File name:

AirExplorer_5.6.1_Portable.7z

Full analysis: https://app.any.run/tasks/1c011d34-fb86-4ba6-88bf-41035ccdfc07
Verdict: Malicious activity
Analysis date: September 26, 2024, 22:54:44
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
opendir
netreactor
Indicators:
MIME: application/x-7z-compressed
File info: 7-zip archive data, version 0.4
MD5:

C2F93900A098B47F2599D7D876248E51

SHA1:

3BC33E1262FC350494B7EB9EDD3D167CAD57AB6E

SHA256:

8225E9976C179ED023B998A41CD0152E693A33B864F6648DB8CB8306CD7277AE

SSDEEP:

98304:OLAohNvhP+0nyPN8r05yphf2+BLrtFqTM4BReucaAaQt4tGUinz1s7ZIhhmDcr9D:+g7B6He90VRVbd

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • The process creates files with name similar to system file names

      • WinRAR.exe (PID: 1148)
    • Process drops legitimate windows executable

      • WinRAR.exe (PID: 1148)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • Air Explorer-1.exe (PID: 4920)
    • Executable content was dropped or overwritten

      • Air Explorer-1.exe (PID: 4920)
    • Starts CMD.EXE for commands execution

      • Air Explorer-1.exe (PID: 4920)
    • Write to the desktop.ini file (may be used to cloak folders)

      • WinRAR.exe (PID: 1148)
  • INFO

    • The process uses the downloaded file

      • WinRAR.exe (PID: 1148)
    • .NET Reactor protector has been detected

      • AirExplorer.exe (PID: 4976)
    • Manual execution by a user

      • Air Explorer-1.exe (PID: 6432)
      • Air Explorer-1.exe (PID: 4920)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 1148)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.7z | 7-Zip compressed archive (v0.4) (57.1)
.7z | 7-Zip compressed archive (gen) (42.8)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
137
Monitored processes
9
Malicious processes
0
Suspicious processes
2

Behavior graph

Click at the process to see the details
start winrar.exe rundll32.exe no specs air explorer-1.exe no specs air explorer-1.exe cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs THREAT airexplorer.exe

Process information

PID
CMD
Path
Indicators
Parent process
1148"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\AirExplorer_5.6.1_Portable.7zC:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
3040\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
4920"C:\Users\admin\Desktop\AirExplorer_5.6.1_Portable\Air Explorer-1.exe" C:\Users\admin\Desktop\AirExplorer_5.6.1_Portable\Air Explorer-1.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Description:
Air Explorer Portable
Version:
0.0.0.0
Modules
Images
c:\users\admin\desktop\airexplorer_5.6.1_portable\air explorer-1.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
4976C:\Users\admin\Desktop\AirExplorer_5.6.1_Portable\App\AirExplorer.exeC:\Users\admin\Desktop\AirExplorer_5.6.1_Portable\App\AirExplorer.exe
Air Explorer-1.exe
User:
admin
Integrity Level:
HIGH
Description:
Air Explorer
Version:
5.6.1.0
Modules
Images
c:\users\admin\desktop\airexplorer_5.6.1_portable\app\airexplorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
5492cmd /c MKLINK /J "%APPDATA%\AirExplorer" "C:\Users\admin\Desktop\AirExplorer_5.6.1_Portable\Data\S-1-5-21-1693682860-607145093-2874071422-1001\AirExplorer-1"C:\Windows\SysWOW64\cmd.exeAir Explorer-1.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
6432"C:\Users\admin\Desktop\AirExplorer_5.6.1_Portable\Air Explorer-1.exe" C:\Users\admin\Desktop\AirExplorer_5.6.1_Portable\Air Explorer-1.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Air Explorer Portable
Exit code:
3221226540
Version:
0.0.0.0
Modules
Images
c:\users\admin\desktop\airexplorer_5.6.1_portable\air explorer-1.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
6448\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
6708C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -EmbeddingC:\Windows\System32\rundll32.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shcore.dll
c:\windows\system32\imagehlp.dll
7088cmd /c "echo 0.0.0.0 www.airexplorer.net>> C:\WINDOWS\system32\drivers\etc\hosts"C:\Windows\SysWOW64\cmd.exeAir Explorer-1.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
Total events
10 999
Read events
10 948
Write events
41
Delete events
10

Modification events

(PID) Process:(1148) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\GoogleChromeEnterpriseBundle64.zip
(PID) Process:(1148) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\AirExplorer_5.6.1_Portable.7z
(PID) Process:(1148) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(1148) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(1148) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(1148) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(1148) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF3D0000002D000000FD03000016020000
(PID) Process:(1148) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\ArcColumnWidths
Operation:writeName:name
Value:
256
(PID) Process:(1148) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\ArcColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(1148) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\ArcColumnWidths
Operation:writeName:psize
Value:
80
Executable files
54
Suspicious files
12
Text files
16
Unknown types
0

Dropped files

PID
Process
Filename
Type
1148WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1148.11397\AirExplorer_5.6.1_Portable\desktop.iniini
MD5:07102F20B72F2843E82FB57D11E16C47
SHA256:9B725B4226A24817DAFA2E387D8761263A03D8202294B590A5F40742A4678256
1148WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1148.11397\AirExplorer_5.6.1_Portable\App\Language\airexplorer_ru-RU.xmlxml
MD5:0F0856207C3BFAEDA4C0769EC1D4E7FF
SHA256:6E56935488D1164740CC04A7063D88420DF2BA1247B383CF695C3BD37AA6A8E3
1148WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1148.11397\AirExplorer_5.6.1_Portable\App\AirExplorerCmd.exe.configxml
MD5:DDC25AEFCAE9826CCE1754C2C89E959D
SHA256:F8AD17C37D444521B3905CCBD75EA6CB6E3D2763B16EB56B2E1AA4274173E614
1148WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1148.11397\AirExplorer_5.6.1_Portable\К сведению.txttext
MD5:D26CAB05E09452DEDBB9B13B151282F7
SHA256:22632E1B2ED268224FD559C30A9131459837124E5C8619E39BCAD7B179A75DD1
1148WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1148.11397\AirExplorer_5.6.1_Portable\App\AirExplorer.exe.configxml
MD5:B3397C6E8105D5439227C0263A0E3D2F
SHA256:B4D9717A2FD2E664527BCA9FB6446FFC743F52EFB7278EBC2C9D949EA79C85FD
1148WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1148.11397\AirExplorer_5.6.1_Portable\App\Language\airexplorer_en-US.xmlxml
MD5:1A5D45BEDA7CFE29EF151528224FD7DF
SHA256:513A7F6EF3F0238AAF781552CEDEC96F9DF8F179A61DB02E83D8F12B04371984
1148WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1148.11397\AirExplorer_5.6.1_Portable\App\Language\airexplorer_uk-UA.xmlxml
MD5:565CD6D99BFA68D7B9D2D162ED2ECF6A
SHA256:B46B80D52ABBA60029B77AC2934BF94F26A9B83BA32E343B7E66684354C76079
1148WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1148.11397\AirExplorer_5.6.1_Portable\Air Explorer-1.exeexecutable
MD5:A0A30E07C8D2F1BBF5DCB7474D5C3F8C
SHA256:863BD46B062670C0D6D09F364006EC6E3EF674E150633A0992CCF4E0E3058B3E
1148WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1148.11397\AirExplorer_5.6.1_Portable\Air Explorer-4.exeexecutable
MD5:2C1CB67BFF3C78C4EBC59324D4D99A48
SHA256:2331FC57636F4E25AB9B5199C435CC9110764FA971C1A7069629A32ADB1CE601
1148WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1148.11397\AirExplorer_5.6.1_Portable\App\AirExplorer.exeexecutable
MD5:99023416BCB685CB6DA880BB775EAC1F
SHA256:BE854834FB9B1BAE42277C87EE762AC516940B5825C935D5139D23AF1CE95E7F
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
14
TCP/UDP connections
49
DNS requests
23
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2524
svchost.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEA77flR%2B3w%2FxBpruV2lte6A%3D
unknown
whitelisted
6572
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6112
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
6112
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
4976
AirExplorer.exe
GET
200
95.101.111.151:80
http://crl.certum.pl/ctnca.crl
unknown
whitelisted
4976
AirExplorer.exe
GET
200
95.101.111.144:80
http://subca.ocsp-certum.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTYOkzrrCGQj08njZXbUQQpkoUmuQQUCHbNywf%2FJPbFze27kLzihDdGdfcCEBu1jyUq3yMASSjJrj1%2B7Sc%3D
unknown
whitelisted
4976
AirExplorer.exe
GET
200
95.101.111.144:80
http://subca.ocsp-certum.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTYOkzrrCGQj08njZXbUQQpkoUmuQQUCHbNywf%2FJPbFze27kLzihDdGdfcCEBu1jyUq3yMASSjJrj1%2B7Sc%3D
unknown
whitelisted
4976
AirExplorer.exe
GET
200
104.18.38.233:80
http://ocsp.usertrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTNMNJMNDqCqx8FcBWK16EHdimS6QQUU3m%2FWqorSs9UgOHYm8Cd8rIDZssCEB2iSDBvmyYY0ILgln0z02o%3D
unknown
whitelisted
4976
AirExplorer.exe
GET
200
95.101.111.144:80
http://ccsca2021.ocsp-certum.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRxypYNH69rICCzQBIRXN0YAFa3AAQU3XRdTADbe5%2BgdMqxbvc8wDLAcM0CEEscjPKw%2Bjzc1ISguR3v99g%3D
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4004
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2944
RUXIMICS.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2120
MoUsoCoreWorker.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
51.116.246.105:443
browser.pipe.aria.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
DE
whitelisted
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2524
svchost.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
3888
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:138
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
  • 20.73.194.208
  • 40.127.240.158
whitelisted
browser.pipe.aria.microsoft.com
  • 51.116.246.105
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
www.microsoft.com
  • 184.30.21.171
  • 95.101.149.131
whitelisted
google.com
  • 142.250.186.110
whitelisted
go.microsoft.com
  • 23.35.238.131
whitelisted
login.live.com
  • 40.126.31.67
  • 20.190.159.0
  • 20.190.159.64
  • 20.190.159.75
  • 20.190.159.23
  • 40.126.31.69
  • 40.126.31.73
  • 20.190.159.4
whitelisted
slscr.update.microsoft.com
  • 13.85.23.86
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 20.3.187.198
whitelisted
nexusrules.officeapps.live.com
  • 52.111.229.48
whitelisted

Threats

No threats detected
No debug info