| File name: | maksim.rar |
| Full analysis: | https://app.any.run/tasks/9b5189b7-97f7-4e89-9784-e5aa0ccdaf3e |
| Verdict: | Malicious activity |
| Analysis date: | July 24, 2024, 09:09:35 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Indicators: | |
| MIME: | application/x-rar |
| File info: | RAR archive data, v5 |
| MD5: | DA2D42D05FB1C41F66301E9E75DA03F2 |
| SHA1: | 48BCAFBD5664CEE47D8B9B69F108BEF6C654F31B |
| SHA256: | BA4F98080FCDFDC17B5C3063B2878CA8BFB51DFEC83FF13ECC8C75A498992BA3 |
| SSDEEP: | 98304:QXFjELUDrgH4Je8otRtEVgNl5v7Rboh6/q3goNeRdwgT8kkPmSwzj0uv1iVeIi/5:8XvtInl1x7R08mFEbiW7 |
| .rar | | | RAR compressed archive (v5.0) (61.5) |
|---|---|---|
| .rar | | | RAR compressed archive (gen) (38.4) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1108 | "C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\maksim.rar | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| 2588 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | run.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) | |||||||||||||||
| 2884 | "C:\WINDOWS\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\TextInputHost.exe" -ServerName:InputApp.AppXjd5de1g66v206tj52m9d0dtpppx4cgpn.mca | C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\TextInputHost.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Version: 123.26505.0.0 Modules
| |||||||||||||||
| 4656 | C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -Embedding | C:\Windows\System32\rundll32.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows host process (Rundll32) Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) | |||||||||||||||
| 5672 | "./HMC 1.8.0.exe" | C:\Users\admin\Desktop\maksim\HMC 1.8.0.exe | — | run.exe | |||||||||||
User: admin Integrity Level: HIGH Description: Hackus Mail Checker Reforged Exit code: 0 Version: 1.0.0.0 Modules
| |||||||||||||||
| 6444 | "C:\Users\admin\Desktop\maksim\run.exe" | C:\Users\admin\Desktop\maksim\run.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 6820 | C:\WINDOWS\System32\slui.exe -Embedding | C:\Windows\System32\slui.exe | svchost.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Activation Client Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| (PID) Process: | (1108) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\GoogleChromeEnterpriseBundle64.zip | |||
| (PID) Process: | (1108) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\maksim.rar | |||
| (PID) Process: | (1108) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (1108) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (1108) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (1108) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1108 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa1108.1198\maksim\.hackus\Configuration.cfg | — | |
MD5:— | SHA256:— | |||
| 1108 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa1108.1198\maksim\.hackus\Settings.cfg | binary | |
MD5:A1C88BF2D11BC8C5906ECBC7DDF81611 | SHA256:BAEE25A379750D0C4ED9CE11B26879E32E5285E93ABC7C87AE3BE97F722CC55C | |||
| 1108 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa1108.1198\maksim\Results\25.12.2022 14.20 — 84K_PRIVATE_UKRAINE\Error.txt | text | |
MD5:66C9DC9F8770B5AF3A297E869181F59B | SHA256:A8CC9D5A2F290FCE313F9A011AE9A3708F066D016117ECCE293F64826ABC43D9 | |||
| 1108 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa1108.1198\maksim\Results\25.12.2022 14.18 — 16.7K_PRIVATE_MYR_Gaming Combo\Blocked.txt | text | |
MD5:5633F645C7D8E74D6EA013827317A4D0 | SHA256:4FCCF6C61B2D2FF40AE9C9DB171616268A8060125F78564DDC78552B80302395 | |||
| 1108 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa1108.1198\maksim\HackusErrors.txt | text | |
MD5:8D6DC990844364AB08EE0D86026C9867 | SHA256:D5AC8478BAFF3472658A99AD519BC1B143772F0DC9180B83465E3524FC909F6C | |||
| 1108 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa1108.1198\maksim\Results\25.12.2022 14.20 — 84K_PRIVATE_UKRAINE\Bad.txt | text | |
MD5:32EB8D013392AB7AA3DE0848FBB3AD6E | SHA256:025553D46DE9A26AE035C00F148F58CC9B0B91D73E1E92AF848E075B9DD2DBB1 | |||
| 1108 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa1108.1198\maksim\Results\25.12.2022 14.18 — 16.7K_PRIVATE_MYR_Gaming Combo\Bad.txt | text | |
MD5:474334B6B9697C515DF8C2107B23EF34 | SHA256:B08A9AD3DF80B7A80328F15DD39B63BD3B1CD61C342ECA40AE93C9D70177B27B | |||
| 1108 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa1108.1198\maksim\Results\25.12.2022 14.18 — 16.7K_PRIVATE_MYR_Gaming Combo\HostNotFound.txt | text | |
MD5:B642524CCB32E808925C5BCD2FF9EE53 | SHA256:2349CE782A3E2CFD3A35894F1ABFC22DC692C590CF88E9908706E24E936A466B | |||
| 1108 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa1108.1198\maksim\Results\25.12.2022 14.18 — 16.7K_PRIVATE_MYR_Gaming Combo\Error.txt | text | |
MD5:B87F2DBE21CC82273A98B1EF40624830 | SHA256:C59B38C24952795CAE447EE6AA2C76A549D2112E2F868C49144D7177F0752B23 | |||
| 1108 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa1108.1198\maksim\Results\25.12.2022 14.20 — 84K_PRIVATE_UKRAINE\Blocked.txt | text | |
MD5:F1AC3B553B3857DDF80775AE1143F02E | SHA256:0E290710FAD6EDF918F77921086B8359E21EC796262FE72D44738D9813DC409B | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
916 | backgroundTaskHost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D | unknown | — | — | whitelisted |
3148 | OfficeClickToRun.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D | unknown | — | — | whitelisted |
1468 | backgroundTaskHost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
6012 | MoUsoCoreWorker.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
3044 | RUXIMICS.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
3360 | svchost.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
— | — | 92.123.104.41:443 | — | Akamai International B.V. | DE | unknown |
4204 | svchost.exe | 4.209.32.67:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | US | unknown |
3952 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
784 | slui.exe | 40.91.76.224:443 | activation-v2.sls.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
6012 | MoUsoCoreWorker.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
activation-v2.sls.microsoft.com |
| whitelisted |
login.live.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
arc.msn.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
go.microsoft.com |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |
fd.api.iris.microsoft.com |
| whitelisted |