analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

Contract#2648.iso

Full analysis: https://app.any.run/tasks/984211b6-845c-498b-b9f3-2aaa92a4c181
Verdict: Malicious activity
Analysis date: October 04, 2022, 23:55:43
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-iso9660-image
File info: ISO 9660 CD-ROM filesystem data 'CD_ROM'
MD5:

3CA24F6A18CBB56C2E6189ACAD3813B6

SHA1:

A274B69F8CFAE8647F0DF4ADF5052CA98ADD9E28

SHA256:

9E66994AB67FAF93AA26E84A2790C5B9516D30E031263CFF076B32BCE9E19EB5

SSDEEP:

24576:jwFOHrwcwjHmvw1urOkVhEs7RK7Jb0y/cT5SLnujfHH:jwFOHrwcwjHmvwcrOYCs7RKb1/cT5SOf

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops executable file immediately after starts

      • WinRAR.exe (PID: 3164)
  • SUSPICIOUS

    • Reads the computer name

      • WinRAR.exe (PID: 3164)
      • WScript.exe (PID: 3504)
    • Checks supported languages

      • WinRAR.exe (PID: 3164)
      • WScript.exe (PID: 3504)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3164)
    • Executes scripts

      • WinRAR.exe (PID: 3164)
    • Uses RUNDLL32.EXE to load library

      • WinRAR.exe (PID: 3164)
    • Drops a file with a compile date too recent

      • WinRAR.exe (PID: 3164)
  • INFO

    • Checks Windows Trust Settings

      • WScript.exe (PID: 3504)
    • Checks supported languages

      • rundll32.exe (PID: 2576)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.iso | ISO 9660 CD image (27.6)
.atn | Photoshop Action (27.1)
.gmc | Game Music Creator Music (6.1)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
35
Monitored processes
3
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe wscript.exe no specs rundll32.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
3164"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Contract#2648.iso"C:\Program Files\WinRAR\WinRAR.exe
Explorer.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
3504"C:\Windows\System32\WScript.exe" "C:\Users\admin\AppData\Local\Temp\Rar$DIa3164.41832\pilgrimsNankeen.vbs" C:\Windows\System32\WScript.exeWinRAR.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft ® Windows Based Script Host
Exit code:
0
Version:
5.8.7600.16385
2576"C:\Windows\system32\rundll32.exe" C:\Windows\system32\shell32.dll,OpenAs_RunDLL C:\Users\admin\AppData\Local\Temp\Rar$DIa3164.42390\fuss.datC:\Windows\system32\rundll32.exeWinRAR.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Total events
1 342
Read events
1 310
Write events
32
Delete events
0

Modification events

(PID) Process:(3164) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3164) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3164) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3164) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(3164) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(3164) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Contract#2648.iso
(PID) Process:(3164) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3164) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3164) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3164) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
Executable files
1
Suspicious files
0
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
3164WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DIa3164.42390\fuss.datexecutable
MD5:A5332F86382D9FA4201FB1D5A7E8C1DA
SHA256:EA28BE72DC6FDA30D9E33A1A805D3DD95B88904804CB806DC39B5129E1BBD3A2
3164WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DIa3164.41832\pilgrimsNankeen.vbstext
MD5:C74ED96F8C74A0A63BCD142A3A07F45B
SHA256:AF9AFB53186842D71A9EC0A73A05BA6C1753590B29652AD2C882299FD4A8BEE6
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info