File name:

Waircut V2.0.zip

Full analysis: https://app.any.run/tasks/147412b4-9c62-4743-8bfc-c3ed82a297b3
Verdict: No threats detected
Analysis date: February 09, 2019, 15:43:39
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

59AF5690B5FA9F0821D9A2581446300E

SHA1:

9458421C7F4437D60F6A6B092CF7BE91215E987B

SHA256:

67F2EA6607423920A9177FFE99933AE6E7C8EA852C6B58E0E482FE8B5B158C57

SSDEEP:

49152:txvfIKVG0MJfDZFkbB9zhStmAAkwgmyDwtIU77C4O4Ou22lSlV3Syth3h8TZo189:txvfFVG0MFF6VCabHyUtBC4O41YlV3St

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Waircut.exe (PID: 4036)
      • Waircut.exe (PID: 2992)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3028)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2018:05:15 19:19:01
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: Waircut V2.0/
No data.
screenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
35
Monitored processes
3
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
drop and start drop and start start winrar.exe waircut.exe no specs waircut.exe

Process information

PID
CMD
Path
Indicators
Parent process
2992"C:\Users\admin\AppData\Local\Temp\Rar$EXa3028.4900\Waircut V2.0\Waircut.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3028.4900\Waircut V2.0\Waircut.exeWinRAR.exe
User:
admin
Company:
Patcher
Integrity Level:
MEDIUM
Description:
waircut
Exit code:
3221226540
Version:
2.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3028.4900\waircut v2.0\waircut.exe
c:\systemroot\system32\ntdll.dll
3028"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Waircut V2.0.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
4036"C:\Users\admin\AppData\Local\Temp\Rar$EXa3028.4900\Waircut V2.0\Waircut.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3028.4900\Waircut V2.0\Waircut.exe
WinRAR.exe
User:
admin
Company:
Patcher
Integrity Level:
HIGH
Description:
waircut
Exit code:
0
Version:
2.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3028.4900\waircut v2.0\waircut.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
Total events
452
Read events
435
Write events
17
Delete events
0

Modification events

(PID) Process:(3028) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3028) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3028) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3028) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Waircut V2.0.zip
(PID) Process:(3028) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3028) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3028) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3028) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3028) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(3028) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
Executable files
6
Suspicious files
0
Text files
4
Unknown types
2

Dropped files

PID
Process
Filename
Type
3028WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3028.4900\Waircut V2.0\Bd\ApLog.dbsqlite
MD5:8B9F4E200FABD3D75D00EAB9AEDB3C2E
SHA256:8C115D8E85DCC74130A152ACE7F8BA65AE23FF6E1928F9D984B6B9F017A64C4D
3028WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3028.4900\Waircut V2.0\wAirCut.exe.configxml
MD5:38D8EBC77C915D5CF70AFB5BD5769AFB
SHA256:0ABAD5F4E905942EB27185D72C3A60DD6032B521B6F0100B36B2CFC8EC132644
3028WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3028.4900\Waircut V2.0\fr\Waircut.resources.dllexecutable
MD5:B5107672783AF3622B2515060B104EB1
SHA256:D235C67605725C4F732D5E0ACCB3C5671EA6681C77EB896874E11F20187D785F
3028WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3028.4900\Waircut V2.0\PixieWps\PixieWps.exeexecutable
MD5:2DE73A1D6D43C3CF9ED9AFC4792FC26E
SHA256:9657EFA0A8C63C8B53923BDC46980B85B7DDDC688FFF9F3C3A1C0545B045235A
3028WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3028.4900\Waircut V2.0\PixieWps\README.mdtext
MD5:0B0CCC1BF80E86E49ADF807B7151E2AD
SHA256:2C03A1AEA33F34954C8825290FDA075C0D0129D242AA944A8985AF779C1D53C0
3028WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3028.4900\Waircut V2.0\Waircut.exeexecutable
MD5:9D11A8641AAE3C20C2F39C89E75798AB
SHA256:600986E9892988BA772CE853C559FB7C28186E84422AF9AED53F2327F5FF45DE
3028WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3028.4900\Waircut V2.0\System.Data.SQLite.dllexecutable
MD5:DEAF98E10B82FC9BC2476A432724492F
SHA256:3CCAF0BF3B927ACEDA3645F0A592C2DB6B9AFB7680E766042BF9CA6D51774886
3028WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3028.4900\Waircut V2.0\PixieWps\LICENSE.mdtext
MD5:DEDCFD78CA4EAB2EFDF6A4C5BE1AB762
SHA256:CCB349B4132ED7737F25E5ADEBFE61F3D52DCA33708DF1E50352320438D1D4C2
3028WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3028.4900\Waircut V2.0\ChangeLog.txttext
MD5:AE7F9DF96C5304BA802BDB5B32476E48
SHA256:5CFD82232FC4603228C8F9AE239126B3FE6930150AFFEC8336D9ABA19DEE349D
3028WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3028.4900\Waircut V2.0\Bd\WpsProbePin.dbsqlite
MD5:1484B2BFFF2CFB2A6F02BCDC9713F079
SHA256:BE6C085B1A29D131C78D76EBDA033E7FDF434E152E81A97A87F5BFB41ED355F7
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info