File name:

NetFlix Checker by xRisky v2.rar

Full analysis: https://app.any.run/tasks/27a2cc61-87e3-4825-a647-3efc452f542e
Verdict: Malicious activity
Analysis date: January 24, 2022, 17:35:37
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

F8FB64E8D50CC6D9BF05D5C8E20D56C0

SHA1:

EDC49D759ADBA60C69A18BF9233E6E2035F1FCB0

SHA256:

D5E66C54CF7AC370D1701C48C73A8002F9437D8497D201EF1D784E813CD44945

SSDEEP:

196608:fzAgmwkpgI6+BaICCSF2+vAvhqTZSWxGOk+YxoByFphgMU:fzh4x6ovqs+BExo47OMU

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • SearchProtocolHost.exe (PID: 3796)
      • Launcher.exe (PID: 584)
      • NetCheck.exe (PID: 2608)
    • Application was dropped or rewritten from another process

      • NetFlix Checker by xRisky v2.exe (PID: 3132)
      • Launcher.exe (PID: 584)
      • Runtime Explorer.exe (PID: 2748)
      • Secure System Shell.exe (PID: 1972)
      • Windows Services.exe (PID: 4036)
      • Runtime Explorer.exe (PID: 3856)
      • NetCheck.exe (PID: 2608)
    • Writes to a start menu file

      • Launcher.exe (PID: 584)
    • Changes the autorun value in the registry

      • Launcher.exe (PID: 584)
  • SUSPICIOUS

    • Reads the computer name

      • WinRAR.exe (PID: 3860)
      • NetFlix Checker by xRisky v2.exe (PID: 3132)
      • Launcher.exe (PID: 584)
      • powershell.exe (PID: 2572)
      • NetCheck.exe (PID: 2608)
      • Windows Services.exe (PID: 4036)
      • Secure System Shell.exe (PID: 1972)
    • Checks supported languages

      • WinRAR.exe (PID: 3860)
      • NetFlix Checker by xRisky v2.exe (PID: 3132)
      • Launcher.exe (PID: 584)
      • NetCheck.exe (PID: 2608)
      • Windows Services.exe (PID: 4036)
      • Secure System Shell.exe (PID: 1972)
      • Runtime Explorer.exe (PID: 3856)
      • Runtime Explorer.exe (PID: 2748)
      • powershell.exe (PID: 2572)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3860)
      • Launcher.exe (PID: 584)
    • Executes PowerShell scripts

      • Launcher.exe (PID: 584)
    • Drops a file with a compile date too recent

      • WinRAR.exe (PID: 3860)
    • Drops a file that was compiled in debug mode

      • WinRAR.exe (PID: 3860)
    • Creates files in the Windows directory

      • Launcher.exe (PID: 584)
    • Creates files in the user directory

      • Launcher.exe (PID: 584)
  • INFO

    • Checks Windows Trust Settings

      • powershell.exe (PID: 2572)
    • Manual execution by user

      • NetFlix Checker by xRisky v2.exe (PID: 3132)
    • Dropped object may contain Bitcoin addresses

      • Launcher.exe (PID: 584)
    • Reads settings of System Certificates

      • powershell.exe (PID: 2572)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
49
Monitored processes
10
Malicious processes
6
Suspicious processes
4

Behavior graph

Click at the process to see the details
start drop and start winrar.exe searchprotocolhost.exe no specs netflix checker by xrisky v2.exe no specs launcher.exe powershell.exe no specs netcheck.exe windows services.exe no specs secure system shell.exe no specs runtime explorer.exe no specs runtime explorer.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
584"C:\Users\admin\Desktop\NetFlix Checker by xRisky v2\debug\Launcher.exe" C:\Users\admin\Desktop\NetFlix Checker by xRisky v2\debug\Launcher.exe
NetFlix Checker by xRisky v2.exe
User:
admin
Integrity Level:
HIGH
Description:
Launcher
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\netflix checker by xrisky v2\debug\launcher.exe
c:\windows\system32\mscoree.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
1972"C:\Windows\IMF\Secure System Shell.exe" C:\Windows\IMF\Secure System Shell.exeWindows Services.exe
User:
admin
Integrity Level:
HIGH
Description:
Secure System Shell
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\windows\imf\secure system shell.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
2572"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" add-mppreference -exclusionpath C:\Windows\IMF\C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeLauncher.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows PowerShell
Exit code:
1
Version:
10.0.14409.1005 (rs1_srvoob.161208-1155)
Modules
Images
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\atl.dll
c:\windows\system32\user32.dll
2608"C:\Users\admin\Desktop\NetFlix Checker by xRisky v2\debug\NetCheck.exe" C:\Users\admin\Desktop\NetFlix Checker by xRisky v2\debug\NetCheck.exe
NetFlix Checker by xRisky v2.exe
User:
admin
Company:
__xRisky__
Integrity Level:
HIGH
Description:
NetFlix Checker by xRisky v2
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\netflix checker by xrisky v2\debug\netcheck.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2748"C:\Windows\IMF\Runtime Explorer.exe" C:\Windows\IMF\Runtime Explorer.exeWindows Services.exe
User:
admin
Company:
Microsoft Windows
Integrity Level:
HIGH
Exit code:
0
Version:
1.00
Modules
Images
c:\windows\imf\runtime explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvbvm60.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
3132"C:\Users\admin\Desktop\NetFlix Checker by xRisky v2\NetFlix Checker by xRisky v2.exe" C:\Users\admin\Desktop\NetFlix Checker by xRisky v2\NetFlix Checker by xRisky v2.exeExplorer.EXE
User:
admin
Integrity Level:
MEDIUM
Description:
Launcher
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\netflix checker by xrisky v2\netflix checker by xrisky v2.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3796"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe2_ Global\UsGthrCtrlFltPipeMssGthrPipe2 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" C:\Windows\system32\SearchProtocolHost.exeSearchIndexer.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Windows Search Protocol Host
Exit code:
0
Version:
7.00.7601.24542 (win7sp1_ldr_escrow.191209-2211)
Modules
Images
c:\windows\system32\searchprotocolhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3856"C:\Windows\IMF\Runtime Explorer.exe" C:\Windows\IMF\Runtime Explorer.exeWindows Services.exe
User:
admin
Company:
Microsoft Windows
Integrity Level:
HIGH
Exit code:
0
Version:
1.00
Modules
Images
c:\windows\imf\runtime explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvbvm60.dll
3860"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\NetFlix Checker by xRisky v2.rar"C:\Program Files\WinRAR\WinRAR.exe
Explorer.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
4036"C:\Windows\IMF\Windows Services.exe" {Arguments If Needed}C:\Windows\IMF\Windows Services.exeLauncher.exe
User:
admin
Integrity Level:
HIGH
Description:
Windows Services
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\windows\imf\windows services.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
Total events
6 424
Read events
6 345
Write events
79
Delete events
0

Modification events

(PID) Process:(3860) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3860) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3860) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3860) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(3860) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(3860) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\NetFlix Checker by xRisky v2.rar
(PID) Process:(3860) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3860) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3860) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3860) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
Executable files
18
Suspicious files
6
Text files
1
Unknown types
2

Dropped files

PID
Process
Filename
Type
3860WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3860.40162\NetFlix Checker by xRisky v2\debug\chromedriver.exeexecutable
MD5:467838B0DA3380609A468679B0639ABC
SHA256:282DD0A35F2336E409FC82EBC8649B0F9257C4016AF75111ED709EE7C9132EF2
3860WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3860.40162\NetFlix Checker by xRisky v2\debug\d3dx10_43.dllexecutable
MD5:20C835843FCEC4DEDFCD7BFFA3B91641
SHA256:56FCD13650FD1F075743154E8C48465DD68A236AB8960667D75373139D2631BF
3860WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3860.40162\NetFlix Checker by xRisky v2\debug\Launcher.exeexecutable
MD5:C6D4C881112022EB30725978ECD7C6EC
SHA256:0D87B9B141A592711C52E7409EC64DE3AB296CDDC890BE761D9AF57CEA381B32
3860WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3860.40162\NetFlix Checker by xRisky v2\debug\MetroSuite 2.0.dllexecutable
MD5:0D30A398CEC0FF006B6EA2B52D11E744
SHA256:8604BF2A1FE2E94DC1EA1FBD0CF54E77303493B93994DF48479DC683580AA654
3860WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3860.40162\NetFlix Checker by xRisky v2\debug\Qoollo.Turbo.dllexecutable
MD5:4E8246DF4EE956EC273C4BAA2054593C
SHA256:1172732FD0FE6B679F5C6BF750598133DC815622C55EF1FA84087087BF42B495
3860WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3860.40162\NetFlix Checker by xRisky v2\debug\LICENCE.datcompressed
MD5:F3014A18051F4E596AB95DA9138F6F6B
SHA256:1F84A00808D5ECA122FDE7F20708F272C349FAE1EAA1129B5C694750F2E047D6
3860WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3860.40162\NetFlix Checker by xRisky v2\debug\WIA\wiatrace.logtext
MD5:FCE6ED7DFBD860CA121ECEF06523470A
SHA256:732A3C9184B5458C8B22F4B03611D9E60AF30A0B7236622200562455FF87085A
3860WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3860.40162\NetFlix Checker by xRisky v2\NetFlix Checker by xRisky v2.exeexecutable
MD5:
SHA256:
2572powershell.exeC:\Users\admin\AppData\Local\Temp\wnon3rn0.h2o.psm1binary
MD5:C4CA4238A0B923820DCC509A6F75849B
SHA256:
3860WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3860.40162\NetFlix Checker by xRisky v2\xNet.dllexecutable
MD5:158DEFD55A804AA8D4D67BFDF7A4AF9C
SHA256:6C7EC4CC31A2CE0B97703B7A42E3448E9B87D96DDA12761CA24D8787AC27CFF1
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info