File name:

Spider Hack Tools Plus v1.0 By Spider Virus.rar

Full analysis: https://app.any.run/tasks/9ff94d8f-79f5-4d6b-aef5-0ff672dc70a5
Verdict: Malicious activity
Analysis date: October 29, 2018, 17:22:01
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v4, os: Win32
MD5:

A15F88459DA8EC283BFD45833A6B5526

SHA1:

2BA79AB33CFD6FCD8626B3ACF1EC63E1BEFB4168

SHA256:

F9FE3E52C43215CE9D217C5A839BC7051B7FCD865BE9860B4F984601A3298C1B

SSDEEP:

12288:pVNGkPAaUx7h3SkQS1/OTege/w8WjFwh1MSNLb3GmAtMeO0yZ:0kAaREgenWj6gWb1A6eWZ

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Spider Hack Tools Plus.exe (PID: 2444)
      • Spider Hack Tools Plus.exe (PID: 3596)
      • netprotocol.exe (PID: 2304)
      • netprotocol.exe (PID: 2524)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • Spider Hack Tools Plus.exe (PID: 3596)
    • Starts itself from another location

      • Spider Hack Tools Plus.exe (PID: 3596)
    • Uses NETSH.EXE for network configuration

      • netprotocol.exe (PID: 2304)
    • Application launched itself

      • netprotocol.exe (PID: 2524)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v-4.x) (58.3)
.rar | RAR compressed archive (gen) (41.6)

EXIF

ZIP

CompressedSize: 497027
UncompressedSize: 942080
OperatingSystem: Win32
ModifyDate: 2017:08:23 16:24:25
PackingMethod: Normal
ArchivedFileName: Spider Hack Tools Plus\Spider Hack Tools Plus.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
39
Monitored processes
6
Malicious processes
0
Suspicious processes
2

Behavior graph

Click at the process to see the details
start drop and start drop and start winrar.exe no specs spider hack tools plus.exe spider hack tools plus.exe no specs netprotocol.exe no specs netprotocol.exe no specs netsh.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1968"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Spider Hack Tools Plus v1.0 By Spider Virus.rar"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2304"C:\Users\admin\AppData\Roaming\Microsoft\Windows\ScreenToGif\netprotocol.exe"C:\Users\admin\AppData\Roaming\Microsoft\Windows\ScreenToGif\netprotocol.exenetprotocol.exe
User:
admin
Company:
Spider virus
Integrity Level:
MEDIUM
Description:
Spider Hack Tools Plus
Exit code:
0
Version:
2.0.0.0
Modules
Images
c:\users\admin\appdata\roaming\microsoft\windows\screentogif\netprotocol.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2444"C:\Users\admin\AppData\Local\Temp\Spider Hack Tools Plus.exe" C:\Users\admin\AppData\Local\Temp\Spider Hack Tools Plus.exeSpider Hack Tools Plus.exe
User:
admin
Company:
Spider virus
Integrity Level:
MEDIUM
Description:
Spider Hack Tools Plus
Exit code:
0
Version:
2.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\spider hack tools plus.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2524"C:\Users\admin\AppData\Roaming\Microsoft\Windows\ScreenToGif\netprotocol.exe" -nC:\Users\admin\AppData\Roaming\Microsoft\Windows\ScreenToGif\netprotocol.exeSpider Hack Tools Plus.exe
User:
admin
Company:
Spider virus
Integrity Level:
MEDIUM
Description:
Spider Hack Tools Plus
Exit code:
0
Version:
2.0.0.0
Modules
Images
c:\users\admin\appdata\roaming\microsoft\windows\screentogif\netprotocol.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2544netsh firewall add allowedprogram "C:\Users\admin\AppData\Roaming\Microsoft\Windows\ScreenToGif\netprotocol.exe" "netprotocol.exe" ENABLEC:\Windows\system32\netsh.exenetprotocol.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Network Command Shell
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\netsh.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\credui.dll
c:\windows\system32\user32.dll
3596"C:\Users\admin\Desktop\Spider Hack Tools Plus\Spider Hack Tools Plus.exe" C:\Users\admin\Desktop\Spider Hack Tools Plus\Spider Hack Tools Plus.exe
explorer.exe
User:
admin
Company:
Spider virus
Integrity Level:
MEDIUM
Description:
Spider Hack Tools Plus
Exit code:
0
Version:
2.0.0.0
Modules
Images
c:\users\admin\desktop\spider hack tools plus\spider hack tools plus.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
Total events
906
Read events
804
Write events
102
Delete events
0

Modification events

(PID) Process:(1968) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(1968) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(1968) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1968) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Spider Hack Tools Plus v1.0 By Spider Virus.rar
(PID) Process:(1968) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(1968) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(1968) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(1968) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(1968) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface
Operation:writeName:ShowPassword
Value:
0
(PID) Process:(1968) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000
Executable files
2
Suspicious files
0
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
1968WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb1968.43337\Spider Hack Tools Plus\Spider Hack Tools Plus.exe
MD5:
SHA256:
3596Spider Hack Tools Plus.exeC:\Users\admin\Documents\man.log
MD5:
SHA256:
3596Spider Hack Tools Plus.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\ScreenToGif\netprotocol.exeexecutable
MD5:
SHA256:
3596Spider Hack Tools Plus.exeC:\Users\admin\AppData\Local\Temp\Spider Hack Tools Plus.exeexecutable
MD5:A1619317FBFD48B128326FD38C9E1E40
SHA256:D5C2D2FAE56F25397E15B605A35F3075D9D98C39196EB3B8ADFECC78E164EDAB
3596Spider Hack Tools Plus.exeC:\Users\admin\AppData\Local\Temp\info.txttext
MD5:E4FB9CBF17BADB04CA4CBD30BC8820F1
SHA256:EF31EE61F5D4797F5166BD8A483A02192B6B8054B5DA9B3842BB3EF61D03CC08
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
1
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

Domain
IP
Reputation
secku03.ddns.net
unknown

Threats

No threats detected
No debug info