| File name: | ToxidPP.rar |
| Full analysis: | https://app.any.run/tasks/7a72f412-7a0b-42be-98d6-5a2baa35d73d |
| Verdict: | Malicious activity |
| Analysis date: | March 14, 2022, 04:10:53 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-rar |
| File info: | RAR archive data, v5 |
| MD5: | 0F0060E989FB469D48ABF9C9C11F154B |
| SHA1: | 61A162E4FB461FF60281EED0A22BE0275CB1DEDC |
| SHA256: | FC45A9D72BA77DBC1066743790A71687F51E84652B6B573502D00FC63292C539 |
| SSDEEP: | 6144:eL9EcXS3dp2W+G8KY2RF5GASUP/uUtBLQRW5RknRfB3W6yX8sj8BLRekYBNdiRWz:eL99Ctp21KxrsAjioknJhDe8BLRk3uWz |
| .rar | | | RAR compressed archive (v5.0) (61.5) |
|---|---|---|
| .rar | | | RAR compressed archive (gen) (38.4) |
PID | CMD | Path | Indicators | Parent process |
|---|---|---|---|---|
| 1148 | "C:\Users\admin\Desktop\ToxidPP\ToxidPP.exe" | C:\Users\admin\Desktop\ToxidPP\ToxidPP.exe | — | Explorer.EXE |
User: admin Integrity Level: MEDIUM Description: ToxidPP Exit code: 3221226540 Version: 1.0.0.0 | ||||
| 1324 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\ToxidPP.rar" | C:\Program Files\WinRAR\WinRAR.exe | Explorer.EXE | |
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 | ||||
| 2232 | "C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe3_ Global\UsGthrCtrlFltPipeMssGthrPipe3 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" | C:\Windows\system32\SearchProtocolHost.exe | — | SearchIndexer.exe |
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft Windows Search Protocol Host Exit code: 0 Version: 7.00.7601.24542 (win7sp1_ldr_escrow.191209-2211) | ||||
| 2252 | "C:\Users\admin\Desktop\ToxidPP\ToxidPP.exe" | C:\Users\admin\Desktop\ToxidPP\ToxidPP.exe | Explorer.EXE | |
User: admin Integrity Level: HIGH Description: ToxidPP Exit code: 0 Version: 1.0.0.0 | ||||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1324 | WinRAR.exe | C:\Users\admin\Desktop\ToxidPP\ToxidPP.exe | executable | |
MD5:DFC559E2A5994DBCB4CCFE080FC28CAF | SHA256:9DBAB7AF2FC3FEB7CF356F055A67469212655ED65613FA854AF16BF4DAEDA244 | |||
| 1324 | WinRAR.exe | C:\Users\admin\Desktop\ToxidPP\DiscordRPC.dll | executable | |
MD5:AD463F573775C43A561ADE842C41B0E8 | SHA256:6A18DFC8BDC6030787B5814C76B8663DBE5B8CA469BEB65A2CA9F5731FA1906F | |||
| 1324 | WinRAR.exe | C:\Users\admin\Desktop\ToxidPP\DiscordRPC.xml | xml | |
MD5:07DCEB643B73DD3B700DCF82E1D6663A | SHA256:24FC42B9582988ED65E5F003AA8E44358691A58F5DB6A0E8821560C0FE9B2EE4 | |||
| 1324 | WinRAR.exe | C:\Users\admin\Desktop\ToxidPP\Newtonsoft.Json.dll | executable | |
MD5:4DF6C8781E70C3A4912B5BE796E6D337 | SHA256:3598CCCAD5B535FEA6F93662107A4183BFD6167BF1D0F80260436093EDC2E3AF | |||
| 1324 | WinRAR.exe | C:\Users\admin\Desktop\ToxidPP\Newtonsoft.Json.xml | xml | |
MD5:ED67AC96769018255050AC0829CA459A | SHA256:F32ED922FE5B22DD693E160AEE4F0DCAB753EBD740BED40490AE4179274B4B49 | |||