File name:

САПЕР.rar

Full analysis: https://app.any.run/tasks/d2268b09-2aba-4f86-9915-d92b1f11084a
Verdict: Malicious activity
Analysis date: December 13, 2024, 21:59:42
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
arch-doc
arch-email
python
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

D2BA16458647CF3E153626C2E316F1C9

SHA1:

92BCA3AEF569B45FD2F478B553D5D112D267343B

SHA256:

2DEB9F605A5543C6027DC32A434190F53CAD4FBCD50B5E596906465894DD3AA3

SSDEEP:

98304:rkuZnV/QcWLvtuWT6l/FFdNPLBzGG9K+YSlI3+M8A1cuH+fbmFR1TEgEsQ6xi7hi:8Q6qM1gYpIuUjZG

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Process drops python dynamic module

      • WinRAR.exe (PID: 5920)
    • Generic archive extractor

      • WinRAR.exe (PID: 5920)
    • Loads Python modules

      • САПЕР.exe (PID: 4136)
      • САПЕР.exe (PID: 836)
      • САПЕР.exe (PID: 4640)
    • Process drops legitimate windows executable

      • WinRAR.exe (PID: 5920)
  • INFO

    • Reads the computer name

      • САПЕР.exe (PID: 4640)
      • САПЕР.exe (PID: 4136)
    • Checks supported languages

      • САПЕР.exe (PID: 836)
      • САПЕР.exe (PID: 4136)
      • САПЕР.exe (PID: 4640)
    • Manual execution by a user

      • САПЕР.exe (PID: 836)
      • notepad.exe (PID: 1616)
      • САПЕР.exe (PID: 4136)
      • САПЕР.exe (PID: 4640)
    • Reads security settings of Internet Explorer

      • notepad.exe (PID: 1616)
    • The sample compiled with english language support

      • WinRAR.exe (PID: 5920)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 5920)
    • Create files in a temporary directory

      • САПЕР.exe (PID: 4136)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)

EXIF

ZIP

ArchivedFileName: САПЕР/procenti.txt
OperatingSystem: Win32
UncompressedSize: 50
CompressedSize: 23
FileVersion: RAR v5
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
133
Monitored processes
6
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe rundll32.exe no specs сапер.exe no specs notepad.exe no specs сапер.exe no specs сапер.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
5920"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\САПЕР.rarC:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
1476C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -EmbeddingC:\Windows\System32\rundll32.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shcore.dll
c:\windows\system32\imagehlp.dll
4136"C:\Users\admin\Desktop\САПЕР\САПЕР.exe" C:\Users\admin\Desktop\САПЕР\САПЕР.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\сапер\сапер.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
1616"C:\WINDOWS\system32\NOTEPAD.EXE" C:\Users\admin\Desktop\САПЕР\procenti.txtC:\Windows\System32\notepad.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\notepad.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
836"C:\Users\admin\Desktop\САПЕР\САПЕР.exe" C:\Users\admin\Desktop\САПЕР\САПЕР.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
1
Modules
Images
c:\users\admin\desktop\сапер\сапер.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
4640"C:\Users\admin\Desktop\САПЕР\САПЕР.exe" C:\Users\admin\Desktop\САПЕР\САПЕР.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
1
Modules
Images
c:\users\admin\desktop\сапер\сапер.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
Total events
2 341
Read events
2 333
Write events
8
Delete events
0

Modification events

(PID) Process:(5920) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(5920) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(5920) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(5920) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\САПЕР.rar
(PID) Process:(5920) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(5920) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(5920) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(5920) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
Executable files
55
Suspicious files
3
Text files
922
Unknown types
0

Dropped files

PID
Process
Filename
Type
5920WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa5920.188\САПЕР\procenti.txttext
MD5:9309DEC0D7E8715D1A48D8298B97B2C8
SHA256:24318D5043599ED3BD9ADC2F751A66D75BCA08C3FB3BD79C261DF76E4C074CF6
5920WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa5920.188\САПЕР\_internal\api-ms-win-core-debug-l1-1-0.dllexecutable
MD5:6F5C5015C4E74602F582C21F54CECBEC
SHA256:CF7DC6F5ABE58E31B41912B4A84CABD106EECF7CAD7F5A1942C4BEFACA703536
5920WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa5920.188\САПЕР\_internal\api-ms-win-core-libraryloader-l1-1-0.dllexecutable
MD5:2137C99CB93C37C13252BB76B06A40EE
SHA256:B942E2A62D69CE41534CA7C9822F672EDEB8FF37B8E650001C9432C28B765CD7
5920WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa5920.188\САПЕР\_internal\api-ms-win-core-processenvironment-l1-1-0.dllexecutable
MD5:F29002525B0562CA1AEC53B0FB9B0E9A
SHA256:F4D5BE821780A3DB520258A451B50FA8CDE1486B607477A958F6F529DCB74F43
5920WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa5920.188\САПЕР\_internal\api-ms-win-core-file-l1-2-0.dllexecutable
MD5:D54860BC805F73CD8E7E3FE05D544108
SHA256:68E28B5944193AB45BE2CC14E49424BA0C5D8713BB6B027E96FF1C16147F19A3
5920WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa5920.188\САПЕР\_internal\api-ms-win-core-errorhandling-l1-1-0.dllexecutable
MD5:A3D85E6AC7C84D25E288BEAD48197B9E
SHA256:41DD8451C6B25A7A924A7A42A3D466350BCD2820FCA4177EF5F6305E6EADB97A
5920WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa5920.188\САПЕР\_internal\api-ms-win-core-processthreads-l1-1-0.dllexecutable
MD5:C0CD80654C61C5DF82AD0A52064AB584
SHA256:AE507DCDD0E6C6BDED417A64918EF0CC76E41FFE475F67478B841BA05CC73BBB
5920WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa5920.188\САПЕР\_internal\api-ms-win-core-console-l1-1-0.dllexecutable
MD5:93B762FED6EABF7BE765A190E2CEC0AD
SHA256:CB3F7B194D220004FFA6EEF1305849BCEF38033C49CB1B16C5AB3C3D60BD9D20
5920WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa5920.188\САПЕР\_internal\api-ms-win-core-interlocked-l1-1-0.dllexecutable
MD5:C53B1D75109B9F6B2FEE53A8794CB883
SHA256:39883213A6434F6F3A3F6D174630A1286C28EF7F47B7E3E1DE4623CD9F3CE270
5920WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa5920.188\САПЕР\_internal\api-ms-win-core-heap-l1-1-0.dllexecutable
MD5:BF44C8DF95C1849DAC7BE1EBFE29CFBC
SHA256:9669EE54D953BBA692FC6B5E806F7F7645258C5F0618D253F8043E832FE75E2D
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
32
DNS requests
18
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6252
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
7100
SIHClient.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
7100
SIHClient.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
440
svchost.exe
GET
200
23.215.121.133:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
440
svchost.exe
GET
200
23.32.238.153:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
1176
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
5064
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4712
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
440
svchost.exe
23.32.238.153:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
440
svchost.exe
23.215.121.133:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
5064
SearchApp.exe
2.19.80.56:443
www.bing.com
Akamai International B.V.
DE
whitelisted
1176
svchost.exe
20.190.160.20:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1176
svchost.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
5064
SearchApp.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 51.124.78.146
whitelisted
crl.microsoft.com
  • 23.32.238.153
  • 2.19.198.75
  • 23.32.238.90
  • 23.32.238.107
  • 2.19.198.43
whitelisted
www.microsoft.com
  • 23.215.121.133
  • 88.221.169.152
whitelisted
google.com
  • 142.250.181.238
whitelisted
www.bing.com
  • 2.19.80.56
  • 2.19.80.27
  • 2.19.80.89
whitelisted
login.live.com
  • 20.190.160.20
  • 40.126.32.136
  • 40.126.32.76
  • 40.126.32.72
  • 40.126.32.74
  • 40.126.32.140
  • 20.190.160.14
  • 40.126.32.133
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
go.microsoft.com
  • 23.218.210.69
whitelisted
arc.msn.com
  • 20.199.58.43
whitelisted
fd.api.iris.microsoft.com
  • 20.74.47.205
whitelisted

Threats

No threats detected
No debug info