File name:

install-809.rar

Full analysis: https://app.any.run/tasks/80cb4164-b89d-46ec-a9da-aae924809f06
Verdict: Malicious activity
Analysis date: May 21, 2022, 04:18:29
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v4, os: Win32
MD5:

851875EB4D4EC083C25239A40AA7AF0C

SHA1:

40CC2D8CF87C43E5DE25ACC91A495BBDCB67FF2A

SHA256:

7E0287564B654063C45B93D2D2404C76505BE037F91BF0E0E86BC694B2B00F32

SSDEEP:

49152:BMhSQ8L4fDmVXOgwGfpGW3QAeCczjmfrF2taFAe3A:BMwQGVXOrUpx3QAejfmfrQt+AeQ

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • install-809.exe (PID: 2932)
      • install-809.exe (PID: 456)
      • apmanager.exe (PID: 3988)
      • apmanager.exe (PID: 3524)
    • Drops executable file immediately after starts

      • WinRAR.exe (PID: 1332)
      • install-809.exe (PID: 456)
    • Changes the autorun value in the registry

      • install-809.exe (PID: 456)
    • Changes the login/logoff helper path in the registry

      • install-809.exe (PID: 456)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 1332)
      • install-809.exe (PID: 456)
    • Checks supported languages

      • WinRAR.exe (PID: 1332)
      • install-809.exe (PID: 456)
      • apmanager.exe (PID: 3988)
      • apmanager.exe (PID: 3524)
    • Reads the computer name

      • WinRAR.exe (PID: 1332)
      • install-809.exe (PID: 456)
      • apmanager.exe (PID: 3988)
      • apmanager.exe (PID: 3524)
    • Drops a file with a compile date too recent

      • WinRAR.exe (PID: 1332)
      • install-809.exe (PID: 456)
    • Creates files in the user directory

      • install-809.exe (PID: 456)
      • apmanager.exe (PID: 3988)
    • Creates a software uninstall entry

      • install-809.exe (PID: 456)
  • INFO

    • Manual execution by user

      • install-809.exe (PID: 2932)
      • install-809.exe (PID: 456)
      • apmanager.exe (PID: 3524)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v-4.x) (58.3)
.rar | RAR compressed archive (gen) (41.6)

EXIF

ZIP

ArchivedFileName: install-809.ex1
PackingMethod: Best Compression
ModifyDate: 2010:04:26 00:44:17
OperatingSystem: Win32
UncompressedSize: 1836531
CompressedSize: 1647100
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
42
Monitored processes
5
Malicious processes
2
Suspicious processes
2

Behavior graph

Click at the process to see the details
start drop and start winrar.exe install-809.exe no specs install-809.exe apmanager.exe apmanager.exe

Process information

PID
CMD
Path
Indicators
Parent process
456"C:\Users\admin\Desktop\install-809.exe" C:\Users\admin\Desktop\install-809.exe
Explorer.EXE
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\desktop\install-809.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shell32.dll
1332"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\install-809.rar"C:\Program Files\WinRAR\WinRAR.exe
Explorer.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
c:\windows\system32\comdlg32.dll
2932"C:\Users\admin\Desktop\install-809.exe" C:\Users\admin\Desktop\install-809.exeExplorer.EXE
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\desktop\install-809.exe
c:\windows\system32\ntdll.dll
3524"C:\Users\admin\AppData\Roaming\APManager\apmanager.exe" C:\Users\admin\AppData\Roaming\APManager\apmanager.exe
Explorer.EXE
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\roaming\apmanager\apmanager.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\lpk.dll
3988C:\Users\admin\AppData\Roaming\APManager\apmanager.exeC:\Users\admin\AppData\Roaming\APManager\apmanager.exe
install-809.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\roaming\apmanager\apmanager.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
Total events
2 306
Read events
2 276
Write events
30
Delete events
0

Modification events

(PID) Process:(1332) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(1332) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(1332) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1332) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(1332) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(1332) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\install-809.rar
(PID) Process:(1332) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(1332) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(1332) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(1332) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
Executable files
3
Suspicious files
0
Text files
13
Unknown types
2

Dropped files

PID
Process
Filename
Type
1332WinRAR.exeC:\Users\admin\Desktop\install-809.ex1executable
MD5:663BE6DF6004F677D3D3E223FD8B0DDB
SHA256:DA33DE94D959F9F195A95F6063ED1575653F4B839E6046F12126F019D65B5917
456install-809.exeC:\Users\admin\Desktop\AP Manager.lnklnk
MD5:
SHA256:
456install-809.exeC:\Users\Administrator\Desktop\AP Manager.lnklnk
MD5:
SHA256:
456install-809.exeC:\Users\admin\AppData\Roaming\APManager\languages\Czech.lngtext
MD5:DDDBCE036DADAAC069230B1343F59270
SHA256:D5631B1F16E08AA03A619582B181034851454B4876573C457BA96A6D38448223
456install-809.exeC:\Users\admin\AppData\Roaming\APManager\languages\Spanish.lngtext
MD5:C44309378E43A5537D7910D27C866473
SHA256:906AB3226C84AA27C935C40D2DA2713606B3D3510A584C78E89B54A44D0B0BFD
456install-809.exeC:\Users\admin\AppData\Roaming\APManager\languages\Slovak.lngtext
MD5:DEC4FF6EB60D866CBB6B8DBAC6419B96
SHA256:3EDEF8659BAC5DE53B42C88262EB87CBD3579BADE3ED3D6B1E061908DAB567D0
456install-809.exeC:\Users\admin\AppData\Roaming\APManager\languages\template.lngtext
MD5:8DBB083BD093BF856F518AEAA03FB71B
SHA256:813FF5D06448A87DF90DDDAAF40156A0AB961C44B85FE9B6EFFB18189ACC83BD
456install-809.exeC:\Users\admin\AppData\Roaming\APManager\settings.initext
MD5:D51CF9B392D1919A3150FDC966286DA7
SHA256:BAEE3E11B56F75212851AD749CDCF5B3B1004566FF1E379BA011D5F940F7BC51
456install-809.exeC:\Users\admin\AppData\Roaming\APManager\wallpaper.jpgimage
MD5:9A96E0C4848609AF12690DC9D2450DD8
SHA256:044737DE8F5072781B926FD60814834FA4FAD375ABEC0FAF81EDF51EF706A0AC
456install-809.exeC:\Users\admin\AppData\Roaming\APManager\languages\Danish.lngtext
MD5:1E8739ED929D702F6E8A9762C15249C2
SHA256:9084FEF116AE779255B4F02558F0E702A607FCD93B94A0C82BB641024097764A
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
6
DNS requests
0
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3988
apmanager.exe
GET
91.209.238.10:80
http://91.209.238.10/m5tools/ip.php
GB
unknown
3524
apmanager.exe
GET
91.209.238.10:80
http://91.209.238.10/m5install/809/1
GB
unknown
3988
apmanager.exe
GET
91.209.238.10:80
http://91.209.238.10/m5tools/whois.php?short
GB
unknown
3524
apmanager.exe
GET
91.209.238.10:80
http://91.209.238.10/m5tools/whois.php?short
GB
unknown
3524
apmanager.exe
GET
91.209.238.10:80
http://91.209.238.10/m5tools/ip.php
GB
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3988
apmanager.exe
91.209.238.10:80
Crown Office and Procurator Fiscal Service
GB
unknown
3524
apmanager.exe
91.209.238.10:80
Crown Office and Procurator Fiscal Service
GB
unknown

DNS requests

No data

Threats

No threats detected
No debug info