| File name: | 8.rar |
| Full analysis: | https://app.any.run/tasks/40fb8548-d461-4ea1-a1ed-a4dfc8fdfa6c |
| Verdict: | Malicious activity |
| Threats: | Ransomware is a type of malicious software that locks users out of their system or data using different methods to force them to pay a ransom. Most often, such programs encrypt files on an infected machine and demand a fee to be paid in exchange for the decryption key. Additionally, such programs can be used to steal sensitive information from the compromised computer and even conduct DDoS attacks against affected organizations to pressure them into paying. |
| Analysis date: | July 16, 2019, 06:59:56 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-rar |
| File info: | RAR archive data, v5 |
| MD5: | F602EFBEF62D2A1384FE8F2DABB8A212 |
| SHA1: | 334D9F730BEFF1C0BD5C033F9C97C6B0A4CAA3ED |
| SHA256: | F3337B9F8607019A2173CDED2D2ABE6D85048AE4F8E2897E9FF1F81C66CC469C |
| SSDEEP: | 393216:BOaL8Ay0n2Tg6AQAAzfrso+NRLtQFLCwWBXlzB:lL/Nezr+/tQFb+XJB |
| .rar | | | RAR compressed archive (v5.0) (61.5) |
|---|---|---|
| .rar | | | RAR compressed archive (gen) (38.4) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 124 | C:\Windows\Explorer.EXE | C:\Windows\explorer.exe | — | — | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Explorer Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1472 | "C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe8_ Global\UsGthrCtrlFltPipeMssGthrPipe8 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" | C:\Windows\System32\SearchProtocolHost.exe | — | SearchIndexer.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft Windows Search Protocol Host Exit code: 0 Version: 7.00.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1984 | "C:\Users\admin\Desktop\Xrisky Checkers\CyberGhost_VPN_Checker_by_xRisky\CyberGhost VPN Checker by xRisky\CyberGhost VPN Checker by xRisky.exe" | C:\Users\admin\Desktop\Xrisky Checkers\CyberGhost_VPN_Checker_by_xRisky\CyberGhost VPN Checker by xRisky\CyberGhost VPN Checker by xRisky.exe | — | explorer.exe | |||||||||||
User: admin Company: CyberGhost VPN Checker by xRisky Integrity Level: MEDIUM Description: CyberGhost VPN Checker by xRisky Exit code: 0 Version: 1.0.0.0 Modules
| |||||||||||||||
| 2272 | "C:\Users\admin\Desktop\Xrisky Checkers\NetFlix_Checker_by_xRisky\NetFlix Checker by xRisky\Netflix Checker by xRisky.exe" | C:\Users\admin\Desktop\Xrisky Checkers\NetFlix_Checker_by_xRisky\NetFlix Checker by xRisky\Netflix Checker by xRisky.exe | — | explorer.exe | |||||||||||
User: admin Company: NetFlix Checker by xRisky Integrity Level: MEDIUM Description: NetFlix Checker by xRisky Exit code: 0 Version: 1.0.0.0 Modules
| |||||||||||||||
| 2384 | "C:\Users\admin\Desktop\Xrisky Checkers\NordVPN_Checker_by_xRisky_v2\NordVPN Checker by xRisky v2\NordVPN Checker by xRisky v2.exe" | C:\Users\admin\Desktop\Xrisky Checkers\NordVPN_Checker_by_xRisky_v2\NordVPN Checker by xRisky v2\NordVPN Checker by xRisky v2.exe | — | explorer.exe | |||||||||||
User: admin Company: NordVPN Checker by xRisky v2 Integrity Level: MEDIUM Description: NordVPN Checker by xRisky v2 Exit code: 0 Version: 1.0.0.0 Modules
| |||||||||||||||
| 2456 | "C:\Users\admin\Desktop\Xrisky Checkers\instagram Checker by xRisky\instagram Checker by xRisky\instagram Checker by xRisky.exe" | C:\Users\admin\Desktop\Xrisky Checkers\instagram Checker by xRisky\instagram Checker by xRisky\instagram Checker by xRisky.exe | — | explorer.exe | |||||||||||
User: admin Company: instagram Checker by xRisky Integrity Level: MEDIUM Description: instagram Checker by xRisky Exit code: 0 Version: 1.0.0.0 Modules
| |||||||||||||||
| 2620 | "C:\Users\admin\Desktop\Xrisky Checkers\Spotify_Checker_by_xRisky\Spotify Checker by xRisky\Spotify Checker by xRisky_protected.exe" | C:\Users\admin\Desktop\Xrisky Checkers\Spotify_Checker_by_xRisky\Spotify Checker by xRisky\Spotify Checker by xRisky_protected.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: WindowsApp45 Exit code: 0 Version: 1.0.0.0 Modules
| |||||||||||||||
| 3016 | "C:\Program Files\WinRAR\WinRAR.exe" x -iext -ow -ver "-an=C:\Users\admin\Desktop\Xrisky Checkers\CyberGhost_VPN_Checker_by_xRisky.rar" "-an=C:\Users\admin\Desktop\Xrisky Checkers\instagram Checker by xRisky.rar" "-an=C:\Users\admin\Desktop\Xrisky Checkers\Malwarebytes Key Checker by xRisky.rar" "-an=C:\Users\admin\Desktop\Xrisky Checkers\Minecraft Checker by xRisky.rar" "-an=C:\Users\admin\Desktop\Xrisky Checkers\NetFlix_Checker_by_xRisky.rar" "-an=C:\Users\admin\Desktop\Xrisky Checkers\NordVPN_Checker_by_xRisky_v2.rar" -ad -- "C:\Users\admin\Desktop\Xrisky Checkers\Spotify_Checker_by_xRisky.rar" "C:\Users\admin\Desktop\Xrisky Checkers\" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.60.0 Modules
| |||||||||||||||
| 3056 | "C:\Users\admin\Desktop\Xrisky Checkers\Minecraft Checker by xRisky\Minecraft Checker by xRisky\Minecraft Checker by xRisky.exe" | C:\Users\admin\Desktop\Xrisky Checkers\Minecraft Checker by xRisky\Minecraft Checker by xRisky\Minecraft Checker by xRisky.exe | explorer.exe | ||||||||||||
User: admin Company: Minecraft Checker by xRisky Integrity Level: MEDIUM Description: Minecraft Checker by xRisky Exit code: 0 Version: 1.0.0.0 Modules
| |||||||||||||||
| 3072 | "C:\Users\admin\Desktop\Xrisky Checkers\Malwarebytes Key Checker by xRisky\Malwarebytes Key Checker by xRisky\Malwarebytes Key Checker by xRisky.exe" | C:\Users\admin\Desktop\Xrisky Checkers\Malwarebytes Key Checker by xRisky\Malwarebytes Key Checker by xRisky\Malwarebytes Key Checker by xRisky.exe | — | explorer.exe | |||||||||||
User: admin Company: Malwarebytes Key Checker by xRisky Integrity Level: MEDIUM Description: Malwarebytes Key Checker by xRisky Exit code: 0 Version: 1.0.0.0 Modules
| |||||||||||||||
| (PID) Process: | (4008) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (4008) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (4008) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\70\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (4008) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\8.rar | |||
| (PID) Process: | (4008) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (4008) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (4008) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (4008) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (124) explorer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rar\OpenWithList |
| Operation: | write | Name: | a |
Value: WinRAR.exe | |||
| (PID) Process: | (124) explorer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rar\OpenWithList |
| Operation: | write | Name: | MRUList |
Value: a | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 4008 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa4008.42657\Xrisky Checkers\CyberGhost_VPN_Checker_by_xRisky.rar | — | |
MD5:— | SHA256:— | |||
| 4008 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa4008.42657\Xrisky Checkers\instagram Checker by xRisky.rar | — | |
MD5:— | SHA256:— | |||
| 4008 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa4008.42657\Xrisky Checkers\Malwarebytes Key Checker by xRisky.rar | — | |
MD5:— | SHA256:— | |||
| 4008 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa4008.42657\Xrisky Checkers\Minecraft Checker by xRisky.rar | — | |
MD5:— | SHA256:— | |||
| 4008 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa4008.42657\Xrisky Checkers\NetFlix_Checker_by_xRisky.rar | — | |
MD5:— | SHA256:— | |||
| 4008 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa4008.42657\Xrisky Checkers\NordVPN_Checker_by_xRisky_v2.rar | — | |
MD5:— | SHA256:— | |||
| 4008 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa4008.42657\Xrisky Checkers\Spotify_Checker_by_xRisky.rar | — | |
MD5:— | SHA256:— | |||
| 124 | explorer.exe | C:\Users\admin\Desktop\Xrisky Checkers | — | |
MD5:— | SHA256:— | |||
| 124 | explorer.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\1b4dd67f29cb1962.automaticDestinations-ms | automaticdestinations-ms | |
MD5:— | SHA256:— | |||
| 3016 | WinRAR.exe | C:\Users\admin\Desktop\Xrisky Checkers\CyberGhost_VPN_Checker_by_xRisky\CyberGhost VPN Checker by xRisky\YouTube 2.lnk | lnk | |
MD5:DEB42BBEC322CD0B8319F788312E28C4 | SHA256:B3BB48A747CC7078D4C4C5BD872A270B59F328AE90A85EF3D955B8A4892BFF41 | |||
Process | Message |
|---|---|
Minecraft Checker by xRisky.exe | %s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s |