File name:

Data.rar

Full analysis: https://app.any.run/tasks/d888a149-5557-4a20-af10-fbe054c071b1
Verdict: Malicious activity
Analysis date: July 10, 2024, 10:05:11
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

6C601F323F0BE0CAF858C05D2CB5E457

SHA1:

99ABF21D0E4E93812836059F157C7841FDF3C097

SHA256:

1929125CA9D94A06BAC946F4ADB4CD96E0DEEAE5C1A3F85704F1760B8F3F5EE6

SSDEEP:

98304:KKLW+9ExNKGbOqVjk1xy8gZEV1gH6f2rajDXxX4cnJj8Lt+cRY51kwbcnh/3/Z0i:KxUbHrY9bWFuW+F1

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 6616)
    • Creates a writable file in the system directory

      • WerFault.exe (PID: 2012)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • WinRAR.exe (PID: 6616)
    • Reads security settings of Internet Explorer

      • WinRAR.exe (PID: 6616)
      • update_task.exe (PID: 240)
      • LockApp.exe (PID: 5048)
      • update_task.exe (PID: 2992)
    • The process creates files with name similar to system file names

      • WinRAR.exe (PID: 6616)
    • Reads the date of Windows installation

      • update_task.exe (PID: 240)
      • update_task.exe (PID: 2992)
    • Executes as Windows Service

      • wsc_proxy.exe (PID: 3724)
      • wsc_proxy.exe (PID: 4320)
    • Executes application which crashes

      • wsc_proxy.exe (PID: 3724)
      • wsc_proxy.exe (PID: 4320)
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 6616)
    • Checks supported languages

      • update_task.exe (PID: 240)
      • SkypeApp.exe (PID: 4164)
      • LockApp.exe (PID: 5048)
      • wsc_proxy.exe (PID: 3724)
      • update_task.exe (PID: 2992)
      • SkypeApp.exe (PID: 4028)
      • wsc_proxy.exe (PID: 4320)
    • Reads the computer name

      • update_task.exe (PID: 240)
      • LockApp.exe (PID: 5048)
      • SkypeApp.exe (PID: 4164)
      • wsc_proxy.exe (PID: 3724)
      • update_task.exe (PID: 2992)
      • wsc_proxy.exe (PID: 4320)
      • SkypeApp.exe (PID: 4028)
    • Process checks computer location settings

      • update_task.exe (PID: 240)
      • update_task.exe (PID: 2992)
    • Create files in a temporary directory

      • SkypeApp.exe (PID: 4164)
      • SkypeApp.exe (PID: 4028)
    • Reads the machine GUID from the registry

      • wsc_proxy.exe (PID: 3724)
      • wsc_proxy.exe (PID: 4320)
    • Reads CPU info

      • wsc_proxy.exe (PID: 3724)
      • wsc_proxy.exe (PID: 4320)
    • Creates files in the program directory

      • wsc_proxy.exe (PID: 3724)
    • Reads the software policy settings

      • WerFault.exe (PID: 2012)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
159
Monitored processes
16
Malicious processes
1
Suspicious processes
2

Behavior graph

Click at the process to see the details
start winrar.exe update_task.exe no specs update_task.exe conhost.exe no specs skypeapp.exe no specs conhost.exe no specs lockapp.exe no specs wsc_proxy.exe werfault.exe update_task.exe no specs update_task.exe conhost.exe no specs skypeapp.exe no specs conhost.exe no specs wsc_proxy.exe werfault.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
240"C:\Users\admin\AppData\Local\Temp\Rar$EXa6616.24560\Data\update_task.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa6616.24560\Data\update_task.exe
WinRAR.exe
User:
admin
Company:
Fortinet Inc.
Integrity Level:
HIGH
Description:
FortiClient Virus Feedback Service
Version:
7.2.4.0972
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa6616.24560\data\update_task.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
448\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeSkypeApp.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
992"C:\Users\admin\AppData\Local\Temp\Rar$EXa6616.24560\Data\update_task.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa6616.24560\Data\update_task.exeWinRAR.exe
User:
admin
Company:
Fortinet Inc.
Integrity Level:
MEDIUM
Description:
FortiClient Virus Feedback Service
Exit code:
3221226540
Version:
7.2.4.0972
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa6616.24560\data\update_task.exe
c:\windows\system32\ntdll.dll
1004\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeupdate_task.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2012C:\WINDOWS\system32\WerFault.exe -u -p 3724 -s 1328C:\Windows\System32\WerFault.exe
wsc_proxy.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Problem Reporting
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
2112C:\WINDOWS\system32\WerFault.exe -u -p 4320 -s 1276C:\Windows\System32\WerFault.exewsc_proxy.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
2132"C:\Users\admin\AppData\Local\Temp\Rar$EXa6616.26787\Data\update_task.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa6616.26787\Data\update_task.exeWinRAR.exe
User:
admin
Company:
Fortinet Inc.
Integrity Level:
MEDIUM
Description:
FortiClient Virus Feedback Service
Exit code:
3221226540
Version:
7.2.4.0972
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa6616.26787\data\update_task.exe
c:\windows\system32\ntdll.dll
2992"C:\Users\admin\AppData\Local\Temp\Rar$EXa6616.26787\Data\update_task.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa6616.26787\Data\update_task.exe
WinRAR.exe
User:
admin
Company:
Fortinet Inc.
Integrity Level:
HIGH
Description:
FortiClient Virus Feedback Service
Version:
7.2.4.0972
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa6616.26787\data\update_task.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\users\admin\appdata\local\temp\rar$exa6616.26787\data\utilsdll.dll
3104\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeSkypeApp.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3724"C:\Users\admin\AppData\Local\Temp\Rar$EXa6616.24560\Data\wsc_proxy.exe" /runassvc /rpcserver /wsc_name:" "C:\Users\admin\AppData\Local\Temp\Rar$EXa6616.24560\Data\wsc_proxy.exe
services.exe
User:
SYSTEM
Company:
AVAST Software
Integrity Level:
SYSTEM
Description:
Avast remediation exe
Version:
21.4.6162.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa6616.24560\data\wsc_proxy.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\users\admin\appdata\local\temp\rar$exa6616.24560\data\wsc.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\msvcrt.dll
Total events
19 454
Read events
19 377
Write events
71
Delete events
6

Modification events

(PID) Process:(6616) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(6616) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(6616) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\GoogleChromeEnterpriseBundle64.zip
(PID) Process:(6616) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Data.rar
(PID) Process:(6616) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(6616) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(6616) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(6616) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(6616) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\DialogEditHistory\ExtrPath
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Data
(PID) Process:(6616) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
Executable files
21
Suspicious files
8
Text files
4
Unknown types
0

Dropped files

PID
Process
Filename
Type
6616WinRAR.exeC:\Users\admin\AppData\Local\Temp\Data\Data\SkypeApp.exeexecutable
MD5:C0DCAE518FE65E407FDBB6F2A71B35C7
SHA256:CB2FF159566E5D73EC3DF5C12ED502648F0F35D1917BEFCE39E9569B09CA4DCD
6616WinRAR.exeC:\Users\admin\AppData\Local\Temp\Data\Data\explorer.exe.muiexecutable
MD5:F84FF7D56E9921D21522821BDE1D3228
SHA256:429D4BC00F03A197300B1791444E47A5CD51AB14D2A35E31D1CB4F96CD555774
6616WinRAR.exeC:\Users\admin\AppData\Local\Temp\Data\Data\wsc.dllexecutable
MD5:D60E8A632A3FF1F145F84C7231BAA6BD
SHA256:DE820B5E592CF456F6A4F8356195C4A335A51C6354CA7AC32CCD390E62D9BECC
6616WinRAR.exeC:\Users\admin\AppData\Local\Temp\Data\Data\bootstat.datbinary
MD5:CD92E4F79851F17ACF0719F3C9C12B39
SHA256:7A510517252AA94DBD5E0C185F3B42C3AAA87292DA681ECF0B6B755B3C627754
6616WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa6616.24560\Data\update_task.exeexecutable
MD5:624A9592ECF9DC33A8F837DC5256A2BC
SHA256:A4B2439027F2F45D95D6C9DF9979B76AB6B3252886CDDE436BF5F9AE88D79B13
6616WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa6616.24560\Data\utilsdll.dllexecutable
MD5:88118F697925A8DD74691B714AB8B4C9
SHA256:E0EDE21DCEE0D47825D7B869395C0805EA9AF2797D1E7CED8F296D55E15DA9A0
6616WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa6616.24560\Data\SkypeApp.exeexecutable
MD5:C0DCAE518FE65E407FDBB6F2A71B35C7
SHA256:CB2FF159566E5D73EC3DF5C12ED502648F0F35D1917BEFCE39E9569B09CA4DCD
6616WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa6616.24560\Data\wsc.dllexecutable
MD5:D60E8A632A3FF1F145F84C7231BAA6BD
SHA256:DE820B5E592CF456F6A4F8356195C4A335A51C6354CA7AC32CCD390E62D9BECC
3724wsc_proxy.exeC:\ProgramData\Avast Software\Avast\log\wsc.logtext
MD5:ECAA88F7FA0BF610A5A26CF545DCD3AA
SHA256:F1945CD6C19E56B3C1C78943EF5EC18116907A4CA1EFC40A57D48AB1DB7ADFC5
6616WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa6616.24560\Data\wsc_proxy.exeexecutable
MD5:1B231B5C4D36DE4750A587F08338DEDE
SHA256:79E53D36A40951AB328E153BAC9C1E3ADF3330B45899345E645889B9046F06E0
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
12
TCP/UDP connections
84
DNS requests
19
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
2.16.241.12:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
GET
200
2.16.241.12:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
GET
200
2.16.241.12:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
4656
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
2456
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
5864
SIHClient.exe
GET
200
88.221.125.143:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
5864
SIHClient.exe
GET
200
88.221.125.143:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4032
svchost.exe
239.255.255.250:1900
unknown
4656
SearchApp.exe
92.123.104.53:443
www.bing.com
Akamai International B.V.
DE
unknown
4
System
192.168.100.255:138
unknown
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
2.16.241.12:80
crl.microsoft.com
Akamai International B.V.
DE
unknown
4656
SearchApp.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
unknown
88.221.169.152:80
www.microsoft.com
AKAMAI-AS
DE
unknown
3676
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
4
System
192.168.100.255:137
unknown
2456
svchost.exe
20.190.160.17:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
unknown

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 4.231.128.59
unknown
www.bing.com
  • 92.123.104.53
  • 92.123.104.60
  • 92.123.104.52
  • 92.123.104.61
  • 92.123.104.59
  • 92.123.104.51
  • 92.123.104.63
  • 92.123.104.57
  • 92.123.104.58
unknown
google.com
  • 142.250.186.46
unknown
crl.microsoft.com
  • 2.16.241.12
  • 2.16.241.14
unknown
ocsp.digicert.com
  • 192.229.221.95
unknown
www.microsoft.com
  • 88.221.169.152
  • 88.221.125.143
unknown
login.live.com
  • 20.190.160.17
  • 40.126.32.76
  • 40.126.32.138
  • 20.190.160.20
  • 40.126.32.140
  • 20.190.160.14
  • 40.126.32.133
  • 40.126.32.136
unknown
go.microsoft.com
  • 184.28.89.167
unknown
nexusrules.officeapps.live.com
  • 52.111.243.31
unknown
arc.msn.com
  • 20.223.35.26
  • 20.223.36.55
unknown

Threats

No threats detected
Process
Message
wsc_proxy.exe
[2024-07-10 10:05:52.031] [error ] [crashguard ] [ 3724: 6152] [E9669F: 103] Dump path 'C:\ProgramData\Avast Software\Avast\log' does not exist. Directory should be already created.