File name:

PolarisBiosEditor 1.7.2.zip

Full analysis: https://app.any.run/tasks/2639d900-ea6e-450f-929b-63b525713995
Verdict: Malicious activity
Threats:

Remote access trojans (RATs) are a type of malware that enables attackers to establish complete to partial control over infected computers. Such malicious programs often have a modular design, offering a wide range of functionalities for conducting illicit activities on compromised systems. Some of the most common features of RATs include access to the users’ data, webcam, and keystrokes. This malware is often distributed through phishing emails and links.

Analysis date: November 24, 2020, 18:44:37
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
trojan
rat
remcos
Indicators:
MIME: application/zip
File info: Zip archive data, at least v1.0 to extract
MD5:

68EBB00E6281681E243FB6C1982F2DAD

SHA1:

995F888F831861DD66270962BB0E2C3E8F4C26FE

SHA256:

EFF0F0191B90331896C670C1A7EC8067FB11A266F5FAF0C7B9BC0E49B39A8F22

SSDEEP:

49152:wZC45tKn7lxWhUIxLXXN8nf3PgekdfjbltxG1fzuW:uC4bIghUItXXNAPQjblEbl

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops executable file immediately after starts

      • PolarisBiosEditor.exe (PID: 3668)
    • Application was dropped or rewritten from another process

      • PolarisBiosEditor.exe (PID: 3664)
      • Rotator.exe (PID: 3972)
    • Runs app for hidden code execution

      • notepad.exe (PID: 3476)
    • Loads the Task Scheduler DLL interface

      • notepad.exe (PID: 2708)
    • REMCOS was detected

      • notepad.exe (PID: 2708)
    • Connects to CnC server

      • notepad.exe (PID: 2708)
  • SUSPICIOUS

    • Reads Windows owner or organization settings

      • PolarisBiosEditor.exe (PID: 2412)
      • PolarisBiosEditor.exe (PID: 3668)
    • Reads the Windows organization settings

      • PolarisBiosEditor.exe (PID: 2412)
      • PolarisBiosEditor.exe (PID: 3668)
    • Application launched itself

      • PolarisBiosEditor.exe (PID: 2412)
      • PolarisBiosEditor.exe (PID: 2688)
      • notepad.exe (PID: 3476)
    • Executable content was dropped or overwritten

      • PolarisBiosEditor.exe (PID: 3668)
      • notepad.exe (PID: 2708)
    • Drops a file that was compiled in debug mode

      • PolarisBiosEditor.exe (PID: 3668)
    • Creates a directory in Program Files

      • PolarisBiosEditor.exe (PID: 3668)
    • Creates files in the program directory

      • PolarisBiosEditor.exe (PID: 3668)
    • Drops a file with a compile date too recent

      • PolarisBiosEditor.exe (PID: 3668)
    • Starts CMD.EXE for commands execution

      • notepad.exe (PID: 3476)
    • Creates files in the user directory

      • notepad.exe (PID: 2708)
    • Creates files in the Windows directory

      • notepad.exe (PID: 2708)
  • INFO

    • Manual execution by user

      • PolarisBiosEditor.exe (PID: 2688)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 10
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2020:11:24 20:46:23
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: PolarisBiosEditor 1.7.2/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
49
Monitored processes
13
Malicious processes
6
Suspicious processes
0

Behavior graph

Click at the process to see the details
start drop and start drop and start winrar.exe no specs polarisbioseditor.exe no specs polarisbioseditor.exe polarisbioseditor.exe polarisbioseditor.exe no specs rotator.exe no specs notepad.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs #REMCOS notepad.exe

Process information

PID
CMD
Path
Indicators
Parent process
2044"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\PolarisBiosEditor 1.7.2.zip"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2160"C:\Windows\system32\cmd.exe"C:\Windows\system32\cmd.exenotepad.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
2200"C:\Windows\system32\cmd.exe"C:\Windows\system32\cmd.exenotepad.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
2412"C:\Users\admin\Desktop\PolarisBiosEditor 1.7.2\PolarisBiosEditor.exe" /SPAWNWND=$101E2 /NOTIFYWND=$101E2 C:\Users\admin\Desktop\PolarisBiosEditor 1.7.2\PolarisBiosEditor.exe
PolarisBiosEditor.exe
User:
admin
Company:
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
1
Version:
51.1052.0.0
Modules
Images
c:\users\admin\desktop\polarisbioseditor 1.7.2\polarisbioseditor.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2536"C:\Windows\system32\cmd.exe"C:\Windows\system32\cmd.exenotepad.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
2596"C:\Windows\system32\cmd.exe"C:\Windows\system32\cmd.exenotepad.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
2688"C:\Users\admin\Desktop\PolarisBiosEditor 1.7.2\PolarisBiosEditor.exe" C:\Users\admin\Desktop\PolarisBiosEditor 1.7.2\PolarisBiosEditor.exeexplorer.exe
User:
admin
Company:
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
1
Version:
51.1052.0.0
Modules
Images
c:\users\admin\desktop\polarisbioseditor 1.7.2\polarisbioseditor.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2708"C:\Windows\system32\notepad.exe"C:\Windows\system32\notepad.exe
notepad.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Notepad
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\notepad.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
3352"C:\Windows\system32\cmd.exe"C:\Windows\system32\cmd.exenotepad.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
3476"C:\Windows\system32\notepad.exe"C:\Windows\system32\notepad.exeRotator.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Notepad
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\notepad.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
Total events
718
Read events
686
Write events
22
Delete events
10

Modification events

(PID) Process:(2044) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2044) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2044) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\13B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2044) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\PolarisBiosEditor 1.7.2.zip
(PID) Process:(2044) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2044) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2044) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2044) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2412) PolarisBiosEditor.exeKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
6C0900004C3B5F1492C2D601
(PID) Process:(2412) PolarisBiosEditor.exeKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:SessionHash
Value:
712C838AD5CF94F377104FE530BA822D5B7EB81CA5145983509E6D1D4A4D0D86
Executable files
3
Suspicious files
1
Text files
0
Unknown types
1

Dropped files

PID
Process
Filename
Type
2044WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2044.39531\PolarisBiosEditor 1.7.2\PolarisBiosEditor-0.bin
MD5:
SHA256:
2044WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2044.39531\PolarisBiosEditor 1.7.2\PolarisBiosEditor-1.bin
MD5:
SHA256:
2044WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2044.39531\PolarisBiosEditor 1.7.2\PolarisBiosEditor.exe
MD5:
SHA256:
3668PolarisBiosEditor.exeC:\Program Files\PolarisBiosEditor\is-SAVC0.tmp
MD5:
SHA256:
3668PolarisBiosEditor.exeC:\Program Files\PolarisBiosEditor\is-KLJ2T.tmp
MD5:
SHA256:
2708notepad.exeC:\Users\admin\AppData\Roaming\Microsoft\AddIns\splwow64.exe
MD5:
SHA256:
2708notepad.exeC:\Windows\Tasks\splwow64.jobbinary
MD5:
SHA256:
2708notepad.exeC:\Users\admin\AppData\Roaming\Microsoft\AddIns\libcrypto-1_1.dllexecutable
MD5:
SHA256:
3668PolarisBiosEditor.exeC:\Program Files\PolarisBiosEditor\PolarisBiosEditor.exeexecutable
MD5:403B8BA045D73A0EB7ED091DC9F45922
SHA256:8CBB2FCB33487E4C27197BE958B67493122BE8E8BFF36EA8FE8B2BCD2E5B75FA
3668PolarisBiosEditor.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows NT\LineSecureCoin.lnklnk
MD5:273095750392CB6EC27B9B612C644982
SHA256:04C540A2DDE8FD359E7FE144CA0734AA9C6421010796370984F9A20D9DBF762F
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
8
DNS requests
1
Threats
7

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
151.101.12.193:443
i.imgur.com
Fastly
US
malicious
2708
notepad.exe
188.116.40.77:4545
NEPHAX Spolka jawna Arkadiusz Kawalec Michal Podsiadly
PL
malicious

DNS requests

Domain
IP
Reputation
i.imgur.com
  • 151.101.12.193
malicious

Threats

PID
Process
Class
Message
2708
notepad.exe
A Network Trojan was detected
REMOTE [PTsecurity] Backdoor.Win32/Remcos RAT connection
6 ETPRO signatures available at the full report
No debug info