File name:

AIOSCREENSMALL.rar

Full analysis: https://app.any.run/tasks/305ca026-f758-4ad8-b317-6b21830825b1
Verdict: Malicious activity
Analysis date: December 18, 2024, 16:31:31
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
arch-exec
arch-doc
upx
antivm
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

2B219DEAA203F8EE9A21D6F5782A1A73

SHA1:

B05F65CF990128611507BC31DD345B7993EECE87

SHA256:

0FE8A51C858C36FCECDD7CA6A9A9113EA1A0DEA09224B178B1F7A5C9EAF25EF5

SSDEEP:

98304:hCZQP7YpvmczDYQlgFWTX/T7EwSfkQpVkcUbKRT+tK+jHDM23eTYMgDQIwPORGJr:zQfR+Q0XYMolW/a8

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Generic archive extractor

      • WinRAR.exe (PID: 6476)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • WinRAR.exe (PID: 6676)
    • Drops a system driver (possible attempt to evade defenses)

      • UsbMonitor.exe (PID: 3436)
    • Executable content was dropped or overwritten

      • UsbMonitor.exe (PID: 3436)
    • There is functionality for VM detection antiVM strings (YARA)

      • UsbMonitor.exe (PID: 3436)
    • Reads the BIOS version

      • UsbMonitor.exe (PID: 6832)
  • INFO

    • Manual execution by a user

      • WinRAR.exe (PID: 6676)
      • UsbMonitor.exe (PID: 1480)
      • UsbMonitor.exe (PID: 3436)
      • UsbMonitor.exe (PID: 6832)
      • UsbMonitor.exe (PID: 3524)
      • UsbMonitor.exe (PID: 6748)
    • The sample compiled with french language support

      • WinRAR.exe (PID: 6676)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 6676)
    • The sample compiled with english language support

      • WinRAR.exe (PID: 6676)
      • UsbMonitor.exe (PID: 3436)
    • UPX packer has been detected

      • UsbMonitor.exe (PID: 3436)
    • Reads the computer name

      • UsbMonitor.exe (PID: 3436)
    • Reads the machine GUID from the registry

      • UsbMonitor.exe (PID: 3524)
    • Checks supported languages

      • UsbMonitor.exe (PID: 6748)
    • Reads CPU info

      • UsbMonitor.exe (PID: 6832)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)

EXIF

ZIP

FileVersion: RAR v5
CompressedSize: 2
UncompressedSize: 2
OperatingSystem: Win32
ArchivedFileName: AIOSCREENSMALL/code.ini
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
139
Monitored processes
8
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe no specs winrar.exe rundll32.exe no specs usbmonitor.exe no specs usbmonitor.exe usbmonitor.exe usbmonitor.exe usbmonitor.exe

Process information

PID
CMD
Path
Indicators
Parent process
1480"C:\Users\admin\Desktop\AIOSCREENSMALL\UsbMonitor.exe" C:\Users\admin\Desktop\AIOSCREENSMALL\UsbMonitor.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
TURZX
Exit code:
3221226540
Version:
2.2.1.0
Modules
Images
c:\users\admin\desktop\aioscreensmall\usbmonitor.exe
c:\windows\system32\ntdll.dll
2448C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -EmbeddingC:\Windows\System32\rundll32.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shcore.dll
c:\windows\system32\imagehlp.dll
3436"C:\Users\admin\Desktop\AIOSCREENSMALL\UsbMonitor.exe" C:\Users\admin\Desktop\AIOSCREENSMALL\UsbMonitor.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Description:
TURZX
Exit code:
0
Version:
2.2.1.0
Modules
Images
c:\users\admin\desktop\aioscreensmall\usbmonitor.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
3524"C:\Users\admin\Desktop\AIOSCREENSMALL\UsbMonitor.exe" C:\Users\admin\Desktop\AIOSCREENSMALL\UsbMonitor.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Description:
TURZX
Exit code:
0
Version:
2.2.1.0
Modules
Images
c:\users\admin\desktop\aioscreensmall\usbmonitor.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
6476"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\Desktop\AIOSCREENSMALL.rarC:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
6676"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\AIOSCREENSMALL.rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
6748"C:\Users\admin\Desktop\AIOSCREENSMALL\UsbMonitor.exe" C:\Users\admin\Desktop\AIOSCREENSMALL\UsbMonitor.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Description:
TURZX
Exit code:
0
Version:
2.2.1.0
Modules
Images
c:\users\admin\desktop\aioscreensmall\usbmonitor.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
6832"C:\Users\admin\Desktop\AIOSCREENSMALL\UsbMonitor.exe" C:\Users\admin\Desktop\AIOSCREENSMALL\UsbMonitor.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Description:
TURZX
Version:
2.2.1.0
Modules
Images
c:\users\admin\desktop\aioscreensmall\usbmonitor.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
Total events
11 546
Read events
11 499
Write events
47
Delete events
0

Modification events

(PID) Process:(6476) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(6476) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(6476) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(6476) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\AIOSCREENSMALL.rar
(PID) Process:(6476) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(6476) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(6476) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(6476) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(6676) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\AIOSCREENSMALL.rar
(PID) Process:(6676) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
Executable files
7
Suspicious files
30
Text files
10
Unknown types
19

Dropped files

PID
Process
Filename
Type
6676WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6676.32022\AIOSCREENSMALL\config\A EVA UI 001.datapi2
MD5:1949526A9F0A342117CB07817B64E001
SHA256:B7E9B07DB6DB780E98CD6569ECC79ED0A5C1AE4D3B132129B4EC4562FB7589B1
6676WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6676.32022\AIOSCREENSMALL\config\3.5inchTheme2.datapi2
MD5:1E2B9AECC39C808E4FB22D335489BE4E
SHA256:C522394513118510252B74FE71CEFC4A667CB2D71834EB41205CCAFEBFD1AF11
6676WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6676.32022\AIOSCREENSMALL\config\AppConfig.datapi2
MD5:A86E05235B451405295075695633D85A
SHA256:E7BE2703F122687CE4FE0B2914F29FB55CEEA980BCBEBF33506AFA0AC6B1F441
6676WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6676.32022\AIOSCREENSMALL\config\Gradient.datapi2
MD5:0FF17FB4E6C9EDE0A49CDDC14D5E7D6F
SHA256:0DC0C43965D03CDA343873AB3CFAAA0CC6E5E188DDE1ADD5F6025837AED43A21
6676WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6676.32022\AIOSCREENSMALL\config\Dragon Ball.datapi2
MD5:90D4D46A513F41C36B11E49714B0AC99
SHA256:E07BD266D16DE981866ADDD4225C24593958B83093932D5C56DD2A9F707DA4D2
6676WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6676.32022\AIOSCREENSMALL\config\B cyberpunk.databinary
MD5:26CC535B3F028D8928C523D641FB10C3
SHA256:0CDE29EC197CEB3E842D7576AF6E8389184C66F03A973293B6B87C9B4B9F5E49
6676WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6676.32022\AIOSCREENSMALL\config\AORUS.databinary
MD5:E26383346311930E93C25275D7B232A8
SHA256:1F313FB30DD4904994CBED98DA6DEA5F55A4D81F9C78F4B969BDCCA80475C914
6676WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6676.32022\AIOSCREENSMALL\code.initext
MD5:EA5D2F1C4608232E07D3AA3D998E5135
SHA256:A68B412C4282555F15546CF6E1FC42893B7E07F271557CEB021821098DD66C1B
6676WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6676.32022\AIOSCREENSMALL\config\A cyberpunk.datapi2
MD5:4754DE3C149EC21F693D097B8CEA962C
SHA256:7E212AE98E845B51CC712FEEF330E56CFE74BF8946B0536C333FF7B9C7BFE520
6676WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6676.32022\AIOSCREENSMALL\config\3.5inchTheme1.datapi2
MD5:FA4BF0786E089EDB7A75D0C3387A757B
SHA256:83FCEB936597B25FB9A8E3A895DDCAD3EF45888F42E3DB3CB7A6046707FDDA82
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
9
TCP/UDP connections
34
DNS requests
18
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4712
MoUsoCoreWorker.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
4712
MoUsoCoreWorker.exe
GET
200
2.16.164.51:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6832
UsbMonitor.exe
GET
301
111.230.112.70:80
http://www.turzx.com/update_35.html
unknown
unknown
4996
SIHClient.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
4996
SIHClient.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
6188
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
3436
UsbMonitor.exe
GET
301
111.230.112.70:80
http://www.turzx.com/update_35.html
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
4712
MoUsoCoreWorker.exe
2.16.164.51:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
4712
MoUsoCoreWorker.exe
88.221.169.152:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
5064
SearchApp.exe
2.23.209.160:443
www.bing.com
Akamai International B.V.
GB
whitelisted
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
1176
svchost.exe
20.190.159.68:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1076
svchost.exe
184.28.89.167:443
go.microsoft.com
AKAMAI-AS
US
whitelisted
2124
RUXIMICS.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 51.104.136.2
  • 40.127.240.158
whitelisted
google.com
  • 172.217.23.110
whitelisted
crl.microsoft.com
  • 2.16.164.51
  • 2.16.164.49
whitelisted
www.microsoft.com
  • 88.221.169.152
whitelisted
www.bing.com
  • 2.23.209.160
  • 2.23.209.158
  • 2.23.209.181
  • 2.23.209.183
  • 2.23.209.187
  • 2.23.209.176
  • 2.23.209.161
  • 2.23.209.156
  • 2.23.209.182
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
login.live.com
  • 20.190.159.68
  • 40.126.31.69
  • 40.126.31.71
  • 20.190.159.4
  • 20.190.159.64
  • 20.190.159.0
  • 20.190.159.75
  • 20.190.159.23
whitelisted
go.microsoft.com
  • 184.28.89.167
whitelisted
www.turzx.com
  • 111.230.112.70
unknown
slscr.update.microsoft.com
  • 4.175.87.197
whitelisted

Threats

No threats detected
No debug info