File name:

Player.zip.7z

Full analysis: https://app.any.run/tasks/5555e6b2-4e1c-49ad-a9d5-914f7538173f
Verdict: Malicious activity
Analysis date: November 13, 2020, 10:46:51
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-7z-compressed
File info: 7-zip archive data, version 0.3
MD5:

994739D2F197C1E1523D0DF8A7697B9E

SHA1:

95077556D2D87E207158BB17F6A0E3543E08918D

SHA256:

9165346ADE51E84201A735558661917A0CDE27CD2A0A28AE78BBE653AC31E78E

SSDEEP:

24576:NUKJer2+y5kD0T4oK60I1RfdZTVReAI/CqaZLky7XMKsmeKacXgUICefQrxDih/U:ter2VkD0T4oKwxNkAIc7XFOcXj1rViLe

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • cabarc.exe (PID: 3000)
      • play.exe (PID: 3816)
      • p.exe (PID: 1972)
    • Loads dropped or rewritten executable

      • p.exe (PID: 1972)
      • SearchProtocolHost.exe (PID: 3184)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 996)
      • play.exe (PID: 3816)
      • cabarc.exe (PID: 3000)
  • INFO

    • Manual execution by user

      • WinRAR.exe (PID: 996)
      • play.exe (PID: 3816)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.7z | 7-Zip compressed archive (gen) (100)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
44
Monitored processes
6
Malicious processes
1
Suspicious processes
2

Behavior graph

Click at the process to see the details
start drop and start winrar.exe no specs winrar.exe searchprotocolhost.exe no specs play.exe cabarc.exe p.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
996"C:\Program Files\WinRAR\WinRAR.exe" x -iext -ow -ver -- "C:\Users\admin\Desktop\Player.zip\Player.zip" C:\Users\admin\Desktop\Player.zip\C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
1972"C:\Player_Cut\p.exe" C:\Users\admin\Desktop\Player.zip\player\C:\Player_Cut\p.exeplay.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Version:
2, 1, 3, 0
Modules
Images
c:\player_cut\p.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\player_cut\dhplay.dll
c:\windows\system32\avifil32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
2564"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\Player.zip.7z"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3000"C:\Users\admin\Desktop\Player.zip\player\cabarc.exe" -o X webrec.cab *.dll C:\\Player_Cut\C:\Users\admin\Desktop\Player.zip\player\cabarc.exe
play.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\player.zip\player\cabarc.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
3184"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe4_ Global\UsGthrCtrlFltPipeMssGthrPipe4 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" C:\Windows\System32\SearchProtocolHost.exeSearchIndexer.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Windows Search Protocol Host
Exit code:
0
Version:
7.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\searchprotocolhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3816"C:\Users\admin\Desktop\Player.zip\player\play.exe" C:\Users\admin\Desktop\Player.zip\player\play.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\player.zip\player\play.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
Total events
1 338
Read events
1 261
Write events
76
Delete events
1

Modification events

(PID) Process:(2564) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2564) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2564) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\13B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2564) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\Player.zip.7z
(PID) Process:(2564) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2564) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2564) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2564) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2564) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\DialogEditHistory\ExtrPath
Operation:writeName:0
Value:
C:\Users\admin\Desktop\Player.zip
(PID) Process:(2564) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface
Operation:writeName:ShowPassword
Value:
0
Executable files
13
Suspicious files
2
Text files
15
Unknown types
1

Dropped files

PID
Process
Filename
Type
3000cabarc.exeC:\Player_Cut\dhnetsdk.dllexecutable
MD5:
SHA256:
3000cabarc.exeC:\Player_Cut\dhdvr.dllexecutable
MD5:
SHA256:
3000cabarc.exeC:\Player_Cut\dhplay.dllexecutable
MD5:
SHA256:
3000cabarc.exeC:\Player_Cut\dllh264.dllexecutable
MD5:
SHA256:
996WinRAR.exeC:\Users\admin\Desktop\Player.zip\player\webrec.cabcompressed
MD5:
SHA256:
996WinRAR.exeC:\Users\admin\Desktop\Player.zip\player\skin.initext
MD5:0289B256E30B97B9B619CA348F696602
SHA256:02D12A234D26295AA744E5A188A2011A43A4B662FDA9300CA3E34D500DB7877F
996WinRAR.exeC:\Users\admin\Desktop\Player.zip\player\player.initext
MD5:0BDF1DEA857AE51770FAB8F261D2EAFD
SHA256:AF076901DE32FA110B423AED453FD651CE463247B983BE43CCC7CF255D16D2AD
996WinRAR.exeC:\Users\admin\Desktop\Player.zip\player\p.exeexecutable
MD5:3DBBAED77217E462DC97D2C64D5A8E62
SHA256:B4417DEE18440CB1602B47E379CAC244668746EF421C034E07237BBF99F4B997
996WinRAR.exeC:\Users\admin\Desktop\Player.zip\player\resDll.dllexecutable
MD5:D47A2DD0E9D2A223019647986F5CE313
SHA256:218E6551D445E7479089B8E0B1886B77DE8459C109F981C9D59CBE79DB9673FB
3000cabarc.exeC:\Player_Cut\DllDeinterlace.dllexecutable
MD5:CA1E43C58F45B08DD979189111D66643
SHA256:E3E85612BF20ADD5240F7308C077FAA4ADE6FD3E313D32836F0FE313D1EB8C3A
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info