File name:

Monotone-HWID-Spoofer-0.0.1.7z

Full analysis: https://app.any.run/tasks/d9e8bd72-c180-4d04-b510-d7de569ad5df
Verdict: Malicious activity
Analysis date: August 08, 2023, 13:04:30
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-7z-compressed
File info: 7-zip archive data, version 0.4
MD5:

AF1D2B3725C153BD093D2A0929D8DA6B

SHA1:

97445399186405C5B41F72B1E23E3C8DA97EAB33

SHA256:

BF8206D858EFFDD6F2DE6DA41A9DCDF53DB710DBFEF5EEB98944CD21D61EFE94

SSDEEP:

12288:CpTQTtDfboQpDmUO4xS9f5a4XYjPT8QQk6RuYWC5G9Y:ATSbbo+mCxSa38mYWkGW

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • batbox.exe (PID: 2504)
      • GetInput.exe (PID: 3876)
      • GetInput.exe (PID: 2952)
  • SUSPICIOUS

    • Drops a system driver (possible attempt to evade defenses)

      • WinRAR.exe (PID: 1276)
    • Get information on the list of running processes

      • cmd.exe (PID: 3724)
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 1276)
    • Manual execution by a user

      • GetInput.exe (PID: 3876)
      • batbox.exe (PID: 2504)
      • cmd.exe (PID: 1900)
      • cmd.exe (PID: 2344)
      • cmd.exe (PID: 3724)
      • cmd.exe (PID: 2600)
      • GetInput.exe (PID: 2952)
      • notepad.exe (PID: 3576)
    • Checks supported languages

      • batbox.exe (PID: 2504)
    • The process checks LSA protection

      • tasklist.exe (PID: 1916)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.7z | 7-Zip compressed archive (v0.4) (57.1)
.7z | 7-Zip compressed archive (gen) (42.8)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
59
Monitored processes
12
Malicious processes
2
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe batbox.exe no specs getinput.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs getinput.exe no specs cmd.exe no specs ping.exe no specs tasklist.exe no specs find.exe no specs notepad.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1276"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Monotone-HWID-Spoofer-0.0.1.7z"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\program files\winrar\winrar.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
1900C:\Windows\system32\cmd.exe /c ""C:\Users\admin\Desktop\Monotone-HWID-Spoofer-0.0.1\Box.bat" "C:\Windows\System32\cmd.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msctf.dll
1916tasklist /NH /FI "imagename eq Monotone.exe" C:\Windows\System32\tasklist.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Lists the current running tasks
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\tasklist.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\user32.dll
2344C:\Windows\system32\cmd.exe /c ""C:\Users\admin\Desktop\Monotone-HWID-Spoofer-0.0.1\Getlen.bat" "C:\Windows\System32\cmd.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\lpk.dll
2504"C:\Users\admin\Desktop\Monotone-HWID-Spoofer-0.0.1\batbox.exe" C:\Users\admin\Desktop\Monotone-HWID-Spoofer-0.0.1\batbox.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\monotone-hwid-spoofer-0.0.1\batbox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
2580find /i "Monotone.exe"C:\Windows\System32\find.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Find String (grep) Utility
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\find.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ulib.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\advapi32.dll
2600C:\Windows\system32\cmd.exe /c ""C:\Users\admin\Desktop\Monotone-HWID-Spoofer-0.0.1\Button.bat" "C:\Windows\System32\cmd.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2952"C:\Users\admin\Desktop\Monotone-HWID-Spoofer-0.0.1\GetInput.exe" C:\Users\admin\Desktop\Monotone-HWID-Spoofer-0.0.1\GetInput.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\monotone-hwid-spoofer-0.0.1\getinput.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
3576"C:\Windows\System32\NOTEPAD.EXE" C:\Users\admin\Desktop\Monotone-HWID-Spoofer-0.0.1\Commands\Hidden\process.batC:\Windows\System32\notepad.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\notepad.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3676ping localhost C:\Windows\System32\PING.EXEcmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
TCP/IP Ping Command
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ping.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
Total events
1 217
Read events
1 198
Write events
19
Delete events
0

Modification events

(PID) Process:(1276) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\178\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1276) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(1276) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(1276) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(1276) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(1276) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(1276) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(1276) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(1276) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000
(PID) Process:(1276) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\General
Operation:writeName:LastFolder
Value:
C:\Users\admin\Desktop
Executable files
10
Suspicious files
0
Text files
10
Unknown types
0

Dropped files

PID
Process
Filename
Type
1276WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1276.37214\Monotone-HWID-Spoofer-0.0.1\Commands\Hidden\Adapters2.exeexecutable
MD5:BB36D4578CE201DC932AB6BBC079875C
SHA256:4C831252AA6F193C4474BA74F352BEE7D00099DFAF5AC6E98AB1253E21999B4A
1276WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1276.37214\Monotone-HWID-Spoofer-0.0.1\README.mdtext
MD5:699D03E1E8ED798AEB721E8FD561682B
SHA256:4ABFD24B7422EE66D5849FDA386DFD1318DB4615F9126899A27FDB5A4FFA3D0D
1276WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1276.37214\Monotone-HWID-Spoofer-0.0.1\host.txttext
MD5:CDDA0101630962EAEE1EF0305C2028C0
SHA256:ECF34C7BC93D5B7F1EA5D8D17E488946EED415128658DA3BA2D02633C543234B
1276WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1276.37214\Monotone-HWID-Spoofer-0.0.1\Commands\Hidden\process.battext
MD5:2D3F9B2D001ABD6E58AC6F0E7337C619
SHA256:EF702CE2F8FB1BC71FB60E8B95CB83CEF4FA66AA96AFD7CA4FD67C96530B6E53
1276WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1276.37214\Monotone-HWID-Spoofer-0.0.1\Commands\Hidden\Adapters.exeexecutable
MD5:934BBC5411C532964F3BBE42CB1C1785
SHA256:B3DE6D10D9F94037B88F736609E50A8A4C4D516CA50107DEDD575797A654C28E
1276WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1276.37214\Monotone-HWID-Spoofer-0.0.1\GetInput.exeexecutable
MD5:2BA62AE6F88B11D0E262AF35D8DB8CA9
SHA256:3F5C64717A0092AE214154A730E96E2E56921BE2E3F1121A3E98B1BA84627665
1276WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1276.37214\Monotone-HWID-Spoofer-0.0.1\Commands\Hidden\Block.exeexecutable
MD5:5782B8D469BBC9045EBD2316C2AEFBD5
SHA256:DFD08E1D7A34BAE6836B3915B45B8637B85CDC998198C5BF148FBA5E96F15C21
1276WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1276.37214\Monotone-HWID-Spoofer-0.0.1\Getlen.battext
MD5:8C1812E76BA7BF09CB87384089A0AB7F
SHA256:83CE5342710A2F2E385A363402661E3426728DD6BCFE9D87E22F2FB858B07BDE
1276WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1276.37214\Monotone-HWID-Spoofer-0.0.1\batbox.exeexecutable
MD5:CB4A44BAA20AD26BF74615A7FC515A84
SHA256:9553BC17FA0FD08E026C1865812B3388E3D5495A5394BBF671E5A8F21C79989A
1276WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1276.37214\Monotone-HWID-Spoofer-0.0.1\hwid.ps1text
MD5:05673D49CC5F31E3D4812B7CB7419641
SHA256:C7C54526B07F457E58D423AB22D61A0EFD78AD112BE2EF0A1EFE6C25013DF185
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
2
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
2640
svchost.exe
239.255.255.250:1900
whitelisted

DNS requests

No data

Threats

No threats detected
No debug info