File name:

1_VIDEO_CLIP_982736.mp4.001

Full analysis: https://app.any.run/tasks/664b7695-6316-43a1-941d-fb31f44b62ad
Verdict: Malicious activity
Threats:

A keylogger is a type of spyware that infects a system and has the ability to record every keystroke made on the device. This lets attackers collect personal information of victims, which may include their online banking credentials, as well as personal conversations. The most widespread vector of attack leading to a keylogger infection begins with a phishing email or link. Keylogging is also often present in remote access trojans as part of an extended set of malicious tools.

Analysis date: July 18, 2019, 13:49:03
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
autoit
rat
remcos
keylogger
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

0502683EFD454EA38BEB948D5C859099

SHA1:

D9BDE232A9142D3279788D0629500AB5401DE924

SHA256:

F3B0976B128E78FDB102B1992058055841E723BB3299F1D9207E6ECA8FAF1DAA

SSDEEP:

24576:ykRriAz0CWa7l1B+WUQpN0KsEYTq+IVc1kNR/gFjwwwcYpj5g:vRx1L751n0DEY2+IMkLYydFg

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • 1_VIDEO_CLIP_982736.mp4.exe (PID: 3244)
      • ptl.exe (PID: 1568)
      • ptl.exe (PID: 3652)
      • 1_VIDEO_CLIP_982736.mp4.exe (PID: 2064)
      • ptl.exe (PID: 1076)
      • ptl.exe (PID: 2932)
      • 1_VIDEO_CLIP_982736.mp4.exe (PID: 3800)
      • ptl.exe (PID: 2800)
      • ptl.exe (PID: 1656)
      • ptl.exe (PID: 3520)
      • 1_VIDEO_CLIP_982736.mp4.exe (PID: 616)
      • ptl.exe (PID: 692)
    • Changes the autorun value in the registry

      • ptl.exe (PID: 3652)
      • ptl.exe (PID: 2932)
      • ptl.exe (PID: 3520)
      • ptl.exe (PID: 692)
    • REMCOS was detected

      • RegSvcs.exe (PID: 2928)
    • Detected logs from REMCOS RAT

      • RegSvcs.exe (PID: 2928)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • 1_VIDEO_CLIP_982736.mp4.exe (PID: 3244)
      • WinRAR.exe (PID: 3696)
    • Drop AutoIt3 executable file

      • 1_VIDEO_CLIP_982736.mp4.exe (PID: 3244)
    • Executes scripts

      • 1_VIDEO_CLIP_982736.mp4.exe (PID: 3244)
      • 1_VIDEO_CLIP_982736.mp4.exe (PID: 2064)
      • 1_VIDEO_CLIP_982736.mp4.exe (PID: 616)
      • 1_VIDEO_CLIP_982736.mp4.exe (PID: 3800)
    • Application launched itself

      • ptl.exe (PID: 1568)
      • ptl.exe (PID: 1076)
      • ptl.exe (PID: 2800)
    • Creates files in the user directory

      • RegSvcs.exe (PID: 2928)
    • Writes files like Keylogger logs

      • RegSvcs.exe (PID: 2928)
  • INFO

    • Manual execution by user

      • 1_VIDEO_CLIP_982736.mp4.exe (PID: 3800)
      • 1_VIDEO_CLIP_982736.mp4.exe (PID: 616)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
57
Monitored processes
21
Malicious processes
10
Suspicious processes
8

Behavior graph

Click at the process to see the details
drop and start drop and start start winrar.exe 1_video_clip_982736.mp4.exe wscript.exe no specs ptl.exe no specs ptl.exe #REMCOS regsvcs.exe 1_video_clip_982736.mp4.exe no specs wscript.exe no specs ptl.exe no specs ptl.exe regsvcs.exe no specs 1_video_clip_982736.mp4.exe no specs wscript.exe no specs ptl.exe no specs ptl.exe regsvcs.exe no specs 1_video_clip_982736.mp4.exe wscript.exe no specs ptl.exe no specs ptl.exe regsvcs.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
616"C:\Users\admin\Desktop\1_VIDEO_CLIP_982736.mp4.exe" C:\Users\admin\Desktop\1_VIDEO_CLIP_982736.mp4.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
10
Modules
Images
c:\users\admin\desktop\1_video_clip_982736.mp4.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
692C:\Users\admin\AppData\Local\Temp\27115394\ptl.exe C:\Users\admin\AppData\Local\Temp\27115394\LCKWGC:\Users\admin\AppData\Local\Temp\27115394\ptl.exe
ptl.exe
User:
admin
Company:
AutoIt Team
Integrity Level:
HIGH
Description:
AutoIt v3 Script
Exit code:
0
Version:
3, 3, 14, 4
Modules
Images
c:\users\admin\appdata\local\temp\27115394\ptl.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\version.dll
1076"C:\Users\admin\AppData\Local\Temp\27115394\ptl.exe" oac=mupC:\Users\admin\AppData\Local\Temp\27115394\ptl.exeWScript.exe
User:
admin
Company:
AutoIt Team
Integrity Level:
MEDIUM
Description:
AutoIt v3 Script
Exit code:
0
Version:
3, 3, 14, 4
Modules
Images
c:\users\admin\appdata\local\temp\27115394\ptl.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\version.dll
1568"C:\Users\admin\AppData\Local\Temp\27115394\ptl.exe" oac=mupC:\Users\admin\AppData\Local\Temp\27115394\ptl.exeWScript.exe
User:
admin
Company:
AutoIt Team
Integrity Level:
MEDIUM
Description:
AutoIt v3 Script
Exit code:
0
Version:
3, 3, 14, 4
Modules
Images
c:\users\admin\appdata\local\temp\27115394\ptl.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\nsi.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
1656"C:\Users\admin\AppData\Local\Temp\27115394\ptl.exe" oac=mupC:\Users\admin\AppData\Local\Temp\27115394\ptl.exeWScript.exe
User:
admin
Company:
AutoIt Team
Integrity Level:
MEDIUM
Description:
AutoIt v3 Script
Exit code:
0
Version:
3, 3, 14, 4
Modules
Images
c:\users\admin\appdata\local\temp\27115394\ptl.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\version.dll
2064"C:\Users\admin\AppData\Local\Temp\Rar$EXa3696.28344\1_VIDEO_CLIP_982736.mp4.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3696.28344\1_VIDEO_CLIP_982736.mp4.exeWinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
10
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3696.28344\1_video_clip_982736.mp4.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2236"C:\Windows\System32\WScript.exe" "C:\Users\admin\AppData\Local\Temp\27115394\bkb.vbs" C:\Windows\System32\WScript.exe1_VIDEO_CLIP_982736.mp4.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft ® Windows Based Script Host
Exit code:
0
Version:
5.8.7600.16385
Modules
Images
c:\windows\system32\wscript.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2300"C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe"C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exeptl.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft .NET Services Installation Utility
Exit code:
1
Version:
4.7.3062.0 built by: NET472REL1
Modules
Images
c:\windows\microsoft.net\framework\v4.0.30319\regsvcs.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
2468"C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe"C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exeptl.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft .NET Services Installation Utility
Exit code:
1
Version:
4.7.3062.0 built by: NET472REL1
Modules
Images
c:\windows\microsoft.net\framework\v4.0.30319\regsvcs.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2800"C:\Users\admin\AppData\Local\Temp\27115394\ptl.exe" oac=mupC:\Users\admin\AppData\Local\Temp\27115394\ptl.exeWScript.exe
User:
admin
Company:
AutoIt Team
Integrity Level:
HIGH
Description:
AutoIt v3 Script
Exit code:
0
Version:
3, 3, 14, 4
Modules
Images
c:\users\admin\appdata\local\temp\27115394\ptl.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\version.dll
Total events
3 941
Read events
3 657
Write events
284
Delete events
0

Modification events

(PID) Process:(3696) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3696) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3696) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\70\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3696) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\1_VIDEO_CLIP_982736.mp4.001
(PID) Process:(3696) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3696) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3696) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3696) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3696) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(3696) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
Executable files
4
Suspicious files
0
Text files
56
Unknown types
0

Dropped files

PID
Process
Filename
Type
32441_VIDEO_CLIP_982736.mp4.exeC:\Users\admin\AppData\Local\Temp\27115394\sxv.dattext
MD5:
SHA256:
32441_VIDEO_CLIP_982736.mp4.exeC:\Users\admin\AppData\Local\Temp\27115394\muf.icotext
MD5:
SHA256:
32441_VIDEO_CLIP_982736.mp4.exeC:\Users\admin\AppData\Local\Temp\27115394\oac=muptext
MD5:
SHA256:
32441_VIDEO_CLIP_982736.mp4.exeC:\Users\admin\AppData\Local\Temp\27115394\bkb.vbstext
MD5:
SHA256:
32441_VIDEO_CLIP_982736.mp4.exeC:\Users\admin\AppData\Local\Temp\27115394\wlq.jpgtext
MD5:
SHA256:
32441_VIDEO_CLIP_982736.mp4.exeC:\Users\admin\AppData\Local\Temp\27115394\lmv.pdftext
MD5:
SHA256:
32441_VIDEO_CLIP_982736.mp4.exeC:\Users\admin\AppData\Local\Temp\27115394\uda.icmtext
MD5:
SHA256:
32441_VIDEO_CLIP_982736.mp4.exeC:\Users\admin\AppData\Local\Temp\27115394\wqr.dattext
MD5:
SHA256:
32441_VIDEO_CLIP_982736.mp4.exeC:\Users\admin\AppData\Local\Temp\27115394\afk.bmptext
MD5:
SHA256:
32441_VIDEO_CLIP_982736.mp4.exeC:\Users\admin\AppData\Local\Temp\27115394\eaq.xltext
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
21
DNS requests
1
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2928
RegSvcs.exe
91.189.180.218:9300
niiarmah.dynu.com
ServeTheWorld AS
NO
malicious

DNS requests

Domain
IP
Reputation
niiarmah.dynu.com
  • 91.189.180.218
unknown

Threats

No threats detected
No debug info