| File name: | o.rar |
| Full analysis: | https://app.any.run/tasks/e0f9c9e1-345f-4fb0-8ba0-e5238838eadb |
| Verdict: | Malicious activity |
| Analysis date: | January 28, 2024, 16:53:54 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-rar |
| File info: | RAR archive data, v5 |
| MD5: | 1FADBD7892A7B4B7593D7F4789D78099 |
| SHA1: | 4777F591ABA07220FDE819DF8ACE269D70D507E6 |
| SHA256: | 38B42E6828EB97B359B093B3724B7DFECBF0ABB155257078842B53FB8699E2DA |
| SSDEEP: | 12288:mb+AbITNFikn8amThZowywRC+Q1CzyxCkFA/uGlE:mb+ACNFikn8fTfo/r+Q1CmvA/uG6 |
| .rar | | | RAR compressed archive (v5.0) (61.5) |
|---|---|---|
| .rar | | | RAR compressed archive (gen) (38.4) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 880 | "C:\Users\admin\Desktop\Launch Microsoft Word.exe" | C:\Users\admin\Desktop\Launch Microsoft Word.exe | explorer.exe | ||||||||||||
User: admin Company: PerkedleApps Integrity Level: HIGH Description: Microsoft Office Word 2007 Portable Exit code: 2 Version: 0.0.0.0 Modules
| |||||||||||||||
| 1028 | C:\Windows\system32\DllHost.exe /Processid:{76D0CB12-7604-4048-B83C-1005C7DDC503} | C:\Windows\System32\dllhost.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: COM Surrogate Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1268 | "C:\Users\admin\Desktop\Launch Microsoft Excel.exe" | C:\Users\admin\Desktop\Launch Microsoft Excel.exe | — | explorer.exe | |||||||||||
User: admin Company: PerkedleApps Integrity Level: MEDIUM Description: Microsoft Office Excel 2007 Portable Exit code: 3221226540 Version: 0.0.0.0 Modules
| |||||||||||||||
| 1972 | "C:\Users\admin\Desktop\Launch Microsoft PowerPoint.exe" | C:\Users\admin\Desktop\Launch Microsoft PowerPoint.exe | — | explorer.exe | |||||||||||
User: admin Company: PerkedleApps Integrity Level: MEDIUM Description: Microsoft Office PowerPoint 2007 Portable Exit code: 3221226540 Version: 0.0.0.0 Modules
| |||||||||||||||
| 2356 | "C:\Users\admin\Desktop\Office2007Portable.exe" | C:\Users\admin\Desktop\Office2007Portable.exe | explorer.exe | ||||||||||||
User: admin Company: PerkedleApps Integrity Level: MEDIUM Description: Microsoft Office 2007 Portable Exit code: 0 Version: 0.0.0.0 Modules
| |||||||||||||||
| 2564 | "C:\Users\admin\Desktop\Launch Microsoft PowerPoint.exe" | C:\Users\admin\Desktop\Launch Microsoft PowerPoint.exe | explorer.exe | ||||||||||||
User: admin Company: PerkedleApps Integrity Level: HIGH Description: Microsoft Office PowerPoint 2007 Portable Exit code: 2 Version: 0.0.0.0 Modules
| |||||||||||||||
| 2688 | "C:\Users\admin\Desktop\Launch Microsoft Excel.exe" | C:\Users\admin\Desktop\Launch Microsoft Excel.exe | explorer.exe | ||||||||||||
User: admin Company: PerkedleApps Integrity Level: HIGH Description: Microsoft Office Excel 2007 Portable Exit code: 2 Version: 0.0.0.0 Modules
| |||||||||||||||
| 2808 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\o.rar" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| 3040 | "C:\Windows\system32\NOTEPAD.EXE" C:\Users\admin\Desktop\Office2007Portable.ini | C:\Windows\System32\notepad.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Notepad Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3072 | "C:\Users\admin\Desktop\Launch Microsoft Word.exe" | C:\Users\admin\Desktop\Launch Microsoft Word.exe | — | explorer.exe | |||||||||||
User: admin Company: PerkedleApps Integrity Level: MEDIUM Description: Microsoft Office Word 2007 Portable Exit code: 3221226540 Version: 0.0.0.0 Modules
| |||||||||||||||
| (PID) Process: | (2808) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2808) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip | |||
| (PID) Process: | (2808) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\phacker.zip | |||
| (PID) Process: | (2808) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (2808) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip | |||
| (PID) Process: | (2808) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (2808) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (2808) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (2808) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (2808) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin |
| Operation: | write | Name: | Placement |
Value: 2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2808 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2808.32908\Launch Microsoft Excel.exe | executable | |
MD5:F5F06E05DD0D3F775334719FF755405B | SHA256:A0D534FDB9074C22817C912FF9AC71EF0EA7332FB53E0B296EF0B979D1494F66 | |||
| 2564 | Launch Microsoft PowerPoint.exe | C:\Users\admin\AppData\Local\Temp\nseDF05.tmp | binary | |
MD5:A2C272DD5E04835CF9EB0045EEE1FAF9 | SHA256:C5A7D8F4A4E6403C8DD70D5A4619F402CAB19C6BF8581B76D1F0E03DF8B239B3 | |||
| 2808 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2808.32908\Office2007Portable.exe | executable | |
MD5:62C0AB08B08707DF8BBBA1BE60351AA4 | SHA256:1448404D59F44299D278B2BDD21887B3FF5EA8320E591B2FF7F2676FE2AE3DF3 | |||
| 2688 | Launch Microsoft Excel.exe | C:\Users\admin\AppData\Local\Temp\nsyB7E5.tmp | binary | |
MD5:5E6A01DB5F933D8D1E39DD6892917A58 | SHA256:2B0FF318F6A06655B5309D07736F74FCAB5FBB88C25106C770ED432BA4298FDB | |||
| 2356 | Office2007Portable.exe | C:\Users\admin\AppData\Local\Temp\nsoF721.tmp | binary | |
MD5:8D8985AD5BD91EBBD353D4B39A206C38 | SHA256:28DFEC946FD2A8E2475F7E50FEC68B0A84A95BD381655B19B6567E17B39C9BCF | |||
| 2356 | Office2007Portable.exe | C:\Users\admin\AppData\Local\Temp\nsoF722.tmp\newadvsplash.dll | executable | |
MD5:7EE14DFF57FB6E6C644B318D16768F4C | SHA256:53377D0710F551182EDBAB4150935425948535D11B92BF08A1C2DCF989723BD7 | |||
| 2808 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2808.32908\Office2007Portable.ini | text | |
MD5:13F8C59260BB3E844EAE5AE188872B6A | SHA256:82DE4391C5F4B6DB19CBFD918E1AA5EF1CB784970B66F4030882CF20F07F8EA8 | |||
| 2808 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2808.32908\Launch Microsoft Word.exe | executable | |
MD5:1B13B12ED6851C6B46B1A4BFD4193AC7 | SHA256:62ED82A3DF339C9F8D1FF87BC4ED091B8CB9E355266DEA00A302481D0DC8A552 | |||
| 2808 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2808.32908\Screenshot.png | image | |
MD5:FC71015FC011B441699DE7B68EB5E86F | SHA256:1A7B99D0199E2792C4BA1778C30B8CA1DAC81296AB2F08E7F5D3AE388C2DF82E | |||
| 2808 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2808.32908\Launch Microsoft PowerPoint.exe | executable | |
MD5:DE07DC16F03BA942A45A424B22D13850 | SHA256:6390EFD9385FD690936B3D1AF683227D7E586645998DADD92D39B19B407C37B0 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |