| File name: | New folder.rar |
| Full analysis: | https://app.any.run/tasks/bda36c1b-7bac-4dae-ae1d-c3b20087ebb4 |
| Verdict: | Malicious activity |
| Analysis date: | July 22, 2024, 20:58:50 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-rar |
| File info: | RAR archive data, v5 |
| MD5: | F271F5DC715E54BF2512E879FA3213B3 |
| SHA1: | 0E69E10DE4ED16E875D819779629D51A60758EEC |
| SHA256: | 11D38AEB5398CC5AF77D4D87C35595090A70F4FE348325CD00B9CBC9B2C5B56B |
| SSDEEP: | 196608:zByaJfq+6F9yVbRohs8Ew8kU23MzVAegxa:8aRzbRoqHw8ZOMzuVxa |
| .rar | | | RAR compressed archive (v5.0) (61.5) |
|---|---|---|
| .rar | | | RAR compressed archive (gen) (38.4) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 616 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5824 -childID 4 -isForBrowser -prefsHandle 5868 -prefMapHandle 5864 -prefsLen 31207 -prefMapSize 244343 -jsInitHandle 1440 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {db69bcdf-4f9a-4f90-b20b-f5ea80114879} 6412 "\\.\pipe\gecko-crash-server-pipe.6412" 221091e5d90 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 123.0 Modules
| |||||||||||||||
| 1128 | "C:\Users\admin\Desktop\New folder\ExtremeDumper\Boomx86.exe" | C:\Users\admin\Desktop\New folder\ExtremeDumper\Boomx86.exe | explorer.exe | ||||||||||||
User: admin Company: ExtremeDumper-x86 Integrity Level: HIGH Description: ExtremeDumper-x86 Exit code: 3221225786 Version: 4.0.0.1 Modules
| |||||||||||||||
| 1180 | C:\WINDOWS\System32\slui.exe -Embedding | C:\Windows\System32\slui.exe | svchost.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Activation Client Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1264 | "C:\Program Files\Mozilla Firefox\firefox.exe" | C:\Program Files\Mozilla Firefox\firefox.exe | — | explorer.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 123.0 Modules
| |||||||||||||||
| 1548 | "C:\Users\admin\Desktop\Dumps\genericVolvo.exe" | C:\Users\admin\Desktop\Dumps\genericVolvo.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Description: genericVolvo Exit code: 3762504530 Version: 0.2.6.0 Modules
| |||||||||||||||
| 1676 | C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -Embedding | C:\Windows\System32\rundll32.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows host process (Rundll32) Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1676 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=4680 -childID 2 -isForBrowser -prefsHandle 2608 -prefMapHandle 4656 -prefsLen 36263 -prefMapSize 244343 -jsInitHandle 1440 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {b2679479-220c-40db-8faa-fb09a3ed4f72} 6412 "\\.\pipe\gecko-crash-server-pipe.6412" 2210723ebd0 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 123.0 Modules
| |||||||||||||||
| 1816 | "C:\Users\admin\Desktop\New folder\MegaDumper\Chrome.exe" | C:\Users\admin\Desktop\New folder\MegaDumper\Chrome.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: MegaDumper Exit code: 0 Version: 1.0.5565.36604 Modules
| |||||||||||||||
| 2656 | "C:\Users\admin\Desktop\New folder\AnyCpu\JITFreezer.exe" "C:\Users\admin\Desktop\New folder\GV.exe" | C:\Users\admin\Desktop\New folder\AnyCpu\JITFreezer.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: JITFreezer Exit code: 0 Version: 1.0.0.0 Modules
| |||||||||||||||
| 3484 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | Boomx86.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| (PID) Process: | (5196) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (5196) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (5196) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\GoogleChromeEnterpriseBundle64.zip | |||
| (PID) Process: | (5196) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\New folder.rar | |||
| (PID) Process: | (5196) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (5196) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (5196) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (5196) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (5196) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\MainWin |
| Operation: | write | Name: | Placement |
Value: 2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF3D0000002D000000FD03000016020000 | |||
| (PID) Process: | (5196) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\General |
| Operation: | write | Name: | LastFolder |
Value: C:\Users\admin\AppData\Local\Temp | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 5196 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa5196.25419\New folder\ExtremeDumper\Boom.exe | executable | |
MD5:5B59AEC378E0A011FE24A911090E85C0 | SHA256:42774BB3D8196E410A74F896567EA65156FEB63E3228BFDF54AB5A539293DC57 | |||
| 5196 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa5196.25419\New folder\ExtremeDumper\ExtremeDumper.exe | executable | |
MD5:58DB100B228FF17F83726D4C2738990E | SHA256:F407B67A008FC2186329D5FEFFE830F7EEAD7A11F3B169D0D90099495EDFCF2E | |||
| 1128 | Boomx86.exe | C:\Users\admin\AppData\Local\Temp\Costura\CFA0B0B143E4C50194769B9A2552FFEF\32\extremedumper.loaderhook.dll | executable | |
MD5:666BB02763FE5CEB4FFF36DB4D5CEFAD | SHA256:8B8C972255F75488D0B562DF4DF6A281D52911E39CEEB43E05801B4658FF358D | |||
| 1128 | Boomx86.exe | C:\Users\admin\Desktop\Dumps\_.dll | executable | |
MD5:27A438E3E38E4992FE8D15D4931AC437 | SHA256:9C267142C645EE688FBADC4349DF045468BEB5A430A4346F9EF4371915E642D3 | |||
| 6412 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\9kie7cg6.default-release\startupCache\urlCache-current.bin | binary | |
MD5:297E88D7CEB26E549254EC875649F4EB | SHA256:8B75D4FB1845BAA06122888D11F6B65E6A36B140C54A72CC13DF390FD7C95702 | |||
| 4216 | WerFault.exe | C:\ProgramData\Microsoft\Windows\WER\Temp\WER167C.tmp.dmp | binary | |
MD5:749943107D274B1AD89B5D6A6F1DF0BF | SHA256:4DA23DA9C7E232AD69C3553268684885006EC2DD5758235826668006C370BD83 | |||
| 5196 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa5196.25419\New folder\AnyCpu\Colorful.Console.dll | executable | |
MD5:AC4267B870699A799E05B2BE2D2956DA | SHA256:309C616209120EE751DF11612A8EADD06E8C86E68510D0B31BA21290782516FC | |||
| 5196 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa5196.25419\New folder\MegaDumper\Chrome.exe | executable | |
MD5:F24EB16D357C8466B0D39609290E701B | SHA256:1190F0340F7F211C0AB417FFB125AA7F8781342D1D1FFADA6A48659B6E76429B | |||
| 6412 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\sessionCheckpoints.json | binary | |
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A | SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA | |||
| 4216 | WerFault.exe | C:\ProgramData\Microsoft\Windows\WER\Temp\WER17A7.tmp.xml | xml | |
MD5:1DDCBD6BB19606250E4531B79B9EB19C | SHA256:E086C1D51F905F99CE681B55E326FB65D3FC5E3CDC0D5A5206924E36D039AAB4 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
6412 | firefox.exe | POST | 200 | 184.24.77.67:80 | http://r10.o.lencr.org/ | unknown | — | — | unknown |
6412 | firefox.exe | POST | 200 | 184.24.77.67:80 | http://r3.o.lencr.org/ | unknown | — | — | unknown |
6412 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/success.txt?ipv4 | unknown | — | — | whitelisted |
6412 | firefox.exe | POST | 200 | 184.24.77.67:80 | http://r10.o.lencr.org/ | unknown | — | — | unknown |
6412 | firefox.exe | POST | 200 | 142.250.186.35:80 | http://o.pki.goog/wr2 | unknown | — | — | unknown |
6412 | firefox.exe | POST | 200 | 184.24.77.67:80 | http://r10.o.lencr.org/ | unknown | — | — | unknown |
6412 | firefox.exe | POST | 200 | 142.250.186.35:80 | http://o.pki.goog/wr2 | unknown | — | — | unknown |
6412 | firefox.exe | POST | 200 | 184.24.77.67:80 | http://r10.o.lencr.org/ | unknown | — | — | unknown |
6412 | firefox.exe | POST | 200 | 184.24.77.48:80 | http://r11.o.lencr.org/ | unknown | — | — | unknown |
6412 | firefox.exe | POST | 200 | 184.24.77.48:80 | http://r11.o.lencr.org/ | unknown | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
6012 | MoUsoCoreWorker.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4288 | RUXIMICS.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
3488 | svchost.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
— | — | 239.255.255.250:1900 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 4.209.33.156:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | US | unknown |
4748 | slui.exe | 40.91.76.224:443 | activation-v2.sls.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
3488 | svchost.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
1180 | slui.exe | 40.91.76.224:443 | activation-v2.sls.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
activation-v2.sls.microsoft.com |
| whitelisted |
www.bing.com |
| whitelisted |
login.live.com |
| whitelisted |
go.microsoft.com |
| whitelisted |
arc.msn.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
fd.api.iris.microsoft.com |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
2284 | svchost.exe | Not Suspicious Traffic | INFO [ANY.RUN] Requests to a free CDN for open source projects (jsdelivr .net) |
2284 | svchost.exe | Not Suspicious Traffic | INFO [ANY.RUN] Cloudflare content delivery network (cdnjs .cloudflare .com) |