File name:

exam-testing-engine-vumingo-master.rar

Full analysis: https://app.any.run/tasks/e0376761-f279-458e-8b02-8748444bbbb5
Verdict: Malicious activity
Analysis date: May 02, 2024, 14:29:57
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

1364D2780792FB93FD7D768A9B80876F

SHA1:

EEAFF92129B59613D7D371768E569D2111AD90C8

SHA256:

AA3F645BBD210BE57FDA2E8582935883490E8E0C00A10B9DEF349750CD1ED8AC

SSDEEP:

98304:NzobThAbizEZf9Y2+DkQcXdEDePxQ+rcKPcODc2HhhUgPTXcW2tUnDXFBFYaJ3HJ:Nd3HnIEYbo7

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 3968)
  • SUSPICIOUS

    • Reads the Internet Settings

      • player.exe (PID: 1200)
      • player.exe (PID: 2348)
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3968)
    • Reads the computer name

      • player.exe (PID: 1200)
      • wmpnscfg.exe (PID: 1136)
      • player.exe (PID: 1604)
      • player.exe (PID: 1132)
      • player.exe (PID: 1836)
      • player.exe (PID: 1788)
      • player.exe (PID: 2348)
    • Checks supported languages

      • player.exe (PID: 1200)
      • wmpnscfg.exe (PID: 1136)
      • player.exe (PID: 1604)
      • player.exe (PID: 1132)
      • player.exe (PID: 1836)
      • player.exe (PID: 1788)
      • player.exe (PID: 2348)
    • Checks proxy server information

      • player.exe (PID: 1200)
      • player.exe (PID: 2348)
    • Manual execution by a user

      • player.exe (PID: 1200)
      • rundll32.exe (PID: 304)
      • wmpnscfg.exe (PID: 1136)
      • player.exe (PID: 1132)
      • player.exe (PID: 1836)
      • player.exe (PID: 2348)
      • player.exe (PID: 1788)
      • notepad.exe (PID: 1928)
    • Creates files in the program directory

      • player.exe (PID: 1200)
      • player.exe (PID: 2348)
    • Reads the machine GUID from the registry

      • player.exe (PID: 1200)
      • player.exe (PID: 2348)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
44
Monitored processes
10
Malicious processes
0
Suspicious processes
2

Behavior graph

Click at the process to see the details
start winrar.exe player.exe wmpnscfg.exe no specs rundll32.exe no specs player.exe no specs player.exe no specs player.exe no specs player.exe no specs player.exe notepad.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
304"C:\Windows\system32\rundll32.exe" C:\Windows\system32\shell32.dll,OpenAs_RunDLL C:\Users\admin\Desktop\Exam Testing Engine\samples\Exam Sample.eteC:\Windows\System32\rundll32.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
1132"C:\Users\admin\Desktop\Exam Testing Engine\player.exe" "C:\Users\admin\Desktop\Exam Testing Engine\samples\Exam Sample.ete"C:\Users\admin\Desktop\Exam Testing Engine\player.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\exam testing engine\player.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1136"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1200"C:\Users\admin\Desktop\Exam Testing Engine\player.exe" C:\Users\admin\Desktop\Exam Testing Engine\player.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\exam testing engine\player.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1604"C:\Users\admin\Desktop\Exam Testing Engine\player.exe" "C:\Users\admin\Desktop\Exam Testing Engine\samples\Exam Sample.ete"C:\Users\admin\Desktop\Exam Testing Engine\player.exerundll32.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\exam testing engine\player.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1788"C:\Users\admin\Desktop\Exam Testing Engine\player.exe" "C:\Users\admin\Desktop\Exam Testing Engine\samples\Exam Sample.ete"C:\Users\admin\Desktop\Exam Testing Engine\player.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\exam testing engine\player.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1836"C:\Users\admin\Desktop\Exam Testing Engine\player.exe" "C:\Users\admin\Desktop\Exam Testing Engine\samples\Exam Sample.ete"C:\Users\admin\Desktop\Exam Testing Engine\player.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\exam testing engine\player.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1928"C:\Windows\system32\NOTEPAD.EXE" C:\Users\admin\Desktop\Exam Testing Engine\samples\import_sample.txtC:\Windows\System32\notepad.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\notepad.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2348"C:\Users\admin\Desktop\Exam Testing Engine\player.exe" "C:\Users\admin\Desktop\Exam Testing Engine\samples\Exam Sample.ete"C:\Users\admin\Desktop\Exam Testing Engine\player.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\exam testing engine\player.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
3968"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\exam-testing-engine-vumingo-master.rarC:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
Total events
16 205
Read events
16 010
Write events
182
Delete events
13

Modification events

(PID) Process:(3968) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3968) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3968) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3968) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(3968) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(3968) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(3968) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\exam-testing-engine-vumingo-master.rar
(PID) Process:(3968) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3968) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3968) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
Executable files
6
Suspicious files
7
Text files
3
Unknown types
3

Dropped files

PID
Process
Filename
Type
3968WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3968.2726\exam-testing-engine-vumingo-master\Exam Testing Engine\samples\Exam Sample.etebinary
MD5:227AFC8187CCF734F3902E7BC70043CA
SHA256:A5CE0EA47FEE53E17D03FD78AF7E2F28B6350A6EDE76AD0F2D41E9DF600351C6
3968WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3968.2726\exam-testing-engine-vumingo-master\Exam Testing Engine\ssleay32.dllexecutable
MD5:5FB656AC9061DDB41C89AAC164F5A0D8
SHA256:29E9F2287D012C11460445702CF9D9F0E62F32786F7A87099718F58E94C3AEBE
3968WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3968.2726\exam-testing-engine-vumingo-master\Exam Testing Engine\license.txttext
MD5:61C2850BE101D5AE74EC7887B4171BFC
SHA256:DAE18F6B74DD3B68C31C5B7B92BD077E00F5CBFE62E70367650FFFDE1227976F
3968WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3968.2726\exam-testing-engine-vumingo-master\Exam Testing Engine\applauncher.exeexecutable
MD5:C38819141BAE4EE063C9C3C930F2020F
SHA256:C69412C2F180D150E07B7E97BA6569A8EE1A283BE5ACAEF6F9C915882F9FB9CA
3968WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3968.2726\exam-testing-engine-vumingo-master\Exam Testing Engine\libeay32.dllexecutable
MD5:2C92FC5D92C11FEDD82D904322544E62
SHA256:98085F83771571FDE75E5F0DBCBB590EE3794360D4FA0216D8C34CEE44A651A1
3968WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3968.2726\exam-testing-engine-vumingo-master\Exam Testing Engine\libcrypt.dllexecutable
MD5:B202B28543316B97DB7DA231252C5CF2
SHA256:C2DE2B293D1EFFC7E70F37FF5FD326574387D0976C31DAB632F93BCABFAA12B9
3968WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3968.2726\exam-testing-engine-vumingo-master\Exam Testing Engine\samples\import_sample.rtftext
MD5:00F41E6EEEC0551A7D73AEAE04B89132
SHA256:AFC4BF556E39543CC15DC73B5C6CC734C82809A9429CE96EC4A4276B57C7166D
3968WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3968.2726\exam-testing-engine-vumingo-master\Exam Testing Engine\sqlite3.dllexecutable
MD5:E43390C0147BA9D97A0E7EE9AB241492
SHA256:92C726228BC91F193FB81EE0F7ABA2F6A3C66BB580EDA2465FBF491A1F5FFA00
1200player.exeC:\ProgramData\Exam Testing Engine\etesimulator.db-journalbinary
MD5:ECB579FBD07A287EB40B89692470D7DF
SHA256:8BE156DA74DADD27D48CCE113028F9E60F1817DF85E7C4A7C74A4DEFFE914C1B
3968WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3968.2726\exam-testing-engine-vumingo-master\Exam Testing Engine\samples\import_sample.txttext
MD5:6A0689246852BBD5907307C7A617CAF6
SHA256:21AE5E6D463B2CCB750D520C2DA884AA1E270A7A9960B4112B9D139A5426E2E6
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
6
DNS requests
1
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1200
player.exe
GET
200
138.197.108.120:80
http://update.vumingo.com/update.xml
unknown
unknown
2348
player.exe
GET
200
138.197.108.120:80
http://update.vumingo.com/update.xml
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1088
svchost.exe
224.0.0.252:5355
unknown
1200
player.exe
138.197.108.120:80
update.vumingo.com
DIGITALOCEAN-ASN
US
unknown
2348
player.exe
138.197.108.120:80
update.vumingo.com
DIGITALOCEAN-ASN
US
unknown

DNS requests

Domain
IP
Reputation
update.vumingo.com
  • 138.197.108.120
unknown

Threats

No threats detected
No debug info