File name:

Mernis Data [2015] (1).rar

Full analysis: https://app.any.run/tasks/2b976879-791b-4d3c-ba54-8835f2d3d940
Verdict: Malicious activity
Analysis date: August 29, 2021, 12:57:22
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

0DE21D6ED1EE08C5CA683F9A38A3B256

SHA1:

7109FA612BA43AC4AEF4B648D495EF494E31743F

SHA256:

451603AE01ABAB149CEDB0BEE81EEBB14E4BF6D05294BD1F025BD909FC4396C1

SSDEEP:

98304:JbRjIFV6fglFv4NS57HfqrlLGIoTPtsVq:JdVfglFwNSxC5LGrTPtX

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops executable file immediately after starts

      • WinRAR.exe (PID: 3120)
    • Application was dropped or rewritten from another process

      • start.exe (PID: 2264)
      • full.exe (PID: 1612)
      • full.exe (PID: 2668)
      • mysqld.exe (PID: 1264)
      • full.exe (PID: 2532)
      • start.exe (PID: 1180)
      • mysqld.exe (PID: 2900)
      • full.exe (PID: 1232)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3120)
    • Reads the computer name

      • WinRAR.exe (PID: 2912)
      • WinRAR.exe (PID: 3120)
      • full.exe (PID: 1612)
      • mysqld.exe (PID: 1264)
      • full.exe (PID: 2668)
      • full.exe (PID: 2532)
      • full.exe (PID: 1232)
      • mysqld.exe (PID: 2900)
    • Checks supported languages

      • WinRAR.exe (PID: 2912)
      • full.exe (PID: 1612)
      • full.exe (PID: 2668)
      • WinRAR.exe (PID: 3120)
      • start.exe (PID: 2264)
      • mysqld.exe (PID: 1264)
      • full.exe (PID: 2532)
      • mysqld.exe (PID: 2900)
      • start.exe (PID: 1180)
      • full.exe (PID: 1232)
  • INFO

    • Manual execution by user

      • WinRAR.exe (PID: 3120)
      • start.exe (PID: 2264)
      • full.exe (PID: 1612)
      • full.exe (PID: 2668)
      • full.exe (PID: 2532)
      • start.exe (PID: 1180)
      • full.exe (PID: 1232)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
59
Monitored processes
10
Malicious processes
5
Suspicious processes
2

Behavior graph

Click at the process to see the details
start winrar.exe no specs winrar.exe start.exe no specs mysqld.exe no specs full.exe full.exe no specs full.exe start.exe mysqld.exe no specs full.exe

Process information

PID
CMD
Path
Indicators
Parent process
1180"C:\Users\admin\Desktop\Mernis Data [2015] (1)\start.exe" C:\Users\admin\Desktop\Mernis Data [2015] (1)\start.exe
Explorer.EXE
User:
admin
Company:
MiKhatri
Integrity Level:
HIGH
Exit code:
0
Version:
1.00
Modules
Images
c:\users\admin\desktop\mernis data [2015] (1)\start.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvbvm60.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
1232"C:\Users\admin\Desktop\Mernis Data [2015] (1)\full.exe" C:\Users\admin\Desktop\Mernis Data [2015] (1)\full.exe
Explorer.EXE
User:
admin
Integrity Level:
HIGH
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\mernis data [2015] (1)\full.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1264"C:\Users\admin\Desktop\Mernis Data [2015] (1)\bin\mysqld.exe" --query_cache_size=16M --max_allowed_packet=1G --innodb_data_file_path=ibdata1:1M:autoextendC:\Users\admin\Desktop\Mernis Data [2015] (1)\bin\mysqld.exestart.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Version:
5.5.13.0
Modules
Images
c:\users\admin\desktop\mernis data [2015] (1)\bin\mysqld.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\user32.dll
1612"C:\Users\admin\Desktop\Mernis Data [2015] (1)\full.exe" C:\Users\admin\Desktop\Mernis Data [2015] (1)\full.exe
Explorer.EXE
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\mernis data [2015] (1)\full.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2264"C:\Users\admin\Desktop\Mernis Data [2015] (1)\start.exe" C:\Users\admin\Desktop\Mernis Data [2015] (1)\start.exeExplorer.EXE
User:
admin
Company:
MiKhatri
Integrity Level:
MEDIUM
Exit code:
0
Version:
1.00
Modules
Images
c:\users\admin\desktop\mernis data [2015] (1)\start.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvbvm60.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\msvcrt.dll
2532"C:\Users\admin\Desktop\Mernis Data [2015] (1)\full.exe" C:\Users\admin\Desktop\Mernis Data [2015] (1)\full.exe
Explorer.EXE
User:
admin
Integrity Level:
HIGH
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\mernis data [2015] (1)\full.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2668"C:\Users\admin\Desktop\Mernis Data [2015] (1)\full.exe" C:\Users\admin\Desktop\Mernis Data [2015] (1)\full.exeExplorer.EXE
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\mernis data [2015] (1)\full.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2900"C:\Users\admin\Desktop\Mernis Data [2015] (1)\bin\mysqld.exe" --query_cache_size=16M --max_allowed_packet=1G --innodb_data_file_path=ibdata1:1M:autoextendC:\Users\admin\Desktop\Mernis Data [2015] (1)\bin\mysqld.exestart.exe
User:
admin
Integrity Level:
HIGH
Exit code:
1
Version:
5.5.13.0
Modules
Images
c:\users\admin\desktop\mernis data [2015] (1)\bin\mysqld.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\user32.dll
2912"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Mernis Data [2015] (1).rar"C:\Program Files\WinRAR\WinRAR.exeExplorer.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3120"C:\Program Files\WinRAR\WinRAR.exe" x -iext -ow -ver -- "C:\Users\admin\Desktop\Mernis Data [2015] (1).rar" "C:\Users\admin\Desktop\Mernis Data [2015] (1)\"C:\Program Files\WinRAR\WinRAR.exe
Explorer.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
Total events
2 579
Read events
2 497
Write events
82
Delete events
0

Modification events

(PID) Process:(2912) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2912) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2912) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\171\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2912) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Mernis Data [2015] (1).rar
(PID) Process:(2912) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2912) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2912) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2912) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2912) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\ArcColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2912) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\ArcColumnWidths
Operation:writeName:size
Value:
80
Executable files
5
Suspicious files
31
Text files
61
Unknown types
54

Dropped files

PID
Process
Filename
Type
3120WinRAR.exeC:\Users\admin\Desktop\Mernis Data [2015] (1)\my.initext
MD5:
SHA256:
3120WinRAR.exeC:\Users\admin\Desktop\Mernis Data [2015] (1)\stop.exeexecutable
MD5:28E8151020FA9BD48F8FD799825C1510
SHA256:17014A035EC0DB9BB8652FA0ECD024456208885DF53CC3E8ACDD62ED13DEFF98
3120WinRAR.exeC:\Users\admin\Desktop\Mernis Data [2015] (1)\share\charsets\greek.xmlxml
MD5:43784535EB3E5C2D6481DCD16D0931F1
SHA256:16A97D6C557685B699596244AA506F711FFF3F3A345AFEBDDCE770484FA6B203
3120WinRAR.exeC:\Users\admin\Desktop\Mernis Data [2015] (1)\share\charsets\cp1250.xmlxml
MD5:8980E38E5C73D363167924B82F9B6307
SHA256:D06BC18DA702F1B8FE08C75C27579962580B81647E63651D354AF40551066A6A
3120WinRAR.exeC:\Users\admin\Desktop\Mernis Data [2015] (1)\share\charsets\cp1259.conftext
MD5:CDF3B62F5A62E7F09AF25E4560139DBF
SHA256:D5EE955341AE5EF1008058161E636CD6CCBAF3D4694BFD6708CBF3B212F1534D
3120WinRAR.exeC:\Users\admin\Desktop\Mernis Data [2015] (1)\share\charsets\cp1256.xmlxml
MD5:91A747DDEFC0705F9CF187EF7AEBEDBF
SHA256:6C27DF1E06304C8BBBB923D803E0B9374B80D24F07176DF89C2156F803993E10
3120WinRAR.exeC:\Users\admin\Desktop\Mernis Data [2015] (1)\share\charsets\cp852.xmlxml
MD5:E3A297DB9DEE58CDCCC53F0F33A705D6
SHA256:39EB33C14B41BD906FA2561DED53B85C37055AA8B6F699ECF894E1E414C63E4F
3120WinRAR.exeC:\Users\admin\Desktop\Mernis Data [2015] (1)\share\charsets\cp866.xmlxml
MD5:E6FA1450652D8CEA162A480B486B8A17
SHA256:AC6484FA54D3C8CB31DBF2F2F8CDD21357BBAD9AAA956A4CB1BC0C9D17B0941C
3120WinRAR.exeC:\Users\admin\Desktop\Mernis Data [2015] (1)\share\charsets\latin1.xmlxml
MD5:ACE04E7F96D7F9CC708BB29A8BDF7C96
SHA256:3C46FC7008255C9FCB4AD7AF18FA1995BCFFF596D3F5BDC330334E09BACECFB6
3120WinRAR.exeC:\Users\admin\Desktop\Mernis Data [2015] (1)\share\charsets\latin2.xmlxml
MD5:1B3D66DB05887A77750EAD396620C769
SHA256:D5328B3BA3B8B2BED5636A39EDACE5D006AD75CDE36DA59114902F4D86DD9B19
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
6
DNS requests
1
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1612
full.exe
20.56.176.205:8808
US
unknown
20.56.176.205:8808
US
unknown
1612
full.exe
20.56.176.205:6821
US
unknown

DNS requests

Domain
IP
Reputation
dns.msftncsi.com
  • 131.107.255.255
shared

Threats

No threats detected
No debug info