| File name: | Advanced Rar Repair.exe |
| Full analysis: | https://app.any.run/tasks/45c1f27b-31cb-4ccb-9f1f-88d541a052a7 |
| Verdict: | Malicious activity |
| Analysis date: | June 04, 2018, 22:57:28 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | DB9D4FD30E586AA00833CFB393E06A74 |
| SHA1: | 2704641E92C00AFA5E8AE06D57361B5BC317BA95 |
| SHA256: | 31B08D1F10D48863A2809D3BF5825618FFE30FF56800EA2318101818CED9170F |
| SSDEEP: | 12288:xtoJaSfasxYdaI6PnRtouwuLDdrD9IEnT+ZQa6OUnf7ZrvZuR1s5gTztmGA:xuapsAUf7FdrD9ZnqZNuf7NI1s5YBA |
| .exe | | | Wise Installer executable (96.9) |
|---|---|---|
| .dll | | | Win32 Dynamic Link Library (generic) (1.3) |
| .exe | | | Win32 Executable (generic) (0.9) |
| .exe | | | Generic Win/DOS Executable (0.4) |
| .exe | | | DOS Executable Generic (0.4) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2000:04:25 16:37:12+02:00 |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 8704 |
| InitializedDataSize: | 5632 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x21af |
| OSVersion: | 4 |
| ImageVersion: | 4 |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.0.0.0 |
| ProductVersionNumber: | 1.0.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Windows 16-bit |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Windows, Latin1 |
| CompanyName: | noname |
| FileDescription: | Advanced RAR Repair v1.2 Installation |
| FileVersion: | - |
| LegalCopyright: | noname |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2408 | "C:\Users\admin\AppData\Local\Temp\GLJB9E9.tmp" C:\Program Files\ARAR\ARARSHL.dll | C:\Users\admin\AppData\Local\Temp\GLJB9E9.tmp | — | Advanced Rar Repair.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 2988 | "C:\Users\admin\AppData\Local\Temp\Advanced Rar Repair.exe" | C:\Users\admin\AppData\Local\Temp\Advanced Rar Repair.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 3221226540 Modules
| |||||||||||||||
| 4028 | "C:\Users\admin\AppData\Local\Temp\Advanced Rar Repair.exe" | C:\Users\admin\AppData\Local\Temp\Advanced Rar Repair.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| (PID) Process: | (4028) Advanced Rar Repair.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Advanced RAR Repair v1.2 |
| Operation: | write | Name: | DisplayName |
Value: Advanced RAR Repair v1.2 | |||
| (PID) Process: | (4028) Advanced Rar Repair.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Advanced RAR Repair v1.2 |
| Operation: | write | Name: | UninstallString |
Value: C:\PROGRA~1\ARAR\UNWISE.EXE C:\PROGRA~1\ARAR\INSTALL.LOG | |||
| (PID) Process: | (2408) GLJB9E9.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\7-Zip.rar\shellex\ContextMenuHandlers\ARAR |
| Operation: | write | Name: | |
Value: {51A64D28-F937-4045-A420-065CEFBD8A76} | |||
| (PID) Process: | (2408) GLJB9E9.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved |
| Operation: | write | Name: | {51A64D28-F937-4045-A420-065CEFBD8A76} |
Value: ARAR Context Menu Shell Extension | |||
| (PID) Process: | (2408) GLJB9E9.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShellExt.ARARCtxMenu.1 |
| Operation: | write | Name: | |
Value: ARARCtxMenu Class | |||
| (PID) Process: | (2408) GLJB9E9.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShellExt.ARARCtxMenu.1\CLSID |
| Operation: | write | Name: | |
Value: {51A64D28-F937-4045-A420-065CEFBD8A76} | |||
| (PID) Process: | (2408) GLJB9E9.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShellExt.ARARCtxMenu |
| Operation: | write | Name: | |
Value: ARARCtxMenu Class | |||
| (PID) Process: | (2408) GLJB9E9.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShellExt.ARARCtxMenu\CLSID |
| Operation: | write | Name: | |
Value: {51A64D28-F937-4045-A420-065CEFBD8A76} | |||
| (PID) Process: | (2408) GLJB9E9.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShellExt.ARARCtxMenu\CurVer |
| Operation: | write | Name: | |
Value: ShellExt.ARARCtxMenu.1 | |||
| (PID) Process: | (2408) GLJB9E9.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{51A64D28-F937-4045-A420-065CEFBD8A76} |
| Operation: | write | Name: | |
Value: ARARCtxMenu Class | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 4028 | Advanced Rar Repair.exe | C:\Users\admin\AppData\Local\Temp\~GLH0000.TMP | — | |
MD5:— | SHA256:— | |||
| 4028 | Advanced Rar Repair.exe | C:\Program Files\ARAR\~GLH0001.TMP | — | |
MD5:— | SHA256:— | |||
| 4028 | Advanced Rar Repair.exe | C:\Program Files\ARAR\~GLH0002.TMP | — | |
MD5:— | SHA256:— | |||
| 4028 | Advanced Rar Repair.exe | C:\Program Files\ARAR\~GLH0003.TMP | — | |
MD5:— | SHA256:— | |||
| 4028 | Advanced Rar Repair.exe | C:\Program Files\ARAR\temp.000 | — | |
MD5:— | SHA256:— | |||
| 4028 | Advanced Rar Repair.exe | C:\PROGRA~1\ARAR\~GLH0004.TMP | — | |
MD5:— | SHA256:— | |||
| 4028 | Advanced Rar Repair.exe | C:\Program Files\ARAR\~GLH0005.TMP | — | |
MD5:— | SHA256:— | |||
| 4028 | Advanced Rar Repair.exe | C:\PROGRA~1\ARAR\~GLH0006.TMP | — | |
MD5:— | SHA256:— | |||
| 4028 | Advanced Rar Repair.exe | C:\Program Files\ARAR\~GLH0007.TMP | — | |
MD5:— | SHA256:— | |||
| 4028 | Advanced Rar Repair.exe | C:\Program Files\ARAR\~GLH0008.TMP | — | |
MD5:— | SHA256:— | |||