analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

90830WP.rar

Full analysis: https://app.any.run/tasks/240191b3-b55b-483c-b40c-24e9b228eaca
Verdict: Malicious activity
Analysis date: July 12, 2020, 22:13:59
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v2.0, os: Win32
MD5:

92B657291DAB2CF7AA8A7935239F52F7

SHA1:

0F6D615C71D3DDB3F9CCF27457A5FE43BA60C8FA

SHA256:

0E16D251B174950077AFE3705A4A715A9A0900537193395EAE78129D02B2A579

SSDEEP:

24576:QNk5YRY9SsUvtTJ3PetqXzOd3cuN2+MeEWJHyOxDNdboE07Poh3+w:QS5UEUvtTJ3uai5cuN2+MeEWr5vboE8U

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Spectrasonics_2048_KeyGen.exe (PID: 564)
      • Spectrasonics_2048_KeyGen.exe (PID: 1952)
      • keygen.exe (PID: 1328)
    • Loads dropped or rewritten executable

      • keygen.exe (PID: 1328)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2184)
      • WinRAR.exe (PID: 2504)
      • Spectrasonics_2048_KeyGen.exe (PID: 564)
    • Application launched itself

      • WinRAR.exe (PID: 2528)
  • INFO

    • Manual execution by user

      • Spectrasonics_2048_KeyGen.exe (PID: 1952)
      • Spectrasonics_2048_KeyGen.exe (PID: 564)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v-4.x) (58.3)
.rar | RAR compressed archive (gen) (41.6)

EXIF

ZIP

ArchivedFileName: Spectrasonics.!Omnisphere.v2.0.Patch.and.Keygen.Only-R2R\Spectrasonics.Omnisphere.v2.0.Patch.and.Keygen.Only-R2R\r2r-3505.rar
PackingMethod: Stored
ModifyDate: 2015:06:18 02:36:08
OperatingSystem: Win32
UncompressedSize: 1238737
CompressedSize: 1238888
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
43
Monitored processes
6
Malicious processes
1
Suspicious processes
1

Behavior graph

Click at the process to see the details
start drop and start winrar.exe no specs winrar.exe winrar.exe spectrasonics_2048_keygen.exe no specs spectrasonics_2048_keygen.exe keygen.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2528"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\90830WP.rar"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
2184"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\Rar$DIa2528.38907\r2r-3505.rarC:\Program Files\WinRAR\WinRAR.exe
WinRAR.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
2504"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\Rar$DIa2528.39435\r2r-3505.rarC:\Program Files\WinRAR\WinRAR.exe
WinRAR.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
1952"C:\Users\admin\Desktop\Spectrasonics_2048_KeyGen.exe" C:\Users\admin\Desktop\Spectrasonics_2048_KeyGen.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
564"C:\Users\admin\Desktop\Spectrasonics_2048_KeyGen.exe" C:\Users\admin\Desktop\Spectrasonics_2048_KeyGen.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
1328C:\Users\admin\AppData\Local\Temp\keygen.exeC:\Users\admin\AppData\Local\Temp\keygen.exeSpectrasonics_2048_KeyGen.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Total events
1 416
Read events
1 341
Write events
0
Delete events
0

Modification events

No data
Executable files
6
Suspicious files
2
Text files
0
Unknown types
1

Dropped files

PID
Process
Filename
Type
1328keygen.exeC:\Users\admin\AppData\Local\Temp\~DFB193059AC7F7258B.TMP
MD5:
SHA256:
564Spectrasonics_2048_KeyGen.exeC:\Users\admin\AppData\Local\Temp\nstACC.tmp
MD5:
SHA256:
2528WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DIa2528.38907\r2r-3505.rarcompressed
MD5:1DA2CDE457A3243FB6904624F5DB98F3
SHA256:02D59F43AA28FD9955EF232CF734639AD4073054EA1C86F01472336B9F050747
564Spectrasonics_2048_KeyGen.exeC:\Users\admin\AppData\Local\Temp\bgm.itit
MD5:31F24C0967530394A64CB82AC06A1E2F
SHA256:E66ACF2363DAB9A21265651887799B00DC1413B2F70155B9B94A4BB9CFF045BB
564Spectrasonics_2048_KeyGen.exeC:\Users\admin\AppData\Local\Temp\R2RSS2048.dllexecutable
MD5:4D97354487A74D33552AFC93A7A8E1B9
SHA256:762548049D64380584D2E77B5499F4BEA16693308EE156618C83F0F0B847B064
2184WinRAR.exeC:\Users\admin\Desktop\Spectrasonics_2048_KeyGen.exeexecutable
MD5:17174BC990FCFD50BD3F2E00A2D82ED4
SHA256:D1436AAE15D42FFFE91BB0E77114BB66B4C97E58111E09AF2A10166790FE6EA1
564Spectrasonics_2048_KeyGen.exeC:\Users\admin\AppData\Local\Temp\keygen.exeexecutable
MD5:F1F1B28254FC2816DF83BC4432A6D7CF
SHA256:62287A6C233820F45E7250CAAE8EE068425ECF1D229E29316D9F0038401A3751
564Spectrasonics_2048_KeyGen.exeC:\Users\admin\AppData\Local\Temp\BASSMOD.dllexecutable
MD5:E4EC57E8508C5C4040383EBE6D367928
SHA256:8AD9E47693E292F381DA42DDC13724A3063040E51C26F4CA8E1F8E2F1DDD547F
2528WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DIa2528.39435\r2r-3505.rarcompressed
MD5:1DA2CDE457A3243FB6904624F5DB98F3
SHA256:02D59F43AA28FD9955EF232CF734639AD4073054EA1C86F01472336B9F050747
564Spectrasonics_2048_KeyGen.exeC:\Users\admin\AppData\Local\Temp\R2RTOOL.dllexecutable
MD5:0B0214CDF2577A43AF135B741D98BC0C
SHA256:D224BED5BBA63C1B222E6628E19615278490C1139804AAFEDE4627DA5BE655CC
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info