File name: | 16f3ee95507543bade1b9593d3474591cc4ce61c6c4f78131a8a3708b8c5e43c |
Full analysis: | https://app.any.run/tasks/a9ea7bd4-12a1-4145-95e3-a3feb44ba1d5 |
Verdict: | Malicious activity |
Analysis date: | August 13, 2019, 21:55:55 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | application/x-rar |
File info: | RAR archive data, v4, os: Win32 |
MD5: | F40D09D28D66B6B7EBB93A7F8D8AF4D7 |
SHA1: | 57965B9BFC2B30686CB5B5368DFF9945937F085B |
SHA256: | 16F3EE95507543BADE1B9593D3474591CC4CE61C6C4F78131A8A3708B8C5E43C |
SSDEEP: | 3072:sR02hGnU2zywJYvMSQQszpEHCY+HjiXqKsufCiPQe3L:sR7hGhDGES/r8kqZsaeb |
.rar | | | RAR compressed archive (v-4.x) (58.3) |
---|---|---|
.rar | | | RAR compressed archive (gen) (41.6) |
ArchivedFileName: | trz8630.tmp |
---|---|
PackingMethod: | Normal |
ModifyDate: | 2018:08:30 07:03:17 |
OperatingSystem: | Win32 |
UncompressedSize: | 215040 |
CompressedSize: | 127053 |
PID | CMD | Path | Indicators | Parent process |
---|---|---|---|---|
2812 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\16f3ee95507543bade1b9593d3474591cc4ce61c6c4f78131a8a3708b8c5e43c.rar" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | |
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Version: 5.60.0 | ||||
316 | "C:\Windows\explorer.exe" | C:\Windows\explorer.exe | — | explorer.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Explorer Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
2376 | "C:\Users\admin\Downloads\trz8630.tmp.exe" | C:\Users\admin\Downloads\trz8630.tmp.exe | — | explorer.exe |
User: admin Company: INTROPRO LLC Integrity Level: MEDIUM Description: Standups Simplicity Brightness Drawtext Succession Catalg Exit code: 0 Version: 3.7.6.5 | ||||
3520 | "C:\Users\admin\Downloads\trz8630.tmp.exe" | C:\Users\admin\Downloads\trz8630.tmp.exe | explorer.exe | |
User: admin Company: INTROPRO LLC Integrity Level: HIGH Description: Standups Simplicity Brightness Drawtext Succession Catalg Exit code: 0 Version: 3.7.6.5 |
(PID) Process: | (2812) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
Operation: | write | Name: | ShellExtBMP |
Value: | |||
(PID) Process: | (2812) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
Operation: | write | Name: | ShellExtIcon |
Value: | |||
(PID) Process: | (2812) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\72\52C64B7E |
Operation: | write | Name: | LanguageList |
Value: en-US | |||
(PID) Process: | (2812) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\16f3ee95507543bade1b9593d3474591cc4ce61c6c4f78131a8a3708b8c5e43c.rar | |||
(PID) Process: | (2812) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | name |
Value: 120 | |||
(PID) Process: | (2812) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | size |
Value: 80 | |||
(PID) Process: | (2812) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | type |
Value: 120 | |||
(PID) Process: | (2812) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | mtime |
Value: 100 | |||
(PID) Process: | (2812) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\DialogEditHistory\ExtrPath |
Operation: | write | Name: | 0 |
Value: C:\Users\admin\Downloads |
PID | Process | Filename | Type | |
---|---|---|---|---|
2812 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2812.38328\trz8630.tmp | — | |
MD5:— | SHA256:— | |||
2812 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2812.42198\trz8630.tmp | — | |
MD5:— | SHA256:— | |||
2812 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\trz8630.tmp | executable | |
MD5:A33583C33863DFA0775E74E6A4FC8D44 | SHA256:A86571D99C5AD4129591309FA96A2071AB7B4B61E2F870646BF0417802FE9245 | |||
2812 | WinRAR.exe | C:\Users\admin\Downloads\trz8630.tmp | executable | |
MD5:A33583C33863DFA0775E74E6A4FC8D44 | SHA256:A86571D99C5AD4129591309FA96A2071AB7B4B61E2F870646BF0417802FE9245 | |||
2812 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2812.40151\trz8630.tmp | executable | |
MD5:A33583C33863DFA0775E74E6A4FC8D44 | SHA256:A86571D99C5AD4129591309FA96A2071AB7B4B61E2F870646BF0417802FE9245 |