analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

1.rar

Full analysis: https://app.any.run/tasks/3e354ae1-b424-48c0-b9b2-3226131fd5e4
Verdict: Malicious activity
Analysis date: April 23, 2019, 08:43:29
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

CBB5BA28A8E99F01CC9587A11822157F

SHA1:

8F49847FB98E46E009B1944002B53FCFA8CCE48C

SHA256:

8153ABFA38D3AB2DDA7BF3776E9B7EF8AC8313D7ACE2DB654ABC7C8E7513CD7F

SSDEEP:

6144:PCXR/yosaaq00uwyd6IeduRQJv2MYB+NyDB6xDONafrEf5qbu75fRP9zeHJT8L/h:PMRsaaq03wyEWk93NocONArLbl18L/rF

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • Nord VPN.exe (PID: 2504)
      • WerFault.exe (PID: 3648)
      • SearchProtocolHost.exe (PID: 3888)
      • Nord VPN.exe (PID: 3116)
      • Nord VPN.exe (PID: 3096)
    • Application was dropped or rewritten from another process

      • Nord VPN.exe (PID: 2504)
      • Nord VPN.exe (PID: 3096)
      • Nord VPN.exe (PID: 3116)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2580)
      • Nord VPN.exe (PID: 2504)
  • INFO

    • Application was crashed

      • Nord VPN.exe (PID: 2504)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
37
Monitored processes
6
Malicious processes
3
Suspicious processes
2

Behavior graph

Click at the process to see the details
start winrar.exe searchprotocolhost.exe no specs nord vpn.exe werfault.exe no specs nord vpn.exe no specs nord vpn.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2580"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\1.rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.60.0
3888"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe4_ Global\UsGthrCtrlFltPipeMssGthrPipe4 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" C:\Windows\System32\SearchProtocolHost.exeSearchIndexer.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Windows Search Protocol Host
Exit code:
0
Version:
7.00.7600.16385 (win7_rtm.090713-1255)
2504"C:\Users\admin\Desktop\NordVPN Spaceman\Nord VPN.exe" C:\Users\admin\Desktop\NordVPN Spaceman\Nord VPN.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Nord VPN
Exit code:
3221225477
Version:
1.0.0.0
3648C:\Windows\system32\WerFault.exe -u -p 2504 -s 760C:\Windows\system32\WerFault.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Problem Reporting
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
3116"C:\Users\admin\Desktop\NordVPN Spaceman\Nord VPN.exe" C:\Users\admin\Desktop\NordVPN Spaceman\Nord VPN.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Nord VPN
Exit code:
0
Version:
1.0.0.0
3096"C:\Users\admin\Desktop\NordVPN Spaceman\Nord VPN.exe" C:\Users\admin\Desktop\NordVPN Spaceman\Nord VPN.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Nord VPN
Version:
1.0.0.0
Total events
809
Read events
799
Write events
10
Delete events
0

Modification events

(PID) Process:(2580) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2580) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2580) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\62\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2580) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\1.rar
(PID) Process:(2580) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2580) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2580) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2580) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3888) SearchProtocolHost.exeKey:HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\62\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3888) SearchProtocolHost.exeKey:HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\62\52C64B7E
Operation:writeName:@C:\Windows\System32\msxml3r.dll,-1
Value:
XML Document
Executable files
5
Suspicious files
1
Text files
8
Unknown types
2

Dropped files

PID
Process
Filename
Type
3648WerFault.exeC:\Users\admin\AppData\Local\CrashDumps\Nord VPN.exe.2504.dmp
MD5:
SHA256:
2580WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2580.3651\NordVPN Spaceman\Nord VPN.xmlxml
MD5:0AB22309C317B4464CC9926C20DD5DF0
SHA256:75ADF3DB1231BA8D1E891DEADBCB41C733F9401A4D1B276BFE19B2B09550215C
2580WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2580.3334\NordVPN Spaceman\Nord VPN.xmlxml
MD5:0AB22309C317B4464CC9926C20DD5DF0
SHA256:75ADF3DB1231BA8D1E891DEADBCB41C733F9401A4D1B276BFE19B2B09550215C
2580WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2580.3334\NordVPN Spaceman\nord.icoimage
MD5:FC5FB10168F43C796A428D8D7E589819
SHA256:35C4D7C5DBB2569AA33692CA0FAFD4FEDD5B8421389C8E426BC3F80CBD9AE8D4
2580WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2580.3334\NordVPN Spaceman\Nord VPN.pdbpdb
MD5:E90E9BE439B7297D575483331958FE2B
SHA256:9CFE02BB053223E576505EC4E477951CCAA6822C2039D05806E9CBEA53F3976B
2580WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2580.3334\NordVPN Spaceman\Nord VPN.exeexecutable
MD5:93ABCB2C37FAAD68B03356A127B55390
SHA256:1975DE6FFE745E38FD7EC470B81FFBE98A840839BA179B2D42D81D91D3C0836D
2580WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2580.3651\NordVPN Spaceman\nord.icoimage
MD5:FC5FB10168F43C796A428D8D7E589819
SHA256:35C4D7C5DBB2569AA33692CA0FAFD4FEDD5B8421389C8E426BC3F80CBD9AE8D4
2580WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2580.3651\NordVPN Spaceman\Nord VPN.pdbpdb
MD5:E90E9BE439B7297D575483331958FE2B
SHA256:9CFE02BB053223E576505EC4E477951CCAA6822C2039D05806E9CBEA53F3976B
2580WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2580.3651\NordVPN Spaceman\Nord VPN.exeexecutable
MD5:93ABCB2C37FAAD68B03356A127B55390
SHA256:1975DE6FFE745E38FD7EC470B81FFBE98A840839BA179B2D42D81D91D3C0836D
3648WerFault.exeC:\Users\admin\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_Nord VPN.exe_d9e8eb9b6f4cebd4a65d170f6978b8c9e7e1081_0e50e64b\Report.werbinary
MD5:7409FDA6E9CB0959DC4BB2A6D230A24B
SHA256:BE589B61E4583EE10622A9531D2D231B71AA4AA8C6A6859C0B536B4E43FF12E7
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info