File name:

Silent XMR Miner Builder.rar

Full analysis: https://app.any.run/tasks/04c276a7-4f45-447f-94b5-2b23c5d850f6
Verdict: Malicious activity
Threats:

Crypto mining malware is a resource-intensive threat that infiltrates computers with the purpose of mining cryptocurrencies. This type of threat can be deployed either on an infected machine or a compromised website. In both cases the miner will utilize the computing power of the device and its network bandwidth.

Analysis date: February 09, 2020, 14:58:38
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
miner
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

531A801D57EE7B1951A6FFE112F5F6B8

SHA1:

E797B86B739D6BFC1F2C113CAC92077ABEA543D7

SHA256:

CF32E9C0EFECE8D49B79974CC9952EBE619D34AB72F8605FAFAF399A5E4947DD

SSDEEP:

393216:69bxOvEHq8TcLXDqnArLPTWCUnOdpFQ7Jo/:69K8TcLDrP6e38o/

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Silent XMR Miner Builder.exe (PID: 3404)
  • SUSPICIOUS

    • Executes scripts

      • Silent XMR Miner Builder.exe (PID: 3404)
    • Dropped object may contain URLs of mainers pools

      • Silent XMR Miner Builder.exe (PID: 3404)
    • Executable content was dropped or overwritten

      • vbc.exe (PID: 1676)
  • INFO

    • Manual execution by user

      • Silent XMR Miner Builder.exe (PID: 3404)
    • Reads the hosts file

      • Silent XMR Miner Builder.exe (PID: 3404)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
40
Monitored processes
4
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe no specs silent xmr miner builder.exe no specs vbc.exe cvtres.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1676"C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe" /noconfig @"C:\Users\admin\AppData\Local\Temp\aw3pppx2.cmdline"C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe
Silent XMR Miner Builder.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Visual Basic Command Line Compiler
Exit code:
0
Version:
14.7.3062.0
Modules
Images
c:\windows\microsoft.net\framework\v4.0.30319\vbc.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\msvcr120_clr0400.dll
c:\windows\system32\ole32.dll
2836C:\Windows\Microsoft.NET\Framework\v4.0.30319\cvtres.exe /NOLOGO /READONLY /MACHINE:AMD64 "/OUT:C:\Users\admin\AppData\Local\Temp\RES4113.tmp" "C:\Users\admin\AppData\Local\Temp\vbcFB6E4DE3B6AD4D9DBEAEF96F4F96C75.TMP"C:\Windows\Microsoft.NET\Framework\v4.0.30319\cvtres.exevbc.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft® Resource File To COFF Object Conversion Utility
Exit code:
0
Version:
12.00.52519.0 built by: VSWINSERVICING
Modules
Images
c:\windows\microsoft.net\framework\v4.0.30319\cvtres.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\msvcr120_clr0400.dll
c:\windows\system32\cryptsp.dll
3404"C:\Users\admin\Desktop\Silent XMR Miner Builder.exe" C:\Users\admin\Desktop\Silent XMR Miner Builder.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Silent XMR Miner Builder
Exit code:
0
Version:
0.0.2.0
Modules
Images
c:\users\admin\desktop\silent xmr miner builder.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3460"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Silent XMR Miner Builder.rar"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
Total events
1 015
Read events
956
Write events
56
Delete events
3

Modification events

(PID) Process:(3460) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3460) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3460) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3460) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Silent XMR Miner Builder.rar
(PID) Process:(3460) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3460) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3460) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3460) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3404) Silent XMR Miner Builder.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\CIDSizeMRU
Operation:writeName:1
Value:
530069006C0065006E007400200058004D00520020004D0069006E006500720020004200750069006C006400650072002E006500780065000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000100000000000000
(PID) Process:(3404) Silent XMR Miner Builder.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
Operation:writeName:NodeSlots
Value:
02020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202
Executable files
1
Suspicious files
0
Text files
2
Unknown types
0

Dropped files

PID
Process
Filename
Type
3460WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3460.34727\Silent XMR Miner Builder.exe
MD5:
SHA256:
3404Silent XMR Miner Builder.exeC:\Users\admin\AppData\Local\Temp\tmp3F00.tmp
MD5:
SHA256:
3404Silent XMR Miner Builder.exeC:\Users\admin\AppData\Local\Temp\ymdsvji.Resources
MD5:
SHA256:
1676vbc.exeC:\Users\admin\AppData\Local\Temp\vbcFB6E4DE3B6AD4D9DBEAEF96F4F96C75.TMP
MD5:
SHA256:
2836cvtres.exeC:\Users\admin\AppData\Local\Temp\RES4113.tmp
MD5:
SHA256:
1676vbc.exeC:\Users\admin\AppData\Local\Temp\vbc549175A95E0B468C9C41BFD7ABCF1FD5.TMP
MD5:
SHA256:
1676vbc.exeC:\Users\admin\AppData\Local\Temp\aw3pppx2.out
MD5:
SHA256:
3404Silent XMR Miner Builder.exeC:\Users\admin\AppData\Local\Temp\aw3pppx2.0.vbtext
MD5:
SHA256:
3404Silent XMR Miner Builder.exeC:\Users\admin\AppData\Local\Temp\aw3pppx2.cmdlinetext
MD5:
SHA256:
1676vbc.exeC:\Users\admin\Desktop\hhh.exeexecutable
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info