File name:

Windows.7.Loader.eXtreme.Edition.3.503-Napalum.rar

Full analysis: https://app.any.run/tasks/a86b3ebe-bcac-457d-a208-2e1a81301613
Verdict: Malicious activity
Analysis date: May 27, 2024, 18:03:23
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v4, os: Win32
MD5:

0C805E760DBD479E243ECE8702F37F71

SHA1:

A9947A92A88A6180A35BE908664D2951B7A3853A

SHA256:

1C80E271468C5B3CE2159AC1CCE71DFF46CCF84C195C447DC3E241043B9D66CA

SSDEEP:

98304:ThpZOzSQHakbxkP4Ed5Xs9CAqTXLYlnLwSH2C4fbTFZc7e2CicBVIer2wa5zXOPY:LPaIvGyV/Q

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 3968)
      • w7lxe.exe (PID: 936)
    • Modifies hosts file to block updates

      • w7lxe.exe (PID: 936)
    • Changes the autorun value in the registry

      • w7lxe.exe (PID: 936)
  • SUSPICIOUS

    • Checks Windows Trust Settings

      • w7lxe.exe (PID: 936)
    • Reads security settings of Internet Explorer

      • w7lxe.exe (PID: 936)
    • Reads settings of System Certificates

      • w7lxe.exe (PID: 936)
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3968)
    • Checks supported languages

      • w7lxe.exe (PID: 936)
      • wmpnscfg.exe (PID: 2344)
    • Reads Windows Product ID

      • w7lxe.exe (PID: 936)
    • Process checks computer location settings

      • w7lxe.exe (PID: 936)
    • Reads the machine GUID from the registry

      • w7lxe.exe (PID: 936)
    • Reads the computer name

      • w7lxe.exe (PID: 936)
      • wmpnscfg.exe (PID: 2344)
    • Reads the software policy settings

      • w7lxe.exe (PID: 936)
    • Manual execution by a user

      • msedge.exe (PID: 2028)
      • w7lxe.exe (PID: 2168)
      • wmpnscfg.exe (PID: 2344)
      • w7lxe.exe (PID: 936)
    • Reads Environment values

      • w7lxe.exe (PID: 936)
    • Reads product name

      • w7lxe.exe (PID: 936)
    • Application launched itself

      • msedge.exe (PID: 2028)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v-4.x) (58.3)
.rar | RAR compressed archive (gen) (41.6)

EXIF

ZIP

CompressedSize: 4322
UncompressedSize: 18458
OperatingSystem: Win32
ModifyDate: 2010:05:21 02:00:48
PackingMethod: Normal
ArchivedFileName: Windows.7.Loader.eXtreme.Edition.3.503-Napalum\FAQ\FAQ(Arabic).txt
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
55
Monitored processes
12
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs wmpnscfg.exe no specs w7lxe.exe no specs w7lxe.exe

Process information

PID
CMD
Path
Indicators
Parent process
372"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" "--metrics-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=109.0.5414.149 "--annotation=exe=C:\Program Files\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win32 "--annotation=prod=Microsoft Edge" --annotation=ver=109.0.1518.115 --initial-client-data=0xc8,0xcc,0xd0,0x9c,0xd8,0x67bdf598,0x67bdf5a8,0x67bdf5b4C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
936"C:\Users\admin\Desktop\Windows.7.Loader.eXtreme.Edition.3.503-Napalum\w7lxe.exe" C:\Users\admin\Desktop\Windows.7.Loader.eXtreme.Edition.3.503-Napalum\w7lxe.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Description:
Universal Windows Activation Tool
Exit code:
0
Version:
3.5.0.3
Modules
Images
c:\users\admin\desktop\windows.7.loader.extreme.edition.3.503-napalum\w7lxe.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1548"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --first-renderer-process --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --mojo-platform-channel-handle=2212 --field-trial-handle=1352,i,14859021256935593133,9899944063556103420,131072 /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1616"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=1664 --field-trial-handle=1352,i,14859021256935593133,9899944063556103420,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1660"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1320 --field-trial-handle=1352,i,14859021256935593133,9899944063556103420,131072 /prefetch:3C:\Program Files\Microsoft\Edge\Application\msedge.exe
msedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1664"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1340 --field-trial-handle=1352,i,14859021256935593133,9899944063556103420,131072 /prefetch:2C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2028"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --single-argument C:\Users\admin\Desktop\Windows.7.Loader.eXtreme.Edition.3.503-Napalum\README.htmC:\Program Files\Microsoft\Edge\Application\msedge.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2168"C:\Users\admin\Desktop\Windows.7.Loader.eXtreme.Edition.3.503-Napalum\w7lxe.exe" C:\Users\admin\Desktop\Windows.7.Loader.eXtreme.Edition.3.503-Napalum\w7lxe.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Universal Windows Activation Tool
Exit code:
3221226540
Version:
3.5.0.3
Modules
Images
c:\users\admin\desktop\windows.7.loader.extreme.edition.3.503-napalum\w7lxe.exe
c:\windows\system32\ntdll.dll
2248"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=2220 --field-trial-handle=1352,i,14859021256935593133,9899944063556103420,131072 /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2344"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
Total events
10 006
Read events
9 930
Write events
69
Delete events
7

Modification events

(PID) Process:(3968) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3968) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3968) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3968) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(3968) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(3968) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(3968) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Windows.7.Loader.eXtreme.Edition.3.503-Napalum.rar
(PID) Process:(3968) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3968) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3968) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
Executable files
1
Suspicious files
60
Text files
38
Unknown types
1

Dropped files

PID
Process
Filename
Type
3968WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3968.33634\Windows.7.Loader.eXtreme.Edition.3.503-Napalum\FAQ\FAQ(Slovak).txtbinary
MD5:2275760664029DCBB3FA116A4124811C
SHA256:28DB9D7C933E114E73DEF4E5DA931A772AD94FF543A58B906B05192EA4073955
3968WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3968.33634\Windows.7.Loader.eXtreme.Edition.3.503-Napalum\FAQ\FAQ(French).txtbinary
MD5:F6DEECDAA3A825253DE705D5E90966FE
SHA256:BD0DDEE82AEA941B339FFCB2FE020F1110B1C20578678E14CCEECBD0CDC57BF4
3968WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3968.33634\Windows.7.Loader.eXtreme.Edition.3.503-Napalum\FAQ\FAQ(Greek).txtbinary
MD5:00073F02B9FBA562F0D6871D50F401E5
SHA256:DC94F21256276622B00E802AFC8F2305A5E621BFF11CA9E6941AF77228AB0CA1
3968WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3968.33634\Windows.7.Loader.eXtreme.Edition.3.503-Napalum\FAQ\FAQ(Czech).txtbinary
MD5:22D4742A6298FC3EA2D7C60FE7443826
SHA256:3120C74CC07C1F13BC6E172E39D56471A1B4D62809D020487845ECA423883134
3968WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3968.33634\Windows.7.Loader.eXtreme.Edition.3.503-Napalum\FAQ\FAQ(Malay).txtbinary
MD5:CDDC748327216A064B9D394BA5FFFF5E
SHA256:688584BA2A51CBC652D719BB0F6D43C36D797912DA008792D225673BBE5BED3B
3968WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3968.33634\Windows.7.Loader.eXtreme.Edition.3.503-Napalum\FAQ\FAQ(Korean).txtbinary
MD5:DD291A0EEF29039FB1C0B322339D345D
SHA256:1D875DFF89EF3493B7E66900345656E691DE111228491FAE1667C183040025D8
3968WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3968.33634\Windows.7.Loader.eXtreme.Edition.3.503-Napalum\FAQ\FAQ(Arabic).txtbinary
MD5:6FB0CAFB2697EA0C12C4087B302587FC
SHA256:0296A6631F9822B163B0EF1B0180FF970D34D15D9A1E5B8039DCB58D9CB45640
3968WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3968.33634\Windows.7.Loader.eXtreme.Edition.3.503-Napalum\FAQ\FAQ(German).txtbinary
MD5:410E6D4382DA4614BAA25D5ADAB709E4
SHA256:A13C1DBE885ACDDFD4C3E9A1C5362FC731F6FFAEEE037162A80847E44DDBB8F0
3968WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3968.33634\Windows.7.Loader.eXtreme.Edition.3.503-Napalum\FAQ\FAQ(Danish).txtbinary
MD5:85CC14E10065C26091F045D6689298F7
SHA256:11769DA102AD8E35FFCBB67857C90DE75467B924D38616A25E1A9A43D67B911D
3968WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3968.33634\Windows.7.Loader.eXtreme.Edition.3.503-Napalum\FAQ\FAQ(Hindi).txtbinary
MD5:A0AD79BCAEBD671BFBED3004C9B6FEE3
SHA256:A5BB130CCAFA1952A8DCC247B1B52C24A6D3BD6C24D009D0447F69BE4FE7B44F
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
23
DNS requests
46
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1660
msedge.exe
GET
200
116.202.102.103:80
http://bin-layer.de/de/
unknown
unknown
1660
msedge.exe
GET
46.105.201.240:80
http://s11.histats.com/js9.js
unknown
unknown
1660
msedge.exe
GET
403
204.11.56.48:80
http://services.picadmedia.com/js/picad.js
unknown
unknown
1660
msedge.exe
GET
200
116.202.102.103:80
http://bin-layer.de/de/
unknown
unknown
1660
msedge.exe
GET
200
142.250.184.234:80
http://ajax.googleapis.com/ajax/libs/jquery/1.3.2/jquery.min.js
unknown
unknown
1660
msedge.exe
GET
302
116.202.102.103:80
http://bin-layer.de/layer-191486-1.js
unknown
unknown
1660
msedge.exe
GET
302
116.202.102.103:80
http://bin-layer.de/popup-191486-1-subid:Bumbles%20.js
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
224.0.0.252:5355
unknown
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1088
svchost.exe
224.0.0.252:5355
unknown
2028
msedge.exe
239.255.255.250:1900
unknown
1660
msedge.exe
13.107.42.16:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
1660
msedge.exe
204.79.197.239:443
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
1660
msedge.exe
49.13.77.253:80
www.bumbles.com.ar
Hetzner Online GmbH
DE
unknown
1660
msedge.exe
172.66.42.247:443
resources.infolinks.com
CLOUDFLARENET
US
unknown
1660
msedge.exe
142.250.184.234:80
ajax.googleapis.com
GOOGLE
US
whitelisted

DNS requests

Domain
IP
Reputation
config.edge.skype.com
  • 13.107.42.16
whitelisted
edge.microsoft.com
  • 204.79.197.239
  • 13.107.21.239
whitelisted
www.bumbles.com.ar
  • 49.13.77.253
unknown
i25.tinypic.com
unknown
s11.histats.com
  • 46.105.201.240
whitelisted
xslt.alexa.com
  • 49.13.77.253
whitelisted
www.freestats.org
  • 49.13.77.253
unknown
ajax.googleapis.com
  • 142.250.184.234
whitelisted
services.picadmedia.com
  • 204.11.56.48
unknown
resources.infolinks.com
  • 172.66.41.9
  • 172.66.42.247
whitelisted

Threats

No threats detected
No debug info