File name:

RFC.zip

Full analysis: https://app.any.run/tasks/33cdf8b1-2cbe-46e7-a607-da98a93b553f
Verdict: Malicious activity
Analysis date: May 25, 2023, 21:58:48
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

2B9B0F60E87672C9303C73E8101B0DEA

SHA1:

8F70B4EAD756F078CE174651D359D51A9D235895

SHA256:

88DF2FCD7D7B242401C63AE1528046D006596FD74E7FFFBF9CEA127AC28CDC75

SSDEEP:

12:5j3ZnJQXkkvqaRoVXVpm25zNNazVxdhnJa8:9ApyAol3Yf

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Application launched itself

      • WinRAR.exe (PID: 3024)
  • INFO

    • Manual execution by a user

      • WinRAR.exe (PID: 3088)
      • WinRAR.exe (PID: 3024)
      • WinRAR.exe (PID: 876)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipFileName: RFC/RFC_394441.zip
ZipUncompressedSize: 315
ZipCompressedSize: 315
ZipCRC: 0x0b6edbec
ZipModifyDate: 2023:05:18 10:24:46
ZipCompression: None
ZipBitFlag: -
ZipRequiredVersion: 20
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
53
Monitored processes
5
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe no specs winrar.exe no specs winrar.exe no specs winrar.exe no specs winrar.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
116"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\RFC.zip"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
312"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\Rar$DIa3024.6076\RFC_394441.zipC:\Program Files\WinRAR\WinRAR.exeWinRAR.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
876"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\RFC_394441.zip"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3024"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\RFC.zip"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\windows\system32\ntdll.dll
c:\program files\winrar\winrar.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3088"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\RFC_394441.zip"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\windows\system32\ntdll.dll
c:\program files\winrar\winrar.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
Total events
3 918
Read events
3 868
Write events
50
Delete events
0

Modification events

(PID) Process:(116) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16D\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(116) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(116) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(116) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(116) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(116) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(116) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(116) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3088) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16D\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3088) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
Executable files
0
Suspicious files
2
Text files
5
Unknown types
0

Dropped files

PID
Process
Filename
Type
876WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa876.4183\mi.rfc.urltext
MD5:2C875A886A128FC34FF1D8DE57462E95
SHA256:FE2EBC3ACBFC7B1E81EE076A6B83482235B2293262BA31904DA2061BD2B69A6B
3024WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DIa3024.6076\RFC_394441.zipcompressed
MD5:0C33D4CD730E655573C3C30E1697B0A1
SHA256:C5BC26C712384FC56C4D540B04DEECF41BB799DB798BACC17D0A6EAB431E8983
116WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa116.43244\RFC\RFC_394441.zipcompressed
MD5:0C33D4CD730E655573C3C30E1697B0A1
SHA256:C5BC26C712384FC56C4D540B04DEECF41BB799DB798BACC17D0A6EAB431E8983
3088WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3088.44239\mi.rfc.urltext
MD5:2C875A886A128FC34FF1D8DE57462E95
SHA256:FE2EBC3ACBFC7B1E81EE076A6B83482235B2293262BA31904DA2061BD2B69A6B
312WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa312.6614\mi.rfc.urltext
MD5:2C875A886A128FC34FF1D8DE57462E95
SHA256:FE2EBC3ACBFC7B1E81EE076A6B83482235B2293262BA31904DA2061BD2B69A6B
3088WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3088.859\mi.rfc.urltext
MD5:2C875A886A128FC34FF1D8DE57462E95
SHA256:FE2EBC3ACBFC7B1E81EE076A6B83482235B2293262BA31904DA2061BD2B69A6B
3088WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3088.2530\mi.rfc.urltext
MD5:2C875A886A128FC34FF1D8DE57462E95
SHA256:FE2EBC3ACBFC7B1E81EE076A6B83482235B2293262BA31904DA2061BD2B69A6B
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
18
TCP/UDP connections
7
DNS requests
0
Threats
10

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3328
SearchProtocolHost.exe
OPTIONS
200
104.156.149.33:80
http://104.156.149.33/
US
suspicious
828
svchost.exe
OPTIONS
200
104.156.149.33:80
http://104.156.149.33/yes
US
suspicious
828
svchost.exe
PROPFIND
207
104.156.149.33:80
http://104.156.149.33/yes
US
xml
848 b
suspicious
828
svchost.exe
PROPFIND
207
104.156.149.33:80
http://104.156.149.33/yes/4496kxyFLzlbzcqManIipAPdolfO.exe
US
xml
957 b
suspicious
828
svchost.exe
PROPFIND
207
104.156.149.33:80
http://104.156.149.33/yes
US
xml
848 b
suspicious
828
svchost.exe
PROPFIND
207
104.156.149.33:80
http://104.156.149.33/yes
US
xml
848 b
suspicious
828
svchost.exe
PROPFIND
207
104.156.149.33:80
http://104.156.149.33/yes/4496kxyFLzlbzcqManIipAPdolfO.exe
US
xml
957 b
suspicious
828
svchost.exe
PROPFIND
207
104.156.149.33:80
http://104.156.149.33/yes/ico/5.ico
US
xml
894 b
suspicious
828
svchost.exe
GET
200
104.156.149.33:80
http://104.156.149.33/yes/ico/5.ico
US
image
209 Kb
suspicious
828
svchost.exe
PROPFIND
207
104.156.149.33:80
http://104.156.149.33/yes/4496kxyFLzlbzcqManIipAPdolfO.exe
US
xml
957 b
suspicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1076
svchost.exe
224.0.0.252:5355
unknown
828
svchost.exe
104.156.149.33:80
US
suspicious
3328
SearchProtocolHost.exe
104.156.149.33:80
US
suspicious
4
System
192.168.100.255:138
whitelisted
3748
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:137
whitelisted

DNS requests

No data

Threats

PID
Process
Class
Message
828
svchost.exe
Potentially Bad Traffic
ET INFO Executable Download from dotted-quad Host
828
svchost.exe
Potentially Bad Traffic
ET INFO Executable Download from dotted-quad Host
828
svchost.exe
Potentially Bad Traffic
ET INFO Executable Download from dotted-quad Host
828
svchost.exe
Potentially Bad Traffic
ET INFO Executable Download from dotted-quad Host
828
svchost.exe
Potentially Bad Traffic
ET INFO Executable Download from dotted-quad Host
828
svchost.exe
Potentially Bad Traffic
ET INFO Executable Download from dotted-quad Host
828
svchost.exe
Potentially Bad Traffic
ET INFO Executable Download from dotted-quad Host
828
svchost.exe
Potentially Bad Traffic
ET INFO Executable Download from dotted-quad Host
828
svchost.exe
Potentially Bad Traffic
ET INFO Executable Download from dotted-quad Host
1 ETPRO signatures available at the full report
No debug info