File name:

Nuevo Archivo WinRAR.rar

Full analysis: https://app.any.run/tasks/7b033ce2-ad4b-4934-81d4-5a84c8a9e368
Verdict: Malicious activity
Analysis date: March 11, 2024, 15:40:01
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

CEC967D9AEFCA6F7BA94C469CAAE44FF

SHA1:

6EA6C99B88BF47D2FAB14F18C54CB58AC9CF3390

SHA256:

B094A648DF06B8A889D911B158D7B063DD3375410CADCE5AF373FE092C619E59

SSDEEP:

98304:Jk+mr9Lv5QZzlE/vw3bP4n0hJA/S9a6Cuc0ybuE0KciEetSenoCwX+5+NajYJiuo:v6zfRB

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 2160)
      • Activador Office v5.exe (PID: 1692)
      • irsetup.exe (PID: 3092)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • Activador Office v5.exe (PID: 1692)
      • irsetup.exe (PID: 3092)
    • Reads the Internet Settings

      • Activador Office v5.exe (PID: 1692)
      • cmd.exe (PID: 3164)
    • Reads security settings of Internet Explorer

      • Activador Office v5.exe (PID: 1692)
    • Reads the Windows owner or organization settings

      • irsetup.exe (PID: 3092)
    • Uses REG/REGEDIT.EXE to modify registry

      • cmd.exe (PID: 3164)
    • Creates a software uninstall entry

      • irsetup.exe (PID: 3092)
    • Creates or modifies Windows services

      • AutoPico.exe (PID: 1308)
  • INFO

    • Manual execution by a user

      • wmpnscfg.exe (PID: 2752)
      • Activador Office v5.exe (PID: 3932)
      • Activador Office v5.exe (PID: 1692)
      • cmd.exe (PID: 3164)
    • Checks supported languages

      • wmpnscfg.exe (PID: 2752)
      • Activador Office v5.exe (PID: 1692)
      • irsetup.exe (PID: 3092)
      • AutoPico.exe (PID: 1308)
    • Reads the computer name

      • wmpnscfg.exe (PID: 2752)
      • Activador Office v5.exe (PID: 1692)
      • irsetup.exe (PID: 3092)
      • AutoPico.exe (PID: 1308)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2160)
    • Create files in a temporary directory

      • Activador Office v5.exe (PID: 1692)
      • irsetup.exe (PID: 3092)
    • Creates files or folders in the user directory

      • irsetup.exe (PID: 3092)
    • Reads the machine GUID from the registry

      • AutoPico.exe (PID: 1308)
    • Reads product name

      • AutoPico.exe (PID: 1308)
    • Reads Environment values

      • AutoPico.exe (PID: 1308)
    • Reads Microsoft Office registry keys

      • AutoPico.exe (PID: 1308)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
62
Monitored processes
13
Malicious processes
2
Suspicious processes
2

Behavior graph

Click at the process to see the details
start winrar.exe wmpnscfg.exe no specs activador office v5.exe no specs activador office v5.exe irsetup.exe cmd.exe no specs regedit.exe no specs regedit.exe no specs regedit.exe autopico.exe no specs autopico.exe no specs autopico.exe schtasks.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1172SCHTASKS /Create /TN "AutoPico Daily Restart" /TR "C:\Windows\Activador\AutoPico.exe /silent" /SC DAILY /ST 23:59:59 /RU SYSTEM /RL Highest /FC:\Windows\System32\schtasks.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Manages scheduled tasks
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
1308"C:\Windows\Activador\AutoPico.exe" C:\Windows\Activador\AutoPico.exe
cmd.exe
User:
admin
Company:
@ByELDI
Integrity Level:
HIGH
Description:
AutoPico
Exit code:
0
Version:
15.0.0.6
Modules
Images
c:\windows\activador\autopico.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1692"C:\Users\admin\Desktop\Activador\Activador Office v5.exe" C:\Users\admin\Desktop\Activador\Activador Office v5.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup Application
Exit code:
0
Version:
9.5.0.0
Modules
Images
c:\users\admin\desktop\activador\activador office v5.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
1740"C:\Windows\regedit.exe" /S DisableSmartScreen.regC:\Windows\regedit.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Registry Editor
Exit code:
3221226540
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\regedit.exe
c:\windows\system32\ntdll.dll
1808"C:\Windows\Activador\AutoPico.exe" C:\Windows\Activador\AutoPico.execmd.exe
User:
admin
Company:
@ByELDI
Integrity Level:
MEDIUM
Description:
AutoPico
Exit code:
3221226540
Version:
15.0.0.6
Modules
Images
c:\windows\activador\autopico.exe
c:\windows\system32\ntdll.dll
2160"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Nuevo Archivo WinRAR.rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2752"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2904"C:\Windows\regedit.exe" /S DisableSmartScreen.regC:\Windows\regedit.exe
cmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Registry Editor
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\regedit.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3072AutoPico.exeC:\Windows\Activador\AutoPico.execmd.exe
User:
admin
Company:
@ByELDI
Integrity Level:
MEDIUM
Description:
AutoPico
Exit code:
3221226540
Version:
15.0.0.6
Modules
Images
c:\windows\activador\autopico.exe
c:\windows\system32\ntdll.dll
3092"C:\Users\admin\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe" __IRAOFF:1884930 "__IRAFN:C:\Users\admin\Desktop\Activador\Activador Office v5.exe" "__IRCT:3" "__IRTSS:0" "__IRSID:S-1-5-21-1302019708-1500728564-335382590-1000"C:\Users\admin\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe
Activador Office v5.exe
User:
admin
Company:
Indigo Rose Corporation
Integrity Level:
HIGH
Description:
Setup Application
Exit code:
0
Version:
9.5.0.0
Modules
Images
c:\users\admin\appdata\local\temp\_ir_sf_temp_0\irsetup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\gdi32.dll
Total events
10 397
Read events
10 286
Write events
110
Delete events
1

Modification events

(PID) Process:(2160) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2160) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2160) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2160) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(2160) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(2160) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(2160) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Nuevo Archivo WinRAR.rar
(PID) Process:(2160) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2160) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2160) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
Executable files
8
Suspicious files
3
Text files
356
Unknown types
18

Dropped files

PID
Process
Filename
Type
3092irsetup.exeC:\Users\admin\AppData\Local\Temp\_ir_sf_temp_0\IRIMG1.JPGimage
MD5:D472A0189AA52F36633AC3D89F5E1219
SHA256:D5E3CD5ADCFDC47B3B9ED57C59960EFC8792A820E404AC8DDA85EF943DE7904B
3092irsetup.exeC:\Users\admin\AppData\Local\Temp\_ir_sf_temp_0\IRIMG3.JPGimage
MD5:F4E6420595B0418AC0379D33FD264FC0
SHA256:6A321BBB3FC68CA597217B87C042B7F1F7B136CC1DDFB29F0DD396C14568E779
3092irsetup.exeC:\Windows\Activador\lua5.1.dllexecutable
MD5:C3F5F4A1FB69B5889F0BBB313CF6017F
SHA256:769416FA7EDF38E91A55F4F7163914EE4AAD9C8C890ED641C300B73157ACAC45
3092irsetup.exeC:\Windows\Activador\Uninstall\uninstall.xmlxml
MD5:D79571085424A88EBD3E86E5A92F3DAD
SHA256:A28EA25BBA43A0595DC7BBFF1EB9DBB1250BDF557259DFBF6CEE31B28282A660
3092irsetup.exeC:\Users\admin\AppData\Local\Temp\_ir_sf_temp_0\irsetup.datbinary
MD5:DA9DCB9888E6077CCB53AD5D91BA53D3
SHA256:2CBE3E29239A97B461156757B376B14EC7B971A6A3A7DA71EB840E8941643208
3092irsetup.exeC:\Windows\Activador\Auto.cmdtext
MD5:3D9673422F0CDD485ADE60AC1ABB2F62
SHA256:7339A4CC48220A161FCC737ED26E99E5678A4D1FAA3F7E2686C46B5A5D234828
1692Activador Office v5.exeC:\Users\admin\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exeexecutable
MD5:9BDCF813D65265255B820BC7A704DA3C
SHA256:B15D67B4A57184E5202DF3C25E20DC0B7F853F4D527D148B337138900989824A
3092irsetup.exeC:\Windows\Activador\uninstall.exeexecutable
MD5:9BDCF813D65265255B820BC7A704DA3C
SHA256:B15D67B4A57184E5202DF3C25E20DC0B7F853F4D527D148B337138900989824A
3092irsetup.exeC:\Windows\Activador\DisableSmartScreen.regtext
MD5:98726CF4E77C2A5159801D4E888833DA
SHA256:20AEE3A1B0ECD68E642A5C8FF550D1525DF1C3F2FDA22B7DB51010947153FEBA
3092irsetup.exeC:\Windows\Activador\Uninstall\uninstall.datbinary
MD5:DBC805E5DF229A0CB9A8F75901C3C549
SHA256:354E992403B2F4A66D99DF619FA35A8EBA75E5CCDF62F0107BC0B85BCEA13CE5
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
5
DNS requests
1
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
224.0.0.252:5355
unknown
1080
svchost.exe
224.0.0.252:5355
unknown
1308
AutoPico.exe
131.188.3.222:123
0.pool.ntp.org
unknown

DNS requests

Domain
IP
Reputation
0.pool.ntp.org
  • 85.214.83.151
  • 131.188.3.222
  • 144.76.139.8
  • 162.159.200.1
whitelisted

Threats

No threats detected
Process
Message
regedit.exe
REGEDIT: CreateFile failed, GetLastError() = 2