File name:

sh-Stardock_Fences_6.00_x64_Multilingual.rar

Full analysis: https://app.any.run/tasks/95d29da8-8b85-4cc3-b4cf-26915cac5193
Verdict: Malicious activity
Analysis date: June 19, 2025, 08:23:07
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
arch-exec
arch-doc
Indicators:
MIME: application/x-rar
File info: RAR archive data, v2.0, os: Unix
MD5:

1B8A6C602841CC0F618B6D7EB8465809

SHA1:

B50EAD43B66656360FDB13F326842F424BA71960

SHA256:

B9B8A43189498E1FAAD4FCDBC5373E8CEBD466E6D321E2BD5EEA7B1E88BB7C4A

SSDEEP:

196608:Enk+AalwHqWBvoOVVAcOHqpDhFywhkKUhLXhL5hL+:Akj6WVV/elFXF5F+

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Generic archive extractor

      • WinRAR.exe (PID: 6980)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • stardock.fences.3.0.5.x64-patch.exe (PID: 1216)
    • Executing commands from a ".bat" file

      • WinRAR.exe (PID: 536)
    • Starts CMD.EXE for commands execution

      • WinRAR.exe (PID: 536)
    • The process executes via Task Scheduler

      • updater.exe (PID: 5724)
    • Application launched itself

      • updater.exe (PID: 5724)
    • Reads security settings of Internet Explorer

      • WinRAR.exe (PID: 536)
  • INFO

    • Create files in a temporary directory

      • stardock.fences.3.0.5.x64-patch.exe (PID: 1216)
      • MpCmdRun.exe (PID: 3788)
    • Manual execution by a user

      • WinRAR.exe (PID: 1800)
      • stardock.fences.3.0.5.x64-patch.exe (PID: 3960)
      • stardock.fences.3.0.5.x64-patch.exe (PID: 1216)
      • WinRAR.exe (PID: 536)
      • notepad.exe (PID: 5564)
      • msinfo32.exe (PID: 4512)
    • Checks supported languages

      • stardock.fences.3.0.5.x64-patch.exe (PID: 1216)
      • updater.exe (PID: 5724)
      • updater.exe (PID: 432)
      • MpCmdRun.exe (PID: 3788)
    • Reads security settings of Internet Explorer

      • notepad.exe (PID: 5564)
    • Reads the computer name

      • stardock.fences.3.0.5.x64-patch.exe (PID: 1216)
      • updater.exe (PID: 5724)
      • MpCmdRun.exe (PID: 3788)
    • The sample compiled with english language support

      • WinRAR.exe (PID: 536)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 536)
    • Checks proxy server information

      • slui.exe (PID: 6232)
    • Reads the software policy settings

      • slui.exe (PID: 6232)
    • Process checks whether UAC notifications are on

      • updater.exe (PID: 5724)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v-4.x) (58.3)
.rar | RAR compressed archive (gen) (41.6)

EXIF

ZIP

FileVersion: RAR v4
CompressedSize: 24155108
UncompressedSize: 24155056
OperatingSystem: Unix
ModifyDate: 2025:05:31 05:18:18
PackingMethod: Stored
ArchivedFileName: sh-mdx-Stardock_Fences_6.00.rar
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
148
Monitored processes
13
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe no specs winrar.exe no specs winrar.exe stardock.fences.3.0.5.x64-patch.exe no specs stardock.fences.3.0.5.x64-patch.exe notepad.exe no specs msinfo32.exe no specs slui.exe cmd.exe no specs conhost.exe no specs mpcmdrun.exe no specs updater.exe no specs updater.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
432"C:\Program Files (x86)\Google\GoogleUpdater\134.0.6985.0\updater.exe" --crash-handler --system "--database=C:\Program Files (x86)\Google\GoogleUpdater\134.0.6985.0\Crashpad" --url=https://clients2.google.com/cr/report --annotation=prod=Update4 --annotation=ver=134.0.6985.0 "--attachment=C:\Program Files (x86)\Google\GoogleUpdater\updater.log" --initial-client-data=0x298,0x29c,0x2a0,0x274,0x2a4,0x111c460,0x111c46c,0x111c478C:\Program Files (x86)\Google\GoogleUpdater\134.0.6985.0\updater.exeupdater.exe
User:
SYSTEM
Company:
Google LLC
Integrity Level:
SYSTEM
Description:
Google Updater
Exit code:
0
Version:
134.0.6985.0
Modules
Images
c:\program files (x86)\google\googleupdater\134.0.6985.0\updater.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\advapi32.dll
c:\windows\syswow64\msvcrt.dll
536"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\Desktop\mdx-Fences.6.00.rarC:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
1216"C:\Users\admin\Desktop\stardock.fences.3.0.5.x64-patch.exe" C:\Users\admin\Desktop\stardock.fences.3.0.5.x64-patch.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Modules
Images
c:\users\admin\desktop\stardock.fences.3.0.5.x64-patch.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\users\admin\appdata\local\temp\dup2patcher.dll
1800"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\Desktop\sh-mdx-Stardock_Fences_6.00.rarC:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
2276C:\WINDOWS\system32\cmd.exe /c ""C:\Users\admin\AppData\Local\Temp\Rar$VR536.27124\Rar$Scan45410.bat" "C:\Windows\System32\cmd.exeWinRAR.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\cmdext.dll
c:\windows\system32\advapi32.dll
3788"C:\Program Files\Windows Defender\MpCmdRun.exe" -Scan -ScanType 3 -File "C:\Users\admin\AppData\Local\Temp\Rar$VR536.27124"C:\Program Files\Windows Defender\MpCmdRun.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Malware Protection Command Line Utility
Exit code:
2
Version:
4.18.1909.6 (WinBuild.160101.0800)
Modules
Images
c:\program files\windows defender\mpcmdrun.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ucrtbase.dll
3960"C:\Users\admin\Desktop\stardock.fences.3.0.5.x64-patch.exe" C:\Users\admin\Desktop\stardock.fences.3.0.5.x64-patch.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\desktop\stardock.fences.3.0.5.x64-patch.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
4512"C:\WINDOWS\system32\msinfo32.exe" C:\Users\admin\Desktop\amped.nfoC:\Windows\System32\msinfo32.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
System Information
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msinfo32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\gdi32.dll
4808\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
5564"C:\WINDOWS\system32\NOTEPAD.EXE" C:\Users\admin\Desktop\AMPED.txtC:\Windows\System32\notepad.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\notepad.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
Total events
8 060
Read events
8 035
Write events
25
Delete events
0

Modification events

(PID) Process:(6980) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(6980) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(6980) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(6980) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\sh-Stardock_Fences_6.00_x64_Multilingual.rar
(PID) Process:(6980) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(6980) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(6980) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(6980) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(1800) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(1800) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
Executable files
4
Suspicious files
0
Text files
5
Unknown types
0

Dropped files

PID
Process
Filename
Type
1216stardock.fences.3.0.5.x64-patch.exeC:\Users\admin\AppData\Local\Temp\C5E3399ED9A072FE864748D49BA96094.dllexecutable
MD5:13249BC6AA781475CDE4A1C90F95EFD4
SHA256:3922A8C1B0F58B74FC3D89D7EEC3FE5C5B0E8BDA6B36491D2380431DD8E8284A
536WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$VR536.27124\mdx-Fences.6.00.rar\amped.nfotext
MD5:3DCA76A9B9D101A4E18BD54A603A4984
SHA256:F16790043FDD3B7D704CD76025A69427A9CE19EA8E56509BC60259BD22DB9EB4
536WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$VR536.27124\mdx-Fences.6.00.rar\AMPED\AMPED.txttext
MD5:4CA637758356B1127E8D265B842B6307
SHA256:224A4E40AC827974D15FADEFD26769C2B65B85698901615AF9AF3EA3BBA23BCF
536WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$VR536.27124\mdx-Fences.6.00.rar\AMPED\stardock.fences.3.0.5.x64-patch.exeexecutable
MD5:A83C862CE356CE27AA1BCAD439DE71AC
SHA256:5405E5C8A154F6219C933DBA05EF3CA2D1162E666CD36B183BA8580F209C898E
3788MpCmdRun.exeC:\Users\admin\AppData\Local\Temp\MpCmdRun.logtext
MD5:414B2F6F2B3AB626DAF40201B99E7495
SHA256:B6E6D2EA875E2B101059A511DCBD7B5D02F99FF579D49D9DDE16C8F2F5F5E3C3
536WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$VR536.27124\Rar$Scan45410.battext
MD5:43D08AF7D4C0406125A1908C2856B71E
SHA256:5AB2D9B3A64CB8998C5AC16B269EFB27BAE4ED0AA3FDB80BBCEB56F43C91EC8B
536WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$VR536.27124\mdx-Fences.6.00.rar\Fences6-sd-setup.exeexecutable
MD5:F05FD4939F54B8FA84A079E1A221B52B
SHA256:DB67CEC5A78DB0D984C975D60795F17D678D261BF9AED5D1DCF4FFA02EB030C3
432updater.exeC:\Program Files (x86)\Google\GoogleUpdater\updater.logtext
MD5:F9EB658B111E3150EE0249C4846AC4EF
SHA256:85E191E417A32CDA2337D93960E470FC399DC06826864807E1991BD3D9E431B8
1216stardock.fences.3.0.5.x64-patch.exeC:\Users\admin\AppData\Local\Temp\dup2patcher.dllexecutable
MD5:86A2F12A950B5F57ACCD8EE868E7CC65
SHA256:CBEF8DF49983B92DC428F4CB970CA4C3F9690774E400A2720BD41B6DEA95229B
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
27
TCP/UDP connections
39
DNS requests
18
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1268
svchost.exe
GET
200
23.55.104.172:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
4156
RUXIMICS.exe
GET
200
23.55.104.172:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5944
MoUsoCoreWorker.exe
GET
200
23.55.104.172:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
1268
svchost.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
5944
MoUsoCoreWorker.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
4156
RUXIMICS.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
POST
200
40.126.31.128:443
https://login.live.com/RST2.srf
unknown
xml
11.0 Kb
whitelisted
POST
200
20.190.159.2:443
https://login.live.com/RST2.srf
unknown
xml
11.1 Kb
whitelisted
POST
200
20.190.159.2:443
https://login.live.com/RST2.srf
unknown
xml
10.3 Kb
whitelisted
4664
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Signing%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1268
svchost.exe
23.55.104.172:80
crl.microsoft.com
Akamai International B.V.
US
whitelisted
5944
MoUsoCoreWorker.exe
23.55.104.172:80
crl.microsoft.com
Akamai International B.V.
US
whitelisted
4156
RUXIMICS.exe
23.55.104.172:80
crl.microsoft.com
Akamai International B.V.
US
whitelisted
1268
svchost.exe
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
4156
RUXIMICS.exe
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
5944
MoUsoCoreWorker.exe
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
5944
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 172.217.16.206
whitelisted
crl.microsoft.com
  • 23.55.104.172
  • 23.55.104.190
  • 23.216.77.25
  • 23.216.77.23
whitelisted
www.microsoft.com
  • 95.101.149.131
  • 23.35.229.160
whitelisted
settings-win.data.microsoft.com
  • 4.231.128.59
whitelisted
client.wns.windows.com
  • 172.211.123.250
  • 172.211.123.248
whitelisted
login.live.com
  • 20.190.159.4
  • 40.126.31.129
  • 20.190.159.2
  • 20.190.159.75
  • 20.190.159.129
  • 20.190.159.130
  • 20.190.159.71
  • 20.190.159.23
whitelisted
nexusrules.officeapps.live.com
  • 52.111.229.19
whitelisted
slscr.update.microsoft.com
  • 4.175.87.197
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 20.3.187.198
whitelisted
activation-v2.sls.microsoft.com
  • 40.91.76.224
whitelisted

Threats

No threats detected
No debug info