File name:

Spotify checker IOS [Crax.Pro - Crax.Tube].rar

Full analysis: https://app.any.run/tasks/38d42e55-3c67-49be-b31b-568522ddeb9e
Verdict: Malicious activity
Threats:

Ransomware is a type of malicious software that locks users out of their system or data using different methods to force them to pay a ransom. Most often, such programs encrypt files on an infected machine and demand a fee to be paid in exchange for the decryption key. Additionally, such programs can be used to steal sensitive information from the compromised computer and even conduct DDoS attacks against affected organizations to pressure them into paying.

Analysis date: February 24, 2022, 10:22:22
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
ransomware
stealer
evasion
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

65FD6938C80D9307E1FC1EE38EF3A06C

SHA1:

F0D7CCC7A0FBB4A5E6B48F9BE4C58C295101C2BD

SHA256:

C84E0FFD38D4FF1FA58F690D08C5412DB0E3778E879B16BCB032D401B24E5546

SSDEEP:

6144:KVwBtp0tqfCGeaihEQajuzSzFwi7hEvKe6Y/WFw2:KVCFePEQUuzSpw1L6Y+W2

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Spotify Checker IOS API.exe (PID: 2744)
    • Actions looks like stealing of personal data

      • Spotify Checker IOS API.exe (PID: 2744)
    • Loads dropped or rewritten executable

      • SearchProtocolHost.exe (PID: 2716)
    • Stealing of credential data

      • Spotify Checker IOS API.exe (PID: 2744)
    • Steals credentials from Web Browsers

      • Spotify Checker IOS API.exe (PID: 2744)
  • SUSPICIOUS

    • Drops a file with a compile date too recent

      • WinRAR.exe (PID: 1988)
    • Drops a file that was compiled in debug mode

      • WinRAR.exe (PID: 1988)
    • Reads the computer name

      • Spotify Checker IOS API.exe (PID: 2744)
      • WinRAR.exe (PID: 1988)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 1988)
    • Checks supported languages

      • Spotify Checker IOS API.exe (PID: 2744)
      • WinRAR.exe (PID: 1988)
      • chcp.com (PID: 1372)
      • cmd.exe (PID: 3428)
      • cmd.exe (PID: 2764)
      • chcp.com (PID: 3548)
    • Reads the cookies of Google Chrome

      • Spotify Checker IOS API.exe (PID: 2744)
    • Reads Environment values

      • Spotify Checker IOS API.exe (PID: 2744)
      • netsh.exe (PID: 3092)
      • netsh.exe (PID: 3148)
    • Creates files like Ransomware instruction

      • Spotify Checker IOS API.exe (PID: 2744)
    • Writes to a desktop.ini file (may be used to cloak folders)

      • Spotify Checker IOS API.exe (PID: 2744)
    • Reads the cookies of Mozilla Firefox

      • Spotify Checker IOS API.exe (PID: 2744)
    • Starts CMD.EXE for commands execution

      • Spotify Checker IOS API.exe (PID: 2744)
    • Uses NETSH.EXE for network configuration

      • cmd.exe (PID: 3428)
      • cmd.exe (PID: 2764)
    • Starts application with an unusual extension

      • cmd.exe (PID: 2764)
      • cmd.exe (PID: 3428)
    • Reads Windows Product ID

      • Spotify Checker IOS API.exe (PID: 2744)
    • Reads CPU info

      • Spotify Checker IOS API.exe (PID: 2744)
    • Checks for external IP

      • Spotify Checker IOS API.exe (PID: 2744)
  • INFO

    • Checks supported languages

      • NOTEPAD.EXE (PID: 2200)
      • netsh.exe (PID: 3092)
      • findstr.exe (PID: 3500)
      • netsh.exe (PID: 3148)
    • Manual execution by user

      • Spotify Checker IOS API.exe (PID: 2744)
      • NOTEPAD.EXE (PID: 2200)
    • Reads the computer name

      • netsh.exe (PID: 3092)
      • netsh.exe (PID: 3148)
    • Reads settings of System Certificates

      • Spotify Checker IOS API.exe (PID: 2744)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
47
Monitored processes
11
Malicious processes
2
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe searchprotocolhost.exe no specs spotify checker ios api.exe notepad.exe no specs cmd.exe no specs chcp.com no specs netsh.exe no specs findstr.exe no specs cmd.exe no specs chcp.com no specs netsh.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1372chcp 65001 C:\Windows\system32\chcp.comcmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Change CodePage Utility
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\chcp.com
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ulib.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1988"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Spotify checker IOS [Crax.Pro - Crax.Tube].rar"C:\Program Files\WinRAR\WinRAR.exe
Explorer.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2200"C:\Windows\system32\NOTEPAD.EXE" C:\Users\admin\Desktop\Spotify checker IOS\ReadMe.txtC:\Windows\system32\NOTEPAD.EXEExplorer.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\notepad.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\rpcrt4.dll
2716"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe3_ Global\UsGthrCtrlFltPipeMssGthrPipe3 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" C:\Windows\system32\SearchProtocolHost.exeSearchIndexer.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Windows Search Protocol Host
Exit code:
0
Version:
7.00.7601.24542 (win7sp1_ldr_escrow.191209-2211)
Modules
Images
c:\windows\system32\searchprotocolhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2744"C:\Users\admin\Desktop\Spotify checker IOS\Spotify Checker IOS API.exe" C:\Users\admin\Desktop\Spotify checker IOS\Spotify Checker IOS API.exe
Explorer.EXE
User:
admin
Integrity Level:
MEDIUM
Description:
Client
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\spotify checker ios\spotify checker ios api.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2764"cmd.exe" /C chcp 65001 && netsh wlan show networks mode=bssidC:\Windows\system32\cmd.exeSpotify Checker IOS API.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
1
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3092netsh wlan show profile C:\Windows\system32\netsh.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Network Command Shell
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\netsh.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\credui.dll
c:\windows\system32\gdi32.dll
3148netsh wlan show networks mode=bssidC:\Windows\system32\netsh.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Network Command Shell
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\netsh.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\credui.dll
c:\windows\system32\user32.dll
3428"cmd.exe" /C chcp 65001 && netsh wlan show profile | findstr AllC:\Windows\system32\cmd.exeSpotify Checker IOS API.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
1
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3500findstr AllC:\Windows\system32\findstr.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Find String (QGREP) Utility
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\findstr.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
Total events
6 657
Read events
6 500
Write events
157
Delete events
0

Modification events

(PID) Process:(1988) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(1988) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(1988) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1988) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(1988) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(1988) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Spotify checker IOS [Crax.Pro - Crax.Tube].rar
(PID) Process:(1988) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(1988) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(1988) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(1988) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
Executable files
3
Suspicious files
2
Text files
37
Unknown types
8

Dropped files

PID
Process
Filename
Type
1988WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1988.30719\Spotify checker IOS\ReadMe.txttext
MD5:
SHA256:
1988WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1988.30719\Spotify checker IOS\Spotify Checker IOS API.exeexecutable
MD5:
SHA256:
2744Spotify Checker IOS API.exeC:\Users\admin\AppData\Local\0cc27f7a79c3cbdaa16aa49037c2e720\admin@USER-PC_en-US\Grabber\DRIVE-C\Users\admin\Documents\longercertificate.rtftext
MD5:
SHA256:
2744Spotify Checker IOS API.exeC:\Users\admin\AppData\Local\0cc27f7a79c3cbdaa16aa49037c2e720\admin@USER-PC_en-US\Grabber\DRIVE-C\Users\admin\Desktop\catmay.rtftext
MD5:
SHA256:
1988WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1988.30719\Spotify checker IOS\MetroSuite 2.0.dllexecutable
MD5:0D30A398CEC0FF006B6EA2B52D11E744
SHA256:8604BF2A1FE2E94DC1EA1FBD0CF54E77303493B93994DF48479DC683580AA654
2744Spotify Checker IOS API.exeC:\Users\admin\AppData\Local\0cc27f7a79c3cbdaa16aa49037c2e720\admin@USER-PC_en-US\Grabber\DRIVE-C\Users\admin\Documents\somefashion.rtftext
MD5:
SHA256:
2744Spotify Checker IOS API.exeC:\Users\admin\AppData\Local\0cc27f7a79c3cbdaa16aa49037c2e720\admin@USER-PC_en-US\Grabber\DRIVE-C\Users\admin\Documents\desktop.initext
MD5:ECF88F261853FE08D58E2E903220DA14
SHA256:CAFEC240D998E4B6E92AD1329CD417E8E9CBD73157488889FD93A542DE4A4844
2744Spotify Checker IOS API.exeC:\Users\admin\AppData\Local\0cc27f7a79c3cbdaa16aa49037c2e720\admin@USER-PC_en-US\Grabber\DRIVE-C\Users\admin\Documents\votewhile.rtftext
MD5:
SHA256:
2744Spotify Checker IOS API.exeC:\Users\admin\AppData\Local\0cc27f7a79c3cbdaa16aa49037c2e720\admin@USER-PC_en-US\Grabber\DRIVE-C\Users\admin\Desktop\duringhistorical.pngimage
MD5:
SHA256:
2744Spotify Checker IOS API.exeC:\Users\admin\AppData\Local\0cc27f7a79c3cbdaa16aa49037c2e720\admin@USER-PC_en-US\Grabber\DRIVE-C\Users\admin\Desktop\modelsmotor.rtftext
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
6
DNS requests
3
Threats
9

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2744
Spotify Checker IOS API.exe
GET
200
104.18.115.97:80
http://icanhazip.com/
US
text
16 b
shared
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2744
Spotify Checker IOS API.exe
172.67.160.130:443
api.mylnikov.org
US
suspicious
149.154.167.220:443
api.telegram.org
Telegram Messenger LLP
GB
malicious
2744
Spotify Checker IOS API.exe
104.18.115.97:80
icanhazip.com
Cloudflare Inc
US
malicious
2744
Spotify Checker IOS API.exe
149.154.167.220:443
api.telegram.org
Telegram Messenger LLP
GB
malicious

DNS requests

Domain
IP
Reputation
icanhazip.com
  • 104.18.115.97
  • 104.18.114.97
shared
api.mylnikov.org
  • 172.67.160.130
  • 104.21.9.139
suspicious
api.telegram.org
  • 149.154.167.220
shared

Threats

PID
Process
Class
Message
2744
Spotify Checker IOS API.exe
Potential Corporate Privacy Violation
ET POLICY Observed Wifi Geolocation Domain (api .mylnikov .org in TLS SNI)
2744
Spotify Checker IOS API.exe
Attempted Information Leak
ET POLICY IP Check Domain (icanhazip. com in HTTP Host)
Misc activity
ET INFO Telegram API Domain in DNS Lookup
2744
Spotify Checker IOS API.exe
Misc activity
ET INFO Observed Telegram API Domain (api .telegram .org in TLS SNI)
2744
Spotify Checker IOS API.exe
Misc activity
ET POLICY Telegram API Certificate Observed
2744
Spotify Checker IOS API.exe
Misc activity
ET INFO Observed Telegram API Domain (api .telegram .org in TLS SNI)
2744
Spotify Checker IOS API.exe
Misc activity
ET POLICY Telegram API Certificate Observed
2744
Spotify Checker IOS API.exe
Misc activity
ET INFO Observed Telegram API Domain (api .telegram .org in TLS SNI)
2744
Spotify Checker IOS API.exe
Misc activity
ET POLICY Telegram API Certificate Observed
No debug info