File name:

NoEscape.exe-Download-main.zip

Full analysis: https://app.any.run/tasks/764e39e5-1d43-4b79-8229-005c69d9b8e6
Verdict: Malicious activity
Analysis date: May 10, 2025, 06:56:09
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
arch-exec
Indicators:
MIME: application/zip
File info: Zip archive data, at least v1.0 to extract, compression method=store
MD5:

6DA84FD648C8811CC112F4FFFE20A24D

SHA1:

BA4F8D7FB51EE0A31B068CCA51D5E5388C4B081B

SHA256:

7B55DFAB141EB69ABBE47267E396FE8EE6BC4054FC8D4A5D91049B950C7D84AA

SSDEEP:

393216:8mpOKhF/fEB5KyYEvARy5DiydlufgDaDh5Z8sJzOvhz9R:8uB3f7koRseynegDU8sJzQR

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • vc_redist.x86.exe (PID: 672)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • WinRAR.exe (PID: 2736)
      • NoEscape.exe (PID: 2168)
      • NoEscape.exe (PID: 2948)
    • Process drops legitimate windows executable

      • WinRAR.exe (PID: 2736)
      • vc_redist.x86.exe (PID: 672)
    • Reads the Internet Settings

      • NoEscape.exe (PID: 2168)
      • NoEscape.exe (PID: 2948)
    • Application launched itself

      • NoEscape.exe (PID: 2168)
      • NoEscape.exe (PID: 2948)
    • Starts a Microsoft application from unusual location

      • vc_redist.x86.exe (PID: 672)
    • Executable content was dropped or overwritten

      • vc_redist.x86.exe (PID: 672)
    • Searches for installed software

      • vc_redist.x86.exe (PID: 672)
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2736)
    • The sample compiled with english language support

      • WinRAR.exe (PID: 2736)
      • vc_redist.x86.exe (PID: 672)
    • Reads the computer name

      • NoEscape.exe (PID: 2168)
      • vc_redist.x86.exe (PID: 672)
      • NoEscape.exe (PID: 2948)
    • Checks supported languages

      • NoEscape.exe (PID: 2168)
      • NoEscape.exe (PID: 1824)
      • vc_redist.x86.exe (PID: 672)
      • NoEscape.exe (PID: 2948)
      • NoEscape.exe (PID: 2532)
    • Create files in a temporary directory

      • vc_redist.x86.exe (PID: 672)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 10
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2021:03:25 03:55:22
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: NoEscape.exe-Download-main/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
44
Monitored processes
6
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe noescape.exe no specs noescape.exe vc_redist.x86.exe noescape.exe no specs noescape.exe

Process information

PID
CMD
Path
Indicators
Parent process
672"C:\Users\admin\AppData\Local\Temp\Rar$EXa2736.1474\NoEscape.exe-Download-main\NoEscape.exe\vc_redist.x86.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa2736.1474\NoEscape.exe-Download-main\NoEscape.exe\vc_redist.x86.exe
WinRAR.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.23026
Exit code:
1638
Version:
14.0.23026.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2736.1474\noescape.exe-download-main\noescape.exe\vc_redist.x86.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.24542_none_5c0717c7a00ddc6d\gdiplus.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1824"C:\Users\admin\AppData\Local\Temp\Rar$EXa2736.784\NoEscape.exe-Download-main\NoEscape.exe\NoEscape.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa2736.784\NoEscape.exe-Download-main\NoEscape.exe\NoEscape.exe
NoEscape.exe
User:
admin
Company:
Endermanch
Integrity Level:
HIGH
Description:
Windows Customization Tool
Exit code:
0
Version:
6.6.6.6
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2736.784\noescape.exe-download-main\noescape.exe\noescape.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\wkscli.dll
2168"C:\Users\admin\AppData\Local\Temp\Rar$EXa2736.784\NoEscape.exe-Download-main\NoEscape.exe\NoEscape.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa2736.784\NoEscape.exe-Download-main\NoEscape.exe\NoEscape.exeWinRAR.exe
User:
admin
Company:
Endermanch
Integrity Level:
MEDIUM
Description:
Windows Customization Tool
Exit code:
0
Version:
6.6.6.6
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2736.784\noescape.exe-download-main\noescape.exe\noescape.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\wkscli.dll
2532"C:\Users\admin\AppData\Local\Temp\Rar$EXa2736.2452\NoEscape.exe-Download-main\NoEscape.exe\NoEscape.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa2736.2452\NoEscape.exe-Download-main\NoEscape.exe\NoEscape.exe
NoEscape.exe
User:
admin
Company:
Endermanch
Integrity Level:
HIGH
Description:
Windows Customization Tool
Exit code:
0
Version:
6.6.6.6
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2736.2452\noescape.exe-download-main\noescape.exe\noescape.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\wkscli.dll
2736"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\NoEscape.exe-Download-main.zipC:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2948"C:\Users\admin\AppData\Local\Temp\Rar$EXa2736.2452\NoEscape.exe-Download-main\NoEscape.exe\NoEscape.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa2736.2452\NoEscape.exe-Download-main\NoEscape.exe\NoEscape.exeWinRAR.exe
User:
admin
Company:
Endermanch
Integrity Level:
MEDIUM
Description:
Windows Customization Tool
Exit code:
0
Version:
6.6.6.6
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2736.2452\noescape.exe-download-main\noescape.exe\noescape.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\wkscli.dll
Total events
2 845
Read events
2 810
Write events
35
Delete events
0

Modification events

(PID) Process:(2736) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2736) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2736) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2736) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(2736) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(2736) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(2736) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\NoEscape.exe-Download-main.zip
(PID) Process:(2736) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2736) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2736) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
Executable files
7
Suspicious files
0
Text files
35
Unknown types
0

Dropped files

PID
Process
Filename
Type
2736WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2736.784\NoEscape.exe-Download-main\NoEscape.exe\NoEscape.exeexecutable
MD5:989AE3D195203B323AA2B3ADF04E9833
SHA256:D30D7676A3B4C91B77D403F81748EBF6B8824749DB5F860E114A8A204BCA5B8F
2736WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2736.1474\NoEscape.exe-Download-main\NoEscape.exe\NoEscape.exeexecutable
MD5:989AE3D195203B323AA2B3ADF04E9833
SHA256:D30D7676A3B4C91B77D403F81748EBF6B8824749DB5F860E114A8A204BCA5B8F
672vc_redist.x86.exeC:\Users\admin\AppData\Local\Temp\{74d0e5db-b326-4dae-a6b2-445b9de1836e}\.ba1\1036\license.rtftext
MD5:6F70759DF32F212DBB65464258ECEEAF
SHA256:C7F03DA5D9A7F689B8DCBD507FF0B3FA98DABA55616F902E5E47E9839B753E1F
2736WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2736.784\NoEscape.exe-Download-main\README.mdtext
MD5:2B4D5EE9469B56EF5AA2231EAAF1830F
SHA256:C20BA8D1782BE19B680E2E8A5BBAB3BD28FB4F69196B5ACB572A3F08EAAA2968
2736WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2736.1474\NoEscape.exe-Download-main\README.mdtext
MD5:2B4D5EE9469B56EF5AA2231EAAF1830F
SHA256:C20BA8D1782BE19B680E2E8A5BBAB3BD28FB4F69196B5ACB572A3F08EAAA2968
2736WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2736.1474\NoEscape.exe-Download-main\NoEscape.exe\vc_redist.x86.exeexecutable
MD5:1A15E6606BAC9647E7AD3CAA543377CF
SHA256:FDD1E1F0DCAE2D0AA0720895EFF33B927D13076E64464BB7C7E5843B7667CD14
672vc_redist.x86.exeC:\Users\admin\AppData\Local\Temp\{74d0e5db-b326-4dae-a6b2-445b9de1836e}\.ba1\wixstdba.dllexecutable
MD5:4D20A950A3571D11236482754B4A8E76
SHA256:A9295AD4E909F979E2B6CB2B2495C3D35C8517E689CD64A918C690E17B49078B
672vc_redist.x86.exeC:\Users\admin\AppData\Local\Temp\{74d0e5db-b326-4dae-a6b2-445b9de1836e}\.ba1\1029\license.rtftext
MD5:FD8353F3BC88A47B8880B59A5DAD3F03
SHA256:2428E8BA8FC9648422333B6B4B92FB476741FC1022DE7CB59D030EC35CC21AC7
672vc_redist.x86.exeC:\Users\admin\AppData\Local\Temp\{74d0e5db-b326-4dae-a6b2-445b9de1836e}\.ba1\1041\license.rtftext
MD5:0D9DD57746D5609494B35314FA88FD93
SHA256:AC0D8E0EAAB1875909A6A6F106A37CD7468F87F71887A44263F5F0178F99C40B
672vc_redist.x86.exeC:\Users\admin\AppData\Local\Temp\{74d0e5db-b326-4dae-a6b2-445b9de1836e}\.ba1\1045\license.rtftext
MD5:A0D88589A339E57E412AB01E763D6A27
SHA256:898D5CA01A3271D97350D06A6CCDB8803A176BB42BAF7E2C8F76C9037235CA8E
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
6
DNS requests
1
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
224.0.0.252:5355
whitelisted
1080
svchost.exe
224.0.0.252:5355
whitelisted
4
System
192.168.100.255:138
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.185.110
whitelisted

Threats

No threats detected
No debug info