| File name: | Router Scan v2.60.rar |
| Full analysis: | https://app.any.run/tasks/8281173a-2af6-4604-9d2b-59a6ce90c84f |
| Verdict: | Malicious activity |
| Analysis date: | December 22, 2023, 19:48:17 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| MIME: | application/x-rar |
| File info: | RAR archive data, v5 |
| MD5: | ED86C7FEBEF09CC671E491D376976774 |
| SHA1: | 0703E900C1AEBA91D54A62EB131FB577F12AE869 |
| SHA256: | 3B6D83AFCBDD76A087EAF71CCAE38F95B63ED4882E03E44FAF08939967C3CECC |
| SSDEEP: | 98304:S1zpuniPsJE49Fg59qx5phOZt95nIHJTQu9LCG3e+A0L/MfBNXvkqQUeFGakPLU/:Ss6TlxoLxiPm |
| .rar | | | RAR compressed archive (v5.0) (61.5) |
|---|---|---|
| .rar | | | RAR compressed archive (gen) (38.4) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 120 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Router Scan v2.60.rar" | C:\Program Files\WinRAR\WinRAR.exe | — | explorer.exe | |||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| 1504 | "C:\Users\admin\Desktop\Router Scan v2.60\RouterScan.exe" | C:\Users\admin\Desktop\Router Scan v2.60\RouterScan.exe | explorer.exe | ||||||||||||
User: admin Company: Stas'M Corp. Integrity Level: MEDIUM Description: Router Scan by Stas'M Exit code: 0 Version: 2.6.0.0 Modules
| |||||||||||||||
| (PID) Process: | (120) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (120) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip | |||
| (PID) Process: | (120) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\phacker.zip | |||
| (PID) Process: | (120) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (120) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip | |||
| (PID) Process: | (120) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (120) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (120) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (120) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (120) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin |
| Operation: | write | Name: | Placement |
Value: 2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 120 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa120.999\Router Scan v2.60\Router Scan v2.60\auth_basic.txt | text | |
MD5:CE1FCAE36BF3B8FD8741D81063DACB74 | SHA256:4753DBD9CF9645C76472BC894A10D6836A3D80229AA391F3883665E24348E4F4 | |||
| 120 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa120.999\Router Scan v2.60\Router Scan v2.60\help\data\manual\window_exclusions.png | image | |
MD5:445458767080CAFFE78E3485FBE073D0 | SHA256:017130EE877058E66FE5488E624B46A96516DF248F8A34CE3BB5B437EC2C2F7D | |||
| 120 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa120.999\Router Scan v2.60\Router Scan v2.60\help\data\code.css | text | |
MD5:EB21D6145A7B341CA198228B2C9930A8 | SHA256:FAB0FD6EEDFD3F618BC3C9522F259F51BF1FF09181A1D482FB965829F2387018 | |||
| 120 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa120.999\Router Scan v2.60\Router Scan v2.60\config.ini | ini | |
MD5:326DB78134DE35A3382FA035B89B678B | SHA256:B937896C8B116F656A0DED724E9F64A5214625BC37631AD062356F5159DEC883 | |||
| 120 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa120.999\Router Scan v2.60\Router Scan v2.60\help\data\manual\menu_main.png | image | |
MD5:6EA94AA073E42F7E79885831DA173462 | SHA256:25FE2D89C8D99B9D8B6D3FFA9CA095A49283CA4A9E23FA9FAC34C755CAA66819 | |||
| 120 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa120.999\Router Scan v2.60\Router Scan v2.60\help\data\manual\menu_table.png | image | |
MD5:8764457F339A125AC67BB57D98961D4A | SHA256:79CBBB622DC431B03D00089BF5D74B290F7A97F8DF3BE504A42CF7C81FC0DC94 | |||
| 120 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa120.999\Router Scan v2.60\Router Scan v2.60\help\data\manual\window_editrange.png | image | |
MD5:DD062442962F063760A0DB3BC8563E6C | SHA256:7EC5DC7B4B21627C9523EE8D448CA8D062B6E48ED3AEB30217DFAA6D507C9A96 | |||
| 120 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa120.999\Router Scan v2.60\Router Scan v2.60\help\data\manual\window_columns.png | image | |
MD5:8E40085DA25C761B7E6D6C8665BFE167 | SHA256:27EC3B2CF19A288129A4010D2381294271896049675E31E59A8790B508B6DA89 | |||
| 120 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa120.999\Router Scan v2.60\Router Scan v2.60\auth_digest.txt | text | |
MD5:C9454C749CE31E591DD65EBF238DE9A2 | SHA256:8A6BAB329F750AAB6C0020C307DC29DB5123D5AE786A0F8497A3493C1AAD68F9 | |||
| 120 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa120.999\Router Scan v2.60\Router Scan v2.60\help\data\manual\window_filter.png | image | |
MD5:82109105D2F4764A79A702497FD421B8 | SHA256:B6EDAC032E00C84CA8B6B0F1BF8CA88FF220F35BAF44670B81448295A4B8AE8B | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1504 | RouterScan.exe | 87.121.96.0:80 | — | — | BG | unknown |
1504 | RouterScan.exe | 87.121.96.0:8080 | — | — | BG | unknown |
1504 | RouterScan.exe | 87.121.96.0:1080 | — | — | BG | unknown |
1504 | RouterScan.exe | 87.121.96.0:8000 | — | — | BG | unknown |
1504 | RouterScan.exe | 87.121.96.1:80 | — | — | BG | unknown |
1504 | RouterScan.exe | 87.121.96.1:8080 | — | — | BG | unknown |
1504 | RouterScan.exe | 87.121.96.1:1080 | — | — | BG | unknown |