analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

QUM, IL VATICANO DELL'ISLAM.rar

Full analysis: https://app.any.run/tasks/cc5e9a52-1a4b-4f37-ab32-18b9d50ba3fb
Verdict: Malicious activity
Threats:

Trojans are a group of malicious programs distinguished by their ability to masquerade as benign software. Depending on their type, trojans possess a variety of capabilities, ranging from maintaining full remote control over the victim’s machine to stealing data and files, as well as dropping other malware. At the same time, the main functionality of each trojan family can differ significantly depending on its type. The most common trojan infection chain starts with a phishing email.

Analysis date: July 12, 2020, 08:01:36
OS: Windows 7 Professional Service Pack 1 (build: 7601, 64 bit)
Tags:
trojan
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

2E69B5ED15156E5680334FA88BE5D1BD

SHA1:

C435C75877B39406DBE06E357EF304710D567DA9

SHA256:

282EEF984C20CC334F926725CC36AB610B00D05B5990C7F55C324791AB156D92

SSDEEP:

3072:yRnizlIWzdBu9+0ZZHmdGHQgracn2mc9DXDmUpEmq8MENdRrF:yRclIkjX0ZZHmd/Ujnzc9DXCxM3F

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads the machine GUID from the registry

      • WinRAR.exe (PID: 1464)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
43
Monitored processes
1
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1464"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\QUM, IL VATICANO DELL'ISLAM.rar"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Total events
336
Read events
327
Write events
0
Delete events
0

Modification events

No data
Executable files
0
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
1464WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1464.27740\QUM, IL VATICANO DELL'ISLAM\QUM, IL VATICANO DELL'ISLAM.docx
MD5:
SHA256:
1464WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1464.27740\QUM, IL VATICANO DELL'ISLAM\QUM, IL VATICANO DELL'ISLAM.exe
MD5:
SHA256:
1464WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1464.27740\QUM, IL VATICANO DELL'ISLAM\wwlib.dll
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
7
DNS requests
2
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
103.85.24.190:80
http://103.85.24.190/qum.dat
CN
binary
348 Kb
malicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
103.85.24.190:80
Starry Network Limited
CN
malicious
167.88.180.32:995
www.systeminfor.com
CA
malicious
167.88.180.32:110
www.systeminfor.com
CA
malicious
167.88.180.32:80
www.systeminfor.com
CA
malicious

DNS requests

Domain
IP
Reputation
www.systeminfor.com
  • 167.88.180.32
malicious

Threats

PID
Process
Class
Message
A Network Trojan was detected
ET USER_AGENTS Suspicious User Agent (Microsoft Internet Explorer)
A Network Trojan was detected
ET TROJAN Request for Malicious .dat File
No debug info