File name:

8.rar

Full analysis: https://app.any.run/tasks/40fb8548-d461-4ea1-a1ed-a4dfc8fdfa6c
Verdict: Malicious activity
Threats:

Ransomware is a type of malicious software that locks users out of their system or data using different methods to force them to pay a ransom. Most often, such programs encrypt files on an infected machine and demand a fee to be paid in exchange for the decryption key. Additionally, such programs can be used to steal sensitive information from the compromised computer and even conduct DDoS attacks against affected organizations to pressure them into paying.

Analysis date: July 16, 2019, 06:59:56
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
ransomware
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

F602EFBEF62D2A1384FE8F2DABB8A212

SHA1:

334D9F730BEFF1C0BD5C033F9C97C6B0A4CAA3ED

SHA256:

F3337B9F8607019A2173CDED2D2ABE6D85048AE4F8E2897E9FF1F81C66CC469C

SSDEEP:

393216:BOaL8Ay0n2Tg6AQAAzfrso+NRLtQFLCwWBXlzB:lL/Nezr+/tQFb+XJB

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Dropped file may contain instructions of ransomware

      • WinRAR.exe (PID: 3016)
    • Loads dropped or rewritten executable

      • SearchProtocolHost.exe (PID: 1472)
      • CyberGhost VPN Checker by xRisky.exe (PID: 1984)
      • explorer.exe (PID: 124)
      • instagram Checker by xRisky.exe (PID: 2456)
      • Malwarebytes Key Checker by xRisky.exe (PID: 3072)
      • Minecraft Checker by xRisky.exe (PID: 3056)
      • Netflix Checker by xRisky.exe (PID: 2272)
      • NordVPN Checker by xRisky v2.exe (PID: 2384)
      • Spotify Checker by xRisky_protected.exe (PID: 2620)
    • Application was dropped or rewritten from another process

      • CyberGhost VPN Checker by xRisky.exe (PID: 1984)
      • instagram Checker by xRisky.exe (PID: 2456)
      • Malwarebytes Key Checker by xRisky.exe (PID: 3072)
      • Minecraft Checker by xRisky.exe (PID: 3056)
      • Netflix Checker by xRisky.exe (PID: 2272)
      • Spotify Checker by xRisky_protected.exe (PID: 2620)
      • NordVPN Checker by xRisky v2.exe (PID: 2384)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3016)
    • Creates files in the user directory

      • Malwarebytes Key Checker by xRisky.exe (PID: 3072)
    • Uses RUNDLL32.EXE to load library

      • explorer.exe (PID: 124)
  • INFO

    • Manual execution by user

      • WinRAR.exe (PID: 3016)
      • CyberGhost VPN Checker by xRisky.exe (PID: 1984)
    • Dropped object may contain Bitcoin addresses

      • WinRAR.exe (PID: 3016)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
50
Monitored processes
12
Malicious processes
10
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe no specs winrar.exe searchprotocolhost.exe no specs cyberghost vpn checker by xrisky.exe no specs explorer.exe no specs instagram checker by xrisky.exe no specs malwarebytes key checker by xrisky.exe no specs minecraft checker by xrisky.exe netflix checker by xrisky.exe no specs nordvpn checker by xrisky v2.exe no specs rundll32.exe no specs spotify checker by xrisky_protected.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
124C:\Windows\Explorer.EXEC:\Windows\explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\devrtl.dll
c:\program files\winrar\winrar.exe
c:\windows\system32\zipfldr.dll
c:\windows\system32\wpdshext.dll
c:\windows\system32\audiodev.dll
c:\windows\system32\wmvcore.dll
c:\windows\system32\wmasf.dll
c:\windows\system32\twext.dll
1472"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe8_ Global\UsGthrCtrlFltPipeMssGthrPipe8 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" C:\Windows\System32\SearchProtocolHost.exeSearchIndexer.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Windows Search Protocol Host
Exit code:
0
Version:
7.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\slc.dll
c:\windows\system32\version.dll
c:\users\admin\desktop\xrisky checkers\cyberghost_vpn_checker_by_xrisky\cyberghost vpn checker by xrisky\cyberghost vpn checker by xrisky.exe
c:\windows\system32\linkinfo.dll
c:\users\admin\desktop\xrisky checkers\spotify_checker_by_xrisky\spotify checker by xrisky\xnet.dll
c:\users\admin\desktop\xrisky checkers\spotify_checker_by_xrisky\spotify checker by xrisky\spotify checker by xrisky_protected.exe
c:\windows\system32\notepad.exe
1984"C:\Users\admin\Desktop\Xrisky Checkers\CyberGhost_VPN_Checker_by_xRisky\CyberGhost VPN Checker by xRisky\CyberGhost VPN Checker by xRisky.exe" C:\Users\admin\Desktop\Xrisky Checkers\CyberGhost_VPN_Checker_by_xRisky\CyberGhost VPN Checker by xRisky\CyberGhost VPN Checker by xRisky.exeexplorer.exe
User:
admin
Company:
CyberGhost VPN Checker by xRisky
Integrity Level:
MEDIUM
Description:
CyberGhost VPN Checker by xRisky
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\xrisky checkers\cyberghost_vpn_checker_by_xrisky\cyberghost vpn checker by xrisky\cyberghost vpn checker by xrisky.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2272"C:\Users\admin\Desktop\Xrisky Checkers\NetFlix_Checker_by_xRisky\NetFlix Checker by xRisky\Netflix Checker by xRisky.exe" C:\Users\admin\Desktop\Xrisky Checkers\NetFlix_Checker_by_xRisky\NetFlix Checker by xRisky\Netflix Checker by xRisky.exeexplorer.exe
User:
admin
Company:
NetFlix Checker by xRisky
Integrity Level:
MEDIUM
Description:
NetFlix Checker by xRisky
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\xrisky checkers\netflix_checker_by_xrisky\netflix checker by xrisky\netflix checker by xrisky.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2384"C:\Users\admin\Desktop\Xrisky Checkers\NordVPN_Checker_by_xRisky_v2\NordVPN Checker by xRisky v2\NordVPN Checker by xRisky v2.exe" C:\Users\admin\Desktop\Xrisky Checkers\NordVPN_Checker_by_xRisky_v2\NordVPN Checker by xRisky v2\NordVPN Checker by xRisky v2.exeexplorer.exe
User:
admin
Company:
NordVPN Checker by xRisky v2
Integrity Level:
MEDIUM
Description:
NordVPN Checker by xRisky v2
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\xrisky checkers\nordvpn_checker_by_xrisky_v2\nordvpn checker by xrisky v2\nordvpn checker by xrisky v2.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2456"C:\Users\admin\Desktop\Xrisky Checkers\instagram Checker by xRisky\instagram Checker by xRisky\instagram Checker by xRisky.exe" C:\Users\admin\Desktop\Xrisky Checkers\instagram Checker by xRisky\instagram Checker by xRisky\instagram Checker by xRisky.exeexplorer.exe
User:
admin
Company:
instagram Checker by xRisky
Integrity Level:
MEDIUM
Description:
instagram Checker by xRisky
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\xrisky checkers\instagram checker by xrisky\instagram checker by xrisky\instagram checker by xrisky.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2620"C:\Users\admin\Desktop\Xrisky Checkers\Spotify_Checker_by_xRisky\Spotify Checker by xRisky\Spotify Checker by xRisky_protected.exe" C:\Users\admin\Desktop\Xrisky Checkers\Spotify_Checker_by_xRisky\Spotify Checker by xRisky\Spotify Checker by xRisky_protected.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
WindowsApp45
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\xrisky checkers\spotify_checker_by_xrisky\spotify checker by xrisky\spotify checker by xrisky_protected.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3016"C:\Program Files\WinRAR\WinRAR.exe" x -iext -ow -ver "-an=C:\Users\admin\Desktop\Xrisky Checkers\CyberGhost_VPN_Checker_by_xRisky.rar" "-an=C:\Users\admin\Desktop\Xrisky Checkers\instagram Checker by xRisky.rar" "-an=C:\Users\admin\Desktop\Xrisky Checkers\Malwarebytes Key Checker by xRisky.rar" "-an=C:\Users\admin\Desktop\Xrisky Checkers\Minecraft Checker by xRisky.rar" "-an=C:\Users\admin\Desktop\Xrisky Checkers\NetFlix_Checker_by_xRisky.rar" "-an=C:\Users\admin\Desktop\Xrisky Checkers\NordVPN_Checker_by_xRisky_v2.rar" -ad -- "C:\Users\admin\Desktop\Xrisky Checkers\Spotify_Checker_by_xRisky.rar" "C:\Users\admin\Desktop\Xrisky Checkers\"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3056"C:\Users\admin\Desktop\Xrisky Checkers\Minecraft Checker by xRisky\Minecraft Checker by xRisky\Minecraft Checker by xRisky.exe" C:\Users\admin\Desktop\Xrisky Checkers\Minecraft Checker by xRisky\Minecraft Checker by xRisky\Minecraft Checker by xRisky.exe
explorer.exe
User:
admin
Company:
Minecraft Checker by xRisky
Integrity Level:
MEDIUM
Description:
Minecraft Checker by xRisky
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\xrisky checkers\minecraft checker by xrisky\minecraft checker by xrisky\minecraft checker by xrisky.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3072"C:\Users\admin\Desktop\Xrisky Checkers\Malwarebytes Key Checker by xRisky\Malwarebytes Key Checker by xRisky\Malwarebytes Key Checker by xRisky.exe" C:\Users\admin\Desktop\Xrisky Checkers\Malwarebytes Key Checker by xRisky\Malwarebytes Key Checker by xRisky\Malwarebytes Key Checker by xRisky.exeexplorer.exe
User:
admin
Company:
Malwarebytes Key Checker by xRisky
Integrity Level:
MEDIUM
Description:
Malwarebytes Key Checker by xRisky
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\xrisky checkers\malwarebytes key checker by xrisky\malwarebytes key checker by xrisky\malwarebytes key checker by xrisky.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
Total events
6 938
Read events
5 948
Write events
990
Delete events
0

Modification events

(PID) Process:(4008) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(4008) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(4008) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\70\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(4008) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\8.rar
(PID) Process:(4008) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(4008) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(4008) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(4008) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(124) explorer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rar\OpenWithList
Operation:writeName:a
Value:
WinRAR.exe
(PID) Process:(124) explorer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rar\OpenWithList
Operation:writeName:MRUList
Value:
a
Executable files
21
Suspicious files
0
Text files
8
Unknown types
15

Dropped files

PID
Process
Filename
Type
4008WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa4008.42657\Xrisky Checkers\CyberGhost_VPN_Checker_by_xRisky.rar
MD5:
SHA256:
4008WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa4008.42657\Xrisky Checkers\instagram Checker by xRisky.rar
MD5:
SHA256:
4008WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa4008.42657\Xrisky Checkers\Malwarebytes Key Checker by xRisky.rar
MD5:
SHA256:
4008WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa4008.42657\Xrisky Checkers\Minecraft Checker by xRisky.rar
MD5:
SHA256:
4008WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa4008.42657\Xrisky Checkers\NetFlix_Checker_by_xRisky.rar
MD5:
SHA256:
4008WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa4008.42657\Xrisky Checkers\NordVPN_Checker_by_xRisky_v2.rar
MD5:
SHA256:
4008WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa4008.42657\Xrisky Checkers\Spotify_Checker_by_xRisky.rar
MD5:
SHA256:
124explorer.exeC:\Users\admin\Desktop\Xrisky Checkers
MD5:
SHA256:
124explorer.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\1b4dd67f29cb1962.automaticDestinations-msautomaticdestinations-ms
MD5:
SHA256:
3016WinRAR.exeC:\Users\admin\Desktop\Xrisky Checkers\CyberGhost_VPN_Checker_by_xRisky\CyberGhost VPN Checker by xRisky\YouTube 2.lnklnk
MD5:DEB42BBEC322CD0B8319F788312E28C4
SHA256:B3BB48A747CC7078D4C4C5BD872A270B59F328AE90A85EF3D955B8A4892BFF41
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
Process
Message
Minecraft Checker by xRisky.exe
%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s