| File name: | Checkers.rar |
| Full analysis: | https://app.any.run/tasks/8f02d882-7944-4b9c-895c-9ace691c597a |
| Verdict: | Malicious activity |
| Analysis date: | October 09, 2021, 15:41:18 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-rar |
| File info: | RAR archive data, v5 |
| MD5: | 7A8E9CFF74574709F9FA16432F1832A5 |
| SHA1: | FFD34CB40DE121397DCFCB4E71AEE0C263D7E588 |
| SHA256: | DF48465FB0CC79DF0227AC10E0B5E6B75173E1E62F310414B4AED65DEFED6DA6 |
| SSDEEP: | 49152:w/gjwC2lvyEU8hl5vedhTmMqU9WYpadzhWs1rMCDNas:KRyEU0veKR0WxhKCxj |
| .rar | | | RAR compressed archive (v5.0) (61.5) |
|---|---|---|
| .rar | | | RAR compressed archive (gen) (38.4) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 312 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -StartupEvent 328 -InterruptEvent 0 -NGENProcess 318 -Pipe 320 -Comment "NGen Worker Process" | C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe | — | ngen.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: .NET Runtime Optimization Service Exit code: 0 Version: 4.7.3062.0 built by: NET472REL1 Modules
| |||||||||||||||
| 600 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -StartupEvent 1b4 -InterruptEvent 0 -NGENProcess 264 -Pipe 288 -Comment "NGen Worker Process" | C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe | — | ngen.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: .NET Runtime Optimization Service Exit code: 0 Version: 4.7.3062.0 built by: NET472REL1 Modules
| |||||||||||||||
| 732 | SetupUtility.exe /aupause | C:\4e5b88f2390ad4d8b2f4a42775a944\SetupUtility.exe | — | Setup.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft .NET Framework 4.5 Setup Exit code: 0 Version: 14.7.3081.0 built by: NET472REL1 Modules
| |||||||||||||||
| 772 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -StartupEvent 240 -InterruptEvent 0 -NGENProcess 244 -Pipe 270 -Comment "NGen Worker Process" | C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe | ngen.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: .NET Runtime Optimization Service Exit code: 0 Version: 4.7.3062.0 built by: NET472REL1 Modules
| |||||||||||||||
| 772 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -StartupEvent 35c -InterruptEvent 0 -NGENProcess 344 -Pipe 3a4 -Comment "NGen Worker Process" | C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe | ngen.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: .NET Runtime Optimization Service Exit code: 0 Version: 4.7.3062.0 built by: NET472REL1 Modules
| |||||||||||||||
| 784 | C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted | C:\Windows\System32\svchost.exe | — | services.exe | |||||||||||
User: LOCAL SERVICE Company: Microsoft Corporation Integrity Level: SYSTEM Description: Host Process for Windows Services Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 796 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -StartupEvent 300 -InterruptEvent 0 -NGENProcess 2b0 -Pipe 310 -Comment "NGen Worker Process" | C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe | — | ngen.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: .NET Runtime Optimization Service Exit code: 0 Version: 4.7.3062.0 built by: NET472REL1 Modules
| |||||||||||||||
| 844 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -StartupEvent 214 -InterruptEvent 0 -NGENProcess 20c -Pipe 208 -Comment "NGen Worker Process" | C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe | — | ngen.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: .NET Runtime Optimization Service Exit code: 0 Version: 4.7.3062.0 built by: NET472REL1 Modules
| |||||||||||||||
| 876 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -StartupEvent 35c -InterruptEvent 0 -NGENProcess 348 -Pipe 3bc -Comment "NGen Worker Process" | C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe | — | ngen.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: .NET Runtime Optimization Service Exit code: 0 Version: 4.7.3062.0 built by: NET472REL1 | |||||||||||||||
| 928 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -StartupEvent 1f4 -InterruptEvent 0 -NGENProcess 1ec -Pipe 1e8 -Comment "NGen Worker Process" | C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe | — | ngen.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: .NET Runtime Optimization Service Exit code: 0 Version: 4.7.3062.0 built by: NET472REL1 Modules
| |||||||||||||||
| (PID) Process: | (1628) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (1628) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (1628) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\171\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (1628) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\Checkers.rar | |||
| (PID) Process: | (1628) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (1628) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (1628) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (1628) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (3052) SearchProtocolHost.exe | Key: | HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\171\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3052) SearchProtocolHost.exe | Key: | HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\171\52C64B7E |
| Operation: | write | Name: | @C:\Windows\System32\msxml3r.dll,-1 |
Value: XML Document | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1628 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa1628.25816\Fansly Checker By PJ v1.1.exe\Latest Checker Design.exe | executable | |
MD5:— | SHA256:— | |||
| 1628 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa1628.25816\Fansly Checker By PJ v1.1.exe\Latest Checker Design.pdb | pdb | |
MD5:— | SHA256:— | |||
| 1628 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa1628.25816\Fansly Checker By PJ v1.1.exe\Latest Checker Design.xml | xml | |
MD5:— | SHA256:— | |||
| 1628 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa1628.25816\Fansly Checker By PJ v1.1.exe\Guna.UI2.dll | executable | |
MD5:ACA7F1CA2525160B85404E638732BD87 | SHA256:BF7FD5EFCD54D00BFDA76187CB3F04DD36BB38D9B36B505E1493CFFB7A7F3D9E | |||
| 2368 | ndp472-kb4054531-web.exe | C:\4e5b88f2390ad4d8b2f4a42775a944\Graphics\Rotate10.ico | image | |
MD5:0CCA04A3468575FDCEFEE9957E32F904 | SHA256:B94E68C711B3B06D9A63C80AD013C7C7BBDB5F8E82CBC866B246FF22D99B03FE | |||
| 1628 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa1628.25816\Fansly Checker By PJ v1.1.exe\Latest Checker Design.exe.config | xml | |
MD5:E44B6F93C65C87159D701EE8821227EE | SHA256:543CB9FD5AD09E2F9148E6FFEAE10C58C73A6C640469AD9ED9475E586F8A2B52 | |||
| 1628 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa1628.25816\Fansly Checker By PJ v1.1.exe\Leaf.xNet.dll | executable | |
MD5:EA87F37E78FB9AF4BF805F6E958F68F4 | SHA256:DE9AEA105F31F3541CBC5C460B0160D0689A2872D80748CA1456E6E223F0A4AA | |||
| 1628 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa1628.25816\ndp472-kb4054531-web.exe | executable | |
MD5:B3844D880D71DE6D787190D2E378101B | SHA256:151B1C11F625E7122D517B6A1778841DF8FF168D931C41730F59B9E4B8BCBE36 | |||
| 2368 | ndp472-kb4054531-web.exe | C:\4e5b88f2390ad4d8b2f4a42775a944\Graphics\Rotate7.ico | image | |
MD5:B4947D242AB4A902031FCD1FFD3A56CD | SHA256:995C9F4EA0D98C0C4E5037EDE43FC44A680D85CB1E37C782ADAB775915E975B8 | |||
| 2368 | ndp472-kb4054531-web.exe | C:\4e5b88f2390ad4d8b2f4a42775a944\header.bmp | image | |
MD5:41C22EFA84CA74F0CE7076EB9A482E38 | SHA256:255025A0D79EF2DAC04BD610363F966EF58328400BF31E1F8915E676478CD750 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | HEAD | 302 | 104.89.38.104:80 | http://go.microsoft.com/fwlink/?prd=11324&pver=netfx&sbp=Net472Rel1&plcid=0x409&clcid=0x409&ar=03062.00&sar=amd64&o1=netfx_Full_x86.msi | NL | — | — | whitelisted |
— | — | GET | 302 | 104.89.38.104:80 | http://go.microsoft.com/fwlink/?prd=11324&pver=netfx&sbp=Net472Rel1&plcid=0x409&clcid=0x409&ar=03062.00&sar=amd64&o1=netfx_Full_x86.msi | NL | — | — | whitelisted |
3552 | Setup.exe | GET | 200 | 2.21.143.74:80 | http://www.microsoft.com/pkiops/crl/MicCodSigPCA2011_2011-07-08.crl | unknown | der | 1.05 Kb | whitelisted |
— | — | GET | 302 | 104.89.38.104:80 | http://go.microsoft.com/fwlink/?prd=11324&pver=netfx&sbp=Net472Rel1&plcid=0x409&clcid=0x409&ar=03081.00&sar=amd64&o1=netfx_Patch_x86.msp | NL | — | — | whitelisted |
— | — | HEAD | 302 | 104.89.38.104:80 | http://go.microsoft.com/fwlink/?LinkId=328846&clcid=0x409 | NL | — | — | whitelisted |
— | — | GET | 302 | 104.89.38.104:80 | http://go.microsoft.com/fwlink/?LinkId=328846&clcid=0x409 | NL | — | — | whitelisted |
— | — | GET | 302 | 104.89.38.104:80 | http://go.microsoft.com/fwlink/?prd=11324&pver=netfx&sbp=Net472Rel1&plcid=0x409&clcid=0x409&ar=03062.00&sar=x86&o1=netfx_Full.mzz | NL | — | — | whitelisted |
3552 | Setup.exe | GET | 200 | 92.123.194.162:80 | http://crl.microsoft.com/pki/crl/products/MicTimStaPCA_2010-07-01.crl | unknown | der | 555 b | whitelisted |
— | — | HEAD | 302 | 104.89.38.104:80 | http://go.microsoft.com/fwlink/?prd=11324&pver=netfx&sbp=Net472Rel1&plcid=0x409&clcid=0x409&ar=03081.00&sar=amd64&o1=netfx_Patch_x86.msp | NL | — | — | whitelisted |
3552 | Setup.exe | GET | 200 | 92.123.194.162:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut_2010-06-23.crl | unknown | der | 824 b | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
3552 | Setup.exe | 209.197.3.8:80 | ctldl.windowsupdate.com | Highwinds Network Group, Inc. | US | whitelisted |
— | — | 68.232.34.200:443 | download.visualstudio.microsoft.com | MCI Communications Services, Inc. d/b/a Verizon Business | US | whitelisted |
— | — | 2.21.140.235:443 | download.microsoft.com | Telia Company AB | — | malicious |
— | — | 104.89.38.104:80 | go.microsoft.com | Akamai Technologies, Inc. | NL | malicious |
3552 | Setup.exe | 2.21.143.74:80 | www.microsoft.com | Telia Company AB | — | malicious |
3552 | Setup.exe | 92.123.194.162:80 | crl.microsoft.com | Akamai International B.V. | — | whitelisted |
Domain | IP | Reputation |
|---|---|---|
ctldl.windowsupdate.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
go.microsoft.com |
| whitelisted |
download.microsoft.com |
| whitelisted |
download.visualstudio.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |