| File name: | MangaMeeya.zip |
| Full analysis: | https://app.any.run/tasks/339e5f69-fd24-48b4-975b-b778de697931 |
| Verdict: | Malicious activity |
| Threats: | A backdoor is a type of cybersecurity threat that allows attackers to secretly compromise a system and conduct malicious activities, such as stealing data and modifying files. Backdoors can be difficult to detect, as they often use legitimate system applications to evade defense mechanisms. Threat actors often utilize special malware, such as PlugX, to establish backdoors on target devices. |
| Analysis date: | March 20, 2025, 07:04:10 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract, compression method=store |
| MD5: | A3EE98FB7645EA4D9B83924CE3868D40 |
| SHA1: | 39DE0771194F9AEA893AC14B5E0F98FF9603008E |
| SHA256: | D6DAD53093A9DA729A3BABE9589FCDDA02BD58544F76EECD052EB1076285FF66 |
| SSDEEP: | 98304:k79D6G7aRXhfIxqkt2iX2xODdvmmphhHAq3nE8HLRzRHfjAmTlkHRCBaW4lRT4+s:x726kUOvYC5 |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 20 |
|---|---|
| ZipBitFlag: | - |
| ZipCompression: | None |
| ZipModifyDate: | 2022:10:10 22:24:00 |
| ZipCRC: | 0x00000000 |
| ZipCompressedSize: | - |
| ZipUncompressedSize: | - |
| ZipFileName: | MangaMeeya/ |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 312 | C:\Users\admin\AppData\Local\Temp\upTVSr.exe | C:\Users\admin\AppData\Local\Temp\upTVSr.exe | MangaMeeya.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 948 | C:\Windows\system32\cmd.exe /c ""C:\Users\admin\AppData\Local\Temp\0b557761.bat" " | C:\Windows\System32\cmd.exe | — | upTVSr.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 1 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 1028 | "C:\Windows\system32\ntvdm.exe" -i4 | C:\Windows\System32\ntvdm.exe | upTVSr.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: NTVDM.EXE Exit code: 3221225477 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1080 | C:\Windows\system32\svchost.exe -k NetworkService | C:\Windows\System32\svchost.exe | services.exe | ||||||||||||
User: NETWORK SERVICE Company: Microsoft Corporation Integrity Level: SYSTEM Description: Host Process for Windows Services Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1500 | "C:\Windows\system32\ntvdm.exe" -i3 | C:\Windows\System32\ntvdm.exe | upTVSr.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: NTVDM.EXE Exit code: 3221225477 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1748 | "C:\Users\admin\Desktop\MangaMeeya\MangaMeeya.exe" | C:\Users\admin\Desktop\MangaMeeya\MangaMeeya.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 1936 | "C:\Windows\system32\NOTEPAD.EXE" C:\Users\admin\AppData\Local\Temp\dd_SetupUtility.txt | C:\Windows\System32\notepad.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Notepad Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2016 | "C:\Windows\system32\ntvdm.exe" -i2 | C:\Windows\System32\ntvdm.exe | — | upTVSr.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: NTVDM.EXE Exit code: 3221225477 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2624 | "C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\MangaMeeya.zip | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Version: 5.91.0 Modules
| |||||||||||||||
| 2748 | "C:\Windows\system32\ntvdm.exe" -i5 | C:\Windows\System32\ntvdm.exe | upTVSr.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: NTVDM.EXE Exit code: 3221225477 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (2624) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (2624) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (2624) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2624) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (2624) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip | |||
| (PID) Process: | (2624) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\omni_23_10_2024_.zip | |||
| (PID) Process: | (2624) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\MangaMeeya.zip | |||
| (PID) Process: | (2624) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (2624) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (2624) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2624 | WinRAR.exe | C:\Users\admin\Desktop\MangaMeeya\altermeeya.ini | text | |
MD5:6BF26321ACB882858D7FB2C21F797F24 | SHA256:814BEBB5A2C587A4CC904B6FA5E3871CB10F830872DFA6C6B657079A7BA79DEE | |||
| 2624 | WinRAR.exe | C:\Users\admin\Desktop\MangaMeeya\AvisynthPlugin\ColorYUY2_for_25.dll | executable | |
MD5:29A858896917F387D51AA355886CB746 | SHA256:66BACF4B214BB7E9EE36A412CC5D8E9F1EBB8FFF7C048684B047B3F6EB49C75A | |||
| 2624 | WinRAR.exe | C:\Users\admin\Desktop\MangaMeeya\AvisynthPlugin\AdjustColor.def | text | |
MD5:CC1D797BD7ACC9C922F84F8A06CCC600 | SHA256:3A13DCF96272FF72061659B457427902F9E638D3DEAA4D15677AE9F2FB8581CB | |||
| 2624 | WinRAR.exe | C:\Users\admin\Desktop\MangaMeeya\AvisynthPlugin\lanczos3.def | text | |
MD5:8B18B88C779B799D3DC5A42D685D1121 | SHA256:CE0CAFD57287443062EFFE1D847BC91AF4BAA494D5D24541E3040F0840E8C7D7 | |||
| 2624 | WinRAR.exe | C:\Users\admin\Desktop\MangaMeeya\arc.dll | executable | |
MD5:670487110964B5E5F0EDB79F5FDB7C81 | SHA256:4CD042F6864430D7B28E109F94496CBDBE5E3FDA293407D79ECFC5D3FD975647 | |||
| 2624 | WinRAR.exe | C:\Users\admin\Desktop\MangaMeeya\AvisynthPlugin\ColorYUV2.dll | executable | |
MD5:A4D6F924AE93E3A7167C2B1DB8AA94CF | SHA256:BFCD819485BB1E04B118AE5942EB6AF2C2CCAD891BF3774EA9ADDE79917C8083 | |||
| 2624 | WinRAR.exe | C:\Users\admin\Desktop\MangaMeeya\AvisynthPlugin\ColorYUY2.def | text | |
MD5:ACB72D42026B1C9457D0773516573655 | SHA256:9852B53BBC15B1DA58CDB6FB3347C91F6E31D3B337587B0D5DE7A3224F3BB53A | |||
| 2624 | WinRAR.exe | C:\Users\admin\Desktop\MangaMeeya\AvisynthPlugin\lanczos3.dll | executable | |
MD5:AAF168FECA33660A999DD9E455832209 | SHA256:F0E4B2249A8BDD17999FA66EF5312FBC59B58B2D484554DD0FF067B22880A188 | |||
| 2624 | WinRAR.exe | C:\Users\admin\Desktop\MangaMeeya\AvisynthPlugin\MangaMeeya.def | text | |
MD5:91C1F8D07135D1B2F6B479052E970BCE | SHA256:2B89CC92E7180D3C1DC377CC519C47F371FE74C95CC3E32E1BC11DB61BF85CFA | |||
| 2624 | WinRAR.exe | C:\Users\admin\Desktop\MangaMeeya\AvisynthPlugin\SimpleResize.def | text | |
MD5:F8CAFD14562FDFC0EEB0BE3A9F8403E6 | SHA256:B1F1E0D0250A062F82B0DF0B431E14A4877CE35D6AE0C891ADBB581BE81AE0D6 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
312 | upTVSr.exe | GET | — | 3.229.117.57:799 | http://ddos.dnsnb8.net:799/cj//k2.rar | unknown | — | — | malicious |
312 | upTVSr.exe | GET | — | 3.229.117.57:799 | http://ddos.dnsnb8.net:799/cj//k1.rar | unknown | — | — | malicious |
312 | upTVSr.exe | GET | — | 3.229.117.57:799 | http://ddos.dnsnb8.net:799/cj//k2.rar | unknown | — | — | malicious |
312 | upTVSr.exe | GET | — | 3.229.117.57:799 | http://ddos.dnsnb8.net:799/cj//k3.rar | unknown | — | — | malicious |
312 | upTVSr.exe | GET | — | 3.229.117.57:799 | http://ddos.dnsnb8.net:799/cj//k4.rar | unknown | — | — | malicious |
312 | upTVSr.exe | GET | — | 3.229.117.57:799 | http://ddos.dnsnb8.net:799/cj//k5.rar | unknown | — | — | malicious |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 224.0.0.252:5355 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | whitelisted |
312 | upTVSr.exe | 3.229.117.57:799 | ddos.dnsnb8.net | AMAZON-AES | US | malicious |
Domain | IP | Reputation |
|---|---|---|
google.com |
| whitelisted |
ddos.dnsnb8.net |
| malicious |
PID | Process | Class | Message |
|---|---|---|---|
1080 | svchost.exe | Misc activity | SUSPICIOUS [ANY.RUN] Domain previously seen in multiple payload deliveries (ddos .dnsnb8 .net) |
312 | upTVSr.exe | A Network Trojan was detected | BACKDOOR [ANY.RUN] Bdaejec Backdoor (download .rar) |
312 | upTVSr.exe | A Network Trojan was detected | BACKDOOR [ANY.RUN] Bdaejec Backdoor (download .rar) |
312 | upTVSr.exe | A Network Trojan was detected | BACKDOOR [ANY.RUN] Bdaejec Backdoor (download .rar) |
312 | upTVSr.exe | A Network Trojan was detected | BACKDOOR [ANY.RUN] Bdaejec Backdoor (download .rar) |
312 | upTVSr.exe | A Network Trojan was detected | BACKDOOR [ANY.RUN] Bdaejec Backdoor (download .rar) |
312 | upTVSr.exe | A Network Trojan was detected | BACKDOOR [ANY.RUN] Bdaejec Backdoor (download .rar) |