File name:

VirtuallHardwares.rar

Full analysis: https://app.any.run/tasks/2218a3c4-35db-4019-86f6-fb9a08a1e9e0
Verdict: Malicious activity
Analysis date: August 02, 2021, 20:56:53
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v4, os: Win32
MD5:

389B0EEA794A59811FCF407BA2115F2B

SHA1:

C188EC39D630FCD2121442D383FD26A4AA426329

SHA256:

71D045697F3C9353104E58DC690A6F4E39663A7B37A53D3601CF0A3DF220ABC2

SSDEEP:

98304:BXnCEpCSBiArrhGLClURumfBy/z565P+pp6XMCxNEa1rmk0KumRdp/9:BS2hBiAfhWu+BYz565PRXLR5

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • hardware.exe (PID: 3248)
      • hardware.exe (PID: 1348)
  • SUSPICIOUS

    • Reads the computer name

      • WinRAR.exe (PID: 2236)
      • hardware.exe (PID: 3248)
    • Reads Windows Product ID

      • hardware.exe (PID: 3248)
    • Checks supported languages

      • WinRAR.exe (PID: 2236)
      • hardware.exe (PID: 3248)
    • Reads internet explorer settings

      • hardware.exe (PID: 3248)
    • Creates files in the user directory

      • hardware.exe (PID: 3248)
    • Executed via COM

      • iexplore.exe (PID: 704)
    • Reads the date of Windows installation

      • hardware.exe (PID: 3248)
    • Reads Microsoft Outlook installation path

      • hardware.exe (PID: 3248)
      • iexplore.exe (PID: 2884)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2236)
  • INFO

    • Checks Windows Trust Settings

      • hardware.exe (PID: 3248)
      • iexplore.exe (PID: 2884)
    • Checks supported languages

      • iexplore.exe (PID: 704)
      • iexplore.exe (PID: 2884)
    • Manual execution by user

      • hardware.exe (PID: 3248)
      • hardware.exe (PID: 1348)
    • Application launched itself

      • iexplore.exe (PID: 704)
    • Reads settings of System Certificates

      • hardware.exe (PID: 3248)
      • iexplore.exe (PID: 2884)
    • Reads the computer name

      • iexplore.exe (PID: 704)
      • iexplore.exe (PID: 2884)
    • Reads internet explorer settings

      • iexplore.exe (PID: 2884)
    • Reads the date of Windows installation

      • iexplore.exe (PID: 704)
    • Changes internet zones settings

      • iexplore.exe (PID: 704)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v-4.x) (58.3)
.rar | RAR compressed archive (gen) (41.6)

EXIF

ZIP

ArchivedFileName: VirtuallHardwares\GameHardware.exe
PackingMethod: Normal
ModifyDate: 2018:08:03 14:09:02
OperatingSystem: Win32
UncompressedSize: 2417152
CompressedSize: 2367188
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
44
Monitored processes
5
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe hardware.exe no specs hardware.exe iexplore.exe no specs iexplore.exe

Process information

PID
CMD
Path
Indicators
Parent process
704"C:\Program Files\Internet Explorer\iexplore.exe" -startmediumtab -EmbeddingC:\Program Files\Internet Explorer\iexplore.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
1348"C:\Users\admin\Desktop\VirtuallHardwares\hardware.exe" C:\Users\admin\Desktop\VirtuallHardwares\hardware.exeExplorer.EXE
User:
admin
Company:
virtualhardwares
Integrity Level:
MEDIUM
Description:
virtualhardwares
Exit code:
3221226540
Version:
1, 0, 0, 0
Modules
Images
c:\users\admin\desktop\virtuallhardwares\hardware.exe
c:\windows\system32\ntdll.dll
2236"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\VirtuallHardwares.rar"C:\Program Files\WinRAR\WinRAR.exe
Explorer.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2884"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:704 CREDAT:275457 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
3248"C:\Users\admin\Desktop\VirtuallHardwares\hardware.exe" C:\Users\admin\Desktop\VirtuallHardwares\hardware.exe
Explorer.EXE
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\desktop\virtuallhardwares\hardware.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
Total events
13 166
Read events
13 020
Write events
145
Delete events
1

Modification events

(PID) Process:(2236) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2236) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2236) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2236) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(2236) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\VirtuallHardwares.rar
(PID) Process:(2236) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2236) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2236) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2236) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2236) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface
Operation:writeName:ShowPassword
Value:
0
Executable files
4
Suspicious files
10
Text files
9
Unknown types
8

Dropped files

PID
Process
Filename
Type
2236WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb2236.596\VirtuallHardwares\vmwarehardware.exeexecutable
MD5:
SHA256:
3248hardware.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\78RFYB7Z\gg[1].htmhtml
MD5:
SHA256:
2236WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb2236.596\VirtuallHardwares\????: www.winwin7.comtext
MD5:
SHA256:
3248hardware.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\A053CFB63FC8E6507871752236B5CCD5_697E4D3275DB453AE6D7746CBBB3AAD1der
MD5:
SHA256:
3248hardware.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:
SHA256:
2236WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb2236.596\VirtuallHardwares\GameHardware.exeexecutable
MD5:
SHA256:
3248hardware.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\ACF244F1A10D4DBED0D88EBA0C43A9B5_16756CC7371BB76A269719AA1471E96Cder
MD5:
SHA256:
3248hardware.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\ACF244F1A10D4DBED0D88EBA0C43A9B5_16756CC7371BB76A269719AA1471E96Cbinary
MD5:
SHA256:
2236WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb2236.596\VirtuallHardwares\??MAC??????.exeexecutable
MD5:
SHA256:
3248hardware.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\A053CFB63FC8E6507871752236B5CCD5_697E4D3275DB453AE6D7746CBBB3AAD1binary
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
9
TCP/UDP connections
14
DNS requests
10
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2884
iexplore.exe
GET
200
104.18.20.226:80
http://ocsp.globalsign.com/rootr1/MEwwSjBIMEYwRDAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCCwQAAAAAAURO8DYx
US
der
1.41 Kb
whitelisted
3248
hardware.exe
GET
200
104.18.20.226:80
http://ocsp2.globalsign.com/gsorganizationvalsha2g2/ME0wSzBJMEcwRTAJBgUrDgMCGgUABBQMnk2cPe3vhNiR6XLHz4QGvBl7BwQUlt5h8b0cFilTHMDMfTuDAEDmGnwCDDB2ZKBWEXfB%2B5Xohw%3D%3D
US
der
1.46 Kb
whitelisted
2884
iexplore.exe
GET
200
104.18.20.226:80
http://ocsp2.globalsign.com/gsalphasha2g2/ME0wSzBJMEcwRTAJBgUrDgMCGgUABBSE1Wv4CYvTB7dm2OHrrWWWqmtnYQQU9c3VPAhQ%2BWpPOreX2laD5mnSaPcCDFgrHwJWV8VptmIxFg%3D%3D
US
der
1.40 Kb
whitelisted
3248
hardware.exe
GET
200
43.129.214.10:80
http://www.virtualhardwares.com/hardware/gg.html
JP
html
477 b
unknown
3248
hardware.exe
GET
200
104.18.20.226:80
http://ocsp.globalsign.com/rootr1/MEwwSjBIMEYwRDAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCCwQAAAAAAURO8EJH
US
der
1.41 Kb
whitelisted
2884
iexplore.exe
GET
200
47.242.247.229:80
http://virtualhardwares.com/Download.html
US
html
114 b
unknown
2884
iexplore.exe
GET
404
47.242.247.229:80
http://virtualhardwares.com/favicon.ico
US
html
106 b
unknown
3248
hardware.exe
GET
200
104.18.20.226:80
http://ocsp2.globalsign.com/gsorganizationvalsha2g2/ME0wSzBJMEcwRTAJBgUrDgMCGgUABBQMnk2cPe3vhNiR6XLHz4QGvBl7BwQUlt5h8b0cFilTHMDMfTuDAEDmGnwCDDSk20WxFnlwLi3iMg%3D%3D
US
der
1.46 Kb
whitelisted
3248
hardware.exe
GET
200
67.27.157.126:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?c635f4b3b6ab347b
US
compressed
4.70 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2884
iexplore.exe
104.18.20.226:80
ocsp.globalsign.com
Cloudflare Inc
US
shared
3248
hardware.exe
43.129.214.10:80
www.virtualhardwares.com
JP
unknown
3248
hardware.exe
218.94.207.228:443
s22.cnzz.com
No.31,Jin-rong Street
CN
unknown
3248
hardware.exe
104.18.20.226:80
ocsp.globalsign.com
Cloudflare Inc
US
shared
3248
hardware.exe
67.27.157.126:80
ctldl.windowsupdate.com
Level 3 Communications, Inc.
US
suspicious
3248
hardware.exe
203.119.128.195:443
z1.cnzz.com
CN
malicious
3248
hardware.exe
47.88.68.21:443
cnzz.mmstat.com
Alibaba (China) Technology Co., Ltd.
US
suspicious
2884
iexplore.exe
114.80.187.102:443
wwa.lanzoui.com
China Telecom (Group)
CN
suspicious
2884
iexplore.exe
47.242.247.229:80
www.virtualhardwares.com
US
unknown

DNS requests

Domain
IP
Reputation
www.virtualhardwares.com
  • 43.129.214.10
  • 47.242.247.229
  • 8.210.51.125
unknown
s22.cnzz.com
  • 218.94.207.228
suspicious
ctldl.windowsupdate.com
  • 67.27.157.126
  • 8.253.204.120
  • 67.27.235.254
  • 67.27.233.254
  • 67.27.157.254
whitelisted
ocsp.globalsign.com
  • 104.18.20.226
  • 104.18.21.226
whitelisted
ocsp2.globalsign.com
  • 104.18.20.226
  • 104.18.21.226
whitelisted
z1.cnzz.com
  • 203.119.128.195
whitelisted
c.cnzz.com
  • 218.94.207.228
whitelisted
cnzz.mmstat.com
  • 47.88.68.21
whitelisted
virtualhardwares.com
  • 47.242.247.229
  • 43.129.214.10
  • 8.210.51.125
unknown
wwa.lanzoui.com
  • 114.80.187.102
malicious

Threats

No threats detected
No debug info