File name:

GooglePlay Giftcard Generator and Checker.rar

Full analysis: https://app.any.run/tasks/7be4c898-8ac8-4c70-a10b-745123dd5e97
Verdict: Malicious activity
Analysis date: May 21, 2021, 19:12:33
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v4, os: Win32
MD5:

6190EC3FEB83F427A744D311D8B81346

SHA1:

BB9A0E992B63AA399E17AB377C82E86DC4F48DD5

SHA256:

D32BBABA2E577C5FD0D44F276982B441C6C872755AEF125060D8283C7501D142

SSDEEP:

196608:G2Z6k/y6UfRkC05hK7TBhzuNitoFefXyMhBTneGE48HY1KxJdmfRAqds:Gk/GXmKC4ZfXykS34dqJdmZAq+

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • SearchProtocolHost.exe (PID: 2548)
      • Google Play Gift Cards Generator And Checker v3 By X-LINE.exe (PID: 3660)
      • Google Play Gift Card Generator v1.0 By X-Line.exe (PID: 2476)
      • Google Play Gift Cards Generator And Checker v2 By X-LINE.exe (PID: 2156)
      • Google Play Gift Cards Generator And Checker v3 By X-LINE.exe (PID: 2520)
      • Google Play Gift Cards Generator And Checker v2 By X-LINE.exe (PID: 3024)
    • Drops executable file immediately after starts

      • Google Play Gift Cards Generator And Checker v3 By X-LINE.exe (PID: 3660)
    • Application was dropped or rewritten from another process

      • Google Play Gift Card Generator v1.0 By X-Line.exe (PID: 2476)
      • Google Play Gift Cards Generator And Checker v3 By X-LINE.exe (PID: 3660)
      • Google Play Gift Cards Generator And Checker v2 By X-LINE.exe (PID: 3024)
      • Google Play Gift Cards Generator And Checker v3 By X-LINE.exe (PID: 2520)
      • Google Play Gift Card Generator v1.0 By X-Line.exe (PID: 2568)
      • Google Play Gift Cards Generator And Checker v2 By X-LINE.exe (PID: 2156)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • Google Play Gift Cards Generator And Checker v3 By X-LINE.exe (PID: 3660)
      • WinRAR.exe (PID: 2456)
      • Google Play Gift Card Generator v1.0 By X-Line.exe (PID: 2476)
      • Google Play Gift Cards Generator And Checker v2 By X-LINE.exe (PID: 2156)
      • Google Play Gift Cards Generator And Checker v3 By X-LINE.exe (PID: 2520)
      • Google Play Gift Card Generator v1.0 By X-Line.exe (PID: 2568)
    • Drops a file with a compile date too recent

      • WinRAR.exe (PID: 2456)
      • Google Play Gift Cards Generator And Checker v3 By X-LINE.exe (PID: 3660)
      • Google Play Gift Cards Generator And Checker v3 By X-LINE.exe (PID: 2520)
      • Google Play Gift Card Generator v1.0 By X-Line.exe (PID: 2568)
      • Google Play Gift Card Generator v1.0 By X-Line.exe (PID: 2476)
    • Drops a file that was compiled in debug mode

      • WinRAR.exe (PID: 2456)
      • Google Play Gift Cards Generator And Checker v3 By X-LINE.exe (PID: 3660)
    • Reads Environment values

      • Google Play Gift Cards Generator And Checker v2 By X-LINE.exe (PID: 2156)
  • INFO

    • Manual execution by user

      • osk.exe (PID: 1148)
      • osk.exe (PID: 692)
      • Google Play Gift Cards Generator And Checker v3 By X-LINE.exe (PID: 3660)
      • Google Play Gift Card Generator v1.0 By X-Line.exe (PID: 2476)
      • Google Play Gift Cards Generator And Checker v3 By X-LINE.exe (PID: 2520)
      • Google Play Gift Card Generator v1.0 By X-Line.exe (PID: 2568)
      • Google Play Gift Cards Generator And Checker v2 By X-LINE.exe (PID: 3024)
      • Google Play Gift Cards Generator And Checker v2 By X-LINE.exe (PID: 2156)
    • Reads settings of System Certificates

      • Google Play Gift Cards Generator And Checker v2 By X-LINE.exe (PID: 2156)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v-4.x) (58.3)
.rar | RAR compressed archive (gen) (41.6)

EXIF

ZIP

ArchivedFileName: SkinSoft.VisualStyler.dll
PackingMethod: Normal
ModifyDate: 2014:09:11 10:35:11
OperatingSystem: Win32
UncompressedSize: 1082880
CompressedSize: 325099
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
55
Monitored processes
10
Malicious processes
4
Suspicious processes
4

Behavior graph

Click at the process to see the details
start winrar.exe osk.exe no specs osk.exe google play gift cards  generator and checker v3 by x-line.exe searchprotocolhost.exe no specs google play gift card generator v1.0 by x-line.exe google play gift cards  generator and checker v2 by x-line.exe google play gift cards  generator and checker v3 by x-line.exe google play gift card generator v1.0 by x-line.exe google play gift cards  generator and checker v2 by x-line.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
692"C:\Windows\system32\osk.exe" C:\Windows\system32\osk.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Accessibility On-Screen Keyboard
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\osk.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1148"C:\Windows\system32\osk.exe" C:\Windows\system32\osk.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Accessibility On-Screen Keyboard
Exit code:
3221226540
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\osk.exe
c:\systemroot\system32\ntdll.dll
2156"C:\Users\admin\Desktop\Google Play Gift Cards Generator And Checker v2 By X-LINE.exe" C:\Users\admin\Desktop\Google Play Gift Cards Generator And Checker v2 By X-LINE.exe
explorer.exe
User:
admin
Company:
Google Play Gift Cards Generator And Checker v3 | X-LINE
Integrity Level:
MEDIUM
Description:
Google Play Gift Cards Generator And Checker v3 | X-LINE
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\google play gift cards generator and checker v2 by x-line.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2456"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\GooglePlay Giftcard Generator and Checker.rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2476"C:\Users\admin\Desktop\Google Play Gift Card Generator v1.0 By X-Line.exe" C:\Users\admin\Desktop\Google Play Gift Card Generator v1.0 By X-Line.exe
explorer.exe
User:
admin
Company:
Google Play Gift Card Generator v1.0 By X-Line
Integrity Level:
MEDIUM
Description:
Google Play Gift Card Generator v1.0 By X-Line
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\google play gift card generator v1.0 by x-line.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2520"C:\Users\admin\Desktop\Google Play Gift Cards Generator And Checker v3 By X-LINE.exe" C:\Users\admin\Desktop\Google Play Gift Cards Generator And Checker v3 By X-LINE.exe
explorer.exe
User:
admin
Company:
Google Play Gift Cards Generator And Checker v3 | X-LINE
Integrity Level:
MEDIUM
Description:
Google Play Gift Cards Generator And Checker v3 | X-LINE
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\google play gift cards generator and checker v3 by x-line.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2548"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe5_ Global\UsGthrCtrlFltPipeMssGthrPipe5 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" C:\Windows\system32\SearchProtocolHost.exeSearchIndexer.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Windows Search Protocol Host
Exit code:
0
Version:
7.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\searchprotocolhost.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2568"C:\Users\admin\Desktop\Google Play Gift Card Generator v1.0 By X-Line.exe" C:\Users\admin\Desktop\Google Play Gift Card Generator v1.0 By X-Line.exe
explorer.exe
User:
admin
Company:
Google Play Gift Card Generator v1.0 By X-Line
Integrity Level:
MEDIUM
Description:
Google Play Gift Card Generator v1.0 By X-Line
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\google play gift card generator v1.0 by x-line.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3024"C:\Users\admin\Desktop\Google Play Gift Cards Generator And Checker v2 By X-LINE.exe" C:\Users\admin\Desktop\Google Play Gift Cards Generator And Checker v2 By X-LINE.exeexplorer.exe
User:
admin
Company:
Google Play Gift Cards Generator And Checker v3 | X-LINE
Integrity Level:
MEDIUM
Description:
Google Play Gift Cards Generator And Checker v3 | X-LINE
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\google play gift cards generator and checker v2 by x-line.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3660"C:\Users\admin\Desktop\Google Play Gift Cards Generator And Checker v3 By X-LINE.exe" C:\Users\admin\Desktop\Google Play Gift Cards Generator And Checker v3 By X-LINE.exe
explorer.exe
User:
admin
Company:
Google Play Gift Cards Generator And Checker v3 | X-LINE
Integrity Level:
MEDIUM
Description:
Google Play Gift Cards Generator And Checker v3 | X-LINE
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\google play gift cards generator and checker v3 by x-line.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
Total events
21 888
Read events
21 335
Write events
552
Delete events
1

Modification events

(PID) Process:(2456) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2456) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2456) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\13D\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2456) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\GooglePlay Giftcard Generator and Checker.rar
(PID) Process:(2456) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2456) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2456) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2456) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2456) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\13D\52C64B7E
Operation:writeName:@C:\Windows\system32\notepad.exe,-469
Value:
Text Document
(PID) Process:(2456) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\General\Toolbar\Buttons
Operation:writeName:f.add
Value:
1
Executable files
11
Suspicious files
0
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
2456WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb2456.21816\Google Play Gift Cards Generator And Checker v3 By X-LINE.exe
MD5:
SHA256:
2456WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb2456.30802\Google Play Gift Card Generator v1.0 By X-Line.exe
MD5:
SHA256:
2456WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb2456.30802\Google Play Gift Cards Generator And Checker v2 By X-LINE.exe
MD5:
SHA256:
3660Google Play Gift Cards Generator And Checker v3 By X-LINE.exeC:\Users\admin\AppData\Local\Temp\Sziqudhrmhl.exeexecutable
MD5:
SHA256:
2156Google Play Gift Cards Generator And Checker v2 By X-LINE.exeC:\Users\admin\Desktop\Results_20-15-06_21.054Parts-Cards.txttext
MD5:
SHA256:
2520Google Play Gift Cards Generator And Checker v3 By X-LINE.exeC:\Users\admin\AppData\Local\Temp\Sziqudhrmhl.exeexecutable
MD5:
SHA256:
2456WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb2456.25070\SkinSoft.VisualStyler.dllexecutable
MD5:60AC512E63A6B95EB37CFD530A01B94E
SHA256:9F3E7EA22D052FEE0E5BE8CD904AC4425F3840DF7452C760D5CC5357830C394E
2568Google Play Gift Card Generator v1.0 By X-Line.exeC:\Users\admin\AppData\Local\Temp\Sshsagrjzaj.exeexecutable
MD5:
SHA256:
2456WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb2456.25070\xNet.dllexecutable
MD5:AC1DCEDDBC66A1AB7915AC9931F0CFEC
SHA256:CC949931EF9533ADCED83F3D58862E9732E5DB7AD17B5FD4CB9D209A99EDB592
2476Google Play Gift Card Generator v1.0 By X-Line.exeC:\Users\admin\AppData\Local\Temp\Sshsagrjzaj.exeexecutable
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
100
DNS requests
4
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2156
Google Play Gift Cards Generator And Checker v2 By X-LINE.exe
172.217.18.78:443
play.google.com
Google Inc.
US
whitelisted
2156
Google Play Gift Cards Generator And Checker v2 By X-LINE.exe
142.250.185.142:443
play.google.com
Google Inc.
US
whitelisted

DNS requests

Domain
IP
Reputation
play.google.com
  • 142.250.185.142
  • 172.217.18.78
whitelisted

Threats

No threats detected
No debug info