| File name: | Desktop.rar |
| Full analysis: | https://app.any.run/tasks/47deec78-c843-48df-bfb0-07cce18cd4ed |
| Verdict: | Malicious activity |
| Analysis date: | June 25, 2023, 18:41:14 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-rar |
| File info: | RAR archive data, v5 |
| MD5: | 547189414E2818270A4F645687603CBF |
| SHA1: | 7DB97C43B0DED660C61330AB6980F925723ACB10 |
| SHA256: | B2782ABE26D2755FDC5AAEBECE3504345D0F73CD9DFFCB8C0A2B37BEF99A6B9E |
| SSDEEP: | 6144:pUucPtyVH+xW3Uw+o0CqMKxkZhK1jMSgXPgY4pKbCv:p/UdxRwhRqp6gY4pwO |
| .rar | | | RAR compressed archive (v5.0) (61.5) |
|---|---|---|
| .rar | | | RAR compressed archive (gen) (38.4) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1188 | "C:\Program Files\Microsoft Gaigkc\Vjezaqn.exe" | C:\Program Files\Microsoft Gaigkc\Vjezaqn.exe | — | services.exe | |||||||||||
User: SYSTEM Integrity Level: SYSTEM Exit code: 0 Modules
| |||||||||||||||
| 1832 | "C:\Program Files\Microsoft Gaigkc\Vjezaqn.exe" Win7 | C:\Program Files\Microsoft Gaigkc\Vjezaqn.exe | — | Vjezaqn.exe | |||||||||||
User: SYSTEM Integrity Level: SYSTEM Exit code: 0 Modules
| |||||||||||||||
| 2508 | "C:\Program Files\Cccogae.exe" Win7 | C:\Program Files\Cccogae.exe | — | Cccogae.exe | |||||||||||
User: SYSTEM Integrity Level: SYSTEM Exit code: 0 Modules
| |||||||||||||||
| 2516 | "C:\Program Files\Cccogae.exe" Win7 | C:\Program Files\Cccogae.exe | — | Cccogae.exe | |||||||||||
User: SYSTEM Integrity Level: SYSTEM Exit code: 0 Modules
| |||||||||||||||
| 2588 | "C:\Program Files\Wywuaym.exe" | C:\Program Files\Wywuaym.exe | services.exe | ||||||||||||
User: SYSTEM Integrity Level: SYSTEM Exit code: 0 Modules
| |||||||||||||||
| 2864 | "C:\Users\admin\Desktop\aaa.exe" | C:\Users\admin\Desktop\aaa.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 3076 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\Desktop.rar" | C:\Program Files\WinRAR\WinRAR.exe | — | explorer.exe | |||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| 3552 | "C:\Users\admin\Desktop\a.exe" | C:\Users\admin\Desktop\a.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 3652 | "C:\Program Files\Cccogae.exe" | C:\Program Files\Cccogae.exe | — | services.exe | |||||||||||
User: SYSTEM Integrity Level: SYSTEM Exit code: 0 Modules
| |||||||||||||||
| 3948 | "C:\Program Files\WinRAR\WinRAR.exe" x -iext -ow -ver "-an=C:\Users\admin\Desktop\088b9498e86195680bfc9de8120e8009f1f0423175dd59f6090e3d745006d77f.7z" "-an=C:\Users\admin\Desktop\aa124697017c46741f54e4f827e171d7c3a2cfff4913f1e11c9efb56faf552eb.7z" -- "C:\Users\admin\Desktop\e39309dfcbb2553ed8c93281a6243d89439bc4a46b29773532005316aebdd989.7z" C:\Users\admin\Desktop\ | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| (PID) Process: | (3076) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\16D\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3076) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip | |||
| (PID) Process: | (3076) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (3076) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop\phacker.zip | |||
| (PID) Process: | (3076) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (3076) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (3076) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (3076) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (3948) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (3948) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3076 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3076.46950\088b9498e86195680bfc9de8120e8009f1f0423175dd59f6090e3d745006d77f.7z | compressed | |
MD5:DDC296CFDD7E35175D724D3A36CD7DB9 | SHA256:BF2B7870568F3CFD4D185C6AF0242CF3D14030183CF5ED94EEDE9BA33642639B | |||
| 3076 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3076.46950\aa124697017c46741f54e4f827e171d7c3a2cfff4913f1e11c9efb56faf552eb.7z | compressed | |
MD5:CAD6F368AA2DDEE122D8228D0992EE9C | SHA256:BC9A2B4137075EF31FB7D297D6753CC263EC805EE1C1426A24A1621CEEE55750 | |||
| 3076 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3076.46950\e39309dfcbb2553ed8c93281a6243d89439bc4a46b29773532005316aebdd989.7z | compressed | |
MD5:95123D1D9BDDC63D689EA395AA266529 | SHA256:BE59DD9BCEB4F0336BED0E2D8C1B51C081FD5F6DBD29E6D6E03CC52CCEC90CFF | |||
| 3948 | WinRAR.exe | C:\Users\admin\Desktop\088b9498e86195680bfc9de8120e8009f1f0423175dd59f6090e3d745006d77f | executable | |
MD5:BD8611002E01D4F9911E85624D431EB0 | SHA256:088B9498E86195680BFC9DE8120E8009F1F0423175DD59F6090E3D745006D77F | |||
| 3552 | a.exe | C:\Program Files\Cccogae.exe | executable | |
MD5:BD8611002E01D4F9911E85624D431EB0 | SHA256:088B9498E86195680BFC9DE8120E8009F1F0423175DD59F6090E3D745006D77F | |||
| 3552 | a.exe | C:\Windows\System32\1191093.bak | executable | |
MD5:BD8611002E01D4F9911E85624D431EB0 | SHA256:088B9498E86195680BFC9DE8120E8009F1F0423175DD59F6090E3D745006D77F | |||
| 4036 | aa.exe | C:\Windows\System32\1192328.bak | executable | |
MD5:9ADC9644A1956DEE23C63221951DD192 | SHA256:AA124697017C46741F54E4F827E171D7C3A2CFFF4913F1E11C9EFB56FAF552EB | |||
| 3948 | WinRAR.exe | C:\Users\admin\Desktop\aa124697017c46741f54e4f827e171d7c3a2cfff4913f1e11c9efb56faf552eb | executable | |
MD5:9ADC9644A1956DEE23C63221951DD192 | SHA256:AA124697017C46741F54E4F827E171D7C3A2CFFF4913F1E11C9EFB56FAF552EB | |||
| 3948 | WinRAR.exe | C:\Users\admin\Desktop\e39309dfcbb2553ed8c93281a6243d89439bc4a46b29773532005316aebdd989 | executable | |
MD5:782CBC8660FF9E94E584ADFCBC4CB961 | SHA256:E39309DFCBB2553ED8C93281A6243D89439BC4A46B29773532005316AEBDD989 | |||
| 4036 | aa.exe | C:\Program Files\Wywuaym.exe | executable | |
MD5:9ADC9644A1956DEE23C63221951DD192 | SHA256:AA124697017C46741F54E4F827E171D7C3A2CFFF4913F1E11C9EFB56FAF552EB | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1076 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
1896 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
3552 | a.exe | 103.66.189.149:2220 | tuwu.meibu.net | CMB | KR | unknown |
4036 | aa.exe | 103.66.189.149:2220 | tuwu.meibu.net | CMB | KR | unknown |
2588 | Wywuaym.exe | 103.66.189.149:2220 | tuwu.meibu.net | CMB | KR | unknown |
2864 | aaa.exe | 172.86.127.224:8000 | — | ASN-QUADRANET-GLOBAL | US | unknown |
Domain | IP | Reputation |
|---|---|---|
tuwu.meibu.net |
| unknown |