analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

install-809.rar

Full analysis: https://app.any.run/tasks/80cb4164-b89d-46ec-a9da-aae924809f06
Verdict: Malicious activity
Analysis date: May 21, 2022, 04:18:29
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v4, os: Win32
MD5:

851875EB4D4EC083C25239A40AA7AF0C

SHA1:

40CC2D8CF87C43E5DE25ACC91A495BBDCB67FF2A

SHA256:

7E0287564B654063C45B93D2D2404C76505BE037F91BF0E0E86BC694B2B00F32

SSDEEP:

49152:BMhSQ8L4fDmVXOgwGfpGW3QAeCczjmfrF2taFAe3A:BMwQGVXOrUpx3QAejfmfrQt+AeQ

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops executable file immediately after starts

      • WinRAR.exe (PID: 1332)
      • install-809.exe (PID: 456)
    • Application was dropped or rewritten from another process

      • install-809.exe (PID: 2932)
      • install-809.exe (PID: 456)
      • apmanager.exe (PID: 3524)
      • apmanager.exe (PID: 3988)
    • Changes the autorun value in the registry

      • install-809.exe (PID: 456)
    • Changes the login/logoff helper path in the registry

      • install-809.exe (PID: 456)
  • SUSPICIOUS

    • Reads the computer name

      • WinRAR.exe (PID: 1332)
      • install-809.exe (PID: 456)
      • apmanager.exe (PID: 3988)
      • apmanager.exe (PID: 3524)
    • Checks supported languages

      • WinRAR.exe (PID: 1332)
      • install-809.exe (PID: 456)
      • apmanager.exe (PID: 3524)
      • apmanager.exe (PID: 3988)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 1332)
      • install-809.exe (PID: 456)
    • Drops a file with a compile date too recent

      • WinRAR.exe (PID: 1332)
      • install-809.exe (PID: 456)
    • Creates a software uninstall entry

      • install-809.exe (PID: 456)
    • Creates files in the user directory

      • install-809.exe (PID: 456)
      • apmanager.exe (PID: 3988)
  • INFO

    • Manual execution by user

      • install-809.exe (PID: 2932)
      • install-809.exe (PID: 456)
      • apmanager.exe (PID: 3524)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v-4.x) (58.3)
.rar | RAR compressed archive (gen) (41.6)

EXIF

ZIP

ArchivedFileName: install-809.ex1
PackingMethod: Best Compression
ModifyDate: 2010:04:26 00:44:17
OperatingSystem: Win32
UncompressedSize: 1836531
CompressedSize: 1647100
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
42
Monitored processes
5
Malicious processes
2
Suspicious processes
2

Behavior graph

Click at the process to see the details
start drop and start winrar.exe install-809.exe no specs install-809.exe apmanager.exe apmanager.exe

Process information

PID
CMD
Path
Indicators
Parent process
1332"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\install-809.rar"C:\Program Files\WinRAR\WinRAR.exe
Explorer.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
2932"C:\Users\admin\Desktop\install-809.exe" C:\Users\admin\Desktop\install-809.exeExplorer.EXE
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
456"C:\Users\admin\Desktop\install-809.exe" C:\Users\admin\Desktop\install-809.exe
Explorer.EXE
User:
admin
Integrity Level:
HIGH
Exit code:
0
3988C:\Users\admin\AppData\Roaming\APManager\apmanager.exeC:\Users\admin\AppData\Roaming\APManager\apmanager.exe
install-809.exe
User:
admin
Integrity Level:
HIGH
3524"C:\Users\admin\AppData\Roaming\APManager\apmanager.exe" C:\Users\admin\AppData\Roaming\APManager\apmanager.exe
Explorer.EXE
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Total events
2 306
Read events
2 276
Write events
30
Delete events
0

Modification events

(PID) Process:(1332) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(1332) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(1332) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1332) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(1332) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(1332) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\install-809.rar
(PID) Process:(1332) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(1332) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(1332) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(1332) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
Executable files
3
Suspicious files
0
Text files
13
Unknown types
2

Dropped files

PID
Process
Filename
Type
456install-809.exeC:\Users\admin\AppData\Roaming\APManager\languages\French.lngtext
MD5:FB9A47EAE7377AF9B301B77E75D64FFA
SHA256:04F5E320F08F3676D0F2EB354FA44A68B0D11492F92B9B33741C8EF6BBDA1346
456install-809.exeC:\Users\admin\AppData\Roaming\APManager\wallpaper.jpgimage
MD5:9A96E0C4848609AF12690DC9D2450DD8
SHA256:044737DE8F5072781B926FD60814834FA4FAD375ABEC0FAF81EDF51EF706A0AC
456install-809.exeC:\Users\admin\AppData\Roaming\APManager\languages\Dutch.lngtext
MD5:441416CB25650C882C49A6B0557F249B
SHA256:A395F57C997E77969FB9943B5BA258D6F17E2ADDED9152C7ECFCA99617037B70
456install-809.exeC:\Users\admin\AppData\Roaming\APManager\languages\Czech.lngtext
MD5:DDDBCE036DADAAC069230B1343F59270
SHA256:D5631B1F16E08AA03A619582B181034851454B4876573C457BA96A6D38448223
1332WinRAR.exeC:\Users\admin\Desktop\install-809.ex1executable
MD5:663BE6DF6004F677D3D3E223FD8B0DDB
SHA256:DA33DE94D959F9F195A95F6063ED1575653F4B839E6046F12126F019D65B5917
456install-809.exeC:\Users\admin\AppData\Roaming\APManager\languages\Italian.lngtext
MD5:09181E2419BD6A44E745F013694C321F
SHA256:69256FFEED274F192294BAC2E426A892743921A040C7F043F97A44B829882471
456install-809.exeC:\Users\admin\AppData\Roaming\APManager\languages\German.lngtext
MD5:D54315C6871300716BB598078971A4F7
SHA256:3519C7CF14C7D4A5014F2406EA1A741FE2B02B9E2440BDD7053A7D403E118C86
456install-809.exeC:\Users\Administrator\Desktop\AP Manager.lnklnk
MD5:AEED4C9C1C32E37F545F5B84ED01C9C9
SHA256:0D07E84ED157E5A6556A3477370E1FA4DF40CA3EAE9AB41CAF3FACB6C197101B
456install-809.exeC:\Users\admin\Desktop\AP Manager.lnklnk
MD5:2B6FF0E99474EA70219915D1EC8FEEB2
SHA256:C6836C9EB126615968D8C7455031FA2AD84CA57FF543B928219CAACDAEA681FA
456install-809.exeC:\Users\admin\AppData\Roaming\APManager\languages\Portuguese.lngtext
MD5:34788C48C5D67583EA2BAC179037A182
SHA256:84152BDAFBDAAA209C2A0E8BBF400D71663C92E10C50D247490A4F6849692F68
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
6
DNS requests
0
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3988
apmanager.exe
GET
91.209.238.10:80
http://91.209.238.10/m5tools/whois.php?short
GB
unknown
3988
apmanager.exe
GET
91.209.238.10:80
http://91.209.238.10/m5tools/ip.php
GB
unknown
3524
apmanager.exe
GET
91.209.238.10:80
http://91.209.238.10/m5install/809/1
GB
unknown
3524
apmanager.exe
GET
91.209.238.10:80
http://91.209.238.10/m5tools/ip.php
GB
unknown
3524
apmanager.exe
GET
91.209.238.10:80
http://91.209.238.10/m5tools/whois.php?short
GB
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3524
apmanager.exe
91.209.238.10:80
Crown Office and Procurator Fiscal Service
GB
unknown
3988
apmanager.exe
91.209.238.10:80
Crown Office and Procurator Fiscal Service
GB
unknown

DNS requests

No data

Threats

No threats detected
No debug info