| File name: | Office_C2R_2023.rar |
| Full analysis: | https://app.any.run/tasks/f8c9a233-0f77-42ec-a555-c77ac1bf6ecd |
| Verdict: | Malicious activity |
| Analysis date: | January 29, 2024, 19:33:39 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-rar |
| File info: | RAR archive data, v5 |
| MD5: | 9C6EA80DD89D68A4F8FB39D11CAADC64 |
| SHA1: | C380DFE70ADDE4A23601D597FC862C4A2E79D750 |
| SHA256: | 149FC381395801B5AD1C79DECF52AA93B8B81161CE71441446252A41BCF6BEFE |
| SSDEEP: | 196608:vJJQlOmGFWWRXPq2WDTkY9/wPCP4nTIeE:vPQlOmGUudWDwY5wZng |
| .rar | | | RAR compressed archive (v5.0) (61.5) |
|---|---|---|
| .rar | | | RAR compressed archive (gen) (38.4) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 268 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Office_C2R_2023.rar" | C:\Program Files\WinRAR\WinRAR.exe | — | explorer.exe | |||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| 908 | "C:\Windows\System32\reg.exe" add "HKLM\SOFTWARE\Microsoft\Windows Script Host\Settings" /v Enabled /t REG_DWORD /d 1 /f | C:\Windows\System32\reg.exe | — | OInstall_7.6.0.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Registry Console Tool Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1072 | "C:\Windows\System32\cmd.exe" /c REG QUERY HKLM\Software\WOW6432Node\Microsoft\Office /s /v Path | C:\Windows\System32\cmd.exe | — | OInstall_7.6.0.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 1 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 1604 | REG QUERY HKLM\Software\Microsoft\Office /s /v Path /reg:64 | C:\Windows\System32\reg.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Registry Console Tool Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1632 | "C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\Rar$DIa268.32882\Office_C2R_2023_7.6.0.rar | C:\Program Files\WinRAR\WinRAR.exe | WinRAR.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| 1652 | REG QUERY HKLM\Software\WOW6432Node\Microsoft\Office /s /v Path | C:\Windows\System32\reg.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Registry Console Tool Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2088 | "C:\Windows\System32\cmd.exe" /c REG QUERY HKLM\Software\Microsoft\Office /s /v Path /reg:64 | C:\Windows\System32\cmd.exe | — | OInstall_7.6.0.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 2204 | "C:\Windows\System32\cmd.exe" /D /c C:\Users\admin\AppData\Local\Temp\test.exe kms.loli.beer:1688 -l Windows -6 | C:\Windows\System32\cmd.exe | — | OInstall_7.6.0.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 2228 | "C:\Windows\System32\cmd.exe" /D /c cscript.exe "" //NoLogo /act | C:\Windows\System32\cmd.exe | — | OInstall_7.6.0.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 1 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 2332 | "C:\Windows\System32\cmd.exe" /c cscript.exe ospp.vbs /dstatusall | C:\Windows\System32\cmd.exe | — | O15-21LicSetup.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| (PID) Process: | (268) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (268) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip | |||
| (PID) Process: | (268) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\phacker.zip | |||
| (PID) Process: | (268) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (268) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip | |||
| (PID) Process: | (268) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (268) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (268) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (268) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (268) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 268 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DIa268.32882\Office_C2R_2023_7.6.0.rar | — | |
MD5:— | SHA256:— | |||
| 1632 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb1632.33232\Office_C2R_2023_7.6.0\files\x86\cleanospp.exe | executable | |
MD5:5FD363D52D04AC200CD24F3BCC903200 | SHA256:3FDEFE2AD092A9A7FE0EDF0AC4DC2DE7E5B9CE6A0804F6511C06564194966CF9 | |||
| 1632 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb1632.33232\Office_C2R_2023_7.6.0\files\Uninstall.xml | text | |
MD5:364F86F97324EA82FE0D142CD01CF6DD | SHA256:09D5B42140BAB13165BA97FBD0E77792304C3C93555BE02C3DCE21A7A69C66DD | |||
| 1632 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb1632.33232\Office_C2R_2023_7.6.0\files\Configure.xml | text | |
MD5:62ED85E5A45666AD7999DB9F19AE0454 | SHA256:E0C5B4921562D8162FFC0D1B4EE70C804EAD5C1569E56A027C504CFD8C2E831F | |||
| 1632 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb1632.33232\Office_C2R_2023_7.6.0\files\x64\cleanospp.exe | executable | |
MD5:162AB955CB2F002A73C1530AA796477F | SHA256:5CE462E5F34065FC878362BA58617FAB28C22D631B9D836DDDCF43FB1AD4DE6E | |||
| 3600 | O15-21LicSetup.exe | C:\Users\admin\AppData\Local\Temp\files.dat | executable | |
MD5:DC2D0D6E8B2D38B3456DACD9D4FCF392 | SHA256:6CCC6BB1569067BFCC579AB0A432987638EB37F3675AADE0388467E232D97EF9 | |||
| 3560 | files.dat | C:\Users\admin\AppData\Local\Temp\o15files\AccessR_Retail-pl.xrm-ms | xml | |
MD5:D6BAF3C4B189AD459BFDCFE0ED872C5F | SHA256:F27BE859E64B4796A7CFB4E210534A5D07C7E77347058C216EA47753B939B4D4 | |||
| 3560 | files.dat | C:\Users\admin\AppData\Local\Temp\o15files\AccessR_OEM_Perp-pl.xrm-ms | xml | |
MD5:2DBFB475049A649A07512E6BE8D5E1B4 | SHA256:C34A77B0F5573B303ECEE1038E5B8AADFA7A2088BA8B8B64669B18723CD54046 | |||
| 2824 | OInstall_7.6.0.exe | C:\Users\admin\AppData\Local\Temp\O15-21LicSetup.exe | executable | |
MD5:E45C355308AC0B2322F96E64CEBBF875 | SHA256:783AD384DE39C8F5BD7DCF46FFEF99BB9DAD4A43D5579C40B982C1CC6FFFEE12 | |||
| 3560 | files.dat | C:\Users\admin\AppData\Local\Temp\o15files\AccessR_Grace-ul-oob.xrm-ms | xml | |
MD5:9602E7CC4CB46F3B6E4FA33E158AB0D7 | SHA256:6B14E4026FEF6E824E07310F570E4C820E18AF35849A9037777EA46DBF2B4FFC | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
3248 | test.exe | 104.208.72.228:1688 | kms.loli.beer | MICROSOFT-CORP-MSN-AS-BLOCK | HK | unknown |
Domain | IP | Reputation |
|---|---|---|
kms.loli.beer |
| unknown |