File name:

manuskript-0.16.1-windows.zip

Full analysis: https://app.any.run/tasks/61f959cf-93f7-45e7-9060-cb87b17492c8
Verdict: Malicious activity
Analysis date: December 13, 2024, 23:42:47
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
arch-doc
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=store
MD5:

9A63D0AC0C26BD16901818BA8C31CEAA

SHA1:

2E159AAB2B182C260378D4CE5D08123366767E65

SHA256:

7B789067FC92947C089C7BD54324742156F04D7A2D670DE4E5170C87ABF72F3D

SSDEEP:

1572864:IJjYutiP5UtgAXYwwsUf/gIlZE9lgQL3171RIU2At9Ez:IJjYu8NQzL311RIU2At8

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Generic archive extractor

      • WinRAR.exe (PID: 3208)
    • Process drops legitimate windows executable

      • WinRAR.exe (PID: 3208)
    • Process drops python dynamic module

      • WinRAR.exe (PID: 3208)
  • INFO

    • Reads security settings of Internet Explorer

      • notepad.exe (PID: 3608)
      • notepad.exe (PID: 5992)
    • Manual execution by a user

      • notepad.exe (PID: 5992)
      • OpenWith.exe (PID: 6056)
      • notepad.exe (PID: 3608)
      • OpenWith.exe (PID: 5712)
      • OpenWith.exe (PID: 5576)
      • OpenWith.exe (PID: 2220)
      • OpenWith.exe (PID: 1580)
      • OpenWith.exe (PID: 1412)
      • OpenWith.exe (PID: 5968)
      • OpenWith.exe (PID: 4024)
    • Reads Microsoft Office registry keys

      • OpenWith.exe (PID: 5712)
      • OpenWith.exe (PID: 1580)
      • OpenWith.exe (PID: 6056)
      • OpenWith.exe (PID: 4024)
      • OpenWith.exe (PID: 5968)
      • OpenWith.exe (PID: 5576)
      • OpenWith.exe (PID: 2220)
      • OpenWith.exe (PID: 1412)
    • The sample compiled with english language support

      • WinRAR.exe (PID: 3208)
    • The process uses the downloaded file

      • WinRAR.exe (PID: 3208)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3208)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.sdinstall | Speckie Dictionary Installation (47.6)
.zip | ZIP compressed archive (19)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2023:12:14 13:26:42
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: _internal/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
119
Monitored processes
11
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe notepad.exe no specs notepad.exe no specs openwith.exe no specs openwith.exe no specs openwith.exe no specs openwith.exe no specs openwith.exe no specs openwith.exe no specs openwith.exe no specs openwith.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1412"C:\WINDOWS\System32\OpenWith.exe" C:\Users\admin\Desktop\qt_gd.qmC:\Windows\System32\OpenWith.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Pick an app
Exit code:
2147943623
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\openwith.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
1580"C:\WINDOWS\System32\OpenWith.exe" C:\Users\admin\Desktop\COPYINGC:\Windows\System32\OpenWith.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Pick an app
Exit code:
2147943623
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\openwith.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
2220"C:\WINDOWS\System32\OpenWith.exe" C:\Users\admin\Desktop\qmldirC:\Windows\System32\OpenWith.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Pick an app
Exit code:
2147943623
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\openwith.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
3208"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\Desktop\manuskript-0.16.1-windows.zipC:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
3608"C:\WINDOWS\system32\NOTEPAD.EXE" C:\Users\admin\Desktop\top_level.txtC:\Windows\System32\notepad.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\notepad.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
4024"C:\WINDOWS\System32\OpenWith.exe" C:\Users\admin\Desktop\qmldirC:\Windows\System32\OpenWith.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Pick an app
Exit code:
2147943623
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\openwith.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
5576"C:\WINDOWS\System32\OpenWith.exe" C:\Users\admin\Desktop\INSTALLERC:\Windows\System32\OpenWith.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Pick an app
Exit code:
2147943623
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\openwith.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
5712"C:\WINDOWS\System32\OpenWith.exe" C:\Users\admin\Desktop\book-of-acts.mskC:\Windows\System32\OpenWith.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Pick an app
Exit code:
2147943623
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\openwith.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
5968"C:\WINDOWS\System32\OpenWith.exe" C:\Users\admin\Desktop\qmldirC:\Windows\System32\OpenWith.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Pick an app
Exit code:
2147943623
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\openwith.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
5992"C:\WINDOWS\system32\NOTEPAD.EXE" C:\Users\admin\Desktop\status.txtC:\Windows\System32\notepad.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\notepad.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
Total events
5 631
Read events
5 621
Write events
10
Delete events
0

Modification events

(PID) Process:(3208) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(3208) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(3208) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(3208) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\manuskript-0.16.1-windows.zip
(PID) Process:(3208) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3208) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3208) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3208) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3208) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\VirusScan
Operation:writeName:DefScanner
Value:
Windows Defender
Executable files
180
Suspicious files
488
Text files
1 168
Unknown types
2

Dropped files

PID
Process
Filename
Type
3208WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$VR3208.24547\manuskript-0.16.1-windows.zip\_internal\_decimal.pydexecutable
MD5:FF0BF710EB2D7817C49E1F4E21502073
SHA256:C6EB532DA62A115AE75F58766B632E005140A2E7C9C67A77564F1804685A377F
3208WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$VR3208.24547\manuskript-0.16.1-windows.zip\manuskriptw.exeexecutable
MD5:39C5BB5C9E75F628EBE32E525C559344
SHA256:F43F6C64844474EC4428331C10B6839ACE75B2A6C191BF3C5D57A5C103740A84
3208WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$VR3208.24547\manuskript-0.16.1-windows.zip\_internal\_ctypes.pydexecutable
MD5:A1E9B3CC6B942251568E59FD3C342205
SHA256:A8703F949C9520B76CB1875D1176A23A2B3EF1D652D6DFAC6E1DE46DC08B2AA3
3208WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$VR3208.24547\manuskript-0.16.1-windows.zip\_internal\_asyncio.pydexecutable
MD5:A3F434F6CFD2F339876E7D345FE178FB
SHA256:102043B17C20043E4624F60E444131382363B69FF0E683C13FA17AF156766483
3208WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$VR3208.24547\manuskript-0.16.1-windows.zip\manuskript.exeexecutable
MD5:7D1DACB21DB5487A6B4ACFC0EE517D97
SHA256:4DA7E32DE5C68A89E9313031C8D90AEDB3A73F6AE1F917E722148A2F6F247DF3
3208WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$VR3208.24547\manuskript-0.16.1-windows.zip\_internal\api-ms-win-core-fibers-l1-1-0.dllexecutable
MD5:EB065ED1B5CABDBB90E2403B8564778F
SHA256:BB2D740333AFAEA2A73A163F95FA102D018CCD68DEF28B6815A2BE0696AB57DB
3208WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$VR3208.24547\manuskript-0.16.1-windows.zip\_internal\api-ms-win-core-debug-l1-1-0.dllexecutable
MD5:720DB2235C4193151FF8987F8A729135
SHA256:092B72832C47F9C4EDCDE61F1A111C20EB73452984E0A6109482DE74EB03C34D
3208WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$VR3208.24547\manuskript-0.16.1-windows.zip\_internal\api-ms-win-core-datetime-l1-1-0.dllexecutable
MD5:2A8065DC6E6E60FB90B4B3F9E6BA7288
SHA256:55E5F10D0DD9C85FF1C6DC7798E46B3A4422FB7EBC583BB00D06A7DF2494397B
3208WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$VR3208.24547\manuskript-0.16.1-windows.zip\_internal\api-ms-win-core-file-l1-1-0.dllexecutable
MD5:36277B52C64CC66216751AAD135528F9
SHA256:F353B6C2DF7AADB457263A02BCE59C44BBAB55F98AE6509674CFBC3751F761B9
3208WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$VR3208.24547\manuskript-0.16.1-windows.zip\_internal\_overlapped.pydexecutable
MD5:FA44F2AC914B98BCEC6DD102EC612F87
SHA256:AC33B6B3AACC31D2DB8A502110881B4B711E2FB94983F85581E30953C9AC4721
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
22
DNS requests
7
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4712
MoUsoCoreWorker.exe
GET
200
2.16.241.12:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
440
svchost.exe
GET
200
2.16.241.12:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
440
svchost.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
4712
MoUsoCoreWorker.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
2.23.209.133:443
www.bing.com
Akamai International B.V.
GB
whitelisted
192.168.100.255:138
whitelisted
4712
MoUsoCoreWorker.exe
2.16.241.12:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
440
svchost.exe
2.16.241.12:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4712
MoUsoCoreWorker.exe
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
440
svchost.exe
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
  • 40.127.240.158
whitelisted
www.bing.com
  • 2.23.209.133
  • 2.23.209.130
  • 2.23.209.187
whitelisted
google.com
  • 142.250.181.238
whitelisted
crl.microsoft.com
  • 2.16.241.12
  • 2.16.241.19
whitelisted
www.microsoft.com
  • 95.101.149.131
whitelisted
self.events.data.microsoft.com
  • 13.89.178.26
whitelisted

Threats

No threats detected
No debug info