File name:

Netflix Gift Card Checker Prv8.rar

Full analysis: https://app.any.run/tasks/9066a4c8-ba42-44c9-b8e7-df67d8809f54
Verdict: Malicious activity
Analysis date: March 21, 2019, 10:23:08
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

773B73CBF4B1809D4451AF23FDB949F3

SHA1:

ABB55EB539A52B558E6E7A661174788B9DF6013C

SHA256:

FC76537C23749111D72202F8D3DF43451320D7EF68574CE75C729DC3D9CBE1BD

SSDEEP:

24576:s8jVl+U9zO5wgkqV0/68XkCy9kayAl8V4bgVNH+vIPWI6JguKUdm1iQXrwCXS:sI9Wwgk/HXQkayQ1sH+geIJu7Ag0zS

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • giftcard_code_gen.exe (PID: 3296)
      • giftcard_code_gen.exe (PID: 3292)
    • Loads dropped or rewritten executable

      • SearchProtocolHost.exe (PID: 1100)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3004)
      • WinRAR.exe (PID: 2696)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
47
Monitored processes
6
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe searchprotocolhost.exe no specs winrar.exe giftcard_code_gen.exe notepad.exe no specs giftcard_code_gen.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1100"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe4_ Global\UsGthrCtrlFltPipeMssGthrPipe4 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" C:\Windows\System32\SearchProtocolHost.exeSearchIndexer.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Windows Search Protocol Host
Exit code:
0
Version:
7.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\searchprotocolhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1140"C:\Windows\system32\NOTEPAD.EXE" C:\Users\admin\Desktop\giftcard_code_gen\fffdd.txtC:\Windows\system32\NOTEPAD.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\notepad.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2696"C:\Program Files\WinRAR\WinRAR.exe" x -iext -ow -ver -- "C:\Users\admin\Desktop\giftcard_code_gen.rar" C:\Users\admin\Desktop\giftcard_code_gen\C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3004"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Netflix Gift Card Checker Prv8.rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3292"C:\Users\admin\Desktop\giftcard_code_gen\giftcard_code_gen.exe" C:\Users\admin\Desktop\giftcard_code_gen\giftcard_code_gen.exeexplorer.exe
User:
admin
Company:
HP Inc.
Integrity Level:
MEDIUM
Description:
LXM Generator
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\giftcard_code_gen\giftcard_code_gen.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3296"C:\Users\admin\Desktop\giftcard_code_gen\giftcard_code_gen.exe" C:\Users\admin\Desktop\giftcard_code_gen\giftcard_code_gen.exe
explorer.exe
User:
admin
Company:
HP Inc.
Integrity Level:
MEDIUM
Description:
LXM Generator
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\giftcard_code_gen\giftcard_code_gen.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
Total events
2 047
Read events
1 855
Write events
181
Delete events
11

Modification events

(PID) Process:(3004) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3004) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3004) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\62\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3004) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Netflix Gift Card Checker Prv8.rar
(PID) Process:(3004) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3004) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3004) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3004) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3004) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\DialogEditHistory\ExtrPath
Operation:writeName:0
Value:
C:\Users\admin\Desktop
(PID) Process:(1100) SearchProtocolHost.exeKey:HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\62\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
Executable files
4
Suspicious files
1
Text files
182
Unknown types
2

Dropped files

PID
Process
Filename
Type
3004WinRAR.exeC:\Users\admin\Desktop\giftcard_code_gen.rarcompressed
MD5:
SHA256:
3004WinRAR.exeC:\Users\admin\Desktop\Netflix Gift Card Checker by xRisky\Leaf.xNet.dllexecutable
MD5:42CF916DF4EA1D300201EC9559B7BEF3
SHA256:939C8980BCB9BD9A2279714F6086714229E7AF194EC4E32677C5A4ED96DB5EDD
3296giftcard_code_gen.exeC:\Users\admin\Desktop\giftcard_code_gen\fffdd.txttext
MD5:
SHA256:
3004WinRAR.exeC:\Users\admin\Desktop\Netflix Gift Card Checker by xRisky\YouTube 2.lnklnk
MD5:DEB42BBEC322CD0B8319F788312E28C4
SHA256:B3BB48A747CC7078D4C4C5BD872A270B59F328AE90A85EF3D955B8A4892BFF41
3004WinRAR.exeC:\Users\admin\Desktop\Netflix Gift Card Checker by xRisky\YouTube.lnklnk
MD5:C7056A1F92245EEC9E5CA71F406C4811
SHA256:BDE117478E44D3AA7D55122CF450F10B5AF74CFB4CE82AE4FC6FB7DD414C2469
3004WinRAR.exeC:\Users\admin\Desktop\Netflix Gift Card Checker by xRisky\Netflix GC Checker Pr8.exeexecutable
MD5:
SHA256:
3004WinRAR.exeC:\Users\admin\Desktop\Netflix Gift Card Checker by xRisky\jjjjjj.txttext
MD5:
SHA256:
3004WinRAR.exeC:\Users\admin\Desktop\Netflix Gift Card Checker by xRisky\MetroSuite 2.0.dllexecutable
MD5:0D30A398CEC0FF006B6EA2B52D11E744
SHA256:8604BF2A1FE2E94DC1EA1FBD0CF54E77303493B93994DF48479DC683580AA654
3004WinRAR.exeC:\Users\admin\Desktop\Netflix Gift Card Checker by xRisky\Read before using.txttext
MD5:6DAEBB9555014EA4CA81161FDF5955D9
SHA256:63C60F2A04A1F40D3784F7818A816D111E3A9522F526BCCA891EDC2BB5E774FC
2696WinRAR.exeC:\Users\admin\Desktop\giftcard_code_gen\giftcard_code_gen.exeexecutable
MD5:C27BC2893245FE99DE143A41EA63F387
SHA256:7D5D4C822A57525F836E14AAC04435642FD3FCE9F6C3EED668E58E62B77B4358
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
Process
Message
giftcard_code_gen.exe
1 1 1
giftcard_code_gen.exe
1 1 1
giftcard_code_gen.exe
1 1 1
giftcard_code_gen.exe
1 1 1