File name:

Microsoft.Web.WebView2.Wpf.zip

Full analysis: https://app.any.run/tasks/04f05c1d-6599-4979-a9e6-9daa9f6eec8d
Verdict: Malicious activity
Analysis date: January 13, 2024, 15:34:53
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

CF1CD7BBB4C709A0571B03EE6D734CFC

SHA1:

591DD82C796FC9B30A9060A98271EB4CA5BD555D

SHA256:

771448770821A1A18BCE5B51962F0B7917E5E629BAA877B7FC6BC8E5E64C51CE

SSDEEP:

49152:GW/j/GK5A3ES5NvijoqEZL8ov2fcdjPmMWpy9UiNc1iN3LS1b6Ce:n/jGK23ES5Nv7qOL5vLrm3yOd1G7S165

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 116)
    • Uses Task Scheduler to autorun other applications

      • Hosts.exe (PID: 2312)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • WinRAR.exe (PID: 116)
    • Reads the Internet Settings

      • Hosts.exe (PID: 2312)
    • Uses TASKKILL.EXE to kill process

      • Hosts.exe (PID: 2312)
  • INFO

    • Manual execution by a user

      • Hosts.vmp.exe (PID: 2024)
      • Hosts.vmp.exe (PID: 1840)
      • Hosts.exe (PID: 2312)
      • Hosts.exe (PID: 696)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 116)
    • Checks supported languages

      • Hosts.vmp.exe (PID: 1840)
      • Hosts.exe (PID: 2312)
    • Reads the machine GUID from the registry

      • Hosts.vmp.exe (PID: 1840)
      • Hosts.exe (PID: 2312)
    • Reads the computer name

      • Hosts.exe (PID: 2312)
      • Hosts.vmp.exe (PID: 1840)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2024:01:14 00:31:28
ZipCRC: 0x9412d69b
ZipCompressedSize: 15360
ZipUncompressedSize: 53760
ZipFileName: AxInterop.WMPLib.dll
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
81
Monitored processes
23
Malicious processes
1
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe hosts.vmp.exe no specs hosts.vmp.exe hosts.exe no specs hosts.exe schtasks.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
116"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Microsoft.Web.WebView2.Wpf.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
188"C:\Windows\System32\taskkill.exe" /f /im explorer.exeC:\Windows\System32\taskkill.exeHosts.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Terminates Processes
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
680"C:\Windows\System32\taskkill.exe" /f /im explorer.exeC:\Windows\System32\taskkill.exeHosts.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Terminates Processes
Exit code:
128
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
696"C:\Users\admin\AppData\Local\Temp\Microsoft.Web.WebView2.Wpf\Hosts.exe" C:\Users\admin\AppData\Local\Temp\Microsoft.Web.WebView2.Wpf\Hosts.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Hosts
Exit code:
3221226540
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\microsoft.web.webview2.wpf\hosts.exe
c:\windows\system32\ntdll.dll
948"C:\Windows\System32\taskkill.exe" /f /im explorer.exeC:\Windows\System32\taskkill.exeHosts.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Terminates Processes
Exit code:
128
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
1408"C:\Windows\System32\taskkill.exe" /f /im explorer.exeC:\Windows\System32\taskkill.exeHosts.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Terminates Processes
Exit code:
128
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
1840"C:\Users\admin\AppData\Local\Temp\Microsoft.Web.WebView2.Wpf\Hosts.vmp.exe" C:\Users\admin\AppData\Local\Temp\Microsoft.Web.WebView2.Wpf\Hosts.vmp.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Description:
Hosts
Exit code:
1
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\microsoft.web.webview2.wpf\hosts.vmp.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1860"C:\Windows\System32\taskkill.exe" /f /im explorer.exeC:\Windows\System32\taskkill.exeHosts.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Terminates Processes
Exit code:
128
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
1992"C:\Windows\System32\taskkill.exe" /f /im explorer.exeC:\Windows\System32\taskkill.exeHosts.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Terminates Processes
Exit code:
128
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
2024"C:\Users\admin\AppData\Local\Temp\Microsoft.Web.WebView2.Wpf\Hosts.vmp.exe" C:\Users\admin\AppData\Local\Temp\Microsoft.Web.WebView2.Wpf\Hosts.vmp.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Hosts
Exit code:
3221226540
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\microsoft.web.webview2.wpf\hosts.vmp.exe
c:\windows\system32\ntdll.dll
Total events
1 927
Read events
1 909
Write events
18
Delete events
0

Modification events

(PID) Process:(116) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(116) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(116) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(116) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(116) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(116) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(116) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(116) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(116) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2312) Hosts.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
Executable files
12
Suspicious files
1
Text files
5
Unknown types
0

Dropped files

PID
Process
Filename
Type
116WinRAR.exeC:\Users\admin\AppData\Local\Temp\Microsoft.Web.WebView2.Wpf\Hosts.pdbpdb
MD5:E52B51B0B680066B319145721974FA02
SHA256:B1704689D268AF5DDBF1EC919FB5F0CFB2905F36F6C6C64B990D94391716EB5E
116WinRAR.exeC:\Users\admin\AppData\Local\Temp\Microsoft.Web.WebView2.Wpf\Hosts.exeexecutable
MD5:D55739906D434A29520A51B81C14F49C
SHA256:696C3D9D1979076737C4031A31DDB10FB55762F481E60FEA1EEA6BC34A786DDC
116WinRAR.exeC:\Users\admin\AppData\Local\Temp\Microsoft.Web.WebView2.Wpf\Hosts.vmp.exeexecutable
MD5:ADA7312C99929D8DDCC4ED13CA399DDE
SHA256:200021B12A59B31C1DFF84BFAFAA91966F64F9194ACAEE4BBF8935B395BD7021
116WinRAR.exeC:\Users\admin\AppData\Local\Temp\Microsoft.Web.WebView2.Wpf\Input.dllexecutable
MD5:5BF779121E2F283B61B5AE2868E47F02
SHA256:2D1BB39C33745A7A82D36CFEF11B1E27BFE1234599D8BE128A1AB3762D146457
116WinRAR.exeC:\Users\admin\AppData\Local\Temp\Microsoft.Web.WebView2.Wpf\Microsoft.Web.WebView2.Core.dllexecutable
MD5:9F9FEEDB05B87E1BE1C7AB710655D0E8
SHA256:5E172B4F558723B7DBB7F568F301077C84D6571436FBE5A5F45BFA621C020403
116WinRAR.exeC:\Users\admin\AppData\Local\Temp\Microsoft.Web.WebView2.Wpf\Microsoft.Web.WebView2.Wpf.dllexecutable
MD5:2B4A31DAA2E0AF6A5FD7DF0252CB3CAB
SHA256:BF8FD64FE7AFBCF7646631BAA160C3A6D85B8A51777E52FB471F0230950DE754
116WinRAR.exeC:\Users\admin\AppData\Local\Temp\Microsoft.Web.WebView2.Wpf\Microsoft.Web.WebView2.WinForms.dllexecutable
MD5:D15BFC4C7CCCC1E99466A1866FFC473D
SHA256:BEF507A4CE7B6A848993BC504AF7E2273CEC22E77469787CB1D47D3F362164ED
116WinRAR.exeC:\Users\admin\AppData\Local\Temp\Microsoft.Web.WebView2.Wpf\AxInterop.WMPLib.dllexecutable
MD5:FE41A3E6621BD0DFEFEC2FD8560DE5CA
SHA256:C83C01F7AA38BFA1B9C6CBF684F3D3707253376C2CC70D30F0FBE877A8043467
116WinRAR.exeC:\Users\admin\AppData\Local\Temp\Microsoft.Web.WebView2.Wpf\Microsoft.Web.WebView2.WinForms.xmlxml
MD5:C09409AAC254F17C1C648E6F0464B035
SHA256:4B40E49AEC5DBDA597224F997D57A16645DDC2EB00F31A6329204D1853A2245A
116WinRAR.exeC:\Users\admin\AppData\Local\Temp\Microsoft.Web.WebView2.Wpf\Interop.WMPLib.dllexecutable
MD5:176106B4AD84FDD07BFF5AB63335ED1D
SHA256:F6E426989B5BFB9C062E76C9401BDD089451EE55BE93A210A65DCB1AB9E1D8D8
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown

DNS requests

No data

Threats

No threats detected
Process
Message
Hosts.exe
WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.
Hosts.exe
WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.
Hosts.exe
WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.
Hosts.exe
WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.
Hosts.exe
WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.
Hosts.exe
WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.
Hosts.exe
WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.
Hosts.exe
WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.
Hosts.exe
WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.
Hosts.exe
WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.