File name:

Windows 7 Loader eXtreme Edition 3.503.rar

Full analysis: https://app.any.run/tasks/243422d7-d6af-49bc-a1cc-8f8d8127fbbc
Verdict: Malicious activity
Analysis date: June 30, 2019, 11:16:01
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v4, os: Win32
MD5:

1DB7B1E08E6330F3315423D1BA1053E3

SHA1:

B4D38CDE891D7102E9524348EC90D9EA8DEFBD6F

SHA256:

9A409819D774CEDD115653F30B0E03AD1A0C6B21B735B87444DAEC60467B2267

SSDEEP:

196608:8CoWay7gLVsP/TR/EbjtggkygIuc021vPcaupQGJ+5ENTo:J7SkTR/kttkyZX1vPcaalQ+to

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • w7lxe.exe (PID: 2748)
      • w7lxe.exe (PID: 3320)
    • Changes settings of System certificates

      • w7lxe.exe (PID: 3320)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3792)
    • Reads Windows Product ID

      • w7lxe.exe (PID: 3320)
    • Reads Environment values

      • w7lxe.exe (PID: 3320)
    • Low-level read access rights to disk partition

      • w7lxe.exe (PID: 3320)
    • Adds / modifies Windows certificates

      • w7lxe.exe (PID: 3320)
  • INFO

    • Manual execution by user

      • w7lxe.exe (PID: 2748)
      • w7lxe.exe (PID: 3320)
    • Reads settings of System Certificates

      • w7lxe.exe (PID: 3320)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v-4.x) (58.3)
.rar | RAR compressed archive (gen) (41.6)

EXIF

ZIP

CompressedSize: 4327
UncompressedSize: 22004
OperatingSystem: Win32
ModifyDate: 2010:05:21 02:00:23
PackingMethod: Normal
ArchivedFileName: Windows 7 Loader eXtreme Edition 3.503\FAQ\FAQ(Afrikaans).txt
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
42
Monitored processes
3
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe w7lxe.exe no specs w7lxe.exe

Process information

PID
CMD
Path
Indicators
Parent process
2748"C:\Users\admin\Desktop\Windows 7 Loader eXtreme Edition 3.503\w7lxe.exe" C:\Users\admin\Desktop\Windows 7 Loader eXtreme Edition 3.503\w7lxe.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Universal Windows Activation Tool
Exit code:
3221226540
Version:
3.5.0.3
Modules
Images
c:\users\admin\desktop\windows 7 loader extreme edition 3.503\w7lxe.exe
c:\systemroot\system32\ntdll.dll
3320"C:\Users\admin\Desktop\Windows 7 Loader eXtreme Edition 3.503\w7lxe.exe" C:\Users\admin\Desktop\Windows 7 Loader eXtreme Edition 3.503\w7lxe.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Description:
Universal Windows Activation Tool
Exit code:
0
Version:
3.5.0.3
Modules
Images
c:\users\admin\desktop\windows 7 loader extreme edition 3.503\w7lxe.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
3792"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Windows 7 Loader eXtreme Edition 3.503.rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
Total events
478
Read events
443
Write events
35
Delete events
0

Modification events

(PID) Process:(3792) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3792) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3792) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\62\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3792) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Windows 7 Loader eXtreme Edition 3.503.rar
(PID) Process:(3792) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3792) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3792) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3792) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3792) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000
(PID) Process:(3792) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\General
Operation:writeName:LastFolder
Value:
C:\Users\admin\AppData\Local\Temp
Executable files
1
Suspicious files
95
Text files
21
Unknown types
0

Dropped files

PID
Process
Filename
Type
3792WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3792.40288\Windows 7 Loader eXtreme Edition 3.503\FAQ\FAQ(Filipino).txtbinary
MD5:30616F1EB6E0EC4498A8843A1A07BD5A
SHA256:E6184371A84FFAF6817158A9D81721503952AC0F9C3AC185E86810269D171936
3792WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3792.40288\Windows 7 Loader eXtreme Edition 3.503\FAQ\FAQ(Arabic).txtbinary
MD5:6FB0CAFB2697EA0C12C4087B302587FC
SHA256:0296A6631F9822B163B0EF1B0180FF970D34D15D9A1E5B8039DCB58D9CB45640
3792WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3792.40288\Windows 7 Loader eXtreme Edition 3.503\FAQ\FAQ(Chinese (Simplified)).txtbinary
MD5:2EC9A2D00D7C81565F83FA294DD69717
SHA256:8FD7172CB87910D91E40AF088B5782B8A85D13AB63CB3B41731EC11AA594A157
3792WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3792.40288\Windows 7 Loader eXtreme Edition 3.503\FAQ\FAQ(Catalan).txtbinary
MD5:43F9A7A8DD1DA5543D8B2E66CADBEC19
SHA256:6D17A7E1E48F63716AE82E2380702BA16942C158E3EF0B38D7E7E14A41AAE2A7
3792WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3792.40288\Windows 7 Loader eXtreme Edition 3.503\FAQ\FAQ(Albanian).txtbinary
MD5:8290251B08DD45FE6869D638549C86B4
SHA256:5A7106D77660FAA536FB0C4E7173C59FC53BF916992973044875431002859B58
3792WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3792.40288\Windows 7 Loader eXtreme Edition 3.503\FAQ\FAQ(Bulgarian).txttext
MD5:22D3BBB32B8C4D91256932F9B4184D35
SHA256:3418CE316CB4B21FEB495E6F2DD612D6AEEB1EC8F1A77BEA068914E23817FFD2
3792WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3792.40288\Windows 7 Loader eXtreme Edition 3.503\FAQ\FAQ(Dutch).txtbinary
MD5:4674A9C8D7CFADE0DA8E0F41735CC267
SHA256:FE58E4A8033CEF600DCC6ED88BFBFE27D8FD7646D926EA9A7D191CB5BED627AA
3792WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3792.40288\Windows 7 Loader eXtreme Edition 3.503\FAQ\FAQ(Czech).txtbinary
MD5:22D4742A6298FC3EA2D7C60FE7443826
SHA256:3120C74CC07C1F13BC6E172E39D56471A1B4D62809D020487845ECA423883134
3792WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3792.40288\Windows 7 Loader eXtreme Edition 3.503\FAQ\FAQ(Croatian).txtbinary
MD5:354E9281DA201B493150890682934C74
SHA256:1C629ED0B868D686EF45AC126A3FE9764A33117150BA7917485ADE1CE5475C1B
3792WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3792.40288\Windows 7 Loader eXtreme Edition 3.503\FAQ\FAQ(Chinese (Traditional)).txtbinary
MD5:DF93B5E4B384B500A3A6FCFD729E6644
SHA256:AEF10393DA1C51ECF792AE1A50C4C47EAD81057D5E3B11E1FA40F1B867D2C567
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info