File name:

lockscreen_4e275af2fa81be13f725e9bceba85a74b0469dcc.7z

Full analysis: https://app.any.run/tasks/f1aea643-b78d-4860-85db-bf486bbbec24
Verdict: Malicious activity
Analysis date: May 15, 2025, 19:00:57
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
arch-exec
Indicators:
MIME: application/x-7z-compressed
File info: 7-zip archive data, version 0.4
MD5:

137192EA73EDC10085FFA77EC3762DC3

SHA1:

B58C7F059B93DCC850E8699A144A9C125FE2041E

SHA256:

8DF06D9CB8119CFD9C073BBBEE5C0D427AC903892535639DDB5FED5EA446DCE2

SSDEEP:

1536:+ASNB7j44L6qZOjzTi+xbLKpplqcerYprrathrMgYe:+ASNB7syZYHxnKnlqcqY9r6g1e

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • lockscreen_4e275af2fa81be13f725e9bceba85a74b0469dcc.exe (PID: 1648)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • lockscreen_4e275af2fa81be13f725e9bceba85a74b0469dcc.exe (PID: 1648)
    • Reads the Internet Settings

      • lockscreen_4e275af2fa81be13f725e9bceba85a74b0469dcc.exe (PID: 1648)
      • firefox.exe (PID: 2412)
    • Reads security settings of Internet Explorer

      • lockscreen_4e275af2fa81be13f725e9bceba85a74b0469dcc.exe (PID: 1648)
      • firefox.exe (PID: 2412)
    • Starts itself from another location

      • lockscreen_4e275af2fa81be13f725e9bceba85a74b0469dcc.exe (PID: 1648)
    • Starts CMD.EXE for commands execution

      • lockscreen_4e275af2fa81be13f725e9bceba85a74b0469dcc.exe (PID: 1648)
    • Executing commands from a ".bat" file

      • lockscreen_4e275af2fa81be13f725e9bceba85a74b0469dcc.exe (PID: 1648)
    • There is functionality for taking screenshot (YARA)

      • firefox.exe (PID: 2412)
  • INFO

    • The sample compiled with english language support

      • lockscreen_4e275af2fa81be13f725e9bceba85a74b0469dcc.exe (PID: 1648)
      • WinRAR.exe (PID: 2452)
    • Creates files or folders in the user directory

      • lockscreen_4e275af2fa81be13f725e9bceba85a74b0469dcc.exe (PID: 1648)
    • Checks supported languages

      • lockscreen_4e275af2fa81be13f725e9bceba85a74b0469dcc.exe (PID: 1648)
      • firefox.exe (PID: 2412)
    • Manual execution by a user

      • lockscreen_4e275af2fa81be13f725e9bceba85a74b0469dcc.exe (PID: 1648)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2452)
    • Reads the computer name

      • lockscreen_4e275af2fa81be13f725e9bceba85a74b0469dcc.exe (PID: 1648)
      • firefox.exe (PID: 2412)
    • Reads the machine GUID from the registry

      • firefox.exe (PID: 2412)
    • Checks proxy server information

      • firefox.exe (PID: 2412)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.7z | 7-Zip compressed archive (v0.4) (57.1)
.7z | 7-Zip compressed archive (gen) (42.8)

EXIF

ZIP

FileVersion: 7z v0.04
ModifyDate: 2011:02:25 05:19:30+00:00
ArchivedFileName: lockscreen_4e275af2fa81be13f725e9bceba85a74b0469dcc.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
43
Monitored processes
4
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe lockscreen_4e275af2fa81be13f725e9bceba85a74b0469dcc.exe cmd.exe no specs firefox.exe

Process information

PID
CMD
Path
Indicators
Parent process
1648"C:\Users\admin\Desktop\lockscreen_4e275af2fa81be13f725e9bceba85a74b0469dcc.exe" C:\Users\admin\Desktop\lockscreen_4e275af2fa81be13f725e9bceba85a74b0469dcc.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\desktop\lockscreen_4e275af2fa81be13f725e9bceba85a74b0469dcc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\gdi32.dll
2100C:\Windows\system32\cmd.exe /c ""C:\Users\admin\Desktop\del.bat" "C:\Windows\System32\cmd.exelockscreen_4e275af2fa81be13f725e9bceba85a74b0469dcc.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
1
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2412"C:\Users\admin\AppData\Roaming\Mozilla\Firefox\firefox.exe" C:\Users\admin\AppData\Roaming\Mozilla\Firefox\firefox.exe
lockscreen_4e275af2fa81be13f725e9bceba85a74b0469dcc.exe
User:
admin
Integrity Level:
HIGH
Modules
Images
c:\users\admin\appdata\roaming\mozilla\firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\gdi32.dll
2452"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\Desktop\lockscreen_4e275af2fa81be13f725e9bceba85a74b0469dcc.7zC:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
Total events
2 558
Read events
2 487
Write events
62
Delete events
9

Modification events

(PID) Process:(2452) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2452) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2452) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2452) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(2452) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(2452) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(2452) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\lockscreen_4e275af2fa81be13f725e9bceba85a74b0469dcc.7z
(PID) Process:(2452) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2452) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2452) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
Executable files
2
Suspicious files
0
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
2452WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb2452.47620\lockscreen_4e275af2fa81be13f725e9bceba85a74b0469dcc.exeexecutable
MD5:48E38C1D8BD97F13BC0ACFAE45880ED3
SHA256:A7D05B80A76A7474EF5ED45A103EE27BFEC3E221C0E405AB054B1135E5AFB116
1648lockscreen_4e275af2fa81be13f725e9bceba85a74b0469dcc.exeC:\Users\admin\Desktop\del.battext
MD5:18B7D78A6F29647BE3B814EF01A54DC5
SHA256:8765C7560F6A63684333F1C5B478565920F84271A4A5F115E95227A72518CD0E
1648lockscreen_4e275af2fa81be13f725e9bceba85a74b0469dcc.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\firefox.exeexecutable
MD5:48E38C1D8BD97F13BC0ACFAE45880ED3
SHA256:A7D05B80A76A7474EF5ED45A103EE27BFEC3E221C0E405AB054B1135E5AFB116
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
13
DNS requests
8
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2412
firefox.exe
POST
404
49.13.77.253:80
http://tucketwadstone.info/index.php
unknown
unknown
2412
firefox.exe
POST
404
49.13.77.253:80
http://forweendbaruria.com/index.php
unknown
unknown
2412
firefox.exe
POST
404
49.13.77.253:80
http://gachotyuemin.info/index.php
unknown
unknown
2412
firefox.exe
POST
404
49.13.77.253:80
http://fileableflorient.info/index.php
unknown
unknown
2412
firefox.exe
POST
404
49.13.77.253:80
http://paschencrisden.info/index.php
unknown
unknown
2412
firefox.exe
POST
404
49.13.77.253:80
http://hallifaxleppanen.info/index.php
unknown
unknown
2412
firefox.exe
POST
404
49.13.77.253:80
http://estockincline.info/index.php
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
224.0.0.252:5355
whitelisted
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
whitelisted
4
System
192.168.100.255:138
whitelisted
2412
firefox.exe
49.13.77.253:80
forweendbaruria.com
Hetzner Online GmbH
DE
unknown

DNS requests

Domain
IP
Reputation
google.com
  • 216.58.206.46
whitelisted
forweendbaruria.com
  • 49.13.77.253
unknown
tucketwadstone.info
  • 49.13.77.253
unknown
estockincline.info
  • 49.13.77.253
unknown
fileableflorient.info
  • 49.13.77.253
unknown
gachotyuemin.info
  • 49.13.77.253
unknown
paschencrisden.info
  • 49.13.77.253
unknown
hallifaxleppanen.info
  • 49.13.77.253
unknown

Threats

No threats detected
No debug info