| File name: | Spotify checker IOS [Crax.Pro - Crax.Tube].rar |
| Full analysis: | https://app.any.run/tasks/38d42e55-3c67-49be-b31b-568522ddeb9e |
| Verdict: | Malicious activity |
| Threats: | Ransomware is a type of malicious software that locks users out of their system or data using different methods to force them to pay a ransom. Most often, such programs encrypt files on an infected machine and demand a fee to be paid in exchange for the decryption key. Additionally, such programs can be used to steal sensitive information from the compromised computer and even conduct DDoS attacks against affected organizations to pressure them into paying. |
| Analysis date: | February 24, 2022, 10:22:22 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-rar |
| File info: | RAR archive data, v5 |
| MD5: | 65FD6938C80D9307E1FC1EE38EF3A06C |
| SHA1: | F0D7CCC7A0FBB4A5E6B48F9BE4C58C295101C2BD |
| SHA256: | C84E0FFD38D4FF1FA58F690D08C5412DB0E3778E879B16BCB032D401B24E5546 |
| SSDEEP: | 6144:KVwBtp0tqfCGeaihEQajuzSzFwi7hEvKe6Y/WFw2:KVCFePEQUuzSpw1L6Y+W2 |
| .rar | | | RAR compressed archive (v5.0) (61.5) |
|---|---|---|
| .rar | | | RAR compressed archive (gen) (38.4) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1372 | chcp 65001 | C:\Windows\system32\chcp.com | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Change CodePage Utility Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1988 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Spotify checker IOS [Crax.Pro - Crax.Tube].rar" | C:\Program Files\WinRAR\WinRAR.exe | Explorer.EXE | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| 2200 | "C:\Windows\system32\NOTEPAD.EXE" C:\Users\admin\Desktop\Spotify checker IOS\ReadMe.txt | C:\Windows\system32\NOTEPAD.EXE | — | Explorer.EXE | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Notepad Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2716 | "C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe3_ Global\UsGthrCtrlFltPipeMssGthrPipe3 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" | C:\Windows\system32\SearchProtocolHost.exe | — | SearchIndexer.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft Windows Search Protocol Host Exit code: 0 Version: 7.00.7601.24542 (win7sp1_ldr_escrow.191209-2211) Modules
| |||||||||||||||
| 2744 | "C:\Users\admin\Desktop\Spotify checker IOS\Spotify Checker IOS API.exe" | C:\Users\admin\Desktop\Spotify checker IOS\Spotify Checker IOS API.exe | Explorer.EXE | ||||||||||||
User: admin Integrity Level: MEDIUM Description: Client Exit code: 0 Version: 1.0.0.0 Modules
| |||||||||||||||
| 2764 | "cmd.exe" /C chcp 65001 && netsh wlan show networks mode=bssid | C:\Windows\system32\cmd.exe | — | Spotify Checker IOS API.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 1 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 3092 | netsh wlan show profile | C:\Windows\system32\netsh.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Network Command Shell Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3148 | netsh wlan show networks mode=bssid | C:\Windows\system32\netsh.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Network Command Shell Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3428 | "cmd.exe" /C chcp 65001 && netsh wlan show profile | findstr All | C:\Windows\system32\cmd.exe | — | Spotify Checker IOS API.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 1 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 3500 | findstr All | C:\Windows\system32\findstr.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Find String (QGREP) Utility Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (1988) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (1988) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (1988) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (1988) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip | |||
| (PID) Process: | (1988) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (1988) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\Spotify checker IOS [Crax.Pro - Crax.Tube].rar | |||
| (PID) Process: | (1988) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (1988) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (1988) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (1988) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1988 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa1988.30719\Spotify checker IOS\ReadMe.txt | text | |
MD5:— | SHA256:— | |||
| 1988 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa1988.30719\Spotify checker IOS\Spotify Checker IOS API.exe | executable | |
MD5:— | SHA256:— | |||
| 2744 | Spotify Checker IOS API.exe | C:\Users\admin\AppData\Local\0cc27f7a79c3cbdaa16aa49037c2e720\admin@USER-PC_en-US\Grabber\DRIVE-C\Users\admin\Documents\longercertificate.rtf | text | |
MD5:— | SHA256:— | |||
| 2744 | Spotify Checker IOS API.exe | C:\Users\admin\AppData\Local\0cc27f7a79c3cbdaa16aa49037c2e720\admin@USER-PC_en-US\Grabber\DRIVE-C\Users\admin\Desktop\catmay.rtf | text | |
MD5:— | SHA256:— | |||
| 1988 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa1988.30719\Spotify checker IOS\MetroSuite 2.0.dll | executable | |
MD5:0D30A398CEC0FF006B6EA2B52D11E744 | SHA256:8604BF2A1FE2E94DC1EA1FBD0CF54E77303493B93994DF48479DC683580AA654 | |||
| 2744 | Spotify Checker IOS API.exe | C:\Users\admin\AppData\Local\0cc27f7a79c3cbdaa16aa49037c2e720\admin@USER-PC_en-US\Grabber\DRIVE-C\Users\admin\Documents\somefashion.rtf | text | |
MD5:— | SHA256:— | |||
| 2744 | Spotify Checker IOS API.exe | C:\Users\admin\AppData\Local\0cc27f7a79c3cbdaa16aa49037c2e720\admin@USER-PC_en-US\Grabber\DRIVE-C\Users\admin\Documents\desktop.ini | text | |
MD5:ECF88F261853FE08D58E2E903220DA14 | SHA256:CAFEC240D998E4B6E92AD1329CD417E8E9CBD73157488889FD93A542DE4A4844 | |||
| 2744 | Spotify Checker IOS API.exe | C:\Users\admin\AppData\Local\0cc27f7a79c3cbdaa16aa49037c2e720\admin@USER-PC_en-US\Grabber\DRIVE-C\Users\admin\Documents\votewhile.rtf | text | |
MD5:— | SHA256:— | |||
| 2744 | Spotify Checker IOS API.exe | C:\Users\admin\AppData\Local\0cc27f7a79c3cbdaa16aa49037c2e720\admin@USER-PC_en-US\Grabber\DRIVE-C\Users\admin\Desktop\duringhistorical.png | image | |
MD5:— | SHA256:— | |||
| 2744 | Spotify Checker IOS API.exe | C:\Users\admin\AppData\Local\0cc27f7a79c3cbdaa16aa49037c2e720\admin@USER-PC_en-US\Grabber\DRIVE-C\Users\admin\Desktop\modelsmotor.rtf | text | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2744 | Spotify Checker IOS API.exe | GET | 200 | 104.18.115.97:80 | http://icanhazip.com/ | US | text | 16 b | shared |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2744 | Spotify Checker IOS API.exe | 172.67.160.130:443 | api.mylnikov.org | — | US | suspicious |
— | — | 149.154.167.220:443 | api.telegram.org | Telegram Messenger LLP | GB | malicious |
2744 | Spotify Checker IOS API.exe | 104.18.115.97:80 | icanhazip.com | Cloudflare Inc | US | malicious |
2744 | Spotify Checker IOS API.exe | 149.154.167.220:443 | api.telegram.org | Telegram Messenger LLP | GB | malicious |
Domain | IP | Reputation |
|---|---|---|
icanhazip.com |
| shared |
api.mylnikov.org |
| suspicious |
api.telegram.org |
| shared |
PID | Process | Class | Message |
|---|---|---|---|
2744 | Spotify Checker IOS API.exe | Potential Corporate Privacy Violation | ET POLICY Observed Wifi Geolocation Domain (api .mylnikov .org in TLS SNI) |
2744 | Spotify Checker IOS API.exe | Attempted Information Leak | ET POLICY IP Check Domain (icanhazip. com in HTTP Host) |
— | — | Misc activity | ET INFO Telegram API Domain in DNS Lookup |
2744 | Spotify Checker IOS API.exe | Misc activity | ET INFO Observed Telegram API Domain (api .telegram .org in TLS SNI) |
2744 | Spotify Checker IOS API.exe | Misc activity | ET POLICY Telegram API Certificate Observed |
2744 | Spotify Checker IOS API.exe | Misc activity | ET INFO Observed Telegram API Domain (api .telegram .org in TLS SNI) |
2744 | Spotify Checker IOS API.exe | Misc activity | ET POLICY Telegram API Certificate Observed |
2744 | Spotify Checker IOS API.exe | Misc activity | ET INFO Observed Telegram API Domain (api .telegram .org in TLS SNI) |
2744 | Spotify Checker IOS API.exe | Misc activity | ET POLICY Telegram API Certificate Observed |