File name:

o.rar

Full analysis: https://app.any.run/tasks/e0f9c9e1-345f-4fb0-8ba0-e5238838eadb
Verdict: Malicious activity
Analysis date: January 28, 2024, 16:53:54
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

1FADBD7892A7B4B7593D7F4789D78099

SHA1:

4777F591ABA07220FDE819DF8ACE269D70D507E6

SHA256:

38B42E6828EB97B359B093B3724B7DFECBF0ABB155257078842B53FB8699E2DA

SSDEEP:

12288:mb+AbITNFikn8amThZowywRC+Q1CzyxCkFA/uGlE:mb+ACNFikn8fTfo/r+Q1CmvA/uG6

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 2808)
      • Office2007Portable.exe (PID: 2356)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • Office2007Portable.exe (PID: 2356)
  • INFO

    • Manual execution by a user

      • Launch Microsoft Excel.exe (PID: 1268)
      • Launch Microsoft Excel.exe (PID: 2688)
      • Launch Microsoft PowerPoint.exe (PID: 1972)
      • Launch Microsoft PowerPoint.exe (PID: 2564)
      • Launch Microsoft Word.exe (PID: 3072)
      • notepad.exe (PID: 3040)
      • Launch Microsoft Word.exe (PID: 880)
      • Office2007Portable.exe (PID: 2356)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2808)
    • Checks supported languages

      • Launch Microsoft Excel.exe (PID: 2688)
      • Launch Microsoft PowerPoint.exe (PID: 2564)
      • Launch Microsoft Word.exe (PID: 880)
      • Office2007Portable.exe (PID: 2356)
    • Reads the computer name

      • Launch Microsoft Excel.exe (PID: 2688)
      • Launch Microsoft PowerPoint.exe (PID: 2564)
      • Launch Microsoft Word.exe (PID: 880)
      • Office2007Portable.exe (PID: 2356)
    • Create files in a temporary directory

      • Launch Microsoft Excel.exe (PID: 2688)
      • Launch Microsoft PowerPoint.exe (PID: 2564)
      • Office2007Portable.exe (PID: 2356)
      • Launch Microsoft Word.exe (PID: 880)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
54
Monitored processes
10
Malicious processes
0
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe launch microsoft excel.exe no specs launch microsoft excel.exe launch microsoft powerpoint.exe no specs launch microsoft powerpoint.exe launch microsoft word.exe no specs launch microsoft word.exe office2007portable.exe notepad.exe no specs PhotoViewer.dll no specs

Process information

PID
CMD
Path
Indicators
Parent process
880"C:\Users\admin\Desktop\Launch Microsoft Word.exe" C:\Users\admin\Desktop\Launch Microsoft Word.exe
explorer.exe
User:
admin
Company:
PerkedleApps
Integrity Level:
HIGH
Description:
Microsoft Office Word 2007 Portable
Exit code:
2
Version:
0.0.0.0
Modules
Images
c:\users\admin\desktop\launch microsoft word.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
1028C:\Windows\system32\DllHost.exe /Processid:{76D0CB12-7604-4048-B83C-1005C7DDC503}C:\Windows\System32\dllhost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
COM Surrogate
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\dllhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1268"C:\Users\admin\Desktop\Launch Microsoft Excel.exe" C:\Users\admin\Desktop\Launch Microsoft Excel.exeexplorer.exe
User:
admin
Company:
PerkedleApps
Integrity Level:
MEDIUM
Description:
Microsoft Office Excel 2007 Portable
Exit code:
3221226540
Version:
0.0.0.0
Modules
Images
c:\users\admin\desktop\launch microsoft excel.exe
c:\windows\system32\ntdll.dll
1972"C:\Users\admin\Desktop\Launch Microsoft PowerPoint.exe" C:\Users\admin\Desktop\Launch Microsoft PowerPoint.exeexplorer.exe
User:
admin
Company:
PerkedleApps
Integrity Level:
MEDIUM
Description:
Microsoft Office PowerPoint 2007 Portable
Exit code:
3221226540
Version:
0.0.0.0
Modules
Images
c:\users\admin\desktop\launch microsoft powerpoint.exe
c:\windows\system32\ntdll.dll
2356"C:\Users\admin\Desktop\Office2007Portable.exe" C:\Users\admin\Desktop\Office2007Portable.exe
explorer.exe
User:
admin
Company:
PerkedleApps
Integrity Level:
MEDIUM
Description:
Microsoft Office 2007 Portable
Exit code:
0
Version:
0.0.0.0
Modules
Images
c:\users\admin\desktop\office2007portable.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
2564"C:\Users\admin\Desktop\Launch Microsoft PowerPoint.exe" C:\Users\admin\Desktop\Launch Microsoft PowerPoint.exe
explorer.exe
User:
admin
Company:
PerkedleApps
Integrity Level:
HIGH
Description:
Microsoft Office PowerPoint 2007 Portable
Exit code:
2
Version:
0.0.0.0
Modules
Images
c:\users\admin\desktop\launch microsoft powerpoint.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
2688"C:\Users\admin\Desktop\Launch Microsoft Excel.exe" C:\Users\admin\Desktop\Launch Microsoft Excel.exe
explorer.exe
User:
admin
Company:
PerkedleApps
Integrity Level:
HIGH
Description:
Microsoft Office Excel 2007 Portable
Exit code:
2
Version:
0.0.0.0
Modules
Images
c:\users\admin\desktop\launch microsoft excel.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
2808"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\o.rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3040"C:\Windows\system32\NOTEPAD.EXE" C:\Users\admin\Desktop\Office2007Portable.iniC:\Windows\System32\notepad.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\notepad.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3072"C:\Users\admin\Desktop\Launch Microsoft Word.exe" C:\Users\admin\Desktop\Launch Microsoft Word.exeexplorer.exe
User:
admin
Company:
PerkedleApps
Integrity Level:
MEDIUM
Description:
Microsoft Office Word 2007 Portable
Exit code:
3221226540
Version:
0.0.0.0
Modules
Images
c:\users\admin\desktop\launch microsoft word.exe
c:\windows\system32\ntdll.dll
Total events
1 187
Read events
1 166
Write events
21
Delete events
0

Modification events

(PID) Process:(2808) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2808) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(2808) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(2808) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(2808) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(2808) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2808) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2808) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2808) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2808) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000
Executable files
6
Suspicious files
4
Text files
2
Unknown types
0

Dropped files

PID
Process
Filename
Type
2808WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2808.32908\Launch Microsoft Excel.exeexecutable
MD5:F5F06E05DD0D3F775334719FF755405B
SHA256:A0D534FDB9074C22817C912FF9AC71EF0EA7332FB53E0B296EF0B979D1494F66
2564Launch Microsoft PowerPoint.exeC:\Users\admin\AppData\Local\Temp\nseDF05.tmpbinary
MD5:A2C272DD5E04835CF9EB0045EEE1FAF9
SHA256:C5A7D8F4A4E6403C8DD70D5A4619F402CAB19C6BF8581B76D1F0E03DF8B239B3
2808WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2808.32908\Office2007Portable.exeexecutable
MD5:62C0AB08B08707DF8BBBA1BE60351AA4
SHA256:1448404D59F44299D278B2BDD21887B3FF5EA8320E591B2FF7F2676FE2AE3DF3
2688Launch Microsoft Excel.exeC:\Users\admin\AppData\Local\Temp\nsyB7E5.tmpbinary
MD5:5E6A01DB5F933D8D1E39DD6892917A58
SHA256:2B0FF318F6A06655B5309D07736F74FCAB5FBB88C25106C770ED432BA4298FDB
2356Office2007Portable.exeC:\Users\admin\AppData\Local\Temp\nsoF721.tmpbinary
MD5:8D8985AD5BD91EBBD353D4B39A206C38
SHA256:28DFEC946FD2A8E2475F7E50FEC68B0A84A95BD381655B19B6567E17B39C9BCF
2356Office2007Portable.exeC:\Users\admin\AppData\Local\Temp\nsoF722.tmp\newadvsplash.dllexecutable
MD5:7EE14DFF57FB6E6C644B318D16768F4C
SHA256:53377D0710F551182EDBAB4150935425948535D11B92BF08A1C2DCF989723BD7
2808WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2808.32908\Office2007Portable.initext
MD5:13F8C59260BB3E844EAE5AE188872B6A
SHA256:82DE4391C5F4B6DB19CBFD918E1AA5EF1CB784970B66F4030882CF20F07F8EA8
2808WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2808.32908\Launch Microsoft Word.exeexecutable
MD5:1B13B12ED6851C6B46B1A4BFD4193AC7
SHA256:62ED82A3DF339C9F8D1FF87BC4ED091B8CB9E355266DEA00A302481D0DC8A552
2808WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2808.32908\Screenshot.pngimage
MD5:FC71015FC011B441699DE7B68EB5E86F
SHA256:1A7B99D0199E2792C4BA1778C30B8CA1DAC81296AB2F08E7F5D3AE388C2DF82E
2808WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2808.32908\Launch Microsoft PowerPoint.exeexecutable
MD5:DE07DC16F03BA942A45A424B22D13850
SHA256:6390EFD9385FD690936B3D1AF683227D7E586645998DADD92D39B19B407C37B0
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1080
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted

DNS requests

No data

Threats

No threats detected
No debug info