File name:

Fast RDP Brute GUI v2.0.zip

Full analysis: https://app.any.run/tasks/2d519ce2-ab53-4abe-8aeb-db43b515e6e1
Verdict: Malicious activity
Analysis date: February 12, 2019, 22:17:27
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

6BD275248AD91AE5D98B8388FBEE60C4

SHA1:

EFE46FEA325E86E36249AB337A4A4F9736116567

SHA256:

E4DBF8319AFE02A36052997DA6B638B05D88658DE03255E29D5B679304242504

SSDEEP:

49152:yjwR3cKNb8jdL6bl+BPNVe8g9lh/YYO5/MbTKP+AVt:ycR3c8b8jxlB1VJg97MpWTm+M

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Fast RDP Brute.exe (PID: 3180)
    • Loads dropped or rewritten executable

      • SearchProtocolHost.exe (PID: 1920)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3228)
    • Connects to unusual port

      • Fast RDP Brute.exe (PID: 3180)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2012:10:19 11:42:00
ZipCRC: 0x8c16576c
ZipCompressedSize: 302
ZipUncompressedSize: 1130
ZipFileName: pass.txt
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
32
Monitored processes
3
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe searchprotocolhost.exe no specs fast rdp brute.exe

Process information

PID
CMD
Path
Indicators
Parent process
1920"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe6_ Global\UsGthrCtrlFltPipeMssGthrPipe6 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" C:\Windows\System32\SearchProtocolHost.exeSearchIndexer.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Windows Search Protocol Host
Exit code:
0
Version:
7.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\searchprotocolhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3180"C:\Users\admin\Desktop\Fast RDP Brute.exe" C:\Users\admin\Desktop\Fast RDP Brute.exe
explorer.exe
User:
admin
Company:
Stas'M Corp.
Integrity Level:
MEDIUM
Description:
Fast RDP Brute GUI v2.0 by Stas'M
Exit code:
0
Version:
2.0.0.0
Modules
Images
c:\users\admin\desktop\fast rdp brute.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
3228"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Fast RDP Brute GUI v2.0.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
Total events
454
Read events
430
Write events
24
Delete events
0

Modification events

(PID) Process:(3228) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3228) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3228) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3228) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Fast RDP Brute GUI v2.0.zip
(PID) Process:(3228) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3228) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3228) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3228) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3228) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\DialogEditHistory\ExtrPath
Operation:writeName:0
Value:
C:\Users\admin\Desktop
(PID) Process:(1920) SearchProtocolHost.exeKey:HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\5F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
Executable files
6
Suspicious files
0
Text files
4
Unknown types
0

Dropped files

PID
Process
Filename
Type
3180Fast RDP Brute.exeC:\Users\admin\Desktop\ranges.txttext
MD5:
SHA256:
3228WinRAR.exeC:\Users\admin\Desktop\Fast RDP Brute.exeexecutable
MD5:
SHA256:
3228WinRAR.exeC:\Users\admin\Desktop\user.txttext
MD5:
SHA256:
3228WinRAR.exeC:\Users\admin\Desktop\rdpthread.exeexecutable
MD5:08460B6F9D3FF0F8FF5D892E4E7854A5
SHA256:4C47A02335BA89B9AE3C15C2BBCEFAEF78E282CCEF88257FA9FB4260D6DA5637
3180Fast RDP Brute.exeC:\Users\admin\Desktop\ports.txttext
MD5:
SHA256:
3228WinRAR.exeC:\Users\admin\Desktop\ssleay32.dllexecutable
MD5:6C06FB9E1D818FDE8D142EE180A65646
SHA256:F07CE36B11699B2FAA37E2604A49D33DB7528262E8BB782A96E7CB2A3E18AA1C
3228WinRAR.exeC:\Users\admin\Desktop\msvcr70.dllexecutable
MD5:2BC64FFE088A76CBAE3C19A9787E391A
SHA256:90BA388A08475BEA3E2FEBB51C3F17CED0CCDA3C9BA3E7B1831DB046CF38BC37
3228WinRAR.exeC:\Users\admin\Desktop\pass.txttext
MD5:75B1E498B766DC1F6351C05CA83ECA8A
SHA256:8A5F92786F52EEE0FC78BEFE23DCDCB48B6DF42586CBC5C495DFBD1D97DBD858
3228WinRAR.exeC:\Users\admin\Desktop\msvcr71.dllexecutable
MD5:CA2F560921B7B8BE1CF555A5A18D54C3
SHA256:C4D4339DF314A27FF75A38967B7569D9962337B8D4CD4B0DB3ABA5FF72B2BFBB
3228WinRAR.exeC:\Users\admin\Desktop\libeay32.dllexecutable
MD5:CDBDEF73515997355E81A99421C1D721
SHA256:EEFCF44CC4252AC145B2AC34D770E4EA69B5B0309BF722669B13A1E0F877560F
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
1 321
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3180
Fast RDP Brute.exe
172.16.0.1:3389
unknown
3180
Fast RDP Brute.exe
172.16.0.1:3390
unknown
3180
Fast RDP Brute.exe
172.16.0.1:3391
unknown
3180
Fast RDP Brute.exe
172.16.0.2:3389
unknown
3180
Fast RDP Brute.exe
172.16.0.2:3390
unknown
3180
Fast RDP Brute.exe
172.16.0.2:3391
unknown
3180
Fast RDP Brute.exe
172.16.0.3:3389
unknown
3180
Fast RDP Brute.exe
172.16.0.3:3390
unknown
3180
Fast RDP Brute.exe
172.16.0.3:3391
unknown
3180
Fast RDP Brute.exe
172.16.0.4:3389
unknown

DNS requests

No data

Threats

No threats detected
No debug info