File name:

WinRAR 5.60.exe

Full analysis: https://app.any.run/tasks/f3db19de-7521-4e00-9a14-a40fe2c40034
Verdict: Malicious activity
Analysis date: March 03, 2024, 06:36:47
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

9FC0CEA3C7B046CBDD96369A052D74EC

SHA1:

66F9B24F4ECB56C97EF25989EA29B91AEB77E7E7

SHA256:

0D19163B3D45D233739AD9AE573B8F12246621D0DEC0F62BDA749E95FEA82A38

SSDEEP:

98304:h+fgvkdU6EBCNaRftYMM1Kcs6P2QwE+a4dYzisUJmR7fom+FTBJX9XJfJy/Xbl0v:QwMYj+c7jync5

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • WinRAR 5.60.exe (PID: 3772)
  • SUSPICIOUS

    • Drops 7-zip archiver for unpacking

      • WinRAR 5.60.exe (PID: 3772)
    • Creates a software uninstall entry

      • WinRAR 5.60.exe (PID: 3772)
    • Executable content was dropped or overwritten

      • WinRAR 5.60.exe (PID: 3772)
    • Reads security settings of Internet Explorer

      • WinRAR 5.60.exe (PID: 3772)
    • Reads the Internet Settings

      • WinRAR 5.60.exe (PID: 3772)
  • INFO

    • Checks supported languages

      • WinRAR 5.60.exe (PID: 3772)
    • Reads the computer name

      • WinRAR 5.60.exe (PID: 3772)
    • Create files in a temporary directory

      • WinRAR 5.60.exe (PID: 3772)
    • Creates files in the program directory

      • WinRAR 5.60.exe (PID: 3772)
    • Manual execution by a user

      • WinRAR.exe (PID: 2336)
      • explorer.exe (PID: 2292)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable Delphi generic (37.4)
.scr | Windows screen saver (34.5)
.exe | Win32 Executable (generic) (11.9)
.exe | Win16/32 Executable Delphi generic (5.4)
.exe | Generic Win/DOS Executable (5.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 1992:06:19 22:22:17+00:00
ImageFileCharacteristics: Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 148992
InitializedDataSize: 94720
UninitializedDataSize: -
EntryPoint: 0x25468
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 5.60.0.0
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
Comments: -
CompanyName: RarLab
FileDescription: WinRAR 5.60 Installation
FileVersion: 5.60
LegalCopyright: RarLab
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
46
Monitored processes
4
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar 5.60.exe explorer.exe no specs winrar.exe no specs winrar 5.60.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2292"C:\Windows\explorer.exe" C:\Windows\explorer.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2336"C:\Program Files\WinRAR\WinRAR.exe" C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3668"C:\Users\admin\AppData\Local\Temp\WinRAR 5.60.exe" C:\Users\admin\AppData\Local\Temp\WinRAR 5.60.exeexplorer.exe
User:
admin
Company:
RarLab
Integrity Level:
MEDIUM
Description:
WinRAR 5.60 Installation
Exit code:
3221226540
Version:
5.60
Modules
Images
c:\users\admin\appdata\local\temp\winrar 5.60.exe
c:\windows\system32\ntdll.dll
3772"C:\Users\admin\AppData\Local\Temp\WinRAR 5.60.exe" C:\Users\admin\AppData\Local\Temp\WinRAR 5.60.exe
explorer.exe
User:
admin
Company:
RarLab
Integrity Level:
HIGH
Description:
WinRAR 5.60 Installation
Exit code:
0
Version:
5.60
Modules
Images
c:\users\admin\appdata\local\temp\winrar 5.60.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
Total events
3 574
Read events
3 537
Write events
37
Delete events
0

Modification events

(PID) Process:(3772) WinRAR 5.60.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WinRAR 5.60
Operation:writeName:DisplayName
Value:
WinRAR 5.60
(PID) Process:(3772) WinRAR 5.60.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WinRAR 5.60
Operation:writeName:DisplayVersion
Value:
5.60
(PID) Process:(3772) WinRAR 5.60.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WinRAR 5.60
Operation:writeName:VersionMajor
Value:
5
(PID) Process:(3772) WinRAR 5.60.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WinRAR 5.60
Operation:writeName:VersionMinor
Value:
60
(PID) Process:(3772) WinRAR 5.60.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WinRAR 5.60
Operation:writeName:Publisher
Value:
RarLab
(PID) Process:(3772) WinRAR 5.60.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WinRAR 5.60
Operation:writeName:DisplayIcon
Value:
C:\Program Files\RarLab\WinRAR\Uninstall.exe
(PID) Process:(3772) WinRAR 5.60.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WinRAR 5.60
Operation:writeName:UninstallString
Value:
C:\Program Files\RarLab\WinRAR\Uninstall.exe
(PID) Process:(3772) WinRAR 5.60.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WinRAR 5.60
Operation:writeName:URLInfoAbout
Value:
https://www.rarlab.com/
(PID) Process:(3772) WinRAR 5.60.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WinRAR 5.60
Operation:writeName:HelpLink
Value:
https://www.win-rar.com/support.html
(PID) Process:(3772) WinRAR 5.60.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WinRAR 5.60
Operation:writeName:InstallLocation
Value:
C:\Program Files\RarLab\WinRAR\
Executable files
23
Suspicious files
5
Text files
14
Unknown types
0

Dropped files

PID
Process
Filename
Type
3772WinRAR 5.60.exeC:\Program Files\RarLab\WinRAR\Default.SFXexecutable
MD5:4E28F3B48E79BFF42D75C8E13DE13F20
SHA256:22750BF72F6677CAA44A7B848C193F26CD4BE2F9E4535B8A2BA8BECCB9A76785
3772WinRAR 5.60.exeC:\Program Files\RarLab\WinRAR\License.txttext
MD5:E1933E349789E955BCABC32B09724D11
SHA256:81C82ACFEA1153E4CE86495C551E0E5300E7C9F219A9DFA82DD41FBB26BC528E
3772WinRAR 5.60.exeC:\Program Files\RarLab\WinRAR\DefaultEn64.SFXexecutable
MD5:D266ECB1F37E485874647EF17E70CD62
SHA256:8273C6EB69E697993AEE6DA432F0A62A4B758EA563C9D14CB97B4E4305741714
3772WinRAR 5.60.exeC:\Program Files\RarLab\WinRAR\Default64.SFXexecutable
MD5:51845B84429205CA4D0F31B966F06B0F
SHA256:1A0376085A87D1E2CB4567DE7BFF743F316EBB605410726E9C26568CBB00F170
3772WinRAR 5.60.exeC:\Users\admin\AppData\Local\Temp\$inst\7.tmpimage
MD5:696641D2325E8B142B6C16D1183ACA43
SHA256:4A56FFCE0E414F3495F70E9C2960837DF25423B0DBAFD21A073DBDBAA461BC90
3772WinRAR 5.60.exeC:\Program Files\RarLab\WinRAR\7zxa.dllexecutable
MD5:ECDD19171F5AEA16789257014EE5B85A
SHA256:28B94E646CA51F013DE733DF98D22643F5FDA5008EE55C0115ACC0A872FD499D
3772WinRAR 5.60.exeC:\Users\admin\AppData\Local\Temp\$inst\5.tmpimage
MD5:F4DF6D88CBA8504B5045F16BCE1EC831
SHA256:516DA23AF7E416AAAE943529260237C5235DA025A43A2E3BCF6E46C10A1905A7
3772WinRAR 5.60.exeC:\Users\admin\AppData\Local\Temp\$inst\temp_0.tmpcompressed
MD5:6E4E7D666C1452EDCD7B42FB7CACE03A
SHA256:D02B5B5260F300FE75C874900425CE5B2124D4B40FF220899B9449804CB05D23
3772WinRAR 5.60.exeC:\Program Files\RarLab\WinRAR\descript.iontext
MD5:B760FBA9F19D4B4457A0039DD27F1B2E
SHA256:DEC9E929B8454590FC596B1630B6C1E63270149AC2A85A6354768FC0465E47DA
3772WinRAR 5.60.exeC:\Users\admin\AppData\Local\Temp\$inst\4.tmpimage
MD5:020BA6C9DF321607A67C1702FF4A31F0
SHA256:05A1D475FD0EF6D069135AF0F337878623EBB2D864AB61E7EE2E1146F664846E
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown

DNS requests

No data

Threats

No threats detected
No debug info