File name:

BLTools_v3.0.0-PRO.zip

Full analysis: https://app.any.run/tasks/750f90a9-89e5-424a-b36b-725ff69294e1
Verdict: Malicious activity
Analysis date: May 29, 2025, 02:58:47
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v1.0 to extract, compression method=store
MD5:

2AB0784F2E1439FF981AD87FAB9780D9

SHA1:

C2D5CF5F9BB06FB756F177E60D565B5964273254

SHA256:

EC198E97898541815E928CA79C5C67FD7F1FE3D4BBDD825BA74A0E151DF7EE7B

SSDEEP:

98304:VNrAEs0QL79/HiEgRktsLs9uLASpvdR/7XadygotYcRxYFX8zjpg/Y+HTs1iaTjD:ac0K/qoKH0w8GyeyYTgw2

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • BLTools-v3.0.exe (PID: 6592)
      • BLTools-v3.0.exe (PID: 6872)
      • BLTools-v3.0.exe (PID: 1180)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • BLTools-v3.0.exe (PID: 1180)
    • Process drops legitimate windows executable

      • WinRAR.exe (PID: 6700)
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 6700)
    • Checks supported languages

      • BLTools-v3.0.exe (PID: 6592)
      • BLTools-v3.0.exe (PID: 1180)
    • Manual execution by a user

      • BLTools-v3.0.exe (PID: 6872)
      • BLTools-v3.0.exe (PID: 1180)
      • BLTools-v3.0.exe (PID: 6592)
    • Create files in a temporary directory

      • BLTools-v3.0.exe (PID: 6592)
      • BLTools-v3.0.exe (PID: 1180)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 10
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2025:05:28 19:35:56
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: BLTools_v3.0.0-PRO/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
135
Monitored processes
6
Malicious processes
0
Suspicious processes
3

Behavior graph

Click at the process to see the details
start winrar.exe rundll32.exe no specs bltools-v3.0.exe no specs bltools-v3.0.exe bltools-v3.0.exe slui.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1180"C:\Users\admin\Desktop\BLTools_v3.0.0-PRO\BLTools-v3.0.exe" C:\Users\admin\Desktop\BLTools_v3.0.0-PRO\BLTools-v3.0.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Description:
BLTools Cookies Checker
Exit code:
1
Version:
3.0.0.0
Modules
Images
c:\users\admin\desktop\bltools_v3.0.0-pro\bltools-v3.0.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2096C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -EmbeddingC:\Windows\System32\rundll32.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shcore.dll
c:\windows\system32\imagehlp.dll
5228C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
6592"C:\Users\admin\Desktop\BLTools_v3.0.0-PRO\BLTools-v3.0.exe" C:\Users\admin\Desktop\BLTools_v3.0.0-PRO\BLTools-v3.0.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Description:
BLTools Cookies Checker
Exit code:
1
Version:
3.0.0.0
Modules
Images
c:\users\admin\desktop\bltools_v3.0.0-pro\bltools-v3.0.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
6700"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\BLTools_v3.0.0-PRO.zipC:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
6872"C:\Users\admin\Desktop\BLTools_v3.0.0-PRO\BLTools-v3.0.exe" C:\Users\admin\Desktop\BLTools_v3.0.0-PRO\BLTools-v3.0.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
BLTools Cookies Checker
Exit code:
3221226540
Version:
3.0.0.0
Modules
Images
c:\users\admin\desktop\bltools_v3.0.0-pro\bltools-v3.0.exe
c:\windows\system32\ntdll.dll
Total events
1 823
Read events
1 804
Write events
19
Delete events
0

Modification events

(PID) Process:(6700) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(6700) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(6700) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(6700) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\BLTools_v3.0.0-PRO.zip
(PID) Process:(6700) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(6700) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(6700) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(6700) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(6700) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface
Operation:writeName:ShowPassword
Value:
0
(PID) Process:(6700) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF800000063000000B80400004C020000
Executable files
8
Suspicious files
0
Text files
29
Unknown types
0

Dropped files

PID
Process
Filename
Type
6700WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb6700.35789\BLTools_v3.0.0-PRO\License.dlltext
MD5:D76BF73F3D3768A4589E72A7B2B83088
SHA256:EAAB53F4B23C3CC9E3C9D4D5D4689438146519E69C7063F4F15B0A43DD861F7B
6700WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb6700.35789\BLTools_v3.0.0-PRO\Extreme.Net.dllexecutable
MD5:F79F0E3A0361CAC000E2D3553753CD68
SHA256:8A6518AB7419FBEC3AC9875BAA3AFB410AD1398C7AA622A09CD9084EC6CADFCD
6700WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb6700.35789\BLTools_v3.0.0-PRO\AlphaFS.dllexecutable
MD5:F2F6F6798D306D6D7DF4267434B5C5F9
SHA256:837F2CEAB6BBD9BC4BF076F1CB90B3158191888C3055DD2B78A1E23F1C3AAFDD
6700WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb6700.35789\BLTools_v3.0.0-PRO\MaterialDesignThemes.Wpf.dllexecutable
MD5:824CBF63999F954AA1747F79586A4D3C
SHA256:344E2CEE979E979932F504DC76BD75E97AE1FF46CAA3FE2795ADFE0A866347F7
6700WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb6700.35789\BLTools_v3.0.0-PRO\Projects\2dehands.be.projtext
MD5:C83ECFBF6D3A250D9D928DF23D069E0C
SHA256:8F63F6C77EED61B0698665F1FCA117B77C7807384310E50C29194D2A3D822689
6700WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb6700.35789\BLTools_v3.0.0-PRO\Projects\carousell_MY.projtext
MD5:A7DC8AAB3EFB58C1A60353B56CE70C1E
SHA256:8DD192EAC540FB29B60327B3A911CF27C13E846924B2BD83D7D2534DCEC69E8B
6700WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb6700.35789\BLTools_v3.0.0-PRO\Projects\Ebay.projtext
MD5:A57E89250A50C010B2B6EDD2EFD0B39F
SHA256:51314174405FE1D723621C67C12C03550426F07A83DDCAB9E36E6D992498D899
6700WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb6700.35789\BLTools_v3.0.0-PRO\Microsoft.Xaml.Behaviors.dllexecutable
MD5:95F46F34C099421D917D5FEADBB33EDB
SHA256:8E77A1DD5E2DF4D4AF801376CC3428B082EB49FCB6E647B933967FAE12AD9D5D
6700WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb6700.35789\BLTools_v3.0.0-PRO\Ookii.Dialogs.Wpf.dllexecutable
MD5:932EBB3F9E7113071C6A17818342B7CC
SHA256:285AA8225732DDBCF211B1158BD6CFF8BF3ACBEEAB69617F4BE85862B7105AB5
6700WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb6700.35789\BLTools_v3.0.0-PRO\Projects\carousell_SG.projtext
MD5:C9E038B00F09D559AE137ADAFFD1BA91
SHA256:EBB25FBF252E0769D66447F885B2B047DFFCD3EEFD715300E5978F1BA13B4F17
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
20
DNS requests
15
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5496
MoUsoCoreWorker.exe
GET
200
2.16.241.12:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6544
svchost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
4120
SIHClient.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
4120
SIHClient.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
2104
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5496
MoUsoCoreWorker.exe
2.16.241.12:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
5496
MoUsoCoreWorker.exe
2.23.246.101:80
www.microsoft.com
Ooredoo Q.S.C.
QA
whitelisted
4
System
192.168.100.255:138
whitelisted
2112
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3216
svchost.exe
172.211.123.249:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
6544
svchost.exe
20.190.160.64:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6544
svchost.exe
2.23.77.188:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 51.104.136.2
whitelisted
google.com
  • 142.250.185.174
whitelisted
crl.microsoft.com
  • 2.16.241.12
  • 2.16.241.19
whitelisted
www.microsoft.com
  • 2.23.246.101
whitelisted
client.wns.windows.com
  • 172.211.123.249
whitelisted
login.live.com
  • 20.190.160.64
  • 20.190.160.22
  • 20.190.160.66
  • 20.190.160.132
  • 40.126.32.76
  • 20.190.160.65
  • 20.190.160.67
  • 20.190.160.130
whitelisted
ocsp.digicert.com
  • 2.23.77.188
whitelisted
slscr.update.microsoft.com
  • 4.245.163.56
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 13.85.23.206
whitelisted
activation-v2.sls.microsoft.com
  • 40.91.76.224
whitelisted

Threats

No threats detected
No debug info