File name:

AirExplorer_5.6.1_Portable.7z

Full analysis: https://app.any.run/tasks/1c011d34-fb86-4ba6-88bf-41035ccdfc07
Verdict: Malicious activity
Analysis date: September 26, 2024, 22:54:44
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
opendir
netreactor
Indicators:
MIME: application/x-7z-compressed
File info: 7-zip archive data, version 0.4
MD5:

C2F93900A098B47F2599D7D876248E51

SHA1:

3BC33E1262FC350494B7EB9EDD3D167CAD57AB6E

SHA256:

8225E9976C179ED023B998A41CD0152E693A33B864F6648DB8CB8306CD7277AE

SSDEEP:

98304:OLAohNvhP+0nyPN8r05yphf2+BLrtFqTM4BReucaAaQt4tGUinz1s7ZIhhmDcr9D:+g7B6He90VRVbd

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • WinRAR.exe (PID: 1148)
    • Write to the desktop.ini file (may be used to cloak folders)

      • WinRAR.exe (PID: 1148)
    • The process creates files with name similar to system file names

      • WinRAR.exe (PID: 1148)
    • Starts CMD.EXE for commands execution

      • Air Explorer-1.exe (PID: 4920)
    • Executable content was dropped or overwritten

      • Air Explorer-1.exe (PID: 4920)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • Air Explorer-1.exe (PID: 4920)
  • INFO

    • The process uses the downloaded file

      • WinRAR.exe (PID: 1148)
    • .NET Reactor protector has been detected

      • AirExplorer.exe (PID: 4976)
    • Manual execution by a user

      • Air Explorer-1.exe (PID: 6432)
      • Air Explorer-1.exe (PID: 4920)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 1148)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.7z | 7-Zip compressed archive (v0.4) (57.1)
.7z | 7-Zip compressed archive (gen) (42.8)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
137
Monitored processes
9
Malicious processes
0
Suspicious processes
2

Behavior graph

Click at the process to see the details
start winrar.exe rundll32.exe no specs air explorer-1.exe no specs air explorer-1.exe cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs THREAT airexplorer.exe

Process information

PID
CMD
Path
Indicators
Parent process
1148"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\AirExplorer_5.6.1_Portable.7zC:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
3040\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
4920"C:\Users\admin\Desktop\AirExplorer_5.6.1_Portable\Air Explorer-1.exe" C:\Users\admin\Desktop\AirExplorer_5.6.1_Portable\Air Explorer-1.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Description:
Air Explorer Portable
Version:
0.0.0.0
Modules
Images
c:\users\admin\desktop\airexplorer_5.6.1_portable\air explorer-1.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
4976C:\Users\admin\Desktop\AirExplorer_5.6.1_Portable\App\AirExplorer.exeC:\Users\admin\Desktop\AirExplorer_5.6.1_Portable\App\AirExplorer.exe
Air Explorer-1.exe
User:
admin
Integrity Level:
HIGH
Description:
Air Explorer
Version:
5.6.1.0
Modules
Images
c:\users\admin\desktop\airexplorer_5.6.1_portable\app\airexplorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
5492cmd /c MKLINK /J "%APPDATA%\AirExplorer" "C:\Users\admin\Desktop\AirExplorer_5.6.1_Portable\Data\S-1-5-21-1693682860-607145093-2874071422-1001\AirExplorer-1"C:\Windows\SysWOW64\cmd.exeAir Explorer-1.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
6432"C:\Users\admin\Desktop\AirExplorer_5.6.1_Portable\Air Explorer-1.exe" C:\Users\admin\Desktop\AirExplorer_5.6.1_Portable\Air Explorer-1.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Air Explorer Portable
Exit code:
3221226540
Version:
0.0.0.0
Modules
Images
c:\users\admin\desktop\airexplorer_5.6.1_portable\air explorer-1.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
6448\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
6708C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -EmbeddingC:\Windows\System32\rundll32.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shcore.dll
c:\windows\system32\imagehlp.dll
7088cmd /c "echo 0.0.0.0 www.airexplorer.net>> C:\WINDOWS\system32\drivers\etc\hosts"C:\Windows\SysWOW64\cmd.exeAir Explorer-1.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
Total events
10 999
Read events
10 948
Write events
41
Delete events
10

Modification events

(PID) Process:(1148) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\GoogleChromeEnterpriseBundle64.zip
(PID) Process:(1148) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\AirExplorer_5.6.1_Portable.7z
(PID) Process:(1148) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(1148) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(1148) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(1148) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(1148) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF3D0000002D000000FD03000016020000
(PID) Process:(1148) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\ArcColumnWidths
Operation:writeName:name
Value:
256
(PID) Process:(1148) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\ArcColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(1148) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\ArcColumnWidths
Operation:writeName:psize
Value:
80
Executable files
54
Suspicious files
12
Text files
16
Unknown types
0

Dropped files

PID
Process
Filename
Type
1148WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1148.11397\AirExplorer_5.6.1_Portable\App\AirExplorerCmd.exe.configxml
MD5:DDC25AEFCAE9826CCE1754C2C89E959D
SHA256:F8AD17C37D444521B3905CCBD75EA6CB6E3D2763B16EB56B2E1AA4274173E614
1148WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1148.11397\AirExplorer_5.6.1_Portable\App\Language\airexplorer_uk-UA.xmlxml
MD5:565CD6D99BFA68D7B9D2D162ED2ECF6A
SHA256:B46B80D52ABBA60029B77AC2934BF94F26A9B83BA32E343B7E66684354C76079
1148WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1148.11397\AirExplorer_5.6.1_Portable\App\CircularProgressBar.dllexecutable
MD5:E3E063960755CB09EFD78B5D88349E98
SHA256:49CB487E04374BB027E54DA755F79FD6A2F2E9D328C4A95E43C1DDEC71F733A2
1148WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1148.11397\AirExplorer_5.6.1_Portable\Air Explorer-5.exeexecutable
MD5:EFE1DDBA3043A868D2D98DACF6B186CB
SHA256:2E858443893D2DE963F8EE55A6166AF916BDD2AEB648F59E9B6517ACCB26714E
1148WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1148.11397\AirExplorer_5.6.1_Portable\Air Explorer-4.exeexecutable
MD5:2C1CB67BFF3C78C4EBC59324D4D99A48
SHA256:2331FC57636F4E25AB9B5199C435CC9110764FA971C1A7069629A32ADB1CE601
1148WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1148.11397\AirExplorer_5.6.1_Portable\Air Explorer-1.exeexecutable
MD5:A0A30E07C8D2F1BBF5DCB7474D5C3F8C
SHA256:863BD46B062670C0D6D09F364006EC6E3EF674E150633A0992CCF4E0E3058B3E
1148WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1148.11397\AirExplorer_5.6.1_Portable\Air Explorer-3.exeexecutable
MD5:9E424CBBCA78D4C84EFE0B257DE28547
SHA256:9524D4394956F17021CC79CAEC3186251AF54D5E8AA051E6B74095BD87822A9F
1148WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1148.11397\AirExplorer_5.6.1_Portable\App\Language\airexplorer_ru-RU.xmlxml
MD5:0F0856207C3BFAEDA4C0769EC1D4E7FF
SHA256:6E56935488D1164740CC04A7063D88420DF2BA1247B383CF695C3BD37AA6A8E3
1148WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1148.11397\AirExplorer_5.6.1_Portable\App\AirExplorer.exeexecutable
MD5:99023416BCB685CB6DA880BB775EAC1F
SHA256:BE854834FB9B1BAE42277C87EE762AC516940B5825C935D5139D23AF1CE95E7F
1148WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1148.11397\AirExplorer_5.6.1_Portable\App\AWSSDK.Core.dllexecutable
MD5:AF47C966DB5EC1FE971420F059BC4C24
SHA256:88F7B5009122899EEC39C0CAAAAE7F31CF77BEB2CD685C1492CF92AC6175B8B9
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
14
TCP/UDP connections
49
DNS requests
23
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEA77flR%2B3w%2FxBpruV2lte6A%3D
unknown
whitelisted
2524
svchost.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6112
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
6572
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6112
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
4976
AirExplorer.exe
GET
200
95.101.111.144:80
http://subca.ocsp-certum.com/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBRIH1V64SBkA%2BzJQVQ6VFBAcvLB3wQUtqFUOQLDoD%2BOirz61PgcptE6Dv0CEQCZo4AKJlU7ZavcboSms%2Bo5
unknown
whitelisted
4976
AirExplorer.exe
GET
200
95.101.111.144:80
http://subca.ocsp-certum.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTYOkzrrCGQj08njZXbUQQpkoUmuQQUCHbNywf%2FJPbFze27kLzihDdGdfcCEBu1jyUq3yMASSjJrj1%2B7Sc%3D
unknown
whitelisted
4976
AirExplorer.exe
GET
200
95.101.111.144:80
http://subca.ocsp-certum.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTYOkzrrCGQj08njZXbUQQpkoUmuQQUCHbNywf%2FJPbFze27kLzihDdGdfcCEBu1jyUq3yMASSjJrj1%2B7Sc%3D
unknown
whitelisted
4976
AirExplorer.exe
GET
200
104.18.38.233:80
http://ocsp.usertrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTNMNJMNDqCqx8FcBWK16EHdimS6QQUU3m%2FWqorSs9UgOHYm8Cd8rIDZssCEB2iSDBvmyYY0ILgln0z02o%3D
unknown
whitelisted
4976
AirExplorer.exe
GET
200
95.101.111.144:80
http://ccsca2021.ocsp-certum.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRxypYNH69rICCzQBIRXN0YAFa3AAQU3XRdTADbe5%2BgdMqxbvc8wDLAcM0CEEscjPKw%2Bjzc1ISguR3v99g%3D
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4004
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2944
RUXIMICS.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2120
MoUsoCoreWorker.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
51.116.246.105:443
browser.pipe.aria.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
DE
whitelisted
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2524
svchost.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
3888
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:138
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
  • 20.73.194.208
  • 40.127.240.158
whitelisted
browser.pipe.aria.microsoft.com
  • 51.116.246.105
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
www.microsoft.com
  • 184.30.21.171
  • 95.101.149.131
whitelisted
google.com
  • 142.250.186.110
whitelisted
go.microsoft.com
  • 23.35.238.131
whitelisted
login.live.com
  • 40.126.31.67
  • 20.190.159.0
  • 20.190.159.64
  • 20.190.159.75
  • 20.190.159.23
  • 40.126.31.69
  • 40.126.31.73
  • 20.190.159.4
whitelisted
slscr.update.microsoft.com
  • 13.85.23.86
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 20.3.187.198
whitelisted
nexusrules.officeapps.live.com
  • 52.111.229.48
whitelisted

Threats

No threats detected
No debug info