File name:

Router Scan v2.60.rar

Full analysis: https://app.any.run/tasks/9feacd88-9e16-46fa-bde3-48dd09dcde9b
Verdict: Malicious activity
Analysis date: January 23, 2025, 00:48:13
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
delphi
arch-scr
arch-doc
arch-html
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

CC86C06D0EC3A7E61942834F878683BF

SHA1:

76ADDA2379259839493E37C5C7E837B5E2588C52

SHA256:

2A1F8A5A1C549095B78D004C3446D4AFB7ED1744A71C64B98FF9C20B73C0B99D

SSDEEP:

98304:0eWjzLRUOORbZpBu59qx5phOZt95nIHJTQu9LVwotatwJ+uOYrrLGVfgXR4DEp+J:AXDbHZt

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • WinRAR.exe (PID: 6564)
    • Reads security settings of Internet Explorer

      • WinRAR.exe (PID: 6564)
    • Connects to unusual port

      • RouterScan.exe (PID: 6528)
  • INFO

    • The sample compiled with english language support

      • WinRAR.exe (PID: 6564)
    • Checks supported languages

      • RouterScan.exe (PID: 6528)
    • Create files in a temporary directory

      • RouterScan.exe (PID: 6528)
    • Reads the computer name

      • RouterScan.exe (PID: 6528)
    • The process uses the downloaded file

      • WinRAR.exe (PID: 6564)
    • Compiled with Borland Delphi (YARA)

      • RouterScan.exe (PID: 6528)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 6564)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)

EXIF

ZIP

FileVersion: RAR v5
CompressedSize: 1380
UncompressedSize: 3229
OperatingSystem: Win32
ArchivedFileName: Router Scan v2.60/auth_basic.txt
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
129
Monitored processes
2
Malicious processes
1
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe routerscan.exe

Process information

PID
CMD
Path
Indicators
Parent process
6528"C:\Users\admin\AppData\Local\Temp\Rar$EXa6564.11857\Router Scan v2.60\RouterScan.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa6564.11857\Router Scan v2.60\RouterScan.exe
WinRAR.exe
User:
admin
Company:
Stas'M Corp.
Integrity Level:
MEDIUM
Description:
Router Scan by Stas'M
Version:
2.6.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa6564.11857\router scan v2.60\routerscan.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\oleaut32.dll
6564"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Router Scan v2.60.rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
Total events
2 356
Read events
2 348
Write events
8
Delete events
0

Modification events

(PID) Process:(6564) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(6564) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(6564) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(6564) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Router Scan v2.60.rar
(PID) Process:(6564) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(6564) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(6564) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(6564) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
Executable files
9
Suspicious files
0
Text files
105
Unknown types
0

Dropped files

PID
Process
Filename
Type
6564WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa6564.11857\Router Scan v2.60\help\data\code.jstext
MD5:0E184C0A27519CD3B4EA684FA5F7B12D
SHA256:0D2596B4DBF933CB26CAC77694E36E65A40B9938815A1561F11DCE5056D0DBBB
6564WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa6564.11857\Router Scan v2.60\help\data\manual\menu_table.pngimage
MD5:8764457F339A125AC67BB57D98961D4A
SHA256:79CBBB622DC431B03D00089BF5D74B290F7A97F8DF3BE504A42CF7C81FC0DC94
6564WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa6564.11857\Router Scan v2.60\help\data\manual\menu_main.pngimage
MD5:6EA94AA073E42F7E79885831DA173462
SHA256:25FE2D89C8D99B9D8B6D3FFA9CA095A49283CA4A9E23FA9FAC34C755CAA66819
6564WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa6564.11857\Router Scan v2.60\help\data\manual\window_exclusions.pngimage
MD5:445458767080CAFFE78E3485FBE073D0
SHA256:017130EE877058E66FE5488E624B46A96516DF248F8A34CE3BB5B437EC2C2F7D
6564WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa6564.11857\Router Scan v2.60\auth_digest.txttext
MD5:700FDF0988080895EDA17D4731C116C3
SHA256:A89BA33D3213E234E58805DDAD92B2F32B5DDEA51175A8F7EE15AA0BCB68006E
6564WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa6564.11857\Router Scan v2.60\help\data\code.csstext
MD5:EB21D6145A7B341CA198228B2C9930A8
SHA256:FAB0FD6EEDFD3F618BC3C9522F259F51BF1FF09181A1D482FB965829F2387018
6564WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa6564.11857\Router Scan v2.60\help\data\manual\window_import_append.pngimage
MD5:3A5E23B0E700630BC9AAD468666F1F51
SHA256:35ACE82FAEF5C2EDCCF1F99F2DDBEBA98E678A36F3E40D21B9274C85204CA899
6564WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa6564.11857\Router Scan v2.60\help\data\manual\window_editrange.pngimage
MD5:DD062442962F063760A0DB3BC8563E6C
SHA256:7EC5DC7B4B21627C9523EE8D448CA8D062B6E48ED3AEB30217DFAA6D507C9A96
6564WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa6564.11857\Router Scan v2.60\config.initext
MD5:E637D6187A62F0399632CD9443A2C6DE
SHA256:2007EA5042C4E41DC9D598EC26910D44B4C436446159F4931A488B5BEB5934FC
6564WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa6564.11857\Router Scan v2.60\help\data\manual\window_filter.pngimage
MD5:82109105D2F4764A79A702497FD421B8
SHA256:B6EDAC032E00C84CA8B6B0F1BF8CA88FF220F35BAF44670B81448295A4B8AE8B
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
62
DNS requests
16
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4712
MoUsoCoreWorker.exe
GET
200
2.16.168.114:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
4712
MoUsoCoreWorker.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
5788
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
6464
backgroundTaskHost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
5788
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
1176
svchost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4712
MoUsoCoreWorker.exe
2.16.168.114:80
crl.microsoft.com
Akamai International B.V.
RU
whitelisted
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
4712
MoUsoCoreWorker.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
2.23.227.208:443
www.bing.com
Ooredoo Q.S.C.
QA
whitelisted
184.30.131.245:80
ocsp.digicert.com
AKAMAI-AS
US
whitelisted
4.231.128.59:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1076
svchost.exe
184.30.18.9:443
go.microsoft.com
AKAMAI-AS
DE
whitelisted
5000
RUXIMICS.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1176
svchost.exe
20.190.159.4:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
crl.microsoft.com
  • 2.16.168.114
  • 2.16.168.124
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
www.bing.com
  • 2.23.227.208
  • 2.23.227.215
whitelisted
ocsp.digicert.com
  • 184.30.131.245
whitelisted
go.microsoft.com
  • 184.30.18.9
whitelisted
settings-win.data.microsoft.com
  • 51.124.78.146
  • 51.104.136.2
whitelisted
login.live.com
  • 20.190.159.4
  • 20.190.159.2
  • 40.126.31.67
  • 20.190.159.0
  • 20.190.159.75
  • 20.190.159.23
  • 40.126.31.69
  • 20.190.159.64
whitelisted
arc.msn.com
  • 20.223.35.26
whitelisted
fd.api.iris.microsoft.com
  • 20.31.169.57
whitelisted
slscr.update.microsoft.com
  • 4.245.163.56
whitelisted

Threats

No threats detected
No debug info