File name:

BLTools-v2.2-Cracked-by-Injuan.zip

Full analysis: https://app.any.run/tasks/7e03ddf9-e9d8-4335-8811-62fef133bda1
Verdict: Malicious activity
Analysis date: November 11, 2023, 22:06:52
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

BFAEDB986DB4AF3A3566CA4D2223AC27

SHA1:

52CD590C823FA3AD8919C7EDEF40AA4294D01036

SHA256:

D67D8E3135E976D5393EAA28C43E506F3D873AE66D5241389DCC5B8F89D5DA6F

SSDEEP:

98304:Q9z7XolB0p46kvslDyxDC7UWOvjyPib08Ry/zUOOBQg2ze3foGr+3FGwJm7B7bya:48WNxKo0Ye

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • BLTools-v2.2.exe (PID: 3576)
    • Create files in the Startup directory

      • BLTools-v2.2.exe (PID: 3576)
  • SUSPICIOUS

    • The process creates files with name similar to system file names

      • BLTools-v2.2.exe (PID: 3576)
    • Reads the Internet Settings

      • BLTools-v2.2.exe (PID: 3656)
      • BLTools-v2.2.exe (PID: 3988)
    • Uses pipe srvsvc via SMB (transferring data)

      • BLTools-v2.2.exe (PID: 3656)
      • BLTools-v2.2.exe (PID: 3988)
  • INFO

    • Reads the computer name

      • winst.exe (PID: 3488)
      • BLTools-v2.2.exe (PID: 3576)
      • BLTools-v2.2.exe (PID: 3656)
      • wmpnscfg.exe (PID: 3812)
      • BLTools-v2.2.exe (PID: 3988)
    • Checks supported languages

      • BLTools-v2.2.exe (PID: 3656)
      • vshost.exe (PID: 3516)
      • winst.exe (PID: 3488)
      • BLTools-v2.2.exe (PID: 3576)
      • wmpnscfg.exe (PID: 3812)
      • BLTools-v2.2.exe (PID: 3988)
    • Manual execution by a user

      • BLTools-v2.2.exe (PID: 3576)
      • BLTools-v2.2.exe (PID: 3656)
      • wmpnscfg.exe (PID: 3812)
      • BLTools-v2.2.exe (PID: 3988)
    • Creates files or folders in the user directory

      • BLTools-v2.2.exe (PID: 3576)
    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 3440)
    • Reads the machine GUID from the registry

      • wmpnscfg.exe (PID: 3812)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: 0x0808
ZipCompression: None
ZipModifyDate: 2023:11:01 14:52:44
ZipCRC: 0x3e080588
ZipCompressedSize: 830976
ZipUncompressedSize: 830976
ZipFileName: BLTools-v2.2-Cracked-by-Injuan/BLTools-v2.2.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
45
Monitored processes
7
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe no specs bltools-v2.2.exe vshost.exe no specs winst.exe bltools-v2.2.exe no specs wmpnscfg.exe no specs bltools-v2.2.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
3440"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\BLTools-v2.2-Cracked-by-Injuan.zip"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3488C:\Users\admin\AppData\Local\\winst\\winst.exe dJanut0blNunvVx3nILAvaZy6ccnKoAJjl7Ygu620fqKAhojAaSOMXX786kb5pIiC:\Users\admin\AppData\Local\winst\winst.exe
BLTools-v2.2.exe
User:
admin
Integrity Level:
MEDIUM
Description:
winst
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\winst\winst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\webio.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3516C:\Users\admin\AppData\Local\\vshost\\vshost.exe ,.C:\Users\admin\AppData\Local\vshost\vshost.exeBLTools-v2.2.exe
User:
admin
Integrity Level:
MEDIUM
Description:
vshost
Exit code:
0
Version:
17.0.33926.201 (WinBuild.170101.0800)
Modules
Images
c:\users\admin\appdata\local\vshost\vshost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
3576"C:\Users\admin\Desktop\BLTools-v2.2-Cracked-by-Injuan\BLTools-v2.2.exe" C:\Users\admin\Desktop\BLTools-v2.2-Cracked-by-Injuan\BLTools-v2.2.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Version:
2.0.0.1
Modules
Images
c:\users\admin\desktop\bltools-v2.2-cracked-by-injuan\bltools-v2.2.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
3656"C:\Users\admin\Desktop\BLTools-v2.2-Cracked-by-Injuan\BLTools-v2.2.exe" C:\Users\admin\Desktop\BLTools-v2.2-Cracked-by-Injuan\BLTools-v2.2.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Version:
2.0.0.1
Modules
Images
c:\users\admin\desktop\bltools-v2.2-cracked-by-injuan\bltools-v2.2.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
3812"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\ole32.dll
3988"C:\Users\admin\Desktop\BLTools-v2.2-Cracked-by-Injuan\BLTools-v2.2.exe" C:\Users\admin\Desktop\BLTools-v2.2-Cracked-by-Injuan\BLTools-v2.2.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Version:
2.0.0.1
Modules
Images
c:\users\admin\desktop\bltools-v2.2-cracked-by-injuan\bltools-v2.2.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
Total events
2 147
Read events
2 125
Write events
19
Delete events
3

Modification events

(PID) Process:(3440) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\17A\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3440) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(3440) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(3440) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(3440) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3440) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3440) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3440) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3440) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000
(PID) Process:(3440) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\General
Operation:writeName:LastFolder
Value:
C:\Users\admin\Desktop
Executable files
12
Suspicious files
2
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
3440WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3440.41471\BLTools-v2.2-Cracked-by-Injuan\strip.cfgexecutable
MD5:EF5EE302110F10993A991FD9A2350594
SHA256:F368811F3BB071D6EE006731FE819A0B7D8CD7ED5FD8110AEB5CB0DA22A3A3A7
3440WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3440.41471\BLTools-v2.2-Cracked-by-Injuan\core32.cfgexecutable
MD5:4E6A7EE0E286AB61D36C26BD38996821
SHA256:F67DAF4BF2AD0E774BBD53F243E66806397036E5FDE694F3856B27BC0463C0A3
3440WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3440.41471\BLTools-v2.2-Cracked-by-Injuan\Ookii.Dialogs.Wpf.dllexecutable
MD5:932EBB3F9E7113071C6A17818342B7CC
SHA256:285AA8225732DDBCF211B1158BD6CFF8BF3ACBEEAB69617F4BE85862B7105AB5
3440WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3440.41471\BLTools-v2.2-Cracked-by-Injuan\mip_core.dllexecutable
MD5:59238144771807B1CBC407B250D6B2C3
SHA256:8BAA5811836C0B4A64810F6A7D6E1D31D7F80350C69643DC9594F58FD0233A7B
3440WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3440.41471\BLTools-v2.2-Cracked-by-Injuan\RandomUserAgent.dllexecutable
MD5:839CD4CE1930EEE45F55F6259468D649
SHA256:53331BFF5E585C471FAD6789313A2A8A687A586CC0A8D006B24085B91ED7FC9A
3440WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3440.41471\BLTools-v2.2-Cracked-by-Injuan\Newtonsoft.Json.dllexecutable
MD5:081D9558BBB7ADCE142DA153B2D5577A
SHA256:B624949DF8B0E3A6153FDFB730A7C6F4990B6592EE0D922E1788433D276610F3
3440WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3440.41471\BLTools-v2.2-Cracked-by-Injuan\Extreme.Net.dllexecutable
MD5:F79F0E3A0361CAC000E2D3553753CD68
SHA256:8A6518AB7419FBEC3AC9875BAA3AFB410AD1398C7AA622A09CD9084EC6CADFCD
3440WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3440.41471\BLTools-v2.2-Cracked-by-Injuan\Settings.initext
MD5:9A07F774B316B2184B0702FE503B530A
SHA256:A8755CC114A77A7FED9FA5DF6BD6539CEB965CDAD9C7DACAB14F1E5ED0CEE715
3576BLTools-v2.2.exeC:\Users\admin\AppData\Local\winst\winst.exeexecutable
MD5:59238144771807B1CBC407B250D6B2C3
SHA256:8BAA5811836C0B4A64810F6A7D6E1D31D7F80350C69643DC9594F58FD0233A7B
3576BLTools-v2.2.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\vshost.lnkbinary
MD5:D469AAD9FBFA4AF5C82EAAD8DA025FBF
SHA256:9657374EC39EDEB64FCACB3B817695101237B438BE5840BA9FB2EA81AC8E824F
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
14
DNS requests
3
Threats
6

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3488
winst.exe
GET
302
162.216.242.206:80
http://stlaip74566.ddnsgeek.com/
US
html
163 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
whitelisted
2588
svchost.exe
239.255.255.250:1900
whitelisted
3488
winst.exe
162.216.242.206:80
stlaip74566.ddnsgeek.com
DYNU
US
unknown
3488
winst.exe
185.247.224.98:443
stlaep34621.ddnsgeek.com
Flokinet Ltd
SC
unknown

DNS requests

Domain
IP
Reputation
stlaip74566.ddnsgeek.com
  • 162.216.242.206
unknown
stlaep34621.ddnsgeek.com
  • 185.247.224.98
unknown
winst.lnk
unknown

Threats

PID
Process
Class
Message
1080
svchost.exe
Potentially Bad Traffic
ET INFO DYNAMIC_DNS Query to a *.ddnsgeek .com Domain
3488
winst.exe
Possibly Unwanted Program Detected
ET ADWARE_PUP User-Agent (Mozilla) - Possible Spyware Related
3488
winst.exe
Potentially Bad Traffic
ET INFO DYNAMIC_DNS HTTP Request to a *.ddnsgeek .com Domain
1080
svchost.exe
Potentially Bad Traffic
ET INFO DYNAMIC_DNS Query to a *.ddnsgeek .com Domain
2 ETPRO signatures available at the full report
No debug info