| File name: | RFQ - 5258 - SSEG SABIC#098787665.lzh |
| Full analysis: | https://app.any.run/tasks/7d9bcce9-28fa-4481-80a3-8d1c39057215 |
| Verdict: | Malicious activity |
| Analysis date: | July 17, 2019, 13:31:46 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-lzh-compressed |
| File info: | LHa (2.x) archive data [lh5], with "RFQ - 5258 - SSEG SABIC#098787665.PIF" |
| MD5: | 1E670CEFF5E6C1A10A158F09527666AE |
| SHA1: | 99EC8C8857F3AA16E12A543D0698CA4F7F658F8C |
| SHA256: | 6DD63D40E00C3558D4F7278B0C9BEEB1E67A377C2259CE323D1B84CC6E631BDC |
| SSDEEP: | 12288:0UquekVDKUvUSoRXYxv72k0A5kbQOHP4eC9wfo2NoKnj0JwXTjNr:02sRRX4yk0jQveCCQkoKnjswX31 |
| .lzh/lha | | | LHARC/LZARK compressed archive (generic) (100) |
|---|
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1356 | "C:\Users\admin\Desktop\RFQ - 5258 - SSEG SABIC#098787665.PIF" | C:\Users\admin\Desktop\RFQ - 5258 - SSEG SABIC#098787665.PIF | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 2904 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\RFQ - 5258 - SSEG SABIC#098787665.lzh" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.60.0 Modules
| |||||||||||||||
| (PID) Process: | (2904) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (2904) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (2904) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\70\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2904) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\RFQ - 5258 - SSEG SABIC#098787665.lzh | |||
| (PID) Process: | (2904) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (2904) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (2904) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (2904) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (2904) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\70\52C64B7E |
| Operation: | write | Name: | @C:\Windows\System32\acppage.dll,-6005 |
Value: Shortcut to MS-DOS Program | |||
| (PID) Process: | (2904) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\DialogEditHistory\ExtrPath |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2904 | WinRAR.exe | C:\Users\admin\Desktop\RFQ - 5258 - SSEG SABIC#098787665.PIF | executable | |
MD5:— | SHA256:— | |||