File name: | САПЕР.rar |
Full analysis: | https://app.any.run/tasks/d2268b09-2aba-4f86-9915-d92b1f11084a |
Verdict: | Malicious activity |
Analysis date: | December 13, 2024, 21:59:42 |
OS: | Windows 10 Professional (build: 19045, 64 bit) |
Tags: | |
Indicators: | |
MIME: | application/x-rar |
File info: | RAR archive data, v5 |
MD5: | D2BA16458647CF3E153626C2E316F1C9 |
SHA1: | 92BCA3AEF569B45FD2F478B553D5D112D267343B |
SHA256: | 2DEB9F605A5543C6027DC32A434190F53CAD4FBCD50B5E596906465894DD3AA3 |
SSDEEP: | 98304:rkuZnV/QcWLvtuWT6l/FFdNPLBzGG9K+YSlI3+M8A1cuH+fbmFR1TEgEsQ6xi7hi:8Q6qM1gYpIuUjZG |
.rar | | | RAR compressed archive (v5.0) (61.5) |
---|---|---|
.rar | | | RAR compressed archive (gen) (38.4) |
ArchivedFileName: | САПЕР/procenti.txt |
---|---|
OperatingSystem: | Win32 |
UncompressedSize: | 50 |
CompressedSize: | 23 |
FileVersion: | RAR v5 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
5920 | "C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\САПЕР.rar | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Version: 5.91.0 Modules
| |||||||||||||||
1476 | C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -Embedding | C:\Windows\System32\rundll32.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows host process (Rundll32) Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
4136 | "C:\Users\admin\Desktop\САПЕР\САПЕР.exe" | C:\Users\admin\Desktop\САПЕР\САПЕР.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
1616 | "C:\WINDOWS\system32\NOTEPAD.EXE" C:\Users\admin\Desktop\САПЕР\procenti.txt | C:\Windows\System32\notepad.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Notepad Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
836 | "C:\Users\admin\Desktop\САПЕР\САПЕР.exe" | C:\Users\admin\Desktop\САПЕР\САПЕР.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 1 Modules
| |||||||||||||||
4640 | "C:\Users\admin\Desktop\САПЕР\САПЕР.exe" | C:\Users\admin\Desktop\САПЕР\САПЕР.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 1 Modules
|
(PID) Process: | (5920) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\preferences.zip | |||
(PID) Process: | (5920) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\chromium_ext.zip | |||
(PID) Process: | (5920) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\omni_23_10_2024_.zip | |||
(PID) Process: | (5920) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\САПЕР.rar | |||
(PID) Process: | (5920) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | name |
Value: 120 | |||
(PID) Process: | (5920) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | size |
Value: 80 | |||
(PID) Process: | (5920) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | type |
Value: 120 | |||
(PID) Process: | (5920) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | mtime |
Value: 100 |
PID | Process | Filename | Type | |
---|---|---|---|---|
5920 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa5920.188\САПЕР\procenti.txt | text | |
MD5:9309DEC0D7E8715D1A48D8298B97B2C8 | SHA256:24318D5043599ED3BD9ADC2F751A66D75BCA08C3FB3BD79C261DF76E4C074CF6 | |||
5920 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa5920.188\САПЕР\_internal\api-ms-win-core-debug-l1-1-0.dll | executable | |
MD5:6F5C5015C4E74602F582C21F54CECBEC | SHA256:CF7DC6F5ABE58E31B41912B4A84CABD106EECF7CAD7F5A1942C4BEFACA703536 | |||
5920 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa5920.188\САПЕР\_internal\api-ms-win-core-libraryloader-l1-1-0.dll | executable | |
MD5:2137C99CB93C37C13252BB76B06A40EE | SHA256:B942E2A62D69CE41534CA7C9822F672EDEB8FF37B8E650001C9432C28B765CD7 | |||
5920 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa5920.188\САПЕР\_internal\api-ms-win-core-processenvironment-l1-1-0.dll | executable | |
MD5:F29002525B0562CA1AEC53B0FB9B0E9A | SHA256:F4D5BE821780A3DB520258A451B50FA8CDE1486B607477A958F6F529DCB74F43 | |||
5920 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa5920.188\САПЕР\_internal\api-ms-win-core-file-l1-2-0.dll | executable | |
MD5:D54860BC805F73CD8E7E3FE05D544108 | SHA256:68E28B5944193AB45BE2CC14E49424BA0C5D8713BB6B027E96FF1C16147F19A3 | |||
5920 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa5920.188\САПЕР\_internal\api-ms-win-core-errorhandling-l1-1-0.dll | executable | |
MD5:A3D85E6AC7C84D25E288BEAD48197B9E | SHA256:41DD8451C6B25A7A924A7A42A3D466350BCD2820FCA4177EF5F6305E6EADB97A | |||
5920 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa5920.188\САПЕР\_internal\api-ms-win-core-processthreads-l1-1-0.dll | executable | |
MD5:C0CD80654C61C5DF82AD0A52064AB584 | SHA256:AE507DCDD0E6C6BDED417A64918EF0CC76E41FFE475F67478B841BA05CC73BBB | |||
5920 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa5920.188\САПЕР\_internal\api-ms-win-core-console-l1-1-0.dll | executable | |
MD5:93B762FED6EABF7BE765A190E2CEC0AD | SHA256:CB3F7B194D220004FFA6EEF1305849BCEF38033C49CB1B16C5AB3C3D60BD9D20 | |||
5920 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa5920.188\САПЕР\_internal\api-ms-win-core-interlocked-l1-1-0.dll | executable | |
MD5:C53B1D75109B9F6B2FEE53A8794CB883 | SHA256:39883213A6434F6F3A3F6D174630A1286C28EF7F47B7E3E1DE4623CD9F3CE270 | |||
5920 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa5920.188\САПЕР\_internal\api-ms-win-core-heap-l1-1-0.dll | executable | |
MD5:BF44C8DF95C1849DAC7BE1EBFE29CFBC | SHA256:9669EE54D953BBA692FC6B5E806F7F7645258C5F0618D253F8043E832FE75E2D |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
6252 | backgroundTaskHost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D | unknown | — | — | whitelisted |
7100 | SIHClient.exe | GET | 200 | 88.221.169.152:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
7100 | SIHClient.exe | GET | 200 | 88.221.169.152:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
440 | svchost.exe | GET | 200 | 23.215.121.133:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
440 | svchost.exe | GET | 200 | 23.32.238.153:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
1176 | svchost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
5064 | SearchApp.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4712 | MoUsoCoreWorker.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
— | — | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
440 | svchost.exe | 23.32.238.153:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
440 | svchost.exe | 23.215.121.133:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
5064 | SearchApp.exe | 2.19.80.56:443 | www.bing.com | Akamai International B.V. | DE | whitelisted |
1176 | svchost.exe | 20.190.160.20:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
1176 | svchost.exe | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
5064 | SearchApp.exe | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
Domain | IP | Reputation |
---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
www.bing.com |
| whitelisted |
login.live.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
go.microsoft.com |
| whitelisted |
arc.msn.com |
| whitelisted |
fd.api.iris.microsoft.com |
| whitelisted |