File name:

Inv_202516 Inv_09876567 Inv_045636.rar

Full analysis: https://app.any.run/tasks/1165a5f6-afca-4a61-bbcc-ee837482b6da
Verdict: Malicious activity
Analysis date: May 16, 2025, 19:08:28
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

2BEF161173678AF0F3F48A4E17C2DA55

SHA1:

400E212EC459D30CA38C5C26A9DA5D617A30D11C

SHA256:

8CD9646AE6F4A1467CDA4C5D281F9CAFC0E5287933269CD82DAB4F329844E0A1

SSDEEP:

98304:YsqU1dETuOvukIcG9f7llgUYrx48BxSG0Y6VJ/i290bzM1XZWVELEB+uU+VUVV4b:VJU0J0Se

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • Inv_202516 Inv_09876567 Inv_045636.exe (PID: 856)
      • Inv_202516 Inv_09876567 Inv_045636.exe (PID: 5892)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • WinRAR.exe (PID: 1276)
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 1276)
    • The sample compiled with english language support

      • WinRAR.exe (PID: 1276)
    • Reads the computer name

      • Inv_202516 Inv_09876567 Inv_045636.exe (PID: 5892)
      • Inv_202516 Inv_09876567 Inv_045636.exe (PID: 856)
    • Process checks computer location settings

      • Inv_202516 Inv_09876567 Inv_045636.exe (PID: 856)
      • Inv_202516 Inv_09876567 Inv_045636.exe (PID: 5892)
    • Checks supported languages

      • Inv_202516 Inv_09876567 Inv_045636.exe (PID: 5892)
      • Inv_202516 Inv_09876567 Inv_045636.exe (PID: 856)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)

EXIF

ZIP

FileVersion: RAR v5
CompressedSize: 93643
UncompressedSize: 224128
OperatingSystem: Win32
ArchivedFileName: libintl-8.dll
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
135
Monitored processes
7
Malicious processes
0
Suspicious processes
3

Behavior graph

Click at the process to see the details
start winrar.exe sppextcomobj.exe no specs slui.exe inv_202516 inv_09876567 inv_045636.exe no specs conhost.exe no specs inv_202516 inv_09876567 inv_045636.exe no specs conhost.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
856"C:\Users\admin\Downloads\Inv_202516 Inv_09876567 Inv_045636\Inv_202516 Inv_09876567 Inv_045636.exe" C:\Users\admin\Downloads\Inv_202516 Inv_09876567 Inv_045636\Inv_202516 Inv_09876567 Inv_045636.exeWinRAR.exe
User:
admin
Company:
The Git Development Community
Integrity Level:
MEDIUM
Description:
Git for Windows
Exit code:
0
Version:
2.49.0.windows.1
Modules
Images
c:\users\admin\downloads\inv_202516 inv_09876567 inv_045636\inv_202516 inv_09876567 inv_045636.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
1184\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeInv_202516 Inv_09876567 Inv_045636.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1276"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Downloads\Inv_202516 Inv_09876567 Inv_045636.rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
3300"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exe
SppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
4944C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
5228\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeInv_202516 Inv_09876567 Inv_045636.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
5892"C:\Users\admin\Downloads\Inv_202516 Inv_09876567 Inv_045636\Inv_202516 Inv_09876567 Inv_045636.exe" C:\Users\admin\Downloads\Inv_202516 Inv_09876567 Inv_045636\Inv_202516 Inv_09876567 Inv_045636.exeWinRAR.exe
User:
admin
Company:
The Git Development Community
Integrity Level:
MEDIUM
Description:
Git for Windows
Exit code:
0
Version:
2.49.0.windows.1
Modules
Images
c:\users\admin\downloads\inv_202516 inv_09876567 inv_045636\inv_202516 inv_09876567 inv_045636.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
Total events
3 559
Read events
3 529
Write events
17
Delete events
13

Modification events

(PID) Process:(1276) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\ArcColumnWidths
Operation:writeName:name
Value:
256
(PID) Process:(1276) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\ArcColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(1276) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\ArcColumnWidths
Operation:writeName:psize
Value:
80
(PID) Process:(1276) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\ArcColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(1276) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\ArcColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(1276) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\ArcColumnWidths
Operation:writeName:crc
Value:
70
(PID) Process:(1276) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(1276) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(1276) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(1276) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Downloads\Inv_202516 Inv_09876567 Inv_045636.rar
Executable files
6
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
1276WinRAR.exeC:\Users\admin\Downloads\Inv_202516 Inv_09876567 Inv_045636\libwinpthread-1.dllexecutable
MD5:8E137B8704B186EA123C8CF3C662F76A
SHA256:AECDCF15FE402E0B87F7F397717D04411808AA75DB0C7EA9129D56BF19E7F32D
1276WinRAR.exeC:\Users\admin\Downloads\Inv_202516 Inv_09876567 Inv_045636\Inv_202516 Inv_09876567 Inv_045636.exeexecutable
MD5:FABF1E78F1785A80E6CEE81CF089E4F8
SHA256:FE0E064C8283DC50B1CE11A8B90D2EC1B68B5DC714FF0B8A8534BB9C43D1D02E
1276WinRAR.exeC:\Users\admin\Downloads\Inv_202516 Inv_09876567 Inv_045636\libiconv-2.dllexecutable
MD5:0FFACA141EF444C38C6766D1E1AD495D
SHA256:169E96B6003A793E49852365DEFB858ED2EBE62B53B7FB67D60B10DA45D06424
1276WinRAR.exeC:\Users\admin\Downloads\Inv_202516 Inv_09876567 Inv_045636\libintl-8.dllexecutable
MD5:4A267F69C8684E7FCB88A98D58B1B91F
SHA256:81EA66BA836248817C3570C78426F52DC6D7486B1B9B851B54EA903E6385AC7B
1276WinRAR.exeC:\Users\admin\Downloads\Inv_202516 Inv_09876567 Inv_045636\libpcre2-8-0.dllexecutable
MD5:ABC800948AF2335550ACCA53AD9383DE
SHA256:3DCE419096651E461EED830EA2789695ADF59727488E94D6C2F9BC9BA989A1CE
1276WinRAR.exeC:\Users\admin\Downloads\Inv_202516 Inv_09876567 Inv_045636\zlib1.dllexecutable
MD5:EBBCDE44E4BDF7078FC56F7421831EA7
SHA256:B4C9F9A79EA2526B9970D2116A6B0ADDB5E68A2BC1BEEC67481F39AB146A840E
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
20
DNS requests
16
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5384
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
5384
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
GET
200
23.48.23.164:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6544
svchost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
2104
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5496
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
23.48.23.164:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
3216
svchost.exe
172.211.123.248:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
5496
MoUsoCoreWorker.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6544
svchost.exe
40.126.31.67:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 20.73.194.208
  • 51.124.78.146
whitelisted
google.com
  • 142.250.181.238
whitelisted
crl.microsoft.com
  • 23.48.23.164
  • 23.48.23.171
  • 23.48.23.163
  • 23.48.23.179
  • 23.48.23.168
  • 23.48.23.166
  • 23.48.23.181
  • 23.48.23.180
  • 23.48.23.176
whitelisted
www.microsoft.com
  • 184.30.21.171
  • 95.101.149.131
whitelisted
client.wns.windows.com
  • 172.211.123.248
whitelisted
login.live.com
  • 40.126.31.67
  • 40.126.31.73
  • 40.126.31.128
  • 20.190.159.73
  • 40.126.31.130
  • 20.190.159.2
  • 20.190.159.68
  • 40.126.31.3
whitelisted
ocsp.digicert.com
  • 2.23.77.188
whitelisted
slscr.update.microsoft.com
  • 172.202.163.200
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 52.165.164.15
whitelisted

Threats

No threats detected
No debug info