File name:

3_checker.rar

Full analysis: https://app.any.run/tasks/108771c2-94fc-4985-9199-6d69c5835b83
Verdict: Malicious activity
Analysis date: August 17, 2019, 17:20:32
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

2EF97EED1401E644051608150FB0E5CE

SHA1:

9BCED3BD807CA99361E9EBA10BD773FCE17D1ADD

SHA256:

DCA6C6A46FBDC7EAB9C8E49D97E4F78067A850CA896D7F3320FD197642EF7485

SSDEEP:

49152:ivUSLEiT5wp7vbQRZmsFFZ2T8maP7w07p3mywN6/75z65ZY9qxl4MERcujHpd:OrLb+p7vbQnmsvAT8380l3/m60jY9olG

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • SearchProtocolHost.exe (PID: 1456)
      • Steam Accounts Checker By X-SLAYER.exe (PID: 2936)
    • Application was dropped or rewritten from another process

      • Steam Accounts Checker By X-SLAYER.exe (PID: 2936)
      • Steam API Cracker Coded by MR.ViPER - v3.0.exe (PID: 460)
      • STORM.exe (PID: 3792)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3576)
      • Steam Accounts Checker By X-SLAYER.exe (PID: 2936)
    • Reads internet explorer settings

      • Steam Accounts Checker By X-SLAYER.exe (PID: 2936)
  • INFO

    • Manual execution by user

      • Steam API Cracker Coded by MR.ViPER - v3.0.exe (PID: 460)
      • Steam Accounts Checker By X-SLAYER.exe (PID: 2936)
      • STORM.exe (PID: 3792)
    • Reads settings of System Certificates

      • STORM.exe (PID: 3792)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
40
Monitored processes
5
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe steam api cracker coded by mr.viper - v3.0.exe no specs searchprotocolhost.exe no specs steam accounts checker by x-slayer.exe storm.exe

Process information

PID
CMD
Path
Indicators
Parent process
460"C:\Users\admin\Desktop\Steam Checkers\Steam API Cracker Coded by MR.ViPER - v3.0.exe" C:\Users\admin\Desktop\Steam Checkers\Steam API Cracker Coded by MR.ViPER - v3.0.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Steam API Cracker
Exit code:
0
Version:
3.0
Modules
Images
c:\users\admin\desktop\steam checkers\steam api cracker coded by mr.viper - v3.0.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1456"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe2_ Global\UsGthrCtrlFltPipeMssGthrPipe2 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" C:\Windows\System32\SearchProtocolHost.exeSearchIndexer.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Windows Search Protocol Host
Exit code:
0
Version:
7.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\searchprotocolhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2936"C:\Users\admin\Desktop\Steam Checkers\Steam Checker by X-SLAYER\Steam Accounts Checker By X-SLAYER.exe" C:\Users\admin\Desktop\Steam Checkers\Steam Checker by X-SLAYER\Steam Accounts Checker By X-SLAYER.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Checker By X-SLAYER
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\steam checkers\steam checker by x-slayer\steam accounts checker by x-slayer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3576"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\3_checker.rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3792"C:\Users\admin\Desktop\STORM\STORM.exe" C:\Users\admin\Desktop\STORM\STORM.exe
explorer.exe
User:
admin
Company:
Cracking.org
Integrity Level:
MEDIUM
Description:
STORM
Exit code:
1
Version:
1.3
Modules
Images
c:\users\admin\desktop\storm\storm.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
Total events
844
Read events
809
Write events
35
Delete events
0

Modification events

(PID) Process:(3576) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3576) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3576) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\72\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3576) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\3_checker.rar
(PID) Process:(3576) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3576) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3576) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3576) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(1456) SearchProtocolHost.exeKey:HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\72\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1456) SearchProtocolHost.exeKey:HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\72\52C64B7E
Operation:writeName:@C:\Windows\system32\notepad.exe,-469
Value:
Text Document
Executable files
7
Suspicious files
0
Text files
3
Unknown types
0

Dropped files

PID
Process
Filename
Type
3576WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3576.46739\STORM\CHANGELOGtext
MD5:
SHA256:
3576WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3576.46739\STORM\BouncyCastle.Crypto.dllexecutable
MD5:3CF6BF0E0A27F3665EDD6362D137E4CC
SHA256:1985B85BB44BE6C6EAF35E02EF11E23A890E809B8EC2E53210A4AD5A85B26C70
3576WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3576.46739\Steam Checkers\Steam Checker by X-SLAYER\Steam Accounts Checker By X-SLAYER.exeexecutable
MD5:559D0FADA4454A2D16A4109DC49BE8E0
SHA256:C4FB143C793502192F663E4AB8670B7A672B62B8B6BABB942AF04AD8825E793D
3576WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3576.46739\STORM\FUCNTIONS DOCUMENTATION.txttext
MD5:
SHA256:
3576WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3576.46739\STORM\readme.txttext
MD5:
SHA256:
3576WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3576.46739\STORM\STORM.exeexecutable
MD5:
SHA256:
3576WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3576.46739\Steam Checkers\Steam Checker by X-SLAYER\SkinSoft.VisualStyler.dllexecutable
MD5:2D84A619D4BD339F860CB48AF0C9B6C8
SHA256:365FFDE7DF914840EB21C96F34C39912A4B031E3814B8E902B67ACEE6DFF65A1
3576WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3576.46739\Steam Checkers\Steam API Cracker Coded by MR.ViPER - v3.0.exeexecutable
MD5:428B193B299ABF00FFB17A13E3485CA3
SHA256:07A95C611EECA43F18C36211BA9A710D5DBB59F4339ED1FAAC1523F31107A092
2936Steam Accounts Checker By X-SLAYER.exeC:\Users\admin\AppData\Local\SkinSoft\VisualStyler\2.3.5.0\x86\ssapihook.dllexecutable
MD5:D7F644C06B4CDE60651D02AED6B4174D
SHA256:A99EA2F5759B34859B484AFA3A58CE82A7F3BF792886A6C838DB852D517D9C0D
3576WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3576.46739\Steam Checkers\Steam Checker by X-SLAYER\xNet.dllexecutable
MD5:3DF8D87A482EFAD957D83819ADB3020F
SHA256:2AC175B4D44245EE8E7AEE9CC36DF86925EF903D8516F20A2C51D84E35F23DA4
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
1
DNS requests
1
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3792
STORM.exe
104.18.36.172:443
stormapp.org
Cloudflare Inc
US
shared

DNS requests

Domain
IP
Reputation
stormapp.org
  • 104.18.36.172
  • 104.18.37.172
suspicious

Threats

No threats detected
No debug info