| File name: | Browny02.rar |
| Full analysis: | https://app.any.run/tasks/4f32c02b-fbb3-42f4-9f38-d4555ff8143b |
| Verdict: | Malicious activity |
| Analysis date: | April 03, 2020, 07:00:12 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-rar |
| File info: | RAR archive data, v4, os: Win32 |
| MD5: | C0F9822A8C59F486F5419E8C7C36F188 |
| SHA1: | F95A1EE8B9CAE84E5FCBBE8BD1072B690DA6B403 |
| SHA256: | 33994C49C4F07C1C436BF156A45A00E238F69DA3826136B3DD4BD5A81187BF17 |
| SSDEEP: | 98304:Ewz3i8VoQ3OBObQ2v5osKFBtg5i2TbxThCRbH15+Ic5YtD+XN:Ewz3ihQ2OlvjOBtg5iORs5H15UX |
| .rar | | | RAR compressed archive (v-4.x) (58.3) |
|---|---|---|
| .rar | | | RAR compressed archive (gen) (41.6) |
| CompressedSize: | 741 |
|---|---|
| UncompressedSize: | 4096 |
| OperatingSystem: | Win32 |
| ModifyDate: | 2020:02:14 12:44:27 |
| PackingMethod: | Good Compression |
| ArchivedFileName: | Browny02\$I30 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1444 | C:\Windows\system32\DllHost.exe /Processid:{3AD05575-8857-4850-9277-11B85BDB8E09} | C:\Windows\system32\DllHost.exe | svchost.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: COM Surrogate Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2672 | "C:\Program Files\Browny02\BrYNSvc.exe" | C:\Program Files\Browny02\BrYNSvc.exe | — | explorer.exe | |||||||||||
User: admin Company: Brother Industries, Ltd. Integrity Level: MEDIUM Description: BrYNCSvc Exit code: 2 Version: 1.5.1.0 Modules
| |||||||||||||||
| 3152 | "C:\Program Files\Browny02\BrYNSvc.exe" | C:\Program Files\Browny02\BrYNSvc.exe | — | explorer.exe | |||||||||||
User: admin Company: Brother Industries, Ltd. Integrity Level: MEDIUM Description: BrYNCSvc Exit code: 2 Version: 1.5.1.0 Modules
| |||||||||||||||
| 3296 | "C:\Program Files\Browny02\BrYNSvc.exe" | C:\Program Files\Browny02\BrYNSvc.exe | — | explorer.exe | |||||||||||
User: admin Company: Brother Industries, Ltd. Integrity Level: MEDIUM Description: BrYNCSvc Exit code: 2 Version: 1.5.1.0 Modules
| |||||||||||||||
| 3732 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Browny02.rar" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.60.0 Modules
| |||||||||||||||
| (PID) Process: | (3732) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (3732) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (3732) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3732) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\Browny02.rar | |||
| (PID) Process: | (3732) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (3732) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (3732) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (3732) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3732 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3732.8067\Browny02\AdditionalMessage_M12AP.ini | text | |
MD5:3D8AAA62932453CE20C338F6F97FCD53 | SHA256:2AB2136B7F812D61B84EC47C4AD1AFC276B375E11D1D298EB00076CB594405AD | |||
| 3732 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3732.8067\Browny02\BRLMW03A.INI | text | |
MD5:DAE4DF3BEB5660A23ABA5398E522218E | SHA256:843E32E02A5806E6F2AB7F1600EE324FDE4018697A57C784C08B383C32857545 | |||
| 3732 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3732.8067\Browny02\BroSNMP.dll | executable | |
MD5:77C344EE478BB4329D16A6DCDF1CE087 | SHA256:2970B92D8F3712F6B4E3588C281EF24879EE3D5D42CD493757C4326EAA2A0484 | |||
| 3732 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3732.8067\Browny02\brif03a.dll | executable | |
MD5:59DBBA43CBBC9F039196DE4DCEB23A4A | SHA256:8FDEB9351936072A23D0CB6A66FE23016C4FE29FE8CB05E5463BC73CCE9036A2 | |||
| 3732 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3732.8067\Browny02\brlm03a.dll | executable | |
MD5:114E9DE7781BEE1FF4738658C12C013A | SHA256:06A37DBF5141589A397ECEFA96DF3E0AAD63DCCBD1BC3FF3BFCDE3284F84FD24 | |||
| 3732 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3732.8067\Browny02\Brother\BrNetToolAru.dll | executable | |
MD5:28EA9EE053EFBC37FE6D1161072D8905 | SHA256:6F1D6D24BA1B9BF32E04464BF50779770239B6D0CA777B5EAEF22042FFD88E96 | |||
| 3732 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3732.8067\Browny02\Brother\BrMfNt.dll | executable | |
MD5:A0BDEE4D0860D9EB71FAC8B0E358BBAD | SHA256:8D4BD21BA5722A641EE2AEE67D6EBCB1976D06A6D9A43D379CD65732302CD8C3 | |||
| 3732 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3732.8067\Browny02\Brother\BrFirmUpdateCheck.dll | executable | |
MD5:53FA6D58BE4782B4D058583ED17521D5 | SHA256:17AB0FCC4B1053F4B548AB6CBDB608551662B5A0DC740DF205BF709ECFF6C074 | |||
| 3732 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3732.8067\Browny02\BrMonitor.dll | executable | |
MD5:E938BB1D7523E4CEC914CDE0C8159E4E | SHA256:86CCE507E2A90604085B99BAC94C62A653BD2843A04D7982DCA7399931B73911 | |||
| 3732 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3732.8067\Browny02\Brother\BrNetTool.fil | text | |
MD5:256145B8CF9263DD929A25D9F0622DA4 | SHA256:F41EDF150D3176A25B579B52FC40E63027902573E03E693D402DAC0107B54503 | |||