File name:

RECYCLER.BIN.rar

Full analysis: https://app.any.run/tasks/68afa3b4-c024-4407-893f-81ca86cc6ff9
Verdict: Malicious activity
Analysis date: April 17, 2020, 07:38:52
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v4, os: Win32
MD5:

3B7824176F12CA9E93C61FD0713BCA2F

SHA1:

92E59D5CDE77B0EFA5DDC67033AC9007C67926F8

SHA256:

80C9A1938C69E3262923B528ED3DC2A4EEF9451C673CB93465C33EE12B312CE2

SSDEEP:

3072:iA/rHleXO26sBALweEHKE4cDlQifB3Ckvi246x3kDcPZha+mii+1y:iozY6sBALqHKzUlQipDviTIhh9i+U

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • explorer.exe (PID: 4084)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3920)
    • Writes to a desktop.ini file (may be used to cloak folders)

      • WinRAR.exe (PID: 3920)
    • Uses RUNDLL32.EXE to load library

      • WinRAR.exe (PID: 3920)
    • Creates executable files which already exist in Windows

      • WinRAR.exe (PID: 3920)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v-4.x) (58.3)
.rar | RAR compressed archive (gen) (41.6)

EXIF

ZIP

CompressedSize: 99493
UncompressedSize: 160779
OperatingSystem: Win32
ModifyDate: 2020:01:07 15:47:11
PackingMethod: Normal
ArchivedFileName: RECYCLER.BIN\adobeupdate.dat
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
42
Monitored processes
5
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
drop and start start winrar.exe explorer.exe no specs notepad.exe no specs rundll32.exe no specs rundll32.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
3048"C:\Windows\system32\rundll32.exe" C:\Windows\system32\shell32.dll,OpenAs_RunDLL C:\Users\admin\AppData\Local\Temp\Rar$DIa3920.49865\adobeupdate.datC:\Windows\system32\rundll32.exeWinRAR.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
3488"C:\Windows\system32\NOTEPAD.EXE" C:\Users\admin\AppData\Local\Temp\Rar$DIa3920.48963\desktop.iniC:\Windows\system32\NOTEPAD.EXEWinRAR.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\notepad.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3920"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\RECYCLER.BIN.rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3988"C:\Windows\system32\rundll32.exe" C:\Windows\system32\shell32.dll,OpenAs_RunDLL C:\Users\admin\AppData\Local\Temp\Rar$DIa3920.1716\adobeupdate.datC:\Windows\system32\rundll32.exeWinRAR.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
4084"C:\Users\admin\AppData\Local\Temp\Rar$EXa3920.48507\RECYCLER.BIN\explorer.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3920.48507\RECYCLER.BIN\explorer.exeWinRAR.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
MEDIUM
Description:
Adobe CEF Helper
Exit code:
0
Version:
3.9.0.327
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3920.48507\recycler.bin\explorer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
Total events
461
Read events
444
Write events
17
Delete events
0

Modification events

(PID) Process:(3920) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3920) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3920) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3920) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\RECYCLER.BIN.rar
(PID) Process:(3920) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3920) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3920) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3920) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3920) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(3920) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
Executable files
1
Suspicious files
3
Text files
2
Unknown types
0

Dropped files

PID
Process
Filename
Type
3920WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DIa3920.1716\adobeupdate.datbinary
MD5:58BDF783DA4C627D2F13612A09A9B5A8
SHA256:E3FAFA3B5C5EB9EDD1002A848312BC182460F2FF9C0DF732E6B6ACF6E00FC5EA
3920WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3920.48507\RECYCLER.BIN\desktop.iniini
MD5:295E2C458447AD6C7315FB993804A7DE
SHA256:FBEA7BF4E29763EAE80BBFAAE38DBDBCCFDFCCA562959C2714ADB17844FE8954
3920WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DIa3920.49865\adobeupdate.datbinary
MD5:58BDF783DA4C627D2F13612A09A9B5A8
SHA256:E3FAFA3B5C5EB9EDD1002A848312BC182460F2FF9C0DF732E6B6ACF6E00FC5EA
3920WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3920.48507\RECYCLER.BIN\adobeupdate.datbinary
MD5:58BDF783DA4C627D2F13612A09A9B5A8
SHA256:E3FAFA3B5C5EB9EDD1002A848312BC182460F2FF9C0DF732E6B6ACF6E00FC5EA
3920WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DIa3920.48963\desktop.iniini
MD5:295E2C458447AD6C7315FB993804A7DE
SHA256:FBEA7BF4E29763EAE80BBFAAE38DBDBCCFDFCCA562959C2714ADB17844FE8954
3920WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3920.48507\RECYCLER.BIN\explorer.exeexecutable
MD5:C70D8DCE46B4551133ECC58AED84BF0E
SHA256:0459E62C5444896D5BE404C559C834BA455FA5CAE1689C70FC8C61BC15468681
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info