File name:

BLTools v2.9.zip

Full analysis: https://app.any.run/tasks/d137df62-a5bb-49b9-8733-0106380d9788
Verdict: Malicious activity
Analysis date: March 15, 2024, 23:24:59
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v1.0 to extract, compression method=store
MD5:

6CA164FC54FDA35FD4F0BF419631C6AE

SHA1:

82BFEDCB7A497C451ABD14CD94F70FA8EB7DA4D3

SHA256:

D8DBADBA21FC4BA280ADD2F874C35380B6C07A534E23E9006D6E3C6C55EB231C

SSDEEP:

98304:twWajSfoY/IqcikV/E0v+750vPGJssIzbfxwx0U5Kj5gO9pB39/32c4hYjG4BQDR:WZ35QM2tdwNhPjFp9d8

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • WinRAR.exe (PID: 2124)
    • Reads settings of System Certificates

      • BLTools v2.9.exe (PID: 3516)
    • Reads the Internet Settings

      • BLTools v2.9.exe (PID: 3516)
    • Reads the BIOS version

      • BLTools v2.9.exe (PID: 3516)
  • INFO

    • Manual execution by a user

      • BLTools v2.9.exe (PID: 3516)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2124)
    • Reads the computer name

      • BLTools v2.9.exe (PID: 3516)
    • Reads Environment values

      • BLTools v2.9.exe (PID: 3516)
    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 2124)
    • Reads the software policy settings

      • BLTools v2.9.exe (PID: 3516)
    • Checks supported languages

      • BLTools v2.9.exe (PID: 3516)
    • Reads the machine GUID from the registry

      • BLTools v2.9.exe (PID: 3516)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 10
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2024:03:15 16:22:18
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: BLTools v2.9/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
39
Monitored processes
2
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe bltools v2.9.exe

Process information

PID
CMD
Path
Indicators
Parent process
2124"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\BLTools v2.9.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3516"C:\Users\admin\Desktop\BLTools v2.9\BLTools v2.9\BLTools v2.9.exe" C:\Users\admin\Desktop\BLTools v2.9\BLTools v2.9\BLTools v2.9.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
BLTools Cookies Checker
Exit code:
0
Version:
2.9.0.0
Modules
Images
c:\users\admin\desktop\bltools v2.9\bltools v2.9\bltools v2.9.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
Total events
8 531
Read events
8 481
Write events
50
Delete events
0

Modification events

(PID) Process:(2124) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2124) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2124) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2124) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(2124) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(2124) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(2124) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\BLTools v2.9.zip
(PID) Process:(2124) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2124) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2124) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
Executable files
8
Suspicious files
2
Text files
27
Unknown types
0

Dropped files

PID
Process
Filename
Type
2124WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb2124.10818\BLTools v2.9\BLTools v2.9\CookiesCreator v1.2.exeexecutable
MD5:30C33F45545B68BD1E0D7EC79A090883
SHA256:4E95226CCE6E17FDC39F3A5F9050720D7848BB34CE2DF72E63C878235C5BE630
2124WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb2124.10818\BLTools v2.9\BLTools v2.9\Projects\carousell_MY.projtext
MD5:A7DC8AAB3EFB58C1A60353B56CE70C1E
SHA256:8DD192EAC540FB29B60327B3A911CF27C13E846924B2BD83D7D2534DCEC69E8B
2124WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb2124.10818\BLTools v2.9\BLTools v2.9\License.dlltext
MD5:B08A5C34CF0A06615DA2CA89010D8B4F
SHA256:04CC5B3B49A7E9E9B6C66C7BE59A20992BF2653746B5D43829C383FB233F88FA
2124WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb2124.10818\BLTools v2.9\BLTools v2.9\Projects\2ememain.be.projtext
MD5:F8A23F836EF27D836E15F62F6851940B
SHA256:7E3548D9D3A318ECDB996C8C23E52A065FC07C12C72407CD4AA9AA631F2769AC
2124WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb2124.10818\BLTools v2.9\BLTools v2.9\Projects\2dehands.be.projtext
MD5:C83ECFBF6D3A250D9D928DF23D069E0C
SHA256:8F63F6C77EED61B0698665F1FCA117B77C7807384310E50C29194D2A3D822689
2124WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb2124.10818\BLTools v2.9\BLTools v2.9\Projects\carousell_SG.projtext
MD5:C9E038B00F09D559AE137ADAFFD1BA91
SHA256:EBB25FBF252E0769D66447F885B2B047DFFCD3EEFD715300E5978F1BA13B4F17
2124WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb2124.10818\BLTools v2.9\BLTools v2.9\Projects\capmonster.cloud.projtext
MD5:C4A6593B93DEADE325163A2258668DD4
SHA256:067A5DC77C7EFAC341B2D543F01C6CC6E1D5585B7417EBB93C333BF91774116D
2124WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb2124.10818\BLTools v2.9\BLTools v2.9\Extreme.Net.dllexecutable
MD5:F79F0E3A0361CAC000E2D3553753CD68
SHA256:8A6518AB7419FBEC3AC9875BAA3AFB410AD1398C7AA622A09CD9084EC6CADFCD
2124WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb2124.10818\BLTools v2.9\BLTools v2.9\Projects\dba.dk.projtext
MD5:90E1CBC56BF62EDE9F7D1A2F93F367E4
SHA256:E51CCB0D3D0A98708FB18B80BE431863FCF8CC5E78EAF3AFDDD0E5E2FA3A9045
2124WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb2124.10818\BLTools v2.9\BLTools v2.9\BLTools v2.9.exeexecutable
MD5:4B935AC09137C47F5A0A32C86386F0C6
SHA256:2B22FDE0954F1780E0F692493651B5B6DEE40CFA994921C139C0D49D05BB1098
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
9
DNS requests
4
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3516
BLTools v2.9.exe
GET
200
2.16.100.168:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?86d6139f3b7ef26c
unknown
compressed
67.5 Kb
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
unknown
4
System
192.168.100.255:137
unknown
224.0.0.252:5355
unknown
1080
svchost.exe
224.0.0.252:5355
unknown
3516
BLTools v2.9.exe
172.67.72.57:443
keyauth.win
CLOUDFLARENET
US
unknown
3516
BLTools v2.9.exe
88.221.110.91:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown
3516
BLTools v2.9.exe
2.16.100.168:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown

DNS requests

Domain
IP
Reputation
keyauth.win
  • 172.67.72.57
  • 104.26.1.5
  • 104.26.0.5
unknown
ctldl.windowsupdate.com
  • 88.221.110.91
  • 2.16.100.168
unknown
dns.msftncsi.com
  • 131.107.255.255
unknown

Threats

PID
Process
Class
Message
Potentially Bad Traffic
ET INFO Fake Game Cheat Related Domain in DNS Lookup (keyauth .win)
Potentially Bad Traffic
ET INFO Fake Game Cheat Related Domain (keyauth .win) in TLS SNI
No debug info