download:

/xmrig/xmrig/releases/download/v6.22.2/xmrig-6.22.2-msvc-win64.zip

Full analysis: https://app.any.run/tasks/f1775f26-7228-4df2-b4f9-b0afc6709a91
Verdict: Malicious activity
Analysis date: November 26, 2024, 14:58:49
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
arch-exec
xmrig
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=store
MD5:

57B7AB5BCE7D5E47FD168E1F0D437D32

SHA1:

050EEAE3E0F0E876F9DA175347B586871D14FE83

SHA256:

1D903D39C7E4E1706C32C44721D6A6C851AA8C4C10DF1479478EE93CD67301BC

SSDEEP:

98304:4X7GS/jQ7r5gofzPgBPyn+Cusep1aNrpymfGGXm8qrqLlbg214CBGHM2E8Q2Lxeh:agBYbuJj

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • XMRig has been detected

      • xmrig.exe (PID: 2380)
    • Generic archive extractor

      • WinRAR.exe (PID: 4144)
  • SUSPICIOUS

    • Connects to unusual port

      • xmrig.exe (PID: 2380)
    • Drops a system driver (possible attempt to evade defenses)

      • WinRAR.exe (PID: 4144)
  • INFO

    • Manual execution by a user

      • xmrig.exe (PID: 2380)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 4144)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2024:11:03 14:41:34
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: xmrig-6.22.2/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
121
Monitored processes
4
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe rundll32.exe no specs #XMRIG xmrig.exe conhost.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2380"C:\Users\admin\Desktop\xmrig-6.22.2\xmrig.exe" C:\Users\admin\Desktop\xmrig-6.22.2\xmrig.exe
explorer.exe
User:
admin
Company:
www.xmrig.com
Integrity Level:
MEDIUM
Description:
XMRig miner
Version:
6.22.2
Modules
Images
c:\users\admin\desktop\xmrig-6.22.2\xmrig.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
3688C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -EmbeddingC:\Windows\System32\rundll32.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shcore.dll
c:\windows\system32\imagehlp.dll
4144"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\Desktop\xmrig-6.22.2-msvc-win64.zipC:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
5536\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exexmrig.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
1 629
Read events
1 621
Write events
8
Delete events
0

Modification events

(PID) Process:(4144) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(4144) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(4144) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(4144) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\xmrig-6.22.2-msvc-win64.zip
(PID) Process:(4144) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(4144) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(4144) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(4144) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
Executable files
2
Suspicious files
1
Text files
7
Unknown types
0

Dropped files

PID
Process
Filename
Type
4144WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa4144.45919\xmrig-6.22.2\SHA256SUMStext
MD5:C7A209DEE0F5D1C6C3DD496BA22F78AB
SHA256:C83B38B121842A02FB910FE260C83CCED6AA90663C2A1626231FF5122850DEE8
4144WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa4144.45919\xmrig-6.22.2\config.jsonbinary
MD5:66F38C96A4901E7B345787C447842B3E
SHA256:2B03943244871CA75E44513E4D20470B8F3E0F209D185395DE82B447022437EC
4144WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa4144.45919\xmrig-6.22.2\pool_mine_example.cmdtext
MD5:2E737F5C3AF9C8AA5216DFDC5BE02CC6
SHA256:E73491065D86B1AD69229BB5D2019E08B947E11A2A57ADF5C2D9A2B5D8F4ACAD
4144WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa4144.45919\xmrig-6.22.2\rtm_ghostrider_example.cmdtext
MD5:3F0155ABE745BE1F6089EAFC4F517AC8
SHA256:810614290BDB14D2DDF10F65F8ADC988A8272764F2A9E2C378E52FAD162DA344
4144WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa4144.45919\xmrig-6.22.2\WinRing0x64.sysexecutable
MD5:0C0195C48B6B8582FA6F6373032118DA
SHA256:11BD2C9F9E2397C9A16E0990E4ED2CF0679498FE0FD418A3DFDAC60B5C160EE5
4144WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa4144.45919\xmrig-6.22.2\xmrig.exeexecutable
MD5:F6D520AE125F03056C4646C508218D16
SHA256:D2FCF28897DDC2137141D838B734664FF7592E03FCD467A433A51CB4976B4FB1
4144WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa4144.45919\xmrig-6.22.2\solo_mine_example.cmdtext
MD5:090703E56F46330ED625AC4363C9D25C
SHA256:33497C69C21FA96BBC96F1D7F09608E462F8AB22555364977C0BD35FEF27BC29
4144WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa4144.45919\xmrig-6.22.2\benchmark_10M.cmdtext
MD5:5BE1C4CACB5AE37C43527E99A097DC7A
SHA256:235A64E3520B1C2C27763122B303F78AEE8D7C083DFD9F1EB936CD5174383609
4144WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa4144.45919\xmrig-6.22.2\benchmark_1M.cmdtext
MD5:CBA1927CF6959DC99ECBD0C553E4DB6F
SHA256:D7747E7A3C782009F4CEB6E9C106115876386853929563B509DA5258E3968D15
4144WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa4144.45919\xmrig-6.22.2\start.cmdtext
MD5:EAF3A00CC0465F8AF471B849ADA29843
SHA256:8E70EF38FE14A2EE2848DF3D6F7E260D1CAF8CFC15DE694D678B8AF151D62333
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
35
DNS requests
5
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
92.123.104.11:443
www.bing.com
Akamai International B.V.
DE
whitelisted
92.123.104.18:443
www.bing.com
Akamai International B.V.
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
4712
MoUsoCoreWorker.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5064
SearchApp.exe
92.123.104.11:443
www.bing.com
Akamai International B.V.
DE
whitelisted
3976
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3700
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2380
xmrig.exe
178.128.242.134:3333
donate.v2.xmrig.com
DIGITALOCEAN-ASN
NL
unknown

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 40.127.240.158
whitelisted
www.bing.com
  • 92.123.104.11
  • 92.123.104.18
  • 92.123.104.14
  • 92.123.104.12
  • 92.123.104.20
  • 92.123.104.15
  • 92.123.104.16
  • 92.123.104.19
  • 92.123.104.17
whitelisted
google.com
  • 142.250.185.206
whitelisted
donate.v2.xmrig.com
  • 199.247.27.41
  • 178.128.242.134
unknown

Threats

No threats detected
No debug info