File name:

САПЕР.rar

Full analysis: https://app.any.run/tasks/d2268b09-2aba-4f86-9915-d92b1f11084a
Verdict: Malicious activity
Analysis date: December 13, 2024, 21:59:42
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
arch-doc
arch-email
python
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

D2BA16458647CF3E153626C2E316F1C9

SHA1:

92BCA3AEF569B45FD2F478B553D5D112D267343B

SHA256:

2DEB9F605A5543C6027DC32A434190F53CAD4FBCD50B5E596906465894DD3AA3

SSDEEP:

98304:rkuZnV/QcWLvtuWT6l/FFdNPLBzGG9K+YSlI3+M8A1cuH+fbmFR1TEgEsQ6xi7hi:8Q6qM1gYpIuUjZG

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • WinRAR.exe (PID: 5920)
    • Generic archive extractor

      • WinRAR.exe (PID: 5920)
    • Process drops python dynamic module

      • WinRAR.exe (PID: 5920)
    • Loads Python modules

      • САПЕР.exe (PID: 4136)
      • САПЕР.exe (PID: 836)
      • САПЕР.exe (PID: 4640)
  • INFO

    • The sample compiled with english language support

      • WinRAR.exe (PID: 5920)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 5920)
    • Manual execution by a user

      • САПЕР.exe (PID: 4136)
      • notepad.exe (PID: 1616)
      • САПЕР.exe (PID: 836)
      • САПЕР.exe (PID: 4640)
    • Checks supported languages

      • САПЕР.exe (PID: 4136)
      • САПЕР.exe (PID: 836)
      • САПЕР.exe (PID: 4640)
    • Create files in a temporary directory

      • САПЕР.exe (PID: 4136)
    • Reads the computer name

      • САПЕР.exe (PID: 4136)
      • САПЕР.exe (PID: 4640)
    • Reads security settings of Internet Explorer

      • notepad.exe (PID: 1616)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)

EXIF

ZIP

FileVersion: RAR v5
CompressedSize: 23
UncompressedSize: 50
OperatingSystem: Win32
ArchivedFileName: САПЕР/procenti.txt
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
133
Monitored processes
6
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe rundll32.exe no specs сапер.exe no specs notepad.exe no specs сапер.exe no specs сапер.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
836"C:\Users\admin\Desktop\САПЕР\САПЕР.exe" C:\Users\admin\Desktop\САПЕР\САПЕР.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
1
Modules
Images
c:\users\admin\desktop\сапер\сапер.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
1476C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -EmbeddingC:\Windows\System32\rundll32.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shcore.dll
c:\windows\system32\imagehlp.dll
1616"C:\WINDOWS\system32\NOTEPAD.EXE" C:\Users\admin\Desktop\САПЕР\procenti.txtC:\Windows\System32\notepad.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\notepad.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
4136"C:\Users\admin\Desktop\САПЕР\САПЕР.exe" C:\Users\admin\Desktop\САПЕР\САПЕР.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\сапер\сапер.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
4640"C:\Users\admin\Desktop\САПЕР\САПЕР.exe" C:\Users\admin\Desktop\САПЕР\САПЕР.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
1
Modules
Images
c:\users\admin\desktop\сапер\сапер.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
5920"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\САПЕР.rarC:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
Total events
2 341
Read events
2 333
Write events
8
Delete events
0

Modification events

(PID) Process:(5920) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(5920) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(5920) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(5920) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\САПЕР.rar
(PID) Process:(5920) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(5920) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(5920) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(5920) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
Executable files
55
Suspicious files
3
Text files
922
Unknown types
0

Dropped files

PID
Process
Filename
Type
5920WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa5920.188\САПЕР\procenti.txttext
MD5:9309DEC0D7E8715D1A48D8298B97B2C8
SHA256:24318D5043599ED3BD9ADC2F751A66D75BCA08C3FB3BD79C261DF76E4C074CF6
5920WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa5920.188\САПЕР\_internal\api-ms-win-core-debug-l1-1-0.dllexecutable
MD5:6F5C5015C4E74602F582C21F54CECBEC
SHA256:CF7DC6F5ABE58E31B41912B4A84CABD106EECF7CAD7F5A1942C4BEFACA703536
5920WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa5920.188\САПЕР\_internal\api-ms-win-core-errorhandling-l1-1-0.dllexecutable
MD5:A3D85E6AC7C84D25E288BEAD48197B9E
SHA256:41DD8451C6B25A7A924A7A42A3D466350BCD2820FCA4177EF5F6305E6EADB97A
5920WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa5920.188\САПЕР\_internal\api-ms-win-core-file-l1-2-0.dllexecutable
MD5:D54860BC805F73CD8E7E3FE05D544108
SHA256:68E28B5944193AB45BE2CC14E49424BA0C5D8713BB6B027E96FF1C16147F19A3
5920WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa5920.188\САПЕР\_internal\api-ms-win-core-console-l1-1-0.dllexecutable
MD5:93B762FED6EABF7BE765A190E2CEC0AD
SHA256:CB3F7B194D220004FFA6EEF1305849BCEF38033C49CB1B16C5AB3C3D60BD9D20
5920WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa5920.188\САПЕР\_internal\api-ms-win-core-libraryloader-l1-1-0.dllexecutable
MD5:2137C99CB93C37C13252BB76B06A40EE
SHA256:B942E2A62D69CE41534CA7C9822F672EDEB8FF37B8E650001C9432C28B765CD7
5920WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa5920.188\САПЕР\_internal\api-ms-win-core-datetime-l1-1-0.dllexecutable
MD5:9C145AA4EB0F18AD768988612CB56D03
SHA256:2161C0ADD0EE0A312E12D0346A1B24B6E5E1356A5A7E264911650A8E1D017E1C
5920WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa5920.188\САПЕР\_internal\api-ms-win-core-file-l1-1-0.dllexecutable
MD5:DE7B537E3AD4BBD23BC1AA1461DA7893
SHA256:A198091842029A252E0112120B93BF7323B04ED647A3D2BD27FDE72637385A7B
5920WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa5920.188\САПЕР\_internal\api-ms-win-core-memory-l1-1-0.dllexecutable
MD5:6C43A7FADD205D330C9D1AA360CE8BAF
SHA256:52785BB917C6E38FB69ED5BC1D2BCF01A1C84EC6FB0B94319DDE3835CF64FB7C
5920WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa5920.188\САПЕР\_internal\api-ms-win-core-file-l2-1-0.dllexecutable
MD5:51CDD94858EADFA992E3A397AAE6A4EE
SHA256:57CB180884F33B064957D9C1DD509BB5E8FD541E9458B84D88E025790C1DC986
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
32
DNS requests
18
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1176
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
5064
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
440
svchost.exe
GET
200
23.32.238.153:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
440
svchost.exe
GET
200
23.215.121.133:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
7100
SIHClient.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
6252
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
7100
SIHClient.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4712
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
440
svchost.exe
23.32.238.153:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
440
svchost.exe
23.215.121.133:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
5064
SearchApp.exe
2.19.80.56:443
www.bing.com
Akamai International B.V.
DE
whitelisted
1176
svchost.exe
20.190.160.20:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1176
svchost.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
5064
SearchApp.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 51.124.78.146
whitelisted
crl.microsoft.com
  • 23.32.238.153
  • 2.19.198.75
  • 23.32.238.90
  • 23.32.238.107
  • 2.19.198.43
whitelisted
www.microsoft.com
  • 23.215.121.133
  • 88.221.169.152
whitelisted
google.com
  • 142.250.181.238
whitelisted
www.bing.com
  • 2.19.80.56
  • 2.19.80.27
  • 2.19.80.89
whitelisted
login.live.com
  • 20.190.160.20
  • 40.126.32.136
  • 40.126.32.76
  • 40.126.32.72
  • 40.126.32.74
  • 40.126.32.140
  • 20.190.160.14
  • 40.126.32.133
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
go.microsoft.com
  • 23.218.210.69
whitelisted
arc.msn.com
  • 20.199.58.43
whitelisted
fd.api.iris.microsoft.com
  • 20.74.47.205
whitelisted

Threats

No threats detected
No debug info