analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

File_Setup_Pass_1234.rar

Full analysis: https://app.any.run/tasks/74a95a28-335b-44a2-8a9a-635475caf772
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: May 21, 2022, 10:25:30
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
loader
stealer
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

41DEA84C2FCB05C4A3B30F8366006F62

SHA1:

3C956D1D73915D02CE79901661332D5670383581

SHA256:

639F5D7D13AF72E08FE10A584AFBE62AC4F508A8EEA9FB0923597599C21E5925

SSDEEP:

98304:DCOrktHAyv5u5yY8Cjq/Z6tY89OnQEALRclDmKrHisfs5o0hc9gt/AxQoU2EsLWE:GwlyvtWm/Z6tN9OnX9BrC8yr/AxQZkt3

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Setup.exe (PID: 2348)
      • Setup.exe (PID: 2944)
    • Drops executable file immediately after starts

      • WinRAR.exe (PID: 3036)
      • Setup.exe (PID: 2944)
    • Loads dropped or rewritten executable

      • Setup.exe (PID: 2944)
    • Actions looks like stealing of personal data

      • Setup.exe (PID: 2944)
    • Stealing of credential data

      • Setup.exe (PID: 2944)
    • Steals credentials from Web Browsers

      • Setup.exe (PID: 2944)
  • SUSPICIOUS

    • Checks supported languages

      • WinRAR.exe (PID: 3036)
      • Setup.exe (PID: 2944)
    • Reads the computer name

      • WinRAR.exe (PID: 3036)
      • Setup.exe (PID: 2944)
    • Drops a file with a compile date too recent

      • WinRAR.exe (PID: 3036)
      • Setup.exe (PID: 2944)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3036)
      • Setup.exe (PID: 2944)
    • Reads Environment values

      • Setup.exe (PID: 2944)
    • Reads the cookies of Mozilla Firefox

      • Setup.exe (PID: 2944)
    • Reads the cookies of Google Chrome

      • Setup.exe (PID: 2944)
    • Searches for installed software

      • Setup.exe (PID: 2944)
  • INFO

    • Manual execution by user

      • Setup.exe (PID: 2944)
      • Setup.exe (PID: 2348)
    • Dropped object may contain Bitcoin addresses

      • Setup.exe (PID: 2944)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
40
Monitored processes
3
Malicious processes
1
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe setup.exe no specs setup.exe

Process information

PID
CMD
Path
Indicators
Parent process
3036"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\File_Setup_Pass_1234.rar"C:\Program Files\WinRAR\WinRAR.exe
Explorer.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
2348"C:\Users\admin\Desktop\Setup.exe" C:\Users\admin\Desktop\Setup.exeExplorer.EXE
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
2944"C:\Users\admin\Desktop\Setup.exe" C:\Users\admin\Desktop\Setup.exe
Explorer.EXE
User:
admin
Integrity Level:
HIGH
Exit code:
0
Total events
2 198
Read events
2 156
Write events
42
Delete events
0

Modification events

(PID) Process:(3036) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3036) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3036) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3036) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(3036) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(3036) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\File_Setup_Pass_1234.rar
(PID) Process:(3036) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3036) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3036) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3036) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
Executable files
9
Suspicious files
1
Text files
2
Unknown types
6

Dropped files

PID
Process
Filename
Type
2944Setup.exeC:\Users\admin\AppData\LocalLow\nssdbm3.dllexecutable
MD5:FDC6551687F1D915994DFFA27B3B9044
SHA256:844F878AABB7E3C06986DD6879912BB403ECB81B1CFB13E95CAF9CBD350713AE
3036WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb3036.40091\Setup.exeexecutable
MD5:ADA1CF2FB2812726F5DE2F8172DA8DED
SHA256:12E81B998B37955C4E028A9F46378B8B664646E3CC5F177A867321C54AF30CA3
2944Setup.exeC:\Users\admin\AppData\LocalLow\8OtZg3Kuh0mOimage
MD5:8A649D28F38EACABD6B6382701189B13
SHA256:225380C2A84407618A5865B10D45B4B05A127175F401F140837EA2B744362C21
2944Setup.exeC:\Users\admin\AppData\LocalLow\28sd8uD67I9Ysqlite
MD5:D02907BE1C995E1E51571EEDB82FA281
SHA256:2189977F6EA58BDAD5883720B099E12B869F223FB9B18AC40E7D37C5954A55DD
2944Setup.exeC:\Users\admin\AppData\LocalLow\softokn3.dllexecutable
MD5:63A1FE06BE877497C4C2017CA0303537
SHA256:44BE3153C15C2D18F49674A092C135D3482FB89B77A1B2063D01D02985555FE0
2944Setup.exeC:\Users\admin\AppData\LocalLow\IF3A8UJ12bkt-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
2944Setup.exeC:\Users\admin\AppData\LocalLow\46391n79jDJtsqlite
MD5:D02907BE1C995E1E51571EEDB82FA281
SHA256:2189977F6EA58BDAD5883720B099E12B869F223FB9B18AC40E7D37C5954A55DD
2944Setup.exeC:\Users\admin\AppData\LocalLow\mozglue.dllexecutable
MD5:F07D9977430E762B563EAADC2B94BBFA
SHA256:4191FAF7E5EB105A0F4C5C6ED3E9E9C71014E8AA39BBEE313BC92D1411E9E862
2944Setup.exeC:\Users\admin\AppData\LocalLow\IF3A8UJ12bktsqlite
MD5:23D08A78BC908C0B29E9800D3D5614E7
SHA256:F6BD7DF5DFAE9FD88811A807DBA14085E00C1B5A6D7CC3D06CC68F6015363D59
2944Setup.exeC:\Users\admin\AppData\LocalLow\freebl3.dllexecutable
MD5:15B61E4A910C172B25FB7D8CCB92F754
SHA256:B2AE93D30C8BEB0B26F03D4A8325AC89B92A299E8F853E5CAA51BB32575B06C6
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
13
TCP/UDP connections
2
DNS requests
0
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2944
Setup.exe
GET
200
94.158.247.44:80
http://94.158.247.44/aN7jD0qO6kT5bK5bQ4eR8fE1xP7hL2vK/mozglue.dll
unknown
executable
612 Kb
suspicious
2944
Setup.exe
GET
200
94.158.247.44:80
http://94.158.247.44/aN7jD0qO6kT5bK5bQ4eR8fE1xP7hL2vK/softokn3.dll
unknown
executable
248 Kb
suspicious
2944
Setup.exe
POST
200
194.180.174.180:80
http://194.180.174.180/
DE
text
4.34 Kb
malicious
2944
Setup.exe
GET
200
94.158.247.44:80
http://94.158.247.44/aN7jD0qO6kT5bK5bQ4eR8fE1xP7hL2vK/nssdbm3.dll
unknown
executable
90.6 Kb
suspicious
2944
Setup.exe
GET
200
94.158.247.44:80
http://94.158.247.44/aN7jD0qO6kT5bK5bQ4eR8fE1xP7hL2vK/vcruntime140.dll
unknown
executable
81.8 Kb
suspicious
2944
Setup.exe
GET
200
94.158.247.44:80
http://94.158.247.44/aN7jD0qO6kT5bK5bQ4eR8fE1xP7hL2vK/nss3.dll
unknown
executable
1.95 Mb
suspicious
2944
Setup.exe
POST
200
194.180.174.180:80
http://194.180.174.180/c220754b0a505fed781976e610c32f9c
DE
text
8 b
malicious
2944
Setup.exe
GET
200
94.158.247.44:80
http://94.158.247.44/aN7jD0qO6kT5bK5bQ4eR8fE1xP7hL2vK/sqlite3.dll
unknown
executable
1.05 Mb
suspicious
2944
Setup.exe
GET
200
94.158.247.44:80
http://94.158.247.44/aN7jD0qO6kT5bK5bQ4eR8fE1xP7hL2vK/msvcp140.dll
unknown
executable
438 Kb
suspicious
2944
Setup.exe
GET
200
94.158.247.44:80
http://94.158.247.44/aN7jD0qO6kT5bK5bQ4eR8fE1xP7hL2vK/freebl3.dll
unknown
executable
668 Kb
suspicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2944
Setup.exe
194.180.174.180:80
DE
malicious
2944
Setup.exe
94.158.247.44:80
suspicious

DNS requests

No data

Threats

PID
Process
Class
Message
2944
Setup.exe
Potentially Bad Traffic
ET INFO Dotted Quad Host DLL Request
2944
Setup.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
2944
Setup.exe
Potentially Bad Traffic
ET INFO Dotted Quad Host DLL Request
2944
Setup.exe
Potentially Bad Traffic
ET INFO Dotted Quad Host DLL Request
2944
Setup.exe
Potentially Bad Traffic
ET INFO Dotted Quad Host DLL Request
2944
Setup.exe
Potentially Bad Traffic
ET INFO Dotted Quad Host DLL Request
2944
Setup.exe
Potentially Bad Traffic
ET INFO Dotted Quad Host DLL Request
2944
Setup.exe
Potentially Bad Traffic
ET INFO Dotted Quad Host DLL Request
2944
Setup.exe
Potentially Bad Traffic
ET INFO Dotted Quad Host DLL Request
Process
Message
Setup.exe
response:
Setup.exe
libs_nss3:http://94.158.247.44/aN7jD0qO6kT5bK5bQ4eR8fE1xP7hL2vK/nss3.dll libs_msvcp140:http://94.158.247.44/aN7jD0qO6kT5bK5bQ4eR8fE1xP7hL2vK/msvcp140.dll libs_vcruntime140:http://94.158.247.44/aN7jD0qO6kT5bK5bQ4eR8fE1xP7hL2vK/vcruntime140.dll libs_mozglue:http://94.158.247.44/aN7jD0qO6kT5bK5bQ4eR8fE1xP7hL2vK/mozglue.dll libs_freebl3:http://94.158.247.44/aN7jD0qO6kT5bK5bQ4eR8fE1xP7hL2vK/freebl3.dll libs_softokn3:http://94.158.247.44/aN7jD0qO6kT5bK5bQ4eR8fE1xP7hL2vK/softokn3.dll ews_meta_e:ejbalbakoplchlghecdalmeeeajnimhm;MetaMask;Local Extension Settings ews_tronl:ibnejdfjmmkpcnlpebklmnkoeoihofec;TronLink;Local Extension Settings libs_sqlite3:http://94.158.247.44/aN7jD0qO6kT5bK5bQ4eR8fE1xP7hL2vK/sqlite3.dll ews_bsc:fhbohimaelbohpjbbldcngcnapndodjp;BinanceChain;Local Extension Settings ews_ronin:fnjhmkhhmkbjkkabndcnnogagogbneec;Ronin;Local Extension Settings wlts_exodus:Exodus;26;exodus;*;*partitio*,*cache*,*dictionar* wlts_atomic:Atomic;26;atomic;*;*cache*,*IndexedDB* wlts_jaxxl:JaxxLiberty;26;com.liberty.jaxx;*;*cache* wlts_binance:Binance;26;Binance;*app-store.*;- wlts_coinomi:Coinomi;28;Coinomi\Coinomi\wallets;*;- wlts_electrum:Electrum;26;Electrum\wallets;*;- wlts_elecltc:Electrum-LTC;26;Electrum-LTC\wallets;*;- wlts_elecbch:ElectronCash;26;ElectronCash\wallets;*;- wlts_guarda:Guarda;26;Guarda;*;*cache*,*IndexedDB* wlts_green:BlockstreamGreen;28;Blockstream\Green;*;cache,gdk,*logs* wlts_ledger:Ledger Live;26;Ledger Live;*;*cache*,*dictionar*,*sqlite* ews_ronin_e:kjmoohlgokccodicjjfebfomlbljgfhk;Ronin;Local Extension Settings ews_meta:nkbihfbeogaeaoehlefnkodbefgpgknn;MetaMask;Local Extension Settings sstmnfo_System Info.txt:System Information: |Installed applications: | libs_nssdbm3:http://94.158.247.44/aN7jD0qO6kT5bK5bQ4eR8fE1xP7hL2vK/nssdbm3.dll wlts_daedalus:Daedalus;26;Daedalus Mainnet;*;log*,*cache,chain,dictionar* wlts_mymonero:MyMonero;26;MyMonero;*;*cache* wlts_xmr:Monero;5;Monero\\wallets;*.keys;- wlts_wasabi:Wasabi;26;WalletWasabi\\Client;*;*tor*,*log* ews_metax:mcohilncbfahbmgdjkbpemcciiolgcge;MetaX;Local Extension Settings ews_xdefi:hmeobnfnfcmdkdcmlblgagmfpfboieaf;XDEFI;IndexedDB ews_waveskeeper:lpilbniiabackdjcionkobglmddfbcjo;WavesKeeper;Local Extension Settings ews_solflare:bhhhlbepdkbapadjdnnojkbgioiodbic;Solflare;Local Extension Settings ews_rabby:acmacodkjbdgmoleebolmdjonilkdbch;Rabby;Local Extension Settings ews_cyano:dkdedlpgdmmkkfjabffeganieamfklkm;CyanoWallet;Local Extension Settings ews_coinbase:hnfanknocfeofbddgcijnmhnfnkdnaad;Coinbase;IndexedDB ews_auromina:cnmamaachppnkjgnildpdmkaakejnhae;AuroWallet;Local Extension Settings ews_khc:hcflpincpppdclinealmandijcmnkbgn;KHC;Local Extension Settings ews_tezbox:mnfifefkajgofkcjkemidiaecocnkjeh;TezBox;Local Extension Settings ews_coin98:aeachknmefphepccionboohckonoeemg;Coin98;Local Extension Settings ews_temple:ookjlbkiijinhpmnjffcofjonbfbgaoc;Temple;Local Extension Settings ews_iconex:flpiciilemghbmfalicajoolhkkenfel;ICONex;Local Extension Settings ews_sollet:fhmfendgdocmcbmfikdcogofphimnkno;Sollet;Local Extension Settings ews_clover:nhnkbkgjikgcigadomkphalanndcapjk;CloverWallet;Local Extension Settings ews_polymesh:jojhfeoedkpkglbfimdfabpdfjaoolaf;PolymeshWallet;Local Extension Settings ews_neoline:cphhlgmgameodnhkjdmkpanlelnlohao;NeoLine;Local Extension Settings ews_keplr:dmkamcknogkgcdfhhbddcghachkejeap;Keplr;Local Extension Settings ews_terra_e:ajkhoeiiokighlmdnlakpjfoobnjinie;TerraStation;Local Extension Settings ews_terra:aiifbnbfobpmeekipheeijimdpnlpgpp;TerraStation;Local Extension Settings ews_liquality:kpfopkelmapcoipemfendmdcghnegimn;Liquality;Local Extension Settings ews_saturn:nkddgncdjgjfcddamfgcmfnlhccnimig;SaturnWallet;Local Extension Settings ews_guild:nanjmdknhkinifnkgdcggcfnhdaammmj;GuildWallet;Local Extension Settings ews_phantom:bfnaelmomeimhlpmgjnjophhpkkoljpa;Phantom;Local Extension Settings ews_tronlink:ibnejdfjmmkpcnlpebklmnkoeoihofec;TronLink;Local Extension Settings ews_brave:odbfpeeihdkbihmopkbjmoonfanlbfcl;Brave;Local Extension Settings ews_meta_e:ejbalbakoplchlghecdalmeeeajnimhm;MetaMask;Local Extension Settings ews
Setup.exe
_ronin_e:kjmoohlgokccodicjjfebfomlbljgfhk;Ronin;Local Extension Settings ews_mewcx:nlbmnnijcnlegkjjpcfjclmcfggfefdm;MEW_CX;Sync Extension Settings ews_ton:cgeeodpfagjceefieflmdfphplkenlfk;TON;Local Extension Settings scrnsht_Screenshot.jpeg:1 tlgrm_Telegram:Telegram Desktop\tdata|*|*emoji*,*user_data*,*tdummy*,*dumps* token:c220754b0a505fed781976e610c32f9c
Setup.exe