File name:

a7994f9aa26ba3ea2efb963904671f7fe448df042b3341ec3502cbc7c5e67ed77ea0888b

Full analysis: https://app.any.run/tasks/61486891-37b6-41e0-adf3-e5a114ddfa40
Verdict: Malicious activity
Analysis date: September 30, 2020, 10:59:29
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

A7994F9AA26BA3EA2EFB963904671F7F

SHA1:

E448DF042B3341EC3502CBC7C5E67ED77EA0888B

SHA256:

0F01F469DC49ACE8969FA49E0B4E32FC55E0A359AAB3F360112967BEBF1A6D93

SSDEEP:

12288:EnlkG1Lfgk6i4SDa2SsvJf+f25YQbEC5j/dbbLyE5:EnlkGpVa2X1EU95bdbSE5

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • 我司已汇$23856 (Our remitted $ 23856).exe (PID: 2768)
      • 我司已汇$23856 (Our remitted $ 23856).exe (PID: 3776)
      • 我司已汇$23856 (Our remitted $ 23856).exe (PID: 2436)
    • Uses Task Scheduler to run other applications

      • 我司已汇$23856 (Our remitted $ 23856).exe (PID: 3776)
      • 我司已汇$23856 (Our remitted $ 23856).exe (PID: 2768)
      • 我司已汇$23856 (Our remitted $ 23856).exe (PID: 2436)
    • Loads the Task Scheduler COM API

      • schtasks.exe (PID: 3228)
      • schtasks.exe (PID: 1244)
      • schtasks.exe (PID: 1928)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2496)
      • 我司已汇$23856 (Our remitted $ 23856).exe (PID: 3776)
    • Creates files in the user directory

      • 我司已汇$23856 (Our remitted $ 23856).exe (PID: 3776)
  • INFO

    • Manual execution by user

      • 我司已汇$23856 (Our remitted $ 23856).exe (PID: 2436)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
47
Monitored processes
10
Malicious processes
1
Suspicious processes
3

Behavior graph

Click at the process to see the details
drop and start drop and start start winrar.exe 我司已汇$23856 (our remitted $ 23856).exe 我司已汇$23856 (our remitted $ 23856).exe 我司已汇$23856 (our remitted $ 23856).exe schtasks.exe no specs dw20.exe no specs schtasks.exe no specs dw20.exe no specs schtasks.exe no specs dw20.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1244"C:\Windows\System32\schtasks.exe" /Create /TN "Updates\UfqJVSjbq" /XML "C:\Users\admin\AppData\Local\Temp\tmpE309.tmp"C:\Windows\System32\schtasks.exe我司已汇$23856 (Our remitted $ 23856).exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Manages scheduled tasks
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\schtasks.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
1928"C:\Windows\System32\schtasks.exe" /Create /TN "Updates\UfqJVSjbq" /XML "C:\Users\admin\AppData\Local\Temp\tmp629A.tmp"C:\Windows\System32\schtasks.exe我司已汇$23856 (Our remitted $ 23856).exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Manages scheduled tasks
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\schtasks.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
2140dw20.exe -x -s 860C:\Windows\Microsoft.NET\Framework\v2.0.50727\dw20.exe我司已汇$23856 (Our remitted $ 23856).exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft .NET Error Reporting Shim
Exit code:
0
Version:
2.0.50727.4927 (NetFXspW7.050727-4900)
Modules
Images
c:\windows\microsoft.net\framework\v2.0.50727\dw20.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc\msvcr80.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
2304dw20.exe -x -s 856C:\Windows\Microsoft.NET\Framework\v2.0.50727\dw20.exe我司已汇$23856 (Our remitted $ 23856).exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft .NET Error Reporting Shim
Exit code:
0
Version:
2.0.50727.4927 (NetFXspW7.050727-4900)
Modules
Images
c:\windows\microsoft.net\framework\v2.0.50727\dw20.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc\msvcr80.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
2436"C:\Users\admin\Desktop\我司已汇$23856 (Our remitted $ 23856).exe" C:\Users\admin\Desktop\我司已汇$23856 (Our remitted $ 23856).exe
explorer.exe
User:
admin
Company:
C.S.D Team
Integrity Level:
MEDIUM
Description:
Folder Protector
Exit code:
0
Version:
18.3.0.3
Modules
Images
c:\users\admin\desktop\我司已汇$23856 (our remitted $ 23856).exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2496"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\a7994f9aa26ba3ea2efb963904671f7fe448df042b3341ec3502cbc7c5e67ed77ea0888b.rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2768"C:\Users\admin\AppData\Local\Temp\Rar$EXa2496.43840\我司已汇$23856 (Our remitted $ 23856).exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa2496.43840\我司已汇$23856 (Our remitted $ 23856).exe
WinRAR.exe
User:
admin
Company:
C.S.D Team
Integrity Level:
MEDIUM
Description:
Folder Protector
Exit code:
3762507597
Version:
18.3.0.3
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2496.43840\我司已汇$23856 (our remitted $ 23856).exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2928dw20.exe -x -s 856C:\Windows\Microsoft.NET\Framework\v2.0.50727\dw20.exe我司已汇$23856 (Our remitted $ 23856).exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft .NET Error Reporting Shim
Exit code:
0
Version:
2.0.50727.4927 (NetFXspW7.050727-4900)
Modules
Images
c:\windows\microsoft.net\framework\v2.0.50727\dw20.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc\msvcr80.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
3228"C:\Windows\System32\schtasks.exe" /Create /TN "Updates\UfqJVSjbq" /XML "C:\Users\admin\AppData\Local\Temp\tmpD965.tmp"C:\Windows\System32\schtasks.exe我司已汇$23856 (Our remitted $ 23856).exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Manages scheduled tasks
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\schtasks.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
3776"C:\Users\admin\AppData\Local\Temp\Rar$EXa2496.43506\我司已汇$23856 (Our remitted $ 23856).exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa2496.43506\我司已汇$23856 (Our remitted $ 23856).exe
WinRAR.exe
User:
admin
Company:
C.S.D Team
Integrity Level:
MEDIUM
Description:
Folder Protector
Exit code:
3762507597
Version:
18.3.0.3
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2496.43506\我司已汇$23856 (our remitted $ 23856).exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
Total events
700
Read events
663
Write events
37
Delete events
0

Modification events

(PID) Process:(2496) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2496) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2496) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\13B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2496) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\a7994f9aa26ba3ea2efb963904671f7fe448df042b3341ec3502cbc7c5e67ed77ea0888b.rar
(PID) Process:(2496) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2496) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2496) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2496) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2496) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(2496) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
Executable files
4
Suspicious files
2
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
3776我司已汇$23856 (Our remitted $ 23856).exeC:\Users\admin\AppData\Local\Temp\tmpD965.tmp
MD5:
SHA256:
2768我司已汇$23856 (Our remitted $ 23856).exeC:\Users\admin\AppData\Local\Temp\tmpE309.tmp
MD5:
SHA256:
2496WinRAR.exeC:\Users\admin\Desktop\我司已汇$23856 (Our remitted $ 23856).exeexecutable
MD5:
SHA256:
2496WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2496.43506\我司已汇$23856 (Our remitted $ 23856).exeexecutable
MD5:
SHA256:
2928dw20.exeC:\Users\admin\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_LXWYYB2L4QXOP4KY_3ca99b877b602331fdc5fd9646ca1ce96b8bd261_0b6c3e29\Report.werbinary
MD5:
SHA256:
2436我司已汇$23856 (Our remitted $ 23856).exeC:\Users\admin\AppData\Local\Temp\tmp629A.tmpxml
MD5:
SHA256:
2496WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2496.43840\我司已汇$23856 (Our remitted $ 23856).exeexecutable
MD5:
SHA256:
3776我司已汇$23856 (Our remitted $ 23856).exeC:\Users\admin\AppData\Roaming\UfqJVSjbq.exeexecutable
MD5:
SHA256:
2140dw20.exeC:\Users\admin\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_LXWYYB2L4QXOP4KY_3ca99b877b602331fdc5fd9646ca1ce96b8bd261_0840523e\Report.werbinary
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info