File name:

Microsoft.Web.WebView2.Wpf.zip

Full analysis: https://app.any.run/tasks/04f05c1d-6599-4979-a9e6-9daa9f6eec8d
Verdict: Malicious activity
Analysis date: January 13, 2024, 15:34:53
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

CF1CD7BBB4C709A0571B03EE6D734CFC

SHA1:

591DD82C796FC9B30A9060A98271EB4CA5BD555D

SHA256:

771448770821A1A18BCE5B51962F0B7917E5E629BAA877B7FC6BC8E5E64C51CE

SSDEEP:

49152:GW/j/GK5A3ES5NvijoqEZL8ov2fcdjPmMWpy9UiNc1iN3LS1b6Ce:n/jGK23ES5Nv7qOL5vLrm3yOd1G7S165

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 116)
    • Uses Task Scheduler to autorun other applications

      • Hosts.exe (PID: 2312)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • WinRAR.exe (PID: 116)
    • Reads the Internet Settings

      • Hosts.exe (PID: 2312)
    • Uses TASKKILL.EXE to kill process

      • Hosts.exe (PID: 2312)
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 116)
    • Manual execution by a user

      • Hosts.vmp.exe (PID: 2024)
      • Hosts.vmp.exe (PID: 1840)
      • Hosts.exe (PID: 696)
      • Hosts.exe (PID: 2312)
    • Checks supported languages

      • Hosts.vmp.exe (PID: 1840)
      • Hosts.exe (PID: 2312)
    • Reads the computer name

      • Hosts.vmp.exe (PID: 1840)
      • Hosts.exe (PID: 2312)
    • Reads the machine GUID from the registry

      • Hosts.vmp.exe (PID: 1840)
      • Hosts.exe (PID: 2312)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2024:01:14 00:31:28
ZipCRC: 0x9412d69b
ZipCompressedSize: 15360
ZipUncompressedSize: 53760
ZipFileName: AxInterop.WMPLib.dll
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
81
Monitored processes
23
Malicious processes
1
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe hosts.vmp.exe no specs hosts.vmp.exe hosts.exe no specs hosts.exe schtasks.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
116"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Microsoft.Web.WebView2.Wpf.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
188"C:\Windows\System32\taskkill.exe" /f /im explorer.exeC:\Windows\System32\taskkill.exeHosts.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Terminates Processes
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
680"C:\Windows\System32\taskkill.exe" /f /im explorer.exeC:\Windows\System32\taskkill.exeHosts.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Terminates Processes
Exit code:
128
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
696"C:\Users\admin\AppData\Local\Temp\Microsoft.Web.WebView2.Wpf\Hosts.exe" C:\Users\admin\AppData\Local\Temp\Microsoft.Web.WebView2.Wpf\Hosts.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Hosts
Exit code:
3221226540
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\microsoft.web.webview2.wpf\hosts.exe
c:\windows\system32\ntdll.dll
948"C:\Windows\System32\taskkill.exe" /f /im explorer.exeC:\Windows\System32\taskkill.exeHosts.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Terminates Processes
Exit code:
128
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
1408"C:\Windows\System32\taskkill.exe" /f /im explorer.exeC:\Windows\System32\taskkill.exeHosts.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Terminates Processes
Exit code:
128
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
1840"C:\Users\admin\AppData\Local\Temp\Microsoft.Web.WebView2.Wpf\Hosts.vmp.exe" C:\Users\admin\AppData\Local\Temp\Microsoft.Web.WebView2.Wpf\Hosts.vmp.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Description:
Hosts
Exit code:
1
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\microsoft.web.webview2.wpf\hosts.vmp.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1860"C:\Windows\System32\taskkill.exe" /f /im explorer.exeC:\Windows\System32\taskkill.exeHosts.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Terminates Processes
Exit code:
128
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
1992"C:\Windows\System32\taskkill.exe" /f /im explorer.exeC:\Windows\System32\taskkill.exeHosts.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Terminates Processes
Exit code:
128
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
2024"C:\Users\admin\AppData\Local\Temp\Microsoft.Web.WebView2.Wpf\Hosts.vmp.exe" C:\Users\admin\AppData\Local\Temp\Microsoft.Web.WebView2.Wpf\Hosts.vmp.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Hosts
Exit code:
3221226540
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\microsoft.web.webview2.wpf\hosts.vmp.exe
c:\windows\system32\ntdll.dll
Total events
1 927
Read events
1 909
Write events
18
Delete events
0

Modification events

(PID) Process:(116) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(116) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(116) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(116) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(116) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(116) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(116) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(116) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(116) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2312) Hosts.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
Executable files
12
Suspicious files
1
Text files
5
Unknown types
0

Dropped files

PID
Process
Filename
Type
116WinRAR.exeC:\Users\admin\AppData\Local\Temp\Microsoft.Web.WebView2.Wpf\Microsoft.Web.WebView2.WinForms.xmlxml
MD5:C09409AAC254F17C1C648E6F0464B035
SHA256:4B40E49AEC5DBDA597224F997D57A16645DDC2EB00F31A6329204D1853A2245A
116WinRAR.exeC:\Users\admin\AppData\Local\Temp\Microsoft.Web.WebView2.Wpf\Microsoft.Web.WebView2.WinForms.dllexecutable
MD5:D15BFC4C7CCCC1E99466A1866FFC473D
SHA256:BEF507A4CE7B6A848993BC504AF7E2273CEC22E77469787CB1D47D3F362164ED
116WinRAR.exeC:\Users\admin\AppData\Local\Temp\Microsoft.Web.WebView2.Wpf\Interop.WMPLib.dllexecutable
MD5:176106B4AD84FDD07BFF5AB63335ED1D
SHA256:F6E426989B5BFB9C062E76C9401BDD089451EE55BE93A210A65DCB1AB9E1D8D8
116WinRAR.exeC:\Users\admin\AppData\Local\Temp\Microsoft.Web.WebView2.Wpf\runtimes\win-x64\native\WebView2Loader.dllexecutable
MD5:AEE20EF43CF692C9080C5973B1B79855
SHA256:31423E905E29C8A40A483E81DAE1491990805FA066634D218B35BB96692BEF0D
116WinRAR.exeC:\Users\admin\AppData\Local\Temp\Microsoft.Web.WebView2.Wpf\Microsoft.Web.WebView2.Core.xmlxml
MD5:443B25209D76ABF00375742E1B1DAD7B
SHA256:E961F24722E98D6BDA96853BF9B6DD26CCB1F1163EB1885B6567B681144FDF94
116WinRAR.exeC:\Users\admin\AppData\Local\Temp\Microsoft.Web.WebView2.Wpf\Microsoft.Web.WebView2.Core.dllexecutable
MD5:9F9FEEDB05B87E1BE1C7AB710655D0E8
SHA256:5E172B4F558723B7DBB7F568F301077C84D6571436FBE5A5F45BFA621C020403
116WinRAR.exeC:\Users\admin\AppData\Local\Temp\Microsoft.Web.WebView2.Wpf\runtimes\win-arm64\native\WebView2Loader.dllexecutable
MD5:06ECF3F289CE5D2E2862217D2E2A63A8
SHA256:A2DB5A4F76238837D46ABAC8255D1C5F7691D39BBA20C5C5271E64A9700964E5
116WinRAR.exeC:\Users\admin\AppData\Local\Temp\Microsoft.Web.WebView2.Wpf\Microsoft.Web.WebView2.Wpf.xmlxml
MD5:F3A793529EA2EB9071677903BE1EC4E5
SHA256:7C2966F6937F3F230E818357C824332E75D09EF762CDBFD2CE6E036487DB9A30
116WinRAR.exeC:\Users\admin\AppData\Local\Temp\Microsoft.Web.WebView2.Wpf\runtimes\win-x86\native\WebView2Loader.dllexecutable
MD5:9A9DF483ED55BD568CCCDD7485804931
SHA256:AD5CFE82F102739D4CC15C3EB38A411525762520C9C4229C902F67DBAB23C5FB
116WinRAR.exeC:\Users\admin\AppData\Local\Temp\Microsoft.Web.WebView2.Wpf\Hosts.exeexecutable
MD5:D55739906D434A29520A51B81C14F49C
SHA256:696C3D9D1979076737C4031A31DDB10FB55762F481E60FEA1EEA6BC34A786DDC
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown

DNS requests

No data

Threats

No threats detected
Process
Message
Hosts.exe
WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.
Hosts.exe
WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.
Hosts.exe
WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.
Hosts.exe
WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.
Hosts.exe
WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.
Hosts.exe
WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.
Hosts.exe
WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.
Hosts.exe
WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.
Hosts.exe
WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.
Hosts.exe
WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.