File name:

Ana.rar

Full analysis: https://app.any.run/tasks/ab9d2fd0-e667-4795-a507-742a0bced0b7
Verdict: Malicious activity
Analysis date: October 06, 2021, 22:39:45
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

6B1335924DAD8B015A4E3BE9F3EE99A2

SHA1:

0AFE8B95CEE31F49A0F04663F9D3F9043866F6D3

SHA256:

C41503708C30087FBC1ED228994F3F06609EC08A0D734D22B426530CEBA356A4

SSDEEP:

49152:I0RJLjODt+O28HTmgQouNjpg345uRUOM2N:1JLjOYJoT+F4WuRB

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • AnaFortnitecheat.exe (PID: 3944)
      • AnaFortnitecheat.exe (PID: 2380)
    • Drops executable file immediately after starts

      • AnaFortnitecheat.exe (PID: 2380)
      • wscript.exe (PID: 272)
    • Task Manager has been disabled (taskmgr)

      • wscript.exe (PID: 3628)
    • Disables registry editing tools (regedit)

      • wscript.exe (PID: 3628)
    • Changes the login/logoff helper path in the registry

      • wscript.exe (PID: 3628)
    • Disables Windows Defender

      • wscript.exe (PID: 3628)
  • SUSPICIOUS

    • Checks supported languages

      • WinRAR.exe (PID: 2504)
      • AnaFortnitecheat.exe (PID: 2380)
      • wscript.exe (PID: 272)
      • wscript.exe (PID: 3628)
      • wmplayer.exe (PID: 3920)
      • setup_wm.exe (PID: 1980)
    • Reads the computer name

      • WinRAR.exe (PID: 2504)
      • AnaFortnitecheat.exe (PID: 2380)
      • wscript.exe (PID: 272)
      • wscript.exe (PID: 3628)
      • wmplayer.exe (PID: 3920)
      • setup_wm.exe (PID: 1980)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2504)
      • AnaFortnitecheat.exe (PID: 2380)
      • wscript.exe (PID: 272)
    • Executes scripts

      • AnaFortnitecheat.exe (PID: 2380)
      • wscript.exe (PID: 272)
    • Drops a file that was compiled in debug mode

      • AnaFortnitecheat.exe (PID: 2380)
      • wscript.exe (PID: 272)
    • Creates a directory in Program Files

      • wscript.exe (PID: 272)
    • Creates files in the program directory

      • wscript.exe (PID: 272)
      • wscript.exe (PID: 3628)
    • Application launched itself

      • wscript.exe (PID: 272)
    • Reads Environment values

      • setup_wm.exe (PID: 1980)
  • INFO

    • Manual execution by user

      • AnaFortnitecheat.exe (PID: 3944)
      • AnaFortnitecheat.exe (PID: 2380)
    • Checks Windows Trust Settings

      • wscript.exe (PID: 272)
      • wscript.exe (PID: 3628)
    • Checks supported languages

      • notepad.exe (PID: 3052)
      • shutdown.exe (PID: 3420)
    • Reads the computer name

      • shutdown.exe (PID: 3420)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
49
Monitored processes
9
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe anafortnitecheat.exe no specs anafortnitecheat.exe wscript.exe notepad.exe no specs wscript.exe wmplayer.exe no specs setup_wm.exe no specs shutdown.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
272"C:\Windows\system32\wscript.exe" C:\Users\admin\AppData\Local\Temp\2AB3.tmp\2AB4.vbs C:\Windows\system32\wscript.exe
AnaFortnitecheat.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft � Windows Based Script Host
Exit code:
0
Version:
5.8.7600.16385
Modules
Images
c:\windows\system32\wscript.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1980"C:\Program Files\Windows Media Player\setup_wm.exe" /RunOnce:"C:\Program Files\Windows Media Player\wmplayer.exe" "C:\Program Files\mrsmajor\def_resource\f11.mp4"C:\Program Files\Windows Media Player\setup_wm.exewmplayer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Windows Media Configuration Utility
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\windows media player\setup_wm.exe
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2380"C:\Users\admin\Desktop\AnaFortnitecheat.exe" C:\Users\admin\Desktop\AnaFortnitecheat.exe
Explorer.EXE
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\desktop\anafortnitecheat.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
2504"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Ana.rar"C:\Program Files\WinRAR\WinRAR.exe
Explorer.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\windows\system32\ntdll.dll
c:\program files\winrar\winrar.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3052"C:\Windows\System32\notepad.exe" C:\Windows\System32\notepad.exewscript.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Notepad
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\notepad.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\rpcrt4.dll
3420"C:\Windows\System32\shutdown.exe" -r -t 03C:\Windows\System32\shutdown.exewscript.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Shutdown and Annotation Tool
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\shutdown.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\secur32.dll
3628"C:\Windows\System32\wscript.exe" "C:\Program files\mrsmajor\mrsmajorlauncher.vbs" RunAsAdministratorC:\Windows\System32\wscript.exe
wscript.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft � Windows Based Script Host
Exit code:
0
Version:
5.8.7600.16385
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\wscript.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
3920"C:\Program Files\Windows Media Player\wmplayer.exe" "C:\Program Files\mrsmajor\def_resource\f11.mp4"C:\Program Files\Windows Media Player\wmplayer.exewscript.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Media Player
Exit code:
0
Version:
12.0.7601.23517 (win7sp1_ldr.160812-0732)
Modules
Images
c:\program files\windows media player\wmplayer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3944"C:\Users\admin\Desktop\AnaFortnitecheat.exe" C:\Users\admin\Desktop\AnaFortnitecheat.exeExplorer.EXE
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\desktop\anafortnitecheat.exe
c:\windows\system32\ntdll.dll
Total events
2 454
Read events
2 371
Write events
83
Delete events
0

Modification events

(PID) Process:(2504) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2504) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2504) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2504) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(2504) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Ana.rar
(PID) Process:(2504) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2504) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2504) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2504) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2504) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000
Executable files
3
Suspicious files
0
Text files
75
Unknown types
4

Dropped files

PID
Process
Filename
Type
2380AnaFortnitecheat.exeC:\Users\admin\AppData\Local\Temp\2AB3.tmp\mrsmajor\def_resource\f11.mp4m4v
MD5:17042B9E5FC04A571311CD484F17B9EB
SHA256:A9B0F1F849E0B41924F5E80B0C4948E63FC4B4F335BBDF0F997B03A3AFF55424
2380AnaFortnitecheat.exeC:\Users\admin\AppData\Local\Temp\2AB3.tmp\2AB4.vbstext
MD5:5706BC5D518069A3B2BE5E6FAC51B12F
SHA256:8A74EEAD47657582C84209EB4CDBA545404D9C67DD288C605515A86E06DE0AAD
2380AnaFortnitecheat.exeC:\Users\admin\AppData\Local\Temp\2AB3.tmp\mrsmajor\Launcher.vbstext
MD5:B5A1C9AE4C2AE863AC3F6A019F556A22
SHA256:6F0BB8CC239AF15C9215867D6225C8FF344052AAA0DEEB3452DBF463B8C46529
272wscript.exeC:\Program Files\mrsmajor\CPUUsage.vbstext
MD5:0E4C01BF30B13C953F8F76DB4A7E857D
SHA256:28E69E90466034CE392E84DB2BDE3AD43AD556D12609E3860F92016641B2A738
2380AnaFortnitecheat.exeC:\Users\admin\AppData\Local\Temp\2AB3.tmp\mrsmajor\MrsMjrGui.exeexecutable
MD5:450F49426B4519ECAAC8CD04814C03A4
SHA256:087FCA40E079746B9C1DFAF777D3994C0321EA8F69D08238CDFC02FB109ADD1D
2380AnaFortnitecheat.exeC:\Users\admin\AppData\Local\Temp\2AB3.tmp\mrsmajor\Icon_resource\SkullIco.icoimage
MD5:C7BF05D7CB3535F7485606CF5B5987FE
SHA256:4C1CFBE274F993941AC5FA512C376B6D7344800FB8BE08CC6344E6C16A418311
2380AnaFortnitecheat.exeC:\Users\admin\AppData\Local\Temp\2AB3.tmp\mrsmajor\WinLogon.battext
MD5:870BCE376C1B71365390A9E9AEFB9A33
SHA256:2798DAD008F62AACE1841EDFB43146147A9CADE388C419C96DA788FCAA2F76BC
2380AnaFortnitecheat.exeC:\Users\admin\AppData\Local\Temp\2AB3.tmp\mrsmajor\def_resource\@Tile@@.jpgimage
MD5:3E21BCF0D1E7F39D8B8EC2C940489CA2
SHA256:064F135FCC026A574552F42901B51052345F4B0F122EDD7ACD5F2DCC023160A5
2380AnaFortnitecheat.exeC:\Users\admin\AppData\Local\Temp\2AB3.tmp\mrsmajor\def_resource\creepysound.mp3mov
MD5:4A9B1D8A8FE8A75C81DDBA3E411DDC5D
SHA256:79E9A3611494B5FFAFAA79788BA7E11DD218E3800C40B56684CCC0C33AB64EAC
2380AnaFortnitecheat.exeC:\Users\admin\AppData\Local\Temp\2AB3.tmp\mrsmajor\def_resource\Skullcur.curimage
MD5:CEA57C3A54A04118F1DB9DB8B38EA17A
SHA256:D2B6DB8B28112DA51E34972DEC513278A56783D24B8B5408F11997E9E67D422B
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info