File name:

NBTExplorer-2.8.0.rar

Full analysis: https://app.any.run/tasks/9505d526-29b5-4f68-b0d2-bc2c48c530e1
Verdict: Malicious activity
Analysis date: October 23, 2023, 08:20:26
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

7D679D29045E2B2A75A6809AFE70AC1D

SHA1:

84D3025D88A708A5F546BB163D7F2141B44B90D7

SHA256:

D4D545C1D5CD3C69615F1A928EE97043E56AF36718B87DCF6A1C0E8088AD93A4

SSDEEP:

6144:cS3AwAg9Wd7aOOUxZ4+/bwUsZcL80/9msiPgRln4u/MojPusoji:cSxAgcGAL4MFnYk9msqgjn4EMFi

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • NBTExplorer.exe (PID: 460)
    • Loads dropped or rewritten executable

      • NBTExplorer.exe (PID: 460)
  • SUSPICIOUS

    • The process creates files with name similar to system file names

      • WinRAR.exe (PID: 556)
      • NBTExplorer.exe (PID: 460)
    • Reads the Internet Settings

      • NBTExplorer.exe (PID: 460)
  • INFO

    • Manual execution by a user

      • NBTExplorer.exe (PID: 460)
    • Reads the computer name

      • NBTExplorer.exe (PID: 460)
    • Checks supported languages

      • NBTExplorer.exe (PID: 460)
    • Reads the machine GUID from the registry

      • NBTExplorer.exe (PID: 460)
    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 556)
    • Creates files or folders in the user directory

      • NBTExplorer.exe (PID: 460)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
38
Monitored processes
3
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe no specs searchprotocolhost.exe no specs nbtexplorer.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
460"C:\Users\admin\Desktop\NBTExplorer-2.8.0\NBTExplorer.exe" C:\Users\admin\Desktop\NBTExplorer-2.8.0\NBTExplorer.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
NBTExplorer
Exit code:
0
Version:
2.8.0.0
Modules
Images
c:\users\admin\desktop\nbtexplorer-2.8.0\nbtexplorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shlwapi.dll
556"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\NBTExplorer-2.8.0.rar"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\usp10.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\shlwapi.dll
2764"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe6_ Global\UsGthrCtrlFltPipeMssGthrPipe6 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" C:\Windows\System32\SearchProtocolHost.exeSearchIndexer.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Windows Search Protocol Host
Exit code:
0
Version:
7.00.7601.24542 (win7sp1_ldr_escrow.191209-2211)
Modules
Images
c:\windows\system32\searchprotocolhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
1 812
Read events
1 785
Write events
27
Delete events
0

Modification events

(PID) Process:(556) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\178\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(556) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(556) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(556) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(556) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(556) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(556) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(556) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(556) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000
(PID) Process:(556) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\General
Operation:writeName:LastFolder
Value:
C:\Users\admin\Desktop
Executable files
4
Suspicious files
0
Text files
4
Unknown types
0

Dropped files

PID
Process
Filename
Type
556WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa556.22399\NBTExplorer-2.8.0\NBTExplorer.exeexecutable
MD5:7D39AD6228157EBA3D4872AFEAF042B0
SHA256:C5E26B88085AD4AA60A434D2554EAAA4F3C4A37AA26B12F40B70FB0C7F6D6A3F
556WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa556.22399\NBTExplorer-2.8.0\NBTModel.dllexecutable
MD5:4F6755F0ADCCECEEBDF45C056B5A885A
SHA256:482A8F6810C8D2B659FCF313BEA15E914B54923F9CFE5D0A11508CD16C81AEAE
556WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa556.22399\NBTExplorer-2.8.0\NBTExplorer.exe.configxml
MD5:B241C600A41ADD92F22DBA80D4CED85F
SHA256:CBD941CA8C1E1171A21054EB9D6795EC6D677C5A06EBB33850C1547D3D051D8A
556WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa556.22399\NBTExplorer-2.8.0\NBTUtil.exeexecutable
MD5:5CE4B1B7AD0BF2D489133BC1CD91FAD2
SHA256:C26A46E87E270A168E55429588BEE2839B702C0C5C57EF25C6515F38F2D7D0DA
556WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa556.22399\NBTExplorer-2.8.0\NBTUtil.exe.configxml
MD5:357B302903F3FD55C20DDF876835AE35
SHA256:309E6FEDB75EDB45DFF3937EFB1565F19443EC2CDB8EA20B91254701C3E7AC6D
556WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa556.22399\NBTExplorer-2.8.0\Substrate.dllexecutable
MD5:1368BE03ADEC59D273442910ABDD8741
SHA256:BD27F3309530A1937B068E6B9F1B5663BF5E28E4619EF25724A3290EB491E765
460NBTExplorer.exeC:\Users\admin\AppData\Local\NBTExplorer\NBTExplorer.exe_Url_1nmcjzqtyeaja35k44whrepf1hogxcu4\2.8.0.0\wlrkn2pe.newcfgxml
MD5:148D5A80F78732A26553E7A1AF6D730A
SHA256:3891C21478ADEC84B3CB77EBED41867366A28FBC9D8CD6F1CCAF8E83BBC2EF74
460NBTExplorer.exeC:\Users\admin\AppData\Local\NBTExplorer\NBTExplorer.exe_Url_1nmcjzqtyeaja35k44whrepf1hogxcu4\2.8.0.0\user.configxml
MD5:148D5A80F78732A26553E7A1AF6D730A
SHA256:3891C21478ADEC84B3CB77EBED41867366A28FBC9D8CD6F1CCAF8E83BBC2EF74
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
2
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted

DNS requests

No data

Threats

No threats detected
No debug info