| File name: | WinRAR_6.24_Final___CascadedMenu.exe |
| Full analysis: | https://app.any.run/tasks/2d1d1266-56d5-4da6-ba06-c89ad43859e7 |
| Verdict: | Malicious activity |
| Analysis date: | November 18, 2023, 06:48:32 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | F52EEE712E14765B59257078DAE863E7 |
| SHA1: | F0024F6A4AAE0FD00E703FAB239E4596763F468E |
| SHA256: | 525BE1CA1EDCAA4C33B23A8262D1DC846E8F00FB968229622BA378ACC2DD9F52 |
| SSDEEP: | 98304:JDQP9xyG1zsDY3+2jc7YDddoMNWtkCaK0VbI0D6oGKx1WFcWDxMnMILAKB0B0oY4:8yyZ2hbxU1nh3aTgI |
| .exe | | | Generic Win/DOS Executable (50) |
|---|---|---|
| .exe | | | DOS Executable Generic (49.9) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2012:12:31 01:38:51+01:00 |
| ImageFileCharacteristics: | No relocs, Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 8 |
| CodeSize: | 101888 |
| InitializedDataSize: | 182272 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x1942f |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 6.24.0.0 |
| ProductVersionNumber: | 6.24.0.0 |
| FileFlagsMask: | 0x0000 |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Unknown |
| FileSubtype: | - |
| LanguageCode: | Russian |
| CharacterSet: | Unicode |
| CompanyName: | SolidShare |
| FileDescription: | SolidShare.Net Unattended Installer |
| LegalCopyright: | © 2023 By KiNGHaZe |
| LegalTrademarks: | - |
| InternalName: | - |
| ProductName: | WinRAR Final + CascadedMenu |
| OriginalFileName: | - |
| FileVersion: | 6.24 |
| ProductVersion: | 6.24 |
| Comments: | SolidShare.Net Unattended Installer |
| PrivateBuild: | - |
| SpecialBuild: | - |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 3428 | "C:\Users\admin\AppData\Local\Temp\WinRAR_6.24_Final___CascadedMenu.exe" | C:\Users\admin\AppData\Local\Temp\WinRAR_6.24_Final___CascadedMenu.exe | — | explorer.exe | |||||||||||
User: admin Company: SolidShare Integrity Level: MEDIUM Description: SolidShare.Net Unattended Installer Exit code: 0 Version: 6.24 Modules
| |||||||||||||||
| 3472 | "C:\Users\admin\AppData\Local\Temp\WinRAR_6.24_Final___CascadedMenu.exe" -sfxelevation | C:\Users\admin\AppData\Local\Temp\WinRAR_6.24_Final___CascadedMenu.exe | WinRAR_6.24_Final___CascadedMenu.exe | ||||||||||||
User: admin Company: SolidShare Integrity Level: HIGH Description: SolidShare.Net Unattended Installer Exit code: 0 Version: 6.24 Modules
| |||||||||||||||
| 3500 | "C:\Kinghaze\Kur.exe" | C:\Kinghaze\Kur.exe | — | WinRAR_6.24_Final___CascadedMenu.exe | |||||||||||
User: admin Company: SolidShare TEAM Integrity Level: HIGH Description: SolidShare.Net Unattended Installer Exit code: 0 Version: 6.24 Modules
| |||||||||||||||
| 3576 | "C:\Kinghaze\X86.exe" /S | C:\Kinghaze\x86.exe | — | Kur.exe | |||||||||||
User: admin Company: Alexander Roshal Integrity Level: HIGH Description: WinRAR archiver Exit code: 0 Version: 6.24.0 Modules
| |||||||||||||||
| 3596 | "C:\Program Files\WinRAR\uninstall.exe" /setup | C:\Program Files\WinRAR\uninstall.exe | — | x86.exe | |||||||||||
User: admin Company: Alexander Roshal Integrity Level: HIGH Description: Uninstall WinRAR Exit code: 0 Version: 6.24.0 Modules
| |||||||||||||||
| (PID) Process: | (3428) WinRAR_6.24_Final___CascadedMenu.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (3428) WinRAR_6.24_Final___CascadedMenu.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (3428) WinRAR_6.24_Final___CascadedMenu.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (3428) WinRAR_6.24_Final___CascadedMenu.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (3472) WinRAR_6.24_Final___CascadedMenu.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (3472) WinRAR_6.24_Final___CascadedMenu.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (3472) WinRAR_6.24_Final___CascadedMenu.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (3472) WinRAR_6.24_Final___CascadedMenu.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (3500) Kur.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (3500) Kur.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3472 | WinRAR_6.24_Final___CascadedMenu.exe | C:\Kinghaze\Themes\ext\FolderUp.bmp | image | |
MD5:BDBFF89D514F5E83273AB2C949BB0318 | SHA256:4DD27666A78A84855A774105C3F1C283C1A2167F9C9931ACB7E61F9785EC60B1 | |||
| 3472 | WinRAR_6.24_Final___CascadedMenu.exe | C:\Kinghaze\Themes\ext\SortDown.bmp | binary | |
MD5:33BF162D3DE7CFB4C47F3A4DA5ECEEAC | SHA256:4581700A71F9B90928B42D0F24E412A80A1CC43157346D35F6EE885C1413E082 | |||
| 3472 | WinRAR_6.24_Final___CascadedMenu.exe | C:\Kinghaze\Themes\ext\SortUp.bmp | binary | |
MD5:63962C13E0FD49AD5D52D7E2715D159B | SHA256:E7EF06FDBB8F46AFCD9DB93F512BFCAD6B6EE391B767A4ADF66A7CDCCC40B883 | |||
| 3472 | WinRAR_6.24_Final___CascadedMenu.exe | C:\Kinghaze\Themes\ext\AboutLogo.bmp | image | |
MD5:2F58246104A129C8449816CEBC1D6903 | SHA256:65312D5D09D45C330ED80A84094632D99C94C19FBFF8A625320623D57E9051DF | |||
| 3472 | WinRAR_6.24_Final___CascadedMenu.exe | C:\Kinghaze\Themes\ext\PasswordOn.ico | image | |
MD5:7B34ADC866B789D76D92B01ADFED3908 | SHA256:E35BEA741E3D6B5DFD3E624939970C349F8BF75856306C53325515E07C779E05 | |||
| 3472 | WinRAR_6.24_Final___CascadedMenu.exe | C:\Kinghaze\Themes\ext\REV.ico | image | |
MD5:C37604BCE1FDB63BF225E85B1AE8776E | SHA256:FD36F5802AA011419C9BCFF23AEBBF836775CE081D05F0FB14010382D95F579A | |||
| 3472 | WinRAR_6.24_Final___CascadedMenu.exe | C:\Kinghaze\Themes\ext\DragCopy.cur | binary | |
MD5:56F8155793179B6036A082A07024826F | SHA256:5095F4151626FD62A2BE17EE34DADA1EF909914B150B8BE7F0BADD267FA2679E | |||
| 3472 | WinRAR_6.24_Final___CascadedMenu.exe | C:\Kinghaze\Themes\ext\File.ico | image | |
MD5:7F5222D064AF4107BEE2B80D912DD933 | SHA256:34991D1B1251C4A77DFB9C3CF40C2B443BE60B81DE3AE43B36239A64474647BA | |||
| 3472 | WinRAR_6.24_Final___CascadedMenu.exe | C:\Kinghaze\Themes\ext\RAR.ico | image | |
MD5:FDB478BF8B931BC30F744CCC1DE6AAE0 | SHA256:75F973BCBE0351947B4012C1E0EDD286D8C71F55761AAE00CE1BC64BC8CFAFAE | |||
| 3472 | WinRAR_6.24_Final___CascadedMenu.exe | C:\Kinghaze\Themes\ext\Setup.ico | image | |
MD5:C37604BCE1FDB63BF225E85B1AE8776E | SHA256:FD36F5802AA011419C9BCFF23AEBBF836775CE081D05F0FB14010382D95F579A | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
2588 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |