| File name: | winmtr-0-92-en-win.zip |
| Full analysis: | https://app.any.run/tasks/b021d603-061f-4ff9-9f69-794da7502064 |
| Verdict: | No threats detected |
| Analysis date: | November 20, 2019, 07:05:11 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v1.0 to extract |
| MD5: | 4F98064CD9F2FADF07D2A69D4EDF4BA3 |
| SHA1: | 3D0553DABD788B67EAA328DB90FA77635A30813B |
| SHA256: | 4F5C38B0D9B26A4E4285214D0C8A54CA1DF96FF892AB852860787D7B4A8A7715 |
| SSDEEP: | 49152:c2lNlYNMo7cGnoUj4jMvmYd3N5n7zfyL83pwT5WJOgn:c2lNa+o7cGn2jDutCT5WJOgn |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 10 |
|---|---|
| ZipBitFlag: | - |
| ZipCompression: | None |
| ZipModifyDate: | 2011:01:31 19:10:29 |
| ZipCRC: | 0x00000000 |
| ZipCompressedSize: | - |
| ZipUncompressedSize: | - |
| ZipFileName: | WinMTR-v092/ |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1908 | "C:\Windows\System32\cmd.exe" | C:\Windows\System32\cmd.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 2392 | tracert br.rgsbank.ru | C:\Windows\system32\TRACERT.EXE | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: TCP/IP Traceroute Command Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2864 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa3464.4893\WinMTR-v092\WinMTR_x32\WinMTR.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa3464.4893\WinMTR-v092\WinMTR_x32\WinMTR.exe | WinRAR.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Description: WinMTR by Appnor MSP - www.winmtr.net Exit code: 0 Version: 0.9.0.2 Modules
| |||||||||||||||
| 3464 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\winmtr-0-92-en-win.zip" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.60.0 Modules
| |||||||||||||||
| (PID) Process: | (3464) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (3464) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (3464) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3464) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop\winmtr-0-92-en-win.zip | |||
| (PID) Process: | (3464) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (3464) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (3464) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (3464) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (3464) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\ArcColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (3464) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\ArcColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3464 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3464.4893\WinMTR-v092\WinMTR_x32\README.TXT | text | |
MD5:E9EA7C7BF58E4B6DA844814ED3CA2F4E | SHA256:70ACF84BA0796B8912FBBDF9C1A3B4A752606BB68D018F89BB85D9A673AF7EEC | |||
| 3464 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3464.4893\WinMTR-v092\WinMTR_x64\README.TXT | text | |
MD5:E9EA7C7BF58E4B6DA844814ED3CA2F4E | SHA256:70ACF84BA0796B8912FBBDF9C1A3B4A752606BB68D018F89BB85D9A673AF7EEC | |||
| 3464 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3464.4893\WinMTR-v092\WinMTR_x32\WinMTR.exe | executable | |
MD5:CD2D703E459435A715A6B83C812AE84D | SHA256:E1C9BDAAF926C7A568571E430E868966FE80CB1BFAC3742A9C2B6EBB03B71E5F | |||
| 3464 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3464.4893\WinMTR-v092\README.TXT | text | |
MD5:E9EA7C7BF58E4B6DA844814ED3CA2F4E | SHA256:70ACF84BA0796B8912FBBDF9C1A3B4A752606BB68D018F89BB85D9A673AF7EEC | |||
| 3464 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3464.4893\WinMTR-v092\WinMTR_x64\WinMTR.exe | executable | |
MD5:7174CCF02161DAB6E424E2DE83807DEB | SHA256:9AD74A0F18CE39A0D92A9DABC6EF7EBB2AEBF1471ED868F14E183FAF0123EB87 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 185.107.116.21:137 | — | NForce Entertainment B.V. | NL | unknown |
— | — | 185.107.116.22:137 | — | NForce Entertainment B.V. | NL | unknown |
— | — | 46.166.186.30:137 | — | NForce Entertainment B.V. | NL | unknown |
Domain | IP | Reputation |
|---|---|---|
online.rgsbank.ru |
| unknown |
br.rgsbank.ru |
| unknown |
help.rgsbank.ru |
| unknown |
Process | Message |
|---|---|
WinMTR.exe | Threaad with TTL=1 started.
|
WinMTR.exe | Threaad with TTL=2 started.
|
WinMTR.exe | Threaad with TTL=3 started.
|
WinMTR.exe | Threaad with TTL=4 started.
|
WinMTR.exe | Threaad with TTL=6 started.
|
WinMTR.exe | Threaad with TTL=5 started.
|
WinMTR.exe | Threaad with TTL=7 started.
|
WinMTR.exe | Threaad with TTL=8 started.
|
WinMTR.exe | Threaad with TTL=9 started.
|
WinMTR.exe | TTL 1 reply TTL @ Status 11013 Reply count 1
|