File name:

9.rar

Full analysis: https://app.any.run/tasks/a8a23635-5fe8-483b-80c5-39315511d822
Verdict: Malicious activity
Analysis date: July 17, 2019, 09:20:18
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

C3AB11C1BBD6EA349EBF9346FDAED09E

SHA1:

1F305EAFE3ED8C0FF4F979EB1D038DBADCCCD048

SHA256:

E6C6D0091EE3BC8396034BB0858387050CBB38109116316463CE8A245CCFBDD2

SSDEEP:

12288:T5Fi+yV9YVzmoGUdIfDZ6NsIE0H3kmZjVILThH0Q58F/KyV2EZL:THRyV9YMoGtrZaE0F8F1KtJ/J

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • PornHub Checker.exe (PID: 3092)
      • PornHub Checker.exe (PID: 2420)
      • Pornhub Crackeddd.exe (PID: 2388)
      • Chrome.exe (PID: 3496)
      • Pornhub Cracked.exe (PID: 904)
    • Loads dropped or rewritten executable

      • SearchProtocolHost.exe (PID: 2564)
    • Writes to a start menu file

      • Pornhub Cracked.exe (PID: 904)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3840)
      • PornHub Checker.exe (PID: 3092)
      • Pornhub Cracked.exe (PID: 904)
    • Creates files in the user directory

      • Pornhub Cracked.exe (PID: 904)
  • INFO

    • Dropped object may contain Bitcoin addresses

      • PornHub Checker.exe (PID: 3092)
      • Pornhub Cracked.exe (PID: 904)
    • Manual execution by user

      • PornHub Checker.exe (PID: 2420)
      • PornHub Checker.exe (PID: 3092)
    • Application was crashed

      • Pornhub Crackeddd.exe (PID: 2388)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
48
Monitored processes
7
Malicious processes
2
Suspicious processes
1

Behavior graph

Click at the process to see the details
start drop and start drop and start drop and start winrar.exe searchprotocolhost.exe no specs pornhub checker.exe no specs pornhub checker.exe pornhub cracked.exe pornhub crackeddd.exe chrome.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
904"C:\Users\admin\AppData\Local\Temp\Pornhub Cracked.exe" C:\Users\admin\AppData\Local\Temp\Pornhub Cracked.exe
PornHub Checker.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\pornhub cracked.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2388"C:\Users\admin\AppData\Local\Temp\Pornhub Crackeddd.exe" C:\Users\admin\AppData\Local\Temp\Pornhub Crackeddd.exe
PornHub Checker.exe
User:
admin
Company:
Azetej Company
Integrity Level:
HIGH
Description:
ViaGoGo Checker
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\pornhub crackeddd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
2420"C:\Users\admin\Desktop\PornHub Checker.exe" C:\Users\admin\Desktop\PornHub Checker.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\desktop\pornhub checker.exe
c:\systemroot\system32\ntdll.dll
2564"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe6_ Global\UsGthrCtrlFltPipeMssGthrPipe6 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" C:\Windows\System32\SearchProtocolHost.exeSearchIndexer.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Windows Search Protocol Host
Exit code:
0
Version:
7.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\version.dll
c:\users\admin\desktop\colorful.console.dll
c:\windows\system32\notepad.exe
c:\users\admin\desktop\pornhub checker.exe
c:\users\admin\desktop\newtonsoft.json.dll
c:\users\admin\desktop\leaf.xnet.dll
3092"C:\Users\admin\Desktop\PornHub Checker.exe" C:\Users\admin\Desktop\PornHub Checker.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\desktop\pornhub checker.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
3496"C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Chrome.exe" C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Chrome.exePornhub Cracked.exe
User:
admin
Integrity Level:
HIGH
Description:
Exit code:
0
Version:
0.0.0.0
Modules
Images
c:\users\admin\appdata\roaming\microsoft\windows\start menu\programs\startup\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
3840"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\9.rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
Total events
1 185
Read events
1 154
Write events
31
Delete events
0

Modification events

(PID) Process:(3840) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3840) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3840) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\70\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3840) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\9.rar
(PID) Process:(3840) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3840) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3840) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3840) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2564) SearchProtocolHost.exeKey:HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\70\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2564) SearchProtocolHost.exeKey:HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\70\52C64B7E
Operation:writeName:@C:\Windows\system32\notepad.exe,-469
Value:
Text Document
Executable files
7
Suspicious files
0
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
904Pornhub Cracked.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\dd.htmltext
MD5:
SHA256:
3092PornHub Checker.exeC:\Users\admin\AppData\Local\Temp\Pornhub Crackeddd.exeexecutable
MD5:
SHA256:
3840WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3840.24811\PornHub Checker.exeexecutable
MD5:
SHA256:
3092PornHub Checker.exeC:\Users\admin\AppData\Local\Temp\Pornhub Cracked.exeexecutable
MD5:
SHA256:
3840WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3840.24811\Newtonsoft.Json.dllexecutable
MD5:5AFDA7C7D4F7085E744C2E7599279DB3
SHA256:F58C374FFCAAE4E36D740D90FBF7FE70D0ABB7328CD9AF3A0A7B70803E994BA4
3840WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3840.24811\Colorful.Console.dllexecutable
MD5:5F3D2CFBC21591B8FEEF1EFA3E59A4D0
SHA256:F31D4FD7E729FC6CF4ECAB972B6B1EE897918A325B1CA572030966F831E768FB
3840WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3840.24811\Leaf.xNet.dllexecutable
MD5:43C82221E0B667D0A0DA9BF73E9951A8
SHA256:4D06AB17F6137362F254F389B071C235AABA37FC3F0C4D2E941B58517BC4E503
904Pornhub Cracked.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Chrome.exeexecutable
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info