| File name: | [Snipcola] Synapse X (V2).rar |
| Full analysis: | https://app.any.run/tasks/df6a1826-f1b7-4d5d-849a-5c5e1308c2d4 |
| Verdict: | Malicious activity |
| Analysis date: | January 21, 2020, 12:17:32 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-rar |
| File info: | RAR archive data, v5 |
| MD5: | FAF77CCD6047EA423328EEB1CE198784 |
| SHA1: | 683FB62F5C368F7AAC8485AC4A4084263BE61D65 |
| SHA256: | F3BFE8C8523B950642433E1A989FA5FA4DF01968CC9C28B8E7AAA0FF203A3653 |
| SSDEEP: | 393216:RuZopsGcbc6EivKRKCyGm8GmtDpo5kel3WYzmj4jBWZm:goj6PKRKCdDp6kexWYzmcjBWQ |
| .rar | | | RAR compressed archive (v5.0) (61.5) |
|---|---|---|
| .rar | | | RAR compressed archive (gen) (38.4) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2336 | "C:\Users\admin\Desktop\Synapse X (V2)\Synapse X (V2).exe" | C:\Users\admin\Desktop\Synapse X (V2)\Synapse X (V2).exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Description: SynapseX - main Exit code: 0 Version: 1.0.0.0 Modules
| |||||||||||||||
| 2996 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\[Snipcola] Synapse X (V2).rar" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.60.0 Modules
| |||||||||||||||
| (PID) Process: | (2996) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (2996) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (2996) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2996) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\[Snipcola] Synapse X (V2).rar | |||
| (PID) Process: | (2996) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (2996) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (2996) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (2996) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (2996) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin |
| Operation: | write | Name: | Placement |
Value: 2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000 | |||
| (PID) Process: | (2996) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\General |
| Operation: | write | Name: | LastFolder |
Value: C:\Users\admin\AppData\Local\Temp | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2996 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2996.8729\Synapse X (V2)\Monaco\globalv.txt | text | |
MD5:5CF9F238D4E62C8BCDE351651C3A2A45 | SHA256:EEB98F2C9911AE8DDD25F1B3BE3732000F16788BDA60AA962E9F8452012B1062 | |||
| 2996 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2996.8729\Synapse X (V2)\Monaco\classfunc.txt | text | |
MD5:BF32E93D11011EB780619B3E17FB824A | SHA256:519DA000DE235C331F10660509FAB51A1815ACE566B8AE5B511B75813922DCB1 | |||
| 2996 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2996.8729\Synapse X (V2)\Monaco\vs\base\worker\workerMain.js | text | |
MD5:27EAD90C7702154755785E0E53398755 | SHA256:BDF9433692A08851E13DD58504EEF19F51BD2EC7241923A68EDF5772E0E53AF5 | |||
| 2996 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2996.8729\Synapse X (V2)\exploit-main.dll | executable | |
MD5:69907F276CD3B9CE0B2674B239BE9E2C | SHA256:9256432625A30A1E88F383E7E0672D16AC82B3B78EFC9BF40AC971746BF637D4 | |||
| 2996 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2996.8729\Synapse X (V2)\Monaco\vs\basic-languages\csharp\csharp.js | text | |
MD5:F8F841D13C9220E15DCD6BC386B37BA2 | SHA256:6B3BE9A86EE8E3202F51745D94D24CC1EEFBCF7D9E6D94FBAF70146B084E835F | |||
| 2996 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2996.8729\Synapse X (V2)\Monaco\vs\basic-languages\css\css.js | text | |
MD5:49AD30F1151CFD7A74677FDC6DD13DA9 | SHA256:BD331FD3BD2C37B0C3150035325F163AC9266BF6D942310764815E676D856D91 | |||
| 2996 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2996.8729\Synapse X (V2)\Bunifu_UI_v1.5.3.dll | executable | |
MD5:2ECB51AB00C5F340380ECF849291DBCF | SHA256:F1B3E0F2750A9103E46A6A4A34F1CF9D17779725F98042CC2475EC66484801CF | |||
| 2996 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2996.8729\Synapse X (V2)\Monaco\vs\basic-languages\bat\bat.js | text | |
MD5:4CB475399C4490EEA41982DCD6D9653E | SHA256:9BCA42394FE8922FEC24B768EEB8CE04692DE6FAD82F9052D5B7E70F5C6B0F40 | |||
| 2996 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2996.8729\Synapse X (V2)\Monaco\Monaco.html | html | |
MD5:999896134BD43CEFA865F37E514BA62F | SHA256:1ECDD9529EF5487F92736894D94FF680F6C32EE821615D29C0FC814F3A310B4A | |||
| 2996 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2996.8729\Synapse X (V2)\Monaco\base.txt | text | |
MD5:0D834904A252E1AB786F9637BEF6819F | SHA256:DBE440C5DEE6367EBCA919886FFE593246E1E52618E4713373000C9FC77C87CC | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2336 | Synapse X (V2).exe | 104.27.107.80:443 | wearedevs.net | Cloudflare Inc | US | unknown |
2336 | Synapse X (V2).exe | 104.27.106.80:443 | wearedevs.net | Cloudflare Inc | US | unknown |
2336 | Synapse X (V2).exe | 162.159.135.233:443 | cdn.discordapp.com | Cloudflare Inc | — | shared |
Domain | IP | Reputation |
|---|---|---|
wearedevs.net |
| whitelisted |
dns.msftncsi.com |
| shared |
cdn.wearedevs.net |
| whitelisted |
cdn.discordapp.com |
| shared |