download:

Express.rar

Full analysis: https://app.any.run/tasks/c6e8bcf2-b6de-4b8e-90e7-7534d7204949
Verdict: Malicious activity
Analysis date: January 18, 2019, 00:50:11
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

515EE0E75125301AE7B5B41604A82B53

SHA1:

78862E128CD1C971F01DBD4F99F12838EB85BC3D

SHA256:

959620DBF2D6D2E0EA9ED069046B3C50591A9E948C7FF198042719BA43DDA6B6

SSDEEP:

24576:ZDOrmvDlXdPb+bgboz5Cc1xDKfpVDug4oOft3vHVN2H64v3DrXj5iTZ1BFGtfBg:ZiEzKbgbg5Cc1OVDDcFdN2a03Dv50rB3

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Express.exe (PID: 556)
      • Express.exe (PID: 3176)
  • SUSPICIOUS

    • Changes IE settings (feature browser emulation)

      • Express.exe (PID: 3176)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2880)
    • Reads internet explorer settings

      • Express.exe (PID: 3176)
    • Reads Internet Cache Settings

      • Express.exe (PID: 3176)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
35
Monitored processes
3
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe express.exe no specs express.exe

Process information

PID
CMD
Path
Indicators
Parent process
556"C:\Users\admin\Desktop\Express\Express.exe" C:\Users\admin\Desktop\Express\Express.exeexplorer.exe
User:
admin
Company:
SparePowered (Spare Squad)
Integrity Level:
MEDIUM
Description:
Illuminate
Exit code:
3221226540
Version:
1.5.0.0
Modules
Images
c:\users\admin\desktop\express\express.exe
c:\systemroot\system32\ntdll.dll
2880"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Express.rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3176"C:\Users\admin\Desktop\Express\Express.exe" C:\Users\admin\Desktop\Express\Express.exe
explorer.exe
User:
admin
Company:
SparePowered (Spare Squad)
Integrity Level:
HIGH
Description:
Illuminate
Exit code:
0
Version:
1.5.0.0
Modules
Images
c:\users\admin\desktop\express\express.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
Total events
1 102
Read events
1 042
Write events
57
Delete events
3

Modification events

(PID) Process:(2880) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2880) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2880) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2880) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Express.rar
(PID) Process:(2880) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2880) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2880) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2880) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2880) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000
(PID) Process:(2880) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\General
Operation:writeName:LastFolder
Value:
C:\Users\admin\AppData\Local\Temp
Executable files
2
Suspicious files
0
Text files
75
Unknown types
1

Dropped files

PID
Process
Filename
Type
2880WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2880.15041\Express\Express.dllexecutable
MD5:
SHA256:
2880WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2880.15041\Express\Monaco\vs\base\worker\workerMain.jstext
MD5:27EAD90C7702154755785E0E53398755
SHA256:BDF9433692A08851E13DD58504EEF19F51BD2EC7241923A68EDF5772E0E53AF5
2880WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2880.15041\Express\Express.exeexecutable
MD5:
SHA256:
2880WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2880.15041\Express\Monaco\Monaco.htmlhtml
MD5:
SHA256:
2880WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2880.15041\Express\Monaco\vs\basic-languages\csharp\csharp.jstext
MD5:F8F841D13C9220E15DCD6BC386B37BA2
SHA256:6B3BE9A86EE8E3202F51745D94D24CC1EEFBCF7D9E6D94FBAF70146B084E835F
2880WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2880.15041\Express\Monaco\vs\basic-languages\ini\ini.jstext
MD5:B9252B74381FE17565D494711F4C9093
SHA256:1F0FEEAE58C32F6E1F31B78F7E2AAB3C91DA387E464234C0F55EBFF0E77444A2
2880WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2880.15041\Express\Monaco\vs\basic-languages\go\go.jstext
MD5:5B4484C914CD97AFF4510B803F2517EF
SHA256:46D1757C3CD3DBC3C7B465A338880144922A1C34C30E36F06FF2DB8C2FF75B86
2880WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2880.15041\Express\Monaco\vs\basic-languages\fsharp\fsharp.jstext
MD5:DE122B3BC44A8714F386DC80282DCB12
SHA256:1390079BABC117D3F376735780D98F409F317EB4628D17106642C6933EA1DA7F
2880WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2880.15041\Express\Monaco\vs\basic-languages\csp\csp.jstext
MD5:22ADA25D590811DCFF4E5F5D698E583B
SHA256:4B5A5D7D50986B86B00833447E097C0F01A4388CE1765B48E7E371D06E3A4789
2880WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2880.15041\Express\Monaco\vs\basic-languages\dockerfile\dockerfile.jstext
MD5:E32DE981BDAF75E6FFB8FE40BC955A68
SHA256:65B86FC54E9B35D6CB84F01DFB905680DBCAD6605757DE1D6BCA84E3029889AF
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info