analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

N-A.rar

Full analysis: https://app.any.run/tasks/01d45ae7-4e8e-487a-9c0e-9127813fe48e
Verdict: Malicious activity
Analysis date: May 20, 2019, 12:19:35
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, flags: EncryptedBlockHeader
MD5:

0885A4CB43BB866017E19BD3776D8F82

SHA1:

7695B3374C69487BAF670DE76DC2BDFEEB85C362

SHA256:

1B6C6433413E64657B7B13BF24D6D1B64895604D57C85C291DC39A0AF68E1648

SSDEEP:

24:HUnDMX8laWnLt3m0K6Sk/D43zlp/LsxgjRNt7oL26z+le4o0O75ABBc74777:0D7l53m6SkMh5LsCj7oqs6kABBcK

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes settings of System certificates

      • WScript.exe (PID: 2704)
      • WScript.exe (PID: 2792)
  • SUSPICIOUS

    • Creates files in the user directory

      • WScript.exe (PID: 2792)
    • Adds / modifies Windows certificates

      • WScript.exe (PID: 2792)
      • WScript.exe (PID: 2704)
    • Executes scripts

      • WinRAR.exe (PID: 2816)
  • INFO

    • Manual execution by user

      • WScript.exe (PID: 2704)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v-4.x) (58.3)
.rar | RAR compressed archive (gen) (41.6)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
36
Monitored processes
3
Malicious processes
2
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe no specs wscript.exe wscript.exe

Process information

PID
CMD
Path
Indicators
Parent process
2816"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\N-A.rar"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.60.0
2792"C:\Windows\System32\WScript.exe" "C:\Users\admin\AppData\Local\Temp\Rar$DIb2816.30352\АО Нордавиа — региональные авиалинии информация о заказе.js" C:\Windows\System32\WScript.exe
WinRAR.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft ® Windows Based Script Host
Exit code:
0
Version:
5.8.7600.16385
2704"C:\Windows\System32\WScript.exe" "C:\Users\admin\Desktop\АО Нордавиа — региональные авиалинии информация о заказе.js" C:\Windows\System32\WScript.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft ® Windows Based Script Host
Exit code:
0
Version:
5.8.7600.16385
Total events
582
Read events
511
Write events
0
Delete events
0

Modification events

No data
Executable files
0
Suspicious files
0
Text files
1
Unknown types
1

Dropped files

PID
Process
Filename
Type
2816WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb2816.33211\АО Нордавиа — региональные авиалинии информация о заказе.js
MD5:
SHA256:
2792WScript.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\IETldCache\index.datdat
MD5:D7A950FEFD60DBAA01DF2D85FEFB3862
SHA256:75D0B1743F61B76A35B1FEDD32378837805DE58D79FA950CB6E8164BFA72073A
2816WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DIb2816.30352\АО Нордавиа — региональные авиалинии информация о заказе.jstext
MD5:90506B39F897D808FAF922BC02919576
SHA256:A97F89E38CA8EB7E2306D8D2EDBCCA08B84F73DD59C19A76819B925F5A6BCF3F
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
10
DNS requests
2
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2792
WScript.exe
82.100.197.110:443
webalytics.de
MK Netzdienste GmbH & Co. KG
DE
unknown
82.100.197.110:443
webalytics.de
MK Netzdienste GmbH & Co. KG
DE
unknown
2792
WScript.exe
67.225.176.232:443
paabay.com
Liquid Web, L.L.C
US
unknown
2704
WScript.exe
82.100.197.110:443
webalytics.de
MK Netzdienste GmbH & Co. KG
DE
unknown
2704
WScript.exe
67.225.176.232:443
paabay.com
Liquid Web, L.L.C
US
unknown

DNS requests

Domain
IP
Reputation
webalytics.de
  • 82.100.197.110
unknown
paabay.com
  • 67.225.176.232
unknown

Threats

No threats detected
No debug info