File name:

WinRAR7.11-Final-x64烈火汉化版_2.exe

Full analysis: https://app.any.run/tasks/e07f9c13-0e38-4a37-b8f8-5330a591a497
Verdict: Malicious activity
Analysis date: April 13, 2025, 14:24:34
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32+ executable (GUI) x86-64, for MS Windows, 7 sections
MD5:

F5F45C0626ADBBD3D5E3F125B8C40170

SHA1:

9D673DAF2C778E4CE01B7204A94F71B32FE66080

SHA256:

2A3231967803697DB9029EC67A6BABFF7059030390E4884D36A9F96FEE7D2A8B

SSDEEP:

98304:6krIspnFyG9I952GrVPXVN4MEd+dj64ln8GMAXviR3i4SSQ+54yxKKBabL2aqaHw:6T1pZjW+mP

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads Microsoft Outlook installation path

      • WinRAR7.11-Final-x64烈火汉化版_2.exe (PID: 6964)
    • Reads the date of Windows installation

      • WinRAR7.11-Final-x64烈火汉化版_2.exe (PID: 6964)
    • There is functionality for taking screenshot (YARA)

      • WinRAR7.11-Final-x64烈火汉化版_2.exe (PID: 6964)
    • Reads security settings of Internet Explorer

      • WinRAR7.11-Final-x64烈火汉化版_2.exe (PID: 6964)
    • Executable content was dropped or overwritten

      • WinRAR7.11-Final-x64烈火汉化版_2.exe (PID: 6964)
    • Reads Internet Explorer settings

      • WinRAR7.11-Final-x64烈火汉化版_2.exe (PID: 6964)
    • Drops 7-zip archiver for unpacking

      • WinRAR7.11-Final-x64烈火汉化版_2.exe (PID: 6964)
    • Creates/Modifies COM task schedule object

      • Uninstall.exe (PID: 4188)
    • Creates a software uninstall entry

      • Uninstall.exe (PID: 4188)
    • Searches for installed software

      • Uninstall.exe (PID: 4188)
  • INFO

    • The sample compiled with english language support

      • WinRAR7.11-Final-x64烈火汉化版_2.exe (PID: 6964)
    • Reads the computer name

      • WinRAR7.11-Final-x64烈火汉化版_2.exe (PID: 6964)
      • Uninstall.exe (PID: 4188)
    • Checks proxy server information

      • WinRAR7.11-Final-x64烈火汉化版_2.exe (PID: 6964)
    • Checks supported languages

      • WinRAR7.11-Final-x64烈火汉化版_2.exe (PID: 6964)
      • Uninstall.exe (PID: 6388)
      • Uninstall.exe (PID: 4188)
    • Process checks computer location settings

      • WinRAR7.11-Final-x64烈火汉化版_2.exe (PID: 6964)
    • Creates files in the program directory

      • WinRAR7.11-Final-x64烈火汉化版_2.exe (PID: 6964)
      • Uninstall.exe (PID: 4188)
    • The sample compiled with chinese language support

      • WinRAR7.11-Final-x64烈火汉化版_2.exe (PID: 6964)
    • Creates files or folders in the user directory

      • Uninstall.exe (PID: 4188)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (87.3)
.exe | Generic Win/DOS Executable (6.3)
.exe | DOS Executable Generic (6.3)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2024:11:06 10:03:59+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 14.41
CodeSize: 248320
InitializedDataSize: 231424
UninitializedDataSize: -
EntryPoint: 0x24510
OSVersion: 6.1
ImageVersion: -
SubsystemVersion: 6.1
Subsystem: Windows GUI
FileVersionNumber: 7.11.2.0
ProductVersionNumber: 7.11.2.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
ProductName: WinRAR 压缩管理软件
CompanyName: 全球发行商 win.rar GmbH
FileDescription: WinRAR 压缩文件管理器
FileVersion: 7.11.2
ProductVersion: 7.11.2
InternalName: WinRAR 压缩管理软件
LegalCopyright: 版权所有 © Alexander Roshal 1993-2025
OriginalFileName: WinRAR.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
133
Monitored processes
6
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar7.11-final-x64烈火汉化版_2.exe sppextcomobj.exe no specs slui.exe no specs uninstall.exe no specs uninstall.exe no specs winrar7.11-final-x64烈火汉化版_2.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
904"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exeSppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
4188"C:\Program Files\WinRAR\uninstall.exe" /setupC:\Program Files\WinRAR\Uninstall.exeWinRAR7.11-Final-x64烈火汉化版_2.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
HIGH
Description:
卸载 WinRAR
Exit code:
0
Version:
7.11.2
Modules
Images
c:\program files\winrar\uninstall.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
4300"C:\Users\admin\AppData\Local\Temp\WinRAR7.11-Final-x64烈火汉化版_2.exe" C:\Users\admin\AppData\Local\Temp\WinRAR7.11-Final-x64烈火汉化版_2.exeexplorer.exe
User:
admin
Company:
全球发行商 win.rar GmbH
Integrity Level:
MEDIUM
Description:
WinRAR 压缩文件管理器
Exit code:
3221226540
Version:
7.11.2
Modules
Images
c:\users\admin\appdata\local\temp\winrar7.11-final-x64烈火汉化版_2.exe
c:\windows\system32\ntdll.dll
6388"C:\Program Files\WinRAR\uninstall.exe" /cleanC:\Program Files\WinRAR\Uninstall.exeWinRAR7.11-Final-x64烈火汉化版_2.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
HIGH
Description:
Uninstall WinRAR
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\uninstall.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
6964"C:\Users\admin\AppData\Local\Temp\WinRAR7.11-Final-x64烈火汉化版_2.exe" C:\Users\admin\AppData\Local\Temp\WinRAR7.11-Final-x64烈火汉化版_2.exe
explorer.exe
User:
admin
Company:
全球发行商 win.rar GmbH
Integrity Level:
HIGH
Description:
WinRAR 压缩文件管理器
Exit code:
0
Version:
7.11.2
Modules
Images
c:\users\admin\appdata\local\temp\winrar7.11-final-x64烈火汉化版_2.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
7144C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
Total events
1 299
Read events
1 207
Write events
88
Delete events
4

Modification events

(PID) Process:(6964) WinRAR7.11-Final-x64烈火汉化版_2.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(6964) WinRAR7.11-Final-x64烈火汉化版_2.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(6964) WinRAR7.11-Final-x64烈火汉化版_2.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(6964) WinRAR7.11-Final-x64烈火汉化版_2.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR SFX
Operation:writeName:C%%Program Files%WinRAR
Value:
C:\Program Files\WinRAR
(PID) Process:(6964) WinRAR7.11-Final-x64烈火汉化版_2.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\LowRegistry
Operation:delete valueName:AddToFavoritesInitialSelection
Value:
(PID) Process:(6964) WinRAR7.11-Final-x64烈火汉化版_2.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\LowRegistry
Operation:delete valueName:AddToFeedsInitialSelection
Value:
(PID) Process:(4188) Uninstall.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.rar\ShellNew
Operation:writeName:FileName
Value:
C:\Program Files\WinRAR\rarnew.dat
(PID) Process:(4188) Uninstall.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zip\ShellNew
Operation:delete keyName:(default)
Value:
(PID) Process:(4188) Uninstall.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zip\ShellNew
Operation:writeName:FileName
Value:
C:\Program Files\WinRAR\zipnew.dat
(PID) Process:(4188) Uninstall.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Setup\.jar
Operation:writeName:Exist
Value:
1
Executable files
13
Suspicious files
14
Text files
12
Unknown types
0

Dropped files

PID
Process
Filename
Type
6964WinRAR7.11-Final-x64烈火汉化版_2.exe
MD5:
SHA256:
6964WinRAR7.11-Final-x64烈火汉化版_2.exeC:\Program Files\WinRAR\Descript.iontext
MD5:D4F4BA061E5B947B7BEDC0B2F7077450
SHA256:EF04F311AD98253E6D6162F47B6DA4CB16538FBC1BBF0E643CC181AF6039AD30
6964WinRAR7.11-Final-x64烈火汉化版_2.exeC:\Program Files\WinRAR\Order.htmhtml
MD5:CE28C19DDF7D42C76DD9763CDBC7EACE
SHA256:C30A7874872BFEF2ED29C6F83C4D8E33C4A2A79B8B5E850C6CB6481E4F90114C
6964WinRAR7.11-Final-x64烈火汉化版_2.exeC:\Program Files\WinRAR\Rar.exeexecutable
MD5:2642B64F3ACC61230B724AF57F01E13A
SHA256:C335F4725015823029AFE01763059E6A2B793A428323FBF1DCB1F738E196FC29
6964WinRAR7.11-Final-x64烈火汉化版_2.exeC:\Program Files\WinRAR\Rar.txttext
MD5:FB57D1064D38E6F08CE17F4B485BE879
SHA256:24925659D92EB2375880E56604CC67282FFD91C4DFDDD953414B81F287952327
6964WinRAR7.11-Final-x64烈火汉化版_2.exeC:\Program Files\WinRAR\RarFiles.lsttext
MD5:2725B7E7D7CD96D507961AB7E2807575
SHA256:B1E8179074131A11F5E877FC969B58CAB1B90C24D73B754E2FFB7C302954266D
6964WinRAR7.11-Final-x64烈火汉化版_2.exeC:\Program Files\WinRAR\Uninstall.exeexecutable
MD5:63425E4BC8F08F76084EE8F283790DCC
SHA256:70EEC4A4834D5C21843BCF0F8ED42E75D01FE56D4C38373247CCF6A99C44C8D6
6964WinRAR7.11-Final-x64烈火汉化版_2.exeC:\Program Files\WinRAR\WhatsNew.txttext
MD5:C7C2B744054EB5E428CEEDB3C95B1519
SHA256:E8FB27A05290518D53BC93003834ECE5FC72C828115D624F167C0DCCD2A584E6
6964WinRAR7.11-Final-x64烈火汉化版_2.exeC:\Program Files\WinRAR\UnRAR.exeexecutable
MD5:E522660A105607B5B081A8D7F22E4162
SHA256:E6CCFC9F2DDF2490FDC33177BB2038F890201426168959E42B916FE3894E9C56
6964WinRAR7.11-Final-x64烈火汉化版_2.exeC:\Program Files\WinRAR\RarExtInstaller.exeexecutable
MD5:13F58E3D2C8E28A1A57C8DD1D107CAEC
SHA256:67087D0EF15C29E1A23A9C8B3332BCFD630F1B58EF65EABD1C8F357CAF83D9BB
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
18
DNS requests
13
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
23.48.23.156:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
7148
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
7148
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
6544
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
2104
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
23.48.23.156:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
2112
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3216
svchost.exe
172.211.123.250:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
6544
svchost.exe
20.190.160.130:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6544
svchost.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
2104
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
  • 51.104.136.2
whitelisted
crl.microsoft.com
  • 23.48.23.156
  • 23.48.23.143
whitelisted
google.com
  • 142.250.186.174
whitelisted
client.wns.windows.com
  • 172.211.123.250
whitelisted
login.live.com
  • 20.190.160.130
  • 20.190.160.64
  • 20.190.160.66
  • 20.190.160.22
  • 20.190.160.2
  • 20.190.160.5
  • 20.190.160.65
  • 40.126.32.134
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
slscr.update.microsoft.com
  • 20.12.23.50
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 40.69.42.241
whitelisted

Threats

No threats detected
No debug info