File name:

NoEscape.exe-Download-main.zip

Full analysis: https://app.any.run/tasks/764e39e5-1d43-4b79-8229-005c69d9b8e6
Verdict: Malicious activity
Analysis date: May 10, 2025, 06:56:09
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
arch-exec
Indicators:
MIME: application/zip
File info: Zip archive data, at least v1.0 to extract, compression method=store
MD5:

6DA84FD648C8811CC112F4FFFE20A24D

SHA1:

BA4F8D7FB51EE0A31B068CCA51D5E5388C4B081B

SHA256:

7B55DFAB141EB69ABBE47267E396FE8EE6BC4054FC8D4A5D91049B950C7D84AA

SSDEEP:

393216:8mpOKhF/fEB5KyYEvARy5DiydlufgDaDh5Z8sJzOvhz9R:8uB3f7koRseynegDU8sJzQR

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • vc_redist.x86.exe (PID: 672)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • WinRAR.exe (PID: 2736)
      • vc_redist.x86.exe (PID: 672)
    • Reads security settings of Internet Explorer

      • NoEscape.exe (PID: 2168)
      • WinRAR.exe (PID: 2736)
      • NoEscape.exe (PID: 2948)
    • Executable content was dropped or overwritten

      • vc_redist.x86.exe (PID: 672)
    • Application launched itself

      • NoEscape.exe (PID: 2168)
      • NoEscape.exe (PID: 2948)
    • Reads the Internet Settings

      • NoEscape.exe (PID: 2168)
      • NoEscape.exe (PID: 2948)
    • Starts a Microsoft application from unusual location

      • vc_redist.x86.exe (PID: 672)
    • Searches for installed software

      • vc_redist.x86.exe (PID: 672)
  • INFO

    • The sample compiled with english language support

      • WinRAR.exe (PID: 2736)
      • vc_redist.x86.exe (PID: 672)
    • Checks supported languages

      • NoEscape.exe (PID: 2168)
      • NoEscape.exe (PID: 1824)
      • vc_redist.x86.exe (PID: 672)
      • NoEscape.exe (PID: 2948)
      • NoEscape.exe (PID: 2532)
    • Reads the computer name

      • NoEscape.exe (PID: 2168)
      • vc_redist.x86.exe (PID: 672)
      • NoEscape.exe (PID: 2948)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2736)
    • Create files in a temporary directory

      • vc_redist.x86.exe (PID: 672)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 10
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2021:03:25 03:55:22
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: NoEscape.exe-Download-main/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
44
Monitored processes
6
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe noescape.exe no specs noescape.exe vc_redist.x86.exe noescape.exe no specs noescape.exe

Process information

PID
CMD
Path
Indicators
Parent process
672"C:\Users\admin\AppData\Local\Temp\Rar$EXa2736.1474\NoEscape.exe-Download-main\NoEscape.exe\vc_redist.x86.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa2736.1474\NoEscape.exe-Download-main\NoEscape.exe\vc_redist.x86.exe
WinRAR.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.23026
Exit code:
1638
Version:
14.0.23026.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2736.1474\noescape.exe-download-main\noescape.exe\vc_redist.x86.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.24542_none_5c0717c7a00ddc6d\gdiplus.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1824"C:\Users\admin\AppData\Local\Temp\Rar$EXa2736.784\NoEscape.exe-Download-main\NoEscape.exe\NoEscape.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa2736.784\NoEscape.exe-Download-main\NoEscape.exe\NoEscape.exe
NoEscape.exe
User:
admin
Company:
Endermanch
Integrity Level:
HIGH
Description:
Windows Customization Tool
Exit code:
0
Version:
6.6.6.6
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2736.784\noescape.exe-download-main\noescape.exe\noescape.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\wkscli.dll
2168"C:\Users\admin\AppData\Local\Temp\Rar$EXa2736.784\NoEscape.exe-Download-main\NoEscape.exe\NoEscape.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa2736.784\NoEscape.exe-Download-main\NoEscape.exe\NoEscape.exeWinRAR.exe
User:
admin
Company:
Endermanch
Integrity Level:
MEDIUM
Description:
Windows Customization Tool
Exit code:
0
Version:
6.6.6.6
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2736.784\noescape.exe-download-main\noescape.exe\noescape.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\wkscli.dll
2532"C:\Users\admin\AppData\Local\Temp\Rar$EXa2736.2452\NoEscape.exe-Download-main\NoEscape.exe\NoEscape.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa2736.2452\NoEscape.exe-Download-main\NoEscape.exe\NoEscape.exe
NoEscape.exe
User:
admin
Company:
Endermanch
Integrity Level:
HIGH
Description:
Windows Customization Tool
Exit code:
0
Version:
6.6.6.6
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2736.2452\noescape.exe-download-main\noescape.exe\noescape.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\wkscli.dll
2736"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\NoEscape.exe-Download-main.zipC:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2948"C:\Users\admin\AppData\Local\Temp\Rar$EXa2736.2452\NoEscape.exe-Download-main\NoEscape.exe\NoEscape.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa2736.2452\NoEscape.exe-Download-main\NoEscape.exe\NoEscape.exeWinRAR.exe
User:
admin
Company:
Endermanch
Integrity Level:
MEDIUM
Description:
Windows Customization Tool
Exit code:
0
Version:
6.6.6.6
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2736.2452\noescape.exe-download-main\noescape.exe\noescape.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\wkscli.dll
Total events
2 845
Read events
2 810
Write events
35
Delete events
0

Modification events

(PID) Process:(2736) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2736) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2736) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2736) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(2736) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(2736) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(2736) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\NoEscape.exe-Download-main.zip
(PID) Process:(2736) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2736) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2736) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
Executable files
7
Suspicious files
0
Text files
35
Unknown types
0

Dropped files

PID
Process
Filename
Type
2736WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2736.1474\NoEscape.exe-Download-main\NoEscape.exe\NoEscape.exeexecutable
MD5:989AE3D195203B323AA2B3ADF04E9833
SHA256:D30D7676A3B4C91B77D403F81748EBF6B8824749DB5F860E114A8A204BCA5B8F
2736WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2736.784\NoEscape.exe-Download-main\NoEscape.exe\NoEscape.exeexecutable
MD5:989AE3D195203B323AA2B3ADF04E9833
SHA256:D30D7676A3B4C91B77D403F81748EBF6B8824749DB5F860E114A8A204BCA5B8F
672vc_redist.x86.exeC:\Users\admin\AppData\Local\Temp\{74d0e5db-b326-4dae-a6b2-445b9de1836e}\.ba1\1049\license.rtftext
MD5:EFF73C35DB2D6AC9F29D1B633C984A95
SHA256:F00A2A67106CA3BADB4C233951A262EC0A9BBA3151E1D8DA0362DCADA7928DCD
672vc_redist.x86.exeC:\Users\admin\AppData\Local\Temp\{74d0e5db-b326-4dae-a6b2-445b9de1836e}\.ba1\1042\license.rtftext
MD5:F6E7A2A05EFB4413295C156A179578A3
SHA256:DCEFD9B37D78F37ED8AAEF70AC2BFCDE441DCFB97469A6AA6AF89C1FFADBF814
672vc_redist.x86.exeC:\Users\admin\AppData\Local\Temp\{74d0e5db-b326-4dae-a6b2-445b9de1836e}\.ba1\1031\license.rtftext
MD5:B4A1F60A329E18DD44C19F91E19E9A0D
SHA256:C017EDFE3B0D308E20FBF3DE8795FD4451A530475A2D0EE0824E166045EADFB7
672vc_redist.x86.exeC:\Users\admin\AppData\Local\Temp\{74d0e5db-b326-4dae-a6b2-445b9de1836e}\.ba1\1045\license.rtftext
MD5:A0D88589A339E57E412AB01E763D6A27
SHA256:898D5CA01A3271D97350D06A6CCDB8803A176BB42BAF7E2C8F76C9037235CA8E
672vc_redist.x86.exeC:\Users\admin\AppData\Local\Temp\{74d0e5db-b326-4dae-a6b2-445b9de1836e}\.ba1\1046\license.rtftext
MD5:137A9579BA2E02EBB87817440FCBDCB9
SHA256:42DC678EF9D5E4E147BF178FFE2FA3CD4BBBF9C904872B4E344D8BB22C473ED5
672vc_redist.x86.exeC:\Users\admin\AppData\Local\Temp\{74d0e5db-b326-4dae-a6b2-445b9de1836e}\.ba1\2052\license.rtftext
MD5:31AFEC54446E496CE2A1D1CD3B257738
SHA256:63F463F0ACE41FA088ACFB70F501DB47E3B83600DB31538D8DABA010E6B83D42
672vc_redist.x86.exeC:\Users\admin\AppData\Local\Temp\{74d0e5db-b326-4dae-a6b2-445b9de1836e}\.ba1\1055\license.rtftext
MD5:362F60F539B629BF59021003F426583C
SHA256:1E602773F3071636E0F9C6B27037B7B4094DC26F7C2FABCDF3287BC9BCAA8652
672vc_redist.x86.exeC:\Users\admin\AppData\Local\Temp\{74d0e5db-b326-4dae-a6b2-445b9de1836e}\.ba1\3082\license.rtftext
MD5:64F1444D27E3F3489F057E7280E9C973
SHA256:55929413B6A530F8C4ACBB1E7EEE81FB9ED0BD64AF5CD26D6F5637CEDFAF0A2D
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
6
DNS requests
1
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
224.0.0.252:5355
whitelisted
1080
svchost.exe
224.0.0.252:5355
whitelisted
4
System
192.168.100.255:138
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.185.110
whitelisted

Threats

No threats detected
No debug info