File name:

Dork Searcher EZ (1).rar

Full analysis: https://app.any.run/tasks/54154876-98bf-456e-99ff-58f419beca6d
Verdict: Malicious activity
Analysis date: July 28, 2021, 22:47:53
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v4, os: Win32
MD5:

722E65606A53746B9A54F27813ADDC23

SHA1:

7D0CD8F05DA5BF83EF4CBF81AB8122F8D7F22094

SHA256:

B8971B38C74625B3D2ADC5E15F6C11662D84687D376AE14C634E50E0AD85DF5D

SSDEEP:

196608:csKg+h9syL/QSsYOshRZIIEDNy6CiJqv0nW5e/DGNf9LP6L1ZMMyuU/:DoSyTQSlmfpysJqsnW5qDW9Ly39yuW

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • SearchProtocolHost.exe (PID: 2232)
      • Searcher.exe (PID: 2260)
    • Application was dropped or rewritten from another process

      • Searcher.exe (PID: 2260)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 1988)
    • Reads the computer name

      • WinRAR.exe (PID: 1988)
      • Searcher.exe (PID: 2260)
    • Checks supported languages

      • WinRAR.exe (PID: 1988)
      • Searcher.exe (PID: 2260)
    • Drops a file that was compiled in debug mode

      • WinRAR.exe (PID: 1988)
  • INFO

    • Manual execution by user

      • Searcher.exe (PID: 2260)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v-4.x) (58.3)
.rar | RAR compressed archive (gen) (41.6)

EXIF

ZIP

ArchivedFileName: Dork Searcher EZ\AntiPublic\link.db
PackingMethod: Normal
ModifyDate: 2017:04:10 19:16:21
OperatingSystem: Win32
UncompressedSize: 12288
CompressedSize: 258
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
36
Monitored processes
3
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe searchprotocolhost.exe no specs searcher.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1988"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Dork Searcher EZ (1).rar"C:\Program Files\WinRAR\WinRAR.exe
Explorer.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
c:\windows\system32\comdlg32.dll
2232"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe4_ Global\UsGthrCtrlFltPipeMssGthrPipe4 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" C:\Windows\system32\SearchProtocolHost.exeSearchIndexer.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Windows Search Protocol Host
Exit code:
0
Version:
7.00.7601.24542 (win7sp1_ldr_escrow.191209-2211)
Modules
Images
c:\windows\system32\searchprotocolhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2260"C:\Users\admin\Desktop\Dork Searcher EZ\Searcher.exe" C:\Users\admin\Desktop\Dork Searcher EZ\Searcher.exeExplorer.EXE
User:
admin
Integrity Level:
MEDIUM
Description:
Searcher
Exit code:
0
Version:
4.2.2.1
Modules
Images
c:\windows\system32\ntdll.dll
c:\users\admin\desktop\dork searcher ez\searcher.exe
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
Total events
1 997
Read events
1 982
Write events
14
Delete events
1

Modification events

(PID) Process:(1988) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(1988) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(1988) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1988) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(1988) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Dork Searcher EZ (1).rar
(PID) Process:(1988) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(1988) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(1988) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(1988) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2232) SearchProtocolHost.exeKey:HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\16C\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
Executable files
13
Suspicious files
2
Text files
5
Unknown types
4

Dropped files

PID
Process
Filename
Type
1988WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1988.16397\Dork Searcher EZ\Control.dllexecutable
MD5:AE6283E2CD932FB4A0D8FB62BA456C14
SHA256:627057D1D155445A96D54B88F6100627C18A621B18A4303F211739B464BA9CBA
1988WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1988.16397\Dork Searcher EZ\Key.txttext
MD5:69E41005F04DEF3F58DE7A087993C416
SHA256:C70E0FB02B2E232A88812A77CC8628BE077DA4593B86C968D8538E4FBB898B11
1988WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1988.16397\Dork Searcher EZ\blacktext
MD5:8F161398F61DCEE24D2F3284F4DB1D0C
SHA256:0DFAE6BF57B4F5DD68896C3DF7E7110B380DBBC8BA69D8372455027E15AFBD9A
1988WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1988.16397\Dork Searcher EZ\EntityFramework.SqlServer.dllexecutable
MD5:D9D5F50534E80494B41E00D1EEBE8B23
SHA256:F221C96EB93282B94A70A4C67E2893E1CBA4B5FD2B59FEDEDEFF94E36E10EF84
1988WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1988.16397\Dork Searcher EZ\EntityFramework.dllexecutable
MD5:470BE89A6DB2444175461B54AD00EC72
SHA256:A963696A7C3C3424A566644900FEC5528D0CF1BD66033A0E2D36B6E4882A7D3A
1988WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1988.16397\Dork Searcher EZ\Interop.WMPLib.dllbinary
MD5:B9F1241E02B83A443BAFCCF4839E4724
SHA256:16C18A3E6A5F2DD5EA7431E103F3FA76467B2B66D8166ABAB28D567F08584254
1988WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1988.16397\Dork Searcher EZ\AntiPublic\link.dbsqlite
MD5:AECECEE2C7B44FA2EEE601469AA374AB
SHA256:2AFF4F903986614C4E535D8D38BFC93EFC353DC4A9846D386EFC9521C95BFA68
1988WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1988.16397\Dork Searcher EZ\Update.exeexecutable
MD5:E2032456744FD06C43C2097F8FCD1A1F
SHA256:BF9BA9E515C43C1C7D394CBC528E2FA500D98C423DF89958485F61D2BD7BB874
1988WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1988.16397\Dork Searcher EZ\xNet.dllexecutable
MD5:E0DC512F55C29E333EB8B60DA1045C09
SHA256:A649C16F8308347092D376123DE7586902FA9939CA7C63A28421257359FA94CA
1988WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1988.16397\Dork Searcher EZ\System.Data.SQLite.EF6.dllexecutable
MD5:B02B80D5F34A4F66B647643A89B29D01
SHA256:F5369CE6E06AFDAAAB36C38661FB63F844BCBDC6DC32379F05776B3F4B041B63
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info