File name:

HCU_322 .zip

Full analysis: https://app.any.run/tasks/51251bd7-72f4-4b19-ace1-95a1c6304abd
Verdict: Suspicious activity
Analysis date: May 19, 2019, 20:56:19
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

9A4562916BC3947F6547D7F8A615405A

SHA1:

02B2FF638B270B21E3CDF24AC42DF77A1C63542F

SHA256:

16278359B7480023EF9FBD834DD3D124AECB40F1410077E38353E8418475F2DD

SSDEEP:

393216:2YcLCxxCCxYoObGh9Cp452QTOBaimRxV6aHHSlxQhofD:5PxQXOgo2QqahEanSlxuofD

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • HCU.exe (PID: 3036)
      • HCU.exe (PID: 2060)
    • Loads dropped or rewritten executable

      • HCU.exe (PID: 3036)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2908)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2017:05:12 18:25:02
ZipCRC: 0xa9154eac
ZipCompressedSize: 621642
ZipUncompressedSize: 1542656
ZipFileName: adb.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
37
Monitored processes
3
Malicious processes
1
Suspicious processes
1

Behavior graph

Click at the process to see the details
drop and start drop and start start winrar.exe hcu.exe no specs hcu.exe

Process information

PID
CMD
Path
Indicators
Parent process
2060"C:\Users\admin\AppData\Local\Temp\Rar$EXb2908.41167\HCU.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXb2908.41167\HCU.exeWinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Version:
1.0.0.322
Modules
Images
c:\users\admin\appdata\local\temp\rar$exb2908.41167\hcu.exe
c:\systemroot\system32\ntdll.dll
2908"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\HCU_322 .zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3036"C:\Users\admin\AppData\Local\Temp\Rar$EXb2908.41167\HCU.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXb2908.41167\HCU.exe
WinRAR.exe
User:
admin
Integrity Level:
HIGH
Exit code:
3735929054
Version:
1.0.0.322
Modules
Images
c:\users\admin\appdata\local\temp\rar$exb2908.41167\hcu.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
Total events
438
Read events
424
Write events
14
Delete events
0

Modification events

(PID) Process:(2908) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2908) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2908) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\62\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2908) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\HCU_322 .zip
(PID) Process:(2908) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2908) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2908) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2908) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2908) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface
Operation:writeName:ShowPassword
Value:
0
(PID) Process:(2908) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
Executable files
14
Suspicious files
0
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
2908WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb2908.41167\HCU.exeexecutable
MD5:
SHA256:
2908WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb2908.41167\FlashToolLib.dllexecutable
MD5:
SHA256:
2908WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb2908.41167\FilterBinTrans.dllexecutable
MD5:52F31086D535C5FE39737C7E1D05FA44
SHA256:43FC466340973093D3A7E92EA52EBBABDB4293E0340B1F161B72743AD76494AC
2908WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb2908.41167\AdbWinUsbApi.dllexecutable
MD5:0E24119DAF1909E398FA1850B6112077
SHA256:25207C506D29C4E8DCEB61B4BD50E8669BA26012988A43FBF26A890B1E60FC97
2908WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb2908.41167\libwinpthread-1.dllexecutable
MD5:27B901BB44C6E3417BAEEE03C9CDC4BF
SHA256:83D6E9CB6151C9ECDB330ED9CCDA7CAB7F27E5F1585D494954526A17FF69D02E
2908WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb2908.41167\password.txttext
MD5:8970FDD332B5E345AFA285F1723799D3
SHA256:F9CADE8E7587A88C035852995ED328DD144F355165BFE66C9EA72F9A58923AA2
2908WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb2908.41167\FrameCommModule.dllexecutable
MD5:B6418B8AE8D7A94C7032B990F80368EA
SHA256:75DD70CF5A423B5B5DF5C0E153432A645B779E6EE025AF36911E3063BCFED58D
2908WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb2908.41167\AdbWinApi.dllexecutable
MD5:ED5A809DC0024D83CBAB4FB9933D598D
SHA256:D60103A5E99BC9888F786EE916F5D6E45493C3247972CB053833803DE7E95CF9
2908WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb2908.41167\brom.dllexecutable
MD5:75934B7ED420478CCEA0FD210245C8F0
SHA256:882EC15BFD447756139A7F7394E9DFAE6266CDC5472FB0E19D7CBD23ED5206DF
2908WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb2908.41167\adb.exeexecutable
MD5:DEC7E5E645ADED51F9D7F02D60E9ED41
SHA256:A3887975396C74B6D4BDB49D2030881165E09B4ED89B0C7BBAF4B821D44D4643
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
Process
Message
HCU.exe
[META] Free Data library resource
HCU.exe
[META] Free Data library resource
HCU.exe
[META] Free Data library resource
HCU.exe
[META] Free Data library resource
HCU.exe
[META] Free Data library resource
HCU.exe
[META] Free Data library resource
HCU.exe
[META] Free Data library resource
HCU.exe
[META] Free Data library resource
HCU.exe
[META] Free Data library resource
HCU.exe
[META] Free Data library resource