File name:

INSTINCT.rar

Full analysis: https://app.any.run/tasks/5d1324d8-a360-47c9-bc0a-0775504c1652
Verdict: Malicious activity
Analysis date: November 25, 2020, 21:58:21
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v4, os: Win32
MD5:

B4CB7BB2282C27A32040FA564D1444F5

SHA1:

B942BC85CC8F97C71DC5A1468FB16CE699C915EC

SHA256:

5C7262C3A142C09BD823ED6527E7E98DD363B08F6EDA13E835A2784EC8010359

SSDEEP:

3072:K+AEtY3eEZBeUeiGe2c6CkOqFFmHQH4PC8teiaHeGfbRrffVScFCNC:K+NaBBeUpgeqFQQf8lG1TY4Cw

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • INSTINCT.exe (PID: 3156)
      • INSTINCT.exe (PID: 2400)
    • Changes settings of System certificates

      • INSTINCT.exe (PID: 3156)
  • SUSPICIOUS

    • Reads the computer name

      • WinRAR.exe (PID: 2972)
      • INSTINCT.exe (PID: 3156)
    • Checks supported languages

      • INSTINCT.exe (PID: 3156)
      • WinRAR.exe (PID: 2972)
    • Drops a file that was compiled in debug mode

      • WinRAR.exe (PID: 2972)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2972)
    • Adds / modifies Windows certificates

      • INSTINCT.exe (PID: 3156)
    • Reads Environment values

      • INSTINCT.exe (PID: 3156)
  • INFO

    • Reads settings of System Certificates

      • INSTINCT.exe (PID: 3156)
    • Manual execution by user

      • INSTINCT.exe (PID: 3156)
      • INSTINCT.exe (PID: 2400)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v-4.x) (58.3)
.rar | RAR compressed archive (gen) (41.6)

EXIF

ZIP

CompressedSize: 178212
UncompressedSize: 319488
OperatingSystem: Win32
ModifyDate: 2020:10:12 02:36:28
PackingMethod: Normal
ArchivedFileName: INSTINCT\INSTINCT.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
40
Monitored processes
3
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe instinct.exe no specs instinct.exe

Process information

PID
CMD
Path
Indicators
Parent process
2400"C:\Users\admin\Desktop\INSTINCT.exe" C:\Users\admin\Desktop\INSTINCT.exeExplorer.EXE
User:
admin
Integrity Level:
MEDIUM
Description:
SimpleLoader
Exit code:
3221226540
Version:
1.0.0.0
Modules
Images
c:\windows\system32\ntdll.dll
c:\users\admin\desktop\instinct.exe
2972"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\INSTINCT.rar"C:\Program Files\WinRAR\WinRAR.exe
Explorer.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\windows\system32\msctf.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msimg32.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\devobj.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\setupapi.dll
3156"C:\Users\admin\Desktop\INSTINCT.exe" C:\Users\admin\Desktop\INSTINCT.exe
Explorer.EXE
User:
admin
Integrity Level:
HIGH
Description:
SimpleLoader
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\windows\system32\version.dll
c:\windows\system32\msctf.dll
c:\windows\system32\imm32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\lpk.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\shlwapi.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\system32\rpcrt4.dll
Total events
6 362
Read events
6 329
Write events
33
Delete events
0

Modification events

(PID) Process:(2972) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2972) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2972) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\13D\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2972) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2972) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2972) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2972) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2972) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\INSTINCT.rar
(PID) Process:(2972) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(3156) INSTINCT.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\INSTINCT_RASMANCS
Operation:writeName:FileDirectory
Value:
%windir%\tracing
Executable files
1
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
2972WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2972.38429\INSTINCT\INSTINCT.exeexecutable
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
3
DNS requests
2
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3156
INSTINCT.exe
216.58.212.142:443
google.com
Google Inc.
US
whitelisted
3156
INSTINCT.exe
216.58.207.68:443
www.google.com
Google Inc.
US
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 216.58.212.142
malicious
www.google.com
  • 216.58.207.68
malicious

Threats

No threats detected
No debug info