File name:

sex mod minecraft.exe

Full analysis: https://app.any.run/tasks/38cbcc74-7f8a-494a-b78f-dbb59f025a39
Verdict: Malicious activity
Threats:

Remote access trojans (RATs) are a type of malware that enables attackers to establish complete to partial control over infected computers. Such malicious programs often have a modular design, offering a wide range of functionalities for conducting illicit activities on compromised systems. Some of the most common features of RATs include access to the users’ data, webcam, and keystrokes. This malware is often distributed through phishing emails and links.

Analysis date: September 19, 2021, 03:42:32
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
trojan
rat
redline
stealer
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (console) Intel 80386, for MS Windows
MD5:

75E23B3D3920BCC1CF14CEA670AFF6DB

SHA1:

FCD41CFA075778DCDFBB1EEBDAB1D2882A47C26D

SHA256:

C954B94A3FEE451C79C372D9798254301068D01BD21EC256059857D16FC5F170

SSDEEP:

24576:kc1Zfyv3nGMK5NtWUEkudFY96RhLv5kaJIUw7l38oQx:VXafnSJWUE1dFW6f1kaJvw7lZS

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • REDLINE was detected

      • sex mod minecraft.exe (PID: 3508)
    • Connects to CnC server

      • sex mod minecraft.exe (PID: 3508)
    • Actions looks like stealing of personal data

      • sex mod minecraft.exe (PID: 3508)
    • Steals credentials from Web Browsers

      • sex mod minecraft.exe (PID: 3508)
    • Stealing of credential data

      • sex mod minecraft.exe (PID: 3508)
  • SUSPICIOUS

    • Reads the cookies of Google Chrome

      • sex mod minecraft.exe (PID: 3508)
    • Checks supported languages

      • sex mod minecraft.exe (PID: 3508)
    • Reads the computer name

      • sex mod minecraft.exe (PID: 3508)
    • Reads the cookies of Mozilla Firefox

      • sex mod minecraft.exe (PID: 3508)
    • Reads Environment values

      • sex mod minecraft.exe (PID: 3508)
    • Searches for installed software

      • sex mod minecraft.exe (PID: 3508)
  • INFO

    • Reads settings of System Certificates

      • sex mod minecraft.exe (PID: 3508)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (61.6)
.dll | Win32 Dynamic Link Library (generic) (14.6)
.exe | Win32 Executable (generic) (10)
.exe | Win16/32 Executable Delphi generic (4.6)
.exe | Generic Win/DOS Executable (4.4)

EXIF

EXE

Subsystem: Windows command line
SubsystemVersion: 4
ImageVersion: -
OSVersion: 4
EntryPoint: 0x9fc8
UninitializedDataSize: -
InitializedDataSize: 2048
CodeSize: 103936
LinkerVersion: 2.25
PEType: PE32
TimeStamp: 2046:04:11 20:46:34+02:00
MachineType: Intel 386 or later, and compatibles
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
37
Monitored processes
1
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start #REDLINE sex mod minecraft.exe

Process information

PID
CMD
Path
Indicators
Parent process
3508"C:\Users\admin\AppData\Local\Temp\sex mod minecraft.exe" C:\Users\admin\AppData\Local\Temp\sex mod minecraft.exe
Explorer.EXE
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Version:
2.11.40.4
Modules
Images
c:\windows\system32\ntdll.dll
c:\users\admin\appdata\local\temp\sex mod minecraft.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
Total events
4 143
Read events
4 119
Write events
24
Delete events
0

Modification events

(PID) Process:(3508) sex mod minecraft.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\sex mod minecraft_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(3508) sex mod minecraft.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\sex mod minecraft_RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(3508) sex mod minecraft.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\sex mod minecraft_RASAPI32
Operation:writeName:FileTracingMask
Value:
(PID) Process:(3508) sex mod minecraft.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\sex mod minecraft_RASAPI32
Operation:writeName:ConsoleTracingMask
Value:
(PID) Process:(3508) sex mod minecraft.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\sex mod minecraft_RASAPI32
Operation:writeName:MaxFileSize
Value:
1048576
(PID) Process:(3508) sex mod minecraft.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\sex mod minecraft_RASAPI32
Operation:writeName:FileDirectory
Value:
%windir%\tracing
(PID) Process:(3508) sex mod minecraft.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\sex mod minecraft_RASMANCS
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(3508) sex mod minecraft.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\sex mod minecraft_RASMANCS
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(3508) sex mod minecraft.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\sex mod minecraft_RASMANCS
Operation:writeName:FileTracingMask
Value:
(PID) Process:(3508) sex mod minecraft.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\sex mod minecraft_RASMANCS
Operation:writeName:ConsoleTracingMask
Value:
Executable files
0
Suspicious files
0
Text files
0
Unknown types
28

Dropped files

PID
Process
Filename
Type
3508sex mod minecraft.exeC:\Users\admin\AppData\Local\Temp\tmpDC0B.tmpsqlite
MD5:
SHA256:
3508sex mod minecraft.exeC:\Users\admin\AppData\Local\Temp\tmpDC3F.tmpsqlite
MD5:
SHA256:
3508sex mod minecraft.exeC:\Users\admin\AppData\Local\Temp\tmpDC3E.tmpsqlite
MD5:
SHA256:
3508sex mod minecraft.exeC:\Users\admin\AppData\Local\Temp\tmpDBBB.tmpsqlite
MD5:CC104C4E4E904C3AD7AD5C45FBFA7087
SHA256:321BE844CECC903EF1E7F875B729C96BB3ED0D4986314384CD5944A29A670C9B
3508sex mod minecraft.exeC:\Users\admin\AppData\Local\Temp\tmpDC67.tmpsqlite
MD5:D02907BE1C995E1E51571EEDB82FA281
SHA256:2189977F6EA58BDAD5883720B099E12B869F223FB9B18AC40E7D37C5954A55DD
3508sex mod minecraft.exeC:\Users\admin\AppData\Local\Temp\tmpDC2C.tmpsqlite
MD5:
SHA256:
3508sex mod minecraft.exeC:\Users\admin\AppData\Local\Temp\tmpDC2D.tmpsqlite
MD5:
SHA256:
3508sex mod minecraft.exeC:\Users\admin\AppData\Local\Temp\tmpDC65.tmpsqlite
MD5:D02907BE1C995E1E51571EEDB82FA281
SHA256:2189977F6EA58BDAD5883720B099E12B869F223FB9B18AC40E7D37C5954A55DD
3508sex mod minecraft.exeC:\Users\admin\AppData\Local\Temp\tmpDC54.tmpsqlite
MD5:D02907BE1C995E1E51571EEDB82FA281
SHA256:2189977F6EA58BDAD5883720B099E12B869F223FB9B18AC40E7D37C5954A55DD
3508sex mod minecraft.exeC:\Users\admin\AppData\Local\Temp\tmpDBCC.tmpsqlite
MD5:CC104C4E4E904C3AD7AD5C45FBFA7087
SHA256:321BE844CECC903EF1E7F875B729C96BB3ED0D4986314384CD5944A29A670C9B
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
2
DNS requests
1
Threats
11

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3508
sex mod minecraft.exe
172.67.75.172:443
api.ip.sb
US
suspicious
3508
sex mod minecraft.exe
185.206.215.216:80
LeaseWeb Netherlands B.V.
NL
malicious

DNS requests

Domain
IP
Reputation
api.ip.sb
  • 172.67.75.172
  • 104.26.13.31
  • 104.26.12.31
whitelisted

Threats

Found threats are available for the paid subscriptions
11 ETPRO signatures available at the full report
No debug info