File name:

SirHurt V2 Trial 5-17-19.rar

Full analysis: https://app.any.run/tasks/c1a67931-1b21-4ef2-a7b6-ff2222e86056
Verdict: Malicious activity
Analysis date: June 21, 2019, 16:46:29
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

76E5A0AB4552AF7B2D057BEB7A4E17C3

SHA1:

F93EA6AF8FD37ADF9693B960EF2E56438C4E0FCE

SHA256:

38096E737399933D6BEC5E71F5CC193F335A7B16902C9729404D89EF9342BFBD

SSDEEP:

393216:TgqVzX62QE/Ergd0nCKOirNaOE9q7JShoMQGj0kYA3m1R4K1:0q1n0gGn8iE6JShoK0kJHO

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • SearchProtocolHost.exe (PID: 832)
      • explorer.exe (PID: 116)
      • SirHurt V2.exe (PID: 2796)
    • Application was dropped or rewritten from another process

      • SirHurt V2.exe (PID: 2796)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • explorer.exe (PID: 116)
      • WinRAR.exe (PID: 1820)
      • SirHurt V2.exe (PID: 2796)
  • INFO

    • Reads Microsoft Office registry keys

      • WinRAR.exe (PID: 1820)
      • explorer.exe (PID: 116)
    • Manual execution by user

      • SirHurt V2.exe (PID: 2796)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
34
Monitored processes
4
Malicious processes
2
Suspicious processes
1

Behavior graph

Click at the process to see the details
start drop and start winrar.exe explorer.exe sirhurt v2.exe searchprotocolhost.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
116C:\Windows\Explorer.EXEC:\Windows\explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\winanr.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
832"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe5_ Global\UsGthrCtrlFltPipeMssGthrPipe5 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" C:\Windows\System32\SearchProtocolHost.exeSearchIndexer.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Windows Search Protocol Host
Exit code:
0
Version:
7.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\searchprotocolhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1820"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\SirHurt V2 Trial 5-17-19.rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2796"C:\Users\admin\Desktop\SirHurt V2.exe" C:\Users\admin\Desktop\SirHurt V2.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
SirhurtUI
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\sirhurt v2.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
Total events
1 751
Read events
1 705
Write events
46
Delete events
0

Modification events

(PID) Process:(1820) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(1820) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(1820) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\62\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1820) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\SirHurt V2 Trial 5-17-19.rar
(PID) Process:(1820) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(1820) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(1820) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(1820) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(116) explorer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rar\OpenWithList
Operation:writeName:a
Value:
WinRAR.exe
(PID) Process:(116) explorer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rar\OpenWithList
Operation:writeName:MRUList
Value:
a
Executable files
9
Suspicious files
0
Text files
6
Unknown types
0

Dropped files

PID
Process
Filename
Type
116explorer.exeC:\Users\admin\Desktop\autoexe
MD5:
SHA256:
116explorer.exeC:\Users\admin\Desktop\scripts
MD5:
SHA256:
116explorer.exeC:\Users\admin\Desktop\workspace
MD5:
SHA256:
1820WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1820.13760\autoexe\loaded.luatext
MD5:8F57FF2D7107EE2811B1FE356A0FF16A
SHA256:94061B27FEE76B3AC49BCCC3F3C3D9B34B717FA47AD3CCB5A73ABDD986BCA498
116explorer.exeC:\Users\admin\Desktop\SirHurt V2 Documentation.htmltext
MD5:ED54D7D0CC5FD06454D989005B9B02CA
SHA256:F469D7D3117624CF4FB5E310D261FCCE401E73EFDC78AAC9FBDBB34DFFC52BA9
1820WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1820.13760\SirHurt.dllexecutable
MD5:3B0A8FF95F47A32DA04AB4E88AE45925
SHA256:2E3307B7B1EF7DC2AADB6704690AB4EB2722EF5DA59D3972C7F0A63D16428623
1820WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1820.13760\SirHurtInjector.dllexecutable
MD5:F008EA5BE27028B4F8ECFD8A36DAA5C9
SHA256:55643251311B621EDF1181415C4B6D66BF4C837C98122A26EEA75A444B2B968F
116explorer.exeC:\Users\admin\Desktop\SirHurt.dllexecutable
MD5:3B0A8FF95F47A32DA04AB4E88AE45925
SHA256:2E3307B7B1EF7DC2AADB6704690AB4EB2722EF5DA59D3972C7F0A63D16428623
116explorer.exeC:\Users\admin\Desktop\SirHurtInjector.dllexecutable
MD5:F008EA5BE27028B4F8ECFD8A36DAA5C9
SHA256:55643251311B621EDF1181415C4B6D66BF4C837C98122A26EEA75A444B2B968F
116explorer.exeC:\Users\admin\Desktop\SirHurt V2.exeexecutable
MD5:E8B668689C64BE637F140A9ECAB416C8
SHA256:3D74ADA58676267294075EA17C9CC8D4385568626015DD1488E546DFC715E264
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info