| File name: | Router Scan v2.60.rar |
| Full analysis: | https://app.any.run/tasks/513f3212-b695-4575-92f0-0c5cf122cbda |
| Verdict: | Malicious activity |
| Analysis date: | December 22, 2023, 20:04:45 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| MIME: | application/x-rar |
| File info: | RAR archive data, v5 |
| MD5: | ED86C7FEBEF09CC671E491D376976774 |
| SHA1: | 0703E900C1AEBA91D54A62EB131FB577F12AE869 |
| SHA256: | 3B6D83AFCBDD76A087EAF71CCAE38F95B63ED4882E03E44FAF08939967C3CECC |
| SSDEEP: | 98304:S1zpuniPsJE49Fg59qx5phOZt95nIHJTQu9LCG3e+A0L/MfBNXvkqQUeFGakPLU/:Ss6TlxoLxiPm |
| .rar | | | RAR compressed archive (v5.0) (61.5) |
|---|---|---|
| .rar | | | RAR compressed archive (gen) (38.4) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 128 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Router Scan v2.60.rar" | C:\Program Files\WinRAR\WinRAR.exe | — | explorer.exe | |||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| 1808 | "C:\Users\admin\Desktop\Router Scan v2.60\Router Scan v2.60\RouterScan.exe" | C:\Users\admin\Desktop\Router Scan v2.60\Router Scan v2.60\RouterScan.exe | explorer.exe | ||||||||||||
User: admin Company: Stas'M Corp. Integrity Level: MEDIUM Description: Router Scan by Stas'M Exit code: 0 Version: 2.6.0.0 Modules
| |||||||||||||||
| (PID) Process: | (128) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (128) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip | |||
| (PID) Process: | (128) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\phacker.zip | |||
| (PID) Process: | (128) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (128) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip | |||
| (PID) Process: | (128) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (128) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (128) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (128) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (128) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin |
| Operation: | write | Name: | Placement |
Value: 2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 128 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa128.2705\Router Scan v2.60\Router Scan v2.60\config.ini | ini | |
MD5:326DB78134DE35A3382FA035B89B678B | SHA256:B937896C8B116F656A0DED724E9F64A5214625BC37631AD062356F5159DEC883 | |||
| 128 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa128.2705\Router Scan v2.60\Router Scan v2.60\auth_form.txt | text | |
MD5:FDFE557CECE636AF604C126CE7A7B20D | SHA256:37CE9BCAD680A4D6DB2C4E0AA9F84C7A31C61D6A0135FBB702C28BC94A1C71AE | |||
| 128 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa128.2705\Router Scan v2.60\Router Scan v2.60\help\data\code.js | text | |
MD5:0E184C0A27519CD3B4EA684FA5F7B12D | SHA256:0D2596B4DBF933CB26CAC77694E36E65A40B9938815A1561F11DCE5056D0DBBB | |||
| 128 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa128.2705\Router Scan v2.60\Router Scan v2.60\help\data\manual\window_columns.png | image | |
MD5:8E40085DA25C761B7E6D6C8665BFE167 | SHA256:27EC3B2CF19A288129A4010D2381294271896049675E31E59A8790B508B6DA89 | |||
| 128 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa128.2705\Router Scan v2.60\Router Scan v2.60\help\data\manual\menu_main.png | image | |
MD5:6EA94AA073E42F7E79885831DA173462 | SHA256:25FE2D89C8D99B9D8B6D3FFA9CA095A49283CA4A9E23FA9FAC34C755CAA66819 | |||
| 128 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa128.2705\Router Scan v2.60\Router Scan v2.60\auth_digest.txt | text | |
MD5:C9454C749CE31E591DD65EBF238DE9A2 | SHA256:8A6BAB329F750AAB6C0020C307DC29DB5123D5AE786A0F8497A3493C1AAD68F9 | |||
| 128 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa128.2705\Router Scan v2.60\Router Scan v2.60\help\data\manual\window_import_append.png | image | |
MD5:3A5E23B0E700630BC9AAD468666F1F51 | SHA256:35ACE82FAEF5C2EDCCF1F99F2DDBEBA98E678A36F3E40D21B9274C85204CA899 | |||
| 128 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa128.2705\Router Scan v2.60\Router Scan v2.60\help\data\manual\window_import_clear.png | image | |
MD5:68349DFB2D1FE56AEA55945CFAFB5E42 | SHA256:E0E83DE8081C9E02E19A57D5C6B40C6088BDE82F9022577F3781A8A4030BC3BF | |||
| 128 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa128.2705\Router Scan v2.60\Router Scan v2.60\help\data\manual\window_settings_portscan.png | image | |
MD5:6D367E4E3CBE206B73D1A87F60B4793B | SHA256:5CA57B9347B3BF071B045FC95BB0EE3A56C3B2D84B68058E71C7C9535D8397D5 | |||
| 128 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa128.2705\Router Scan v2.60\Router Scan v2.60\help\data\manual\window_settings_http.png | image | |
MD5:E004D89FA88E7E069C40934086BAB5F2 | SHA256:E23B06E03D796B81739DD9FA84A10844F41C4D9AFF0A1C980A5697A3127543CC | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
1808 | RouterScan.exe | 28.28.0.0:80 | — | DNIC-AS-00749 | US | unknown |
1808 | RouterScan.exe | 28.28.0.0:8080 | — | DNIC-AS-00749 | US | unknown |
1808 | RouterScan.exe | 28.28.0.0:1080 | — | DNIC-AS-00749 | US | unknown |
1808 | RouterScan.exe | 28.28.0.0:8000 | — | DNIC-AS-00749 | US | unknown |
1808 | RouterScan.exe | 28.28.0.1:80 | — | DNIC-AS-00749 | US | unknown |
1808 | RouterScan.exe | 28.28.0.1:8080 | — | DNIC-AS-00749 | US | unknown |
1808 | RouterScan.exe | 28.28.0.1:1080 | — | DNIC-AS-00749 | US | unknown |