| File name: | SoldierCards NEW.rar |
| Full analysis: | https://app.any.run/tasks/3473cc83-0138-4e4e-9b81-efb9d796f025 |
| Verdict: | Malicious activity |
| Threats: | Netwire is an advanced RAT — it is a malware that takes control of infected PCs and allows its operators to perform various actions. Unlike many RATs, this one can target every major operating system, including Windows, Linux, and MacOS. |
| Analysis date: | December 15, 2018, 10:32:06 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-rar |
| File info: | RAR archive data, v4, os: Win32 |
| MD5: | EA124110EC1CA5EF9856C69C2BCFE2CC |
| SHA1: | 5369F34AB536733EE74C8C4C7EA1E315D82B2245 |
| SHA256: | E05C3B47A45BEDFC3391E52013E03FA23D36320384320CA5BC9628342F6DBBCD |
| SSDEEP: | 6144:dJmbqti8vEVxpXNKFIJTknnn1WU4j3wOTimklfPxLpEoubRXw+IX7DXyTO4SZKqt:dYbhAeNkFT1W3TwxLpEou1g+YbyTO4gt |
| .rar | | | RAR compressed archive (v-4.x) (58.3) |
|---|---|---|
| .rar | | | RAR compressed archive (gen) (41.6) |
| CompressedSize: | 342086 |
|---|---|
| UncompressedSize: | 859648 |
| OperatingSystem: | Win32 |
| ModifyDate: | 2018:12:15 11:57:14 |
| PackingMethod: | Normal |
| ArchivedFileName: | SoldierCards .exe |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 904 | cmd /c del "C:\Users\admin\AppData\Local\Temp\mGk2U0c0s.bat" | C:\Windows\system32\cmd.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 2116 | "C:\Users\admin\Desktop\SoldierCards .exe" | C:\Users\admin\Desktop\SoldierCards .exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 1 Version: 1.0.0.0 Modules
| |||||||||||||||
| 2292 | "C:\Users\admin\Desktop\SoldierCards .exe" | C:\Users\admin\Desktop\SoldierCards .exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 1 Version: 1.0.0.0 Modules
| |||||||||||||||
| 2420 | C:\Windows\system32\cmd.exe /c "C:\Users\admin\AppData\Local\Temp\mGk2U0c0s.bat" | C:\Windows\system32\cmd.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 2560 | "C:\Users\admin\AppData\Roaming\Microsoft\Network\svchost.exe" | C:\Users\admin\AppData\Roaming\Microsoft\Network\svchost.exe | — | sc.exe | |||||||||||
User: admin Company: New Program Integrity Level: MEDIUM Description: New Program Exit code: 1 Version: 8.3.3.6 Modules
| |||||||||||||||
| 2564 | "C:\Users\admin\AppData\Local\Temp\SoldierCards.exe" 0 | C:\Users\admin\AppData\Local\Temp\SoldierCards.exe | — | SoldierCards .exe | |||||||||||
User: admin Company: SoldierCrimes Integrity Level: HIGH Description: SoldierCards Exit code: 3221225786 Version: 1.0.0.0 Modules
| |||||||||||||||
| 2572 | "C:\Windows\explorer.exe" | C:\Windows\explorer.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Explorer Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2596 | cmd /c del "C:\Users\admin\AppData\Local\Temp\Gaa2o0uuC4.bat" | C:\Windows\system32\cmd.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 2672 | "C:\Windows\System32\NOTEPAD.EXE" C:\Users\admin\Desktop\cCuik6m8i.bat | C:\Windows\System32\NOTEPAD.EXE | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Notepad Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2692 | "C:\Users\admin\AppData\Local\Temp\sc.exe" 0 | C:\Users\admin\AppData\Local\Temp\sc.exe | — | SoldierCards .exe | |||||||||||
User: admin Company: New Program Integrity Level: MEDIUM Description: New Program Exit code: 1 Version: 8.3.3.6 Modules
| |||||||||||||||
| (PID) Process: | (3400) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (3400) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (3400) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3400) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\SoldierCards NEW.rar | |||
| (PID) Process: | (3400) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (3400) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (3400) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (3400) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (3400) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin |
| Operation: | write | Name: | Placement |
Value: 2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000 | |||
| (PID) Process: | (3400) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\General |
| Operation: | write | Name: | LastFolder |
Value: C:\Users\admin\AppData\Local\Temp | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3400 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3400.45843\SoldierCards .exe | — | |
MD5:— | SHA256:— | |||
| 3564 | SoldierCards .exe | C:\Users\admin\AppData\Local\Temp\SoldierCards.exe | executable | |
MD5:— | SHA256:— | |||
| 3148 | SoldierCards .exe | C:\Users\admin\AppData\Local\Temp\SoldierCards.exe | executable | |
MD5:— | SHA256:— | |||
| 4012 | svchost.exe | C:\Users\admin\AppData\Roaming\Microsoft\Network\Settings.ini | binary | |
MD5:— | SHA256:— | |||
| 4068 | sc.exe | C:\Users\admin\AppData\Roaming\Microsoft\Network\svchost.exe | executable | |
MD5:— | SHA256:— | |||
| 3136 | svchost.exe | C:\Users\admin\AppData\Local\Temp\Gaa2o0uuC4.bat | text | |
MD5:— | SHA256:— | |||
| 4012 | svchost.exe | C:\Users\admin\AppData\Local\Temp\mGk2U0c0s.bat | text | |
MD5:— | SHA256:— | |||
| 3564 | SoldierCards .exe | C:\Users\admin\AppData\Local\Temp\sc.exe | executable | |
MD5:— | SHA256:— | |||
| 4012 | svchost.exe | C:\Users\admin\AppData\Roaming\Microsoft\Network\Logs\15-12-2018 | binary | |
MD5:— | SHA256:— | |||
| 3148 | SoldierCards .exe | C:\Users\admin\AppData\Local\Temp\sc.exe | executable | |
MD5:— | SHA256:— | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
3136 | svchost.exe | 37.228.134.84:8999 | playhardgopro.life | Mike Kaldig | DE | suspicious |
3096 | svchost.exe | 37.228.134.84:8999 | playhardgopro.life | Mike Kaldig | DE | suspicious |
4012 | svchost.exe | 37.228.134.84:8999 | playhardgopro.life | Mike Kaldig | DE | suspicious |
Domain | IP | Reputation |
|---|---|---|
playhardgopro.life |
| malicious |
PID | Process | Class | Message |
|---|---|---|---|
4012 | svchost.exe | A Network Trojan was detected | SC SPYWARE Spyware Weecnaw Win32 |
4012 | svchost.exe | A Network Trojan was detected | MALWARE [PTsecurity] Netwire.RAT |
4012 | svchost.exe | A Network Trojan was detected | ET TROJAN Possible Netwire RAT Client HeartBeat C2 |
3136 | svchost.exe | A Network Trojan was detected | SC SPYWARE Spyware Weecnaw Win32 |
3136 | svchost.exe | A Network Trojan was detected | MALWARE [PTsecurity] Netwire.RAT |
3096 | svchost.exe | A Network Trojan was detected | SC SPYWARE Spyware Weecnaw Win32 |
3096 | svchost.exe | A Network Trojan was detected | MALWARE [PTsecurity] Netwire.RAT |