analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

hello_new.rar

Full analysis: https://app.any.run/tasks/009f4a3b-394a-4f61-aa4c-6c151d4e2f3d
Verdict: Malicious activity
Analysis date: August 09, 2020, 07:00:34
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v4, os: Win32
MD5:

6399DCEC360D8B5D7059CB8FC4EC5B2C

SHA1:

607AE1DD91A5C36B2DEF49CA234CE41AB5265FD5

SHA256:

311F6319354A93EB5422A407335A485762AB92BFDD4779FA9DC27D2309DBB26A

SSDEEP:

1536:XpDwfZcx0Y3qxV0y/VXtUsLaJ7fz1wkZ6JuO7f4+wbEh/ymADpgzNbD8S2:5kRU6LTttUsGJ7io6J7U+wJmy48S2

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Actions looks like stealing of personal data

      • hello_new.exe (PID: 1228)
    • Loads dropped or rewritten executable

      • SearchProtocolHost.exe (PID: 2568)
    • Application was dropped or rewritten from another process

      • hello_new.exe (PID: 1228)
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    • Manual execution by user

      • WinRAR.exe (PID: 3924)
      • hello_new.exe (PID: 1228)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v-4.x) (58.3)
.rar | RAR compressed archive (gen) (41.6)

EXIF

ZIP

CompressedSize: 48987
UncompressedSize: 100352
OperatingSystem: Win32
ModifyDate: 2020:08:08 16:40:24
PackingMethod: Normal
ArchivedFileName: hello_new.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
45
Monitored processes
4
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe no specs searchprotocolhost.exe no specs hello_new.exe winrar.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1884"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\hello_new.rar"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
2568"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe3_ Global\UsGthrCtrlFltPipeMssGthrPipe3 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" C:\Windows\System32\SearchProtocolHost.exeSearchIndexer.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Windows Search Protocol Host
Version:
7.00.7600.16385 (win7_rtm.090713-1255)
1228"C:\Users\admin\Desktop\hello_new.exe" C:\Users\admin\Desktop\hello_new.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
3924"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\plk33y4ar7sxt87v0i.tar"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.60.0
Total events
781
Read events
752
Write events
0
Delete events
0

Modification events

No data
Executable files
0
Suspicious files
1
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
1884WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1884.28767\hello_new.exe
MD5:
SHA256:
1884WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1884.28767\rde.dll
MD5:
SHA256:
1228hello_new.exeC:\Users\admin\AppData\Local\Temp\bszd4636.tmp
MD5:
SHA256:
1228hello_new.exeC:\Users\admin\Desktop\plk33y4ar7sxt87v0i.tarcompressed
MD5:F2091CA39BC24A818AF7BE8CF123BC15
SHA256:89C6188AD597500FC7FAC531E6E10C8010167672B0EBDC17A8DDD17A32EB2885
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
1
DNS requests
1
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1228
hello_new.exe
POST
404
185.176.43.98:80
http://5ndisjtu.c1.biz/sos.php
BG
html
324 b
malicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1228
hello_new.exe
185.176.43.98:80
5ndisjtu.c1.biz
Zetta Hosting Solutions LLC.
BG
malicious

DNS requests

Domain
IP
Reputation
5ndisjtu.c1.biz
  • 185.176.43.98
malicious

Threats

PID
Process
Class
Message
Potentially Bad Traffic
ET INFO Observed DNS Query to .biz TLD
No debug info