File name:

KPortScan 3.0.rar

Full analysis: https://app.any.run/tasks/8d351d59-3b9d-4dad-a27c-455c21aba287
Verdict: Malicious activity
Analysis date: June 12, 2020, 15:53:53
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v4, os: Win32
MD5:

04B6966F8CA0920E9739B5543EE78B0B

SHA1:

E4D14FF6E546827EBCB18C502BF2A46F75D1B32D

SHA256:

3C06B17527E56F49BDB09CD00C6FBE44963F6DB1E2CA65A31FAE7671C8C5B732

SSDEEP:

98304:KG/DoT2s3IXaIA8LGZs70fQ/tTa54jlYl7HmCWBLphI+6Y0xrbF:KG/Do38hZ5FMQlYrWzyfRF

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • KPortScan3.exe (PID: 2868)
      • WerFault.exe (PID: 3556)
      • KPortScan3.exe (PID: 2248)
    • Application was dropped or rewritten from another process

      • KPortScan3.exe (PID: 2868)
      • KPortScan3.exe (PID: 2248)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3020)
  • INFO

    • Dropped object may contain Bitcoin addresses

      • WinRAR.exe (PID: 3020)
    • Manual execution by user

      • KPortScan3.exe (PID: 2868)
      • KPortScan3.exe (PID: 2248)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v-4.x) (58.3)
.rar | RAR compressed archive (gen) (41.6)

EXIF

ZIP

CompressedSize: 39
UncompressedSize: -
OperatingSystem: Win32
ModifyDate: 2013:11:25 00:39:04
PackingMethod: Stored
ArchivedFileName: KPortScan 3.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
38
Monitored processes
4
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe kportscan3.exe werfault.exe no specs kportscan3.exe

Process information

PID
CMD
Path
Indicators
Parent process
2248"C:\Users\admin\Desktop\KPortScan 3.0\KPortScan3.exe" C:\Users\admin\Desktop\KPortScan 3.0\KPortScan3.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\kportscan 3.0\kportscan3.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\desktop\kportscan 3.0\qtgui4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
2868"C:\Users\admin\Desktop\KPortScan 3.0\KPortScan3.exe" C:\Users\admin\Desktop\KPortScan 3.0\KPortScan3.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221225477
Modules
Images
c:\users\admin\desktop\kportscan 3.0\kportscan3.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\desktop\kportscan 3.0\qtgui4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
3020"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\KPortScan 3.0.rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3556C:\Windows\system32\WerFault.exe -u -p 2868 -s 624C:\Windows\system32\WerFault.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Problem Reporting
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\werfault.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
439
Read events
429
Write events
10
Delete events
0

Modification events

(PID) Process:(3020) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3020) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3020) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3020) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12F\52C64B7E
Operation:writeName:@C:\Windows\system32\NetworkExplorer.dll,-1
Value:
Network
(PID) Process:(3020) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\KPortScan 3.0.rar
(PID) Process:(3020) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3020) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3020) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3020) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3020) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface
Operation:writeName:ShowPassword
Value:
0
Executable files
4
Suspicious files
1
Text files
0
Unknown types
1

Dropped files

PID
Process
Filename
Type
3556WerFault.exeC:\Users\admin\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_KPortScan3.exe_1db9f0211b157a683ce96c7a51baef47c2528258_0df084de\Report.werbinary
MD5:
SHA256:
3556WerFault.exeC:\Users\admin\AppData\Local\CrashDumps\KPortScan3.exe.2868.dmpdmp
MD5:
SHA256:
3020WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb3020.9205\KPortScan 3.0\KPortScan3.exeexecutable
MD5:C0A8AF17A2912A08A20D65FE85191C28
SHA256:080C6108C3BD0F8A43D5647DB36DC434032842339F0BA38AD1FF62F72999C4E5
3020WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb3020.9205\KPortScan 3.0\QtNetwork4.dllexecutable
MD5:5C6AFAE60414546CEF0A9B759DA93912
SHA256:99757EC661FD7DE3B22FB641F25CF1565AAE13DAF8D31C6686C6C7CBD2BE6FC9
3020WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb3020.9205\KPortScan 3.0\QtCore4.dllexecutable
MD5:438717377B9DF0F53F283C9E4AA722CC
SHA256:A679CF46E128D028DE22FB9ED8432E5107E53F8E7E6FB7F5E169B3EEAB8F000A
3020WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb3020.9205\KPortScan 3.0\QtGui4.dllexecutable
MD5:37957FACC9AFBDFBD119C8372C9CF0E3
SHA256:BF52FEC00B4F640D07BEA3850096CC77983FCA518BBEC8122997B7CA561205F1
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
Process
Message
KPortScan3.exe
QMetaObject::connectSlotsByName: No matching signal for on_result(QString,int,bool)
KPortScan3.exe
QMetaObject::connectSlotsByName: No matching signal for on_finished()
KPortScan3.exe
QMetaObject::connectSlotsByName: No matching signal for on_scanFinished()
KPortScan3.exe
QMetaObject::connectSlotsByName: No matching signal for on_timeout()
KPortScan3.exe
QMetaObject::connectSlotsByName: No matching signal for on_stop()
KPortScan3.exe
QMetaObject::connectSlotsByName: No matching signal for on_loadFinished(QNetworkReply*)
KPortScan3.exe
QMetaObject::connectSlotsByName: No matching signal for on_scanDiapFinished()
KPortScan3.exe
QMetaObject::connectSlotsByName: No matching signal for on_scanFinished()
KPortScan3.exe
QMetaObject::connectSlotsByName: No matching signal for on_result(QStri냦ы쿅䃑ǖ끚ыQMetaObject::connectSlotsByName: No matching signal for on_timeout()
KPortScan3.exe
QMetaObject::connectSlotsByName: No matching signal for on_timeout()