File name:

Win32.Bootkit.Lkf.rar

Full analysis: https://app.any.run/tasks/2d4b5831-1abe-4d43-a43c-f335002c68f7
Verdict: Malicious activity
Analysis date: January 14, 2022, 22:13:24
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

D33B2978F7F889DBF082CA25A35C1397

SHA1:

E928A8A00AA7928C89D1344DE9E7A3ED101B012F

SHA256:

1F86982E8A7B4A58D5FD57278BC198D6B39E04CA95282BFFABA11C24EB89CBDA

SSDEEP:

12288:Ej8udgCq9BEL+11eFTlBI1kzk42XEWzqQV+N6iLshO6aXS8OX:nuWCq9Bn1OI1k16VzqQYMhO6aXHa

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • nc.exe (PID: 3120)
      • WinFlash.exe (PID: 2752)
  • SUSPICIOUS

    • Checks supported languages

      • WinRAR.exe (PID: 2164)
      • nc.exe (PID: 3120)
      • WinFlash.exe (PID: 2752)
    • Reads the computer name

      • WinRAR.exe (PID: 2164)
      • WinFlash.exe (PID: 2752)
    • Drops a file with a compile date too recent

      • WinRAR.exe (PID: 2164)
    • Drops a file that was compiled in debug mode

      • WinRAR.exe (PID: 2164)
    • Drops a file with too old compile date

      • WinRAR.exe (PID: 2164)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2164)
    • Reads default file associations for system extensions

      • WinFlash.exe (PID: 2752)
      • WinRAR.exe (PID: 2164)
    • Executes application which crashes

      • WinRAR.exe (PID: 2164)
  • INFO

    • Checks supported languages

      • ntvdm.exe (PID: 2332)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
39
Monitored processes
4
Malicious processes
1
Suspicious processes
1

Behavior graph

Click at the process to see the details
drop and start drop and start start winrar.exe nc.exe no specs ntvdm.exe no specs winflash.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2164"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Win32.Bootkit.Lkf.rar"C:\Program Files\WinRAR\WinRAR.exe
Explorer.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2332"C:\Windows\system32\ntvdm.exe" -i1 C:\Windows\system32\ntvdm.exeWinRAR.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
NTVDM.EXE
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ntvdm.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2752"C:\Users\admin\AppData\Local\Temp\Rar$EXa2164.8034\LkfBiosRootkit\????\WinFlash\WinFlash.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa2164.8034\LkfBiosRootkit\????\WinFlash\WinFlash.exeWinRAR.exe
User:
admin
Company:
Phoenix Technologies Ltd.
Integrity Level:
MEDIUM
Description:
WinFlash MFC ????
Exit code:
0
Version:
1.74
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2164.8034\lkfbiosrootkit\????\winflash\winflash.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3120"C:\Users\admin\AppData\Local\Temp\Rar$EXa2164.7153\LkfBiosRootkit\????\nc.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa2164.7153\LkfBiosRootkit\????\nc.exeWinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221225786
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2164.7153\lkfbiosrootkit\????\nc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\nsi.dll
c:\windows\system32\rpcrt4.dll
Total events
2 612
Read events
2 559
Write events
52
Delete events
1

Modification events

(PID) Process:(2164) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2164) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2164) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2164) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(2164) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(2164) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Win32.Bootkit.Lkf.rar
(PID) Process:(2164) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2164) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2164) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2164) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
Executable files
21
Suspicious files
0
Text files
23
Unknown types
0

Dropped files

PID
Process
Filename
Type
2164WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2164.7153\LkfBiosRootkit\Source\test.ASMtext
MD5:
SHA256:
2164WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2164.7153\LkfBiosRootkit\Source\??.battext
MD5:
SHA256:
2164WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2164.7153\LkfBiosRootkit\Source\romtools.exeexecutable
MD5:
SHA256:
2164WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2164.7153\LkfBiosRootkit\Source\ML.ERRtext
MD5:6383413E54EB693E5BD1488422F925B9
SHA256:092755D3A488767DA3DE277C141BE7C8144110A156CDBD8AE1391EBA64697CEE
2164WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2164.7153\LkfBiosRootkit\Source\cmd.battext
MD5:45E0EDACA8702E6E90D1D98CF3647D5F
SHA256:
2164WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2164.7153\LkfBiosRootkit\Source\ML.EXEexecutable
MD5:0A05C3EAE7888A2F01330862EEEA7EFD
SHA256:94595B9CCC09DBCAF6B877AA11A35576F78DE2AB0EB39546ABFDE430B79DCE2F
2164WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2164.7153\LkfBiosRootkit\????\??.txttext
MD5:
SHA256:
2164WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2164.7153\LkfBiosRootkit\Source\link.exeexecutable
MD5:706E1856D28B963911306168C4744844
SHA256:2B5236E3F6198A5C4CEBEC02178786CDCEA423F9B6B9823D538A1838E65F045C
2164WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2164.7153\LkfBiosRootkit\????\nc.exeexecutable
MD5:
SHA256:
2164WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2164.7153\LkfBiosRootkit\????\WinFlash\WinFlash.sysexecutable
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info