File name:

Air.Explorer.Pro.v2.5.5_2.rar

Full analysis: https://app.any.run/tasks/107b05ad-a843-41d6-8d17-364202172a1d
Verdict: Malicious activity
Analysis date: July 26, 2019, 09:00:39
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

D0AAFD946E0D89C20FDAB3C540C0DB0A

SHA1:

B180FCA1FADE9793A669D475C83633CAE8E8F378

SHA256:

4B64BEF0A51DFC5291B4AA679556205F457E4C11C2B7D5C7543A5E6413F4F1A2

SSDEEP:

98304:teB3/m+iahlP3Woqy5VhZyUT8TlTZK897l8J:c3/dia7Grkyp58J

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Air.Explorer.Pro.v2.5.5.exe (PID: 936)
      • Air.Explorer.Pro.v2.5.5.exe (PID: 3064)
      • ns5C66.tmp (PID: 1492)
      • ns5E0D.tmp (PID: 1316)
      • dec.exe (PID: 936)
      • hiru.exe (PID: 576)
      • hiru.exe (PID: 2260)
      • AirExplorer.exe (PID: 3480)
      • Air.Explorer.Pro.v2.5.5.exe (PID: 3996)
      • Air.Explorer.Pro.v2.5.5.exe (PID: 3160)
      • Air.Explorer.Pro.v2.5.5.exe (PID: 3640)
      • nsB5A2.tmp (PID: 2232)
    • Loads dropped or rewritten executable

      • Air.Explorer.Pro.v2.5.5.exe (PID: 3064)
      • hiru.exe (PID: 2260)
      • AirExplorer.exe (PID: 3480)
      • Air.Explorer.Pro.v2.5.5.exe (PID: 3996)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3392)
      • Air.Explorer.Pro.v2.5.5.exe (PID: 3064)
      • dec.exe (PID: 936)
      • hiru.exe (PID: 576)
      • Air.Explorer.Pro.v2.5.5.exe (PID: 3996)
      • hiru.exe (PID: 2260)
    • Starts application with an unusual extension

      • Air.Explorer.Pro.v2.5.5.exe (PID: 3064)
      • Air.Explorer.Pro.v2.5.5.exe (PID: 3996)
    • Uses IPCONFIG.EXE to discover IP address

      • ns5C66.tmp (PID: 1492)
      • nsB5A2.tmp (PID: 2232)
    • Creates files in the user directory

      • Air.Explorer.Pro.v2.5.5.exe (PID: 3064)
      • AirExplorer.exe (PID: 3480)
    • Creates a software uninstall entry

      • Air.Explorer.Pro.v2.5.5.exe (PID: 3064)
      • hiru.exe (PID: 2260)
      • Air.Explorer.Pro.v2.5.5.exe (PID: 3996)
    • Creates files in the program directory

      • Air.Explorer.Pro.v2.5.5.exe (PID: 3064)
      • hiru.exe (PID: 2260)
    • Starts CMD.EXE for commands execution

      • Air.Explorer.Pro.v2.5.5.exe (PID: 3064)
    • Changes IE settings (feature browser emulation)

      • AirExplorer.exe (PID: 3480)
    • Reads internet explorer settings

      • AirExplorer.exe (PID: 3480)
  • INFO

    • Manual execution by user

      • Air.Explorer.Pro.v2.5.5.exe (PID: 936)
      • Air.Explorer.Pro.v2.5.5.exe (PID: 3064)
      • cmd.exe (PID: 3628)
    • Dropped object may contain Bitcoin addresses

      • Air.Explorer.Pro.v2.5.5.exe (PID: 3064)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
62
Monitored processes
18
Malicious processes
7
Suspicious processes
0

Behavior graph

Click at the process to see the details
start drop and start drop and start drop and start drop and start winrar.exe air.explorer.pro.v2.5.5.exe no specs air.explorer.pro.v2.5.5.exe ns5c66.tmp no specs ipconfig.exe no specs ns5e0d.tmp no specs dec.exe cmd.exe no specs hiru.exe hiru.exe airexplorer.exe no specs cmd.exe no specs mode.com no specs air.explorer.pro.v2.5.5.exe no specs air.explorer.pro.v2.5.5.exe no specs air.explorer.pro.v2.5.5.exe nsb5a2.tmp no specs ipconfig.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
324ipconfig /flushdnsC:\Windows\system32\ipconfig.exens5C66.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
IP Configuration Utility
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ipconfig.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\ws2_32.dll
576C:\Users\admin\AppData\Local\Temp\nsb36FB.tmp\hiru.exe -p390775C:\Users\admin\AppData\Local\Temp\nsb36FB.tmp\hiru.exe
cmd.exe
User:
admin
Integrity Level:
HIGH
Exit code:
1000
Modules
Images
c:\users\admin\appdata\local\temp\nsb36fb.tmp\hiru.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
936"C:\Users\admin\Desktop\Air.Explorer.Pro.v2.5.5_2\Air.Explorer.Pro.v2.5.5.exe" C:\Users\admin\Desktop\Air.Explorer.Pro.v2.5.5_2\Air.Explorer.Pro.v2.5.5.exeexplorer.exe
User:
admin
Company:
airexplorer.net
Integrity Level:
MEDIUM
Description:
Air Explorer Pro v2.5.5
Exit code:
3221226540
Version:
2.5.5.0
Modules
Images
c:\users\admin\desktop\air.explorer.pro.v2.5.5_2\air.explorer.pro.v2.5.5.exe
c:\systemroot\system32\ntdll.dll
936"C:\Users\admin\AppData\Local\Temp\nsb36FB.tmp\dec.exe" hiru exeC:\Users\admin\AppData\Local\Temp\nsb36FB.tmp\dec.exe
ns5E0D.tmp
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\nsb36fb.tmp\dec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imm32.dll
1316"C:\Users\admin\AppData\Local\Temp\nsb36FB.tmp\ns5E0D.tmp" "C:\Users\admin\AppData\Local\Temp\nsb36FB.tmp\dec.exe" hiru exeC:\Users\admin\AppData\Local\Temp\nsb36FB.tmp\ns5E0D.tmpAir.Explorer.Pro.v2.5.5.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\nsb36fb.tmp\ns5e0d.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
1492"C:\Users\admin\AppData\Local\Temp\nsb36FB.tmp\ns5C66.tmp" ipconfig /flushdnsC:\Users\admin\AppData\Local\Temp\nsb36FB.tmp\ns5C66.tmpAir.Explorer.Pro.v2.5.5.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\nsb36fb.tmp\ns5c66.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2232"C:\Users\admin\AppData\Local\Temp\nspB2F1.tmp\nsB5A2.tmp" ipconfig /flushdnsC:\Users\admin\AppData\Local\Temp\nspB2F1.tmp\nsB5A2.tmpAir.Explorer.Pro.v2.5.5.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\nspb2f1.tmp\nsb5a2.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2260"C:\Users\admin\AppData\Local\Temp\RarSFX0\hiru.exe" C:\Users\admin\AppData\Local\Temp\RarSFX0\hiru.exe
hiru.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\rarsfx0\hiru.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
2556mode con:cols=100 lines=15C:\Windows\system32\mode.comcmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
DOS Device MODE Utility
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\mode.com
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ulib.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3064"C:\Users\admin\Desktop\Air.Explorer.Pro.v2.5.5_2\Air.Explorer.Pro.v2.5.5.exe" C:\Users\admin\Desktop\Air.Explorer.Pro.v2.5.5_2\Air.Explorer.Pro.v2.5.5.exe
explorer.exe
User:
admin
Company:
airexplorer.net
Integrity Level:
HIGH
Description:
Air Explorer Pro v2.5.5
Exit code:
0
Version:
2.5.5.0
Modules
Images
c:\users\admin\desktop\air.explorer.pro.v2.5.5_2\air.explorer.pro.v2.5.5.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
Total events
1 620
Read events
1 559
Write events
61
Delete events
0

Modification events

(PID) Process:(3392) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3392) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3392) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\70\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3392) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Air.Explorer.Pro.v2.5.5_2.rar
(PID) Process:(3392) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3392) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3392) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3392) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3392) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\DialogEditHistory\ExtrPath
Operation:writeName:0
Value:
C:\Users\admin\Desktop
(PID) Process:(3064) Air.Explorer.Pro.v2.5.5.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
Executable files
45
Suspicious files
0
Text files
56
Unknown types
8

Dropped files

PID
Process
Filename
Type
3392WinRAR.exeC:\Users\admin\Desktop\Air.Explorer.Pro.v2.5.5_2\Air.Explorer.Pro.v2.5.5.exeexecutable
MD5:
SHA256:
3392WinRAR.exeC:\Users\admin\Desktop\Air.Explorer.Pro.v2.5.5_2\INSTALL.cmdtext
MD5:
SHA256:
3392WinRAR.exeC:\Users\admin\Desktop\Air.Explorer.Pro.v2.5.5_2\PORTABLE.cmdtext
MD5:
SHA256:
3064Air.Explorer.Pro.v2.5.5.exeC:\Users\admin\AppData\Local\Temp\nsb36FB.tmp\LangDLL.dllexecutable
MD5:A1CD3F159EF78D9ACE162F067B544FD9
SHA256:47B9E251C9C90F43E3524965AECC07BD53C8E09C5B9F9862B44C306667E2B0B6
3064Air.Explorer.Pro.v2.5.5.exeC:\Users\admin\AppData\Local\Temp\nsb36FB.tmp\modern-header.bmpimage
MD5:FCE32CFF69894E582054E47A7E5E075E
SHA256:AA7E095F977B17FD27FF4A58EAA679A56117D1D3BD0E2B69292AE42227278866
3064Air.Explorer.Pro.v2.5.5.exeC:\Program Files\Air Explorer Pro\AirExplorer.exeexecutable
MD5:
SHA256:
3064Air.Explorer.Pro.v2.5.5.exeC:\Program Files\Air Explorer Pro\AirExplorerCmd.exeexecutable
MD5:
SHA256:
3064Air.Explorer.Pro.v2.5.5.exeC:\Users\admin\AppData\Local\Temp\nsb36FB.tmp\nsDialogs.dllexecutable
MD5:4CCC4A742D4423F2F0ED744FD9C81F63
SHA256:416133DD86C0DFF6B0FCAF1F46DFE97FDC85B37F90EFFB2D369164A8F7E13AE6
3064Air.Explorer.Pro.v2.5.5.exeC:\Program Files\Air Explorer Pro\AirExplorerCmd.exe.configxml
MD5:883E12BBEB8A0A597FC52F10FD452571
SHA256:1ECA35EF367B194701DF0FA77851457A8C3E81869D976DD81F6253330EECCF49
3064Air.Explorer.Pro.v2.5.5.exeC:\Program Files\Air Explorer Pro\AirExplorer.exe.configxml
MD5:8EBFFD2214CFF72720C5B1319BBF436F
SHA256:583E045A1D7EDE8D1ADD17F7250AF0B41051D0DAF39075656115BBC8491D89A7
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info