File name:

OpenBullet 1.2.9 (Beta version Paid Gold) BY Anom [Modded By OB.rar

Full analysis: https://app.any.run/tasks/c5c71f0a-82fa-41d8-a73b-a5231d2f2ac4
Verdict: Malicious activity
Analysis date: October 30, 2019, 18:45:31
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

5B6B9C1105994467BAEFF4F72A484FB0

SHA1:

89B2400F0E494D4732D3A935DE909F5715E4B02E

SHA256:

CDCECF51FC33C673691D1C1380DFAB17F531C6ADE80EC6E08D87DBF761D94372

SSDEEP:

393216:v+acLGssu9azh4x6ovqsf3s7s3eZBCWa8AmkwN:v+bpnAzex6oCs3Es3ONJAmku

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • OpenBullet.exe (PID: 3084)
    • Application was dropped or rewritten from another process

      • OpenBullet.exe (PID: 3084)
  • SUSPICIOUS

    • Reads Environment values

      • OpenBullet.exe (PID: 3084)
    • Executed via COM

      • DllHost.exe (PID: 2812)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3788)
  • INFO

    • Reads settings of System Certificates

      • OpenBullet.exe (PID: 3084)
    • Reads Microsoft Office registry keys

      • WINWORD.EXE (PID: 3268)
    • Manual execution by user

      • WINWORD.EXE (PID: 3268)
      • explorer.exe (PID: 4088)
    • Creates files in the user directory

      • WINWORD.EXE (PID: 3268)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
44
Monitored processes
5
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
drop and start start winrar.exe openbullet.exe explorer.exe no specs PhotoViewer.dll no specs winword.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2812C:\Windows\system32\DllHost.exe /Processid:{76D0CB12-7604-4048-B83C-1005C7DDC503}C:\Windows\system32\DllHost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
COM Surrogate
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\dllhost.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3084"C:\Users\admin\AppData\Local\Temp\Rar$EXa3788.17858\OpenBullet 1.2.9 (Beta version Paid Gold) BY Anom [Modded By OB\OpenBullet.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3788.17858\OpenBullet 1.2.9 (Beta version Paid Gold) BY Anom [Modded By OB\OpenBullet.exe
WinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Description:
OpenBullet
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3788.17858\openbullet 1.2.9 (beta version paid gold) by anom [modded by ob\openbullet.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3268"C:\Program Files\Microsoft Office\Office14\WINWORD.EXE" /n "C:\Users\admin\Desktop\discussionresponse.rtf"C:\Program Files\Microsoft Office\Office14\WINWORD.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Word
Exit code:
0
Version:
14.0.6024.1000
Modules
Images
c:\program files\microsoft office\office14\winword.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
3788"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\OpenBullet 1.2.9 (Beta version Paid Gold) BY Anom [Modded By OB.rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
4088"C:\Windows\explorer.exe" C:\Windows\explorer.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\explorer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
Total events
1 913
Read events
1 558
Write events
219
Delete events
136

Modification events

(PID) Process:(3788) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3788) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3788) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3788) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\OpenBullet 1.2.9 (Beta version Paid Gold) BY Anom [Modded By OB.rar
(PID) Process:(3788) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3788) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3788) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3788) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3788) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E
Operation:writeName:@C:\Windows\System32\msxml3r.dll,-1
Value:
XML Document
(PID) Process:(3788) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
Executable files
40
Suspicious files
0
Text files
11
Unknown types
7

Dropped files

PID
Process
Filename
Type
3788WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3788.17858\OpenBullet 1.2.9 (Beta version Paid Gold) BY Anom [Modded By OB\bin\Extreme.Net.dllexecutable
MD5:
SHA256:
3788WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3788.17858\OpenBullet 1.2.9 (Beta version Paid Gold) BY Anom [Modded By OB\bin\CloudflareSolver.dllexecutable
MD5:00390D98A549F926124A414948FBF606
SHA256:8DAB176D8DD3B4992CD22FCDEA1A46F7E0A34CDBC9E40925763664323CC42241
3788WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3788.17858\OpenBullet 1.2.9 (Beta version Paid Gold) BY Anom [Modded By OB\bin\2Captcha.dllexecutable
MD5:007F2210FC5A0CA51516BB5CA77ED01A
SHA256:DE53E27553D738EC82ADC0F48B6F118D9AF93791482CCEAF28E4A5033A413A7B
3788WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3788.17858\OpenBullet 1.2.9 (Beta version Paid Gold) BY Anom [Modded By OB\bin\AngleSharp.dllexecutable
MD5:BF331AB2E9BB06D900929DE29C659AE8
SHA256:0B6D37C6113914DECB8AE2142DEE7CF476206036806821AC6DC63D69269F827B
3788WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3788.17858\OpenBullet 1.2.9 (Beta version Paid Gold) BY Anom [Modded By OB\bin\IronPython.Modules.dllexecutable
MD5:621192DB357916F2261989A49FA2C6BD
SHA256:87525121D7826DCFC76963AB8BD7996B9644BF4F148D1296757EB702A43DA51F
3788WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3788.17858\OpenBullet 1.2.9 (Beta version Paid Gold) BY Anom [Modded By OB\bin\AntiCaptcha.dllexecutable
MD5:595CB3CD2F929A641391A529219A2F75
SHA256:DFFD4A411F58232D32B1DF1A2B4F2B73B611D01F98FEE8346D3A3211CFEAA3C2
3788WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3788.17858\OpenBullet 1.2.9 (Beta version Paid Gold) BY Anom [Modded By OB\bin\ICSharpCode.AvalonEdit.dllexecutable
MD5:B4D5D46E50006E87B30E7D514E95173C
SHA256:058F38F33F3F99F904AB9588447A234346C859718404B4E8A523673ED19CDBE7
3788WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3788.17858\OpenBullet 1.2.9 (Beta version Paid Gold) BY Anom [Modded By OB\bin\IronPython.dllexecutable
MD5:9A39A51E6DCB22B80DB481FBFBCD7826
SHA256:61B809B97DC878F42E85EE2C5D8471853527754E4F53B17C0507334C57E19E04
3788WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3788.17858\OpenBullet 1.2.9 (Beta version Paid Gold) BY Anom [Modded By OB\bin\IronPython.SQLite.dllexecutable
MD5:B7EFBF654402C78226B8D69AD0011BBB
SHA256:5A6E2EDA86E863E155F67CEBEF095355B7EA7B1DCD97D87E4058F0A5AC60D798
3788WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3788.17858\OpenBullet 1.2.9 (Beta version Paid Gold) BY Anom [Modded By OB\bin\LiteDB.dllexecutable
MD5:25B242D00C6C32E1F437EB2064EA2E29
SHA256:E72ACDDF47586BC0999D598E3BD125A254BB6F4AE151C076993304F6E31FBBED
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
1
DNS requests
1
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3084
OpenBullet.exe
151.101.0.133:443
raw.githubusercontent.com
Fastly
US
malicious

DNS requests

Domain
IP
Reputation
raw.githubusercontent.com
  • 151.101.0.133
  • 151.101.64.133
  • 151.101.128.133
  • 151.101.192.133
shared

Threats

No threats detected
No debug info