File name:

AIOSCREENSMALL.rar

Full analysis: https://app.any.run/tasks/305ca026-f758-4ad8-b317-6b21830825b1
Verdict: Malicious activity
Analysis date: December 18, 2024, 16:31:31
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
arch-exec
arch-doc
upx
antivm
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

2B219DEAA203F8EE9A21D6F5782A1A73

SHA1:

B05F65CF990128611507BC31DD345B7993EECE87

SHA256:

0FE8A51C858C36FCECDD7CA6A9A9113EA1A0DEA09224B178B1F7A5C9EAF25EF5

SSDEEP:

98304:hCZQP7YpvmczDYQlgFWTX/T7EwSfkQpVkcUbKRT+tK+jHDM23eTYMgDQIwPORGJr:zQfR+Q0XYMolW/a8

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Generic archive extractor

      • WinRAR.exe (PID: 6476)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • WinRAR.exe (PID: 6676)
    • Drops a system driver (possible attempt to evade defenses)

      • UsbMonitor.exe (PID: 3436)
    • Executable content was dropped or overwritten

      • UsbMonitor.exe (PID: 3436)
    • Reads the BIOS version

      • UsbMonitor.exe (PID: 6832)
    • There is functionality for VM detection antiVM strings (YARA)

      • UsbMonitor.exe (PID: 3436)
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 6676)
    • Manual execution by a user

      • WinRAR.exe (PID: 6676)
      • UsbMonitor.exe (PID: 1480)
      • UsbMonitor.exe (PID: 3436)
      • UsbMonitor.exe (PID: 3524)
      • UsbMonitor.exe (PID: 6832)
      • UsbMonitor.exe (PID: 6748)
    • The sample compiled with english language support

      • WinRAR.exe (PID: 6676)
      • UsbMonitor.exe (PID: 3436)
    • The sample compiled with french language support

      • WinRAR.exe (PID: 6676)
    • Reads the computer name

      • UsbMonitor.exe (PID: 3436)
    • UPX packer has been detected

      • UsbMonitor.exe (PID: 3436)
    • Reads the machine GUID from the registry

      • UsbMonitor.exe (PID: 3524)
    • Checks supported languages

      • UsbMonitor.exe (PID: 6748)
    • Reads CPU info

      • UsbMonitor.exe (PID: 6832)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)

EXIF

ZIP

FileVersion: RAR v5
CompressedSize: 2
UncompressedSize: 2
OperatingSystem: Win32
ArchivedFileName: AIOSCREENSMALL/code.ini
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
139
Monitored processes
8
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe no specs winrar.exe rundll32.exe no specs usbmonitor.exe no specs usbmonitor.exe usbmonitor.exe usbmonitor.exe usbmonitor.exe

Process information

PID
CMD
Path
Indicators
Parent process
1480"C:\Users\admin\Desktop\AIOSCREENSMALL\UsbMonitor.exe" C:\Users\admin\Desktop\AIOSCREENSMALL\UsbMonitor.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
TURZX
Exit code:
3221226540
Version:
2.2.1.0
Modules
Images
c:\users\admin\desktop\aioscreensmall\usbmonitor.exe
c:\windows\system32\ntdll.dll
2448C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -EmbeddingC:\Windows\System32\rundll32.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shcore.dll
c:\windows\system32\imagehlp.dll
3436"C:\Users\admin\Desktop\AIOSCREENSMALL\UsbMonitor.exe" C:\Users\admin\Desktop\AIOSCREENSMALL\UsbMonitor.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Description:
TURZX
Exit code:
0
Version:
2.2.1.0
Modules
Images
c:\users\admin\desktop\aioscreensmall\usbmonitor.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
3524"C:\Users\admin\Desktop\AIOSCREENSMALL\UsbMonitor.exe" C:\Users\admin\Desktop\AIOSCREENSMALL\UsbMonitor.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Description:
TURZX
Exit code:
0
Version:
2.2.1.0
Modules
Images
c:\users\admin\desktop\aioscreensmall\usbmonitor.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
6476"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\Desktop\AIOSCREENSMALL.rarC:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
6676"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\AIOSCREENSMALL.rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
6748"C:\Users\admin\Desktop\AIOSCREENSMALL\UsbMonitor.exe" C:\Users\admin\Desktop\AIOSCREENSMALL\UsbMonitor.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Description:
TURZX
Exit code:
0
Version:
2.2.1.0
Modules
Images
c:\users\admin\desktop\aioscreensmall\usbmonitor.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
6832"C:\Users\admin\Desktop\AIOSCREENSMALL\UsbMonitor.exe" C:\Users\admin\Desktop\AIOSCREENSMALL\UsbMonitor.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Description:
TURZX
Version:
2.2.1.0
Modules
Images
c:\users\admin\desktop\aioscreensmall\usbmonitor.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
Total events
11 546
Read events
11 499
Write events
47
Delete events
0

Modification events

(PID) Process:(6476) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(6476) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(6476) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(6476) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\AIOSCREENSMALL.rar
(PID) Process:(6476) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(6476) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(6476) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(6476) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(6676) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\AIOSCREENSMALL.rar
(PID) Process:(6676) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
Executable files
7
Suspicious files
30
Text files
10
Unknown types
19

Dropped files

PID
Process
Filename
Type
6676WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6676.32022\AIOSCREENSMALL\code.initext
MD5:EA5D2F1C4608232E07D3AA3D998E5135
SHA256:A68B412C4282555F15546CF6E1FC42893B7E07F271557CEB021821098DD66C1B
6676WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6676.32022\AIOSCREENSMALL\config\A EVA UI 001.datapi2
MD5:1949526A9F0A342117CB07817B64E001
SHA256:B7E9B07DB6DB780E98CD6569ECC79ED0A5C1AE4D3B132129B4EC4562FB7589B1
6676WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6676.32022\AIOSCREENSMALL\config\Earth theme.datapi2
MD5:075CEBA11520CD4972095DAE1EFD31F6
SHA256:5813609025792850C5626669EEDA0F55DF189D66784105EC97B5190BE610D67A
6676WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6676.32022\AIOSCREENSMALL\config\Cyberpunk2077.databinary
MD5:5BB5EF49252E03CB5F71CFE07CAD364E
SHA256:2400D616192C69EA9C870F6568BD8D3EA20CA3F8AC02D19432C8339B4350E066
6676WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6676.32022\AIOSCREENSMALL\config\blank for image.datapi2
MD5:57B193B7BCB05DA9BAF8FC1E609DA1A0
SHA256:CD18A4F46894281A23BB3DA358BED65DADBF3B4067635B759B94AC8E28BAADB4
6676WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6676.32022\AIOSCREENSMALL\config\LandscapeMagicBlue.datapi2
MD5:D45761BC13CB09E13A62CF7D1B29C786
SHA256:B7F514D53E1B5CEFCB68A2822F30F061F1ED16FE03386AA94C6CECE227AA22DE
6676WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6676.32022\AIOSCREENSMALL\config\A EVA UI 002.databinary
MD5:90BD0908C02FF5A3E48A70BB28CF437E
SHA256:1261B796F18DEB09F3FE7A5741DC13AFCC551E7267EDD9F13B4A397A0AD5C95A
6676WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6676.32022\AIOSCREENSMALL\config\B cyberpunk.databinary
MD5:26CC535B3F028D8928C523D641FB10C3
SHA256:0CDE29EC197CEB3E842D7576AF6E8389184C66F03A973293B6B87C9B4B9F5E49
6676WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6676.32022\AIOSCREENSMALL\config\AppConfig.datapi2
MD5:A86E05235B451405295075695633D85A
SHA256:E7BE2703F122687CE4FE0B2914F29FB55CEEA980BCBEBF33506AFA0AC6B1F441
6676WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6676.32022\AIOSCREENSMALL\config\AORUS.databinary
MD5:E26383346311930E93C25275D7B232A8
SHA256:1F313FB30DD4904994CBED98DA6DEA5F55A4D81F9C78F4B969BDCCA80475C914
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
9
TCP/UDP connections
34
DNS requests
18
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4712
MoUsoCoreWorker.exe
GET
200
2.16.164.51:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
4712
MoUsoCoreWorker.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
6188
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
6832
UsbMonitor.exe
GET
301
111.230.112.70:80
http://www.turzx.com/update_35.html
unknown
4996
SIHClient.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
4996
SIHClient.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
3436
UsbMonitor.exe
GET
301
111.230.112.70:80
http://www.turzx.com/update_35.html
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
4712
MoUsoCoreWorker.exe
2.16.164.51:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
4712
MoUsoCoreWorker.exe
88.221.169.152:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
5064
SearchApp.exe
2.23.209.160:443
www.bing.com
Akamai International B.V.
GB
whitelisted
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
1176
svchost.exe
20.190.159.68:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1076
svchost.exe
184.28.89.167:443
go.microsoft.com
AKAMAI-AS
US
whitelisted
2124
RUXIMICS.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 51.104.136.2
  • 40.127.240.158
whitelisted
google.com
  • 172.217.23.110
whitelisted
crl.microsoft.com
  • 2.16.164.51
  • 2.16.164.49
whitelisted
www.microsoft.com
  • 88.221.169.152
whitelisted
www.bing.com
  • 2.23.209.160
  • 2.23.209.158
  • 2.23.209.181
  • 2.23.209.183
  • 2.23.209.187
  • 2.23.209.176
  • 2.23.209.161
  • 2.23.209.156
  • 2.23.209.182
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
login.live.com
  • 20.190.159.68
  • 40.126.31.69
  • 40.126.31.71
  • 20.190.159.4
  • 20.190.159.64
  • 20.190.159.0
  • 20.190.159.75
  • 20.190.159.23
whitelisted
go.microsoft.com
  • 184.28.89.167
whitelisted
www.turzx.com
  • 111.230.112.70
unknown
slscr.update.microsoft.com
  • 4.175.87.197
whitelisted

Threats

No threats detected
No debug info