA256:A895D3C655800B8DBA8C684DBF9F9F1A406827B16C2FF6497C37E2843701180D
2368WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2368.33339\Privacy Policy\UBT_fr.rtftext
MD5:C6BE419117B4AB16AF0D14750BECB783
SHA256:F51739C75939297822F32D872E82C9E5B22535FEC41F910DD40042077060930B
2368WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2368.33339\Privacy Policy\UBT_da.rtftext
MD5:2FFDB0BB667EC42B624D6934055DDE9C
SHA256:E182177BCBC5296F335E04A90DE522153C9680B87FBE9EA049495AB5AD8111A7
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
2
DNS requests
2
Threats
29

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1996
TradingView (Premium) Desktop.exe
45.83.122.135:80
xardelitty.xyz
malicious
1996
TradingView (Premium) Desktop.exe
172.67.75.172:443
api.ip.sb
US
suspicious

DNS requests

Domain
IP
Reputation
xardelitty.xyz
  • 45.83.122.135
malicious
api.ip.sb
  • 172.67.75.172
  • 104.26.12.31
  • 104.26.13.31
whitelisted

Threats

Found threats are available for the paid subscriptions
29 ETPRO signatures available at the full report
No debug info