File name:

WinRAR7.11-Final-x64烈火汉化版_2.exe

Full analysis: https://app.any.run/tasks/e07f9c13-0e38-4a37-b8f8-5330a591a497
Verdict: Malicious activity
Analysis date: April 13, 2025, 14:24:34
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32+ executable (GUI) x86-64, for MS Windows, 7 sections
MD5:

F5F45C0626ADBBD3D5E3F125B8C40170

SHA1:

9D673DAF2C778E4CE01B7204A94F71B32FE66080

SHA256:

2A3231967803697DB9029EC67A6BABFF7059030390E4884D36A9F96FEE7D2A8B

SSDEEP:

98304:6krIspnFyG9I952GrVPXVN4MEd+dj64ln8GMAXviR3i4SSQ+54yxKKBabL2aqaHw:6T1pZjW+mP

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • WinRAR7.11-Final-x64烈火汉化版_2.exe (PID: 6964)
    • Reads Microsoft Outlook installation path

      • WinRAR7.11-Final-x64烈火汉化版_2.exe (PID: 6964)
    • Reads Internet Explorer settings

      • WinRAR7.11-Final-x64烈火汉化版_2.exe (PID: 6964)
    • There is functionality for taking screenshot (YARA)

      • WinRAR7.11-Final-x64烈火汉化版_2.exe (PID: 6964)
    • Executable content was dropped or overwritten

      • WinRAR7.11-Final-x64烈火汉化版_2.exe (PID: 6964)
    • Searches for installed software

      • Uninstall.exe (PID: 4188)
    • Reads the date of Windows installation

      • WinRAR7.11-Final-x64烈火汉化版_2.exe (PID: 6964)
    • Drops 7-zip archiver for unpacking

      • WinRAR7.11-Final-x64烈火汉化版_2.exe (PID: 6964)
    • Creates/Modifies COM task schedule object

      • Uninstall.exe (PID: 4188)
    • Creates a software uninstall entry

      • Uninstall.exe (PID: 4188)
  • INFO

    • The sample compiled with english language support

      • WinRAR7.11-Final-x64烈火汉化版_2.exe (PID: 6964)
    • Checks supported languages

      • WinRAR7.11-Final-x64烈火汉化版_2.exe (PID: 6964)
      • Uninstall.exe (PID: 6388)
      • Uninstall.exe (PID: 4188)
    • Reads the computer name

      • WinRAR7.11-Final-x64烈火汉化版_2.exe (PID: 6964)
      • Uninstall.exe (PID: 4188)
    • Checks proxy server information

      • WinRAR7.11-Final-x64烈火汉化版_2.exe (PID: 6964)
    • Process checks computer location settings

      • WinRAR7.11-Final-x64烈火汉化版_2.exe (PID: 6964)
    • Creates files in the program directory

      • WinRAR7.11-Final-x64烈火汉化版_2.exe (PID: 6964)
      • Uninstall.exe (PID: 4188)
    • Creates files or folders in the user directory

      • Uninstall.exe (PID: 4188)
    • The sample compiled with chinese language support

      • WinRAR7.11-Final-x64烈火汉化版_2.exe (PID: 6964)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (87.3)
.exe | Generic Win/DOS Executable (6.3)
.exe | DOS Executable Generic (6.3)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2024:11:06 10:03:59+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 14.41
CodeSize: 248320
InitializedDataSize: 231424
UninitializedDataSize: -
EntryPoint: 0x24510
OSVersion: 6.1
ImageVersion: -
SubsystemVersion: 6.1
Subsystem: Windows GUI
FileVersionNumber: 7.11.2.0
ProductVersionNumber: 7.11.2.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
ProductName: WinRAR 压缩管理软件
CompanyName: 全球发行商 win.rar GmbH
FileDescription: WinRAR 压缩文件管理器
FileVersion: 7.11.2
ProductVersion: 7.11.2
InternalName: WinRAR 压缩管理软件
LegalCopyright: 版权所有 © Alexander Roshal 1993-2025
OriginalFileName: WinRAR.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
133
Monitored processes
6
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar7.11-final-x64烈火汉化版_2.exe sppextcomobj.exe no specs slui.exe no specs uninstall.exe no specs uninstall.exe no specs winrar7.11-final-x64烈火汉化版_2.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
904"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exeSppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
4188"C:\Program Files\WinRAR\uninstall.exe" /setupC:\Program Files\WinRAR\Uninstall.exeWinRAR7.11-Final-x64烈火汉化版_2.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
HIGH
Description:
卸载 WinRAR
Exit code:
0
Version:
7.11.2
Modules
Images
c:\program files\winrar\uninstall.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
4300"C:\Users\admin\AppData\Local\Temp\WinRAR7.11-Final-x64烈火汉化版_2.exe" C:\Users\admin\AppData\Local\Temp\WinRAR7.11-Final-x64烈火汉化版_2.exeexplorer.exe
User:
admin
Company:
全球发行商 win.rar GmbH
Integrity Level:
MEDIUM
Description:
WinRAR 压缩文件管理器
Exit code:
3221226540
Version:
7.11.2
Modules
Images
c:\users\admin\appdata\local\temp\winrar7.11-final-x64烈火汉化版_2.exe
c:\windows\system32\ntdll.dll
6388"C:\Program Files\WinRAR\uninstall.exe" /cleanC:\Program Files\WinRAR\Uninstall.exeWinRAR7.11-Final-x64烈火汉化版_2.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
HIGH
Description:
Uninstall WinRAR
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\uninstall.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
6964"C:\Users\admin\AppData\Local\Temp\WinRAR7.11-Final-x64烈火汉化版_2.exe" C:\Users\admin\AppData\Local\Temp\WinRAR7.11-Final-x64烈火汉化版_2.exe
explorer.exe
User:
admin
Company:
全球发行商 win.rar GmbH
Integrity Level:
HIGH
Description:
WinRAR 压缩文件管理器
Exit code:
0
Version:
7.11.2
Modules
Images
c:\users\admin\appdata\local\temp\winrar7.11-final-x64烈火汉化版_2.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
7144C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
Total events
1 299
Read events
1 207
Write events
88
Delete events
4

Modification events

(PID) Process:(6964) WinRAR7.11-Final-x64烈火汉化版_2.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(6964) WinRAR7.11-Final-x64烈火汉化版_2.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(6964) WinRAR7.11-Final-x64烈火汉化版_2.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(6964) WinRAR7.11-Final-x64烈火汉化版_2.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR SFX
Operation:writeName:C%%Program Files%WinRAR
Value:
C:\Program Files\WinRAR
(PID) Process:(6964) WinRAR7.11-Final-x64烈火汉化版_2.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\LowRegistry
Operation:delete valueName:AddToFavoritesInitialSelection
Value:
(PID) Process:(6964) WinRAR7.11-Final-x64烈火汉化版_2.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\LowRegistry
Operation:delete valueName:AddToFeedsInitialSelection
Value:
(PID) Process:(4188) Uninstall.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.rar\ShellNew
Operation:writeName:FileName
Value:
C:\Program Files\WinRAR\rarnew.dat
(PID) Process:(4188) Uninstall.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zip\ShellNew
Operation:delete keyName:(default)
Value:
(PID) Process:(4188) Uninstall.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zip\ShellNew
Operation:writeName:FileName
Value:
C:\Program Files\WinRAR\zipnew.dat
(PID) Process:(4188) Uninstall.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Setup\.jar
Operation:writeName:Exist
Value:
1
Executable files
13
Suspicious files
14
Text files
12
Unknown types
0

Dropped files

PID
Process
Filename
Type
6964WinRAR7.11-Final-x64烈火汉化版_2.exe
MD5:
SHA256:
6964WinRAR7.11-Final-x64烈火汉化版_2.exeC:\Program Files\WinRAR\ReadMe.txttext
MD5:69915CA1C473DC56A4BCE4F25AEBD09C
SHA256:B32BA6FA2364D5D7216A9D7C92D5F5D934AF6909287F0D551811A1A1902FDC1D
6964WinRAR7.11-Final-x64烈火汉化版_2.exeC:\Program Files\WinRAR\License.txttext
MD5:4B0AA788DD86551290BC6E9A88509BBD
SHA256:8EF25883C24371C0F617AA1A217B9237D91522C1C3BFED110A2B191A7402D706
6964WinRAR7.11-Final-x64烈火汉化版_2.exeC:\Program Files\WinRAR\Descript.iontext
MD5:D4F4BA061E5B947B7BEDC0B2F7077450
SHA256:EF04F311AD98253E6D6162F47B6DA4CB16538FBC1BBF0E643CC181AF6039AD30
6964WinRAR7.11-Final-x64烈火汉化版_2.exeC:\Program Files\WinRAR\RarExtInstaller.exeexecutable
MD5:13F58E3D2C8E28A1A57C8DD1D107CAEC
SHA256:67087D0EF15C29E1A23A9C8B3332BCFD630F1B58EF65EABD1C8F357CAF83D9BB
6964WinRAR7.11-Final-x64烈火汉化版_2.exeC:\Program Files\WinRAR\7zxa.dllexecutable
MD5:46175FED2691F8B5D363350E4A703AE0
SHA256:1656FC44D7D28ECEE5013D4FE74D376A945BC03FA788CF9E2D17A0A53DAF708D
6964WinRAR7.11-Final-x64烈火汉化版_2.exeC:\Program Files\WinRAR\UnRAR.exeexecutable
MD5:E522660A105607B5B081A8D7F22E4162
SHA256:E6CCFC9F2DDF2490FDC33177BB2038F890201426168959E42B916FE3894E9C56
6964WinRAR7.11-Final-x64烈火汉化版_2.exeC:\Program Files\WinRAR\RarExt.dllexecutable
MD5:9F34BFAEB95BBBCEE5E5C4BE963CD7BB
SHA256:EF108B0320E0230368CCDA403F7ED5D7E9F4A89307FF65F320C672E69D6FC0FD
6964WinRAR7.11-Final-x64烈火汉化版_2.exeC:\Program Files\WinRAR\Order.htmhtml
MD5:CE28C19DDF7D42C76DD9763CDBC7EACE
SHA256:C30A7874872BFEF2ED29C6F83C4D8E33C4A2A79B8B5E850C6CB6481E4F90114C
6964WinRAR7.11-Final-x64烈火汉化版_2.exeC:\Program Files\WinRAR\Uninstall.exeexecutable
MD5:63425E4BC8F08F76084EE8F283790DCC
SHA256:70EEC4A4834D5C21843BCF0F8ED42E75D01FE56D4C38373247CCF6A99C44C8D6
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
18
DNS requests
13
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
23.48.23.156:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
7148
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
7148
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
6544
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
2104
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
23.48.23.156:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
2112
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3216
svchost.exe
172.211.123.250:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
6544
svchost.exe
20.190.160.130:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6544
svchost.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
2104
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
  • 51.104.136.2
whitelisted
crl.microsoft.com
  • 23.48.23.156
  • 23.48.23.143
whitelisted
google.com
  • 142.250.186.174
whitelisted
client.wns.windows.com
  • 172.211.123.250
whitelisted
login.live.com
  • 20.190.160.130
  • 20.190.160.64
  • 20.190.160.66
  • 20.190.160.22
  • 20.190.160.2
  • 20.190.160.5
  • 20.190.160.65
  • 40.126.32.134
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
slscr.update.microsoft.com
  • 20.12.23.50
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 40.69.42.241
whitelisted

Threats

No threats detected
No debug info