analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

VyprVPN Checker by xRisky.7z

Full analysis: https://app.any.run/tasks/2280758f-5f90-48e0-a4fa-b9649e87fd2f
Verdict: Malicious activity
Analysis date: February 10, 2019, 18:29:54
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-7z-compressed
File info: 7-zip archive data, version 0.4
MD5:

0AAA661FBB5966DA2D79B735E2BCB0DE

SHA1:

75F682E5389F8A2233239B153C8F8E790AC8E6DD

SHA256:

DE540068D1CEF53D0A21E8AB67341A5C97BEFF91B202713DB3321150CF72EA2E

SSDEEP:

49152:0EMFgBulqA5tnKB0c8FERUGbTU8tdE0KBYq0t:0EP8BtnKVVmUTU800KYq0t

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • VyprVPN Checker by xRisky.exe (PID: 1712)
      • VyprVPN Checker by xRisky.exe (PID: 2856)
    • Loads dropped or rewritten executable

      • VyprVPN Checker by xRisky.exe (PID: 2856)
      • VyprVPN Checker by xRisky.exe (PID: 1712)
      • explorer.exe (PID: 116)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3608)
    • Creates files in the user directory

      • explorer.exe (PID: 116)
    • Reads Internet Cache Settings

      • explorer.exe (PID: 116)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.7z | 7-Zip compressed archive (v0.4) (57.1)
.7z | 7-Zip compressed archive (gen) (42.8)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
41
Monitored processes
4
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe vyprvpn checker by xrisky.exe no specs vyprvpn checker by xrisky.exe explorer.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
3608"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\VyprVPN Checker by xRisky.7z"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
2856"C:\Users\admin\Desktop\VyprVPN Checker by xRisky\VyprVPN Checker by xRisky.exe" C:\Users\admin\Desktop\VyprVPN Checker by xRisky\VyprVPN Checker by xRisky.exeexplorer.exe
User:
admin
Company:
xRisky
Integrity Level:
MEDIUM
Description:
VyprVPN Checker by xRisky
Exit code:
4294967295
Version:
1.0.0.0
1712"C:\Users\admin\Desktop\VyprVPN Checker by xRisky\VyprVPN Checker by xRisky.exe" C:\Users\admin\Desktop\VyprVPN Checker by xRisky\VyprVPN Checker by xRisky.exe
explorer.exe
User:
admin
Company:
xRisky
Integrity Level:
HIGH
Description:
VyprVPN Checker by xRisky
Exit code:
4294967295
Version:
1.0.0.0
116C:\Windows\Explorer.EXEC:\Windows\explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Total events
4 691
Read events
4 546
Write events
0
Delete events
0

Modification events

No data
Executable files
3
Suspicious files
1
Text files
150
Unknown types
6

Dropped files

PID
Process
Filename
Type
116explorer.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\VyprVPN Checker by xRisky.7z.lnklnk
MD5:0013ED8BB5F709AF785C01792EC50637
SHA256:2CF731CC13A0820E8C2EAE23364C78ACCE4AC4F3ED63BA1905EE11004D67FFA8
3608WinRAR.exeC:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\17 януари (03;15)\Free.txttext
MD5:D456FF1295ADE432B9D844014BD44AB8
SHA256:C16D913FBB84E16CFA399FA50EC955AD9A968DF7E11B0983390F93A28258CBA8
116explorer.exeC:\Users\admin\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012019021020190211\index.datdat
MD5:6493D7203F8286BF8B129A35CF44664E
SHA256:27343E5626F3D7AFAB1AEC0A00CF0D301CD07DFE6EB8D8D9EC52E0A902B5F44C
3608WinRAR.exeC:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\17 януари (05;15)\Locked.txttext
MD5:E65FD0175F90189CD8F7D1F6F8939D58
SHA256:141C458397C93CD039F5CE4B4108A5953A66267036D314E1C4A2AD90C22B63BF
3608WinRAR.exeC:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\17 януари (03;56)\Locked.txttext
MD5:08E1CE2ABB3C374DC05A7F62D9823694
SHA256:4E528856873BB771DE4692697A671A2496F687A52F047708AD411E94AA8BCCC4
3608WinRAR.exeC:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\17 януари (02;49)\Locked.txttext
MD5:C090AE8D41678C24D5C97538D0D733A5
SHA256:490575FD0062A045682F420AE856C41E901E4227FB78CE00748FCED514B1CD55
3608WinRAR.exeC:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\17 януари (03;16)\Locked.txttext
MD5:4AAD9EA5F618A9FA02847B6A33324464
SHA256:0F12BF34A7DC5ED081AD63AAF2C018CF8BEAB06964B383FC3661AED6864A0B50
3608WinRAR.exeC:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\17 януари (03;20)\Locked.txttext
MD5:3EC67C15EEA8CC92DBE3523CFFC46FE3
SHA256:1725E2EF26652F14D3A65A15A074AFC15252B1C5EA59FF0A2D1A98CBBA26EA3E
116explorer.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\290532160612e071.automaticDestinations-msautomaticdestinations-ms
MD5:DB8C758E8C2ADDA398840846302613A5
SHA256:9DF02DD5A0B3E67F4AAEE7FE8AFE80B1CA97FDB05535EB285D3DAB776937BED1
3608WinRAR.exeC:\Users\admin\Desktop\VyprVPN Checker by xRisky\Results\17 януари (02;45)\Premium.txttext
MD5:51ACAA693020E0D343FA44FC127BCF11
SHA256:2657A86D823176FEEC93B07821697902A3B1F25A2A78B9A1C6528A1888FA48D2
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info