analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

LoL Hack & Cheat Map Hacks.zip

Full analysis: https://app.any.run/tasks/a914dc2b-1af1-421e-8b29-a56e34adc128
Verdict: Malicious activity
Threats:

Remote access trojans (RATs) are a type of malware that enables attackers to establish complete to partial control over infected computers. Such malicious programs often have a modular design, offering a wide range of functionalities for conducting illicit activities on compromised systems. Some of the most common features of RATs include access to the users’ data, webcam, and keystrokes. This malware is often distributed through phishing emails and links.

Analysis date: May 30, 2020, 16:43:37
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
rat
redline
Indicators:
MIME: application/zip
File info: Zip archive data, at least v1.0 to extract
MD5:

905EE80F7DECE73CE41303AE28FA57C2

SHA1:

623135CBB9B84310FF71F858A23544BA410BAAF3

SHA256:

F784624F9315DB399E168F5D30D26321381426CD794321AE513179C5E1A9B3E2

SSDEEP:

49152:C+SQRwTd5xSljq8ZcabNAo63/CVGC8dscUPu:C+SOEd3Sxq8Z5b83/gGrQu

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • LoL Hack & Cheat Map Hacks.exe (PID: 3900)
    • REDLINE was detected

      • AddInProcess.exe (PID: 788)
    • Changes settings of System certificates

      • LoL Hack & Cheat Map Hacks.exe (PID: 3900)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 764)
    • Executed via COM

      • DllHost.exe (PID: 1964)
    • Connects to server without host name

      • AddInProcess.exe (PID: 788)
    • Adds / modifies Windows certificates

      • LoL Hack & Cheat Map Hacks.exe (PID: 3900)
  • INFO

    • Manual execution by user

      • LoL Hack & Cheat Map Hacks.exe (PID: 3900)
      • NOTEPAD.EXE (PID: 884)
    • Reads settings of System Certificates

      • LoL Hack & Cheat Map Hacks.exe (PID: 3900)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 10
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2020:05:28 21:46:21
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: LoL Hack & Cheat Map Hacks/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
40
Monitored processes
5
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe lol hack & cheat map hacks.exe PhotoViewer.dll no specs notepad.exe no specs #REDLINE addinprocess.exe

Process information

PID
CMD
Path
Indicators
Parent process
764"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\LoL Hack & Cheat Map Hacks.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.60.0
3900"C:\Users\admin\Desktop\LoL Hack & Cheat Map Hacks\LoL Hack & Cheat Map Hacks.exe" C:\Users\admin\Desktop\LoL Hack & Cheat Map Hacks\LoL Hack & Cheat Map Hacks.exe
explorer.exe
User:
admin
Company:
The ICU Project
Integrity Level:
MEDIUM
Description:
ICU Data DLL
Exit code:
0
Version:
53, 1, 0, 0
1964C:\Windows\system32\DllHost.exe /Processid:{76D0CB12-7604-4048-B83C-1005C7DDC503}C:\Windows\system32\DllHost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
COM Surrogate
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
884"C:\Windows\system32\NOTEPAD.EXE" C:\Users\admin\Desktop\LoL Hack & Cheat Map Hacks\READMY.txtC:\Windows\system32\NOTEPAD.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
788C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess.exeC:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess.exe
LoL Hack & Cheat Map Hacks.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
AddInProcess.exe
Version:
4.7.3062.0 built by: NET472REL1
Total events
4 124
Read events
543
Write events
0
Delete events
0

Modification events

No data
Executable files
1
Suspicious files
1
Text files
2
Unknown types
0

Dropped files

PID
Process
Filename
Type
764WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa764.37126\LoL Hack & Cheat Map Hacks\1.pngimage
MD5:C1B1475114AA5015586A8C1C15729208
SHA256:D10062FBADF2118527CD141A3F19A6C41253FB5D9830F6F2F9CBDF9BEE8AD0D1
764WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa764.37126\LoL Hack & Cheat Map Hacks\HackLoader.dllbinary
MD5:1AD3BCE06CF3686BE434DA960AE3AE77
SHA256:C02FB93A05B0E18D0383BE41A9FFBDB39EE1F263E454E844575D586AAB2E7E1D
764WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa764.37126\LoL Hack & Cheat Map Hacks\READMY.txttext
MD5:EEDC3CEBCF78691286D76A2B8A426230
SHA256:742C0AB27037B78AFE65296BDCB02C50293A9BC801578C7897B0A1C595910515
764WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa764.37126\LoL Hack & Cheat Map Hacks\LoL Hack & Cheat Map Hacks.exeexecutable
MD5:D68F26C72EFD6060E466A352B737453C
SHA256:9686318E6EEB2859FA987194B429A9EA167BD075C905C525FD908409D36A0999
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
2
DNS requests
2
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
788
AddInProcess.exe
POST
81.177.136.230:80
http://81.177.136.230/IRemotePanel
RU
malicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3900
LoL Hack & Cheat Map Hacks.exe
81.177.141.121:443
wryx7t.uenothingrealy.ru
JSC RTComm.RU
RU
unknown
788
AddInProcess.exe
81.177.136.230:80
JSC RTComm.RU
RU
malicious

DNS requests

Domain
IP
Reputation
wryx7t.uenothingrealy.ru
  • 81.177.141.121
unknown

Threats

PID
Process
Class
Message
788
AddInProcess.exe
A Network Trojan was detected
SPYWARE [PTsecurity] RedLine
No debug info