File name:

Windows 7 Loader eXtreme Edition 3.503.rar

Full analysis: https://app.any.run/tasks/243422d7-d6af-49bc-a1cc-8f8d8127fbbc
Verdict: Malicious activity
Analysis date: June 30, 2019, 11:16:01
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v4, os: Win32
MD5:

1DB7B1E08E6330F3315423D1BA1053E3

SHA1:

B4D38CDE891D7102E9524348EC90D9EA8DEFBD6F

SHA256:

9A409819D774CEDD115653F30B0E03AD1A0C6B21B735B87444DAEC60467B2267

SSDEEP:

196608:8CoWay7gLVsP/TR/EbjtggkygIuc021vPcaupQGJ+5ENTo:J7SkTR/kttkyZX1vPcaalQ+to

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • w7lxe.exe (PID: 3320)
      • w7lxe.exe (PID: 2748)
    • Changes settings of System certificates

      • w7lxe.exe (PID: 3320)
  • SUSPICIOUS

    • Reads Windows Product ID

      • w7lxe.exe (PID: 3320)
    • Low-level read access rights to disk partition

      • w7lxe.exe (PID: 3320)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3792)
    • Adds / modifies Windows certificates

      • w7lxe.exe (PID: 3320)
    • Reads Environment values

      • w7lxe.exe (PID: 3320)
  • INFO

    • Manual execution by user

      • w7lxe.exe (PID: 3320)
      • w7lxe.exe (PID: 2748)
    • Reads settings of System Certificates

      • w7lxe.exe (PID: 3320)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v-4.x) (58.3)
.rar | RAR compressed archive (gen) (41.6)

EXIF

ZIP

CompressedSize: 4327
UncompressedSize: 22004
OperatingSystem: Win32
ModifyDate: 2010:05:21 02:00:23
PackingMethod: Normal
ArchivedFileName: Windows 7 Loader eXtreme Edition 3.503\FAQ\FAQ(Afrikaans).txt
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
42
Monitored processes
3
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe w7lxe.exe no specs w7lxe.exe

Process information

PID
CMD
Path
Indicators
Parent process
2748"C:\Users\admin\Desktop\Windows 7 Loader eXtreme Edition 3.503\w7lxe.exe" C:\Users\admin\Desktop\Windows 7 Loader eXtreme Edition 3.503\w7lxe.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Universal Windows Activation Tool
Exit code:
3221226540
Version:
3.5.0.3
Modules
Images
c:\users\admin\desktop\windows 7 loader extreme edition 3.503\w7lxe.exe
c:\systemroot\system32\ntdll.dll
3320"C:\Users\admin\Desktop\Windows 7 Loader eXtreme Edition 3.503\w7lxe.exe" C:\Users\admin\Desktop\Windows 7 Loader eXtreme Edition 3.503\w7lxe.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Description:
Universal Windows Activation Tool
Exit code:
0
Version:
3.5.0.3
Modules
Images
c:\users\admin\desktop\windows 7 loader extreme edition 3.503\w7lxe.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
3792"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Windows 7 Loader eXtreme Edition 3.503.rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
Total events
478
Read events
443
Write events
35
Delete events
0

Modification events

(PID) Process:(3792) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3792) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3792) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\62\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3792) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Windows 7 Loader eXtreme Edition 3.503.rar
(PID) Process:(3792) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3792) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3792) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3792) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3792) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000
(PID) Process:(3792) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\General
Operation:writeName:LastFolder
Value:
C:\Users\admin\AppData\Local\Temp
Executable files
1
Suspicious files
95
Text files
21
Unknown types
0

Dropped files

PID
Process
Filename
Type
3792WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3792.40288\Windows 7 Loader eXtreme Edition 3.503\FAQ\FAQ(Afrikaans).txtbinary
MD5:46BE00B8239196105C09F0219F5CDCAF
SHA256:34384F1BE3267A46B6247405F80EE6CBECDC0D90C7FDBB723A8FB1ABBA12D223
3792WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3792.40288\Windows 7 Loader eXtreme Edition 3.503\FAQ\FAQ(Albanian).txtbinary
MD5:8290251B08DD45FE6869D638549C86B4
SHA256:5A7106D77660FAA536FB0C4E7173C59FC53BF916992973044875431002859B58
3792WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3792.40288\Windows 7 Loader eXtreme Edition 3.503\FAQ\FAQ(English).txttext
MD5:0325ECC140438B5B9DC216556F903B8B
SHA256:596EE8B48101C3D20A932B3982C4AFB887117CCA3D253A8069DF28648A75C980
3792WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3792.40288\Windows 7 Loader eXtreme Edition 3.503\FAQ\FAQ(French).txtbinary
MD5:F6DEECDAA3A825253DE705D5E90966FE
SHA256:BD0DDEE82AEA941B339FFCB2FE020F1110B1C20578678E14CCEECBD0CDC57BF4
3792WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3792.40288\Windows 7 Loader eXtreme Edition 3.503\FAQ\FAQ(Croatian).txtbinary
MD5:354E9281DA201B493150890682934C74
SHA256:1C629ED0B868D686EF45AC126A3FE9764A33117150BA7917485ADE1CE5475C1B
3792WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3792.40288\Windows 7 Loader eXtreme Edition 3.503\FAQ\FAQ(Danish).txtbinary
MD5:85CC14E10065C26091F045D6689298F7
SHA256:11769DA102AD8E35FFCBB67857C90DE75467B924D38616A25E1A9A43D67B911D
3792WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3792.40288\Windows 7 Loader eXtreme Edition 3.503\FAQ\FAQ(German).txtbinary
MD5:410E6D4382DA4614BAA25D5ADAB709E4
SHA256:A13C1DBE885ACDDFD4C3E9A1C5362FC731F6FFAEEE037162A80847E44DDBB8F0
3792WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3792.40288\Windows 7 Loader eXtreme Edition 3.503\FAQ\FAQ(Czech).txtbinary
MD5:22D4742A6298FC3EA2D7C60FE7443826
SHA256:3120C74CC07C1F13BC6E172E39D56471A1B4D62809D020487845ECA423883134
3792WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3792.40288\Windows 7 Loader eXtreme Edition 3.503\FAQ\FAQ(Estonian).txtbinary
MD5:FF33FC66A5EC5C5062E51C90B5517632
SHA256:BDE342CC3DE7B5FEE4C611EF030ED33614ADBF6B50749ADD54926DFB8DBAA0DB
3792WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3792.40288\Windows 7 Loader eXtreme Edition 3.503\FAQ\FAQ(Finnish).txtbinary
MD5:AB46BC7BA8FC98FF3FA9FF4C96BB0A34
SHA256:2F373BAFC1B70F9F069DC5D545FDC92C3E2FDE3E533E74BB43B757570E09CEE6
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info