File name:

Ana.rar

Full analysis: https://app.any.run/tasks/ab9d2fd0-e667-4795-a507-742a0bced0b7
Verdict: Malicious activity
Analysis date: October 06, 2021, 22:39:45
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

6B1335924DAD8B015A4E3BE9F3EE99A2

SHA1:

0AFE8B95CEE31F49A0F04663F9D3F9043866F6D3

SHA256:

C41503708C30087FBC1ED228994F3F06609EC08A0D734D22B426530CEBA356A4

SSDEEP:

49152:I0RJLjODt+O28HTmgQouNjpg345uRUOM2N:1JLjOYJoT+F4WuRB

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • AnaFortnitecheat.exe (PID: 3944)
      • AnaFortnitecheat.exe (PID: 2380)
    • Drops executable file immediately after starts

      • AnaFortnitecheat.exe (PID: 2380)
      • wscript.exe (PID: 272)
    • Disables Windows Defender

      • wscript.exe (PID: 3628)
    • Task Manager has been disabled (taskmgr)

      • wscript.exe (PID: 3628)
    • Disables registry editing tools (regedit)

      • wscript.exe (PID: 3628)
    • Changes the login/logoff helper path in the registry

      • wscript.exe (PID: 3628)
  • SUSPICIOUS

    • Checks supported languages

      • WinRAR.exe (PID: 2504)
      • AnaFortnitecheat.exe (PID: 2380)
      • wscript.exe (PID: 272)
      • wscript.exe (PID: 3628)
      • wmplayer.exe (PID: 3920)
      • setup_wm.exe (PID: 1980)
    • Reads the computer name

      • WinRAR.exe (PID: 2504)
      • AnaFortnitecheat.exe (PID: 2380)
      • wscript.exe (PID: 272)
      • wscript.exe (PID: 3628)
      • wmplayer.exe (PID: 3920)
      • setup_wm.exe (PID: 1980)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2504)
      • AnaFortnitecheat.exe (PID: 2380)
      • wscript.exe (PID: 272)
    • Drops a file that was compiled in debug mode

      • AnaFortnitecheat.exe (PID: 2380)
      • wscript.exe (PID: 272)
    • Executes scripts

      • AnaFortnitecheat.exe (PID: 2380)
      • wscript.exe (PID: 272)
    • Creates a directory in Program Files

      • wscript.exe (PID: 272)
    • Creates files in the program directory

      • wscript.exe (PID: 272)
      • wscript.exe (PID: 3628)
    • Application launched itself

      • wscript.exe (PID: 272)
    • Reads Environment values

      • setup_wm.exe (PID: 1980)
  • INFO

    • Manual execution by user

      • AnaFortnitecheat.exe (PID: 2380)
      • AnaFortnitecheat.exe (PID: 3944)
    • Checks Windows Trust Settings

      • wscript.exe (PID: 272)
      • wscript.exe (PID: 3628)
    • Checks supported languages

      • notepad.exe (PID: 3052)
      • shutdown.exe (PID: 3420)
    • Reads the computer name

      • shutdown.exe (PID: 3420)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
49
Monitored processes
9
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe anafortnitecheat.exe no specs anafortnitecheat.exe wscript.exe notepad.exe no specs wscript.exe wmplayer.exe no specs setup_wm.exe no specs shutdown.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
272"C:\Windows\system32\wscript.exe" C:\Users\admin\AppData\Local\Temp\2AB3.tmp\2AB4.vbs C:\Windows\system32\wscript.exe
AnaFortnitecheat.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft � Windows Based Script Host
Exit code:
0
Version:
5.8.7600.16385
Modules
Images
c:\windows\system32\wscript.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1980"C:\Program Files\Windows Media Player\setup_wm.exe" /RunOnce:"C:\Program Files\Windows Media Player\wmplayer.exe" "C:\Program Files\mrsmajor\def_resource\f11.mp4"C:\Program Files\Windows Media Player\setup_wm.exewmplayer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Windows Media Configuration Utility
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\windows media player\setup_wm.exe
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2380"C:\Users\admin\Desktop\AnaFortnitecheat.exe" C:\Users\admin\Desktop\AnaFortnitecheat.exe
Explorer.EXE
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\desktop\anafortnitecheat.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
2504"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Ana.rar"C:\Program Files\WinRAR\WinRAR.exe
Explorer.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\windows\system32\ntdll.dll
c:\program files\winrar\winrar.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3052"C:\Windows\System32\notepad.exe" C:\Windows\System32\notepad.exewscript.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Notepad
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\notepad.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\rpcrt4.dll
3420"C:\Windows\System32\shutdown.exe" -r -t 03C:\Windows\System32\shutdown.exewscript.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Shutdown and Annotation Tool
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\shutdown.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\secur32.dll
3628"C:\Windows\System32\wscript.exe" "C:\Program files\mrsmajor\mrsmajorlauncher.vbs" RunAsAdministratorC:\Windows\System32\wscript.exe
wscript.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft � Windows Based Script Host
Exit code:
0
Version:
5.8.7600.16385
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\wscript.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
3920"C:\Program Files\Windows Media Player\wmplayer.exe" "C:\Program Files\mrsmajor\def_resource\f11.mp4"C:\Program Files\Windows Media Player\wmplayer.exewscript.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Media Player
Exit code:
0
Version:
12.0.7601.23517 (win7sp1_ldr.160812-0732)
Modules
Images
c:\program files\windows media player\wmplayer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3944"C:\Users\admin\Desktop\AnaFortnitecheat.exe" C:\Users\admin\Desktop\AnaFortnitecheat.exeExplorer.EXE
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\desktop\anafortnitecheat.exe
c:\windows\system32\ntdll.dll
Total events
2 454
Read events
2 371
Write events
83
Delete events
0

Modification events

(PID) Process:(2504) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2504) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2504) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2504) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(2504) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Ana.rar
(PID) Process:(2504) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2504) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2504) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2504) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2504) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000
Executable files
3
Suspicious files
0
Text files
75
Unknown types
4

Dropped files

PID
Process
Filename
Type
2380AnaFortnitecheat.exeC:\Users\admin\AppData\Local\Temp\2AB3.tmp\mrsmajor\def_resource\@Tile@@.jpgimage
MD5:3E21BCF0D1E7F39D8B8EC2C940489CA2
SHA256:064F135FCC026A574552F42901B51052345F4B0F122EDD7ACD5F2DCC023160A5
2380AnaFortnitecheat.exeC:\Users\admin\AppData\Local\Temp\2AB3.tmp\2AB4.vbstext
MD5:5706BC5D518069A3B2BE5E6FAC51B12F
SHA256:8A74EEAD47657582C84209EB4CDBA545404D9C67DD288C605515A86E06DE0AAD
2380AnaFortnitecheat.exeC:\Users\admin\AppData\Local\Temp\2AB3.tmp\mrsmajor\MrsMjrGui.exeexecutable
MD5:450F49426B4519ECAAC8CD04814C03A4
SHA256:087FCA40E079746B9C1DFAF777D3994C0321EA8F69D08238CDFC02FB109ADD1D
272wscript.exeC:\Program Files\mrsmajor\CPUUsage.vbstext
MD5:0E4C01BF30B13C953F8F76DB4A7E857D
SHA256:28E69E90466034CE392E84DB2BDE3AD43AD556D12609E3860F92016641B2A738
2380AnaFortnitecheat.exeC:\Users\admin\AppData\Local\Temp\2AB3.tmp\mrsmajor\mrsmajorlauncher.vbstext
MD5:E3FDF285B14FB588F674EBFC2134200C
SHA256:4D3AA3ECD16A6BA46A9D6C0BDACDCD9DCE70D93585941A94E544696E3E6F7D92
2380AnaFortnitecheat.exeC:\Users\admin\AppData\Local\Temp\2AB3.tmp\mrsmajor\MrsMjrGuiLauncher.battext
MD5:C7146F88F4184C6EE5DCF7A62846AA23
SHA256:47E6C9F62FFC41FBC555F8644AD099A96573C8C023797127F78B1A952CA1B963
2380AnaFortnitecheat.exeC:\Users\admin\AppData\Local\Temp\2AB3.tmp\mrsmajor\reStart.vbstext
MD5:0851E8D791F618DAA5B72D40E0C8E32B
SHA256:2CBD8BC239C5CFC3EF02F8472D867DFF61E5AED9FDE8A3823CDA28CC37D77722
2380AnaFortnitecheat.exeC:\Users\admin\AppData\Local\Temp\2AB3.tmp\mrsmajor\def_resource\f11.mp4m4v
MD5:17042B9E5FC04A571311CD484F17B9EB
SHA256:A9B0F1F849E0B41924F5E80B0C4948E63FC4B4F335BBDF0F997B03A3AFF55424
2504WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2504.15622\AnaFortnitecheat.exeexecutable
MD5:38FF71C1DEE2A9ADD67F1EDB1A30FF8C
SHA256:730A41A7656F606A22E9F0D68782612D6E00AB8CFE1260160B9E0B00BC2E442A
2380AnaFortnitecheat.exeC:\Users\admin\AppData\Local\Temp\2AB3.tmp\mrsmajor\Launcher.vbstext
MD5:B5A1C9AE4C2AE863AC3F6A019F556A22
SHA256:6F0BB8CC239AF15C9215867D6225C8FF344052AAA0DEEB3452DBF463B8C46529
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info