File name:

5.rar

Full analysis: https://app.any.run/tasks/2813e8f6-f3b2-4e93-bf3b-47be0328c8f0
Verdict: Malicious activity
Analysis date: May 01, 2020, 07:51:46
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
evasion
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

A94530F6774CF5C232FE681FAE0590A4

SHA1:

EBF5377465FB6B601401231085EFF9776D468FAC

SHA256:

BF94C9ED64E31592E885863B07A83961228412203D2E91023926B7DC1F469001

SSDEEP:

98304:8jL3U7CgS1oTSWTl7el3wwREzWeAQKERbk29GJ7M:kGCroTSWFBie429GJ7M

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • IPTV Checker 2.1.exe (PID: 2736)
      • IPTV Checker 1.09.exe (PID: 2064)
      • Playlist Checker -2017- Playlist Tarayici-Albatros.exe (PID: 816)
  • SUSPICIOUS

    • Reads Environment values

      • IPTV Checker 2.1.exe (PID: 2736)
    • Executes JAVA applets

      • IPTV-UrlChecker V3.5.exe (PID: 1696)
    • Starts Internet Explorer

      • IPTV Checker 1.09.exe (PID: 2064)
    • Checks for external IP

      • IPTV Checker 1.09.exe (PID: 2064)
      • IPTV Checker 2.1.exe (PID: 2736)
  • INFO

    • Manual execution by user

      • IPTV Checker 2.1.exe (PID: 2736)
      • IPTV-UrlChecker V3.5.exe (PID: 1696)
      • Playlist Checker -2017- Playlist Tarayici-Albatros.exe (PID: 816)
      • Playlist Checker.exe (PID: 3740)
      • IPTV Checker 1.09.exe (PID: 2064)
    • Changes internet zones settings

      • iexplore.exe (PID: 1536)
    • Reads internet explorer settings

      • iexplore.exe (PID: 1136)
    • Reads Internet Cache Settings

      • iexplore.exe (PID: 1536)
      • iexplore.exe (PID: 1136)
    • Application launched itself

      • iexplore.exe (PID: 1536)
    • Reads settings of System Certificates

      • iexplore.exe (PID: 1136)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
44
Monitored processes
9
Malicious processes
1
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe no specs iptv checker 2.1.exe iptv checker 1.09.exe playlist checker -2017- playlist tarayici-albatros.exe no specs playlist checker.exe no specs iptv-urlchecker v3.5.exe no specs javaw.exe iexplore.exe no specs iexplore.exe

Process information

PID
CMD
Path
Indicators
Parent process
540"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\5.rar"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
816"C:\Users\admin\Desktop\Playlist Checker -2017- Playlist Tarayici-Albatros.exe" C:\Users\admin\Desktop\Playlist Checker -2017- Playlist Tarayici-Albatros.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Playlist Checker-uyduportal.com
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\playlist checker -2017- playlist tarayici-albatros.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1136"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:1536 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
1536"C:\Program Files\Internet Explorer\iexplore.exe" https://absidev.com/C:\Program Files\Internet Explorer\iexplore.exeIPTV Checker 1.09.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
1
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
1696"C:\Users\admin\Desktop\IPTV_UrlChecker_V3.5\IPTV-UrlChecker V3.5.exe" C:\Users\admin\Desktop\IPTV_UrlChecker_V3.5\IPTV-UrlChecker V3.5.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\iptv_urlchecker_v3.5\iptv-urlchecker v3.5.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
2064"C:\Users\admin\Desktop\IPTV Checker 1.09.exe" C:\Users\admin\Desktop\IPTV Checker 1.09.exe
explorer.exe
User:
admin
Company:
Tiny-Tools.com
Integrity Level:
MEDIUM
Description:
IPTV Checker 1.09
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\iptv checker 1.09.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2736"C:\Users\admin\Desktop\IPTV Checker 2.1.exe" C:\Users\admin\Desktop\IPTV Checker 2.1.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
IPTV Checker 2.0
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\iptv checker 2.1.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3740"C:\Users\admin\Desktop\Playlist Checker\Playlist Checker.exe" C:\Users\admin\Desktop\Playlist Checker\Playlist Checker.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Playlist Checker
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\playlist checker\playlist checker.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3972"C:\Program Files\Java\jre1.8.0_92\bin\javaw.exe" -classpath "C:\Users\admin\AppData\Local\Temp\temp0.jar;C:\Users\admin\AppData\Local\Temp\temp1.jar;" propro.PROpro C:\Program Files\Java\jre1.8.0_92\bin\javaw.exe
IPTV-UrlChecker V3.5.exe
User:
admin
Company:
Oracle Corporation
Integrity Level:
MEDIUM
Description:
Java(TM) Platform SE binary
Exit code:
0
Version:
8.0.920.14
Modules
Images
c:\program files\java\jre1.8.0_92\bin\javaw.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
1 162
Read events
1 048
Write events
110
Delete events
4

Modification events

(PID) Process:(540) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(540) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(540) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(540) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\5.rar
(PID) Process:(540) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(540) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(540) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(540) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2736) IPTV Checker 2.1.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Direct3D\MostRecentApplication
Operation:writeName:Name
Value:
IPTV Checker 2.1.exe
(PID) Process:(2736) IPTV Checker 2.1.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\IPTV Checker 2_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
Executable files
2
Suspicious files
13
Text files
19
Unknown types
6

Dropped files

PID
Process
Filename
Type
540WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa540.35958\Playlist Checker\Playlist Checker.exe
MD5:
SHA256:
540WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa540.35958\IPTV Checker 1.09.exe
MD5:
SHA256:
540WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa540.35958\IPTV Checker 2.1.exe
MD5:
SHA256:
540WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa540.35958\Playlist Checker -2017- Playlist Tarayici-Albatros.exe
MD5:
SHA256:
540WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa540.35958\IPTV_UrlChecker_V3.5\DATA\Jico.dat
MD5:
SHA256:
540WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa540.35958\IPTV_UrlChecker_V3.5\IPTV-UrlChecker V3.5.exe
MD5:
SHA256:
540WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa540.35958\IPTV_UrlChecker_V3.5\Playlists\infos Plylists.txt
MD5:
SHA256:
540WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa540.35958\IPTV_UrlChecker_V3.5\Playlists\Playlist 0.m3u
MD5:
SHA256:
540WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa540.35958\IPTV_UrlChecker_V3.5\Playlists\Playlist 10.m3u
MD5:
SHA256:
540WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa540.35958\IPTV_UrlChecker_V3.5\Playlists\Playlist 12.m3u
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
10
TCP/UDP connections
24
DNS requests
11
Threats
4

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2064
IPTV Checker 1.09.exe
GET
307
86.252.225.170:80
http://tiny-tools.com/software/app2/iptv_checker
FR
whitelisted
1136
iexplore.exe
GET
200
216.58.206.3:80
http://ocsp.pki.goog/gts1o1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRCRjDCJxnb3nDwj%2Fxz5aZfZjgXvAQUmNH4bhDrz5vsYJ8YkBug630J%2FSsCEApFQkhjIuntAgAAAABiB5I%3D
US
der
471 b
whitelisted
1136
iexplore.exe
GET
200
216.58.206.3:80
http://ocsp.pki.goog/gsr2/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBTgXIsxbvr2lBkPpoIEVRE6gHlCnAQUm%2BIHV2ccHsBqBt5ZtJot39wZhi4CDQHjtJqhjYqpgSVpULg%3D
US
der
468 b
whitelisted
1136
iexplore.exe
GET
200
2.16.186.35:80
http://isrg.trustid.ocsp.identrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRv9GhNQxLSSGKBnMArPUcsHYovpgQUxKexpHsscfrb4UuQdf%2FEFWCFiRACEAoBQUIAAAFThXNqC4Xspwg%3D
unknown
der
1.37 Kb
whitelisted
3972
javaw.exe
GET
301
67.199.248.10:80
http://bit.ly/2zTez35
US
html
162 b
shared
1136
iexplore.exe
GET
200
2.16.186.11:80
http://isrg.trustid.ocsp.identrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRv9GhNQxLSSGKBnMArPUcsHYovpgQUxKexpHsscfrb4UuQdf%2FEFWCFiRACEAoBQUIAAAFThXNqC4Xspwg%3D
unknown
der
1.37 Kb
whitelisted
2064
IPTV Checker 1.09.exe
GET
200
208.95.112.1:80
http://ip-api.com/json
unknown
text
260 b
malicious
1136
iexplore.exe
GET
200
216.58.206.3:80
http://ocsp.pki.goog/gsr2/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBTgXIsxbvr2lBkPpoIEVRE6gHlCnAQUm%2BIHV2ccHsBqBt5ZtJot39wZhi4CDQHjtJqhjYqpgSVpULg%3D
US
der
468 b
whitelisted
3972
javaw.exe
GET
404
173.212.219.42:80
http://star7-dz.info/user.asp?id=107524&f=CharFcontroler351.txt
DE
html
1.22 Kb
malicious
1136
iexplore.exe
GET
200
216.58.206.3:80
http://ocsp.pki.goog/gts1o1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRCRjDCJxnb3nDwj%2Fxz5aZfZjgXvAQUmNH4bhDrz5vsYJ8YkBug630J%2FSsCEApFQkhjIuntAgAAAABiB5I%3D
US
der
471 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2736
IPTV Checker 2.1.exe
86.252.225.170:80
tiny-tools.com
Orange
FR
unknown
2736
IPTV Checker 2.1.exe
208.95.112.1:80
ip-api.com
IBURST
malicious
1136
iexplore.exe
86.252.225.170:443
tiny-tools.com
Orange
FR
unknown
2064
IPTV Checker 1.09.exe
208.95.112.1:80
ip-api.com
IBURST
malicious
3972
javaw.exe
67.199.248.10:80
bit.ly
Bitly Inc
US
shared
2064
IPTV Checker 1.09.exe
86.252.225.170:80
tiny-tools.com
Orange
FR
unknown
1136
iexplore.exe
46.105.201.240:443
s10.histats.com
OVH SAS
FR
suspicious
1136
iexplore.exe
172.217.18.10:443
fonts.googleapis.com
Google Inc.
US
whitelisted
1136
iexplore.exe
2.16.186.11:80
isrg.trustid.ocsp.identrust.com
Akamai International B.V.
whitelisted
1136
iexplore.exe
216.58.206.3:443
ocsp.pki.goog
Google Inc.
US
whitelisted

DNS requests

Domain
IP
Reputation
tiny-tools.com
  • 86.252.225.170
whitelisted
ip-api.com
  • 208.95.112.1
malicious
bit.ly
  • 67.199.248.10
  • 67.199.248.11
shared
star7-dz.info
  • 173.212.219.42
unknown
absidev.com
  • 86.252.225.170
unknown
isrg.trustid.ocsp.identrust.com
  • 2.16.186.35
  • 2.16.186.11
whitelisted
fonts.googleapis.com
  • 172.217.18.10
whitelisted
ocsp.pki.goog
  • 216.58.206.3
whitelisted
fonts.gstatic.com
  • 216.58.206.3
whitelisted
s10.histats.com
  • 46.105.201.240
whitelisted

Threats

PID
Process
Class
Message
2064
IPTV Checker 1.09.exe
Potential Corporate Privacy Violation
ET POLICY External IP Lookup ip-api.com
2064
IPTV Checker 1.09.exe
Potential Corporate Privacy Violation
AV POLICY Internal Host Retrieving External IP Address (ip-api. com)
2736
IPTV Checker 2.1.exe
Potential Corporate Privacy Violation
ET POLICY External IP Lookup ip-api.com
2736
IPTV Checker 2.1.exe
Potential Corporate Privacy Violation
AV POLICY Internal Host Retrieving External IP Address (ip-api. com)
No debug info