File name:

manuskript-0.16.1-windows.zip

Full analysis: https://app.any.run/tasks/61f959cf-93f7-45e7-9060-cb87b17492c8
Verdict: Malicious activity
Analysis date: December 13, 2024, 23:42:47
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
arch-doc
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=store
MD5:

9A63D0AC0C26BD16901818BA8C31CEAA

SHA1:

2E159AAB2B182C260378D4CE5D08123366767E65

SHA256:

7B789067FC92947C089C7BD54324742156F04D7A2D670DE4E5170C87ABF72F3D

SSDEEP:

1572864:IJjYutiP5UtgAXYwwsUf/gIlZE9lgQL3171RIU2At9Ez:IJjYu8NQzL311RIU2At8

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Generic archive extractor

      • WinRAR.exe (PID: 3208)
    • Process drops python dynamic module

      • WinRAR.exe (PID: 3208)
    • Process drops legitimate windows executable

      • WinRAR.exe (PID: 3208)
  • INFO

    • Manual execution by a user

      • notepad.exe (PID: 5992)
      • OpenWith.exe (PID: 6056)
      • notepad.exe (PID: 3608)
      • OpenWith.exe (PID: 1580)
      • OpenWith.exe (PID: 5712)
      • OpenWith.exe (PID: 5968)
      • OpenWith.exe (PID: 1412)
      • OpenWith.exe (PID: 4024)
      • OpenWith.exe (PID: 5576)
      • OpenWith.exe (PID: 2220)
    • Reads security settings of Internet Explorer

      • notepad.exe (PID: 5992)
      • notepad.exe (PID: 3608)
    • Reads Microsoft Office registry keys

      • OpenWith.exe (PID: 5968)
      • OpenWith.exe (PID: 5712)
      • OpenWith.exe (PID: 6056)
      • OpenWith.exe (PID: 1580)
      • OpenWith.exe (PID: 1412)
      • OpenWith.exe (PID: 5576)
      • OpenWith.exe (PID: 4024)
      • OpenWith.exe (PID: 2220)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3208)
    • The sample compiled with english language support

      • WinRAR.exe (PID: 3208)
    • The process uses the downloaded file

      • WinRAR.exe (PID: 3208)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.sdinstall | Speckie Dictionary Installation (47.6)
.zip | ZIP compressed archive (19)

EXIF

ZIP

ZipFileName: _internal/
ZipUncompressedSize: -
ZipCompressedSize: -
ZipCRC: 0x00000000
ZipModifyDate: 2023:12:14 13:26:42
ZipCompression: None
ZipBitFlag: -
ZipRequiredVersion: 20
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
119
Monitored processes
11
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe notepad.exe no specs notepad.exe no specs openwith.exe no specs openwith.exe no specs openwith.exe no specs openwith.exe no specs openwith.exe no specs openwith.exe no specs openwith.exe no specs openwith.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
3208"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\Desktop\manuskript-0.16.1-windows.zipC:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
3608"C:\WINDOWS\system32\NOTEPAD.EXE" C:\Users\admin\Desktop\top_level.txtC:\Windows\System32\notepad.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\notepad.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
5992"C:\WINDOWS\system32\NOTEPAD.EXE" C:\Users\admin\Desktop\status.txtC:\Windows\System32\notepad.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\notepad.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
6056"C:\WINDOWS\System32\OpenWith.exe" C:\Users\admin\Desktop\qmldirC:\Windows\System32\OpenWith.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Pick an app
Exit code:
2147943623
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\openwith.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
5712"C:\WINDOWS\System32\OpenWith.exe" C:\Users\admin\Desktop\book-of-acts.mskC:\Windows\System32\OpenWith.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Pick an app
Exit code:
2147943623
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\openwith.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
1580"C:\WINDOWS\System32\OpenWith.exe" C:\Users\admin\Desktop\COPYINGC:\Windows\System32\OpenWith.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Pick an app
Exit code:
2147943623
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\openwith.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
5968"C:\WINDOWS\System32\OpenWith.exe" C:\Users\admin\Desktop\qmldirC:\Windows\System32\OpenWith.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Pick an app
Exit code:
2147943623
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\openwith.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
5576"C:\WINDOWS\System32\OpenWith.exe" C:\Users\admin\Desktop\INSTALLERC:\Windows\System32\OpenWith.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Pick an app
Exit code:
2147943623
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\openwith.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
2220"C:\WINDOWS\System32\OpenWith.exe" C:\Users\admin\Desktop\qmldirC:\Windows\System32\OpenWith.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Pick an app
Exit code:
2147943623
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\openwith.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
4024"C:\WINDOWS\System32\OpenWith.exe" C:\Users\admin\Desktop\qmldirC:\Windows\System32\OpenWith.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Pick an app
Exit code:
2147943623
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\openwith.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
Total events
5 631
Read events
5 621
Write events
10
Delete events
0

Modification events

(PID) Process:(3208) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(3208) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(3208) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(3208) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\manuskript-0.16.1-windows.zip
(PID) Process:(3208) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3208) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3208) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3208) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3208) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\VirusScan
Operation:writeName:DefScanner
Value:
Windows Defender
Executable files
180
Suspicious files
488
Text files
1 168
Unknown types
2

Dropped files

PID
Process
Filename
Type
3208WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$VR3208.24547\manuskript-0.16.1-windows.zip\manuskript.exeexecutable
MD5:7D1DACB21DB5487A6B4ACFC0EE517D97
SHA256:4DA7E32DE5C68A89E9313031C8D90AEDB3A73F6AE1F917E722148A2F6F247DF3
3208WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$VR3208.24547\manuskript-0.16.1-windows.zip\_internal\_overlapped.pydexecutable
MD5:FA44F2AC914B98BCEC6DD102EC612F87
SHA256:AC33B6B3AACC31D2DB8A502110881B4B711E2FB94983F85581E30953C9AC4721
3208WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$VR3208.24547\manuskript-0.16.1-windows.zip\_internal\_multiprocessing.pydexecutable
MD5:D01D2743F2E38D40722C3F219A4950C6
SHA256:336D2D5F4E4BEBD6B3823DD218DCAEC49BBBE902DDEAE9ECD66E4CDE1B2BDA6E
3208WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$VR3208.24547\manuskript-0.16.1-windows.zip\manuskriptw.exeexecutable
MD5:39C5BB5C9E75F628EBE32E525C559344
SHA256:F43F6C64844474EC4428331C10B6839ACE75B2A6C191BF3C5D57A5C103740A84
3208WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$VR3208.24547\manuskript-0.16.1-windows.zip\_internal\_lzma.pydexecutable
MD5:77B78B43D58FE7CE9EB2FBB1420889FA
SHA256:6E571D93CE55D09583EC91C607883A43C1DA3D4D36794D68C6ECD6BEA4AB466A
3208WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$VR3208.24547\manuskript-0.16.1-windows.zip\_internal\_bz2.pydexecutable
MD5:B024A6F227EAFA8D43EDFC1A560FE651
SHA256:C0DD9496B19BA9536A78A43A97704E7D4BEF3C901D196ED385E771366682819D
3208WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$VR3208.24547\manuskript-0.16.1-windows.zip\_internal\_hashlib.pydexecutable
MD5:69DC506CF2FA3DA9D0CABA05FCA6A35D
SHA256:C5B8C4582E201FEF2D8CB2C8672D07B86DEC31AFB4A17B758DBFB2CFF163B12F
3208WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$VR3208.24547\manuskript-0.16.1-windows.zip\_internal\_ctypes.pydexecutable
MD5:A1E9B3CC6B942251568E59FD3C342205
SHA256:A8703F949C9520B76CB1875D1176A23A2B3EF1D652D6DFAC6E1DE46DC08B2AA3
3208WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$VR3208.24547\manuskript-0.16.1-windows.zip\_internal\_decimal.pydexecutable
MD5:FF0BF710EB2D7817C49E1F4E21502073
SHA256:C6EB532DA62A115AE75F58766B632E005140A2E7C9C67A77564F1804685A377F
3208WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$VR3208.24547\manuskript-0.16.1-windows.zip\_internal\api-ms-win-core-console-l1-1-0.dllexecutable
MD5:681C84FB102B5761477D8DA2D68CD834
SHA256:F0F7CB2A9FFCCB43400DB88D6BF99F2FCC3161DE1AC96C48501D4D522C48C2CA
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
22
DNS requests
7
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
440
svchost.exe
GET
200
2.16.241.12:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
4712
MoUsoCoreWorker.exe
GET
200
2.16.241.12:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
440
svchost.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
4712
MoUsoCoreWorker.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
2.23.209.133:443
www.bing.com
Akamai International B.V.
GB
whitelisted
192.168.100.255:138
whitelisted
4712
MoUsoCoreWorker.exe
2.16.241.12:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
440
svchost.exe
2.16.241.12:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4712
MoUsoCoreWorker.exe
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
440
svchost.exe
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
  • 40.127.240.158
whitelisted
www.bing.com
  • 2.23.209.133
  • 2.23.209.130
  • 2.23.209.187
whitelisted
google.com
  • 142.250.181.238
whitelisted
crl.microsoft.com
  • 2.16.241.12
  • 2.16.241.19
whitelisted
www.microsoft.com
  • 95.101.149.131
whitelisted
self.events.data.microsoft.com
  • 13.89.178.26
whitelisted

Threats

No threats detected
No debug info