File name:

main.zip

Full analysis: https://app.any.run/tasks/c4c26e64-b8e4-4054-a659-935eae5f090e
Verdict: Malicious activity
Analysis date: November 20, 2024, 18:56:40
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v1.0 to extract, compression method=store
MD5:

B667356D0FD2F2B950FAD9D9E92E6ECF

SHA1:

9B89DCD2D459F51BFDE58ED6279E2E5E86A90B0A

SHA256:

7B80B47BF8544DC821175720ADC89ED99FFADBCD4252C132E688F67C3AD11E2A

SSDEEP:

786432:sIXSOzEUq5tK705Bo9f/a19pFVelzQRwau+z:sIXSiuV5Boda9pFVehow2z

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • The process checks if it is being run in the virtual environment

      • WinRAR.exe (PID: 3608)
    • Reads security settings of Internet Explorer

      • WinRAR.exe (PID: 3608)
    • Drops a system driver (possible attempt to evade defenses)

      • WinRAR.exe (PID: 3608)
  • INFO

    • The process uses the downloaded file

      • WinRAR.exe (PID: 3608)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3608)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 10
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2021:09:25 21:14:06
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: VMProtect-Ultimate--main/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
110
Monitored processes
4
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe confused.exe no specs confused.exe vaporobfuscator.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1472"C:\Users\admin\AppData\Local\Temp\Rar$EXa3608.47213\VMProtect-Ultimate--main\VMProtect Ultimate\VMProtect Ultimate x64\Confused.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3608.47213\VMProtect-Ultimate--main\VMProtect Ultimate\VMProtect Ultimate x64\Confused.exeWinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Panel
Exit code:
3221226540
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3608.47213\vmprotect-ultimate--main\vmprotect ultimate\vmprotect ultimate x64\confused.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
2164"C:\Users\admin\AppData\Local\Temp\Rar$EXa3608.47213\VMProtect-Ultimate--main\VMProtect Ultimate\VMProtect Ultimate x64\Confused.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3608.47213\VMProtect-Ultimate--main\VMProtect Ultimate\VMProtect Ultimate x64\Confused.exe
WinRAR.exe
User:
admin
Integrity Level:
HIGH
Description:
Panel
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3608.47213\vmprotect-ultimate--main\vmprotect ultimate\vmprotect ultimate x64\confused.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
2940"C:\Users\admin\AppData\Local\Temp\Rar$EXa3608.47492\VMProtect-Ultimate--main\VMProtect Ultimate\VMProtect Ultimate x64\VaporObfuscator.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3608.47492\VMProtect-Ultimate--main\VMProtect Ultimate\VMProtect Ultimate x64\VaporObfuscator.exeWinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Description:
VaporObfuscator
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3608.47492\vmprotect-ultimate--main\vmprotect ultimate\vmprotect ultimate x64\vaporobfuscator.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
3608"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\Desktop\main.zipC:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
Total events
1 797
Read events
1 789
Write events
8
Delete events
0

Modification events

(PID) Process:(3608) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(3608) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(3608) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(3608) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\main.zip
(PID) Process:(3608) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3608) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3608) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3608) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
Executable files
43
Suspicious files
60
Text files
41
Unknown types
24

Dropped files

PID
Process
Filename
Type
3608WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3608.47213\VMProtect-Ultimate--main\VMProtect Ultimate\VMProtect Ultimate x64\Help\en\_23.cfsbinary
MD5:5A56255B3A4220EE8952D39825F3A9A4
SHA256:10F696C428B625BF0993BE4E012DF770994C55F19DC9B9DA63AE35D23F374D3C
3608WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3608.47213\VMProtect-Ultimate--main\VMProtect Ultimate\VMProtect Ultimate x64\Help\en\segmentsbinary
MD5:F957A9DD8D5EE888B5281F70B9A72DA8
SHA256:F9A4DA0093540FB132061A925230DD25AB8C91D4606111CCA51AF7B587E38695
3608WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3608.47213\VMProtect-Ultimate--main\VMProtect Ultimate\VMProtect Ultimate x64\Help\en.qhcsqlite
MD5:79827B0D245C28B6A38C042BFE33AE6F
SHA256:99883E36D9788B36D66EBFD1434A1C9E861D4679CDED61F3558AA415B11C198D
3608WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3608.47213\VMProtect-Ultimate--main\VMProtect Ultimate\VMProtect Ultimate x64\Include\ASM\VMProtectSDK.inctext
MD5:A8C48A4A96B59B8BB464223CC5A7C66F
SHA256:9D41F7BF8F220E721E34F54665DB9B63CACA9EA00FC650F81492736A196F731E
3608WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3608.47213\VMProtect-Ultimate--main\VMProtect Ultimate\VMProtect Ultimate x64\Langs\fr.lngtext
MD5:187E7FA4A2F429F45F339FC6FCFD224D
SHA256:BCF8B033A2FFBE657683CB2B94CC871F1D0FCDB99680BC54A7AF9BFAE751B4D7
3608WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3608.47213\VMProtect-Ultimate--main\VMProtect Ultimate\VMProtect Ultimate x64\Help\ru.qhcbinary
MD5:0ACAAA400E412FB6A4F6C2735522E201
SHA256:8CAFE2A9A915ED01E3C3384138D574807C580B656669A51F9656E218188596F9
3608WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3608.47213\VMProtect-Ultimate--main\VMProtect Ultimate\VMProtect Ultimate x64\Help\en\deletablebinary
MD5:F1D3FF8443297732862DF21DC4E57262
SHA256:DF3F619804A92FDB4057192DC43DD748EA778ADC52BC498CE80524C014B81119
3608WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3608.47213\VMProtect-Ultimate--main\VMProtect Ultimate\VMProtect Ultimate x64\Help\ru\deletablebinary
MD5:F1D3FF8443297732862DF21DC4E57262
SHA256:DF3F619804A92FDB4057192DC43DD748EA778ADC52BC498CE80524C014B81119
3608WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3608.47213\VMProtect-Ultimate--main\VMProtect Ultimate\VMProtect Ultimate x64\Confused.exeexecutable
MD5:81C6A8CCD47647C4297AFE20FCF87EEC
SHA256:CBAA687115266698F94F10CC0F7807B5F7D5AE2B734C36306BCC7DD0163C7885
3608WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3608.47213\VMProtect-Ultimate--main\VMProtect Ultimate\VMProtect Ultimate x64\Help\ru\_23.cfsbinary
MD5:42B57DDE629AB220606F4D43D57FAEDC
SHA256:E28ECE67BCAC17E2562CFA12B885B4558D0BCCF9EBBF678FC2AB05898B2D445A
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
17
DNS requests
7
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
2.16.241.19:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
4712
MoUsoCoreWorker.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
4932
svchost.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
2.16.241.19:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
88.221.169.152:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
4712
MoUsoCoreWorker.exe
88.221.169.152:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
4932
svchost.exe
88.221.169.152:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
  • 40.127.240.158
  • 51.104.136.2
whitelisted
google.com
  • 142.250.184.206
whitelisted
crl.microsoft.com
  • 2.16.241.19
  • 2.16.241.12
whitelisted
www.microsoft.com
  • 88.221.169.152
whitelisted
self.events.data.microsoft.com
  • 52.182.143.213
whitelisted

Threats

No threats detected
No debug info