File name:

infected.rar

Full analysis: https://app.any.run/tasks/7617b0c8-4fc6-4efa-a843-5188b528aa0a
Verdict: Malicious activity
Analysis date: September 17, 2019, 11:47:24
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

57924A38F3DB2E59F0CBDA644A5CA837

SHA1:

4625ACBEDEBD6A55ABD7C91DC553FF12CF91BA73

SHA256:

EEEFD6FB222770FF66B2C2DE6AA98F972C16F016B82BCF728E3B1F90DC8194FB

SSDEEP:

49152:FiyEQgwgWFcGSlNs7ffCCuhGmY0J09Bpz5QXVdlYiuyqhc7bGxIuxYHd7052MM57:kccn7sNuhGmY0J0Pp5QXVdlXAGiKgM57

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Netflix Checker by xRisky.exe (PID: 2496)
      • BlackBullet.2.0.2.0.exe (PID: 2352)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3084)
      • Netflix Checker by xRisky.exe (PID: 2496)
  • INFO

    • Manual execution by user

      • Netflix Checker by xRisky.exe (PID: 2496)
      • Checker Netflix V3.0.exe (PID: 3944)
      • BlackBullet.2.0.2.0.exe (PID: 2352)
      • Netflix Checker V0.3.exe (PID: 2224)
      • The Netflix Checker 2.0.exe (PID: 2632)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
55
Monitored processes
6
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe blackbullet.2.0.2.0.exe netflix checker v0.3.exe netflix checker by xrisky.exe checker netflix v3.0.exe the netflix checker 2.0.exe

Process information

PID
CMD
Path
Indicators
Parent process
2224"C:\Users\admin\Desktop\NETFLIX CHECKER UPDATE VERY FAST BY INTELECTO\Netflix Checker 2018 V0.3\Netflix Checker V0.3.exe" C:\Users\admin\Desktop\NETFLIX CHECKER UPDATE VERY FAST BY INTELECTO\Netflix Checker 2018 V0.3\Netflix Checker V0.3.exe
explorer.exe
User:
admin
Company:
Samad.Dz
Integrity Level:
HIGH
Description:
Netflix Checker Notificaciones
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\netflix checker update very fast by intelecto\netflix checker 2018 v0.3\netflix checker v0.3.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2352"C:\Users\admin\Desktop\NETFLIX CHECKER UPDATE VERY FAST BY INTELECTO\BlackBullet CRACKED + AUTO-CONFIGED netflix,beinsport,vpns\BlackBullet.2.0.2.0.exe" C:\Users\admin\Desktop\NETFLIX CHECKER UPDATE VERY FAST BY INTELECTO\BlackBullet CRACKED + AUTO-CONFIGED netflix,beinsport,vpns\BlackBullet.2.0.2.0.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
10
Modules
Images
c:\users\admin\desktop\netflix checker update very fast by intelecto\blackbullet cracked + auto-configed netflix,beinsport,vpns\blackbullet.2.0.2.0.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\sfc_os.dll
2496"C:\Users\admin\Desktop\NETFLIX CHECKER UPDATE VERY FAST BY INTELECTO\NetFlix Checker by xRisky\Netflix Checker by xRisky.exe" C:\Users\admin\Desktop\NETFLIX CHECKER UPDATE VERY FAST BY INTELECTO\NetFlix Checker by xRisky\Netflix Checker by xRisky.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\desktop\netflix checker update very fast by intelecto\netflix checker by xrisky\netflix checker by xrisky.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
2632"C:\Users\admin\Desktop\NETFLIX CHECKER UPDATE VERY FAST BY INTELECTO\THE NETFLIX CRACKER 2.0 BY STONERSTEVE\The Netflix Checker 2.0.exe" C:\Users\admin\Desktop\NETFLIX CHECKER UPDATE VERY FAST BY INTELECTO\THE NETFLIX CRACKER 2.0 BY STONERSTEVE\The Netflix Checker 2.0.exe
explorer.exe
User:
admin
Company:
Samad.Dz
Integrity Level:
HIGH
Description:
Netflix.com Checker 1.1
Exit code:
0
Version:
1.1.0.0
Modules
Images
c:\users\admin\desktop\netflix checker update very fast by intelecto\the netflix cracker 2.0 by stonersteve\the netflix checker 2.0.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3084"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\infected.rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3944"C:\Users\admin\Desktop\NETFLIX CHECKER UPDATE VERY FAST BY INTELECTO\NETFLIX CHECKER UPDATE VERY FAST BY INTELECTO\Checker Netflix V3.0.exe" C:\Users\admin\Desktop\NETFLIX CHECKER UPDATE VERY FAST BY INTELECTO\NETFLIX CHECKER UPDATE VERY FAST BY INTELECTO\Checker Netflix V3.0.exe
explorer.exe
User:
admin
Company:
FireCrack.net
Integrity Level:
HIGH
Description:
Checker Netflix Free Edition V3.0 By Intelecto
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\netflix checker update very fast by intelecto\netflix checker update very fast by intelecto\checker netflix v3.0.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
Total events
438
Read events
430
Write events
8
Delete events
0

Modification events

(PID) Process:(3084) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3084) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3084) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\72\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3084) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\infected.rar
(PID) Process:(3084) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3084) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3084) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3084) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
Executable files
2
Suspicious files
0
Text files
2
Unknown types
0

Dropped files

PID
Process
Filename
Type
3084WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3084.37553\NETFLIX CHECKER UPDATE VERY FAST BY INTELECTO\BlackBullet CRACKED + AUTO-CONFIGED netflix,beinsport,vpns\Resources\config\api.crunchyroll.ini
MD5:
SHA256:
3084WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3084.37553\NETFLIX CHECKER UPDATE VERY FAST BY INTELECTO\BlackBullet CRACKED + AUTO-CONFIGED netflix,beinsport,vpns\Resources\config\bein.portail.ini
MD5:
SHA256:
3084WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3084.37553\NETFLIX CHECKER UPDATE VERY FAST BY INTELECTO\BlackBullet CRACKED + AUTO-CONFIGED netflix,beinsport,vpns\Resources\config\cambly.ini
MD5:
SHA256:
3084WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3084.37553\NETFLIX CHECKER UPDATE VERY FAST BY INTELECTO\BlackBullet CRACKED + AUTO-CONFIGED netflix,beinsport,vpns\Resources\config\icflix.ini
MD5:
SHA256:
3084WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3084.37553\NETFLIX CHECKER UPDATE VERY FAST BY INTELECTO\BlackBullet CRACKED + AUTO-CONFIGED netflix,beinsport,vpns\Resources\config\iflix.ini
MD5:
SHA256:
3084WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3084.37553\NETFLIX CHECKER UPDATE VERY FAST BY INTELECTO\BlackBullet CRACKED + AUTO-CONFIGED netflix,beinsport,vpns\Resources\config\iptv.wssiptv.com.ini
MD5:
SHA256:
3084WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3084.37553\NETFLIX CHECKER UPDATE VERY FAST BY INTELECTO\BlackBullet CRACKED + AUTO-CONFIGED netflix,beinsport,vpns\Resources\config\ipvanish.ini
MD5:
SHA256:
3084WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3084.37553\NETFLIX CHECKER UPDATE VERY FAST BY INTELECTO\BlackBullet CRACKED + AUTO-CONFIGED netflix,beinsport,vpns\Resources\config\m.facebook.com.ini
MD5:
SHA256:
3084WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3084.37553\NETFLIX CHECKER UPDATE VERY FAST BY INTELECTO\BlackBullet CRACKED + AUTO-CONFIGED netflix,beinsport,vpns\Resources\config\NordVPN.ini
MD5:
SHA256:
3084WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3084.37553\NETFLIX CHECKER UPDATE VERY FAST BY INTELECTO\BlackBullet CRACKED + AUTO-CONFIGED netflix,beinsport,vpns\Resources\config\READ ME.txt
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
1
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

Domain
IP
Reputation
botnetz0285.ddns.net
unknown

Threats

No threats detected
No debug info