File name:

firefox (pass - infected).rar

Full analysis: https://app.any.run/tasks/f6978744-5ff1-4ee3-b045-a63cb3df247a
Verdict: Malicious activity
Analysis date: May 11, 2025, 13:46:14
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
arch-exec
Indicators:
MIME: application/x-rar
File info: RAR archive data, v4, os: Win32
MD5:

184B530684BFAC1236DB3B0A40DC105B

SHA1:

0DD8C278B7C3E0D8EBFBEED539A7ABCB9AB99A15

SHA256:

0234FCEF72EA4E6F3704DFDA627AEE56F8C4D1151C815D93AB7FFA0B0E19253B

SSDEEP:

1536:Fw2RHPAEoVaB/Vw05/rzZ2El1/nLv4hhZUiVieQ3+04kYj6:+2Wbe/n5HZ2Y1/nLAhhNVieQ3B4kYu

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • firefox.exe (PID: 1500)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • firefox.exe (PID: 1500)
    • Reads the Internet Settings

      • firefox.exe (PID: 1500)
      • firefox.exe (PID: 704)
    • Reads security settings of Internet Explorer

      • firefox.exe (PID: 1500)
      • firefox.exe (PID: 704)
    • Starts CMD.EXE for commands execution

      • firefox.exe (PID: 1500)
    • Executing commands from a ".bat" file

      • firefox.exe (PID: 1500)
    • Starts itself from another location

      • firefox.exe (PID: 1500)
    • There is functionality for taking screenshot (YARA)

      • firefox.exe (PID: 704)
  • INFO

    • Manual execution by a user

      • firefox.exe (PID: 1500)
    • Creates files or folders in the user directory

      • firefox.exe (PID: 1500)
    • The sample compiled with english language support

      • WinRAR.exe (PID: 2812)
      • firefox.exe (PID: 1500)
    • Checks supported languages

      • firefox.exe (PID: 1500)
      • firefox.exe (PID: 704)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2812)
    • Reads the computer name

      • firefox.exe (PID: 1500)
      • firefox.exe (PID: 704)
    • Checks proxy server information

      • firefox.exe (PID: 704)
    • Reads the machine GUID from the registry

      • firefox.exe (PID: 704)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v-4.x) (58.3)
.rar | RAR compressed archive (gen) (41.6)

EXIF

ZIP

FileVersion: RAR v4
CompressedSize: 62232
UncompressedSize: 65536
OperatingSystem: Win32
ModifyDate: 2008:10:29 07:29:40
PackingMethod: Best Compression
ArchivedFileName: firefox.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
44
Monitored processes
4
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe firefox.exe cmd.exe no specs firefox.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
704"C:\Users\admin\AppData\Roaming\Mozilla\Firefox\firefox.exe" C:\Users\admin\AppData\Roaming\Mozilla\Firefox\firefox.exefirefox.exe
User:
admin
Integrity Level:
HIGH
Modules
Images
c:\users\admin\appdata\roaming\mozilla\firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\gdi32.dll
1500"C:\Users\admin\Desktop\firefox.exe" C:\Users\admin\Desktop\firefox.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\desktop\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\gdi32.dll
2812"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\firefox (pass - infected).rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3096C:\Windows\system32\cmd.exe /c ""C:\Users\admin\Desktop\clean.bat" "C:\Windows\System32\cmd.exefirefox.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
1
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
Total events
2 512
Read events
2 437
Write events
66
Delete events
9

Modification events

(PID) Process:(2812) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2812) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(2812) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(2812) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(2812) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\firefox (pass - infected).rar
(PID) Process:(2812) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2812) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2812) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2812) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2812) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
Executable files
2
Suspicious files
0
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
1500firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\firefox.exeexecutable
MD5:0F31BCF2BC607097B12EEC7D74D9BE9E
SHA256:E10240A117DAAFC802B5004B757470F777F821875EBB2428BA4BC3298590ABC7
2812WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb2812.49130\firefox.exeexecutable
MD5:0F31BCF2BC607097B12EEC7D74D9BE9E
SHA256:E10240A117DAAFC802B5004B757470F777F821875EBB2428BA4BC3298590ABC7
1500firefox.exeC:\Users\admin\Desktop\clean.battext
MD5:5B80DFBCB5674C8C02368EB1BE05A5C2
SHA256:A3B22FE263BA276E84AF833464E04E9FF722809F26ECD88F4595173867F3A79C
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
5
DNS requests
4
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
224.0.0.252:5355
whitelisted
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.185.110
whitelisted
restlezma.info
unknown
quiwerw.info
unknown
apoqwdsd.info
unknown

Threats

No threats detected
No debug info