File name:

Synthesia.rar

Full analysis: https://app.any.run/tasks/6e639788-afab-469d-89c9-59e05a74247d
Verdict: Malicious activity
Analysis date: September 22, 2018, 21:31:34
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v4, os: Win32
MD5:

7BA2048D946FC42C4E8AE09BACA898F1

SHA1:

A04CD3E8B178075A4CE3966A75BEDBC923C737F2

SHA256:

04472CEDE7471B02AC06E411D5E34424AB93DA6D1828F108835C014353BDD115

SSDEEP:

49152:TCFkk7crYgcQQgWbYDqSjMn8kzixkzifNaIWtduQjcv8dZSXbEZF6ywe7ahSRO6M:eFDQrYg8gZjM8kzixoi1YE8SLvFsahSg

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Synthesia.9.x-patch.exe (PID: 1840)
      • synthesia-9.0-installer.exe (PID: 4012)
      • Synthesia.9.x-patch.exe (PID: 3888)
      • synthesia-9.0-installer.exe (PID: 4064)
    • Loads dropped or rewritten executable

      • Synthesia.9.x-patch.exe (PID: 3888)
      • synthesia-9.0-installer.exe (PID: 4064)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2684)
      • Synthesia.9.x-patch.exe (PID: 3888)
      • synthesia-9.0-installer.exe (PID: 4064)
    • Creates files in the program directory

      • synthesia-9.0-installer.exe (PID: 4064)
    • Creates a software uninstall entry

      • synthesia-9.0-installer.exe (PID: 4064)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v-4.x) (58.3)
.rar | RAR compressed archive (gen) (41.6)

EXIF

ZIP

CompressedSize: 2804500
UncompressedSize: 2821848
OperatingSystem: Win32
ModifyDate: 2017:09:13 16:04:11
PackingMethod: Normal
ArchivedFileName: synthesia-9.0-installer.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
43
Monitored processes
5
Malicious processes
2
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe synthesia.9.x-patch.exe no specs synthesia.9.x-patch.exe synthesia-9.0-installer.exe no specs synthesia-9.0-installer.exe

Process information

PID
CMD
Path
Indicators
Parent process
1840"C:\Users\admin\AppData\Local\Temp\Rar$EXa2684.10192\Synthesia.9.x-patch.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa2684.10192\Synthesia.9.x-patch.exeWinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2684.10192\synthesia.9.x-patch.exe
c:\systemroot\system32\ntdll.dll
2684"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Synthesia.rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3888"C:\Users\admin\AppData\Local\Temp\Rar$EXa2684.10192\Synthesia.9.x-patch.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa2684.10192\Synthesia.9.x-patch.exe
WinRAR.exe
User:
admin
Integrity Level:
HIGH
Exit code:
3221225547
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2684.10192\synthesia.9.x-patch.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\temp\dup2patcher.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\comdlg32.dll
4012"C:\Users\admin\AppData\Local\Temp\Rar$EXa2684.10937\synthesia-9.0-installer.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa2684.10937\synthesia-9.0-installer.exeWinRAR.exe
User:
admin
Company:
Synthesia LLC
Integrity Level:
MEDIUM
Description:
Synthesia 9 Installer
Exit code:
3221226540
Version:
9.0.0.2495
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2684.10937\synthesia-9.0-installer.exe
c:\systemroot\system32\ntdll.dll
4064"C:\Users\admin\AppData\Local\Temp\Rar$EXa2684.10937\synthesia-9.0-installer.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa2684.10937\synthesia-9.0-installer.exe
WinRAR.exe
User:
admin
Company:
Synthesia LLC
Integrity Level:
HIGH
Description:
Synthesia 9 Installer
Exit code:
0
Version:
9.0.0.2495
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2684.10937\synthesia-9.0-installer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
Total events
796
Read events
764
Write events
32
Delete events
0

Modification events

(PID) Process:(2684) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2684) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2684) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2684) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Synthesia.rar
(PID) Process:(2684) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2684) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2684) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2684) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2684) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(2684) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
Executable files
10
Suspicious files
0
Text files
4
Unknown types
182

Dropped files

PID
Process
Filename
Type
3888Synthesia.9.x-patch.exeC:\Users\admin\AppData\Local\Temp\dup2patcher.dllexecutable
MD5:B7DBCBD4405EBA36DD7149B1019715AB
SHA256:3F94EF035C5F0230162CDCA28E0969F978B0A7EB6D7A44D6B5AB3F650273A7F2
2684WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2684.10937\synthesia-9.0-installer.exeexecutable
MD5:CA89286C0DB575E38303FD6727E62952
SHA256:99666C93BD83F9ADA1A92F87BCAA590C4FEC7D9165E17ACB555D8D3DCD38A381
2684WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2684.10192\Synthesia.9.x-patch.exeexecutable
MD5:1D29457A8333131B90BDB6294A54334F
SHA256:4E3EF1A24692863FE53DAA1AE020757AB1CCDED83F9C957E96053C5586FC6D03
4064synthesia-9.0-installer.exeC:\Users\admin\Documents\Synthesia Music\G Major Music\G Major Music.txttext
MD5:7604FB72643F16EFC8F49013BE5B7805
SHA256:5DC5EF268006055325BA4920383BEFD562051B213AEACE458D971C00B6F4E822
4064synthesia-9.0-installer.exeC:\Users\admin\Documents\Synthesia Music\G Major Music\0.0 - First Pieces\A Tisket, A Tasket.midmid
MD5:92659C04C4176CCA36CB09D15BC20185
SHA256:8703646F125B4159D2871E4955CC9B013B310EF6D1376AF9ED176EA0D250EAE8
4064synthesia-9.0-installer.exeC:\Users\admin\Documents\Synthesia Music\G Major Music\0.0 - First Pieces\Au Clair de la Lune.midmid
MD5:2FA6392877A644122E8685A968010F28
SHA256:BB233552A367A98AE786CB1EDC1BB7E4271554B5F9EE7F2C9DEEE62577F3EEF8
4064synthesia-9.0-installer.exeC:\Program Files\Synthesia\license.txttext
MD5:E24A531292B52BA117F64AB4F3D10891
SHA256:57EC3CF96237305F5CF547483A2198D024F91099A360E85F38B2A35E92B50881
4064synthesia-9.0-installer.exeC:\Users\admin\Documents\Synthesia Music\G Major Music\0.0 - First Pieces\Away in the Deep Forest.midmid
MD5:87AB86C589237FD6B975175FFDEBEC64
SHA256:7CC210EA2B1B1C008302CFB1F38BBFC29BAA96498248A39BF67121229D0BAD5D
4064synthesia-9.0-installer.exeC:\Users\admin\Documents\Synthesia Music\G Major Music\0.0 - First Pieces\Chopsticks (Short Version).midmid
MD5:AA8BAD5BCD62572CB589ED75340EAAAD
SHA256:4F8B3A9D05F96ECF7A8B6E77FD234C3BD9C8DBE2316F9AF0AACF2BD3BC0A5820
4064synthesia-9.0-installer.exeC:\Users\admin\Documents\Synthesia Music\G Major Music\0.0 - First Pieces\Aura Lee (Love Me Tender).midmid
MD5:19C3E3DDBD05B37B31676BAD591E198A
SHA256:F152E8FCD7D210ACA6636F5D125534F961CE6F1E845315EBEA3257A1B27DD490
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info