File name:

WinRAR 5.60.exe

Full analysis: https://app.any.run/tasks/f3db19de-7521-4e00-9a14-a40fe2c40034
Verdict: Malicious activity
Analysis date: March 03, 2024, 06:36:47
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

9FC0CEA3C7B046CBDD96369A052D74EC

SHA1:

66F9B24F4ECB56C97EF25989EA29B91AEB77E7E7

SHA256:

0D19163B3D45D233739AD9AE573B8F12246621D0DEC0F62BDA749E95FEA82A38

SSDEEP:

98304:h+fgvkdU6EBCNaRftYMM1Kcs6P2QwE+a4dYzisUJmR7fom+FTBJX9XJfJy/Xbl0v:QwMYj+c7jync5

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • WinRAR 5.60.exe (PID: 3772)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR 5.60.exe (PID: 3772)
    • Drops 7-zip archiver for unpacking

      • WinRAR 5.60.exe (PID: 3772)
    • Creates a software uninstall entry

      • WinRAR 5.60.exe (PID: 3772)
    • Reads the Internet Settings

      • WinRAR 5.60.exe (PID: 3772)
    • Reads security settings of Internet Explorer

      • WinRAR 5.60.exe (PID: 3772)
  • INFO

    • Reads the computer name

      • WinRAR 5.60.exe (PID: 3772)
    • Checks supported languages

      • WinRAR 5.60.exe (PID: 3772)
    • Creates files in the program directory

      • WinRAR 5.60.exe (PID: 3772)
    • Create files in a temporary directory

      • WinRAR 5.60.exe (PID: 3772)
    • Manual execution by a user

      • explorer.exe (PID: 2292)
      • WinRAR.exe (PID: 2336)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable Delphi generic (37.4)
.scr | Windows screen saver (34.5)
.exe | Win32 Executable (generic) (11.9)
.exe | Win16/32 Executable Delphi generic (5.4)
.exe | Generic Win/DOS Executable (5.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 1992:06:19 22:22:17+00:00
ImageFileCharacteristics: Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 148992
InitializedDataSize: 94720
UninitializedDataSize: -
EntryPoint: 0x25468
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 5.60.0.0
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
Comments: -
CompanyName: RarLab
FileDescription: WinRAR 5.60 Installation
FileVersion: 5.60
LegalCopyright: RarLab
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
46
Monitored processes
4
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar 5.60.exe explorer.exe no specs winrar.exe no specs winrar 5.60.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2292"C:\Windows\explorer.exe" C:\Windows\explorer.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2336"C:\Program Files\WinRAR\WinRAR.exe" C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3668"C:\Users\admin\AppData\Local\Temp\WinRAR 5.60.exe" C:\Users\admin\AppData\Local\Temp\WinRAR 5.60.exeexplorer.exe
User:
admin
Company:
RarLab
Integrity Level:
MEDIUM
Description:
WinRAR 5.60 Installation
Exit code:
3221226540
Version:
5.60
Modules
Images
c:\users\admin\appdata\local\temp\winrar 5.60.exe
c:\windows\system32\ntdll.dll
3772"C:\Users\admin\AppData\Local\Temp\WinRAR 5.60.exe" C:\Users\admin\AppData\Local\Temp\WinRAR 5.60.exe
explorer.exe
User:
admin
Company:
RarLab
Integrity Level:
HIGH
Description:
WinRAR 5.60 Installation
Exit code:
0
Version:
5.60
Modules
Images
c:\users\admin\appdata\local\temp\winrar 5.60.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
Total events
3 574
Read events
3 537
Write events
37
Delete events
0

Modification events

(PID) Process:(3772) WinRAR 5.60.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WinRAR 5.60
Operation:writeName:DisplayName
Value:
WinRAR 5.60
(PID) Process:(3772) WinRAR 5.60.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WinRAR 5.60
Operation:writeName:DisplayVersion
Value:
5.60
(PID) Process:(3772) WinRAR 5.60.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WinRAR 5.60
Operation:writeName:VersionMajor
Value:
5
(PID) Process:(3772) WinRAR 5.60.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WinRAR 5.60
Operation:writeName:VersionMinor
Value:
60
(PID) Process:(3772) WinRAR 5.60.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WinRAR 5.60
Operation:writeName:Publisher
Value:
RarLab
(PID) Process:(3772) WinRAR 5.60.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WinRAR 5.60
Operation:writeName:DisplayIcon
Value:
C:\Program Files\RarLab\WinRAR\Uninstall.exe
(PID) Process:(3772) WinRAR 5.60.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WinRAR 5.60
Operation:writeName:UninstallString
Value:
C:\Program Files\RarLab\WinRAR\Uninstall.exe
(PID) Process:(3772) WinRAR 5.60.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WinRAR 5.60
Operation:writeName:URLInfoAbout
Value:
https://www.rarlab.com/
(PID) Process:(3772) WinRAR 5.60.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WinRAR 5.60
Operation:writeName:HelpLink
Value:
https://www.win-rar.com/support.html
(PID) Process:(3772) WinRAR 5.60.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WinRAR 5.60
Operation:writeName:InstallLocation
Value:
C:\Program Files\RarLab\WinRAR\
Executable files
23
Suspicious files
5
Text files
14
Unknown types
0

Dropped files

PID
Process
Filename
Type
3772WinRAR 5.60.exeC:\Users\admin\AppData\Local\Temp\$inst\2.tmpcompressed
MD5:9AB9332B5E860735D2543DDEFA3D2BC1
SHA256:7B45644DEF817272C84BA385B037701AE3269DD69951B0BD048DD7D1060345F0
3772WinRAR 5.60.exeC:\Program Files\RarLab\WinRAR\Ace32Loader.exeexecutable
MD5:E3763B3CBC04A02653481AAEA8FC2E82
SHA256:823ABC32E19EB0354C41FF0568DDDCEB732595FBA1E3D80154FE046951B337A3
3772WinRAR 5.60.exeC:\Program Files\RarLab\WinRAR\RarLng.dllexecutable
MD5:50744ADDBBC30418687743C8E13246BC
SHA256:B1D05CEC1259111B89F1F6896D5F8137F6200DE623C93E3F7DFDD100B616506A
3772WinRAR 5.60.exeC:\Program Files\RarLab\WinRAR\License.txttext
MD5:E1933E349789E955BCABC32B09724D11
SHA256:81C82ACFEA1153E4CE86495C551E0E5300E7C9F219A9DFA82DD41FBB26BC528E
3772WinRAR 5.60.exeC:\Program Files\RarLab\WinRAR\descript.iontext
MD5:B760FBA9F19D4B4457A0039DD27F1B2E
SHA256:DEC9E929B8454590FC596B1630B6C1E63270149AC2A85A6354768FC0465E47DA
3772WinRAR 5.60.exeC:\Program Files\RarLab\WinRAR\Rar.exeexecutable
MD5:A3AF8F589A1D693FE9DE72099AAEE783
SHA256:2CF58A93DBAC2EAA7C3334FC1343C78956866AB46FF6D16E5AA48F2B463ED61E
3772WinRAR 5.60.exeC:\Program Files\RarLab\WinRAR\RarExt32.dllexecutable
MD5:529953E3D949AE27F017298FB1CA2687
SHA256:A7E52CA0863B84B2AAB85944DED2B33CCD6C319989111B82D75616DA1707825F
3772WinRAR 5.60.exeC:\Program Files\RarLab\WinRAR\Default64.SFXexecutable
MD5:51845B84429205CA4D0F31B966F06B0F
SHA256:1A0376085A87D1E2CB4567DE7BFF743F316EBB605410726E9C26568CBB00F170
3772WinRAR 5.60.exeC:\Program Files\RarLab\WinRAR\Default.SFXexecutable
MD5:4E28F3B48E79BFF42D75C8E13DE13F20
SHA256:22750BF72F6677CAA44A7B848C193F26CD4BE2F9E4535B8A2BA8BECCB9A76785
3772WinRAR 5.60.exeC:\Program Files\RarLab\WinRAR\DefaultEn64.SFXexecutable
MD5:D266ECB1F37E485874647EF17E70CD62
SHA256:8273C6EB69E697993AEE6DA432F0A62A4B758EA563C9D14CB97B4E4305741714
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown

DNS requests

No data

Threats

No threats detected
No debug info