File name:

Orion Keylogger 2.1 by Shadow.rar

Full analysis: https://app.any.run/tasks/fd176214-fc09-4586-baa9-57ebd0a48381
Verdict: Malicious activity
Analysis date: June 04, 2019, 11:11:21
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v4, os: Win32
MD5:

AE61E4332F8AEBBF5508C1A166D40085

SHA1:

A047442F927CDE5904C7169D6E0916D386F566B9

SHA256:

D0B1496ECF4D3E62D0D8B98D599FA3684FF71682A5003AD3849B2A3A97E42984

SSDEEP:

49152:JyaGmXNjoEsuU9k4adIuMnw4jcq4PyCDAI8X3VnHfT7:JyeXhoduX4twq46CeX3pX

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • SearchProtocolHost.exe (PID: 3572)
    • Application was dropped or rewritten from another process

      • Orion Keylogger.exe (PID: 2960)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2436)
  • INFO

    • Manual execution by user

      • Orion Keylogger.exe (PID: 2960)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v-4.x) (58.3)
.rar | RAR compressed archive (gen) (41.6)

EXIF

ZIP

CompressedSize: 7731
UncompressedSize: 18432
OperatingSystem: Win32
ModifyDate: 2017:05:29 02:02:12
PackingMethod: Normal
ArchivedFileName: Orion Keylogger 2.1 Cracked\961API.dll
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
34
Monitored processes
3
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe searchprotocolhost.exe no specs orion keylogger.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2436"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Orion Keylogger 2.1 by Shadow.rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2960"C:\Users\admin\Desktop\Orion Keylogger 2.1 Cracked\Orion Keylogger.exe" C:\Users\admin\Desktop\Orion Keylogger 2.1 Cracked\Orion Keylogger.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Orion Keylogger
Exit code:
0
Version:
2.1.0.0
Modules
Images
c:\users\admin\desktop\orion keylogger 2.1 cracked\orion keylogger.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\rpcrt4.dll
3572"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe4_ Global\UsGthrCtrlFltPipeMssGthrPipe4 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" C:\Windows\System32\SearchProtocolHost.exeSearchIndexer.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Windows Search Protocol Host
Exit code:
0
Version:
7.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\searchprotocolhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
797
Read events
778
Write events
19
Delete events
0

Modification events

(PID) Process:(2436) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2436) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2436) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\62\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2436) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Orion Keylogger 2.1 by Shadow.rar
(PID) Process:(2436) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2436) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2436) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2436) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2436) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000200000003000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000
(PID) Process:(2436) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\General
Operation:writeName:LastFolder
Value:
C:\Users\admin\AppData\Local\Temp
Executable files
11
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
2436WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2436.20767\Orion Keylogger 2.1 Cracked\ranger.browserlogging.vault.dllexecutable
MD5:203A65F044E610957503BEF112566E87
SHA256:4D8FD614BAA65B40EAD4225FAFF90A38D5A0F7FDB166ABB09778B5255C8576B4
2436WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2436.20767\Orion Keylogger 2.1 Cracked\Ranger.BrowserLogging.dllexecutable
MD5:E38908149F2825B604F7D8F2D91194CA
SHA256:71CAAAAA2CD513485F1D5901090EF022C943185F9F53713123AF9C6C5F24A22D
2436WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2436.20767\Orion Keylogger 2.1 Cracked\Newtonsoft.Json.dllexecutable
MD5:F33CBE589B769956284868104686CC2D
SHA256:973FD70CE48E5AC433A101B42871680C51E2FEBA2AEEC3D400DEA4115AF3A278
2436WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2436.20767\Orion Keylogger 2.1 Cracked\KeikoObfuscator.dllexecutable
MD5:4C3C8964A7DA9778CE4A43EDC1598D90
SHA256:88278312B79D042F340814EC031F83B3B50C76BEF62D2DE376F581205956A509
2436WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2436.20767\Orion Keylogger 2.1 Cracked\MintUI.dllexecutable
MD5:A9C6542147B7ADE88D6FDC6529819A86
SHA256:CA8B786ECA2FFBFD5567C3BE3084D0D54DF27DAD26181719CE4DBBFB659FB75E
2436WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2436.20767\Orion Keylogger 2.1 Cracked\961API.dllexecutable
MD5:5F02810707B72BAC26CF2B0DA83E0335
SHA256:4FAA5CBE75F96AFB5DBBDE84C0E5011F0D1F9C06240FB0361A185921B1676E31
2436WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2436.20767\Orion Keylogger 2.1 Cracked\Booya Theme.dllexecutable
MD5:1230BB7CC6A5979AF5BFA54B3CBF3C05
SHA256:1F6D1F6EA18FA5D477AC6BFE7F4AA32EFF97F788D02EF02D2698502099A7EAC8
2436WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2436.20767\Orion Keylogger 2.1 Cracked\Cure Tool.exeexecutable
MD5:7658C455F3ACDC2B574DA9F863855F01
SHA256:8D0AB3AC5F70AB0D16C1C3F1F66E4580E4116175D30BECE8B14514858C9174DC
2436WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2436.20767\Orion Keylogger 2.1 Cracked\Mono.Cecil.dllexecutable
MD5:A9C1EEA90BCA2E1971FBA535E1916E5D
SHA256:659E04C5DD62888B6ED6FE8413B9D2D55DECE0E6E4964929E661372A3D9B2538
2436WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2436.20767\Orion Keylogger 2.1 Cracked\RedPandaUI.dllexecutable
MD5:8346FDE589DE3CEEEAAB8F8100B3928F
SHA256:136B11772E6B27CB85F0199316961767F10EA8A4F8095B9568919384B9FF8F07
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info