analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

6.rar

Full analysis: https://app.any.run/tasks/60e3ded9-73e4-4d30-a878-d4a0f41fb7f0
Verdict: Malicious activity
Analysis date: April 25, 2019, 17:40:08
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

D1BA15FF9B27217E9C6A06625898EA5C

SHA1:

BA7AEC4345166898A1E10A52323501C279ECC373

SHA256:

0D7698CE04FB9B0B29647A698EA4E7B98A6174F44E9AADDE8C2190DA27293EF8

SSDEEP:

24576:BSgyhhx1QdLdPbPpW5r15VWFLIW9apmVW2SVVpi8cY/Q:BSgyhhx1Q51Tp+TVW6WUf2Gg

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • instagram Checker by xRisky.exe (PID: 3476)
      • SearchProtocolHost.exe (PID: 700)
    • Application was dropped or rewritten from another process

      • instagram Checker by xRisky.exe (PID: 3476)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2980)
  • INFO

    • Dropped object may contain Bitcoin addresses

      • WinRAR.exe (PID: 2980)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
33
Monitored processes
3
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe searchprotocolhost.exe no specs instagram checker by xrisky.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2980"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\6.rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.60.0
700"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe5_ Global\UsGthrCtrlFltPipeMssGthrPipe5 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" C:\Windows\System32\SearchProtocolHost.exeSearchIndexer.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Windows Search Protocol Host
Exit code:
0
Version:
7.00.7600.16385 (win7_rtm.090713-1255)
3476"C:\Users\admin\Desktop\instagram Checker by xRisky\instagram Checker by xRisky.exe" C:\Users\admin\Desktop\instagram Checker by xRisky\instagram Checker by xRisky.exeexplorer.exe
User:
admin
Company:
instagram Checker by xRisky
Integrity Level:
MEDIUM
Description:
instagram Checker by xRisky
Version:
1.0.0.0
Total events
774
Read events
764
Write events
10
Delete events
0

Modification events

(PID) Process:(2980) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2980) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2980) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\62\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2980) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\6.rar
(PID) Process:(2980) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2980) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2980) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2980) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(700) SearchProtocolHost.exeKey:HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\62\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(700) SearchProtocolHost.exeKey:HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\62\52C64B7E
Operation:writeName:@C:\Windows\system32\notepad.exe,-469
Value:
Text Document
Executable files
3
Suspicious files
0
Text files
1
Unknown types
2

Dropped files

PID
Process
Filename
Type
2980WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2980.3755\instagram Checker by xRisky\YouTube 2.lnklnk
MD5:DEB42BBEC322CD0B8319F788312E28C4
SHA256:B3BB48A747CC7078D4C4C5BD872A270B59F328AE90A85EF3D955B8A4892BFF41
2980WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2980.3755\instagram Checker by xRisky\Read before using.txttext
MD5:1A85FC37ABD96A54C2307BD5A00C8758
SHA256:D8D52A7D872EBF71C9655F7F7CCE89F276083DE1AAF1F11FF8A859ECA16F9806
2980WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2980.3755\instagram Checker by xRisky\Leaf.xNet.dllexecutable
MD5:42CF916DF4EA1D300201EC9559B7BEF3
SHA256:939C8980BCB9BD9A2279714F6086714229E7AF194EC4E32677C5A4ED96DB5EDD
2980WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2980.3755\instagram Checker by xRisky\instagram Checker by xRisky.exeexecutable
MD5:B2FF1DB56C714C1D0F643C9EFB6255CC
SHA256:F4A5FC9DF76AA68B9778B168FD0924F5C74248E2B639AD6E70ED8585FC4C494D
2980WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2980.3755\instagram Checker by xRisky\MetroSuite 2.0.dllexecutable
MD5:0D30A398CEC0FF006B6EA2B52D11E744
SHA256:8604BF2A1FE2E94DC1EA1FBD0CF54E77303493B93994DF48479DC683580AA654
2980WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2980.3755\instagram Checker by xRisky\YouTube.lnklnk
MD5:C7056A1F92245EEC9E5CA71F406C4811
SHA256:BDE117478E44D3AA7D55122CF450F10B5AF74CFB4CE82AE4FC6FB7DD414C2469
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info