File name:

LANCv2.rar

Full analysis: https://app.any.run/tasks/29cb51ec-9310-4659-9736-426015a876e6
Verdict: Malicious activity
Analysis date: August 09, 2019, 21:23:35
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

4A813F5A792CEBC7E59538B2236BB076

SHA1:

336DF6A541648250ED29B6DD1A5D93E8D0C3CDE4

SHA256:

510310BD1773B9731B23D90406DA8639B5C2DD77C7D42C4FDD76565CE81891F2

SSDEEP:

24576:Cz+OS55EuWVLE3F0vs8PwTZB2Uc8Z0Ycq5j32JBD+/wWT46e:zrWVMFZwNUc8Z00IJt+n49

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • LANC v2.exe (PID: 3688)
      • LANC v2.exe (PID: 2104)
    • Application was dropped or rewritten from another process

      • LANC v2.exe (PID: 3688)
      • LANC v2.exe (PID: 2104)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2360)
    • Uses RUNDLL32.EXE to load library

      • WinRAR.exe (PID: 2360)
  • INFO

    • Application was crashed

      • LANC v2.exe (PID: 3688)
      • LANC v2.exe (PID: 2104)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
40
Monitored processes
4
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
drop and start drop and start start winrar.exe lanc v2.exe rundll32.exe no specs lanc v2.exe

Process information

PID
CMD
Path
Indicators
Parent process
916"C:\Windows\system32\rundll32.exe" C:\Windows\system32\shell32.dll,OpenAs_RunDLL C:\Users\admin\AppData\Local\Temp\Rar$DIa2360.37659\database.datC:\Windows\system32\rundll32.exeWinRAR.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
2104"C:\Users\admin\AppData\Local\Temp\Rar$EXa2360.38076\LANCv2\LANC v2.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa2360.38076\LANCv2\LANC v2.exe
WinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Description:
LANC v2
Exit code:
3762504530
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2360.38076\lancv2\lanc v2.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2360"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\LANCv2.rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3688"C:\Users\admin\AppData\Local\Temp\Rar$EXa2360.34444\LANCv2\LANC v2.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa2360.34444\LANCv2\LANC v2.exe
WinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Description:
LANC v2
Exit code:
3762504530
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2360.34444\lancv2\lanc v2.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
Total events
441
Read events
429
Write events
12
Delete events
0

Modification events

(PID) Process:(2360) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2360) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2360) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\72\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2360) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\LANCv2.rar
(PID) Process:(2360) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2360) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2360) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2360) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2360) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(2360) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
Executable files
16
Suspicious files
0
Text files
13
Unknown types
0

Dropped files

PID
Process
Filename
Type
2360WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DIa2360.37659\database.dattext
MD5:
SHA256:
2360WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2360.34444\LANCv2\PcapDotNet.Packets.dllexecutable
MD5:8CC42BD7D00F047ED71A5BAE500F4EC9
SHA256:C91619C54D3783DB57C6ED446049BEBBE04D42D90304A30B098DCA6E6E546BBF
2360WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2360.34444\LANCv2\MephTheme.dllexecutable
MD5:C9AF2E1FADD1DCD07D22E02C7D299B9A
SHA256:B1C21BCF0BC7D157751C378603511FE03AAE768CF886E3C0E14E4A19F9408BDC
2360WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2360.34444\LANCv2\LoginTheme.dllexecutable
MD5:78C847DA2E3C7FD889E24F4756CACFA7
SHA256:1AF039906D73069B2A2D5F09552EB5807FB16121414EFD0989040578806D6609
2360WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2360.34444\LANCv2\PcapDotNet.Base.dllexecutable
MD5:6F2E6B9046E7ED3CE43A34A7B701FBF9
SHA256:39D850B2412D78580EA842730BB56F59474A8DE4C2D9218D7593CD5B96AC9BAF
2360WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2360.34444\LANCv2\ports.dattext
MD5:0EE8E8D0002C559E47C11200C0CF0F9E
SHA256:D5F32B0E2026D1273D8A8797D7166B573394081B705FB87CEFDD4A759634165F
2360WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2360.34444\LANCv2\PcapDotNet.Analysis.dllexecutable
MD5:894D0649D55E0813BF5D0F0FB96F3C99
SHA256:1F4F96A4DCED09133AEE3BD028CC35B5FBD3D642190ABF5611016920CD9CE260
2360WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2360.34444\LANCv2\settings.initext
MD5:C019E9173AE2F24A3D83E6DE10CD30A3
SHA256:1D5079FA7C019866FEB248E8930A08C32E10CEB4469337A86E96BF456F617B1D
2360WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2360.34444\LANCv2\LANC v2.exeexecutable
MD5:F594847C2E806183624275D877ACF069
SHA256:5D600C4A17065F936875F00CFDDF0F04B78CA49D68596025BB9512D81BCBC766
2360WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2360.34444\LANCv2\DBs\ports.txthtml
MD5:9F93D65F2B9EEF7BF579EBAD1794823C
SHA256:049655CE1572A2B17B3445C4092C83ADD299841B944794EAA48ED591E4D1AF2B
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info