File name:

burp-loader-keygen-2_1_07.jar

Full analysis: https://app.any.run/tasks/80a9496c-f549-4aa9-be09-372dc1732210
Verdict: No threats detected
Analysis date: January 05, 2020, 00:15:26
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

421B24B19081BF3A18F3DB545D09B6E9

SHA1:

24F81FC509265D56B52FD3165670EE221138179B

SHA256:

AE37C4B69AF3B6B0D3B21DFAD20531C3B16889D8416D77B74DDE57CC1372BA05

SSDEEP:

768:3yox5t0GJV2vbNE2jn3VlpCMQaMUS5ZAXaRZtI6YbDO6b3y0/BoH7d+IjBxiDV:3pGQYbCwjQwSfAX2H63IFxiDV

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Uses RUNDLL32.EXE to load library

      • WinRAR.exe (PID: 2168)
  • INFO

    • Manual execution by user

      • WinRAR.exe (PID: 952)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2019:12:02 12:12:13
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: com/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
43
Monitored processes
3
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe no specs rundll32.exe no specs winrar.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
952"C:\Program Files\WinRAR\WinRAR.exe" x -iext -ow -ver -- "C:\Users\admin\Desktop\burp-loader-keygen-2_1_07.jar.zip" C:\Users\admin\Desktop\burp-loader-keygen-2_1_07.jar\C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2156"C:\Windows\system32\rundll32.exe" C:\Windows\system32\shell32.dll,OpenAs_RunDLL C:\Users\admin\AppData\Local\Temp\Rar$DIa2168.44741\KeygenDialog.classC:\Windows\system32\rundll32.exeWinRAR.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
2168"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\burp-loader-keygen-2_1_07.jar.zip"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
Total events
507
Read events
481
Write events
26
Delete events
0

Modification events

(PID) Process:(2168) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2168) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2168) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2168) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\burp-loader-keygen-2_1_07.jar.zip
(PID) Process:(2168) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2168) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2168) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2168) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2168) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList
Operation:writeName:ArcSort
Value:
32
(PID) Process:(2168) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFAC0000004B0000006C04000040020000
Executable files
0
Suspicious files
0
Text files
1
Unknown types
19

Dropped files

PID
Process
Filename
Type
2168WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DIa2168.44741\KeygenDialog.classclass
MD5:
SHA256:
952WinRAR.exeC:\Users\admin\Desktop\burp-loader-keygen-2_1_07.jar\com\intellij\uiDesigner\core\AbstractLayout.classclass
MD5:2EFF4AA2683BDF5181776CC41C6B51E5
SHA256:1519E3F23D37BE4FCB89268B406D547DC83B0081A7E5D1945359346F601295E6
952WinRAR.exeC:\Users\admin\Desktop\burp-loader-keygen-2_1_07.jar\com\intellij\uiDesigner\core\GridConstraints.classclass
MD5:5993F7DF071B1C9493EFBA8595065963
SHA256:0015FA74239E4CD5EC8B78B78F1D4B448708E6A98886A92EDBC09F0726162844
952WinRAR.exeC:\Users\admin\Desktop\burp-loader-keygen-2_1_07.jar\com\intellij\uiDesigner\core\HorizontalInfo.classclass
MD5:50FEE54B83201DCF2FE2972B1CD3B3F8
SHA256:AD4729092A410EA68CCA3E03062917165043BC4C0EB22ADD8EE1B00311EE4D22
952WinRAR.exeC:\Users\admin\Desktop\burp-loader-keygen-2_1_07.jar\com\intellij\uiDesigner\core\LayoutState.classclass
MD5:7BFBCDF7379B4122AD61851C266FF708
SHA256:B93ED6003D7D9FD5020EEF9BA7CD633475BFAA8E04E6BD301A753BFF307B2C3B
952WinRAR.exeC:\Users\admin\Desktop\burp-loader-keygen-2_1_07.jar\com\intellij\uiDesigner\core\Spacer.classclass
MD5:029BD4C20C69062CBEB976CE6D853B27
SHA256:FB6BADED097E888991D1000FE63AFD844C5390A47EABBD863CD69957D8F6CAEF
952WinRAR.exeC:\Users\admin\Desktop\burp-loader-keygen-2_1_07.jar\com\intellij\uiDesigner\core\GridLayoutManager.classclass
MD5:1886B4A727845145771620AD8EC8E718
SHA256:62F4F59F4DCC0F2C5D1AD1BBC43EA4F4383CA932CEF5CBFCE9F1054F093F2AF0
952WinRAR.exeC:\Users\admin\Desktop\burp-loader-keygen-2_1_07.jar\com\intellij\uiDesigner\core\SupportCode$TextWithMnemonic.classclass
MD5:E580703B289FEF920BDEDABD2E7432AF
SHA256:340B8B3ED8ED2A010924BBBB778E0684547161E4433BC24E67C8F026C49C5CC1
952WinRAR.exeC:\Users\admin\Desktop\burp-loader-keygen-2_1_07.jar\com\intellij\uiDesigner\core\Util.classclass
MD5:402F994ABA609587971E2DBE41F32645
SHA256:644B49C2EA6584AEA23F2EA60691FB002C3D7DDE1B53393109519769A66AB072
952WinRAR.exeC:\Users\admin\Desktop\burp-loader-keygen-2_1_07.jar\enjoy\reversing\me\KeygenDialog$3.classclass
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info