File name:

release.rar

Full analysis: https://app.any.run/tasks/e34f5770-6111-45f4-b385-1d4f33c1f0f7
Verdict: Malicious activity
Analysis date: May 30, 2020, 03:51:55
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

716B085E71C6285F3B1D1DB544DD1730

SHA1:

A2E2953CF894E51045D08BAE5382F5178F75A3EE

SHA256:

4A05003267AB6AC0FA6B498005F8A4CBD72699AA5C414996CBFB9A3A77A03427

SSDEEP:

196608:aM2Beo54plm8qkZv/B/7c7g6LNfNtcDVRa1z5HU1InrYO3j8kKC989vbxitZXNwR:af53Bc3BTGXLxNtwAyij8kKLbxit4d/

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • x96dbg.exe (PID: 688)
      • x32dbg.exe (PID: 2608)
      • x96dbg.exe (PID: 1704)
      • x96dbg.exe (PID: 2960)
      • x96dbg.exe (PID: 1756)
      • x32dbg.exe (PID: 2568)
    • Loads dropped or rewritten executable

      • SearchProtocolHost.exe (PID: 3364)
      • x32dbg.exe (PID: 2608)
      • x32dbg.exe (PID: 2568)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2472)
    • Application launched itself

      • x96dbg.exe (PID: 1704)
  • INFO

    • Dropped object may contain Bitcoin addresses

      • WinRAR.exe (PID: 2472)
    • Manual execution by user

      • x96dbg.exe (PID: 688)
      • x96dbg.exe (PID: 1704)
      • x96dbg.exe (PID: 1756)
      • x32dbg.exe (PID: 2568)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
47
Monitored processes
8
Malicious processes
5
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe searchprotocolhost.exe no specs x96dbg.exe x32dbg.exe x96dbg.exe x96dbg.exe x96dbg.exe x32dbg.exe

Process information

PID
CMD
Path
Indicators
Parent process
688"C:\Users\admin\Desktop\x96dbg.exe" C:\Users\admin\Desktop\x96dbg.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
x64dbg
Exit code:
0
Version:
0.0.2.5
Modules
Images
c:\users\admin\desktop\x96dbg.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
1704"C:\Users\admin\Desktop\x96dbg.exe" C:\Users\admin\Desktop\x96dbg.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
x64dbg
Exit code:
0
Version:
0.0.2.5
Modules
Images
c:\users\admin\desktop\x96dbg.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
1756"C:\Users\admin\Desktop\x96dbg.exe" C:\Users\admin\Desktop\x96dbg.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
x64dbg
Exit code:
0
Version:
0.0.2.5
Modules
Images
c:\users\admin\desktop\x96dbg.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
2472"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\release.rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2568"C:\Users\admin\Desktop\x32\x32dbg.exe" C:\Users\admin\Desktop\x32\x32dbg.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
x64dbg
Exit code:
0
Version:
0.0.2.5
Modules
Images
c:\users\admin\desktop\x32\x32dbg.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\users\admin\desktop\x32\x32bridge.dll
2608"C:\Users\admin\Desktop\x32\x32dbg.exe" C:\Users\admin\Desktop\x32\x32dbg.exe
x96dbg.exe
User:
admin
Integrity Level:
MEDIUM
Description:
x64dbg
Exit code:
0
Version:
0.0.2.5
Modules
Images
c:\users\admin\desktop\x32\x32dbg.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\users\admin\desktop\x32\x32bridge.dll
2960"C:\Users\admin\Desktop\x96dbg.exe" ::installC:\Users\admin\Desktop\x96dbg.exe
x96dbg.exe
User:
admin
Integrity Level:
HIGH
Description:
x64dbg
Exit code:
0
Version:
0.0.2.5
Modules
Images
c:\users\admin\desktop\x96dbg.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
3364"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe4_ Global\UsGthrCtrlFltPipeMssGthrPipe4 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" C:\Windows\System32\SearchProtocolHost.exeSearchIndexer.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Windows Search Protocol Host
Exit code:
0
Version:
7.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\searchprotocolhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
1 030
Read events
983
Write events
47
Delete events
0

Modification events

(PID) Process:(2472) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2472) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2472) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2472) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12F\52C64B7E
Operation:writeName:@C:\Windows\system32\NetworkExplorer.dll,-1
Value:
Network
(PID) Process:(2472) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\release.rar
(PID) Process:(2472) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2472) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2472) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2472) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2472) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12F\52C64B7E
Operation:writeName:@C:\Windows\system32\notepad.exe,-469
Value:
Text Document
Executable files
29
Suspicious files
0
Text files
5
Unknown types
2

Dropped files

PID
Process
Filename
Type
2472WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2472.8002\x32\loaddll.exeexecutable
MD5:
SHA256:
2472WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2472.8002\x32\asmjit.dllexecutable
MD5:D70B3BD199EA6C80D751E8146F493BA6
SHA256:9D578A3DB04DB58DF4BC4F4000E93C8D51449CFD4547AD26B90445501CEC048F
2472WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2472.8002\x32\dbghelp.dllexecutable
MD5:6329180A43F2E000AC991FEF82A2A7E3
SHA256:FCE7AD5C5D85FA547F86605C93F2E52654E5C43E686CEEAF24C28C157E91ED72
2472WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2472.8002\x32\jansson.dllexecutable
MD5:112B0ACFB3EC66861FF569B4F370FCBC
SHA256:EDEA94824751746AB1498E9DBF15BE20E37ECE7533C51ED410EDDE724103CAA4
2472WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2472.8002\x32\DeviceNameResolver.dllexecutable
MD5:A35A5D965A7697242AF24F93F4978E19
SHA256:4FA654D71CE434F364575B642A745BDF4BA94544C762EABAF383449795EDD506
2472WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2472.8002\x32\ldconvert.dllexecutable
MD5:059891FB43C1E7D4135D2ED23D4A81B5
SHA256:BCE19949FD256954B98512C5DA06AFAE1639D6415B195730019533B76334BA2C
2472WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2472.8002\x32\lz4.dllexecutable
MD5:D23F2ACC42F13D4FC0F199CFFFC9A8F8
SHA256:60498530395D935E9BE5E11DDCB8412E97A6D494A250A4D6EE78E1B11E9C5D7E
2472WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2472.8002\x32\symsrv.dllexecutable
MD5:99709608037C776938CAD4304C3C08F3
SHA256:BA9756FD3B5B75E028387DC722CF881FDD991AE21BB9315BD87266FBD01B4F13
2472WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2472.8002\x32\Scylla.dllexecutable
MD5:9CEC18438D3071B57770DB4EB0197EA3
SHA256:C860196803460448941BED5A99C5D77A8B16E8B6D57D7F26A740F52E26ABBAD8
2472WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2472.8002\errordb.txt
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
Process
Message
x96dbg.exe
"C:\Users\admin\Desktop\x96dbg.exe"
x96dbg.exe
"C:\Users\admin\Desktop\x96dbg.exe"
x32dbg.exe
QMetaObject::connectSlotsByName: No matching signal for on_txtUnicode_clicked()
x32dbg.exe
QMetaObject::connectSlotsByName: No matching signal for on_txtUnicode_clicked()¶
x96dbg.exe
"C:\Users\admin\Desktop\x96dbg.exe"
x96dbg.exe
"C:\Users\admin\Desktop\x96dbg.exe"
x96dbg.exe
"C:\Users\admin\Desktop\x96dbg.exe" ::install
x96dbg.exe
"C:\Users\admin\Desktop\x96dbg.exe" ::install
x96dbg.exe
[x96dbg] Command line:
x96dbg.exe
"C:\Users\admin\Desktop\x96dbg.exe"