analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

Jaravoi.zip

Full analysis: https://app.any.run/tasks/6a99bf58-fdc4-440c-bbd4-c2cca0fd4a46
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: January 25, 2022, 00:53:43
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
opendir
loader
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

7D35C8B4F7C31F24A725803711F8A79A

SHA1:

DD898BCA5E607738AAB9FC9C057D543A4BA8BB9A

SHA256:

AF9C7804D32A40B6ACB0BFC5E262555783D9577A40B520A4B0A7DFA2BA6F574A

SSDEEP:

12288:672X/dymS3rhmADIzrNnVU7UCsUb0bVTFCvEmlHwKKrmcopSow1FI:HVgQADIzrN+zbiZYlHw7nPPI

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Jaravoi.exe (PID: 2656)
      • Jaravoi.exe (PID: 3196)
      • 89522.exe (PID: 2032)
      • Jaravoi.exe (PID: 2092)
      • 23256.exe (PID: 4020)
    • Changes settings of System certificates

      • Jaravoi.exe (PID: 3196)
  • SUSPICIOUS

    • Reads the computer name

      • WinRAR.exe (PID: 1044)
      • Jaravoi.exe (PID: 3196)
      • AppLaunch.exe (PID: 3684)
      • Jaravoi.exe (PID: 2092)
      • AppLaunch.exe (PID: 2904)
    • Checks supported languages

      • WinRAR.exe (PID: 1044)
      • Jaravoi.exe (PID: 3196)
      • 89522.exe (PID: 2032)
      • AppLaunch.exe (PID: 3684)
      • Jaravoi.exe (PID: 2092)
      • 23256.exe (PID: 4020)
      • AppLaunch.exe (PID: 2904)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 1044)
      • Jaravoi.exe (PID: 3196)
      • Jaravoi.exe (PID: 2092)
    • Drops a file that was compiled in debug mode

      • WinRAR.exe (PID: 1044)
    • Drops a file with a compile date too recent

      • WinRAR.exe (PID: 1044)
      • Jaravoi.exe (PID: 3196)
      • Jaravoi.exe (PID: 2092)
    • Reads Environment values

      • Jaravoi.exe (PID: 3196)
      • Jaravoi.exe (PID: 2092)
    • Adds / modifies Windows certificates

      • Jaravoi.exe (PID: 3196)
  • INFO

    • Checks Windows Trust Settings

      • Jaravoi.exe (PID: 3196)
      • Jaravoi.exe (PID: 2092)
    • Manual execution by user

      • Jaravoi.exe (PID: 2656)
      • Jaravoi.exe (PID: 3196)
      • Jaravoi.exe (PID: 2092)
    • Reads settings of System Certificates

      • Jaravoi.exe (PID: 3196)
      • Jaravoi.exe (PID: 2092)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipFileName: Instruction.txt
ZipUncompressedSize: 79
ZipCompressedSize: 73
ZipCRC: 0x78891324
ZipModifyDate: 2022:01:23 23:35:25
ZipCompression: Deflated
ZipBitFlag: -
ZipRequiredVersion: 20
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
51
Monitored processes
8
Malicious processes
2
Suspicious processes
2

Behavior graph

Click at the process to see the details
start drop and start drop and start winrar.exe jaravoi.exe no specs jaravoi.exe 89522.exe applaunch.exe jaravoi.exe 23256.exe applaunch.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1044"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Jaravoi.zip"C:\Program Files\WinRAR\WinRAR.exe
Explorer.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\windows\system32\ntdll.dll
c:\program files\winrar\winrar.exe
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2656"C:\Users\admin\Desktop\Jaravoi.exe" C:\Users\admin\Desktop\Jaravoi.exeExplorer.EXE
User:
admin
Company:
Stehr-Rolfson
Integrity Level:
MEDIUM
Description:
loader
Exit code:
3221226540
Version:
3.8.5.20
Modules
Images
c:\users\admin\desktop\jaravoi.exe
c:\windows\system32\ntdll.dll
3196"C:\Users\admin\Desktop\Jaravoi.exe" C:\Users\admin\Desktop\Jaravoi.exe
Explorer.EXE
User:
admin
Company:
Stehr-Rolfson
Integrity Level:
HIGH
Description:
loader
Exit code:
0
Version:
3.8.5.20
Modules
Images
c:\users\admin\desktop\jaravoi.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\system32\rpcrt4.dll
2032"C:\Users\admin\AppData\Local\Temp\89522.exe"C:\Users\admin\AppData\Local\Temp\89522.exe
Jaravoi.exe
User:
admin
Integrity Level:
HIGH
Exit code:
3221225477
Modules
Images
c:\users\admin\appdata\local\temp\89522.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
3684"C:\Windows\Microsoft.NET\Framework\v4.0.30319\AppLaunch.exe"C:\Windows\Microsoft.NET\Framework\v4.0.30319\AppLaunch.exe
89522.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft .NET ClickOnce Launch Utility
Version:
4.0.30319.34209 built by: FX452RTMGDR
Modules
Images
c:\windows\microsoft.net\framework\v4.0.30319\applaunch.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2092"C:\Users\admin\Desktop\Jaravoi.exe" C:\Users\admin\Desktop\Jaravoi.exe
Explorer.EXE
User:
admin
Company:
Stehr-Rolfson
Integrity Level:
HIGH
Description:
loader
Exit code:
0
Version:
3.8.5.20
Modules
Images
c:\users\admin\desktop\jaravoi.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
4020"C:\Users\admin\AppData\Local\Temp\23256.exe"C:\Users\admin\AppData\Local\Temp\23256.exe
Jaravoi.exe
User:
admin
Integrity Level:
HIGH
Exit code:
3221225477
Modules
Images
c:\users\admin\appdata\local\temp\23256.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
2904"C:\Windows\Microsoft.NET\Framework\v4.0.30319\AppLaunch.exe"C:\Windows\Microsoft.NET\Framework\v4.0.30319\AppLaunch.exe23256.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft .NET ClickOnce Launch Utility
Exit code:
0
Version:
4.0.30319.34209 built by: FX452RTMGDR
Modules
Images
c:\windows\microsoft.net\framework\v4.0.30319\applaunch.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
Total events
8 773
Read events
8 709
Write events
64
Delete events
0

Modification events

(PID) Process:(1044) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(1044) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(1044) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1044) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(1044) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(1044) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Jaravoi.zip
(PID) Process:(1044) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(1044) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(1044) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(1044) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
Executable files
5
Suspicious files
1
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
1044WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1044.18819\Instruction.txttext
MD5:B4925612B7FC489BEC50FF6D957D16E4
SHA256:1680B68ED8704355556A443670ACEC4FE63A7AF2101326A66980FE3759CD83B3
3196Jaravoi.exeC:\Users\admin\AppData\Local\Temp\4571.exeexecutable
MD5:8B4E2502A960818406D0E6E739315DEF
SHA256:5D07DD3151EC5394D4DA7C972D018F18DE5A54A3EEA272C8C8381F791F407EEB
1044WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1044.18819\win.dllbinary
MD5:163AB3E087A7E7AB60CE9A71A3C43E77
SHA256:8EEF1BAE0CA4023D77A0FC8721B6330AA98316E79CD9237B76CD5D292A7956C5
2092Jaravoi.exeC:\Users\admin\AppData\Local\Temp\10066.exeexecutable
MD5:8B4E2502A960818406D0E6E739315DEF
SHA256:5D07DD3151EC5394D4DA7C972D018F18DE5A54A3EEA272C8C8381F791F407EEB
2092Jaravoi.exeC:\Users\admin\AppData\Local\Temp\23256.exeexecutable
MD5:93653EEA94AAAD4EF414E93483C6BC72
SHA256:303A24EE6972ACA879D885EC5ECA537A66F7A3F30319D539B41A6842FD191508
3196Jaravoi.exeC:\Users\admin\AppData\Local\Temp\89522.exeexecutable
MD5:93653EEA94AAAD4EF414E93483C6BC72
SHA256:303A24EE6972ACA879D885EC5ECA537A66F7A3F30319D539B41A6842FD191508
1044WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1044.18819\Jaravoi.exeexecutable
MD5:D41CEC6D678B0EE212190FECDD83210A
SHA256:E38EFC8E966EFD60823070B5008ECC8E739E79F10742E6C7A3701BFDEF4878C7
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
8
TCP/UDP connections
6
DNS requests
0
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3684
AppLaunch.exe
GET
91.219.236.133:80
http://91.219.236.133/jjbadb0y
HU
malicious
3196
Jaravoi.exe
GET
200
95.143.178.121:80
http://95.143.178.121/pOGrJaaW2.exe
RU
executable
29.0 Kb
malicious
2092
Jaravoi.exe
GET
200
95.143.178.121:80
http://95.143.178.121/KXDXUnLt1.exe
RU
executable
3.94 Mb
malicious
2092
Jaravoi.exe
GET
200
95.143.178.121:80
http://95.143.178.121/oifRXHsS.dll
RU
executable
44.5 Kb
malicious
3684
AppLaunch.exe
GET
91.219.236.133:80
http://91.219.236.133/jjbadb0y
HU
malicious
2092
Jaravoi.exe
GET
200
95.143.178.121:80
http://95.143.178.121/pOGrJaaW2.exe
RU
executable
29.0 Kb
malicious
3196
Jaravoi.exe
GET
200
95.143.178.121:80
http://95.143.178.121/KXDXUnLt1.exe
RU
executable
3.94 Mb
malicious
3196
Jaravoi.exe
GET
200
95.143.178.121:80
http://95.143.178.121/oifRXHsS.dll
RU
executable
44.5 Kb
malicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3196
Jaravoi.exe
95.143.178.121:80
RU
malicious
2092
Jaravoi.exe
95.143.178.121:80
RU
malicious
3684
AppLaunch.exe
91.219.236.133:80
ServerAstra Kft.
HU
malicious

DNS requests

No data

Threats

PID
Process
Class
Message
3196
Jaravoi.exe
Potentially Bad Traffic
ET INFO Dotted Quad Host DLL Request
3196
Jaravoi.exe
Potential Corporate Privacy Violation
AV POLICY HTTP request for .dll file with no User-Agent
3196
Jaravoi.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
3196
Jaravoi.exe
Potentially Bad Traffic
ET INFO Executable Retrieved With Minimal HTTP Headers - Potential Second Stage Download
3196
Jaravoi.exe
A Network Trojan was detected
ET INFO Executable Download from dotted-quad Host
3196
Jaravoi.exe
Potential Corporate Privacy Violation
AV POLICY HTTP request for .exe file with no User-Agent
3196
Jaravoi.exe
Misc activity
ET INFO Packed Executable Download
3196
Jaravoi.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
3196
Jaravoi.exe
Potentially Bad Traffic
ET INFO Executable Retrieved With Minimal HTTP Headers - Potential Second Stage Download
3196
Jaravoi.exe
Potentially Bad Traffic
ET INFO SUSPICIOUS Dotted Quad Host MZ Response
No debug info