| File name: | WinRAR_6.24_Final___CascadedMenu.exe |
| Full analysis: | https://app.any.run/tasks/2d1d1266-56d5-4da6-ba06-c89ad43859e7 |
| Verdict: | Malicious activity |
| Analysis date: | November 18, 2023, 06:48:32 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | F52EEE712E14765B59257078DAE863E7 |
| SHA1: | F0024F6A4AAE0FD00E703FAB239E4596763F468E |
| SHA256: | 525BE1CA1EDCAA4C33B23A8262D1DC846E8F00FB968229622BA378ACC2DD9F52 |
| SSDEEP: | 98304:JDQP9xyG1zsDY3+2jc7YDddoMNWtkCaK0VbI0D6oGKx1WFcWDxMnMILAKB0B0oY4:8yyZ2hbxU1nh3aTgI |
| .exe | | | Generic Win/DOS Executable (50) |
|---|---|---|
| .exe | | | DOS Executable Generic (49.9) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2012:12:31 01:38:51+01:00 |
| ImageFileCharacteristics: | No relocs, Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 8 |
| CodeSize: | 101888 |
| InitializedDataSize: | 182272 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x1942f |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 6.24.0.0 |
| ProductVersionNumber: | 6.24.0.0 |
| FileFlagsMask: | 0x0000 |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Unknown |
| FileSubtype: | - |
| LanguageCode: | Russian |
| CharacterSet: | Unicode |
| CompanyName: | SolidShare |
| FileDescription: | SolidShare.Net Unattended Installer |
| LegalCopyright: | © 2023 By KiNGHaZe |
| LegalTrademarks: | - |
| InternalName: | - |
| ProductName: | WinRAR Final + CascadedMenu |
| OriginalFileName: | - |
| FileVersion: | 6.24 |
| ProductVersion: | 6.24 |
| Comments: | SolidShare.Net Unattended Installer |
| PrivateBuild: | - |
| SpecialBuild: | - |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 3428 | "C:\Users\admin\AppData\Local\Temp\WinRAR_6.24_Final___CascadedMenu.exe" | C:\Users\admin\AppData\Local\Temp\WinRAR_6.24_Final___CascadedMenu.exe | — | explorer.exe | |||||||||||
User: admin Company: SolidShare Integrity Level: MEDIUM Description: SolidShare.Net Unattended Installer Exit code: 0 Version: 6.24 Modules
| |||||||||||||||
| 3472 | "C:\Users\admin\AppData\Local\Temp\WinRAR_6.24_Final___CascadedMenu.exe" -sfxelevation | C:\Users\admin\AppData\Local\Temp\WinRAR_6.24_Final___CascadedMenu.exe | WinRAR_6.24_Final___CascadedMenu.exe | ||||||||||||
User: admin Company: SolidShare Integrity Level: HIGH Description: SolidShare.Net Unattended Installer Exit code: 0 Version: 6.24 Modules
| |||||||||||||||
| 3500 | "C:\Kinghaze\Kur.exe" | C:\Kinghaze\Kur.exe | — | WinRAR_6.24_Final___CascadedMenu.exe | |||||||||||
User: admin Company: SolidShare TEAM Integrity Level: HIGH Description: SolidShare.Net Unattended Installer Exit code: 0 Version: 6.24 Modules
| |||||||||||||||
| 3576 | "C:\Kinghaze\X86.exe" /S | C:\Kinghaze\x86.exe | — | Kur.exe | |||||||||||
User: admin Company: Alexander Roshal Integrity Level: HIGH Description: WinRAR archiver Exit code: 0 Version: 6.24.0 Modules
| |||||||||||||||
| 3596 | "C:\Program Files\WinRAR\uninstall.exe" /setup | C:\Program Files\WinRAR\uninstall.exe | — | x86.exe | |||||||||||
User: admin Company: Alexander Roshal Integrity Level: HIGH Description: Uninstall WinRAR Exit code: 0 Version: 6.24.0 Modules
| |||||||||||||||
| (PID) Process: | (3428) WinRAR_6.24_Final___CascadedMenu.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (3428) WinRAR_6.24_Final___CascadedMenu.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (3428) WinRAR_6.24_Final___CascadedMenu.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (3428) WinRAR_6.24_Final___CascadedMenu.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (3472) WinRAR_6.24_Final___CascadedMenu.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (3472) WinRAR_6.24_Final___CascadedMenu.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (3472) WinRAR_6.24_Final___CascadedMenu.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (3472) WinRAR_6.24_Final___CascadedMenu.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (3500) Kur.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (3500) Kur.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3472 | WinRAR_6.24_Final___CascadedMenu.exe | C:\Kinghaze\Themes\ext\DiskOn.ico | image | |
MD5:C99678A7CD3AC314B5DCAC74F9062B0B | SHA256:C9370B0E27B99ACA6F042F8D11E5785E0835FF38C00D752351CA25EDE21088FE | |||
| 3472 | WinRAR_6.24_Final___CascadedMenu.exe | C:\Kinghaze\Themes\ext\REV.ico | image | |
MD5:C37604BCE1FDB63BF225E85B1AE8776E | SHA256:FD36F5802AA011419C9BCFF23AEBBF836775CE081D05F0FB14010382D95F579A | |||
| 3472 | WinRAR_6.24_Final___CascadedMenu.exe | C:\Kinghaze\Themes\ext\AboutLogo.bmp | image | |
MD5:2F58246104A129C8449816CEBC1D6903 | SHA256:65312D5D09D45C330ED80A84094632D99C94C19FBFF8A625320623D57E9051DF | |||
| 3472 | WinRAR_6.24_Final___CascadedMenu.exe | C:\Kinghaze\Themes\ext\RarSmall.bmp | image | |
MD5:989687274BE7EE966353D19A57CDEAFB | SHA256:8D91D5323F226DC3733EF627DE05A5177EEB7F1EE8137F715228A0A81D40A59C | |||
| 3472 | WinRAR_6.24_Final___CascadedMenu.exe | C:\Kinghaze\Themes\ext\FolderUp.bmp | image | |
MD5:BDBFF89D514F5E83273AB2C949BB0318 | SHA256:4DD27666A78A84855A774105C3F1C283C1A2167F9C9931ACB7E61F9785EC60B1 | |||
| 3472 | WinRAR_6.24_Final___CascadedMenu.exe | C:\Kinghaze\Themes\ext\DiskOff.ico | image | |
MD5:D0CFB21666FA59E243F8141D3BAB93DE | SHA256:DAED0E1D98C6D0817F73705D3845AED30E8282FB9B31EAB45301816C4746E7CE | |||
| 3472 | WinRAR_6.24_Final___CascadedMenu.exe | C:\Kinghaze\Themes\ext\Setup.ico | image | |
MD5:C37604BCE1FDB63BF225E85B1AE8776E | SHA256:FD36F5802AA011419C9BCFF23AEBBF836775CE081D05F0FB14010382D95F579A | |||
| 3472 | WinRAR_6.24_Final___CascadedMenu.exe | C:\Kinghaze\Themes\ext\SortUp.bmp | binary | |
MD5:63962C13E0FD49AD5D52D7E2715D159B | SHA256:E7EF06FDBB8F46AFCD9DB93F512BFCAD6B6EE391B767A4ADF66A7CDCCC40B883 | |||
| 3472 | WinRAR_6.24_Final___CascadedMenu.exe | C:\Kinghaze\Themes\ext\SFXLogo.bmp | image | |
MD5:9C1C374EDB5C96B9DDE8C30CFD96D9FC | SHA256:4085B0E2A9F1A15D3BD40DF7A5300BE70C21E0196DC3F6E2DDBEF2127AB47E5D | |||
| 3472 | WinRAR_6.24_Final___CascadedMenu.exe | C:\Kinghaze\Themes\ext\SFX.ico | image | |
MD5:C37604BCE1FDB63BF225E85B1AE8776E | SHA256:FD36F5802AA011419C9BCFF23AEBBF836775CE081D05F0FB14010382D95F579A | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
2588 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |