File name:

FDS.com.zip

Full analysis: https://app.any.run/tasks/56fb661d-3121-4cdc-ad75-191759c9f968
Verdict: Malicious activity
Analysis date: December 27, 2021, 17:11:40
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

388AF144588950829213E1C30DD337E6

SHA1:

024978201B4E8BE69DEDA5F02BF1F2237294AC7D

SHA256:

4E8584CB1191521FC05D6E547DFC2D9E5EAC658B4A8F330823278DB474F1E8F5

SSDEEP:

98304:8aI6rPxlQDTb2/rvIyQfEX8RNx3Cwt9Bh6uNozxa8XnBmCtAI9PRt0dy8DdQ8LZs:8aIqATb2TvIyoLNxywlcNQ8XBmsj95tF

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • SearchProtocolHost.exe (PID: 3272)
  • SUSPICIOUS

    • Reads the computer name

      • WinRAR.exe (PID: 3104)
    • Checks supported languages

      • WinRAR.exe (PID: 3104)
    • Drops a file with a compile date too recent

      • WinRAR.exe (PID: 3104)
    • Drops a file that was compiled in debug mode

      • WinRAR.exe (PID: 3104)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3104)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipFileName: Guna.UI.dll
ZipUncompressedSize: 1136808
ZipCompressedSize: 670801
ZipCRC: 0x24642fc8
ZipModifyDate: 2020:05:18 10:37:07
ZipCompression: Deflated
ZipBitFlag: -
ZipRequiredVersion: 20
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
35
Monitored processes
2
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe searchprotocolhost.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
3104"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\FDS.com.zip"C:\Program Files\WinRAR\WinRAR.exe
Explorer.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3272"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe2_ Global\UsGthrCtrlFltPipeMssGthrPipe2 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" C:\Windows\system32\SearchProtocolHost.exeSearchIndexer.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Windows Search Protocol Host
Exit code:
0
Version:
7.00.7601.24542 (win7sp1_ldr_escrow.191209-2211)
Modules
Images
c:\windows\system32\searchprotocolhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
1 263
Read events
1 225
Write events
38
Delete events
0

Modification events

(PID) Process:(3104) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3104) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3104) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3104) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(3104) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(3104) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\FDS.com.zip
(PID) Process:(3104) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3104) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3104) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3104) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
Executable files
24
Suspicious files
2
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
3104WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3104.27752\Memory.dllexecutable
MD5:
SHA256:
3104WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3104.27752\JournalTrace.exeexecutable
MD5:
SHA256:
3104WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3104.28511\Memory.dllexecutable
MD5:
SHA256:
3104WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3104.27066\Memory.dllexecutable
MD5:
SHA256:
3104WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3104.27066\JournalTrace.exeexecutable
MD5:
SHA256:
3104WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3104.27752\Siticone.UI.dllexecutable
MD5:FA842FFA299C794E57597AAE857D9CB3
SHA256:B1D4CDC7891D51636C5E82A91B9BF20E6BB6E68DDF515AC6F51FBDA7B199D07D
3104WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3104.27066\Guna.UI2.dllexecutable
MD5:ACEC68D05E0B9B6C34A24DA530DC07B2
SHA256:BF72939922AFA2CD17071F5170B4A82D05BCEB1FC33CE29CDFBC68DBB97F0277
3104WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3104.27752\WindowsInput.dllexecutable
MD5:6A633F99CDA2B123AA740D579A30276A
SHA256:BEE5F9A71E9EA922BC9E712B9257CFB059B689AC8D436DD44CC99C025F6F83A5
3104WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3104.28511\JournalTrace.exeexecutable
MD5:
SHA256:
3104WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3104.30043\JournalTrace.exeexecutable
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info