| File name: | Router Scan v2.60.rar |
| Full analysis: | https://app.any.run/tasks/8281173a-2af6-4604-9d2b-59a6ce90c84f |
| Verdict: | Malicious activity |
| Analysis date: | December 22, 2023, 19:48:17 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| MIME: | application/x-rar |
| File info: | RAR archive data, v5 |
| MD5: | ED86C7FEBEF09CC671E491D376976774 |
| SHA1: | 0703E900C1AEBA91D54A62EB131FB577F12AE869 |
| SHA256: | 3B6D83AFCBDD76A087EAF71CCAE38F95B63ED4882E03E44FAF08939967C3CECC |
| SSDEEP: | 98304:S1zpuniPsJE49Fg59qx5phOZt95nIHJTQu9LCG3e+A0L/MfBNXvkqQUeFGakPLU/:Ss6TlxoLxiPm |
| .rar | | | RAR compressed archive (v5.0) (61.5) |
|---|---|---|
| .rar | | | RAR compressed archive (gen) (38.4) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 120 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Router Scan v2.60.rar" | C:\Program Files\WinRAR\WinRAR.exe | — | explorer.exe | |||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| 1504 | "C:\Users\admin\Desktop\Router Scan v2.60\RouterScan.exe" | C:\Users\admin\Desktop\Router Scan v2.60\RouterScan.exe | explorer.exe | ||||||||||||
User: admin Company: Stas'M Corp. Integrity Level: MEDIUM Description: Router Scan by Stas'M Exit code: 0 Version: 2.6.0.0 Modules
| |||||||||||||||
| (PID) Process: | (120) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (120) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip | |||
| (PID) Process: | (120) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\phacker.zip | |||
| (PID) Process: | (120) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (120) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip | |||
| (PID) Process: | (120) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (120) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (120) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (120) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (120) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin |
| Operation: | write | Name: | Placement |
Value: 2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 120 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa120.999\Router Scan v2.60\Router Scan v2.60\auth_digest.txt | text | |
MD5:C9454C749CE31E591DD65EBF238DE9A2 | SHA256:8A6BAB329F750AAB6C0020C307DC29DB5123D5AE786A0F8497A3493C1AAD68F9 | |||
| 120 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa120.999\Router Scan v2.60\Router Scan v2.60\help\data\manual\window_filter.png | image | |
MD5:82109105D2F4764A79A702497FD421B8 | SHA256:B6EDAC032E00C84CA8B6B0F1BF8CA88FF220F35BAF44670B81448295A4B8AE8B | |||
| 120 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa120.999\Router Scan v2.60\Router Scan v2.60\help\data\manual\menu_table.png | image | |
MD5:8764457F339A125AC67BB57D98961D4A | SHA256:79CBBB622DC431B03D00089BF5D74B290F7A97F8DF3BE504A42CF7C81FC0DC94 | |||
| 120 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa120.999\Router Scan v2.60\Router Scan v2.60\auth_basic.txt | text | |
MD5:CE1FCAE36BF3B8FD8741D81063DACB74 | SHA256:4753DBD9CF9645C76472BC894A10D6836A3D80229AA391F3883665E24348E4F4 | |||
| 120 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa120.999\Router Scan v2.60\Router Scan v2.60\auth_form.txt | text | |
MD5:FDFE557CECE636AF604C126CE7A7B20D | SHA256:37CE9BCAD680A4D6DB2C4E0AA9F84C7A31C61D6A0135FBB702C28BC94A1C71AE | |||
| 120 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa120.999\Router Scan v2.60\Router Scan v2.60\help\data\code.js | text | |
MD5:0E184C0A27519CD3B4EA684FA5F7B12D | SHA256:0D2596B4DBF933CB26CAC77694E36E65A40B9938815A1561F11DCE5056D0DBBB | |||
| 120 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa120.999\Router Scan v2.60\Router Scan v2.60\help\data\manual\window_main.png | image | |
MD5:618FE6F9B14BA25D42609958C00D9ED2 | SHA256:81F08AB3D27A5B6934DF62FB0587A8E5760B2F42EBE90F9C84568327E9A9DE1F | |||
| 120 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa120.999\Router Scan v2.60\Router Scan v2.60\help\data\manual\window_settings_http.png | image | |
MD5:E004D89FA88E7E069C40934086BAB5F2 | SHA256:E23B06E03D796B81739DD9FA84A10844F41C4D9AFF0A1C980A5697A3127543CC | |||
| 120 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa120.999\Router Scan v2.60\Router Scan v2.60\help\data\manual\window_import_append.png | image | |
MD5:3A5E23B0E700630BC9AAD468666F1F51 | SHA256:35ACE82FAEF5C2EDCCF1F99F2DDBEBA98E678A36F3E40D21B9274C85204CA899 | |||
| 120 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa120.999\Router Scan v2.60\Router Scan v2.60\help\data\manual\window_settings_portscan.png | image | |
MD5:6D367E4E3CBE206B73D1A87F60B4793B | SHA256:5CA57B9347B3BF071B045FC95BB0EE3A56C3B2D84B68058E71C7C9535D8397D5 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1504 | RouterScan.exe | 87.121.96.0:80 | — | — | BG | unknown |
1504 | RouterScan.exe | 87.121.96.0:8080 | — | — | BG | unknown |
1504 | RouterScan.exe | 87.121.96.0:1080 | — | — | BG | unknown |
1504 | RouterScan.exe | 87.121.96.0:8000 | — | — | BG | unknown |
1504 | RouterScan.exe | 87.121.96.1:80 | — | — | BG | unknown |
1504 | RouterScan.exe | 87.121.96.1:8080 | — | — | BG | unknown |
1504 | RouterScan.exe | 87.121.96.1:1080 | — | — | BG | unknown |