File name: | RFQ - 5258 - SSEG SABIC#098787665.lzh |
Full analysis: | https://app.any.run/tasks/7d9bcce9-28fa-4481-80a3-8d1c39057215 |
Verdict: | Malicious activity |
Analysis date: | July 17, 2019, 13:31:46 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | application/x-lzh-compressed |
File info: | LHa (2.x) archive data [lh5], with "RFQ - 5258 - SSEG SABIC#098787665.PIF" |
MD5: | 1E670CEFF5E6C1A10A158F09527666AE |
SHA1: | 99EC8C8857F3AA16E12A543D0698CA4F7F658F8C |
SHA256: | 6DD63D40E00C3558D4F7278B0C9BEEB1E67A377C2259CE323D1B84CC6E631BDC |
SSDEEP: | 12288:0UquekVDKUvUSoRXYxv72k0A5kbQOHP4eC9wfo2NoKnj0JwXTjNr:02sRRX4yk0jQveCCQkoKnjswX31 |
.lzh/lha | | | LHARC/LZARK compressed archive (generic) (100) |
---|
PID | CMD | Path | Indicators | Parent process |
---|---|---|---|---|
2904 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\RFQ - 5258 - SSEG SABIC#098787665.lzh" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | |
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Version: 5.60.0 | ||||
1356 | "C:\Users\admin\Desktop\RFQ - 5258 - SSEG SABIC#098787665.PIF" | C:\Users\admin\Desktop\RFQ - 5258 - SSEG SABIC#098787665.PIF | — | explorer.exe |
User: admin Integrity Level: MEDIUM |
(PID) Process: | (2904) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
Operation: | write | Name: | ShellExtBMP |
Value: | |||
(PID) Process: | (2904) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
Operation: | write | Name: | ShellExtIcon |
Value: | |||
(PID) Process: | (2904) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\70\52C64B7E |
Operation: | write | Name: | LanguageList |
Value: en-US | |||
(PID) Process: | (2904) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\RFQ - 5258 - SSEG SABIC#098787665.lzh | |||
(PID) Process: | (2904) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | name |
Value: 120 | |||
(PID) Process: | (2904) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | size |
Value: 80 | |||
(PID) Process: | (2904) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | type |
Value: 120 | |||
(PID) Process: | (2904) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | mtime |
Value: 100 | |||
(PID) Process: | (2904) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\70\52C64B7E |
Operation: | write | Name: | @C:\Windows\System32\acppage.dll,-6005 |
Value: Shortcut to MS-DOS Program | |||
(PID) Process: | (2904) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\DialogEditHistory\ExtrPath |
Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop |
PID | Process | Filename | Type | |
---|---|---|---|---|
2904 | WinRAR.exe | C:\Users\admin\Desktop\RFQ - 5258 - SSEG SABIC#098787665.PIF | executable | |
MD5:C7F6499801CDB8D75C72A5011D9AB06C | SHA256:8D609CDC1F6C6DAB0738BF236F182AF9EB042F51BE18044BB248A247DE663416 |