analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

Contra_City_Hack_Loader.rar

Full analysis: https://app.any.run/tasks/9bb408a7-8f05-4812-9658-5cbc6d177cff
Verdict: Malicious activity
Analysis date: August 25, 2019, 10:57:15
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v4, os: Win32, flags: Solid
MD5:

0954F5C080AC0671DFF071D1E122CF8F

SHA1:

602E8FB5D90D80FF1EEAC1B2E9ABECDEDC819A75

SHA256:

D4141225CC0430807A4FC6DBA7C2D5F3BA5377CE80EE216E0FA3648DEE7A680B

SSDEEP:

98304:auldPxLiNSJEN0solwQnR50JUlbw0T+YGbSxWoAXnUqiook:9JiNSe3ollr0JUZw0T+/SxWTink

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • SearchProtocolHost.exe (PID: 752)
      • Contra_City_Hack_Loader.exe (PID: 3512)
      • explorer.exe (PID: 276)
    • Application was dropped or rewritten from another process

      • Contra_City_Hack_Loader.exe (PID: 3512)
      • Contra_City_Hack_Loader.exe (PID: 3156)
      • Contra_City_Hack_Loader.exe (PID: 3476)
      • Contra_City_Hack_Loader.exe (PID: 3380)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • explorer.exe (PID: 276)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v-4.x) (58.3)
.rar | RAR compressed archive (gen) (41.6)

EXIF

ZIP

CompressedSize: 4383677
UncompressedSize: 4474880
OperatingSystem: Win32
ModifyDate: 2019:07:04 14:30:24
PackingMethod: Best Compression
ArchivedFileName: Contra_City_Hack_Loader.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
44
Monitored processes
7
Malicious processes
2
Suspicious processes
1

Behavior graph

Click at the process to see the details
null

Process information

PID
CMD
Path
Indicators
Parent process
3128"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Contra_City_Hack_Loader.rar"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.60.0
276C:\Windows\Explorer.EXEC:\Windows\explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
752"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe2_ Global\UsGthrCtrlFltPipeMssGthrPipe2 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" C:\Windows\System32\SearchProtocolHost.exeSearchIndexer.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Windows Search Protocol Host
Version:
7.00.7600.16385 (win7_rtm.090713-1255)
3156"C:\Users\admin\Desktop\Contra_City_Hack_Loader.exe" C:\Users\admin\Desktop\Contra_City_Hack_Loader.exeexplorer.exe
User:
admin
Company:
Made by #Виктор Таскин
Integrity Level:
MEDIUM
Description:
Contra_City_Hack_Loader
Exit code:
3221226540
Version:
2.0.0.0
3512"C:\Users\admin\Desktop\Contra_City_Hack_Loader.exe" C:\Users\admin\Desktop\Contra_City_Hack_Loader.exe
explorer.exe
User:
admin
Company:
Made by #Виктор Таскин
Integrity Level:
HIGH
Description:
Contra_City_Hack_Loader
Exit code:
4294967295
Version:
2.0.0.0
3380"C:\Users\admin\Desktop\Contra_City_Hack_Loader.exe" C:\Users\admin\Desktop\Contra_City_Hack_Loader.exeexplorer.exe
User:
admin
Company:
Made by #Виктор Таскин
Integrity Level:
MEDIUM
Description:
Contra_City_Hack_Loader
Exit code:
3221226540
Version:
2.0.0.0
3476"C:\Users\admin\Desktop\Contra_City_Hack_Loader.exe" C:\Users\admin\Desktop\Contra_City_Hack_Loader.exe
explorer.exe
User:
admin
Company:
Made by #Виктор Таскин
Integrity Level:
HIGH
Description:
Contra_City_Hack_Loader
Version:
2.0.0.0
Total events
1 350
Read events
1 306
Write events
0
Delete events
0

Modification events

No data
Executable files
2
Suspicious files
0
Text files
2
Unknown types
0

Dropped files

PID
Process
Filename
Type
3128WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3128.16389\Contra_City_Hack_Loader.exe
MD5:
SHA256:
3128WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3128.16389\MaterialSkin.dll
MD5:
SHA256:
3512Contra_City_Hack_Loader.exeC:\Users\admin\AppData\Local\Temp\Settings.initext
MD5:9BFBB0E774A54CE1BCF921F04E5A26C3
SHA256:3410F06F8921A9B14A542E043C04F6267AA2723C5F4DC435832EB5EBC0AEAB03
276explorer.exeC:\Users\admin\Desktop\Contra_City_Hack_Loader.exeexecutable
MD5:475CF4034A2138E95A85AB9EFEC7F25A
SHA256:7D7DCFED15D992ACEB9BC979C83FFD5EE2BA27E9214420318D2ADC34AC2DBF03
276explorer.exeC:\Users\admin\Desktop\MaterialSkin.dllexecutable
MD5:DAE45E51F8763BD0369A221480DB0EE1
SHA256:B9879DF15E82C52E9166C71F7B177C57BD4C8289821A65A9D3F5228B3F606B4E
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
1
DNS requests
1
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3512
Contra_City_Hack_Loader.exe
GET
200
5.101.152.87:80
http://kirillsd.beget.tech/CheatBase/Sallers/Buy.list
RU
text
88 b
malicious
3512
Contra_City_Hack_Loader.exe
GET
200
5.101.152.87:80
http://kirillsd.beget.tech/CheatBase/Sallers/Sallers.list
RU
text
81 b
malicious
3512
Contra_City_Hack_Loader.exe
POST
200
5.101.152.87:80
http://kirillsd.beget.tech/CheatBase/api/cheat.php
RU
text
19 b
malicious
3512
Contra_City_Hack_Loader.exe
POST
200
5.101.152.87:80
http://kirillsd.beget.tech/CheatBase/api/cheat.php
RU
text
19 b
malicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3512
Contra_City_Hack_Loader.exe
5.101.152.87:80
kirillsd.beget.tech
Beget Ltd
RU
malicious

DNS requests

Domain
IP
Reputation
kirillsd.beget.tech
  • 5.101.152.87
malicious

Threats

Found threats are available for the paid subscriptions
1 ETPRO signatures available at the full report
No debug info