File name:

SunCrypt.zip

Full analysis: https://app.any.run/tasks/1022c40d-efc7-4408-82ef-33721a53f64d
Verdict: Malicious activity
Analysis date: February 02, 2021, 16:36:36
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

517C860A64851BDD8D89B51548D087A4

SHA1:

C99DDC3002617BD8FE46CCEACAFFC198A3BEE194

SHA256:

871657C601626BD84E38467213E7C30FF7D611ACFA0DCA351C21B589572CCE4E

SSDEEP:

6144:58oRDYnekRplQHG7gY79MAkRplQHG7gY79MNnOE6MXDri5Gvk+Q02p8EDYukZmal:jD9kr6Gkr6fn1DwGv552p8EDY7pFZB

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops executable file immediately after starts

      • DllHost.exe (PID: 1948)
  • SUSPICIOUS

    • Drops a file with too old compile date

      • DllHost.exe (PID: 1948)
      • WinRAR.exe (PID: 2524)
    • Executed via COM

      • DllHost.exe (PID: 1948)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2524)
      • DllHost.exe (PID: 1948)
  • INFO

    • Manual execution by user

      • WinRAR.exe (PID: 1180)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2021:02:02 14:34:28
ZipCRC: 0x412de8ee
ZipCompressedSize: 77901
ZipUncompressedSize: 149504
ZipFileName: decryptor.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
43
Monitored processes
3
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe winrar.exe no specs Copy/Move/Rename/Delete/Link Object

Process information

PID
CMD
Path
Indicators
Parent process
1180"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\SunCrypt.zip"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
1948C:\Windows\system32\DllHost.exe /Processid:{3AD05575-8857-4850-9277-11B85BDB8E09}C:\Windows\system32\DllHost.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
COM Surrogate
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\dllhost.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2524"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\SunCrypt.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
Total events
755
Read events
717
Write events
38
Delete events
0

Modification events

(PID) Process:(2524) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2524) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2524) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\13B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2524) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\SunCrypt.zip
(PID) Process:(2524) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2524) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2524) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2524) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(1180) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(1180) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
Executable files
8
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
2524WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2524.15424\SunCrypt.exe
MD5:
SHA256:
2524WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2524.19115\decryptor_1.exeexecutable
MD5:
SHA256:
1948DllHost.exeC:\Program Files\Common Files\decryptor.exeexecutable
MD5:
SHA256:
2524WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2524.19115\decryptor_2.exeexecutable
MD5:
SHA256:
2524WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2524.19115\decryptor.exeexecutable
MD5:
SHA256:
1948DllHost.exeC:\Program Files\Common Files\decryptor_2.exeexecutable
MD5:
SHA256:
1948DllHost.exeC:\Program Files\Common Files\decryptor_1.exeexecutable
MD5:
SHA256:
2524WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2524.19115\SunCrypt.exeexecutable
MD5:3721354256C68818C9D0B5CB349A73D3
SHA256:0D7ED584DD1AE3CC071AD1B2400A5C534D19206BE7A98A6046959A7267C063A1
1948DllHost.exeC:\Program Files\Common Files\SunCrypt.exeexecutable
MD5:3721354256C68818C9D0B5CB349A73D3
SHA256:0D7ED584DD1AE3CC071AD1B2400A5C534D19206BE7A98A6046959A7267C063A1
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info