| File name: | X1 Emv chip writer V5.rar |
| Full analysis: | https://app.any.run/tasks/476781ab-6503-4952-99c4-bc9b5211ca87 |
| Verdict: | Malicious activity |
| Threats: | njRAT is a remote access trojan. It is one of the most widely accessible RATs on the market that features an abundance of educational information. Interested attackers can even find tutorials on YouTube. This allows it to become one of the most popular RATs in the world. |
| Analysis date: | November 12, 2019, 07:39:10 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-rar |
| File info: | RAR archive data, v4, os: Win32 |
| MD5: | 6B536D3369F91BC7081D1339C1615F75 |
| SHA1: | 59644D1313ACF61E3F1BBBD5698E5E51938F966E |
| SHA256: | DCBFB408DC6A69CC5F18D0602275FE4F86C5675232BAF7736507870FA0BC9496 |
| SSDEEP: | 98304:PaAb3KAkRezbYnAnMd8a/ofNoRIFIDaHhBNf4PorRVX:PNb6LozbQz8a/o1oOCDuhBNf4PKRVX |
| .rar | | | RAR compressed archive (v-4.x) (58.3) |
|---|---|---|
| .rar | | | RAR compressed archive (gen) (41.6) |
| CompressedSize: | 4842 |
|---|---|
| UncompressedSize: | 11264 |
| OperatingSystem: | Win32 |
| ModifyDate: | 2016:07:28 17:06:13 |
| PackingMethod: | Normal |
| ArchivedFileName: | X1 Emv chip writer V5\X1v5\Bin.db |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 996 | "C:\Users\admin\AppData\Roaming\win7system.exe" | C:\Users\admin\AppData\Roaming\win7system.exe | win7system.exe | ||||||||||||
User: admin Company: ersanLander Integrity Level: HIGH Description: 5.0 Exit code: 0 Version: 5.0 Modules
| |||||||||||||||
| 1188 | "C:\Users\admin\AppData\Roaming\mscftmon\ntsvc32.exe" | C:\Users\admin\AppData\Roaming\mscftmon\ntsvc32.exe | ntsvc32.exe | ||||||||||||
User: admin Company: ersanLander Integrity Level: HIGH Description: 5.0 Exit code: 0 Version: 5.0 Modules
| |||||||||||||||
| 1328 | C:\Users\admin\AppData\Roaming/win7system.exe | C:\Users\admin\AppData\Roaming\win7system.exe | — | X1.exe | |||||||||||
User: admin Company: ersanLander Integrity Level: HIGH Description: 5.0 Exit code: 0 Version: 5.0 Modules
| |||||||||||||||
| 1704 | "C:\Users\admin\AppData\Local\Temp\SynTPHelper.exe" | C:\Users\admin\AppData\Local\Temp\SynTPHelper.exe | X1.exe | ||||||||||||
User: admin Company: Microsoft Inc Integrity Level: HIGH Description: SynTPHelper Exit code: 0 Version: 6.10.01.01 Modules
| |||||||||||||||
| 1932 | "C:\Users\admin\AppData\Local\Temp\X1.exe" | C:\Users\admin\AppData\Local\Temp\X1.exe | X1.exe | ||||||||||||
User: admin Company: aZoolander Integrity Level: HIGH Description: <X1> Exit code: 0 Version: 5.0 Modules
| |||||||||||||||
| 2660 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\X1 Emv chip writer V5.rar" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.60.0 Modules
| |||||||||||||||
| 2820 | "C:\Windows\SynTPHelper.exe" | C:\Windows\SynTPHelper.exe | SynTPHelper.exe | ||||||||||||
User: admin Company: Microsoft Inc Integrity Level: HIGH Description: SynTPHelper Exit code: 0 Version: 6.10.01.01 Modules
| |||||||||||||||
| 3060 | netsh firewall add allowedprogram "C:\Windows\SynTPHelper.exe" "SynTPHelper.exe" ENABLE | C:\Windows\system32\netsh.exe | — | SynTPHelper.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Network Command Shell Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3300 | C:\Users\admin\AppData\Local\Temp/temp.exe | C:\Users\admin\AppData\Local\Temp\temp.exe | — | X1.exe | |||||||||||
User: admin Company: <O Zoolander> Integrity Level: HIGH Description: <X1> Exit code: 0 Version: 4.1.0.1 Modules
| |||||||||||||||
| 3440 | "C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe2_ Global\UsGthrCtrlFltPipeMssGthrPipe2 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" | C:\Windows\System32\SearchProtocolHost.exe | — | SearchIndexer.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft Windows Search Protocol Host Exit code: 0 Version: 7.00.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (2660) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (2660) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (2660) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2660) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\X1 Emv chip writer V5.rar | |||
| (PID) Process: | (2660) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (2660) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (2660) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (2660) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (2660) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\DialogEditHistory\ExtrPath |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop | |||
| (PID) Process: | (3440) SearchProtocolHost.exe | Key: | HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\12B\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2660 | WinRAR.exe | C:\Users\admin\Desktop\X1 Emv chip writer V5\X1v5\X1.pdb | — | |
MD5:— | SHA256:— | |||
| 1932 | X1.exe | C:\Users\admin\AppData\Local\Temp\autF816.tmp | — | |
MD5:— | SHA256:— | |||
| 1932 | X1.exe | C:\Users\admin\AppData\Local\Temp\autF875.tmp | — | |
MD5:— | SHA256:— | |||
| 2660 | WinRAR.exe | C:\Users\admin\Desktop\X1 Emv chip writer V5\X1v5\Bin.db | sqlite | |
MD5:— | SHA256:— | |||
| 2660 | WinRAR.exe | C:\Users\admin\Desktop\X1 Emv chip writer V5\X1v5\X1.exe | executable | |
MD5:— | SHA256:— | |||
| 2660 | WinRAR.exe | C:\Users\admin\Desktop\X1 Emv chip writer V5\X1v5\cardtemp.dat | binary | |
MD5:— | SHA256:— | |||
| 2660 | WinRAR.exe | C:\Users\admin\Desktop\X1 Emv chip writer V5\X1v5\KEY.txt | text | |
MD5:— | SHA256:— | |||
| 2660 | WinRAR.exe | C:\Users\admin\Desktop\X1 Emv chip writer V5\X1v5\X1.exp | exp | |
MD5:9658F4486DF81E316B74ED4FD729AA44 | SHA256:13A2DEEDC0FC750D4221332747DAD7ACB00EA0F02AD4C0361473FB3D82043BDE | |||
| 2660 | WinRAR.exe | C:\Users\admin\Desktop\X1 Emv chip writer V5\X1v5\GPPcScConnectionPlugin.dll | executable | |
MD5:D65463FC8A37261B6BF5AFBC4139BDD5 | SHA256:789734BBAB7B606E27FAB43F4706250399108DBA98E4428D1B95589DB0A42EA2 | |||
| 1188 | ntsvc32.exe | C:\Users\admin\AppData\Roaming\mscftmon\.Identifier | binary | |
MD5:— | SHA256:— | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2820 | SynTPHelper.exe | 91.109.178.4:1991 | ccdollar.linkpc.net | Lost Oasis SARL | NL | malicious |
— | — | 125.163.67.97:3361 | local.cable-modem.org | PT Telekomunikasi Indonesia | ID | unknown |
Domain | IP | Reputation |
|---|---|---|
ccdollar.linkpc.net |
| malicious |
local.cable-modem.org |
| malicious |
PID | Process | Class | Message |
|---|---|---|---|
1080 | svchost.exe | Potentially Bad Traffic | ET POLICY DNS Query to DynDNS Domain *.cable-modem .org |