| File name: | Router Scan v2.60.rar |
| Full analysis: | https://app.any.run/tasks/8281173a-2af6-4604-9d2b-59a6ce90c84f |
| Verdict: | Malicious activity |
| Analysis date: | December 22, 2023, 19:48:17 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| MIME: | application/x-rar |
| File info: | RAR archive data, v5 |
| MD5: | ED86C7FEBEF09CC671E491D376976774 |
| SHA1: | 0703E900C1AEBA91D54A62EB131FB577F12AE869 |
| SHA256: | 3B6D83AFCBDD76A087EAF71CCAE38F95B63ED4882E03E44FAF08939967C3CECC |
| SSDEEP: | 98304:S1zpuniPsJE49Fg59qx5phOZt95nIHJTQu9LCG3e+A0L/MfBNXvkqQUeFGakPLU/:Ss6TlxoLxiPm |
| .rar | | | RAR compressed archive (v5.0) (61.5) |
|---|---|---|
| .rar | | | RAR compressed archive (gen) (38.4) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 120 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Router Scan v2.60.rar" | C:\Program Files\WinRAR\WinRAR.exe | — | explorer.exe | |||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| 1504 | "C:\Users\admin\Desktop\Router Scan v2.60\RouterScan.exe" | C:\Users\admin\Desktop\Router Scan v2.60\RouterScan.exe | explorer.exe | ||||||||||||
User: admin Company: Stas'M Corp. Integrity Level: MEDIUM Description: Router Scan by Stas'M Exit code: 0 Version: 2.6.0.0 Modules
| |||||||||||||||
| (PID) Process: | (120) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (120) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip | |||
| (PID) Process: | (120) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\phacker.zip | |||
| (PID) Process: | (120) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (120) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip | |||
| (PID) Process: | (120) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (120) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (120) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (120) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (120) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin |
| Operation: | write | Name: | Placement |
Value: 2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 120 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa120.999\Router Scan v2.60\Router Scan v2.60\help\data\code.js | text | |
MD5:0E184C0A27519CD3B4EA684FA5F7B12D | SHA256:0D2596B4DBF933CB26CAC77694E36E65A40B9938815A1561F11DCE5056D0DBBB | |||
| 120 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa120.999\Router Scan v2.60\Router Scan v2.60\auth_basic.txt | text | |
MD5:CE1FCAE36BF3B8FD8741D81063DACB74 | SHA256:4753DBD9CF9645C76472BC894A10D6836A3D80229AA391F3883665E24348E4F4 | |||
| 120 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa120.999\Router Scan v2.60\Router Scan v2.60\help\data\code.css | text | |
MD5:EB21D6145A7B341CA198228B2C9930A8 | SHA256:FAB0FD6EEDFD3F618BC3C9522F259F51BF1FF09181A1D482FB965829F2387018 | |||
| 120 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa120.999\Router Scan v2.60\Router Scan v2.60\auth_digest.txt | text | |
MD5:C9454C749CE31E591DD65EBF238DE9A2 | SHA256:8A6BAB329F750AAB6C0020C307DC29DB5123D5AE786A0F8497A3493C1AAD68F9 | |||
| 120 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa120.999\Router Scan v2.60\Router Scan v2.60\config.ini | ini | |
MD5:326DB78134DE35A3382FA035B89B678B | SHA256:B937896C8B116F656A0DED724E9F64A5214625BC37631AD062356F5159DEC883 | |||
| 120 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa120.999\Router Scan v2.60\Router Scan v2.60\help\data\manual\window_settings_tweaks.png | image | |
MD5:4FB7C2CF547C26B19B7A23625AF31BB5 | SHA256:98E78BEE484433721613CBD145A73C1FCB61D05B739E46A4F115AE76EA47BE28 | |||
| 120 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa120.999\Router Scan v2.60\Router Scan v2.60\help\data\manual\window_exclusions.png | image | |
MD5:445458767080CAFFE78E3485FBE073D0 | SHA256:017130EE877058E66FE5488E624B46A96516DF248F8A34CE3BB5B437EC2C2F7D | |||
| 120 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa120.999\Router Scan v2.60\Router Scan v2.60\help\data\manual\window_settings_http.png | image | |
MD5:E004D89FA88E7E069C40934086BAB5F2 | SHA256:E23B06E03D796B81739DD9FA84A10844F41C4D9AFF0A1C980A5697A3127543CC | |||
| 120 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa120.999\Router Scan v2.60\Router Scan v2.60\help\data\manual\window_import_clear.png | image | |
MD5:68349DFB2D1FE56AEA55945CFAFB5E42 | SHA256:E0E83DE8081C9E02E19A57D5C6B40C6088BDE82F9022577F3781A8A4030BC3BF | |||
| 120 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa120.999\Router Scan v2.60\Router Scan v2.60\help\data\manual\window_import_append.png | image | |
MD5:3A5E23B0E700630BC9AAD468666F1F51 | SHA256:35ACE82FAEF5C2EDCCF1F99F2DDBEBA98E678A36F3E40D21B9274C85204CA899 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1504 | RouterScan.exe | 87.121.96.0:80 | — | — | BG | unknown |
1504 | RouterScan.exe | 87.121.96.0:8080 | — | — | BG | unknown |
1504 | RouterScan.exe | 87.121.96.0:1080 | — | — | BG | unknown |
1504 | RouterScan.exe | 87.121.96.0:8000 | — | — | BG | unknown |
1504 | RouterScan.exe | 87.121.96.1:80 | — | — | BG | unknown |
1504 | RouterScan.exe | 87.121.96.1:8080 | — | — | BG | unknown |
1504 | RouterScan.exe | 87.121.96.1:1080 | — | — | BG | unknown |