File name:

Windows.7.Loader.eXtreme.Edition.3.503-Napalum.rar

Full analysis: https://app.any.run/tasks/a86b3ebe-bcac-457d-a208-2e1a81301613
Verdict: Malicious activity
Analysis date: May 27, 2024, 18:03:23
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v4, os: Win32
MD5:

0C805E760DBD479E243ECE8702F37F71

SHA1:

A9947A92A88A6180A35BE908664D2951B7A3853A

SHA256:

1C80E271468C5B3CE2159AC1CCE71DFF46CCF84C195C447DC3E241043B9D66CA

SSDEEP:

98304:ThpZOzSQHakbxkP4Ed5Xs9CAqTXLYlnLwSH2C4fbTFZc7e2CicBVIer2wa5zXOPY:LPaIvGyV/Q

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 3968)
      • w7lxe.exe (PID: 936)
    • Changes the autorun value in the registry

      • w7lxe.exe (PID: 936)
    • Modifies hosts file to block updates

      • w7lxe.exe (PID: 936)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • w7lxe.exe (PID: 936)
    • Checks Windows Trust Settings

      • w7lxe.exe (PID: 936)
    • Reads settings of System Certificates

      • w7lxe.exe (PID: 936)
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3968)
    • Checks supported languages

      • wmpnscfg.exe (PID: 2344)
      • w7lxe.exe (PID: 936)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 2344)
      • w7lxe.exe (PID: 936)
      • w7lxe.exe (PID: 2168)
      • msedge.exe (PID: 2028)
    • Reads the machine GUID from the registry

      • w7lxe.exe (PID: 936)
    • Reads Windows Product ID

      • w7lxe.exe (PID: 936)
    • Reads the computer name

      • w7lxe.exe (PID: 936)
      • wmpnscfg.exe (PID: 2344)
    • Reads the software policy settings

      • w7lxe.exe (PID: 936)
    • Process checks computer location settings

      • w7lxe.exe (PID: 936)
    • Reads Environment values

      • w7lxe.exe (PID: 936)
    • Reads product name

      • w7lxe.exe (PID: 936)
    • Application launched itself

      • msedge.exe (PID: 2028)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v-4.x) (58.3)
.rar | RAR compressed archive (gen) (41.6)

EXIF

ZIP

CompressedSize: 4322
UncompressedSize: 18458
OperatingSystem: Win32
ModifyDate: 2010:05:21 02:00:48
PackingMethod: Normal
ArchivedFileName: Windows.7.Loader.eXtreme.Edition.3.503-Napalum\FAQ\FAQ(Arabic).txt
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
55
Monitored processes
12
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs wmpnscfg.exe no specs w7lxe.exe no specs w7lxe.exe

Process information

PID
CMD
Path
Indicators
Parent process
372"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" "--metrics-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=109.0.5414.149 "--annotation=exe=C:\Program Files\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win32 "--annotation=prod=Microsoft Edge" --annotation=ver=109.0.1518.115 --initial-client-data=0xc8,0xcc,0xd0,0x9c,0xd8,0x67bdf598,0x67bdf5a8,0x67bdf5b4C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
936"C:\Users\admin\Desktop\Windows.7.Loader.eXtreme.Edition.3.503-Napalum\w7lxe.exe" C:\Users\admin\Desktop\Windows.7.Loader.eXtreme.Edition.3.503-Napalum\w7lxe.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Description:
Universal Windows Activation Tool
Exit code:
0
Version:
3.5.0.3
Modules
Images
c:\users\admin\desktop\windows.7.loader.extreme.edition.3.503-napalum\w7lxe.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1548"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --first-renderer-process --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --mojo-platform-channel-handle=2212 --field-trial-handle=1352,i,14859021256935593133,9899944063556103420,131072 /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1616"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=1664 --field-trial-handle=1352,i,14859021256935593133,9899944063556103420,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1660"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1320 --field-trial-handle=1352,i,14859021256935593133,9899944063556103420,131072 /prefetch:3C:\Program Files\Microsoft\Edge\Application\msedge.exe
msedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1664"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1340 --field-trial-handle=1352,i,14859021256935593133,9899944063556103420,131072 /prefetch:2C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2028"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --single-argument C:\Users\admin\Desktop\Windows.7.Loader.eXtreme.Edition.3.503-Napalum\README.htmC:\Program Files\Microsoft\Edge\Application\msedge.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2168"C:\Users\admin\Desktop\Windows.7.Loader.eXtreme.Edition.3.503-Napalum\w7lxe.exe" C:\Users\admin\Desktop\Windows.7.Loader.eXtreme.Edition.3.503-Napalum\w7lxe.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Universal Windows Activation Tool
Exit code:
3221226540
Version:
3.5.0.3
Modules
Images
c:\users\admin\desktop\windows.7.loader.extreme.edition.3.503-napalum\w7lxe.exe
c:\windows\system32\ntdll.dll
2248"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=2220 --field-trial-handle=1352,i,14859021256935593133,9899944063556103420,131072 /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2344"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
Total events
10 006
Read events
9 930
Write events
69
Delete events
7

Modification events

(PID) Process:(3968) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3968) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3968) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3968) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(3968) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(3968) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(3968) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Windows.7.Loader.eXtreme.Edition.3.503-Napalum.rar
(PID) Process:(3968) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3968) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3968) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
Executable files
1
Suspicious files
60
Text files
38
Unknown types
1

Dropped files

PID
Process
Filename
Type
3968WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3968.33634\Windows.7.Loader.eXtreme.Edition.3.503-Napalum\FAQ\FAQ(Czech).txtbinary
MD5:22D4742A6298FC3EA2D7C60FE7443826
SHA256:3120C74CC07C1F13BC6E172E39D56471A1B4D62809D020487845ECA423883134
3968WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3968.33634\Windows.7.Loader.eXtreme.Edition.3.503-Napalum\FAQ\FAQ(Hebrew).txtbinary
MD5:A14296DAF1E3B920DF1521638D1E984F
SHA256:B3549C7F74839D492A4DAD0ACD0F3B345D007034257FF60FCC435E070D5F4C3B
3968WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3968.33634\Windows.7.Loader.eXtreme.Edition.3.503-Napalum\FAQ\FAQ(French).txtbinary
MD5:F6DEECDAA3A825253DE705D5E90966FE
SHA256:BD0DDEE82AEA941B339FFCB2FE020F1110B1C20578678E14CCEECBD0CDC57BF4
3968WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3968.33634\Windows.7.Loader.eXtreme.Edition.3.503-Napalum\FAQ\FAQ(Korean).txtbinary
MD5:DD291A0EEF29039FB1C0B322339D345D
SHA256:1D875DFF89EF3493B7E66900345656E691DE111228491FAE1667C183040025D8
3968WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3968.33634\Windows.7.Loader.eXtreme.Edition.3.503-Napalum\FAQ\FAQ(Arabic).txtbinary
MD5:6FB0CAFB2697EA0C12C4087B302587FC
SHA256:0296A6631F9822B163B0EF1B0180FF970D34D15D9A1E5B8039DCB58D9CB45640
3968WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3968.33634\Windows.7.Loader.eXtreme.Edition.3.503-Napalum\FAQ\FAQ(Dutch).txtbinary
MD5:4674A9C8D7CFADE0DA8E0F41735CC267
SHA256:FE58E4A8033CEF600DCC6ED88BFBFE27D8FD7646D926EA9A7D191CB5BED627AA
3968WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3968.33634\Windows.7.Loader.eXtreme.Edition.3.503-Napalum\FAQ\FAQ(German).txtbinary
MD5:410E6D4382DA4614BAA25D5ADAB709E4
SHA256:A13C1DBE885ACDDFD4C3E9A1C5362FC731F6FFAEEE037162A80847E44DDBB8F0
3968WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3968.33634\Windows.7.Loader.eXtreme.Edition.3.503-Napalum\FAQ\FAQ(Polish).txtbinary
MD5:1323C84051F6DDBECA52EAFF11D25EE7
SHA256:8B95C586517BE6E379C5D69F6DD8DAD99B327BE4891030CF2967898675F2CD59
3968WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3968.33634\Windows.7.Loader.eXtreme.Edition.3.503-Napalum\FAQ\FAQ(Slovak).txtbinary
MD5:2275760664029DCBB3FA116A4124811C
SHA256:28DB9D7C933E114E73DEF4E5DA931A772AD94FF543A58B906B05192EA4073955
3968WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3968.33634\Windows.7.Loader.eXtreme.Edition.3.503-Napalum\FAQ\FAQ(Welsh).txtbinary
MD5:99D5ABEA7C9B6B0B387BB6731F29939C
SHA256:667A4A0B59FD2CD427258A1C690202D02F4107BAFC63B2A7536B4B1BBDF82781
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
23
DNS requests
46
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1660
msedge.exe
GET
200
142.250.184.234:80
http://ajax.googleapis.com/ajax/libs/jquery/1.3.2/jquery.min.js
unknown
unknown
1660
msedge.exe
GET
46.105.201.240:80
http://s11.histats.com/js9.js
unknown
unknown
1660
msedge.exe
GET
302
116.202.102.103:80
http://bin-layer.de/layer-191486-1.js
unknown
unknown
1660
msedge.exe
GET
302
116.202.102.103:80
http://bin-layer.de/popup-191486-1-subid:Bumbles%20.js
unknown
unknown
1660
msedge.exe
GET
403
204.11.56.48:80
http://services.picadmedia.com/js/picad.js
unknown
unknown
1660
msedge.exe
GET
200
116.202.102.103:80
http://bin-layer.de/de/
unknown
unknown
1660
msedge.exe
GET
200
116.202.102.103:80
http://bin-layer.de/de/
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
224.0.0.252:5355
unknown
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1088
svchost.exe
224.0.0.252:5355
unknown
2028
msedge.exe
239.255.255.250:1900
unknown
1660
msedge.exe
13.107.42.16:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
1660
msedge.exe
204.79.197.239:443
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
1660
msedge.exe
49.13.77.253:80
www.bumbles.com.ar
Hetzner Online GmbH
DE
unknown
1660
msedge.exe
172.66.42.247:443
resources.infolinks.com
CLOUDFLARENET
US
unknown
1660
msedge.exe
142.250.184.234:80
ajax.googleapis.com
GOOGLE
US
whitelisted

DNS requests

Domain
IP
Reputation
config.edge.skype.com
  • 13.107.42.16
whitelisted
edge.microsoft.com
  • 204.79.197.239
  • 13.107.21.239
whitelisted
www.bumbles.com.ar
  • 49.13.77.253
unknown
i25.tinypic.com
unknown
s11.histats.com
  • 46.105.201.240
whitelisted
xslt.alexa.com
  • 49.13.77.253
whitelisted
www.freestats.org
  • 49.13.77.253
unknown
ajax.googleapis.com
  • 142.250.184.234
whitelisted
services.picadmedia.com
  • 204.11.56.48
unknown
resources.infolinks.com
  • 172.66.41.9
  • 172.66.42.247
whitelisted

Threats

No threats detected
No debug info