analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

Desktop.rar

Full analysis: https://app.any.run/tasks/8dafeac5-325a-41ae-a9ff-9975524f89ba
Verdict: Malicious activity
Analysis date: January 17, 2019, 21:03:13
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

AA97164D26F8A4ECE6C40CA98C10D894

SHA1:

A43538D989D57EF5BB8C082CAD500A4261116849

SHA256:

AD64FE4D1D7D5849386C93FDA65CCE9B19D6C646C9BD73F6A8268B726E500547

SSDEEP:

24576:Eevue6QgRyqViXh8bOYWxwZvK1OTlZcTi0uMzMyAbZpILWoCGLplQ82vBGdj:EevuFQlHXeW212ORMNAMjZ2ZUj

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Constructor.Win32.ChmBuilder.a.exe (PID: 3172)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2340)
      • WinRAR.exe (PID: 3460)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
39
Monitored processes
4
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe no specs winrar.exe winrar.exe constructor.win32.chmbuilder.a.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2988"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Desktop.rar"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
2340"C:\Program Files\WinRAR\WinRAR.exe" x -iext -ow -ver -- "C:\Users\admin\Desktop\Constructor.Win32.ChmBuilder.a.zip" C:\Users\admin\Desktop\C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
3460"C:\Program Files\WinRAR\WinRAR.exe" x -iext -ow -ver -- "C:\Users\admin\Desktop\radC8EB1.tmp.zip" C:\Users\admin\Desktop\C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
3172"C:\Users\admin\Desktop\Constructor.Win32.ChmBuilder.a.exe" C:\Users\admin\Desktop\Constructor.Win32.ChmBuilder.a.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Total events
743
Read events
699
Write events
0
Delete events
0

Modification events

No data
Executable files
2
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
2988WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2988.3131\Constructor.Win32.ChmBuilder.a.zip
MD5:
SHA256:
2988WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2988.3131\radC8EB1.tmp.zip
MD5:
SHA256:
2340WinRAR.exeC:\Users\admin\Desktop\Constructor.Win32.ChmBuilder.aexecutable
MD5:EA8C2D18963A44B672D2E65518235977
SHA256:389E65C153E0389497B797125EE6F46BA3BD5EA50D0F640DF0F0358B1A390981
3460WinRAR.exeC:\Users\admin\Desktop\rad24126.tmpexecutable
MD5:EEE6B8FFF025CAFAD98579657B7BCCD0
SHA256:14E44C02A55DE7BA6BCE25648AE343104F90213F2F2D2C382E9C738DE151CD50
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info