File name:

Air.Explorer.Pro.v2.5.5_2.rar

Full analysis: https://app.any.run/tasks/107b05ad-a843-41d6-8d17-364202172a1d
Verdict: Malicious activity
Analysis date: July 26, 2019, 09:00:39
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

D0AAFD946E0D89C20FDAB3C540C0DB0A

SHA1:

B180FCA1FADE9793A669D475C83633CAE8E8F378

SHA256:

4B64BEF0A51DFC5291B4AA679556205F457E4C11C2B7D5C7543A5E6413F4F1A2

SSDEEP:

98304:teB3/m+iahlP3Woqy5VhZyUT8TlTZK897l8J:c3/dia7Grkyp58J

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • dec.exe (PID: 936)
      • ns5E0D.tmp (PID: 1316)
      • ns5C66.tmp (PID: 1492)
      • hiru.exe (PID: 576)
      • Air.Explorer.Pro.v2.5.5.exe (PID: 936)
      • hiru.exe (PID: 2260)
      • AirExplorer.exe (PID: 3480)
      • Air.Explorer.Pro.v2.5.5.exe (PID: 3640)
      • Air.Explorer.Pro.v2.5.5.exe (PID: 3996)
      • Air.Explorer.Pro.v2.5.5.exe (PID: 3160)
      • nsB5A2.tmp (PID: 2232)
      • Air.Explorer.Pro.v2.5.5.exe (PID: 3064)
    • Loads dropped or rewritten executable

      • Air.Explorer.Pro.v2.5.5.exe (PID: 3064)
      • hiru.exe (PID: 2260)
      • AirExplorer.exe (PID: 3480)
      • Air.Explorer.Pro.v2.5.5.exe (PID: 3996)
  • SUSPICIOUS

    • Starts CMD.EXE for commands execution

      • Air.Explorer.Pro.v2.5.5.exe (PID: 3064)
    • Uses IPCONFIG.EXE to discover IP address

      • ns5C66.tmp (PID: 1492)
      • nsB5A2.tmp (PID: 2232)
    • Executable content was dropped or overwritten

      • dec.exe (PID: 936)
      • hiru.exe (PID: 576)
      • WinRAR.exe (PID: 3392)
      • hiru.exe (PID: 2260)
      • Air.Explorer.Pro.v2.5.5.exe (PID: 3996)
      • Air.Explorer.Pro.v2.5.5.exe (PID: 3064)
    • Creates files in the program directory

      • hiru.exe (PID: 2260)
      • Air.Explorer.Pro.v2.5.5.exe (PID: 3064)
    • Creates a software uninstall entry

      • hiru.exe (PID: 2260)
      • Air.Explorer.Pro.v2.5.5.exe (PID: 3996)
      • Air.Explorer.Pro.v2.5.5.exe (PID: 3064)
    • Changes IE settings (feature browser emulation)

      • AirExplorer.exe (PID: 3480)
    • Reads internet explorer settings

      • AirExplorer.exe (PID: 3480)
    • Creates files in the user directory

      • AirExplorer.exe (PID: 3480)
      • Air.Explorer.Pro.v2.5.5.exe (PID: 3064)
    • Starts application with an unusual extension

      • Air.Explorer.Pro.v2.5.5.exe (PID: 3996)
      • Air.Explorer.Pro.v2.5.5.exe (PID: 3064)
  • INFO

    • Manual execution by user

      • Air.Explorer.Pro.v2.5.5.exe (PID: 936)
      • Air.Explorer.Pro.v2.5.5.exe (PID: 3064)
      • cmd.exe (PID: 3628)
    • Dropped object may contain Bitcoin addresses

      • Air.Explorer.Pro.v2.5.5.exe (PID: 3064)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
62
Monitored processes
18
Malicious processes
7
Suspicious processes
0

Behavior graph

Click at the process to see the details
start drop and start drop and start drop and start drop and start winrar.exe air.explorer.pro.v2.5.5.exe no specs air.explorer.pro.v2.5.5.exe ns5c66.tmp no specs ipconfig.exe no specs ns5e0d.tmp no specs dec.exe cmd.exe no specs hiru.exe hiru.exe airexplorer.exe no specs cmd.exe no specs mode.com no specs air.explorer.pro.v2.5.5.exe no specs air.explorer.pro.v2.5.5.exe no specs air.explorer.pro.v2.5.5.exe nsb5a2.tmp no specs ipconfig.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
324ipconfig /flushdnsC:\Windows\system32\ipconfig.exens5C66.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
IP Configuration Utility
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ipconfig.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\ws2_32.dll
576C:\Users\admin\AppData\Local\Temp\nsb36FB.tmp\hiru.exe -p390775C:\Users\admin\AppData\Local\Temp\nsb36FB.tmp\hiru.exe
cmd.exe
User:
admin
Integrity Level:
HIGH
Exit code:
1000
Modules
Images
c:\users\admin\appdata\local\temp\nsb36fb.tmp\hiru.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
936"C:\Users\admin\Desktop\Air.Explorer.Pro.v2.5.5_2\Air.Explorer.Pro.v2.5.5.exe" C:\Users\admin\Desktop\Air.Explorer.Pro.v2.5.5_2\Air.Explorer.Pro.v2.5.5.exeexplorer.exe
User:
admin
Company:
airexplorer.net
Integrity Level:
MEDIUM
Description:
Air Explorer Pro v2.5.5
Exit code:
3221226540
Version:
2.5.5.0
Modules
Images
c:\users\admin\desktop\air.explorer.pro.v2.5.5_2\air.explorer.pro.v2.5.5.exe
c:\systemroot\system32\ntdll.dll
936"C:\Users\admin\AppData\Local\Temp\nsb36FB.tmp\dec.exe" hiru exeC:\Users\admin\AppData\Local\Temp\nsb36FB.tmp\dec.exe
ns5E0D.tmp
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\nsb36fb.tmp\dec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imm32.dll
1316"C:\Users\admin\AppData\Local\Temp\nsb36FB.tmp\ns5E0D.tmp" "C:\Users\admin\AppData\Local\Temp\nsb36FB.tmp\dec.exe" hiru exeC:\Users\admin\AppData\Local\Temp\nsb36FB.tmp\ns5E0D.tmpAir.Explorer.Pro.v2.5.5.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\nsb36fb.tmp\ns5e0d.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
1492"C:\Users\admin\AppData\Local\Temp\nsb36FB.tmp\ns5C66.tmp" ipconfig /flushdnsC:\Users\admin\AppData\Local\Temp\nsb36FB.tmp\ns5C66.tmpAir.Explorer.Pro.v2.5.5.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\nsb36fb.tmp\ns5c66.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2232"C:\Users\admin\AppData\Local\Temp\nspB2F1.tmp\nsB5A2.tmp" ipconfig /flushdnsC:\Users\admin\AppData\Local\Temp\nspB2F1.tmp\nsB5A2.tmpAir.Explorer.Pro.v2.5.5.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\nspb2f1.tmp\nsb5a2.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2260"C:\Users\admin\AppData\Local\Temp\RarSFX0\hiru.exe" C:\Users\admin\AppData\Local\Temp\RarSFX0\hiru.exe
hiru.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\rarsfx0\hiru.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
2556mode con:cols=100 lines=15C:\Windows\system32\mode.comcmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
DOS Device MODE Utility
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\mode.com
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ulib.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3064"C:\Users\admin\Desktop\Air.Explorer.Pro.v2.5.5_2\Air.Explorer.Pro.v2.5.5.exe" C:\Users\admin\Desktop\Air.Explorer.Pro.v2.5.5_2\Air.Explorer.Pro.v2.5.5.exe
explorer.exe
User:
admin
Company:
airexplorer.net
Integrity Level:
HIGH
Description:
Air Explorer Pro v2.5.5
Exit code:
0
Version:
2.5.5.0
Modules
Images
c:\users\admin\desktop\air.explorer.pro.v2.5.5_2\air.explorer.pro.v2.5.5.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
Total events
1 620
Read events
1 559
Write events
61
Delete events
0

Modification events

(PID) Process:(3392) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3392) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3392) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\70\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3392) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Air.Explorer.Pro.v2.5.5_2.rar
(PID) Process:(3392) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3392) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3392) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3392) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3392) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\DialogEditHistory\ExtrPath
Operation:writeName:0
Value:
C:\Users\admin\Desktop
(PID) Process:(3064) Air.Explorer.Pro.v2.5.5.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
Executable files
45
Suspicious files
0
Text files
56
Unknown types
8

Dropped files

PID
Process
Filename
Type
3392WinRAR.exeC:\Users\admin\Desktop\Air.Explorer.Pro.v2.5.5_2\Air.Explorer.Pro.v2.5.5.exeexecutable
MD5:
SHA256:
3392WinRAR.exeC:\Users\admin\Desktop\Air.Explorer.Pro.v2.5.5_2\PORTABLE.cmdtext
MD5:
SHA256:
3392WinRAR.exeC:\Users\admin\Desktop\Air.Explorer.Pro.v2.5.5_2\INSTALL.cmdtext
MD5:
SHA256:
3064Air.Explorer.Pro.v2.5.5.exeC:\Program Files\Air Explorer Pro\AirExplorer.exeexecutable
MD5:
SHA256:
3064Air.Explorer.Pro.v2.5.5.exeC:\Users\admin\AppData\Local\Temp\nsb36FB.tmp\LangDLL.dllexecutable
MD5:A1CD3F159EF78D9ACE162F067B544FD9
SHA256:47B9E251C9C90F43E3524965AECC07BD53C8E09C5B9F9862B44C306667E2B0B6
3064Air.Explorer.Pro.v2.5.5.exeC:\Users\admin\AppData\Local\Temp\nsb36FB.tmp\3.bmpimage
MD5:FC176015020E80F8266906905D30536D
SHA256:475853E54B9B40AB85E3D7FEED1C3EE9CC4E34444E2068B63627A9235E5B6333
3064Air.Explorer.Pro.v2.5.5.exeC:\Users\admin\AppData\Local\Temp\nsb36FB.tmp\1.bmpimage
MD5:DEC435FEBCB6AFA7D48712C6B7B7F797
SHA256:CF0BF3E2326C6D6C60C0EB72F23D2F57E02C50B1C08012EC0F3490AD7992F85A
3064Air.Explorer.Pro.v2.5.5.exeC:\Users\admin\AppData\Local\Temp\nsb36FB.tmp\4.bmpimage
MD5:7B91A8BD71A1534BED881C524474AA66
SHA256:3392CF7BA5655BC4624D133947E13683D4447FAFB1EA6926F070FC3FD3C499B1
3064Air.Explorer.Pro.v2.5.5.exeC:\Users\admin\AppData\Local\Temp\nsb36FB.tmp\repackme.gifimage
MD5:23D3840ADB8F4F1EFC083A1F7E640191
SHA256:82A1454402156D74F4F23C992D5D772B665546208EFF44790871B8DCB36D2304
3064Air.Explorer.Pro.v2.5.5.exeC:\Program Files\Air Explorer Pro\AirExplorerCmd.exeexecutable
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info