File name:

Windows.7.Loader.eXtreme.Edition.3.503-Napalum.rar

Full analysis: https://app.any.run/tasks/a86b3ebe-bcac-457d-a208-2e1a81301613
Verdict: Malicious activity
Analysis date: May 27, 2024, 18:03:23
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v4, os: Win32
MD5:

0C805E760DBD479E243ECE8702F37F71

SHA1:

A9947A92A88A6180A35BE908664D2951B7A3853A

SHA256:

1C80E271468C5B3CE2159AC1CCE71DFF46CCF84C195C447DC3E241043B9D66CA

SSDEEP:

98304:ThpZOzSQHakbxkP4Ed5Xs9CAqTXLYlnLwSH2C4fbTFZc7e2CicBVIer2wa5zXOPY:LPaIvGyV/Q

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 3968)
      • w7lxe.exe (PID: 936)
    • Modifies hosts file to block updates

      • w7lxe.exe (PID: 936)
    • Changes the autorun value in the registry

      • w7lxe.exe (PID: 936)
  • SUSPICIOUS

    • Checks Windows Trust Settings

      • w7lxe.exe (PID: 936)
    • Reads security settings of Internet Explorer

      • w7lxe.exe (PID: 936)
    • Reads settings of System Certificates

      • w7lxe.exe (PID: 936)
  • INFO

    • Application launched itself

      • msedge.exe (PID: 2028)
    • Manual execution by a user

      • msedge.exe (PID: 2028)
      • wmpnscfg.exe (PID: 2344)
      • w7lxe.exe (PID: 2168)
      • w7lxe.exe (PID: 936)
    • Reads the computer name

      • wmpnscfg.exe (PID: 2344)
      • w7lxe.exe (PID: 936)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3968)
    • Checks supported languages

      • wmpnscfg.exe (PID: 2344)
      • w7lxe.exe (PID: 936)
    • Reads the machine GUID from the registry

      • w7lxe.exe (PID: 936)
    • Reads Environment values

      • w7lxe.exe (PID: 936)
    • Reads product name

      • w7lxe.exe (PID: 936)
    • Reads Windows Product ID

      • w7lxe.exe (PID: 936)
    • Process checks computer location settings

      • w7lxe.exe (PID: 936)
    • Reads the software policy settings

      • w7lxe.exe (PID: 936)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v-4.x) (58.3)
.rar | RAR compressed archive (gen) (41.6)

EXIF

ZIP

CompressedSize: 4322
UncompressedSize: 18458
OperatingSystem: Win32
ModifyDate: 2010:05:21 02:00:48
PackingMethod: Normal
ArchivedFileName: Windows.7.Loader.eXtreme.Edition.3.503-Napalum\FAQ\FAQ(Arabic).txt
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
55
Monitored processes
12
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs wmpnscfg.exe no specs w7lxe.exe no specs w7lxe.exe

Process information

PID
CMD
Path
Indicators
Parent process
372"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" "--metrics-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=109.0.5414.149 "--annotation=exe=C:\Program Files\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win32 "--annotation=prod=Microsoft Edge" --annotation=ver=109.0.1518.115 --initial-client-data=0xc8,0xcc,0xd0,0x9c,0xd8,0x67bdf598,0x67bdf5a8,0x67bdf5b4C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
936"C:\Users\admin\Desktop\Windows.7.Loader.eXtreme.Edition.3.503-Napalum\w7lxe.exe" C:\Users\admin\Desktop\Windows.7.Loader.eXtreme.Edition.3.503-Napalum\w7lxe.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Description:
Universal Windows Activation Tool
Exit code:
0
Version:
3.5.0.3
Modules
Images
c:\users\admin\desktop\windows.7.loader.extreme.edition.3.503-napalum\w7lxe.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1548"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --first-renderer-process --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --mojo-platform-channel-handle=2212 --field-trial-handle=1352,i,14859021256935593133,9899944063556103420,131072 /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1616"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=1664 --field-trial-handle=1352,i,14859021256935593133,9899944063556103420,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1660"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1320 --field-trial-handle=1352,i,14859021256935593133,9899944063556103420,131072 /prefetch:3C:\Program Files\Microsoft\Edge\Application\msedge.exe
msedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1664"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1340 --field-trial-handle=1352,i,14859021256935593133,9899944063556103420,131072 /prefetch:2C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2028"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --single-argument C:\Users\admin\Desktop\Windows.7.Loader.eXtreme.Edition.3.503-Napalum\README.htmC:\Program Files\Microsoft\Edge\Application\msedge.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2168"C:\Users\admin\Desktop\Windows.7.Loader.eXtreme.Edition.3.503-Napalum\w7lxe.exe" C:\Users\admin\Desktop\Windows.7.Loader.eXtreme.Edition.3.503-Napalum\w7lxe.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Universal Windows Activation Tool
Exit code:
3221226540
Version:
3.5.0.3
Modules
Images
c:\users\admin\desktop\windows.7.loader.extreme.edition.3.503-napalum\w7lxe.exe
c:\windows\system32\ntdll.dll
2248"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=2220 --field-trial-handle=1352,i,14859021256935593133,9899944063556103420,131072 /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2344"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
Total events
10 006
Read events
9 930
Write events
69
Delete events
7

Modification events

(PID) Process:(3968) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3968) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3968) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3968) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(3968) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(3968) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(3968) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Windows.7.Loader.eXtreme.Edition.3.503-Napalum.rar
(PID) Process:(3968) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3968) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3968) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
Executable files
1
Suspicious files
60
Text files
38
Unknown types
1

Dropped files

PID
Process
Filename
Type
3968WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3968.33634\Windows.7.Loader.eXtreme.Edition.3.503-Napalum\FAQ\FAQ(Danish).txtbinary
MD5:85CC14E10065C26091F045D6689298F7
SHA256:11769DA102AD8E35FFCBB67857C90DE75467B924D38616A25E1A9A43D67B911D
3968WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3968.33634\Windows.7.Loader.eXtreme.Edition.3.503-Napalum\FAQ\FAQ(Hebrew).txtbinary
MD5:A14296DAF1E3B920DF1521638D1E984F
SHA256:B3549C7F74839D492A4DAD0ACD0F3B345D007034257FF60FCC435E070D5F4C3B
3968WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3968.33634\Windows.7.Loader.eXtreme.Edition.3.503-Napalum\FAQ\FAQ(French).txtbinary
MD5:F6DEECDAA3A825253DE705D5E90966FE
SHA256:BD0DDEE82AEA941B339FFCB2FE020F1110B1C20578678E14CCEECBD0CDC57BF4
3968WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3968.33634\Windows.7.Loader.eXtreme.Edition.3.503-Napalum\FAQ\FAQ(Arabic).txtbinary
MD5:6FB0CAFB2697EA0C12C4087B302587FC
SHA256:0296A6631F9822B163B0EF1B0180FF970D34D15D9A1E5B8039DCB58D9CB45640
3968WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3968.33634\Windows.7.Loader.eXtreme.Edition.3.503-Napalum\FAQ\FAQ(Dutch).txtbinary
MD5:4674A9C8D7CFADE0DA8E0F41735CC267
SHA256:FE58E4A8033CEF600DCC6ED88BFBFE27D8FD7646D926EA9A7D191CB5BED627AA
3968WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3968.33634\Windows.7.Loader.eXtreme.Edition.3.503-Napalum\FAQ\FAQ(German).txtbinary
MD5:410E6D4382DA4614BAA25D5ADAB709E4
SHA256:A13C1DBE885ACDDFD4C3E9A1C5362FC731F6FFAEEE037162A80847E44DDBB8F0
3968WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3968.33634\Windows.7.Loader.eXtreme.Edition.3.503-Napalum\FAQ\FAQ(Polish).txtbinary
MD5:1323C84051F6DDBECA52EAFF11D25EE7
SHA256:8B95C586517BE6E379C5D69F6DD8DAD99B327BE4891030CF2967898675F2CD59
3968WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3968.33634\Windows.7.Loader.eXtreme.Edition.3.503-Napalum\FAQ\FAQ(Malay).txtbinary
MD5:CDDC748327216A064B9D394BA5FFFF5E
SHA256:688584BA2A51CBC652D719BB0F6D43C36D797912DA008792D225673BBE5BED3B
3968WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3968.33634\Windows.7.Loader.eXtreme.Edition.3.503-Napalum\Info\README...htmhtml
MD5:F418C43D885DC02AD88EE55FE9769BC0
SHA256:AF897B1AF828F8FBF1E63BAED435DF2B9FE8C261DA775918FA6277FDC1C39D08
3968WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3968.33634\Windows.7.Loader.eXtreme.Edition.3.503-Napalum\FAQ\FAQ(Slovak).txtbinary
MD5:2275760664029DCBB3FA116A4124811C
SHA256:28DB9D7C933E114E73DEF4E5DA931A772AD94FF543A58B906B05192EA4073955
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
23
DNS requests
46
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1660
msedge.exe
GET
46.105.201.240:80
http://s11.histats.com/js9.js
unknown
unknown
1660
msedge.exe
GET
200
142.250.184.234:80
http://ajax.googleapis.com/ajax/libs/jquery/1.3.2/jquery.min.js
unknown
unknown
1660
msedge.exe
GET
302
116.202.102.103:80
http://bin-layer.de/layer-191486-1.js
unknown
unknown
1660
msedge.exe
GET
302
116.202.102.103:80
http://bin-layer.de/popup-191486-1-subid:Bumbles%20.js
unknown
unknown
1660
msedge.exe
GET
200
116.202.102.103:80
http://bin-layer.de/de/
unknown
unknown
1660
msedge.exe
GET
403
204.11.56.48:80
http://services.picadmedia.com/js/picad.js
unknown
unknown
1660
msedge.exe
GET
200
116.202.102.103:80
http://bin-layer.de/de/
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
224.0.0.252:5355
unknown
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1088
svchost.exe
224.0.0.252:5355
unknown
2028
msedge.exe
239.255.255.250:1900
unknown
1660
msedge.exe
13.107.42.16:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
1660
msedge.exe
204.79.197.239:443
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
1660
msedge.exe
49.13.77.253:80
www.bumbles.com.ar
Hetzner Online GmbH
DE
unknown
1660
msedge.exe
172.66.42.247:443
resources.infolinks.com
CLOUDFLARENET
US
unknown
1660
msedge.exe
142.250.184.234:80
ajax.googleapis.com
GOOGLE
US
whitelisted

DNS requests

Domain
IP
Reputation
config.edge.skype.com
  • 13.107.42.16
unknown
edge.microsoft.com
  • 204.79.197.239
  • 13.107.21.239
unknown
www.bumbles.com.ar
  • 49.13.77.253
unknown
i25.tinypic.com
unknown
s11.histats.com
  • 46.105.201.240
unknown
xslt.alexa.com
  • 49.13.77.253
unknown
www.freestats.org
  • 49.13.77.253
unknown
ajax.googleapis.com
  • 142.250.184.234
unknown
services.picadmedia.com
  • 204.11.56.48
unknown
resources.infolinks.com
  • 172.66.41.9
  • 172.66.42.247
unknown

Threats

No threats detected
No debug info