File name:

NoEscape.exe-Download-main.zip

Full analysis: https://app.any.run/tasks/7dae2815-aad4-4d90-bad3-7dd9cf49e568
Verdict: Malicious activity
Analysis date: July 17, 2022, 07:22:32
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v1.0 to extract
MD5:

6DA84FD648C8811CC112F4FFFE20A24D

SHA1:

BA4F8D7FB51EE0A31B068CCA51D5E5388C4B081B

SHA256:

7B55DFAB141EB69ABBE47267E396FE8EE6BC4054FC8D4A5D91049B950C7D84AA

SSDEEP:

393216:8mpOKhF/fEB5KyYEvARy5DiydlufgDaDh5Z8sJzOvhz9R:8uB3f7koRseynegDU8sJzQR

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops executable file immediately after starts

      • WinRAR.exe (PID: 2944)
      • vc_redist.x86.exe (PID: 2496)
    • Application was dropped or rewritten from another process

      • NoEscape.exe (PID: 3032)
      • vc_redist.x86.exe (PID: 2496)
      • NoEscape.exe (PID: 3876)
      • NoEscape.exe (PID: 2520)
      • NoEscape.exe (PID: 3740)
      • NoEscape.exe (PID: 2304)
      • NoEscape.exe (PID: 3424)
    • Loads dropped or rewritten executable

      • vc_redist.x86.exe (PID: 2496)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2944)
      • vc_redist.x86.exe (PID: 2496)
    • Reads the computer name

      • WinRAR.exe (PID: 2944)
      • NoEscape.exe (PID: 3032)
      • vc_redist.x86.exe (PID: 2496)
      • NoEscape.exe (PID: 2520)
      • NoEscape.exe (PID: 3424)
    • Checks supported languages

      • WinRAR.exe (PID: 2944)
      • NoEscape.exe (PID: 3032)
      • NoEscape.exe (PID: 3876)
      • vc_redist.x86.exe (PID: 2496)
      • NoEscape.exe (PID: 2520)
      • NoEscape.exe (PID: 3740)
      • NoEscape.exe (PID: 2304)
      • NoEscape.exe (PID: 3424)
    • Drops a file with a compile date too recent

      • WinRAR.exe (PID: 2944)
      • vc_redist.x86.exe (PID: 2496)
    • Application launched itself

      • NoEscape.exe (PID: 3032)
      • NoEscape.exe (PID: 2520)
      • NoEscape.exe (PID: 3424)
    • Searches for installed software

      • vc_redist.x86.exe (PID: 2496)
  • INFO

    • Manual execution by user

      • NoEscape.exe (PID: 3032)
      • NoEscape.exe (PID: 2520)
      • vc_redist.x86.exe (PID: 2496)
      • NoEscape.exe (PID: 3424)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipFileName: NoEscape.exe-Download-main/
ZipUncompressedSize: -
ZipCompressedSize: -
ZipCRC: 0x00000000
ZipModifyDate: 2021:03:25 03:55:11
ZipCompression: None
ZipBitFlag: -
ZipRequiredVersion: 10
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
51
Monitored processes
8
Malicious processes
6
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe noescape.exe no specs noescape.exe noescape.exe no specs noescape.exe vc_redist.x86.exe noescape.exe no specs noescape.exe

Process information

PID
CMD
Path
Indicators
Parent process
2304"C:\Users\admin\Desktop\NoEscape.exe-Download-main\NoEscape.exe\NoEscape.exe" C:\Users\admin\Desktop\NoEscape.exe-Download-main\NoEscape.exe\NoEscape.exe
NoEscape.exe
User:
admin
Company:
Endermanch
Integrity Level:
HIGH
Description:
Windows Customization Tool
Exit code:
0
Version:
6.6.6.6
Modules
Images
c:\users\admin\desktop\noescape.exe-download-main\noescape.exe\noescape.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\samcli.dll
c:\windows\system32\srvcli.dll
2496"C:\Users\admin\Desktop\NoEscape.exe-Download-main\NoEscape.exe\vc_redist.x86.exe" C:\Users\admin\Desktop\NoEscape.exe-Download-main\NoEscape.exe\vc_redist.x86.exe
Explorer.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.23026
Exit code:
1638
Version:
14.0.23026.0
Modules
Images
c:\users\admin\desktop\noescape.exe-download-main\noescape.exe\vc_redist.x86.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.24542_none_5c0717c7a00ddc6d\gdiplus.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\sechost.dll
2520"C:\Users\admin\Desktop\NoEscape.exe-Download-main\NoEscape.exe\NoEscape.exe" C:\Users\admin\Desktop\NoEscape.exe-Download-main\NoEscape.exe\NoEscape.exeExplorer.EXE
User:
admin
Company:
Endermanch
Integrity Level:
MEDIUM
Description:
Windows Customization Tool
Exit code:
0
Version:
6.6.6.6
Modules
Images
c:\windows\system32\ntdll.dll
c:\users\admin\desktop\noescape.exe-download-main\noescape.exe\noescape.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\netutils.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\samcli.dll
2944"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\NoEscape.exe-Download-main.zip"C:\Program Files\WinRAR\WinRAR.exe
Explorer.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3032"C:\Users\admin\Desktop\NoEscape.exe-Download-main\NoEscape.exe\NoEscape.exe" C:\Users\admin\Desktop\NoEscape.exe-Download-main\NoEscape.exe\NoEscape.exeExplorer.EXE
User:
admin
Company:
Endermanch
Integrity Level:
MEDIUM
Description:
Windows Customization Tool
Exit code:
0
Version:
6.6.6.6
Modules
Images
c:\windows\system32\ntdll.dll
c:\users\admin\desktop\noescape.exe-download-main\noescape.exe\noescape.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\wkscli.dll
3424"C:\Users\admin\Desktop\NoEscape.exe-Download-main\NoEscape.exe\NoEscape.exe" C:\Users\admin\Desktop\NoEscape.exe-Download-main\NoEscape.exe\NoEscape.exeExplorer.EXE
User:
admin
Company:
Endermanch
Integrity Level:
MEDIUM
Description:
Windows Customization Tool
Exit code:
0
Version:
6.6.6.6
Modules
Images
c:\users\admin\desktop\noescape.exe-download-main\noescape.exe\noescape.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\msvcrt.dll
3740"C:\Users\admin\Desktop\NoEscape.exe-Download-main\NoEscape.exe\NoEscape.exe" C:\Users\admin\Desktop\NoEscape.exe-Download-main\NoEscape.exe\NoEscape.exe
NoEscape.exe
User:
admin
Company:
Endermanch
Integrity Level:
HIGH
Description:
Windows Customization Tool
Exit code:
0
Version:
6.6.6.6
Modules
Images
c:\users\admin\desktop\noescape.exe-download-main\noescape.exe\noescape.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\wkscli.dll
3876"C:\Users\admin\Desktop\NoEscape.exe-Download-main\NoEscape.exe\NoEscape.exe" C:\Users\admin\Desktop\NoEscape.exe-Download-main\NoEscape.exe\NoEscape.exe
NoEscape.exe
User:
admin
Company:
Endermanch
Integrity Level:
HIGH
Description:
Windows Customization Tool
Exit code:
0
Version:
6.6.6.6
Modules
Images
c:\users\admin\desktop\noescape.exe-download-main\noescape.exe\noescape.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\rpcrt4.dll
Total events
1 557
Read events
1 523
Write events
34
Delete events
0

Modification events

(PID) Process:(2944) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2944) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2944) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2944) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(2944) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(2944) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\NoEscape.exe-Download-main.zip
(PID) Process:(2944) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2944) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2944) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2944) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
Executable files
3
Suspicious files
0
Text files
33
Unknown types
0

Dropped files

PID
Process
Filename
Type
2496vc_redist.x86.exeC:\Users\admin\AppData\Local\Temp\{74d0e5db-b326-4dae-a6b2-445b9de1836e}\.ba1\1028\license.rtftext
MD5:EFA0E0316DBE1D01B04DB8AE55216E89
SHA256:D5147EE2BA7826D5B68E0DC10FC2AC95079F89C38264C5648D924DEC9290D085
2944WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2944.22577\NoEscape.exe-Download-main\README.mdtext
MD5:2B4D5EE9469B56EF5AA2231EAAF1830F
SHA256:C20BA8D1782BE19B680E2E8A5BBAB3BD28FB4F69196B5ACB572A3F08EAAA2968
2496vc_redist.x86.exeC:\Users\admin\AppData\Local\Temp\{74d0e5db-b326-4dae-a6b2-445b9de1836e}\.ba1\1045\license.rtftext
MD5:A0D88589A339E57E412AB01E763D6A27
SHA256:898D5CA01A3271D97350D06A6CCDB8803A176BB42BAF7E2C8F76C9037235CA8E
2496vc_redist.x86.exeC:\Users\admin\AppData\Local\Temp\{74d0e5db-b326-4dae-a6b2-445b9de1836e}\.ba1\1036\license.rtftext
MD5:6F70759DF32F212DBB65464258ECEEAF
SHA256:C7F03DA5D9A7F689B8DCBD507FF0B3FA98DABA55616F902E5E47E9839B753E1F
2944WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2944.22577\NoEscape.exe-Download-main\NoEscape.exe\NoEscape.exeexecutable
MD5:989AE3D195203B323AA2B3ADF04E9833
SHA256:D30D7676A3B4C91B77D403F81748EBF6B8824749DB5F860E114A8A204BCA5B8F
2496vc_redist.x86.exeC:\Users\admin\AppData\Local\Temp\{74d0e5db-b326-4dae-a6b2-445b9de1836e}\.ba1\1029\license.rtftext
MD5:FD8353F3BC88A47B8880B59A5DAD3F03
SHA256:2428E8BA8FC9648422333B6B4B92FB476741FC1022DE7CB59D030EC35CC21AC7
2496vc_redist.x86.exeC:\Users\admin\AppData\Local\Temp\{74d0e5db-b326-4dae-a6b2-445b9de1836e}\.ba1\wixstdba.dllexecutable
MD5:4D20A950A3571D11236482754B4A8E76
SHA256:A9295AD4E909F979E2B6CB2B2495C3D35C8517E689CD64A918C690E17B49078B
2496vc_redist.x86.exeC:\Users\admin\AppData\Local\Temp\{74d0e5db-b326-4dae-a6b2-445b9de1836e}\.ba1\1049\license.rtftext
MD5:EFF73C35DB2D6AC9F29D1B633C984A95
SHA256:F00A2A67106CA3BADB4C233951A262EC0A9BBA3151E1D8DA0362DCADA7928DCD
2496vc_redist.x86.exeC:\Users\admin\AppData\Local\Temp\{74d0e5db-b326-4dae-a6b2-445b9de1836e}\.ba1\1046\license.rtftext
MD5:137A9579BA2E02EBB87817440FCBDCB9
SHA256:42DC678EF9D5E4E147BF178FFE2FA3CD4BBBF9C904872B4E344D8BB22C473ED5
2496vc_redist.x86.exeC:\Users\admin\AppData\Local\Temp\{74d0e5db-b326-4dae-a6b2-445b9de1836e}\.ba1\1040\license.rtftext
MD5:1D07E27F97CE22A58780A04227BE6465
SHA256:F1214784C57AA3323426AF64D132045970717994EBA500B25283684DC1ADEBAA
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info