| File name: | 1047.rar |
| Full analysis: | https://app.any.run/tasks/07a92ef0-c8bd-4a15-90c7-c9163b8d8e26 |
| Verdict: | Malicious activity |
| Analysis date: | March 29, 2025, 12:15:48 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-rar |
| File info: | RAR archive data, v5 |
| MD5: | C5103D182AAD4D4C516326DE8C8832D1 |
| SHA1: | DC51612F71E301AFEF7FE11566423EAB1FC31FA7 |
| SHA256: | 667DA55DC9EFBC97906D72EEFD9A260BCA80212C8B79D0D36CBC777D3EA0C761 |
| SSDEEP: | 49152:6mhxnEG/cFVjZz9G034qiGRUQjG084f42FS1R5Mk1RH2ZPOEfSxmUzSs+uBje0on:6mLEccL9J5IpGpjLxAlHu2OScsJjee4L |
| .rar | | | RAR compressed archive (v5.0) (61.5) |
|---|---|---|
| .rar | | | RAR compressed archive (gen) (38.4) |
| FileVersion: | RAR v5 |
|---|---|
| CompressedSize: | 881 |
| UncompressedSize: | 1905 |
| OperatingSystem: | Win32 |
| ArchivedFileName: | Read me!!!.txt |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1132 | "C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEvent | C:\Windows\System32\slui.exe | SppExtComObj.Exe | ||||||||||||
User: NETWORK SERVICE Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows Activation Client Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2284 | "C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\1047.rar | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| 2384 | C:\WINDOWS\system32\SppExtComObj.exe -Embedding | C:\Windows\System32\SppExtComObj.Exe | — | svchost.exe | |||||||||||
User: NETWORK SERVICE Company: Microsoft Corporation Integrity Level: SYSTEM Description: KMS Connection Broker Version: 10.0.19041.3996 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2984 | "C:\Program Files\CPUID\HWMonitorPro\HWMonitorPro.exe" | C:\Program Files\CPUID\HWMonitorPro\HWMonitorPro.exe | explorer.exe | ||||||||||||
User: admin Company: CPUID Integrity Level: HIGH Description: Hardware Monitor PRO Version: 1, 5, 4, 0 Modules
| |||||||||||||||
| 3676 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa2284.37465\hwmonitor-pro_1.54.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa2284.37465\hwmonitor-pro_1.54.exe | WinRAR.exe | ||||||||||||
User: admin Company: CPUID, Inc. Integrity Level: HIGH Description: CPUID HWMonitor Pro Setup Exit code: 0 Version: 1.54.0.0 Modules
| |||||||||||||||
| 4896 | "C:\Users\admin\AppData\Local\Temp\is-S6OC1.tmp\hwmonitor-pro_1.54.tmp" /SL5="$60262,1326014,193024,C:\Users\admin\AppData\Local\Temp\Rar$EXa2284.37465\hwmonitor-pro_1.54.exe" | C:\Users\admin\AppData\Local\Temp\is-S6OC1.tmp\hwmonitor-pro_1.54.tmp | hwmonitor-pro_1.54.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 Modules
| |||||||||||||||
| 4896 | C:\WINDOWS\System32\slui.exe -Embedding | C:\Windows\System32\slui.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Activation Client Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6240 | "C:\Program Files\CPUID\HWMonitorPro\HWMonitorPro.exe" | C:\Program Files\CPUID\HWMonitorPro\HWMonitorPro.exe | — | explorer.exe | |||||||||||
User: admin Company: CPUID Integrity Level: MEDIUM Description: Hardware Monitor PRO Exit code: 3221226540 Version: 1, 5, 4, 0 Modules
| |||||||||||||||
| 6652 | "C:\WINDOWS\system32\NOTEPAD.EXE" C:\Program Files\CPUID\HWMonitorPro\hwmpro_readme.txt | C:\Windows\SysWOW64\notepad.exe | — | hwmonitor-pro_1.54.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Notepad Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6808 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa2284.37465\hwmonitor-pro_1.54.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa2284.37465\hwmonitor-pro_1.54.exe | — | WinRAR.exe | |||||||||||
User: admin Company: CPUID, Inc. Integrity Level: MEDIUM Description: CPUID HWMonitor Pro Setup Exit code: 3221226540 Version: 1.54.0.0 Modules
| |||||||||||||||
| (PID) Process: | (2284) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\preferences.zip | |||
| (PID) Process: | (2284) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\chromium_ext.zip | |||
| (PID) Process: | (2284) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\omni_23_10_2024_.zip | |||
| (PID) Process: | (2284) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\1047.rar | |||
| (PID) Process: | (2284) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (2284) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (2284) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (2284) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (4896) hwmonitor-pro_1.54.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\CPUID\HWMonitor Pro |
| Operation: | write | Name: | PATH |
Value: C:\Program Files\CPUID\HWMonitorPro | |||
| (PID) Process: | (4896) hwmonitor-pro_1.54.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\CPUID\HWMonitor Pro |
| Operation: | write | Name: | PRODUCT_NAME |
Value: CPUID HWMonitor Pro | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2284 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2284.37465\大眼仔旭.url | binary | |
MD5:2F74C020629E7811256214881F88C8FC | SHA256:25F652E1D42F07304510A9A900D15DC169DAC8D44DBE50E92BAAA6AB85AF2F1C | |||
| 2284 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2284.37465\hwmonitor-pro_1.54.exe | executable | |
MD5:5581F67EF09665F8E95FB1C1802DC303 | SHA256:BF333FE1D9DAE25C96034D70B4DD156E73695323033A8D026BD25E8D5B4A540C | |||
| 4896 | hwmonitor-pro_1.54.tmp | C:\Users\admin\AppData\Local\Temp\is-UH36V.tmp\_isetup\_setup64.tmp | executable | |
MD5:4FF75F505FDDCC6A9AE62216446205D9 | SHA256:A4C86FC4836AC728D7BD96E7915090FD59521A9E74F1D06EF8E5A47C8695FD81 | |||
| 4896 | hwmonitor-pro_1.54.tmp | C:\Users\admin\AppData\Local\CPUID\hwmpro.pvk | binary | |
MD5:70CD06CA446C654FEB405E3DC6B25C27 | SHA256:249F9B170BE0E269888B9756FA2790329732B4ED6A16218C7C37B52861AEED4F | |||
| 4896 | hwmonitor-pro_1.54.tmp | C:\Program Files\CPUID\HWMonitorPro\is-U0MES.tmp | executable | |
MD5:B1BF203A8B8A7FB1A2763EBD48C6AD3F | SHA256:4B984F0F8E04DF5C2E2D31507FDCCEDFFFEA9396EC7D1DAE6EBC87929086FF95 | |||
| 4896 | hwmonitor-pro_1.54.tmp | C:\Users\admin\AppData\Local\CPUID\is-A3UFH.tmp | binary | |
MD5:70CD06CA446C654FEB405E3DC6B25C27 | SHA256:249F9B170BE0E269888B9756FA2790329732B4ED6A16218C7C37B52861AEED4F | |||
| 4896 | hwmonitor-pro_1.54.tmp | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CPUID\HWMonitorPro\HWMonitorPro.lnk | binary | |
MD5:CCF6590EC983EC333B3421B7A612DA77 | SHA256:405675BC2053E31F233B612D26AEE94989C32D020911FA4D0C7CFB43E941EAAB | |||
| 4896 | hwmonitor-pro_1.54.tmp | C:\Program Files\CPUID\HWMonitorPro\is-DKUD3.tmp | text | |
MD5:34C64DE777954AE9291A76DF094E2EDC | SHA256:23833042F6841DB54E62320A070ECFAA78C1C42B8679ED7F8DB0B59DF02FC207 | |||
| 4896 | hwmonitor-pro_1.54.tmp | C:\Program Files\CPUID\HWMonitorPro\is-91O8H.tmp | executable | |
MD5:AFC06106ACAD078F85FCB11BD4ABE6AB | SHA256:F7017AE621547E90D842A1795CE9D6CB75023BC090323D4E3E4B39DED9394DCD | |||
| 4896 | hwmonitor-pro_1.54.tmp | C:\Program Files\CPUID\HWMonitorPro\HWMonitorPro_eula.pdf | ||
MD5:B936904192413690BB6B6484CE914866 | SHA256:D49E96B71AC313605AA4655F542FAEDCDB30CEB87B7C17978D1835B0809DA11E | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
6544 | svchost.exe | GET | 200 | 2.17.190.73:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
5988 | SIHClient.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
5496 | MoUsoCoreWorker.exe | GET | 200 | 23.48.23.143:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
5988 | SIHClient.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
2984 | HWMonitorPro.exe | GET | 200 | 69.192.161.44:80 | http://x1.c.lencr.org/ | unknown | — | — | whitelisted |
2984 | HWMonitorPro.exe | GET | 200 | 184.24.77.65:80 | http://e6.o.lencr.org/MFMwUTBPME0wSzAJBgUrDgMCGgUABBTUejiAQejpjQc4fOz2ttjyD6VkMQQUDcXM%2FZvuFAWhTDCCpT5eisNYCdICEgQv1v6rfCQxhsjSOx5Zij8FwQ%3D%3D | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
5496 | MoUsoCoreWorker.exe | 23.48.23.143:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
6544 | svchost.exe | 20.190.160.131:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
6544 | svchost.exe | 2.17.190.73:80 | ocsp.digicert.com | AKAMAI-AS | DE | whitelisted |
2104 | svchost.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
5988 | SIHClient.exe | 4.245.163.56:443 | slscr.update.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
5988 | SIHClient.exe | 184.30.21.171:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
5988 | SIHClient.exe | 13.85.23.206:443 | fe3cr.delivery.mp.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
login.live.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
fe3cr.delivery.mp.microsoft.com |
| whitelisted |
ntps1-1.uni-erlangen.de |
| whitelisted |