analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

3_checker.rar

Full analysis: https://app.any.run/tasks/108771c2-94fc-4985-9199-6d69c5835b83
Verdict: Malicious activity
Analysis date: August 17, 2019, 17:20:32
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

2EF97EED1401E644051608150FB0E5CE

SHA1:

9BCED3BD807CA99361E9EBA10BD773FCE17D1ADD

SHA256:

DCA6C6A46FBDC7EAB9C8E49D97E4F78067A850CA896D7F3320FD197642EF7485

SSDEEP:

49152:ivUSLEiT5wp7vbQRZmsFFZ2T8maP7w07p3mywN6/75z65ZY9qxl4MERcujHpd:OrLb+p7vbQnmsvAT8380l3/m60jY9olG

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • SearchProtocolHost.exe (PID: 1456)
      • Steam Accounts Checker By X-SLAYER.exe (PID: 2936)
    • Application was dropped or rewritten from another process

      • Steam API Cracker Coded by MR.ViPER - v3.0.exe (PID: 460)
      • Steam Accounts Checker By X-SLAYER.exe (PID: 2936)
      • STORM.exe (PID: 3792)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3576)
      • Steam Accounts Checker By X-SLAYER.exe (PID: 2936)
    • Reads internet explorer settings

      • Steam Accounts Checker By X-SLAYER.exe (PID: 2936)
  • INFO

    • Manual execution by user

      • Steam Accounts Checker By X-SLAYER.exe (PID: 2936)
      • Steam API Cracker Coded by MR.ViPER - v3.0.exe (PID: 460)
      • STORM.exe (PID: 3792)
    • Reads settings of System Certificates

      • STORM.exe (PID: 3792)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
40
Monitored processes
5
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe steam api cracker coded by mr.viper - v3.0.exe no specs searchprotocolhost.exe no specs steam accounts checker by x-slayer.exe storm.exe

Process information

PID
CMD
Path
Indicators
Parent process
3576"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\3_checker.rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
460"C:\Users\admin\Desktop\Steam Checkers\Steam API Cracker Coded by MR.ViPER - v3.0.exe" C:\Users\admin\Desktop\Steam Checkers\Steam API Cracker Coded by MR.ViPER - v3.0.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Steam API Cracker
Exit code:
0
Version:
3.0
1456"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe2_ Global\UsGthrCtrlFltPipeMssGthrPipe2 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" C:\Windows\System32\SearchProtocolHost.exeSearchIndexer.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Windows Search Protocol Host
Version:
7.00.7600.16385 (win7_rtm.090713-1255)
2936"C:\Users\admin\Desktop\Steam Checkers\Steam Checker by X-SLAYER\Steam Accounts Checker By X-SLAYER.exe" C:\Users\admin\Desktop\Steam Checkers\Steam Checker by X-SLAYER\Steam Accounts Checker By X-SLAYER.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Checker By X-SLAYER
Exit code:
0
Version:
1.0.0.0
3792"C:\Users\admin\Desktop\STORM\STORM.exe" C:\Users\admin\Desktop\STORM\STORM.exe
explorer.exe
User:
admin
Company:
Cracking.org
Integrity Level:
MEDIUM
Description:
STORM
Exit code:
1
Version:
1.3
Total events
844
Read events
809
Write events
35
Delete events
0

Modification events

(PID) Process:(3576) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3576) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3576) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\72\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3576) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\3_checker.rar
(PID) Process:(3576) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3576) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3576) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3576) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(1456) SearchProtocolHost.exeKey:HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\72\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1456) SearchProtocolHost.exeKey:HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\72\52C64B7E
Operation:writeName:@C:\Windows\system32\notepad.exe,-469
Value:
Text Document
Executable files
7
Suspicious files
0
Text files
3
Unknown types
0

Dropped files

PID
Process
Filename
Type
3576WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3576.46739\STORM\FUCNTIONS DOCUMENTATION.txttext
MD5:4317BDC179B883668D044A8793D553D5
SHA256:A0B30FC73FA12831947E51591C30941ACE3CD30CEF1DE778E3ABA35DE767A9B0
3576WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3576.46739\STORM\readme.txttext
MD5:900C829B2E12D425116672AE93509980
SHA256:C76B477F638E0FF175A1C0383515AF8A2DA3DCD0AEE3D551ABCF8D9E9E61AD4B
3576WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3576.46739\STORM\CHANGELOGtext
MD5:5E8EAF8FD4455E073732E6F82681AD07
SHA256:D94E68C9E1802D1D491DE7D35CDEDED9C13BCA8F76920ED0F9BF501942655809
3576WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3576.46739\Steam Checkers\Steam Checker by X-SLAYER\Steam Accounts Checker By X-SLAYER.exeexecutable
MD5:559D0FADA4454A2D16A4109DC49BE8E0
SHA256:C4FB143C793502192F663E4AB8670B7A672B62B8B6BABB942AF04AD8825E793D
3576WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3576.46739\STORM\STORM.exeexecutable
MD5:3465A77066FE7936A42E1FDC44A0F3EB
SHA256:AF525AF6FA5025219B3BFC10E8175FEB202D57821BC033EBAC9E3BD9FF44FDF0
3576WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3576.46739\Steam Checkers\Steam Checker by X-SLAYER\SkinSoft.VisualStyler.dllexecutable
MD5:2D84A619D4BD339F860CB48AF0C9B6C8
SHA256:365FFDE7DF914840EB21C96F34C39912A4B031E3814B8E902B67ACEE6DFF65A1
3576WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3576.46739\Steam Checkers\Steam Checker by X-SLAYER\xNet.dllexecutable
MD5:3DF8D87A482EFAD957D83819ADB3020F
SHA256:2AC175B4D44245EE8E7AEE9CC36DF86925EF903D8516F20A2C51D84E35F23DA4
2936Steam Accounts Checker By X-SLAYER.exeC:\Users\admin\AppData\Local\SkinSoft\VisualStyler\2.3.5.0\x86\ssapihook.dllexecutable
MD5:D7F644C06B4CDE60651D02AED6B4174D
SHA256:A99EA2F5759B34859B484AFA3A58CE82A7F3BF792886A6C838DB852D517D9C0D
3576WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3576.46739\Steam Checkers\Steam API Cracker Coded by MR.ViPER - v3.0.exeexecutable
MD5:428B193B299ABF00FFB17A13E3485CA3
SHA256:07A95C611EECA43F18C36211BA9A710D5DBB59F4339ED1FAAC1523F31107A092
3576WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3576.46739\STORM\BouncyCastle.Crypto.dllexecutable
MD5:3CF6BF0E0A27F3665EDD6362D137E4CC
SHA256:1985B85BB44BE6C6EAF35E02EF11E23A890E809B8EC2E53210A4AD5A85B26C70
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
1
DNS requests
1
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3792
STORM.exe
104.18.36.172:443
stormapp.org
Cloudflare Inc
US
shared

DNS requests

Domain
IP
Reputation
stormapp.org
  • 104.18.36.172
  • 104.18.37.172
suspicious

Threats

No threats detected
No debug info