| File name: | install-809.rar |
| Full analysis: | https://app.any.run/tasks/80cb4164-b89d-46ec-a9da-aae924809f06 |
| Verdict: | Malicious activity |
| Analysis date: | May 21, 2022, 04:18:29 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-rar |
| File info: | RAR archive data, v4, os: Win32 |
| MD5: | 851875EB4D4EC083C25239A40AA7AF0C |
| SHA1: | 40CC2D8CF87C43E5DE25ACC91A495BBDCB67FF2A |
| SHA256: | 7E0287564B654063C45B93D2D2404C76505BE037F91BF0E0E86BC694B2B00F32 |
| SSDEEP: | 49152:BMhSQ8L4fDmVXOgwGfpGW3QAeCczjmfrF2taFAe3A:BMwQGVXOrUpx3QAejfmfrQt+AeQ |
| .rar | | | RAR compressed archive (v-4.x) (58.3) |
|---|---|---|
| .rar | | | RAR compressed archive (gen) (41.6) |
| ArchivedFileName: | install-809.ex1 |
|---|---|
| PackingMethod: | Best Compression |
| ModifyDate: | 2010:04:26 00:44:17 |
| OperatingSystem: | Win32 |
| UncompressedSize: | 1836531 |
| CompressedSize: | 1647100 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 456 | "C:\Users\admin\Desktop\install-809.exe" | C:\Users\admin\Desktop\install-809.exe | Explorer.EXE | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 1332 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\install-809.rar" | C:\Program Files\WinRAR\WinRAR.exe | Explorer.EXE | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| 2932 | "C:\Users\admin\Desktop\install-809.exe" | C:\Users\admin\Desktop\install-809.exe | — | Explorer.EXE | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 3221226540 Modules
| |||||||||||||||
| 3524 | "C:\Users\admin\AppData\Roaming\APManager\apmanager.exe" | C:\Users\admin\AppData\Roaming\APManager\apmanager.exe | Explorer.EXE | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 3988 | C:\Users\admin\AppData\Roaming\APManager\apmanager.exe | C:\Users\admin\AppData\Roaming\APManager\apmanager.exe | install-809.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| (PID) Process: | (1332) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (1332) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (1332) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (1332) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip | |||
| (PID) Process: | (1332) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (1332) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\install-809.rar | |||
| (PID) Process: | (1332) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (1332) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (1332) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (1332) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1332 | WinRAR.exe | C:\Users\admin\Desktop\install-809.ex1 | executable | |
MD5:663BE6DF6004F677D3D3E223FD8B0DDB | SHA256:DA33DE94D959F9F195A95F6063ED1575653F4B839E6046F12126F019D65B5917 | |||
| 456 | install-809.exe | C:\Users\admin\Desktop\AP Manager.lnk | lnk | |
MD5:— | SHA256:— | |||
| 456 | install-809.exe | C:\Users\Administrator\Desktop\AP Manager.lnk | lnk | |
MD5:— | SHA256:— | |||
| 456 | install-809.exe | C:\Users\admin\AppData\Roaming\APManager\languages\Czech.lng | text | |
MD5:DDDBCE036DADAAC069230B1343F59270 | SHA256:D5631B1F16E08AA03A619582B181034851454B4876573C457BA96A6D38448223 | |||
| 456 | install-809.exe | C:\Users\admin\AppData\Roaming\APManager\languages\Spanish.lng | text | |
MD5:C44309378E43A5537D7910D27C866473 | SHA256:906AB3226C84AA27C935C40D2DA2713606B3D3510A584C78E89B54A44D0B0BFD | |||
| 456 | install-809.exe | C:\Users\admin\AppData\Roaming\APManager\languages\Slovak.lng | text | |
MD5:DEC4FF6EB60D866CBB6B8DBAC6419B96 | SHA256:3EDEF8659BAC5DE53B42C88262EB87CBD3579BADE3ED3D6B1E061908DAB567D0 | |||
| 456 | install-809.exe | C:\Users\admin\AppData\Roaming\APManager\languages\template.lng | text | |
MD5:8DBB083BD093BF856F518AEAA03FB71B | SHA256:813FF5D06448A87DF90DDDAAF40156A0AB961C44B85FE9B6EFFB18189ACC83BD | |||
| 456 | install-809.exe | C:\Users\admin\AppData\Roaming\APManager\settings.ini | text | |
MD5:D51CF9B392D1919A3150FDC966286DA7 | SHA256:BAEE3E11B56F75212851AD749CDCF5B3B1004566FF1E379BA011D5F940F7BC51 | |||
| 456 | install-809.exe | C:\Users\admin\AppData\Roaming\APManager\wallpaper.jpg | image | |
MD5:9A96E0C4848609AF12690DC9D2450DD8 | SHA256:044737DE8F5072781B926FD60814834FA4FAD375ABEC0FAF81EDF51EF706A0AC | |||
| 456 | install-809.exe | C:\Users\admin\AppData\Roaming\APManager\languages\Danish.lng | text | |
MD5:1E8739ED929D702F6E8A9762C15249C2 | SHA256:9084FEF116AE779255B4F02558F0E702A607FCD93B94A0C82BB641024097764A | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3988 | apmanager.exe | GET | — | 91.209.238.10:80 | http://91.209.238.10/m5tools/ip.php | GB | — | — | unknown |
3524 | apmanager.exe | GET | — | 91.209.238.10:80 | http://91.209.238.10/m5install/809/1 | GB | — | — | unknown |
3988 | apmanager.exe | GET | — | 91.209.238.10:80 | http://91.209.238.10/m5tools/whois.php?short | GB | — | — | unknown |
3524 | apmanager.exe | GET | — | 91.209.238.10:80 | http://91.209.238.10/m5tools/whois.php?short | GB | — | — | unknown |
3524 | apmanager.exe | GET | — | 91.209.238.10:80 | http://91.209.238.10/m5tools/ip.php | GB | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
3988 | apmanager.exe | 91.209.238.10:80 | — | Crown Office and Procurator Fiscal Service | GB | unknown |
3524 | apmanager.exe | 91.209.238.10:80 | — | Crown Office and Procurator Fiscal Service | GB | unknown |