File name:

winlock5404_9d429e7056cae76bd0dbaf1dfd68af8af184cd66.7z

Full analysis: https://app.any.run/tasks/ad26eff9-4992-4854-97fa-b8454220838a
Verdict: Malicious activity
Analysis date: May 15, 2025, 18:41:33
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
evasion
arch-exec
Indicators:
MIME: application/x-7z-compressed
File info: 7-zip archive data, version 0.4
MD5:

211B8F9162E735CCC1CEA1BA05EA6AA2

SHA1:

C09605906E9195DA6CC1338D70F69E04CFB7F5E0

SHA256:

7E92AFBA2806D27232EC18DB40E654EE0C1DA9B41690D4F1690D30A4BD352B6B

SSDEEP:

6144:zNCA0/O5l/mbBWu8Ua0YbMOWElOK71KFsXVQoG:5CAKemBWlUPYBjKaBG

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • winlock5404_9d429e7056cae76bd0dbaf1dfd68af8af184cd66.exe (PID: 328)
  • SUSPICIOUS

    • Reads the Internet Settings

      • winlock5404_9d429e7056cae76bd0dbaf1dfd68af8af184cd66.exe (PID: 328)
    • Reads security settings of Internet Explorer

      • winlock5404_9d429e7056cae76bd0dbaf1dfd68af8af184cd66.exe (PID: 328)
    • Reads Microsoft Outlook installation path

      • winlock5404_9d429e7056cae76bd0dbaf1dfd68af8af184cd66.exe (PID: 328)
    • Reads Internet Explorer settings

      • winlock5404_9d429e7056cae76bd0dbaf1dfd68af8af184cd66.exe (PID: 328)
    • Checks for external IP

      • winlock5404_9d429e7056cae76bd0dbaf1dfd68af8af184cd66.exe (PID: 328)
    • There is functionality for taking screenshot (YARA)

      • winlock5404_9d429e7056cae76bd0dbaf1dfd68af8af184cd66.exe (PID: 328)
  • INFO

    • The sample compiled with english language support

      • WinRAR.exe (PID: 2480)
    • Manual execution by a user

      • winlock5404_9d429e7056cae76bd0dbaf1dfd68af8af184cd66.exe (PID: 328)
    • Reads the computer name

      • winlock5404_9d429e7056cae76bd0dbaf1dfd68af8af184cd66.exe (PID: 328)
    • Checks supported languages

      • winlock5404_9d429e7056cae76bd0dbaf1dfd68af8af184cd66.exe (PID: 328)
    • Application launched itself

      • iexplore.exe (PID: 2100)
      • iexplore.exe (PID: 988)
      • iexplore.exe (PID: 1268)
      • iexplore.exe (PID: 2732)
      • iexplore.exe (PID: 2204)
      • iexplore.exe (PID: 984)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2480)
    • Reads the machine GUID from the registry

      • winlock5404_9d429e7056cae76bd0dbaf1dfd68af8af184cd66.exe (PID: 328)
    • Checks proxy server information

      • winlock5404_9d429e7056cae76bd0dbaf1dfd68af8af184cd66.exe (PID: 328)
    • Creates files or folders in the user directory

      • winlock5404_9d429e7056cae76bd0dbaf1dfd68af8af184cd66.exe (PID: 328)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.7z | 7-Zip compressed archive (v0.4) (57.1)
.7z | 7-Zip compressed archive (gen) (42.8)

EXIF

ZIP

FileVersion: 7z v0.04
ModifyDate: 2012:01:09 18:46:58+00:00
ArchivedFileName: winlock5404_9d429e7056cae76bd0dbaf1dfd68af8af184cd66.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
53
Monitored processes
14
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe winlock5404_9d429e7056cae76bd0dbaf1dfd68af8af184cd66.exe iexplore.exe iexplore.exe iexplore.exe iexplore.exe iexplore.exe iexplore.exe iexplore.exe iexplore.exe iexplore.exe iexplore.exe iexplore.exe iexplore.exe

Process information

PID
CMD
Path
Indicators
Parent process
328"C:\Users\admin\Desktop\winlock5404_9d429e7056cae76bd0dbaf1dfd68af8af184cd66.exe" C:\Users\admin\Desktop\winlock5404_9d429e7056cae76bd0dbaf1dfd68af8af184cd66.exe
explorer.exe
User:
admin
Company:
AVM GmbH
Integrity Level:
HIGH
Description:
Mother Owner Renew
Version:
1.1
Modules
Images
c:\users\admin\desktop\winlock5404_9d429e7056cae76bd0dbaf1dfd68af8af184cd66.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imm32.dll
984"C:\Program Files\Internet Explorer\iexplore.exe" http://94.23.183.140/i.php?a=45C:\Program Files\Internet Explorer\iexplore.exe
winlock5404_9d429e7056cae76bd0dbaf1dfd68af8af184cd66.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Internet Explorer
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
988"C:\Program Files\Internet Explorer\iexplore.exe" http://95.143.198.56/i.php?a=45C:\Program Files\Internet Explorer\iexplore.exe
winlock5404_9d429e7056cae76bd0dbaf1dfd68af8af184cd66.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Internet Explorer
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
1268"C:\Program Files\Internet Explorer\iexplore.exe" http://95.143.198.56/i.php?a=45C:\Program Files\Internet Explorer\iexplore.exe
winlock5404_9d429e7056cae76bd0dbaf1dfd68af8af184cd66.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Internet Explorer
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
2100"C:\Program Files\Internet Explorer\iexplore.exe" http://94.23.183.140/i.php?a=45C:\Program Files\Internet Explorer\iexplore.exe
winlock5404_9d429e7056cae76bd0dbaf1dfd68af8af184cd66.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Internet Explorer
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
2204"C:\Program Files\Internet Explorer\iexplore.exe" http://89.248.165.131/i.php?a=45C:\Program Files\Internet Explorer\iexplore.exe
winlock5404_9d429e7056cae76bd0dbaf1dfd68af8af184cd66.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Internet Explorer
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
2480"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\Desktop\winlock5404_9d429e7056cae76bd0dbaf1dfd68af8af184cd66.7zC:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2732"C:\Program Files\Internet Explorer\iexplore.exe" http://89.248.165.131/i.php?a=45C:\Program Files\Internet Explorer\iexplore.exe
winlock5404_9d429e7056cae76bd0dbaf1dfd68af8af184cd66.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Internet Explorer
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
2956"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:988 CREDAT:275457 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Internet Explorer
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
3072"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2204 CREDAT:275457 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Internet Explorer
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
Total events
49 383
Read events
47 965
Write events
1 237
Delete events
181

Modification events

(PID) Process:(2480) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2480) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2480) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2480) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(2480) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(2480) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(2480) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\winlock5404_9d429e7056cae76bd0dbaf1dfd68af8af184cd66.7z
(PID) Process:(2480) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2480) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2480) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
Executable files
1
Suspicious files
4
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
2204iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{4688B47B-31BC-11F0-B32B-12A9866C77DE}.datbinary
MD5:9BD684EFA41D8074E56C445F821C2B6D
SHA256:3B6C44AA4F403CAAB67FBD6C97A4402F673D9A477490E583A1EA30BC618D179C
2480WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb2480.31398\winlock5404_9d429e7056cae76bd0dbaf1dfd68af8af184cd66.exeexecutable
MD5:D6D66045C58DB10ED0A7C8E9E430A590
SHA256:1E5B6ADE47C98ABF59870B29AF68A3053A4599FDBD743BF3FA1129AE6022B28B
2100iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{4681665D-31BC-11F0-B32B-12A9866C77DE}.datbinary
MD5:4C163D233BE6A073EF16FCADE4C243CD
SHA256:BE2E2E3FDDAFDC16F5DD70A64191090725435450AD116D8386C85E0B1B755363
1268iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{467CA1A9-31BC-11F0-B32B-12A9866C77DE}.datbinary
MD5:D3EB9D825DD1CBC9CD71FEAD7DC49A3D
SHA256:E53390349FC394524CF9A02FDBD9A2B61B97DB26DEDC89A52834A5C0DB4C5D0B
2732iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{46888D6B-31BC-11F0-B32B-12A9866C77DE}.datbinary
MD5:6E781E50D132E0D6BADBC7B3B378E295
SHA256:8E65FA56A6BE056C8EBF23F83CD38D548DAB1521923E22D4FCA90377B47B95C3
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
26
TCP/UDP connections
57
DNS requests
36
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2956
iexplore.exe
GET
404
95.143.198.56:80
http://95.143.198.56/i.php?a=45
unknown
unknown
3088
iexplore.exe
GET
404
94.23.183.140:80
http://94.23.183.140/i.php?a=45
unknown
unknown
3072
iexplore.exe
GET
404
89.248.165.131:80
http://89.248.165.131/i.php?a=45
unknown
unknown
3776
iexplore.exe
GET
404
94.23.183.140:80
http://94.23.183.140/i.php?a=45
unknown
unknown
3656
iexplore.exe
GET
404
89.248.165.131:80
http://89.248.165.131/i.php?a=45
unknown
unknown
3748
iexplore.exe
GET
404
95.143.198.56:80
http://95.143.198.56/i.php?a=45
unknown
unknown
328
winlock5404_9d429e7056cae76bd0dbaf1dfd68af8af184cd66.exe
GET
404
149.248.7.185:80
http://tools.ip2location.com/ib2/
unknown
unknown
984
iexplore.exe
GET
404
199.232.214.172:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?8dc7eed8c1f42698
unknown
whitelisted
988
iexplore.exe
GET
404
199.232.214.172:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?a09a047769cf5bcf
unknown
whitelisted
1268
iexplore.exe
GET
404
199.232.210.172:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?b75afd84ff3fd676
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
224.0.0.252:5355
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
whitelisted
2956
iexplore.exe
95.143.198.56:80
Internetport Sweden AB
SE
unknown
3088
iexplore.exe
94.23.183.140:80
OVH SAS
FR
unknown
3748
iexplore.exe
95.143.198.56:80
Internetport Sweden AB
SE
unknown
3072
iexplore.exe
89.248.165.131:80
IP Volume inc
NL
unknown
3776
iexplore.exe
94.23.183.140:80
OVH SAS
FR
unknown
3656
iexplore.exe
89.248.165.131:80
IP Volume inc
NL
unknown

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.186.142
whitelisted
tools.ip2location.com
  • 149.248.7.185
unknown
api.bing.com
  • 13.107.5.80
whitelisted
www.bing.com
  • 2.19.96.74
  • 2.19.96.80
  • 2.19.96.90
  • 2.19.96.50
  • 2.19.96.25
  • 2.19.96.49
  • 2.19.96.67
  • 2.19.96.26
whitelisted
ctldl.windowsupdate.com
  • 199.232.214.172
  • 199.232.210.172
whitelisted
r20swj13mr.microsoft.com
  • 49.13.77.253
whitelisted
iecvlist.microsoft.com
  • 52.239.160.33
whitelisted

Threats

PID
Process
Class
Message
328
winlock5404_9d429e7056cae76bd0dbaf1dfd68af8af184cd66.exe
Device Retrieving External IP Address Detected
ET INFO External IP Lookup - ip2location.com
No debug info