File name:

winrar-x64-711pl.exe

Full analysis: https://app.any.run/tasks/d7b56f42-f65c-4b40-a386-09571d8cffe2
Verdict: Malicious activity
Analysis date: April 14, 2025, 10:01:48
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32+ executable (GUI) x86-64, for MS Windows, 7 sections
MD5:

73A10F332946AFE1BAC742C821A67D8C

SHA1:

49A41CFB1297ADEB837CA0BAAFFCDD2BFD92664F

SHA256:

2623C403821A0C35F2A610726253F9F19F1C0F5E0E39CEBECC4587D45BA7204D

SSDEEP:

98304:52d240Hr7U0X9vZMqticyWmn9Ld4CKpPe0D/LPHjW1+0UZvzkLmngvcw9FvgK0pO:57VHJWAjhhFrJOegis

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • winrar-x64-711pl.exe (PID: 2284)
      • Uninstall.exe (PID: 7148)
    • Reads Microsoft Outlook installation path

      • winrar-x64-711pl.exe (PID: 2284)
    • Drops 7-zip archiver for unpacking

      • winrar-x64-711pl.exe (PID: 2284)
    • Reads Internet Explorer settings

      • winrar-x64-711pl.exe (PID: 2284)
    • Executable content was dropped or overwritten

      • winrar-x64-711pl.exe (PID: 2284)
    • Reads the date of Windows installation

      • winrar-x64-711pl.exe (PID: 2284)
      • Uninstall.exe (PID: 7148)
    • Creates/Modifies COM task schedule object

      • Uninstall.exe (PID: 7148)
    • Searches for installed software

      • Uninstall.exe (PID: 7148)
    • Creates a software uninstall entry

      • Uninstall.exe (PID: 7148)
  • INFO

    • Checks supported languages

      • winrar-x64-711pl.exe (PID: 2284)
      • Uninstall.exe (PID: 7148)
      • WinRAR.exe (PID: 7052)
    • The sample compiled with polish language support

      • winrar-x64-711pl.exe (PID: 2284)
    • Reads the computer name

      • winrar-x64-711pl.exe (PID: 2284)
      • Uninstall.exe (PID: 7148)
      • WinRAR.exe (PID: 7052)
    • Checks proxy server information

      • winrar-x64-711pl.exe (PID: 2284)
    • Creates files in the program directory

      • winrar-x64-711pl.exe (PID: 2284)
      • Uninstall.exe (PID: 7148)
    • Process checks computer location settings

      • winrar-x64-711pl.exe (PID: 2284)
      • Uninstall.exe (PID: 7148)
    • The sample compiled with english language support

      • winrar-x64-711pl.exe (PID: 2284)
    • Creates files or folders in the user directory

      • Uninstall.exe (PID: 7148)
    • Reads the software policy settings

      • slui.exe (PID: 672)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic Win/DOS Executable (50)
.exe | DOS Executable Generic (49.9)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2025:03:20 10:01:44+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 14.42
CodeSize: 249344
InitializedDataSize: 558080
UninitializedDataSize: -
EntryPoint: 0x24880
OSVersion: 6.1
ImageVersion: -
SubsystemVersion: 6.1
Subsystem: Windows GUI
FileVersionNumber: 7.11.0.0
ProductVersionNumber: 7.11.0.0
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Polish
CharacterSet: Windows, Latin2 (Eastern European)
ProductName: WinRAR
CompanyName: Alexander Roshal
FileDescription: WinRAR
FileVersion: 7.11.0
ProductVersion: 7.11.0
InternalName: WinRAR
LegalCopyright: Copyright © Alexander Roshal 1993-2025
OriginalFileName: WinRAR.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
136
Monitored processes
7
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar-x64-711pl.exe sppextcomobj.exe no specs slui.exe uninstall.exe no specs winrar.exe no specs slui.exe no specs winrar-x64-711pl.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
672"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exe
SppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
1072C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
2284"C:\Users\admin\AppData\Local\Temp\winrar-x64-711pl.exe" C:\Users\admin\AppData\Local\Temp\winrar-x64-711pl.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
HIGH
Description:
WinRAR
Exit code:
0
Version:
7.11.0
Modules
Images
c:\users\admin\appdata\local\temp\winrar-x64-711pl.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
5680C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
7012"C:\Users\admin\AppData\Local\Temp\winrar-x64-711pl.exe" C:\Users\admin\AppData\Local\Temp\winrar-x64-711pl.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR
Exit code:
3221226540
Version:
7.11.0
Modules
Images
c:\users\admin\appdata\local\temp\winrar-x64-711pl.exe
c:\windows\system32\ntdll.dll
7052"C:\Program Files\WinRAR\WinRAR.exe" C:\Program Files\WinRAR\WinRAR.exeUninstall.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
HIGH
Description:
WinRAR
Version:
7.11.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
7148"C:\Program Files\WinRAR\uninstall.exe" /setupC:\Program Files\WinRAR\Uninstall.exewinrar-x64-711pl.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
HIGH
Description:
Dezinstalator WinRARa
Version:
7.11.0
Modules
Images
c:\program files\winrar\uninstall.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
Total events
3 121
Read events
3 029
Write events
88
Delete events
4

Modification events

(PID) Process:(2284) winrar-x64-711pl.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(2284) winrar-x64-711pl.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(2284) winrar-x64-711pl.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(2284) winrar-x64-711pl.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR SFX
Operation:writeName:C%%Program Files%WinRAR
Value:
C:\Program Files\WinRAR
(PID) Process:(2284) winrar-x64-711pl.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\LowRegistry
Operation:delete valueName:AddToFavoritesInitialSelection
Value:
(PID) Process:(2284) winrar-x64-711pl.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\LowRegistry
Operation:delete valueName:AddToFeedsInitialSelection
Value:
(PID) Process:(7148) Uninstall.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Setup\.rar
Operation:writeName:Set
Value:
1
(PID) Process:(7148) Uninstall.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Setup\.zip
Operation:writeName:Set
Value:
1
(PID) Process:(7148) Uninstall.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Setup\.cab
Operation:writeName:Set
Value:
1
(PID) Process:(7148) Uninstall.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Setup\.arj
Operation:writeName:Set
Value:
1
Executable files
13
Suspicious files
12
Text files
11
Unknown types
0

Dropped files

PID
Process
Filename
Type
2284winrar-x64-711pl.exe
MD5:
SHA256:
2284winrar-x64-711pl.exeC:\Program Files\WinRAR\Order.htmhtml
MD5:12B3671FE02B9531AAE9D8CEDC6339D0
SHA256:5D823EDE622C23D5E02FFE282623CC68E8475CA2EA81D31C2261C106B4768033
2284winrar-x64-711pl.exeC:\Program Files\WinRAR\Rar.txttext
MD5:3D7AF510F3CDA8FAAFE79C5977984277
SHA256:BC0E0F5083A76CFE6BEEA65A8CBCAF5C0A09FCDB73CFC6CAE4CE541BF7EC16A3
2284winrar-x64-711pl.exeC:\Program Files\WinRAR\Licencja.txttext
MD5:316225356C408025803DA7FDDD4F6273
SHA256:7DC927665788B4B2497BB8812BD35CBA450CD2FC9D30562151FC2790BE0650C1
2284winrar-x64-711pl.exeC:\Program Files\WinRAR\CzytajTo.txttext
MD5:59AE5C0F732B8D1E2D431C1309973251
SHA256:A92FECF19C61D5442800679700C6BF3E746070C1EEF79EA660FD95D117C9DA6D
2284winrar-x64-711pl.exeC:\Program Files\WinRAR\CoNowego.txttext
MD5:FBAAAC1FBCC1ABC94024C8044B4FA814
SHA256:99E492D543F8D47723E89880E4BDD515155F3A068AA4225D4B762CC5CC9FD4FE
2284winrar-x64-711pl.exeC:\Program Files\WinRAR\Descript.iontext
MD5:0629F396F9EFC40119AD688BF1E03B5D
SHA256:BCD339562BC47D34B287C3E69601A6B637BDB7537EEFE6B5EBB84A613550B9B0
2284winrar-x64-711pl.exeC:\Program Files\WinRAR\RarExtInstaller.exeexecutable
MD5:B0B34B1FEDDE50F2D9C3D8A428665D97
SHA256:A6383BEE493AE87CE7BEC44FBC93A028A7C1F011AA77045EA8E35E89A92658B7
2284winrar-x64-711pl.exeC:\Program Files\WinRAR\RarExt32.dllexecutable
MD5:D3A4BEE9D55BAB38FA2F2BD33CCFA02F
SHA256:28409C56E7EC3B8996ACC12D2A0C7EC5D38C2C077AB4FB28C5C28F545C0FC6D3
2284winrar-x64-711pl.exeC:\Program Files\WinRAR\Uninstall.lsttext
MD5:9A517187C2AB5F4D5F4BD363116ED764
SHA256:235A5243D3B97B0F35DC088DFE389E2621921154117438C4DAEC1C4102F8CFDF
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
19
DNS requests
14
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
23.53.40.178:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5588
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
5588
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
6544
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
23.53.40.178:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5496
MoUsoCoreWorker.exe
23.53.40.178:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
23.53.40.178:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
3216
svchost.exe
172.211.123.248:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
6544
svchost.exe
40.126.32.138:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6544
svchost.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
2104
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5588
SIHClient.exe
4.175.87.197:443
slscr.update.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.186.110
whitelisted
settings-win.data.microsoft.com
  • 20.73.194.208
  • 40.127.240.158
whitelisted
crl.microsoft.com
  • 23.53.40.178
  • 23.53.40.176
whitelisted
client.wns.windows.com
  • 172.211.123.248
whitelisted
login.live.com
  • 40.126.32.138
  • 20.190.160.130
  • 20.190.160.66
  • 20.190.160.67
  • 40.126.32.76
  • 20.190.160.20
  • 20.190.160.128
  • 40.126.32.74
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
slscr.update.microsoft.com
  • 4.175.87.197
whitelisted
www.microsoft.com
  • 95.101.149.131
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 20.242.39.171
whitelisted
activation-v2.sls.microsoft.com
  • 20.83.72.98
whitelisted

Threats

No threats detected
No debug info