File name:

shellbag_analyzer_cleaner.rar

Full analysis: https://app.any.run/tasks/074e7bd9-1ff6-4b32-a5d2-ebca2f0e6ae5
Verdict: Malicious activity
Analysis date: December 14, 2024, 11:06:08
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
evasion
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

8B3A59520BB737B4C294BC008E8A2401

SHA1:

C3E7B5A055E136F1AAFFAC08F5B11FD975D92889

SHA256:

B9FDC5FF89F5C47509CCD6F01F0337B39B75414E717892529012B48D6FBBADA3

SSDEEP:

49152:fHfLN8GGVmteL+Tei8FFuR3fV9CO66l2ehJp9vReYREqrm2ZWGMfyEZe93H5eJH3:fHTNTfT+FMRPV9/66wop9v38HfyEZYH2

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • shellbag_analyzer_cleaner.exe (PID: 6212)
    • Create files in the Startup directory

      • shellbag_analyzer_cleaner.exe (PID: 6212)
  • SUSPICIOUS

    • Write to the desktop.ini file (may be used to cloak folders)

      • WinRAR.exe (PID: 3840)
    • Checks for external IP

      • svchost.exe (PID: 2192)
      • shellbag_analyzer_cleaner.exe (PID: 6212)
    • Executable content was dropped or overwritten

      • shellbag_analyzer_cleaner.exe (PID: 6212)
  • INFO

    • The process uses the downloaded file

      • WinRAR.exe (PID: 3840)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3840)
    • Checks supported languages

      • shellbag_analyzer_cleaner.exe (PID: 6212)
      • shellbag_analyzer_cleaner.exe (PID: 4528)
    • Manual execution by a user

      • shellbag_analyzer_cleaner.exe (PID: 6212)
      • shellbag_analyzer_cleaner.exe (PID: 4528)
    • Reads the machine GUID from the registry

      • shellbag_analyzer_cleaner.exe (PID: 6212)
      • shellbag_analyzer_cleaner.exe (PID: 4528)
    • Checks proxy server information

      • shellbag_analyzer_cleaner.exe (PID: 6212)
    • Disables trace logs

      • shellbag_analyzer_cleaner.exe (PID: 6212)
    • Reads Environment values

      • shellbag_analyzer_cleaner.exe (PID: 6212)
    • Reads the computer name

      • shellbag_analyzer_cleaner.exe (PID: 6212)
      • shellbag_analyzer_cleaner.exe (PID: 4528)
    • Creates files or folders in the user directory

      • shellbag_analyzer_cleaner.exe (PID: 6212)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)

EXIF

ZIP

ArchivedFileName: shellbag_analyzer_cleaner/desktop.ini
OperatingSystem: Win32
UncompressedSize: 46
CompressedSize: 64
FileVersion: RAR v5
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
132
Monitored processes
5
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe rundll32.exe no specs shellbag_analyzer_cleaner.exe svchost.exe shellbag_analyzer_cleaner.exe

Process information

PID
CMD
Path
Indicators
Parent process
3840"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\shellbag_analyzer_cleaner.rarC:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
7120C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -EmbeddingC:\Windows\System32\rundll32.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shcore.dll
c:\windows\system32\imagehlp.dll
6212"C:\Users\admin\Desktop\shellbag_analyzer_cleaner\shellbag_analyzer_cleaner.exe" C:\Users\admin\Desktop\shellbag_analyzer_cleaner\shellbag_analyzer_cleaner.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\shellbag_analyzer_cleaner\shellbag_analyzer_cleaner.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2192C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s DnscacheC:\Windows\System32\svchost.exe
services.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Host Process for Windows Services
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\kernel.appcore.dll
4528"C:\Users\admin\Desktop\shellbag_analyzer_cleaner\shellbag_analyzer_cleaner.exe" C:\Users\admin\Desktop\shellbag_analyzer_cleaner\shellbag_analyzer_cleaner.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Description:
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\shellbag_analyzer_cleaner\shellbag_analyzer_cleaner.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
Total events
3 103
Read events
3 078
Write events
25
Delete events
0

Modification events

(PID) Process:(3840) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(3840) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(3840) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(3840) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\shellbag_analyzer_cleaner.rar
(PID) Process:(3840) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3840) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3840) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3840) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3840) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface
Operation:writeName:ShowPassword
Value:
0
(PID) Process:(6212) shellbag_analyzer_cleaner.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\shellbag_analyzer_cleaner_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
Executable files
5
Suspicious files
2
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
3840WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb3840.18816\shellbag_analyzer_cleaner\IconExtractor.dllexecutable
MD5:640D8FFA779C6DD5252A262E440C66C0
SHA256:440912D85D2F98BB4F508AB82847067C18E1E15BE0D8ECDCFF0CC19327527FC2
3840WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb3840.18816\shellbag_analyzer_cleaner\GeoIP.datbinary
MD5:8EF41798DF108CE9BD41382C9721B1C9
SHA256:BC07FF22D4EE0B6FAFCC12482ECF2981C172A672194C647CEDF9B4D215AD9740
3840WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb3840.18816\shellbag_analyzer_cleaner\desktop.initext
MD5:15478B340A8362BB79FD2A6EA0DDE1A0
SHA256:27991CD3E2892702F610FD5262898F1C3DFA37E2A05082FD793BCE61E99E2D98
3840WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb3840.18816\shellbag_analyzer_cleaner\Mono.Cecil.dllexecutable
MD5:DE69BB29D6A9DFB615A90DF3580D63B1
SHA256:F66F97866433E688ACC3E4CD1E6EF14505F81DF6B26DD6215E376767F6F954BC
3840WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb3840.18816\shellbag_analyzer_cleaner\shellbag_analyzer_cleaner.exeexecutable
MD5:8BD95B793DDE780BF6C56496FF5A9F06
SHA256:D62E6A4F3C79C02B27F7F71CE90DA98366528209C4FC2FCFABB5BBA55CBBC3F3
6212shellbag_analyzer_cleaner.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\XClient.lnkbinary
MD5:0415F987B4DDD88C0647F1C375A60851
SHA256:9D684E977933334103797D686B1D90D537AB289E40C0144673107F6DD037E7BE
3840WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb3840.18816\shellbag_analyzer_cleaner\Guna.UI2.dllexecutable
MD5:BCC0FE2B28EDD2DA651388F84599059B
SHA256:C6264665A882E73EB2262A74FEA2C29B1921A9AF33180126325FB67A851310EF
6212shellbag_analyzer_cleaner.exeC:\Users\admin\AppData\Roaming\XClient.exeexecutable
MD5:8BD95B793DDE780BF6C56496FF5A9F06
SHA256:D62E6A4F3C79C02B27F7F71CE90DA98366528209C4FC2FCFABB5BBA55CBBC3F3
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
8
TCP/UDP connections
31
DNS requests
17
Threats
4

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6368
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
GET
200
23.32.238.112:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
1176
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
GET
200
23.215.121.133:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
396
SIHClient.exe
GET
200
23.215.121.133:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
396
SIHClient.exe
GET
200
23.215.121.133:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
6212
shellbag_analyzer_cleaner.exe
GET
200
208.95.112.1:80
http://ip-api.com/line/?fields=hosting
unknown
shared
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4712
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
23.32.238.112:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
23.215.121.133:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
5064
SearchApp.exe
2.19.80.89:443
www.bing.com
Akamai International B.V.
DE
whitelisted
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
4
System
192.168.100.255:138
whitelisted
1176
svchost.exe
40.126.32.68:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1176
svchost.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 40.127.240.158
whitelisted
crl.microsoft.com
  • 23.32.238.112
  • 23.32.238.107
whitelisted
google.com
  • 172.217.23.110
whitelisted
www.microsoft.com
  • 23.215.121.133
whitelisted
www.bing.com
  • 2.19.80.89
  • 2.19.80.27
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
login.live.com
  • 40.126.32.68
  • 20.190.160.22
  • 40.126.32.136
  • 40.126.32.138
  • 40.126.32.133
  • 40.126.32.72
  • 40.126.32.76
  • 20.190.160.17
whitelisted
go.microsoft.com
  • 23.218.210.69
whitelisted
arc.msn.com
  • 20.223.36.55
whitelisted
fd.api.iris.microsoft.com
  • 20.223.35.26
whitelisted

Threats

PID
Process
Class
Message
Device Retrieving External IP Address Detected
INFO [ANY.RUN] External IP Check (ip-api .com)
Device Retrieving External IP Address Detected
POLICY [ANY.RUN] External Hosting Lookup by ip-api
Device Retrieving External IP Address Detected
ET POLICY External IP Lookup ip-api.com
Device Retrieving External IP Address Detected
ET INFO External IP Lookup Domain in DNS Lookup (ip-api .com)
No debug info