File name:

NordVPNCracked.rar

Full analysis: https://app.any.run/tasks/619fb59a-909b-46ad-91dc-76e08616e845
Verdict: Malicious activity
Analysis date: November 08, 2018, 09:18:49
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

F3FEC0A5117DC73B1EE72A71E3C157AA

SHA1:

743D82DB2C0D3EFCFAD5DA7BF9B6F5D442AFAF16

SHA256:

E560106A372C2C4C25B7856E290511D51EAE3975A3396BDC85D7585D1E157589

SSDEEP:

196608:dGqOaCHaeb8GYSrkUuvoEn/8h61paJie/xc9euMeYAaOGlaC:dGqOaC9bhk5/8h61paUe/xc3MeYTOGlx

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • NordVPNCracked.exe (PID: 2744)
    • Application was dropped or rewritten from another process

      • NordVPNCracked.exe (PID: 2744)
      • crypted.exe (PID: 3956)
      • CDS.exe (PID: 3452)
    • Loads dropped or rewritten executable

      • CDS.exe (PID: 3452)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • NordVPNCracked.exe (PID: 2744)
      • CDS.exe (PID: 3452)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
39
Monitored processes
4
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start drop and start drop and start winrar.exe no specs nordvpncracked.exe cds.exe crypted.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2744"C:\Users\admin\Desktop\NordVPNCracked.exe" C:\Users\admin\Desktop\NordVPNCracked.exe
explorer.exe
User:
admin
Company:
NordVPN
Integrity Level:
HIGH
Description:
NordVPNCracked
Exit code:
0
Version:
6.5.0.0
Modules
Images
c:\users\admin\desktop\nordvpncracked.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3452C:\Users\admin\AppData\Local\Temp\IXP000.TMP\CDS.exeC:\Users\admin\AppData\Local\Temp\IXP000.TMP\CDS.exe
NordVPNCracked.exe
User:
admin
Integrity Level:
HIGH
Description:
AutoPlay Application
Exit code:
3221225547
Version:
8.5.0.0
Modules
Images
c:\users\admin\appdata\local\temp\ixp000.tmp\cds.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\temp\ixp000.tmp\lua5.1.dll
c:\windows\system32\winmm.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
3832"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\NordVPNCracked.rar"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3956"C:\Users\admin\AppData\Local\Temp\IXP000.TMP\crypted.exe" C:\Users\admin\AppData\Local\Temp\IXP000.TMP\crypted.exeCDS.exe
User:
admin
Integrity Level:
HIGH
Description:
Exit code:
3735929054
Version:
0.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\ixp000.tmp\crypted.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
Total events
814
Read events
786
Write events
27
Delete events
1

Modification events

(PID) Process:(3832) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3832) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3832) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3832) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\NordVPNCracked.rar
(PID) Process:(3832) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3832) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3832) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3832) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3832) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface
Operation:writeName:ShowPassword
Value:
0
(PID) Process:(2744) NordVPNCracked.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
Operation:writeName:wextract_cleanup0
Value:
rundll32.exe C:\Windows\system32\advpack.dll,DelNodeRunDLL32 "C:\Users\admin\AppData\Local\Temp\IXP000.TMP\"
Executable files
4
Suspicious files
3
Text files
2
Unknown types
2

Dropped files

PID
Process
Filename
Type
3832WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb3832.25860\NordVPNCracked.exe
MD5:
SHA256:
2744NordVPNCracked.exeC:\Users\admin\AppData\Local\Temp\IXP000.TMP\c.dat
MD5:
SHA256:
2744NordVPNCracked.exeC:\Users\admin\AppData\Local\Temp\IXP000.TMP\CDS.cddcompressed
MD5:3E7ECAEB51C2812D13B07EC852D74AAF
SHA256:E7E942993864E8B18780EF10A415F7B93924C6378248C52F0C96895735222B96
2744NordVPNCracked.exeC:\Users\admin\AppData\Local\Temp\IXP000.TMP\630_10.pngimage
MD5:340B294EFC691D1B20C64175D565EBC7
SHA256:72566894059452101EA836BBFF9EDE5069141EEB52022AB55BAA24E1666825C9
2744NordVPNCracked.exeC:\Users\admin\AppData\Local\Temp\IXP000.TMP\ap1.datogg
MD5:93270C4FA492E4E4EDEE872A2B961DDE
SHA256:25D49CBBD65D48AD462455F1143F73EE997DF8F747E7D2213DAAB18E321C028B
2744NordVPNCracked.exeC:\Users\admin\AppData\Local\Temp\IXP000.TMP\cdd.zipcompressed
MD5:1D5698B4E2DD3435D103865E881AA2DD
SHA256:064167B67ACEBCA10B61531C2B8A6BC1539406F15002A2F56F3F8ECD29B10890
2744NordVPNCracked.exeC:\Users\admin\AppData\Local\Temp\IXP000.TMP\fs.settingstext
MD5:68934A3E9455FA72420237EB05902327
SHA256:FCBCF165908DD18A9E49F7FF27810176DB8E9F63B4352213741664245224F8AA
2744NordVPNCracked.exeC:\Users\admin\AppData\Local\Temp\IXP000.TMP\ap3.datcompressed
MD5:967FDFE0A01C083804673B4976AD6730
SHA256:72EDA9D49BCD0CD3B540F75C4215714378AFBB1CE40AFCBB7A0B246AB2A44F21
2744NordVPNCracked.exeC:\Users\admin\AppData\Local\Temp\IXP000.TMP\lua51.dllexecutable
MD5:7FA818F532EFFD80CF7C1C54676E5A0D
SHA256:1C2D1BA8425139D45DE89192D2AE4982E9581F8AE0F22B8497AA0055080237CA
2744NordVPNCracked.exeC:\Users\admin\AppData\Local\Temp\IXP000.TMP\ap2.datogg
MD5:FC2A595F574B1EAD82A6DCF06492C985
SHA256:EE9A4903A8DF90EFF4C5B65A8073E564A3581CF73772A72EB82396E69932E769
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info