analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

GBA Co Ltd Products Lists Scan.iso

Full analysis: https://app.any.run/tasks/f8c3d66f-86e5-4e3a-9628-0f5a5d745120
Verdict: Malicious activity
Threats:

LokiBot was developed in 2015 to steal information from a variety of applications. Despite the age, this malware is still rather popular among cybercriminals.

Analysis date: January 22, 2019, 21:08:22
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
trojan
lokibot
Indicators:
MIME: application/x-iso9660-image
File info: ISO 9660 CD-ROM filesystem data 'GBA Co Ltd Products Lists Scan'
MD5:

3291FA5259636CEE2846CCB2C6C85E43

SHA1:

28531C766FA6503B395DBB335A71DC6B797BFF89

SHA256:

C4D963D0FD9A49FC0687D8CDFA4BD47131D13555EAD547EC6BDE4C824795BDBA

SSDEEP:

6144:GFprso/208T2t2srEMdE/jtnA/FNWZKdAJ18:KpQo/2kt2srEM2jhkH6Kdg

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • GBA Co Ltd Products Lists Scan.exe (PID: 2392)
      • RegAsm.exe (PID: 3364)
    • Detected artifacts of LokiBot

      • RegAsm.exe (PID: 3364)
    • Actions looks like stealing of personal data

      • RegAsm.exe (PID: 3364)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3100)
      • RegAsm.exe (PID: 3364)
    • Loads DLL from Mozilla Firefox

      • RegAsm.exe (PID: 3364)
    • Creates files in the user directory

      • RegAsm.exe (PID: 3364)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.iso | ISO 9660 CD image (27.6)
.atn | Photoshop Action (27.1)
.gmc | Game Music Creator Music (6.1)

EXIF

ISO

System: Win32
VolumeName: GBA Co Ltd Products Lists Scan
VolumeBlockCount: 174
VolumeBlockSize: 2048
RootDirectoryCreateDate: 2019:01:20 14:09:17-08:00
Software: PowerISO
VolumeCreateDate: 2019:01:20 14:09:17.00-08:00
VolumeModifyDate: 2019:01:20 14:09:17.00-08:00

Composite

VolumeSize: 348 kB
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
33
Monitored processes
4
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
start drop and start rundll32.exe no specs winrar.exe gba co ltd products lists scan.exe no specs #LOKIBOT regasm.exe

Process information

PID
CMD
Path
Indicators
Parent process
2996"C:\Windows\system32\rundll32.exe" C:\Windows\system32\shell32.dll,OpenAs_RunDLL C:\Users\admin\AppData\Local\Temp\GBA Co Ltd Products Lists Scan.isoC:\Windows\system32\rundll32.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
3100"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\GBA Co Ltd Products Lists Scan.iso"C:\Program Files\WinRAR\WinRAR.exe
rundll32.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.60.0
2392"C:\Users\admin\AppData\Local\Temp\Rar$EXa3100.34669\GBA Co Ltd Products Lists Scan.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3100.34669\GBA Co Ltd Products Lists Scan.exeWinRAR.exe
User:
admin
Company:
Deezer
Integrity Level:
MEDIUM
Description:
Deezer
Exit code:
0
Version:
4.0.5.26
3364C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegAsm.exeC:\Windows\Microsoft.NET\Framework\v2.0.50727\RegAsm.exe
GBA Co Ltd Products Lists Scan.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft .NET Assembly Registration Utility
Version:
2.0.50727.5420 (Win7SP1.050727-5400)
Total events
981
Read events
879
Write events
0
Delete events
0

Modification events

No data
Executable files
2
Suspicious files
0
Text files
0
Unknown types
2

Dropped files

PID
Process
Filename
Type
3364RegAsm.exeC:\Users\admin\AppData\Roaming\F63AAA\A71D80.lck
MD5:
SHA256:
3100WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3100.34669\GBA Co Ltd Products Lists Scan.exeexecutable
MD5:FD8F74C06AA33668FFA587BCCB998321
SHA256:5DE0B0713F666E9EA655E0DB5A3675C51E01BC9AB4ED1381446172F3C92CC558
3364RegAsm.exeC:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\0f5007522459c86e95ffcc62f32308f1_90059c37-1320-41a4-b58d-2b75a9850d2fdbf
MD5:18B8CFC0185C50383AAC0A4F30A9DAC8
SHA256:913E8CED6A447FE791954D382ABA52D490513C5D2F689B391866C7E561F89A03
3364RegAsm.exeC:\Users\admin\AppData\Roaming\F63AAA\A71D80.exeexecutable
MD5:278EDBD499374BF73621F8C1F969D894
SHA256:C6999B9F79932C3B4F1C461A69D9DC8DC301D6A155ABC33EFE1B6E9E4A038391
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
1
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

Domain
IP
Reputation
wetrans0.ru
unknown

Threats

No threats detected
No debug info