File name:

winrar-x64-713uk.exe

Full analysis: https://app.any.run/tasks/1de543b3-58b7-458e-abda-8e01b8167714
Verdict: Malicious activity
Analysis date: August 05, 2025, 19:29:20
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32+ executable (GUI) x86-64, for MS Windows, 8 sections
MD5:

5863F363080757762D03454E3F7F0628

SHA1:

72432ED85CD91654C946167A5D36884BB5C1BB10

SHA256:

5B415245B3113796588A846062EBAF52A6A35C9355F4C182C5F8301C5E52C9DF

SSDEEP:

98304:FdtrhhyyUL5LvPYzEDtD0JySXTmajzmwTPic7cBIhF5/XkKOyrN6qa0DvK7GzbOr:FZJk3

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads Internet Explorer settings

      • winrar-x64-713uk.exe (PID: 2580)
    • Reads Microsoft Outlook installation path

      • winrar-x64-713uk.exe (PID: 2580)
    • Reads security settings of Internet Explorer

      • winrar-x64-713uk.exe (PID: 2580)
      • WinRAR.exe (PID: 6812)
    • Reads the date of Windows installation

      • winrar-x64-713uk.exe (PID: 2580)
      • WinRAR.exe (PID: 6812)
    • Drops 7-zip archiver for unpacking

      • winrar-x64-713uk.exe (PID: 2580)
    • Executable content was dropped or overwritten

      • winrar-x64-713uk.exe (PID: 2580)
    • Creates/Modifies COM task schedule object

      • Uninstall.exe (PID: 4544)
    • Searches for installed software

      • Uninstall.exe (PID: 4544)
    • Creates a software uninstall entry

      • Uninstall.exe (PID: 4544)
    • Application launched itself

      • WinRAR.exe (PID: 6812)
  • INFO

    • Checks supported languages

      • winrar-x64-713uk.exe (PID: 2580)
      • Uninstall.exe (PID: 4544)
      • WinRAR.exe (PID: 6812)
      • WinRAR.exe (PID: 4080)
    • Checks proxy server information

      • winrar-x64-713uk.exe (PID: 2580)
    • Reads the computer name

      • winrar-x64-713uk.exe (PID: 2580)
      • Uninstall.exe (PID: 4544)
      • WinRAR.exe (PID: 6812)
      • WinRAR.exe (PID: 4080)
    • The sample compiled with english language support

      • winrar-x64-713uk.exe (PID: 2580)
    • Creates files in the program directory

      • winrar-x64-713uk.exe (PID: 2580)
      • Uninstall.exe (PID: 4544)
      • WinRAR.exe (PID: 4080)
    • The sample compiled with russian language support

      • winrar-x64-713uk.exe (PID: 2580)
    • Process checks computer location settings

      • winrar-x64-713uk.exe (PID: 2580)
      • WinRAR.exe (PID: 6812)
    • Creates files or folders in the user directory

      • Uninstall.exe (PID: 4544)
    • Manual execution by a user

      • WinRAR.exe (PID: 6812)
    • Reads Microsoft Office registry keys

      • OpenWith.exe (PID: 3704)
      • OpenWith.exe (PID: 3160)
    • Reads the machine GUID from the registry

      • WinRAR.exe (PID: 4080)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (87.3)
.exe | Generic Win/DOS Executable (6.3)
.exe | DOS Executable Generic (6.3)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2025:07:28 09:26:39+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 14.44
CodeSize: 257024
InitializedDataSize: 286208
UninitializedDataSize: -
EntryPoint: 0x261f0
OSVersion: 6.1
ImageVersion: -
SubsystemVersion: 6.1
Subsystem: Windows GUI
FileVersionNumber: 7.13.0.0
ProductVersionNumber: 7.13.0.0
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
ProductName: WinRAR
CompanyName: Alexander Roshal
FileDescription: WinRAR
FileVersion: 7.13.0
ProductVersion: 7.13.0
InternalName: WinRAR
LegalCopyright: Copyright © Alexander Roshal 1993-2025
OriginalFileName: WinRAR.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
147
Monitored processes
9
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar-x64-713uk.exe uninstall.exe no specs rundll32.exe no specs openwith.exe no specs openwith.exe no specs winrar.exe no specs winrar.exe slui.exe no specs winrar-x64-713uk.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1204C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -EmbeddingC:\Windows\System32\rundll32.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shcore.dll
c:\windows\system32\imagehlp.dll
1592"C:\Users\admin\AppData\Local\Temp\winrar-x64-713uk.exe" C:\Users\admin\AppData\Local\Temp\winrar-x64-713uk.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR
Exit code:
3221226540
Version:
7.13.0
Modules
Images
c:\users\admin\appdata\local\temp\winrar-x64-713uk.exe
c:\windows\system32\ntdll.dll
2580"C:\Users\admin\AppData\Local\Temp\winrar-x64-713uk.exe" C:\Users\admin\AppData\Local\Temp\winrar-x64-713uk.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
HIGH
Description:
WinRAR
Exit code:
0
Version:
7.13.0
Modules
Images
c:\users\admin\appdata\local\temp\winrar-x64-713uk.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3160C:\WINDOWS\system32\OpenWith.exe -EmbeddingC:\Windows\System32\OpenWith.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Pick an app
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\openwith.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
3704C:\WINDOWS\system32\OpenWith.exe -EmbeddingC:\Windows\System32\OpenWith.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Pick an app
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\openwith.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
4080"C:\Program Files\WinRAR\WinRAR.exe" -isetup_elevate6812C:\Program Files\WinRAR\WinRAR.exe
WinRAR.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
HIGH
Description:
WinRAR
Exit code:
0
Version:
7.13.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
4544"C:\Program Files\WinRAR\uninstall.exe" /setupC:\Program Files\WinRAR\Uninstall.exewinrar-x64-713uk.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
HIGH
Description:
Uninstall WinRAR
Exit code:
0
Version:
7.13.0
Modules
Images
c:\program files\winrar\uninstall.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
4832C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
6812"C:\Program Files\WinRAR\WinRAR.exe" a -ep1 -scul -r0 -iext -imon1 -- . "C:\Program Files\WinRAR\Default32En.SFX"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR
Exit code:
0
Version:
7.13.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
Total events
3 234
Read events
3 124
Write events
92
Delete events
18

Modification events

(PID) Process:(2580) winrar-x64-713uk.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(2580) winrar-x64-713uk.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(2580) winrar-x64-713uk.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(2580) winrar-x64-713uk.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR SFX
Operation:writeName:C%%Program Files%WinRAR
Value:
C:\Program Files\WinRAR
(PID) Process:(2580) winrar-x64-713uk.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\LowRegistry
Operation:delete valueName:AddToFavoritesInitialSelection
Value:
(PID) Process:(2580) winrar-x64-713uk.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\LowRegistry
Operation:delete valueName:AddToFeedsInitialSelection
Value:
(PID) Process:(4544) Uninstall.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Setup\.rar
Operation:writeName:Set
Value:
1
(PID) Process:(4544) Uninstall.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Setup\.zip
Operation:writeName:Set
Value:
1
(PID) Process:(4544) Uninstall.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Setup\.cab
Operation:writeName:Set
Value:
1
(PID) Process:(4544) Uninstall.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Setup\.arj
Operation:writeName:Set
Value:
1
Executable files
19
Suspicious files
3
Text files
16
Unknown types
10

Dropped files

PID
Process
Filename
Type
2580winrar-x64-713uk.exe
MD5:
SHA256:
2580winrar-x64-713uk.exeC:\Program Files\WinRAR\Descript.iontext
MD5:70345CC7B1D883FDCEB37248274E36FD
SHA256:9C0FBF1BC5531188255A8B8268DE9D4CE10EA72E3FFC809178F687A456066141
2580winrar-x64-713uk.exeC:\Program Files\WinRAR\Order.htmhtml
MD5:29A9CEAFFEB420BDE757E387DEF8CC33
SHA256:4B6E863DC79E175694C4DEAA5C0D2D92008923B1F7056E89F8DBD062045E56B0
2580winrar-x64-713uk.exeC:\Program Files\WinRAR\Rar.exeexecutable
MD5:10913ED85C79C1DAFBBBFF343C73471B
SHA256:A7A155934662984A5063D8D9215DC5E226AA12F4E04FCA932574EA075E32DD3A
2580winrar-x64-713uk.exeC:\Program Files\WinRAR\Uninstall.lsttext
MD5:58F5927300043DE0EE7F1AD9D2844975
SHA256:3EE549EE8045D4265B58D962B4794EC2C2BE77BDD3B2AA92E7113ABB3C448CE2
2580winrar-x64-713uk.exeC:\Program Files\WinRAR\WhatsNew.txttext
MD5:FC5A00A4DCC995842C51DFDBF63EA309
SHA256:3F70B08B71D842B09D5E16B63FC76FD43A2A28D8DF1139C92700991CB2B756CA
2580winrar-x64-713uk.exeC:\Program Files\WinRAR\RarExtInstaller.exeexecutable
MD5:6B5EA97F14A6332C110FB37C32D22D97
SHA256:267E3F3F4FA5201F980063B289A6140423480B8BA9D6361B5D06A76AF709D011
2580winrar-x64-713uk.exeC:\Program Files\WinRAR\7zxa.dllexecutable
MD5:120508BCF2E91C722B832B7AC7772A01
SHA256:3C7EA2144B1738B30E3C2E1BA952684EB43C704A5AE82A4DD492D607A42C517C
2580winrar-x64-713uk.exeC:\Program Files\WinRAR\Uninstall.exeexecutable
MD5:EC35AAE4930DD92C6A14D299DE9E1AD2
SHA256:BBBAD12FA01EA9016BA0DFCBFE414182586FCB862F4BEBB7A456FA5ACD330AD8
2580winrar-x64-713uk.exeC:\Program Files\WinRAR\RarExt.dllexecutable
MD5:49FD5E4A41745BBF95973B7638BA7C9A
SHA256:01EAAB6A082AB12F9227568D841405BF4764F1AA93CFDA285EDACEE5B81DEDAC
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
20
DNS requests
16
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1268
svchost.exe
GET
200
23.48.23.156:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
1268
svchost.exe
GET
200
23.32.97.216:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
2232
svchost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
1852
SIHClient.exe
GET
200
104.79.89.142:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
1852
SIHClient.exe
GET
200
104.79.89.142:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
5944
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
1268
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5504
RUXIMICS.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
1268
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1268
svchost.exe
23.48.23.156:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
1268
svchost.exe
23.32.97.216:80
www.microsoft.com
AKAMAI-AS
SE
whitelisted
1268
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5944
MoUsoCoreWorker.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 51.104.136.2
  • 40.127.240.158
whitelisted
google.com
  • 142.250.185.110
whitelisted
crl.microsoft.com
  • 23.48.23.156
  • 23.48.23.166
  • 23.48.23.143
whitelisted
www.microsoft.com
  • 23.32.97.216
  • 104.79.89.142
whitelisted
login.live.com
  • 20.190.159.73
  • 20.190.159.0
  • 40.126.31.73
  • 20.190.159.4
  • 40.126.31.3
  • 40.126.31.2
  • 40.126.31.129
  • 20.190.159.129
whitelisted
ocsp.digicert.com
  • 184.30.131.245
whitelisted
slscr.update.microsoft.com
  • 52.149.20.212
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 52.165.164.15
whitelisted
self.events.data.microsoft.com
  • 51.116.253.168
whitelisted
activation-v2.sls.microsoft.com
  • 40.91.76.224
whitelisted

Threats

No threats detected
No debug info