analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

timo.rar

Full analysis: https://app.any.run/tasks/78adba9e-65fb-47d0-b7bd-38e6e6c75101
Verdict: Malicious activity
Analysis date: January 24, 2022, 21:03:18
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

278589084354CD3BC2E1D99FF40CC9E1

SHA1:

A045907750B7F4861A42B2821AB8DC910CA1FE54

SHA256:

5EC843F9B67C43998357B687B0B240AE266BB89F0E82585BE516B00CDEF78375

SSDEEP:

3072:1nfHSBkcA8Lr1b8KsP7oaPJ05HiowN/0nWZ1Ra+HXyq3DkpsRLa:daBlA8Lrd8r86WHw2nWZ1Ra+333DkCu

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • QQNetBar.exe (PID: 3824)
      • QQNetBar.exe (PID: 3836)
    • Loads dropped or rewritten executable

      • QQNetBar.exe (PID: 3824)
      • QQNetBar.exe (PID: 3836)
      • SearchProtocolHost.exe (PID: 2148)
  • SUSPICIOUS

    • Checks supported languages

      • WinRAR.exe (PID: 2156)
      • QQNetBar.exe (PID: 3824)
      • QQNetBar.exe (PID: 3836)
    • Reads the computer name

      • WinRAR.exe (PID: 2156)
      • QQNetBar.exe (PID: 3824)
    • Drops a file that was compiled in debug mode

      • WinRAR.exe (PID: 2156)
    • Drops a file with too old compile date

      • WinRAR.exe (PID: 2156)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2156)
    • Executed via COM

      • DllHost.exe (PID: 2396)
  • INFO

    • Reads the computer name

      • DllHost.exe (PID: 2396)
    • Checks supported languages

      • DllHost.exe (PID: 2396)
    • Manual execution by user

      • QQNetBar.exe (PID: 3836)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
40
Monitored processes
5
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
drop and start start winrar.exe qqnetbar.exe PhotoViewer.dll no specs searchprotocolhost.exe no specs qqnetbar.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2156"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\timo.rar"C:\Program Files\WinRAR\WinRAR.exe
Explorer.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\comdlg32.dll
3824"C:\Users\admin\AppData\Local\Temp\Rar$EXa2156.36261\QQNetBar.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa2156.36261\QQNetBar.exe
WinRAR.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Resource Compiler
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
2396C:\Windows\system32\DllHost.exe /Processid:{76D0CB12-7604-4048-B83C-1005C7DDC503}C:\Windows\system32\DllHost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
COM Surrogate
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
2148"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe2_ Global\UsGthrCtrlFltPipeMssGthrPipe2 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" C:\Windows\system32\SearchProtocolHost.exeSearchIndexer.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Windows Search Protocol Host
Version:
7.00.7601.24542 (win7sp1_ldr_escrow.191209-2211)
Modules
Images
c:\windows\system32\searchprotocolhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3836"C:\Users\admin\Desktop\QQNetBar.exe" C:\Users\admin\Desktop\QQNetBar.exeExplorer.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Resource Compiler
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Total events
1 699
Read events
1 674
Write events
25
Delete events
0

Modification events

(PID) Process:(2156) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2156) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2156) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2156) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(2156) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(2156) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\timo.rar
(PID) Process:(2156) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2156) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2156) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2156) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
Executable files
4
Suspicious files
2
Text files
3
Unknown types
0

Dropped files

PID
Process
Filename
Type
2156WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2156.36261\control.txttext
MD5:8CCEB2D6D64A8F2B02F5DA47D9E700E3
SHA256:A2EF818B0357FD1AD3563318EAC0DFB5FD5EE98654FD5EBC72FBC7C336E47CF8
2156WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2156.39732\temp.logbinary
MD5:89941E7BC31614E8AD59DB7DBC19DBD3
SHA256:D99568B16B7DEF7F104E0822EABA214D3159090BAE1AE725B3465F0EC561C08A
2156WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2156.39732\QQNetBar.exeexecutable
MD5:E40740A2502D943FF82EB23982158325
SHA256:2F4DE1BB6B5C6B22261A78C878FB25DB5564F1A17EA8E19101A4BE8877E1C21F
2156WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2156.36261\QQNetBar.exeexecutable
MD5:E40740A2502D943FF82EB23982158325
SHA256:2F4DE1BB6B5C6B22261A78C878FB25DB5564F1A17EA8E19101A4BE8877E1C21F
2156WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2156.39732\RcDLL.dllexecutable
MD5:AA6DB83F4AA830CF731E48D7680A2715
SHA256:C770E00FE2A55D160435CEBA6EA14C795032CFBA4DF9EBD0B53E14E55E5A9942
2156WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2156.39732\control.txttext
MD5:8CCEB2D6D64A8F2B02F5DA47D9E700E3
SHA256:A2EF818B0357FD1AD3563318EAC0DFB5FD5EE98654FD5EBC72FBC7C336E47CF8
2156WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2156.36261\RcDLL.dllexecutable
MD5:AA6DB83F4AA830CF731E48D7680A2715
SHA256:C770E00FE2A55D160435CEBA6EA14C795032CFBA4DF9EBD0B53E14E55E5A9942
2156WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2156.36261\temp.logbinary
MD5:89941E7BC31614E8AD59DB7DBC19DBD3
SHA256:D99568B16B7DEF7F104E0822EABA214D3159090BAE1AE725B3465F0EC561C08A
3824QQNetBar.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2156.36261\QQNetBar.initext
MD5:4B822938E9B9199F773F785AF0351737
SHA256:862F35A75268046F15CD11CCCC0C6C2EBE38348FD4D2FEE94566C15FA33D2BFE
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
3
DNS requests
1
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
103.98.112.249:5556
Ping Network Limited
HK
unknown
3824
QQNetBar.exe
103.98.112.249:5556
Ping Network Limited
HK
unknown

DNS requests

Domain
IP
Reputation
dns.msftncsi.com
  • 131.107.255.255
shared

Threats

No threats detected
No debug info