| download: | Express.rar |
| Full analysis: | https://app.any.run/tasks/c6e8bcf2-b6de-4b8e-90e7-7534d7204949 |
| Verdict: | Malicious activity |
| Analysis date: | January 18, 2019, 00:50:11 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-rar |
| File info: | RAR archive data, v5 |
| MD5: | 515EE0E75125301AE7B5B41604A82B53 |
| SHA1: | 78862E128CD1C971F01DBD4F99F12838EB85BC3D |
| SHA256: | 959620DBF2D6D2E0EA9ED069046B3C50591A9E948C7FF198042719BA43DDA6B6 |
| SSDEEP: | 24576:ZDOrmvDlXdPb+bgboz5Cc1xDKfpVDug4oOft3vHVN2H64v3DrXj5iTZ1BFGtfBg:ZiEzKbgbg5Cc1OVDDcFdN2a03Dv50rB3 |
| .rar | | | RAR compressed archive (v5.0) (61.5) |
|---|---|---|
| .rar | | | RAR compressed archive (gen) (38.4) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 556 | "C:\Users\admin\Desktop\Express\Express.exe" | C:\Users\admin\Desktop\Express\Express.exe | — | explorer.exe | |||||||||||
User: admin Company: SparePowered (Spare Squad) Integrity Level: MEDIUM Description: Illuminate Exit code: 3221226540 Version: 1.5.0.0 Modules
| |||||||||||||||
| 2880 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Express.rar" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.60.0 Modules
| |||||||||||||||
| 3176 | "C:\Users\admin\Desktop\Express\Express.exe" | C:\Users\admin\Desktop\Express\Express.exe | explorer.exe | ||||||||||||
User: admin Company: SparePowered (Spare Squad) Integrity Level: HIGH Description: Illuminate Exit code: 0 Version: 1.5.0.0 Modules
| |||||||||||||||
| (PID) Process: | (2880) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (2880) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (2880) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2880) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\Express.rar | |||
| (PID) Process: | (2880) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (2880) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (2880) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (2880) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (2880) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin |
| Operation: | write | Name: | Placement |
Value: 2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000 | |||
| (PID) Process: | (2880) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\General |
| Operation: | write | Name: | LastFolder |
Value: C:\Users\admin\AppData\Local\Temp | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2880 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2880.15041\Express\Express.dll | executable | |
MD5:— | SHA256:— | |||
| 2880 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2880.15041\Express\Monaco\vs\base\worker\workerMain.js | text | |
MD5:27EAD90C7702154755785E0E53398755 | SHA256:BDF9433692A08851E13DD58504EEF19F51BD2EC7241923A68EDF5772E0E53AF5 | |||
| 2880 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2880.15041\Express\Express.exe | executable | |
MD5:— | SHA256:— | |||
| 2880 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2880.15041\Express\Monaco\Monaco.html | html | |
MD5:— | SHA256:— | |||
| 2880 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2880.15041\Express\Monaco\vs\basic-languages\csharp\csharp.js | text | |
MD5:F8F841D13C9220E15DCD6BC386B37BA2 | SHA256:6B3BE9A86EE8E3202F51745D94D24CC1EEFBCF7D9E6D94FBAF70146B084E835F | |||
| 2880 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2880.15041\Express\Monaco\vs\basic-languages\ini\ini.js | text | |
MD5:B9252B74381FE17565D494711F4C9093 | SHA256:1F0FEEAE58C32F6E1F31B78F7E2AAB3C91DA387E464234C0F55EBFF0E77444A2 | |||
| 2880 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2880.15041\Express\Monaco\vs\basic-languages\go\go.js | text | |
MD5:5B4484C914CD97AFF4510B803F2517EF | SHA256:46D1757C3CD3DBC3C7B465A338880144922A1C34C30E36F06FF2DB8C2FF75B86 | |||
| 2880 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2880.15041\Express\Monaco\vs\basic-languages\fsharp\fsharp.js | text | |
MD5:DE122B3BC44A8714F386DC80282DCB12 | SHA256:1390079BABC117D3F376735780D98F409F317EB4628D17106642C6933EA1DA7F | |||
| 2880 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2880.15041\Express\Monaco\vs\basic-languages\csp\csp.js | text | |
MD5:22ADA25D590811DCFF4E5F5D698E583B | SHA256:4B5A5D7D50986B86B00833447E097C0F01A4388CE1765B48E7E371D06E3A4789 | |||
| 2880 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2880.15041\Express\Monaco\vs\basic-languages\dockerfile\dockerfile.js | text | |
MD5:E32DE981BDAF75E6FFB8FE40BC955A68 | SHA256:65B86FC54E9B35D6CB84F01DFB905680DBCAD6605757DE1D6BCA84E3029889AF | |||