File name:

3.rar

Full analysis: https://app.any.run/tasks/d188293b-8cff-4cb4-bcf4-b6e8a4707d02
Verdict: Malicious activity
Analysis date: December 02, 2023, 21:06:27
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

3C2D3ACCA0A6F4AA1DBDDB3F9F56672D

SHA1:

78D668626AE46490976AA9A806C6FF13E8AA7D17

SHA256:

125C4B80F91917F505CFECE73AE6F73B1300CF0A0C11B455BDC078B091C5CD1A

SSDEEP:

98304:ZYFGwzKocBggxk0MZwwkZVt++gsBlBP5FZ0k/pLU3bgLMmGAfYP0sp2KE/1pkOVW:6Xx2uQScYgwscEuxDAfnh4Whc

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Actions looks like stealing of personal data

      • 127277c0097cef5ce18f0002a2456f84.exe (PID: 2292)
    • Drops the executable file immediately after the start

      • 127277c0097cef5ce18f0002a2456f84.exe (PID: 2292)
    • The DLL Hijacking

      • DismHost.exe (PID: 1376)
    • Creates a writable file in the system directory

      • dispdiag.exe (PID: 3460)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • WinRAR.exe (PID: 564)
      • 127277c0097cef5ce18f0002a2456f84.exe (PID: 2292)
      • cleanmgr.exe (PID: 3784)
    • Application launched itself

      • cmd.exe (PID: 604)
      • cmd.exe (PID: 3080)
      • CompatTelRunner.exe (PID: 3348)
      • cmd.exe (PID: 3084)
    • Starts CMD.EXE for commands execution

      • cmd.exe (PID: 604)
      • cmd.exe (PID: 3080)
      • cmd.exe (PID: 3084)
      • forfiles.exe (PID: 2236)
    • Uses ICACLS.EXE to modify access control lists

      • cmd.exe (PID: 292)
      • cmd.exe (PID: 4768)
    • Executes as Windows Service

      • VSSVC.exe (PID: 2336)
      • vds.exe (PID: 2468)
    • Reads the Internet Settings

      • cleanmgr.exe (PID: 3784)
      • CompMgmtLauncher.exe (PID: 3052)
    • Using 'findstr.exe' to search for text patterns in files and output

      • cmd.exe (PID: 1608)
    • Process uses IPCONFIG to get network configuration information

      • cmd.exe (PID: 5156)
    • Uses DRIVERQUERY.EXE to obtain a list of installed device drivers

      • cmd.exe (PID: 3560)
    • Uses ATTRIB.EXE to modify file attributes

      • cmd.exe (PID: 3664)
  • INFO

    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 564)
      • cleanmgr.exe (PID: 3784)
    • Manual execution by a user

      • notepad.exe (PID: 2076)
      • cmd.exe (PID: 604)
      • notepad.exe (PID: 3856)
      • cmd.exe (PID: 3084)
      • wmpnscfg.exe (PID: 5332)
    • Creates files or folders in the user directory

      • 127277c0097cef5ce18f0002a2456f84.exe (PID: 2292)
      • cleanmgr.exe (PID: 3784)
    • Uses BITSADMIN.EXE

      • cmd.exe (PID: 1928)
    • Reads the computer name

      • 127277c0097cef5ce18f0002a2456f84.exe (PID: 2292)
      • DismHost.exe (PID: 1376)
    • Reads Microsoft Office registry keys

      • cleanmgr.exe (PID: 3784)
    • Create files in a temporary directory

      • cleanmgr.exe (PID: 3784)
      • ddodiag.exe (PID: 4032)
    • Checks supported languages

      • DismHost.exe (PID: 1376)
      • Defrag.exe (PID: 916)
      • 127277c0097cef5ce18f0002a2456f84.exe (PID: 2292)
    • Reads the machine GUID from the registry

      • DismHost.exe (PID: 1376)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
691
Monitored processes
525
Malicious processes
7
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe no specs notepad.exe no specs cmd.exe no specs cmd.exe no specs 127277c0097cef5ce18f0002a2456f84.exe notepad.exe no specs cmd.exe cmd.exe no specs adaptertroubleshooter.exe no specs cmd.exe no specs aitagent.exe no specs cmd.exe no specs aitstatic.exe no specs cmd.exe no specs alg.exe no specs cmd.exe no specs ntvdm.exe no specs cmd.exe no specs appidcertstorecheck.exe no specs cmd.exe no specs appidpolicyconverter.exe no specs cmd.exe no specs arp.exe no specs cmd.exe no specs at.exe no specs cmd.exe no specs atbroker.exe no specs cmd.exe no specs attrib.exe no specs cmd.exe no specs audiodg.exe no specs cmd.exe no specs auditpol.exe no specs cmd.exe no specs autochk.exe no specs cmd.exe no specs autoconv.exe no specs cmd.exe no specs autofmt.exe no specs cmd.exe no specs axinstui.exe no specs cmd.exe no specs bcdboot.exe no specs cmd.exe no specs bcdedit.exe no specs cmd.exe no specs bdeuisrv.exe no specs cmd.exe no specs bdeunlockwizard.exe no specs cmd.exe no specs bitsadmin.exe no specs cmd.exe no specs bootcfg.exe no specs cmd.exe no specs bridgeunattend.exe no specs cmd.exe no specs bthudtask.exe no specs cmd.exe no specs cacls.exe no specs cmd.exe no specs calc.exe no specs cmd.exe no specs certenrollctrl.exe no specs cmd.exe no specs certreq.exe no specs cmd.exe no specs certutil.exe no specs cmd.exe no specs change.exe no specs cmd.exe no specs charmap.exe no specs cmd.exe no specs chglogon.exe no specs cmd.exe no specs chgport.exe no specs cmd.exe no specs chgusr.exe no specs cmd.exe no specs chkdsk.exe no specs cmd.exe no specs chkntfs.exe no specs cmd.exe no specs choice.exe no specs cmd.exe no specs cipher.exe no specs cmd.exe no specs cleanmgr.exe cmd.exe no specs cliconfg.exe no specs vssvc.exe no specs cmd.exe no specs clip.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmdkey.exe no specs cmd.exe no specs cmdl32.exe no specs cmd.exe no specs cmmon32.exe no specs cmd.exe no specs cmstp.exe no specs cmd.exe no specs cofire.exe no specs cmd.exe no specs colorcpl.exe no specs cmd.exe no specs comp.exe no specs cmd.exe no specs compact.exe no specs cmd.exe no specs compattelrunner.exe no specs cmd.exe no specs compmgmtlauncher.exe no specs cmd.exe no specs computerdefaults.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs consent.exe no specs cmd.exe no specs control.exe no specs cmd.exe no specs convert.exe no specs cmd.exe no specs credwiz.exe no specs cmd.exe no specs cscript.exe no specs cmd.exe no specs compattelrunner.exe no specs csrss.exe no specs dismhost.exe no specs cmd.exe no specs csrstub.exe no specs cmd.exe no specs ctfmon.exe no specs cmd.exe no specs cttune.exe no specs cmd.exe no specs mmc.exe no specs cttunesvr.exe no specs cmd.exe no specs dccw.exe no specs cmd.exe no specs dcomcnfg.exe no specs cmd.exe no specs mmc.exe no specs ddodiag.exe no specs cmd.exe no specs devicedisplayobjectprovider.exe no specs ntvdm.exe no specs cmd.exe no specs defrag.exe no specs cmd.exe no specs devicedisplayobjectprovider.exe no specs cmd.exe no specs deviceeject.exe no specs cmd.exe no specs devicepairingwizard.exe no specs cmd.exe no specs deviceproperties.exe no specs cmd.exe no specs dfdwiz.exe no specs cmd.exe no specs dfrgui.exe no specs cmd.exe no specs dialer.exe no specs cmd.exe no specs diantz.exe no specs cmd.exe no specs dinotify.exe no specs cmd.exe no specs diskpart.exe no specs cmd.exe no specs diskperf.exe no specs cmd.exe no specs diskraid.exe no specs cmd.exe no specs dism.exe cmd.exe no specs dispdiag.exe no specs cmd.exe no specs displayswitch.exe no specs cmd.exe no specs vdsldr.exe no specs djoin.exe no specs cmd.exe no specs dllhost.exe no specs vds.exe no specs cmd.exe no specs dllhst3g.exe no specs cmd.exe no specs dnscacheugc.exe no specs cmd.exe no specs doskey.exe no specs cmd.exe no specs ntvdm.exe no specs cmd.exe no specs dpapimig.exe no specs cmd.exe no specs dpiscaling.exe no specs cmd.exe no specs dplaysvr.exe cmd.exe no specs dpnsvr.exe no specs cmd.exe no specs driverquery.exe no specs cmd.exe no specs drvinst.exe no specs cmd.exe no specs ntvdm.exe no specs cmd.exe no specs dvdplay.exe no specs wmplayer.exe no specs cmd.exe no specs dvdupgrd.exe no specs cmd.exe no specs setup_wm.exe no specs dwm.exe no specs cmd.exe no specs dwwin.exe no specs cmd.exe no specs dxdiag.exe no specs cmd.exe no specs dxpserver.exe no specs cmd.exe no specs eap3host.exe no specs cmd.exe no specs ntvdm.exe no specs cmd.exe no specs efsui.exe no specs cmd.exe no specs ehstorauthn.exe no specs cmd.exe no specs eosnotify.exe no specs cmd.exe no specs esentutl.exe no specs cmd.exe no specs eudcedit.exe no specs cmd.exe no specs eventcreate.exe no specs cmd.exe no specs eventvwr.exe no specs cmd.exe no specs ntvdm.exe no specs cmd.exe no specs mmc.exe no specs expand.exe no specs cmd.exe no specs extrac32.exe no specs cmd.exe no specs ntvdm.exe no specs cmd.exe no specs fc.exe no specs cmd.exe no specs find.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs finger.exe no specs cmd.exe no specs fixmapi.exe no specs cmd.exe no specs flashplayerapp.exe no specs cmd.exe no specs fltmc.exe no specs cmd.exe no specs fontview.exe no specs cmd.exe no specs forfiles.exe no specs cmd.exe no specs fsutil.exe no specs cmd.exe no specs ftp.exe no specs cmd.exe no specs fvenotify.exe no specs cmd.exe no specs fveprompt.exe no specs cmd.exe no specs fxscover.exe no specs cmd.exe no specs fxssvc.exe no specs cmd.exe no specs cmd.exe no specs fxsunatd.exe no specs cmd.exe no specs cmd.exe no specs ntvdm.exe no specs cmd.exe no specs cmd.exe no specs getmac.exe no specs cmd.exe no specs cmd.exe no specs gettingstarted.exe no specs cmd.exe no specs cmd.exe no specs gpresult.exe no specs control.exe no specs cmd.exe no specs cmd.exe no specs gpscript.exe no specs cmd.exe no specs cmd.exe no specs gpupdate.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs grpconv.exe no specs cmd.exe no specs cmd.exe no specs hdwwiz.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs help.exe no specs cmd.exe no specs cmd.exe no specs hostname.exe no specs cmd.exe no specs cmd.exe no specs hwrcomp.exe no specs cmd.exe no specs cmd.exe no specs hwrreg.exe no specs cmd.exe no specs cmd.exe no specs icacls.exe no specs cmd.exe no specs cmd.exe no specs icardagt.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs icsunattend.exe no specs cmd.exe no specs ie4uinit.exe no specs cmd.exe no specs cmd.exe no specs ieetwcollector.exe no specs cmd.exe no specs cmd.exe no specs ieunatt.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs iexpress.exe no specs cmd.exe no specs cmd.exe no specs infdefaultinstall.exe no specs cmd.exe no specs cmd.exe no specs ipconfig.exe no specs cmd.exe no specs cmd.exe no specs irftp.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs iscsicli.exe no specs cmd.exe no specs cmd.exe no specs iscsicpl.exe no specs cmd.exe no specs cmd.exe no specs isoburn.exe no specs cmd.exe no specs cmd.exe no specs klist.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs ntvdm.exe no specs cmd.exe no specs cmd.exe no specs ksetup.exe no specs cmd.exe no specs cmd.exe no specs ktmutil.exe no specs cmd.exe no specs cmd.exe no specs label.exe no specs cmd.exe no specs cmd.exe no specs locationnotifications.exe no specs cmd.exe no specs cmd.exe no specs locator.exe no specs cmd.exe no specs cmd.exe no specs lodctr.exe no specs cmd.exe no specs cmd.exe no specs logagent.exe no specs cmd.exe no specs cmd.exe no specs logman.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs logoff.exe no specs cmd.exe no specs cmd.exe no specs logonui.exe no specs cmd.exe no specs cmd.exe no specs lpksetup.exe no specs cmd.exe no specs cmd.exe no specs lpremove.exe no specs cmd.exe no specs cmd.exe no specs lsass.exe no specs cmd.exe no specs cmd.exe no specs lsm.exe no specs lpksetup.exe no specs cmd.exe no specs cmd.exe no specs magnify.exe no specs cmd.exe no specs magnify.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs mcbuilder.exe no specs cmd.exe no specs magnify.exe no specs cmd.exe no specs cmd.exe no specs makecab.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs manage-bde.exe no specs cmd.exe no specs cmd.exe no specs mblctr.exe no specs cmd.exe no specs cmd.exe no specs mcbuilder.exe no specs cmd.exe no specs cmd.exe no specs mctadmin.exe no specs cmd.exe no specs cmd.exe no specs mdres.exe no specs cmd.exe no specs cmd.exe no specs mdsched.exe no specs cmd.exe no specs cmd.exe no specs ntvdm.exe no specs cmd.exe no specs cmd.exe no specs mfpmp.exe no specs cmd.exe no specs cmd.exe no specs migautoplay.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs mmc.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs wmpnscfg.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
120/c echo "api-ms-win-core-fibers-l1-1-0.dll"C:\Windows\System32\cmd.exeforfiles.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
128"CertEnrollCtrl.exe" C:\Windows\System32\CertEnrollCtrl.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Certificate Enrollment Control
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\certenrollctrl.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\certcli.dll
c:\windows\system32\atl.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
148"efsui.exe" C:\Windows\System32\efsui.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
EFS UI Application
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\efsui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
240"dpapimig.exe" C:\Windows\System32\dpapimig.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
DPAPI Key Migration Wizard
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\dpapimig.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
276"attrib.exe" C:\Windows\System32\attrib.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Attribute Utility
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\attrib.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ulib.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
280"C:\Windows\system32\mmc.exe" "C:\Windows\system32\eventvwr.msc" C:\Windows\System32\mmc.exeeventvwr.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Management Console
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\mmc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\mfc42u.dll
292cmd /c start "" "cacls.exe"C:\Windows\System32\cmd.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
296"calc.exe" C:\Windows\System32\calc.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Calculator
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\calc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
528cmd /c start "" "bootcfg.exe"C:\Windows\System32\cmd.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
528"Dism.exe" C:\Windows\System32\Dism.exe
cmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Dism Image Servicing Utility
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\dism.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
11 869
Read events
11 543
Write events
326
Delete events
0

Modification events

(PID) Process:(564) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\17F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(564) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(564) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(564) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(564) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(564) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(564) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(564) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(4088) AdapterTroubleshooter.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Direct3D\MostRecentApplication
Operation:writeName:Name
Value:
Explorer.EXE
(PID) Process:(2896) aitagent.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\AIT
Operation:writeName:LastReadEntryTime
Value:
F482CD25F0B1D301
Executable files
101
Suspicious files
34
Text files
27
Unknown types
0

Dropped files

PID
Process
Filename
Type
564WinRAR.exeC:\Users\admin\Desktop\4b543325cf0e11dee26d58cc1ac38cf5.exeexecutable
MD5:4B543325CF0E11DEE26D58CC1AC38CF5
SHA256:E9EF5889CBC575FABAE55849EEBC9EFE2C14D9532C6CAFB02AAF78CC5DEE3CA0
564WinRAR.exeC:\Users\admin\Desktop\289c1a8a890a567f4f70235ced85f763.exeexecutable
MD5:289C1A8A890A567F4F70235CED85F763
SHA256:4444FC67A93232E1B4F3C9B755AC3B9D0D2D7D0EB86D46F7D7B67EC8DF2D9771
564WinRAR.exeC:\Users\admin\Desktop\127277c0097cef5ce18f0002a2456f84.exeexecutable
MD5:127277C0097CEF5CE18F0002A2456F84
SHA256:E0E43B3AAAACEA4C53B4723C5A9704C7B9C0EA88A45DA58622B0EA85A5A5CDF8
564WinRAR.exeC:\Users\admin\Desktop\26a318ba688442470eb1f247da7d76c1.exeexecutable
MD5:26A318BA688442470EB1F247DA7D76C1
SHA256:D11E6B68E509EC7D7D70CF326BDA76768865687B2753E10EBD44C82EB4BAE9DE
564WinRAR.exeC:\Users\admin\Desktop\12e89420d487205e997bbd25011d45fa.exeexecutable
MD5:12E89420D487205E997BBD25011D45FA
SHA256:6724CE5B748F1C7CE548FC001CDBDC22AC18C81BC631A8CD7C6BD3F60C0A33A3
564WinRAR.exeC:\Users\admin\Desktop\6a609d65263f2c95ab44b534255b53c9.exeexecutable
MD5:6A609D65263F2C95AB44B534255B53C9
SHA256:20DEF0B3ABB9FCE81424CEB394A1E184EF9C504F96B85A4D32637AA5CA069AAA
564WinRAR.exeC:\Users\admin\Desktop\33fe4259a21b93c20ef6a920b6311b8f.exeexecutable
MD5:33FE4259A21B93C20EF6A920B6311B8F
SHA256:3984F62C9C5E3AF60DF7278B321057FCF131B6B30887B4802F4A536277B44589
564WinRAR.exeC:\Users\admin\Desktop\3a5a024582f9c0a6a08e5ff3b3e1ea7e.exeexecutable
MD5:3A5A024582F9C0A6A08E5FF3B3E1EA7E
SHA256:2A0275EF3173C01D4802E0ADFEDED1CA2A67C63D53B3EA60EF82D3D558C614B7
564WinRAR.exeC:\Users\admin\Desktop\b7732333c67d9155ebe9c3a11f966143.exeexecutable
MD5:B7732333C67D9155EBE9C3A11F966143
SHA256:99025DE2DE0CB3B8D407F23EF31B4E0851EE12F0893EFDFC8E02057DDAB954B8
564WinRAR.exeC:\Users\admin\Desktop\545211f79941424f26866b9f00ad361b.exeexecutable
MD5:545211F79941424F26866B9F00AD361B
SHA256:235A898FFCD14C165495DEC3B265492F17D09527FE55C6B0072B25727C6A2BAB
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
10
DNS requests
2
Threats
1

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
whitelisted
2588
svchost.exe
239.255.255.250:1900
whitelisted
2292
127277c0097cef5ce18f0002a2456f84.exe
34.41.229.245:80
pywolwnvd.biz
GOOGLE-CLOUD-PLATFORM
US
unknown
3884
dplaysvr.exe
192.168.100.2:1900
whitelisted
828
svchost.exe
239.255.255.250:3702
whitelisted

DNS requests

Domain
IP
Reputation
pywolwnvd.biz
  • 34.41.229.245
unknown
dns.msftncsi.com
  • 131.107.255.255
shared

Threats

PID
Process
Class
Message
1080
svchost.exe
Potentially Bad Traffic
ET INFO Observed DNS Query to .biz TLD
Process
Message
cleanmgr.exe
PID=3784 Instantiating the Provider Store. - CDISMImageSession::get_ProviderStore
cleanmgr.exe
PID=3784 Initializing a provider store for the LOCAL session type. - CDISMProviderStore::Final_OnConnect
cleanmgr.exe
PID=3784 Getting Provider OSServices - CDISMProviderStore::GetProvider
cleanmgr.exe
PID=3784 Failed to get an OSServices provider. Must be running in local store. Falling back to checking alongside the log provider for wdscore.dll. - CDISMLogger::FindWdsCore(hr:0x80004005)
cleanmgr.exe
PID=3784 Attempting to initialize the logger from the Image Session. - CDISMProviderStore::Final_OnConnect
cleanmgr.exe
PID=3784 Loading Provider from location C:\Windows\System32\Dism\LogProvider.dll - CDISMProviderStore::Internal_GetProvider
cleanmgr.exe
PID=3784 Provider has not previously been encountered. Attempting to initialize the provider. - CDISMProviderStore::Internal_GetProvider
cleanmgr.exe
PID=3784 The requested provider was not found in the Provider Store. - CDISMProviderStore::Internal_GetProvider(hr:0x80004005)
cleanmgr.exe
PID=3784 Connecting to the provider located at C:\Windows\System32\Dism\LogProvider.dll. - CDISMProviderStore::Internal_LoadProvider
Dism.exe
PID=528 Instantiating the Provider Store. - CDISMImageSession::get_ProviderStore