File name: | MRI.rar |
Full analysis: | https://app.any.run/tasks/b6381b78-c83b-4edf-a462-423277b5b713 |
Verdict: | Malicious activity |
Analysis date: | August 20, 2018, 05:00:21 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | application/x-rar |
File info: | RAR archive data, v4, os: Win32 |
MD5: | 0F9A07FECCF4D2B9D9DE4F19A3F99E2E |
SHA1: | 218500E2BA7DCD50C6AD51325BDA1220CE0F8FC3 |
SHA256: | 9EEF3165EA1A4CD8AECDE69AA8A690A191642BF6918851715152F32DEA7F472F |
SSDEEP: | 196608:KNeZKweTpeAA6xjcPyJUXirpbQwkcrzzS8TFyGpURaP6YAXmxuxW9cuNKa7uN:KNgWeejDJUXwbfrzeEFySUrd5E9cC74 |
.rar | | | RAR compressed archive (v-4.x) (58.3) |
---|---|---|
.rar | | | RAR compressed archive (gen) (41.6) |
CompressedSize: | 432 |
---|---|
UncompressedSize: | 625 |
OperatingSystem: | Win32 |
ModifyDate: | 2016:04:28 11:26:07 |
PackingMethod: | Normal |
ArchivedFileName: | Microsoft.VC90.CRT.manifest |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
880 | C:\Windows\system32\svchost.exe -k netsvcs | C:\Windows\System32\svchost.exe | services.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Host Process for Windows Services Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
2416 | "C:\Users\admin\Desktop\MRI\StartupManager.exe" | C:\Users\admin\Desktop\MRI\StartupManager.exe | — | explorer.exe | |||||||||||
User: admin Company: Geek Squad Integrity Level: MEDIUM Description: MRI Startup Manager Exit code: 3221226540 Version: 5.10.7.8 Modules
| |||||||||||||||
2512 | "C:\Users\admin\Desktop\MRI\desktop_information.dll" | C:\Users\admin\Desktop\MRI\desktop_information.dll | StartupManager.exe | ||||||||||||
User: admin Company: Geek Squad Integrity Level: HIGH Description: Geek Squad: Top Secret Exit code: 0 Version: 1.1.0.5 Modules
| |||||||||||||||
3512 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\MRI.rar" | C:\Program Files\WinRAR\WinRAR.exe | — | explorer.exe | |||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.60.0 Modules
| |||||||||||||||
3540 | "C:\Program Files\WinRAR\WinRAR.exe" x -iext -ow -ver -- "C:\Users\admin\Desktop\MRI.rar" C:\Users\admin\Desktop\MRI\ | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.60.0 Modules
| |||||||||||||||
3692 | "C:\Users\admin\Desktop\MRI\StartupManager.exe" | C:\Users\admin\Desktop\MRI\StartupManager.exe | explorer.exe | ||||||||||||
User: admin Company: Geek Squad Integrity Level: HIGH Description: MRI Startup Manager Exit code: 0 Version: 5.10.7.8 Modules
| |||||||||||||||
4044 | "C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe10_ Global\UsGthrCtrlFltPipeMssGthrPipe10 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" | C:\Windows\System32\SearchProtocolHost.exe | — | SearchIndexer.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft Windows Search Protocol Host Exit code: 0 Version: 7.00.7600.16385 (win7_rtm.090713-1255) Modules
|
(PID) Process: | (3512) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
Operation: | write | Name: | ShellExtBMP |
Value: | |||
(PID) Process: | (3512) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
Operation: | write | Name: | ShellExtIcon |
Value: | |||
(PID) Process: | (3512) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\59\52C64B7E |
Operation: | write | Name: | LanguageList |
Value: en-US | |||
(PID) Process: | (3512) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop\MRI.rar | |||
(PID) Process: | (3512) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | name |
Value: 120 | |||
(PID) Process: | (3512) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | size |
Value: 80 | |||
(PID) Process: | (3512) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | type |
Value: 120 | |||
(PID) Process: | (3512) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | mtime |
Value: 100 | |||
(PID) Process: | (3512) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin |
Operation: | write | Name: | Placement |
Value: 2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF2C0000002C000000EC03000021020000 | |||
(PID) Process: | (3512) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\General |
Operation: | write | Name: | LastFolder |
Value: C:\Users\admin\Desktop |
PID | Process | Filename | Type | |
---|---|---|---|---|
3540 | WinRAR.exe | C:\Users\admin\Desktop\MRI\SystemUpdater.exe | executable | |
MD5:— | SHA256:— | |||
3540 | WinRAR.exe | C:\Users\admin\Desktop\MRI\Superior.dll | executable | |
MD5:— | SHA256:— | |||
3540 | WinRAR.exe | C:\Users\admin\Desktop\MRI\StartupManager.exe | executable | |
MD5:— | SHA256:— | |||
3540 | WinRAR.exe | C:\Users\admin\Desktop\MRI\Data\cfg\SystemUpdater.xml | xml | |
MD5:— | SHA256:— | |||
3540 | WinRAR.exe | C:\Users\admin\Desktop\MRI\ProcessAnalyzer.exe | executable | |
MD5:— | SHA256:— | |||
3540 | WinRAR.exe | C:\Users\admin\Desktop\MRI\Data\cfg\Global.ini | text | |
MD5:— | SHA256:— | |||
880 | svchost.exe | C:\Windows\appcompat\programs\RecentFileCache.bcf | txt | |
MD5:— | SHA256:— | |||
3540 | WinRAR.exe | C:\Users\admin\Desktop\MRI\Microsoft.VC90.CRT.manifest | xml | |
MD5:— | SHA256:— | |||
3540 | WinRAR.exe | C:\Users\admin\Desktop\MRI\Data\cfg\Apps.xml | xml | |
MD5:— | SHA256:— | |||
3540 | WinRAR.exe | C:\Users\admin\Desktop\MRI\Uninstaller.exe | executable | |
MD5:— | SHA256:— |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
3692 | StartupManager.exe | POST | 200 | 52.87.60.23:80 | http://ping.geeksquadcentral.com/ws/p/cS.php | US | xml | 499 b | unknown |
3692 | StartupManager.exe | POST | 200 | 52.87.60.23:80 | http://ping.geeksquadcentral.com/ws/p/cS.php | US | xml | 491 b | unknown |
3692 | StartupManager.exe | POST | 200 | 52.87.60.23:80 | http://ping.geeksquadcentral.com/ws/p/cS.php | US | xml | 724 b | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
3692 | StartupManager.exe | 52.87.60.23:80 | ping.geeksquadcentral.com | Amazon.com, Inc. | US | unknown |
2512 | desktop_information.dll | 52.203.115.190:443 | geeksquadcentral.com | Amazon.com, Inc. | US | unknown |
Domain | IP | Reputation |
---|---|---|
ping.geeksquadcentral.com |
| unknown |
geeksquadcentral.com |
| unknown |
Process | Message |
---|---|
StartupManager.exe | DL Status 0x00000001
|
StartupManager.exe | DL Status 0x00000002
|
StartupManager.exe | DL Status 0x00000004
|
StartupManager.exe | DL Status 0x00000008
|
StartupManager.exe | DL Status 0x00000010
|
StartupManager.exe | DL Status 0x00000020
|
StartupManager.exe | DL Status 0x00000010
|
StartupManager.exe | DL Status 0x00000020
|
StartupManager.exe | DL Status 0x00400000
|
StartupManager.exe | DL Status 0x00000040
|