| File name: | WinRAR v7.00 B3 Official Release (32-Bit) Pre-Activated - Unlocked.exe |
| Full analysis: | https://app.any.run/tasks/d7b73038-5a7e-4305-befd-47ab308b857f |
| Verdict: | Malicious activity |
| Analysis date: | January 20, 2024, 08:16:13 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | C353F9C678EA37375EB1542D29B23B2F |
| SHA1: | 1DF5FB74DD84DD973CE91C01935CAA743BC9590A |
| SHA256: | B070797029681E05D41C6A8A1219C6DAD375443C58A824288623020658A63FDF |
| SSDEEP: | 98304:zf13rs3o8yb5FD+0lUpO4dVjgFPDRdtoM3CQNpfcmoHuUoxppO094L13HJ0jn5rL:NlA6 |
| .exe | | | Win64 Executable (generic) (76.4) |
|---|---|---|
| .exe | | | Win32 Executable (generic) (12.4) |
| .exe | | | Generic Win/DOS Executable (5.5) |
| .exe | | | DOS Executable Generic (5.5) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2017:08:11 15:54:17+02:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 14 |
| CodeSize: | 187392 |
| InitializedDataSize: | 316416 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x1c869 |
| OSVersion: | 5.1 |
| ImageVersion: | - |
| SubsystemVersion: | 5.1 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 7.0.3.0 |
| ProductVersionNumber: | 7.0.3.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Windows, Latin1 |
| Email: | inFo@Dr-FarFar.CoM |
| Website: | https://www.Dr-FarFar.com |
| Comments: | www.Dr-FarFar.com |
| CompanyName: | Dr.FarFar | www.Dr-FarFar.com |
| FileDescription: | WinRAR Full Activated [ViP] |
| FileVersion: | 7.0.3 |
| InternalName: | WinRAR.exe |
| LegalCopyright: | Copyright © Dr.FarFar |
| LegalTrademarks: | WinRAR Full Activated [ViP] |
| OriginalFileName: | WinRAR.exe |
| ProductName: | WinRAR Full Activated [ViP] |
| ProductVersion: | 7.0.3 |
| AssemblyVersion: | 7.0.3 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 120 | "C:\Users\admin\AppData\Local\Temp\WinRAR v7.00 B3 Official Release (32-Bit) Pre-Activated - Unlocked.exe" | C:\Users\admin\AppData\Local\Temp\WinRAR v7.00 B3 Official Release (32-Bit) Pre-Activated - Unlocked.exe | — | explorer.exe | |||||||||||
User: admin Company: Dr.FarFar | www.Dr-FarFar.com Integrity Level: MEDIUM Description: WinRAR Full Activated [ViP] Exit code: 3221226540 Version: 7.0.3 Modules
| |||||||||||||||
| 952 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --use-gl=angle --use-angle=swiftshader-webgl --mojo-platform-channel-handle=1560 --field-trial-handle=1272,i,4223016350368070984,10550429769424509923,131072 /prefetch:2 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 980 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1256 --field-trial-handle=1272,i,4223016350368070984,10550429769424509923,131072 /prefetch:2 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1000 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --first-renderer-process --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --mojo-platform-channel-handle=2324 --field-trial-handle=1272,i,4223016350368070984,10550429769424509923,131072 /prefetch:1 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1824 | "C:\Program Files\WinRAR\uninstall.exe" /setup | C:\Program Files\WinRAR\uninstall.exe | — | WinRAR v7.00 B3 Official Release (32-Bit) Pre-Activated - Unlocked.exe | |||||||||||
User: admin Company: Alexander Roshal Integrity Level: HIGH Description: Uninstall WinRAR Exit code: 0 Version: 7.0.3 Modules
| |||||||||||||||
| 1848 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --single-argument https://www.google.com/url?sa=t&rct=j&q=&esrc=s&source=web&cd=2&cad=rja&uact=8&ved=2ahUKEwisysKe7q_mAhVG-YUKHVZDAZ4QFjABegQIBxAC&url=https%3A%2F%2Fwww.dr-farfar.com%2F&usg=AOvVaw22hlzBu7hxTxcihgNzrn0C | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | WinRAR v7.00 B3 Official Release (32-Bit) Pre-Activated - Unlocked.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 2080 | "C:\Users\admin\AppData\Local\Temp\WinRAR v7.00 B3 Official Release (32-Bit) Pre-Activated - Unlocked.exe" | C:\Users\admin\AppData\Local\Temp\WinRAR v7.00 B3 Official Release (32-Bit) Pre-Activated - Unlocked.exe | explorer.exe | ||||||||||||
User: admin Company: Dr.FarFar | www.Dr-FarFar.com Integrity Level: HIGH Description: WinRAR Full Activated [ViP] Exit code: 0 Version: 7.0.3 Modules
| |||||||||||||||
| 2172 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" "--metrics-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=109.0.5414.149 "--annotation=exe=C:\Program Files\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win32 "--annotation=prod=Microsoft Edge" --annotation=ver=109.0.1518.115 --initial-client-data=0xc8,0xcc,0xd0,0x9c,0xd8,0x6d5af598,0x6d5af5a8,0x6d5af5b4 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 2176 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=2332 --field-trial-handle=1272,i,4223016350368070984,10550429769424509923,131072 /prefetch:1 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 2260 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1456 --field-trial-handle=1272,i,4223016350368070984,10550429769424509923,131072 /prefetch:3 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | msedge.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| (PID) Process: | (2080) WinRAR v7.00 B3 Official Release (32-Bit) Pre-Activated - Unlocked.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (2080) WinRAR v7.00 B3 Official Release (32-Bit) Pre-Activated - Unlocked.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (2080) WinRAR v7.00 B3 Official Release (32-Bit) Pre-Activated - Unlocked.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (2080) WinRAR v7.00 B3 Official Release (32-Bit) Pre-Activated - Unlocked.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (2080) WinRAR v7.00 B3 Official Release (32-Bit) Pre-Activated - Unlocked.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (2080) WinRAR v7.00 B3 Official Release (32-Bit) Pre-Activated - Unlocked.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (2080) WinRAR v7.00 B3 Official Release (32-Bit) Pre-Activated - Unlocked.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR SFX |
| Operation: | write | Name: | C%%Program Files%WinRAR |
Value: C:\Program Files\WinRAR | |||
| (PID) Process: | (1848) msedge.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Edge\BLBeacon |
| Operation: | write | Name: | failed_count |
Value: 0 | |||
| (PID) Process: | (1848) msedge.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Edge\BLBeacon |
| Operation: | write | Name: | state |
Value: 1 | |||
| (PID) Process: | (1848) msedge.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Edge\ThirdParty |
| Operation: | write | Name: | StatusCodes |
Value: 01000000 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2080 | WinRAR v7.00 B3 Official Release (32-Bit) Pre-Activated - Unlocked.exe | C:\Program Files\WinRAR\RarReg.key | text | |
MD5:11368B2FA7D08A84F4F270A1418B4FC0 | SHA256:A23B90E60DCA91DF298F1DE4BCEB13E5A5164824EBBD2CEAE874C70E89F0150E | |||
| 2080 | WinRAR v7.00 B3 Official Release (32-Bit) Pre-Activated - Unlocked.exe | C:\Program Files\WinRAR\Web.url | text | |
MD5:F8CC1FBD549B5A9A187FC6AAC948BC45 | SHA256:06187D0DEB8B2FAF4B9F51B9006A0D5435CBCBE62F321926DA48E2D3415DABAD | |||
| 2080 | WinRAR v7.00 B3 Official Release (32-Bit) Pre-Activated - Unlocked.exe | C:\Program Files\WinRAR\License.txt | text | |
MD5:672064CF19DB0B083B981CF0BE7662B0 | SHA256:9FC8AA33CCAFA04C1CE4C0A61047B341297D720ADAB1B77F67B5FE59F43BB59F | |||
| 2080 | WinRAR v7.00 B3 Official Release (32-Bit) Pre-Activated - Unlocked.exe | C:\Program Files\WinRAR\ReadMe.txt | text | |
MD5:00D0A57A6D64EE3DE8F4D5529D6C6447 | SHA256:FCD13E1B97AF47B8B923BA97AE15E9731C66093609667C3171D5DD24A6F7F2E6 | |||
| 2080 | WinRAR v7.00 B3 Official Release (32-Bit) Pre-Activated - Unlocked.exe | binary | ||
MD5:— | SHA256:— | |||
| 2080 | WinRAR v7.00 B3 Official Release (32-Bit) Pre-Activated - Unlocked.exe | C:\Program Files\WinRAR\RarExt64.dll | executable | |
MD5:ADA5F52FF77E4CB15140DA3598B2B928 | SHA256:2FA72E2CA7455C9C90548F70E88710B68AF7FB86BDAA6A62D00D6830AD9BC1B1 | |||
| 2080 | WinRAR v7.00 B3 Official Release (32-Bit) Pre-Activated - Unlocked.exe | C:\Program Files\WinRAR\UnRAR.exe | executable | |
MD5:C3437BE06208AA4CF8CE2C899293F43A | SHA256:8B24E0D5EFEE0672049EB892902A7C0D35491335C732DA1A5F4F11F77528B8DB | |||
| 2080 | WinRAR v7.00 B3 Official Release (32-Bit) Pre-Activated - Unlocked.exe | C:\Program Files\WinRAR\7zxa.dll | executable | |
MD5:6161EB75F65FABE5D05448FA5D7908B4 | SHA256:23D67D4BCD765355C85B831279D61F46B641E7B8F3ED772ADA8C915E5DEA9CB5 | |||
| 2080 | WinRAR v7.00 B3 Official Release (32-Bit) Pre-Activated - Unlocked.exe | C:\Program Files\WinRAR\RarExt.dll | executable | |
MD5:8B3137B3E3DEF9B4F540A3FC004FB371 | SHA256:26EAB307E36358FE287663CE38E6F27FC8F57DFDC2204BCB82375541C3B7F883 | |||
| 2080 | WinRAR v7.00 B3 Official Release (32-Bit) Pre-Activated - Unlocked.exe | C:\Program Files\WinRAR\Zip32.SFX | executable | |
MD5:D71D47C14F48F31B05B76364C1EFADDC | SHA256:F101732A5A10B79837E1D46F92E9A318DDFDBC02CC225B49F2EB0A60CC910615 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
2668 | msedge.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
2260 | msedge.exe | 142.250.186.68:443 | www.google.com | GOOGLE | US | whitelisted |
2260 | msedge.exe | 13.107.42.16:443 | config.edge.skype.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
2260 | msedge.exe | 204.79.197.239:443 | edge.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | unknown |
2260 | msedge.exe | 188.114.97.3:443 | www.dr-farfar.com | CLOUDFLARENET | NL | unknown |
2260 | msedge.exe | 20.166.151.106:443 | nav-edge.smartscreen.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
2260 | msedge.exe | 104.126.37.139:443 | www.bing.com | Akamai International B.V. | DE | unknown |
Domain | IP | Reputation |
|---|---|---|
www.google.com |
| whitelisted |
config.edge.skype.com |
| whitelisted |
edge.microsoft.com |
| whitelisted |
www.dr-farfar.com |
| unknown |
nav-edge.smartscreen.microsoft.com |
| whitelisted |
www.bing.com |
| whitelisted |