File name:

TinyWinRAR.7z

Full analysis: https://app.any.run/tasks/4ef0fe98-fd5b-4032-a9f2-abca5198ed06
Verdict: Malicious activity
Analysis date: May 16, 2025, 17:00:46
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
arch-exec
upx
Indicators:
MIME: application/x-7z-compressed
File info: 7-zip archive data, version 0.4
MD5:

E39CE6A9A27819F94207290CB49C0D95

SHA1:

E1CAC4EB10D9B46F6EF9519FF0C7AAB0691CA1AC

SHA256:

5FFD9E6AA480D96F8B865AA521B20F9A74E08B61E66DD131B54C827B37886A60

SSDEEP:

49152:DD6qzZJkKHjBWa6G+EkhiMMgGSpJoHkEy1HA+5/mZqmv5CHskeCeSewpsFmNrPsc:Hzfk6jQQkhiHgtp2HkvA+5eBoeaeFEak

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads Microsoft Outlook installation path

      • TinyWinRAR.exe (PID: 1228)
    • Reads security settings of Internet Explorer

      • TinyWinRAR.exe (PID: 1228)
      • Uninstall.exe (PID: 5344)
    • Reads Internet Explorer settings

      • TinyWinRAR.exe (PID: 1228)
    • There is functionality for taking screenshot (YARA)

      • TinyWinRAR.exe (PID: 1228)
    • Executable content was dropped or overwritten

      • TinyWinRAR.exe (PID: 1228)
    • Creates a software uninstall entry

      • Uninstall.exe (PID: 5344)
    • Executes application which crashes

      • WinRAR.exe (PID: 4932)
      • WinRAR.exe (PID: 2092)
    • Creates/Modifies COM task schedule object

      • Uninstall.exe (PID: 5344)
  • INFO

    • Reads the computer name

      • TinyWinRAR.exe (PID: 1228)
      • Uninstall.exe (PID: 5344)
    • Manual execution by a user

      • TinyWinRAR.exe (PID: 5936)
      • TinyWinRAR.exe (PID: 1228)
      • WinRAR.exe (PID: 4932)
      • WinRAR.exe (PID: 2092)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2152)
    • Checks supported languages

      • TinyWinRAR.exe (PID: 1228)
      • WinRAR.exe (PID: 4932)
      • Uninstall.exe (PID: 5344)
    • Checks proxy server information

      • TinyWinRAR.exe (PID: 1228)
    • Creates files or folders in the user directory

      • TinyWinRAR.exe (PID: 1228)
      • Uninstall.exe (PID: 5344)
      • WerFault.exe (PID: 5256)
      • WerFault.exe (PID: 6108)
    • Creates files in the program directory

      • TinyWinRAR.exe (PID: 1228)
      • Uninstall.exe (PID: 5344)
    • UPX packer has been detected

      • TinyWinRAR.exe (PID: 1228)
    • The sample compiled with english language support

      • TinyWinRAR.exe (PID: 1228)
    • Process checks computer location settings

      • TinyWinRAR.exe (PID: 1228)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.7z | 7-Zip compressed archive (v0.4) (57.1)
.7z | 7-Zip compressed archive (gen) (42.8)

EXIF

ZIP

FileVersion: 7z v0.04
ModifyDate: 2025:05:16 21:38:15+00:00
ArchivedFileName: TinyWinRAR.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
187
Monitored processes
32
Malicious processes
2
Suspicious processes
2

Behavior graph

Click at the process to see the details
start winrar.exe sppextcomobj.exe no specs slui.exe tinywinrar.exe no specs tinywinrar.exe uninstall.exe no specs rundll32.exe no specs winrar.exe werfault.exe no specs werfault.exe no specs werfault.exe no specs werfault.exe no specs werfault.exe no specs werfault.exe no specs werfault.exe no specs werfault.exe no specs werfault.exe no specs werfault.exe no specs werfault.exe no specs slui.exe no specs winrar.exe werfault.exe no specs werfault.exe no specs werfault.exe no specs werfault.exe no specs werfault.exe no specs werfault.exe no specs werfault.exe no specs werfault.exe no specs werfault.exe no specs werfault.exe no specs werfault.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
780C:\WINDOWS\SysWOW64\WerFault.exe -u -p 2092 -s 696C:\Windows\SysWOW64\WerFault.exeWinRAR.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\combase.dll
1128C:\WINDOWS\SysWOW64\WerFault.exe -u -p 2092 -s 772C:\Windows\SysWOW64\WerFault.exeWinRAR.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\combase.dll
1228"C:\Users\admin\Desktop\TinyWinRAR.exe" C:\Users\admin\Desktop\TinyWinRAR.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\desktop\tinywinrar.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acgenral.dll
1272C:\WINDOWS\SysWOW64\WerFault.exe -u -p 4932 -s 640C:\Windows\SysWOW64\WerFault.exeWinRAR.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\combase.dll
1300C:\WINDOWS\SysWOW64\WerFault.exe -u -p 4932 -s 760C:\Windows\SysWOW64\WerFault.exeWinRAR.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\combase.dll
1348C:\WINDOWS\SysWOW64\WerFault.exe -u -p 4932 -s 784C:\Windows\SysWOW64\WerFault.exeWinRAR.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\combase.dll
2092"C:\Program Files (x86)\WinRAR\WinRAR.exe" C:\Program Files (x86)\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Modules
Images
c:\program files (x86)\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\advapi32.dll
c:\windows\syswow64\msvcrt.dll
2152"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\Desktop\TinyWinRAR.7zC:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
3396C:\WINDOWS\SysWOW64\WerFault.exe -u -p 2092 -s 752C:\Windows\SysWOW64\WerFault.exeWinRAR.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\combase.dll
4056C:\WINDOWS\SysWOW64\WerFault.exe -u -p 2092 -s 752C:\Windows\SysWOW64\WerFault.exeWinRAR.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\combase.dll
Total events
42 390
Read events
42 121
Write events
215
Delete events
54

Modification events

(PID) Process:(2152) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(2152) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(2152) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(2152) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\TinyWinRAR.7z
(PID) Process:(2152) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2152) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2152) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2152) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2152) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF3D0000002D000000FD03000016020000
(PID) Process:(2152) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\ArcColumnWidths
Operation:writeName:name
Value:
256
Executable files
23
Suspicious files
73
Text files
24
Unknown types
2

Dropped files

PID
Process
Filename
Type
1228TinyWinRAR.exeC:\Program Files (x86)\WinRAR\Formats\7z.fmtexecutable
MD5:073D9B294D9385B72D6F5C28B6C5045B
SHA256:99B3F8B26B9B38677B3010823BFE6EEC8AA381352E1ECDF8B8212A235212A057
1228TinyWinRAR.exeC:\Program Files (x86)\WinRAR\Formats\iso.fmtexecutable
MD5:8CD5B466FA733BCD230307BFA1499C70
SHA256:E4D4478FF05EAC2E3104BB0564112939310323FB3944B0E135C271D36FE80E38
1228TinyWinRAR.exeC:\Program Files (x86)\WinRAR\Formats\gz.fmtexecutable
MD5:143EBBA82DDC234ECF8B031A181FB9F0
SHA256:B4DB99948BEAEA1DECCF0ED792F3DDC4F87FCE709A72E37A8E8DAD1FD4735A66
1228TinyWinRAR.exeC:\Program Files (x86)\WinRAR\Rar.exeexecutable
MD5:8DC6DCCD64781DF4200F25560A7D4BD2
SHA256:A165BAD0429A1721D83136D78C36DF0BDE7788ACD9564C2162E5610D8B6694BD
1228TinyWinRAR.exeC:\Program Files (x86)\WinRAR\Formats\cab.fmtexecutable
MD5:FEF29A05CE777D26192F610BEED3B9C4
SHA256:28E967CC03A6DF9BECD6C4B9E996C7007D5C4811FA3AC83FAE2C2D82794ABC88
1228TinyWinRAR.exeC:\Program Files (x86)\WinRAR\Uninstall.exeexecutable
MD5:0A899BCCFDA1A2A68F0E78A477F0F4B6
SHA256:2B8B011047FBF1C3B7892F2AE61CC92820C8BD1B07C92D6345198D1F5158AA76
1228TinyWinRAR.exeC:\Program Files (x86)\WinRAR\Formats\uue.fmtexecutable
MD5:1A80DA39B411E57574862BF9C8912018
SHA256:88BCA7DEF49081BA013B60385E2EAC63B1B17BEA9B76C788FB314DE522406ED6
1228TinyWinRAR.exeC:\Program Files (x86)\WinRAR\Formats\arj.fmtexecutable
MD5:307CB06117C94D100225274A87496EAB
SHA256:5288BAA91884C3E244E8B330E59F5C8CCFF7F4172E0DF34E516D9A771BCD6804
1228TinyWinRAR.exeC:\Program Files (x86)\WinRAR\Formats\lzh.fmtexecutable
MD5:01592954E9B7D77C0DD07534845F69A6
SHA256:0C52535A16CFA412EB507F52D696AAB4F6DB78E90F280AF87459A3F718630639
1228TinyWinRAR.exeC:\Program Files (x86)\WinRAR\Formats\ace.fmtexecutable
MD5:3ACE38AA2FDA854692E160D9B7658F57
SHA256:CB554F4E39C63ED79FC29A105096BE05873833F643E1FBF4988A26A9A42FCF24
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
9
TCP/UDP connections
29
DNS requests
24
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5496
MoUsoCoreWorker.exe
GET
200
23.52.120.96:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
23.48.23.146:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
23.52.120.96:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6544
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6068
SIHClient.exe
GET
200
23.52.120.96:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
6068
SIHClient.exe
GET
200
23.52.120.96:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
2924
SearchApp.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
2924
SearchApp.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
2924
SearchApp.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEApDqVCbATUviZV57HIIulA%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
23.48.23.146:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
23.52.120.96:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
5496
MoUsoCoreWorker.exe
23.52.120.96:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
3216
svchost.exe
172.211.123.250:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
6544
svchost.exe
20.190.160.5:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6544
svchost.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
2104
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
whitelisted
crl.microsoft.com
  • 23.48.23.146
  • 23.48.23.149
  • 23.48.23.140
  • 23.48.23.135
  • 23.48.23.148
  • 23.48.23.147
  • 23.48.23.195
  • 23.48.23.138
  • 23.48.23.139
whitelisted
www.microsoft.com
  • 23.52.120.96
whitelisted
google.com
  • 142.250.185.174
whitelisted
client.wns.windows.com
  • 172.211.123.250
whitelisted
login.live.com
  • 20.190.160.5
  • 40.126.32.136
  • 20.190.160.65
  • 20.190.160.67
  • 20.190.160.17
  • 20.190.160.14
  • 20.190.160.128
  • 20.190.160.20
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
slscr.update.microsoft.com
  • 20.109.210.53
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 40.69.42.241
whitelisted
activation-v2.sls.microsoft.com
  • 40.91.76.224
whitelisted

Threats

No threats detected
No debug info