File name:

ByRR Crypter & Binder.rar

Full analysis: https://app.any.run/tasks/8dd9f78a-d38c-467e-855f-a4ac9dc8fe57
Verdict: Malicious activity
Threats:

AsyncRAT is a RAT that can monitor and remotely control infected systems. This malware was introduced on Github as a legitimate open-source remote administration software, but hackers use it for its many powerful malicious functions.

Analysis date: March 23, 2021, 07:46:17
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
trojan
rat
asyncrat
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

4EE2CD532CD36307AE7ACA567CD92317

SHA1:

EE5F68830DC14DF7D071BEDF59AEA628C2CC1E24

SHA256:

C1A7CB86235EDF4EF81198CC426FB569ADDF85C2F8E7F4A9575B0DD956100CA4

SSDEEP:

12288:MdcEt2UVToRfh12duWlXM0DomHCvD3/5/Mp0Q:gcCV2h12duKc0Domib9Mp1

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • ByRR FUD Crypter and Binder.exe (PID: 2960)
      • wermgr.exe (PID: 2432)
      • ByRR FUD Crypter and Binder.exe (PID: 3872)
      • fgj.exe (PID: 3892)
    • Drops executable file immediately after starts

      • ByRR FUD Crypter and Binder.exe (PID: 2960)
    • ASYNCRAT was detected

      • wermgr.exe (PID: 2432)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2588)
      • ByRR FUD Crypter and Binder.exe (PID: 2960)
      • ByRR FUD Crypter and Binder.exe (PID: 3872)
    • Drops a file with too old compile date

      • WinRAR.exe (PID: 2588)
      • ByRR FUD Crypter and Binder.exe (PID: 2960)
      • ByRR FUD Crypter and Binder.exe (PID: 3872)
    • Creates files in the program directory

      • ByRR FUD Crypter and Binder.exe (PID: 2960)
    • Drops a file that was compiled in debug mode

      • ByRR FUD Crypter and Binder.exe (PID: 2960)
  • INFO

    • Manual execution by user

      • ByRR FUD Crypter and Binder.exe (PID: 2960)
      • fgj.exe (PID: 3892)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
47
Monitored processes
5
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details

Process information

PID
CMD
Path
Indicators
Parent process
2432"C:\ProgramData\wermgr.exe" C:\ProgramData\wermgr.exe
ByRR FUD Crypter and Binder.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19141.785
Modules
Images
c:\programdata\wermgr.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2588"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\ByRR Crypter & Binder.rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2960"C:\Users\admin\Desktop\ByRR FUD Crypter and Binder.exe" C:\Users\admin\Desktop\ByRR FUD Crypter and Binder.exe
explorer.exe
User:
admin
Company:
ByRR
Integrity Level:
MEDIUM
Description:
ByRR FUD Crypter and Binder
Exit code:
0
Version:
3.1.2.1
Modules
Images
c:\users\admin\desktop\byrr fud crypter and binder.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3872"C:\ProgramData\ByRR FUD Crypter and Binder.exe" C:\ProgramData\ByRR FUD Crypter and Binder.exe
ByRR FUD Crypter and Binder.exe
User:
admin
Company:
ByRR
Integrity Level:
MEDIUM
Description:
ByRR FUD Crypter and Binder
Exit code:
0
Version:
3.1.2.1
Modules
Images
c:\programdata\byrr fud crypter and binder.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3892"C:\Users\admin\Desktop\fgj.exe" C:\Users\admin\Desktop\fgj.exe
explorer.exe
User:
admin
Company:
ByRR
Integrity Level:
MEDIUM
Description:
ByRR Stub
Exit code:
0
Version:
1.0.2.1
Modules
Images
c:\users\admin\desktop\fgj.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
Total events
1 200
Read events
1 030
Write events
161
Delete events
9

Modification events

(PID) Process:(2588) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2588) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2588) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\13D\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2588) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\13D\52C64B7E
Operation:writeName:@C:\Windows\system32\NetworkExplorer.dll,-1
Value:
Network
(PID) Process:(2588) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface
Operation:writeName:ShowPassword
Value:
0
(PID) Process:(2588) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface
Operation:writeName:ShowPassword
Value:
1
(PID) Process:(2588) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\ByRR Crypter & Binder.rar
(PID) Process:(2588) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2588) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2588) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
Executable files
5
Suspicious files
4
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
2432wermgr.exeC:\Users\admin\AppData\Local\Temp\CabC112.tmp
MD5:
SHA256:
2432wermgr.exeC:\Users\admin\AppData\Local\Temp\TarC113.tmp
MD5:
SHA256:
2432wermgr.exeC:\Users\admin\AppData\Local\Temp\CabC143.tmp
MD5:
SHA256:
2432wermgr.exeC:\Users\admin\AppData\Local\Temp\TarC144.tmp
MD5:
SHA256:
2432wermgr.exeC:\Users\admin\AppData\Local\Temp\CabC1B3.tmp
MD5:
SHA256:
2432wermgr.exeC:\Users\admin\AppData\Local\Temp\TarC1B4.tmp
MD5:
SHA256:
2432wermgr.exeC:\Users\admin\AppData\Local\Temp\CabC212.tmp
MD5:
SHA256:
2432wermgr.exeC:\Users\admin\AppData\Local\Temp\TarC213.tmp
MD5:
SHA256:
2432wermgr.exeC:\Users\admin\AppData\Local\Temp\CabC253.tmp
MD5:
SHA256:
2432wermgr.exeC:\Users\admin\AppData\Local\Temp\TarC254.tmp
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
3
DNS requests
3
Threats
3

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2432
wermgr.exe
GET
200
8.253.95.249:80
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab
US
compressed
57.2 Kb
whitelisted
2432
wermgr.exe
GET
304
8.253.95.249:80
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab
US
compressed
57.2 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2432
wermgr.exe
104.21.17.70:443
paste.tc
Cloudflare Inc
US
unknown
8.253.95.249:80
www.download.windowsupdate.com
Global Crossing
US
suspicious
2432
wermgr.exe
3.141.210.37:14186
6.tcp.ngrok.io
US
malicious

DNS requests

Domain
IP
Reputation
paste.tc
  • 104.21.17.70
  • 172.67.223.56
unknown
6.tcp.ngrok.io
  • 3.141.210.37
malicious
www.download.windowsupdate.com
  • 8.253.95.249
  • 8.248.137.254
  • 8.248.119.254
  • 67.26.139.254
  • 8.248.117.254
whitelisted

Threats

PID
Process
Class
Message
1052
svchost.exe
Potential Corporate Privacy Violation
ET POLICY DNS Query to a *.ngrok domain (ngrok.io)
2432
wermgr.exe
A Network Trojan was detected
SUSPICIOUS [PTsecurity] Possible AsyncRAT/Quasar SSL certificate
2432
wermgr.exe
A Network Trojan was detected
REMOTE [PTsecurity] AsyncRAT Connection
No debug info