analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

NoirBot_v1.8_Clean.rar

Full analysis: https://app.any.run/tasks/4e36f7c3-a34c-42ba-b2c3-8c0b9a7f743b
Verdict: Malicious activity
Analysis date: December 06, 2018, 11:56:23
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

6C65CD197B1F0A82CB5F7220D5BB8CE6

SHA1:

0D90BB5FAADEA17EDA5597B38CF4F7CD2622E1BD

SHA256:

FE90154B3A28996D55C48EC84901297DEF8AAF64AB1E54FC995347D01D9AEF0F

SSDEEP:

196608:eLkz3/oLyKBvq1HYifTB33qNXslNrpsQPG+tcBJmo9JeI:2kz3/oL71ifxqslN9jCdP

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • vsll.exe (PID: 3424)
      • NoirBot v1.8 Clean.exe (PID: 1048)
    • Loads dropped or rewritten executable

      • SearchProtocolHost.exe (PID: 1224)
    • Uses Task Scheduler to run other applications

      • EMP.EXE (PID: 2672)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3648)
      • NoirBot v1.8 Clean.exe (PID: 1048)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
46
Monitored processes
12
Malicious processes
2
Suspicious processes
1

Behavior graph

Click at the process to see the details
start drop and start winrar.exe searchprotocolhost.exe no specs noirbot v1.8 clean.exe vsll.exe no specs emp.sfx.exe no specs vsnj.exe no specs visnj.exe no specs noirbot v1.7 clean.exe no specs emp.exe no specs schtasks.exe no specs schtasks.exe no specs aaypsvoqa.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
3648"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\NoirBot_v1.8_Clean.rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
1224"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe6_ Global\UsGthrCtrlFltPipeMssGthrPipe6 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" C:\Windows\System32\SearchProtocolHost.exeSearchIndexer.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Windows Search Protocol Host
Version:
7.00.7600.16385 (win7_rtm.090713-1255)
1048"C:\Users\admin\Desktop\NoirBot v1.8 Clean\NoirBot v1.8 Clean.exe" C:\Users\admin\Desktop\NoirBot v1.8 Clean\NoirBot v1.8 Clean.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
3424"C:\Users\admin\AppData\Local\Temp\vsll.exe" C:\Users\admin\AppData\Local\Temp\vsll.exeNoirBot v1.8 Clean.exe
User:
admin
Integrity Level:
HIGH
Description:
vs
Version:
1.0.0.0
3632"C:\Users\admin\AppData\Local\Temp\EMP.sfx.exe" C:\Users\admin\AppData\Local\Temp\EMP.sfx.exeNoirBot v1.8 Clean.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
4076"C:\Users\admin\AppData\Local\Temp\vsnj.exe" C:\Users\admin\AppData\Local\Temp\vsnj.exeNoirBot v1.8 Clean.exe
User:
admin
Integrity Level:
HIGH
Description:
vs
Version:
1.0.0.0
2200"C:\Users\admin\AppData\Local\Temp\visnj.exe" C:\Users\admin\AppData\Local\Temp\visnj.exeNoirBot v1.8 Clean.exe
User:
admin
Integrity Level:
HIGH
Description:
Vis
Version:
1.0.0.0
2780"C:\Users\admin\AppData\Local\Temp\NoirBot v1.7 Clean.exe" C:\Users\admin\AppData\Local\Temp\NoirBot v1.7 Clean.exeNoirBot v1.8 Clean.exe
User:
admin
Integrity Level:
HIGH
Description:
Version:
0.0.0.0
2672"C:\Users\admin\AppData\Local\Temp\EMP.EXE" C:\Users\admin\AppData\Local\Temp\EMP.EXEEMP.sfx.exe
User:
admin
Integrity Level:
HIGH
Description:
Version:
0.0.0.0
3384schtasks.exe /create /tn NHHBXFCOVMPT /tr C:\Users\admin\AppData\Local\HKMFRNJQSFYWAKP\SystemProcess.exe /sc minute /mo 1C:\Windows\system32\schtasks.exeEMP.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Manages scheduled tasks
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Total events
1 654
Read events
1 623
Write events
31
Delete events
0

Modification events

(PID) Process:(3648) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3648) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3648) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3648) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\NoirBot_v1.8_Clean.rar
(PID) Process:(3648) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3648) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3648) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3648) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3648) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000
(PID) Process:(3648) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\General
Operation:writeName:LastFolder
Value:
C:\Users\admin\AppData\Local\Temp
Executable files
3
Suspicious files
0
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
1048NoirBot v1.8 Clean.exeC:\Users\admin\AppData\Local\Temp\vsll.exeexecutable
MD5:0F19B3C29029D08F8A337ADB13891970
SHA256:132A3E17BA038B1B4862AF8280C29DE3A0EDDDD1ACC58C19A0CAC921AD2148C2
3648WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3648.42630\NoirBot v1.8 Clean\README.txttext
MD5:46F91FF8868708322BDE1B22DEBF3545
SHA256:819602F7CA3E4F07DF056EA984590FE142ABB6962501B4D9942D9FA4F90EDDA3
3648WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3648.42630\NoirBot v1.8 Clean\NoirBot v1.8 Clean.exeexecutable
MD5:D8EFF476E0B7B8431E21419B35523428
SHA256:40BABA0686DEC92AC8FB0AF4F6E7CC3358FFF5C61D9FA219BCD0A74C84D68EE4
3648WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3648.42630\NoirBot v1.8 Clean\theme.dllexecutable
MD5:3103FE8ACE86424086D97285F12AF135
SHA256:E9011D9FED685DA012D9F5BAEE15872805E52BF73E2B8AA06B2792D20370D653
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info