File name:

IPTV v.5.0.3 Promotional version.rar

Full analysis: https://app.any.run/tasks/fdb16ac3-c845-433b-a12d-a43e2d19945d
Verdict: Malicious activity
Analysis date: September 05, 2018, 02:12:12
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

A228EA293EEA683539BC91BF89C7EAD9

SHA1:

E546B4A316C6C2ACA45B740ADD6DE10A1955FAEE

SHA256:

C69D87452DC718D49360B6E30191CC78A3A660B952D8AD869BAB477C27BCC533

SSDEEP:

393216:tEaxSLBY3cF9a9aru9bnDz0mCTbXnZWMLI1gR:tuBBa9mAbnPOPZW71gR

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • SearchProtocolHost.exe (PID: 996)
      • IPTV v.5.0.3 Promotional version.exe (PID: 1068)
    • Application was dropped or rewritten from another process

      • IPTV v.5.0.3 Promotional version.exe (PID: 1068)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2796)
    • Creates files in the user directory

      • IPTV v.5.0.3 Promotional version.exe (PID: 1068)
    • Starts Internet Explorer

      • IPTV v.5.0.3 Promotional version.exe (PID: 1068)
    • Connects to unusual port

      • IPTV v.5.0.3 Promotional version.exe (PID: 1068)
  • INFO

    • Dropped object may contain URL's

      • WinRAR.exe (PID: 2796)
      • iexplore.exe (PID: 2792)
      • iexplore.exe (PID: 2872)
    • Changes internet zones settings

      • iexplore.exe (PID: 2872)
    • Reads Internet Cache Settings

      • iexplore.exe (PID: 2792)
    • Creates files in the user directory

      • iexplore.exe (PID: 2792)
      • iexplore.exe (PID: 2872)
    • Reads internet explorer settings

      • iexplore.exe (PID: 2792)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
41
Monitored processes
5
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe searchprotocolhost.exe no specs iptv v.5.0.3 promotional version.exe iexplore.exe iexplore.exe

Process information

PID
CMD
Path
Indicators
Parent process
996"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe12_ Global\UsGthrCtrlFltPipeMssGthrPipe12 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" C:\Windows\System32\SearchProtocolHost.exeSearchIndexer.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Windows Search Protocol Host
Exit code:
0
Version:
7.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\searchprotocolhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1068"C:\Users\admin\Desktop\IPTV v.5.0.3 Promotional version\IPTV v.5.0.3 Promotional version.exe" C:\Users\admin\Desktop\IPTV v.5.0.3 Promotional version\IPTV v.5.0.3 Promotional version.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
IPTV
Exit code:
0
Version:
5.0.2.0
Modules
Images
c:\users\admin\desktop\iptv v.5.0.3 promotional version\iptv v.5.0.3 promotional version.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2792"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2872 CREDAT:71937C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2796"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\IPTV v.5.0.3 Promotional version.rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2872"C:\Program Files\Internet Explorer\iexplore.exe" -nohomeC:\Program Files\Internet Explorer\iexplore.exe
IPTV v.5.0.3 Promotional version.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
1
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
1 585
Read events
1 437
Write events
142
Delete events
6

Modification events

(PID) Process:(2796) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2796) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2796) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\59\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2796) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\IPTV v.5.0.3 Promotional version.rar
(PID) Process:(2796) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2796) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2796) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2796) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2796) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\DialogEditHistory\ExtrPath
Operation:writeName:0
Value:
C:\Users\admin\Desktop\IPTV v.5.0.3 Promotional version
(PID) Process:(996) SearchProtocolHost.exeKey:HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached
Operation:writeName:{E46787A1-4629-4423-A693-BE1F003B2742} {886D8EEB-8CF2-4446-8D02-CDBA1DBDCF99} 0xFFFF
Value:
01000000000000006CEE74F8BD44D401
Executable files
4
Suspicious files
3
Text files
31
Unknown types
5

Dropped files

PID
Process
Filename
Type
2796WinRAR.exeC:\Users\admin\Desktop\IPTV v.5.0.3 Promotional version\info.wav
MD5:
SHA256:
2872iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HHUAAB7W\favicon[1].ico
MD5:
SHA256:
2872iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.ico
MD5:
SHA256:
2792iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MJG226QK\@ZugZang[1].txt
MD5:
SHA256:
2796WinRAR.exeC:\Users\admin\Desktop\IPTV v.5.0.3 Promotional version\HTTP Proxys 02.09.txttext
MD5:
SHA256:
2796WinRAR.exeC:\Users\admin\Desktop\IPTV v.5.0.3 Promotional version\IPTV v.5.0.3 Promotional version.exeexecutable
MD5:
SHA256:
2796WinRAR.exeC:\Users\admin\Desktop\IPTV v.5.0.3 Promotional version\list.txttext
MD5:
SHA256:
2796WinRAR.exeC:\Users\admin\Desktop\IPTV v.5.0.3 Promotional version\serial.lictext
MD5:
SHA256:
2796WinRAR.exeC:\Users\admin\Desktop\IPTV v.5.0.3 Promotional version\good.wavwav
MD5:
SHA256:
2792iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\XBSSZHSR\product-4c158d5ce5c1405bb7f2e33acde4013b[1].csstext
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
29
TCP/UDP connections
59
DNS requests
5
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1068
IPTV v.5.0.3 Promotional version.exe
GET
103.241.205.66:8080
http://99.cccam.us:8000/get.php?username=0023&password=0023&type=m3u
ID
unknown
1068
IPTV v.5.0.3 Promotional version.exe
GET
103.228.117.243:8080
http://99.cccam.us:8000/get.php?username=0026&password=0026&type=m3u
ID
unknown
1068
IPTV v.5.0.3 Promotional version.exe
GET
103.252.163.191:80
http://99.cccam.us:8000/get.php?username=00YHrD6wyT&password=YUX4vFS47J&type=m3u
ID
suspicious
1068
IPTV v.5.0.3 Promotional version.exe
GET
101.51.138.99:8080
http://99.cccam.us:8000/get.php?username=008348909783&password=820083489097&type=m3u
TH
unknown
1068
IPTV v.5.0.3 Promotional version.exe
GET
103.254.185.26:80
http://99.cccam.us:8000/get.php?username=0101&password=0101&type=m3u
NP
unknown
1068
IPTV v.5.0.3 Promotional version.exe
GET
103.251.36.41:80
http://99.cccam.us:8000/get.php?username=003358554888&password=820033585548&type=m3u
HK
unknown
1068
IPTV v.5.0.3 Promotional version.exe
GET
103.242.219.242:8080
http://99.cccam.us:8000/get.php?username=0&password=0&type=m3u
BD
unknown
1068
IPTV v.5.0.3 Promotional version.exe
GET
101.4.136.34:8080
http://99.cccam.us:8000/get.php?username=000000&password=000000&type=m3u
CN
suspicious
1068
IPTV v.5.0.3 Promotional version.exe
GET
101.4.136.34:80
http://99.cccam.us:8000/get.php?username=0029&password=0029&type=m3u
CN
suspicious
1068
IPTV v.5.0.3 Promotional version.exe
GET
103.254.185.26:8080
http://99.cccam.us:8000/get.php?username=01&password=01&type=m3u
NP
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1068
IPTV v.5.0.3 Promotional version.exe
103.228.117.243:8080
PT SUMBER KONEKSI INDOTELEMATIKA
ID
unknown
1068
IPTV v.5.0.3 Promotional version.exe
101.51.138.99:8080
TOT Public Company Limited
TH
unknown
2872
iexplore.exe
204.79.197.200:80
www.bing.com
Microsoft Corporation
US
whitelisted
2792
iexplore.exe
104.20.79.14:443
selly.gg
Cloudflare Inc
US
shared
2792
iexplore.exe
192.0.80.239:443
gravatar.com
Automattic, Inc
US
malicious
2792
iexplore.exe
104.20.40.159:443
camo.selly.gg
Cloudflare Inc
US
shared
2792
iexplore.exe
192.0.77.2:443
i2.wp.com
Automattic, Inc
US
suspicious
2872
iexplore.exe
104.20.79.14:443
selly.gg
Cloudflare Inc
US
shared
1068
IPTV v.5.0.3 Promotional version.exe
101.50.1.2:80
PT. Beon Intermedia
ID
suspicious
1068
IPTV v.5.0.3 Promotional version.exe
101.4.136.34:81
China Education and Research Network Center
CN
suspicious

DNS requests

Domain
IP
Reputation
www.bing.com
  • 204.79.197.200
  • 13.107.21.200
whitelisted
selly.gg
  • 104.20.79.14
  • 104.20.78.14
unknown
gravatar.com
  • 192.0.80.239
  • 192.0.80.240
  • 192.0.80.242
  • 192.0.80.241
whitelisted
camo.selly.gg
  • 104.20.40.159
  • 104.20.41.159
unknown
i2.wp.com
  • 192.0.77.2
whitelisted

Threats

PID
Process
Class
Message
1068
IPTV v.5.0.3 Promotional version.exe
Potential Corporate Privacy Violation
ET CURRENT_EVENTS CoinHive In-Browser Miner Detected
No debug info