File name:

创世v1.rar

Full analysis: https://app.any.run/tasks/1256a774-9e1f-44ee-a544-19f99392f59f
Verdict: Malicious activity
Analysis date: January 20, 2024, 14:55:04
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

881E9B20D5E1EADDB3FCFBA5DC001F9A

SHA1:

B29D4A1A388C34D95797B1F59D7D5DCBD8DFCE8C

SHA256:

BCCD5E64BB3AB2794638CD5BEF2B67156FAAA56B3EC169E0FB51E73BA9DCDF3E

SSDEEP:

98304:XZMgnUl83Vf6/MQyC+ILrDPbfurQwgUo4AvRFdquyuLtdyLDQ8VQl3PDBf7JKnM8:Hi+/W+Oen

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 2044)
      • 创世v1.exe (PID: 316)
      • server.exe (PID: 2348)
    • Starts CMD.EXE for self-deleting

      • server.exe (PID: 2348)
  • SUSPICIOUS

    • Reads the Internet Settings

      • 创世v1.exe (PID: 316)
      • server.exe (PID: 2348)
    • Executable content was dropped or overwritten

      • 创世v1.exe (PID: 316)
      • server.exe (PID: 2348)
      • rundll32.exe (PID: 2500)
    • Starts CMD.EXE for commands execution

      • server.exe (PID: 2348)
    • Runs PING.EXE to delay simulation

      • cmd.exe (PID: 1892)
  • INFO

    • Reads the machine GUID from the registry

      • 创世v1.exe (PID: 316)
    • Checks supported languages

      • 创世v1.exe (PID: 316)
      • server.exe (PID: 2348)
      • 附_文件捆绑器.exe (PID: 2060)
      • 附_文件捆绑器.exe (PID: 1572)
    • Manual execution by a user

      • 创世v1.exe (PID: 316)
      • server.exe (PID: 2348)
      • 附_文件捆绑器.exe (PID: 1572)
      • taskmgr.exe (PID: 2888)
      • 附_文件捆绑器.exe (PID: 2060)
    • Reads the computer name

      • 创世v1.exe (PID: 316)
      • server.exe (PID: 2348)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2044)
    • Create files in a temporary directory

      • server.exe (PID: 2348)
    • Drops the executable file immediately after the start

      • rundll32.exe (PID: 2500)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
56
Monitored processes
9
Malicious processes
0
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe 创世v1.exe server.exe cmd.exe no specs ping.exe no specs 附_文件捆绑器.exe no specs 附_文件捆绑器.exe taskmgr.exe no specs rundll32.exe

Process information

PID
CMD
Path
Indicators
Parent process
316"C:\Users\admin\Desktop\创世v1.exe" C:\Users\admin\Desktop\创世v1.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Gh0st Microsoft 基础类应用程序
Exit code:
0
Version:
1, 0, 0, 1
Modules
Images
c:\users\admin\desktop\创世v1.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\avifil32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1572"C:\Users\admin\Desktop\附_文件捆绑器\附_文件捆绑器.exe" C:\Users\admin\Desktop\附_文件捆绑器\附_文件捆绑器.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\附_文件捆绑器\附_文件捆绑器.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imm32.dll
1892"C:\Windows\System32\cmd.exe" /c ping 127.0.0.1 -n 1 && del /f/q "C:\Users\admin\Desktop\server.exe"C:\Windows\System32\cmd.exeserver.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2044"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\创世v1.rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2060"C:\Users\admin\Desktop\附_文件捆绑器\附_文件捆绑器.exe" C:\Users\admin\Desktop\附_文件捆绑器\附_文件捆绑器.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\desktop\附_文件捆绑器\附_文件捆绑器.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imm32.dll
2348"C:\Users\admin\Desktop\server.exe" C:\Users\admin\Desktop\server.exe
explorer.exe
User:
admin
Company:
SARL CRL
Integrity Level:
HIGH
Description:
Application MFC LoadDll
Exit code:
0
Version:
1, 0, 0, 0
Modules
Images
c:\users\admin\desktop\server.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2440ping 127.0.0.1 -n 1 C:\Windows\System32\PING.EXEcmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
TCP/IP Ping Command
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ping.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
2500Rundll32 "c:\users\admin\appdata\local\temp\947359.dll",UninstallC:\Windows\System32\rundll32.exe
SRDSL.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
2888"C:\Windows\system32\taskmgr.exe" /4C:\Windows\System32\taskmgr.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Task Manager
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskmgr.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
Total events
2 624
Read events
2 566
Write events
54
Delete events
4

Modification events

(PID) Process:(2044) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2044) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(2044) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(2044) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(2044) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(2044) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2044) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2044) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2044) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(316) 创世v1.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
Operation:writeName:NodeSlots
Value:
020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202
Executable files
6
Suspicious files
0
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
2044WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2044.282\创世v1\Install.datexecutable
MD5:58BA5BFC429392E9C92C3382D88696FC
SHA256:9884F13B73B7FCA9A013A940254F6764AE5366083AC669BD9F96037CDE99646C
316创世v1.exeC:\Users\admin\Desktop\server.exeexecutable
MD5:9757C5EB2FF2CDEF69D27FA94D6514D5
SHA256:CD72310E6FA0933BEB0249B40429CB30FFD2227014573E782F035332A2A8BF53
2500rundll32.exeC:\Windows\System32\1021718.bakexecutable
MD5:452848D5DD74D6D6A0BDD61C69CB5620
SHA256:010F61FABCC2671FCAE82FE7895B77B634D6D27DAB6BC15524336D3803408B9B
2348server.exeC:\Users\admin\AppData\Local\Temp\947359.dllexecutable
MD5:452848D5DD74D6D6A0BDD61C69CB5620
SHA256:010F61FABCC2671FCAE82FE7895B77B634D6D27DAB6BC15524336D3803408B9B
2044WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2044.282\创世v1\创世v1.exeexecutable
MD5:FBD6E03F388C9834217B598119DD652D
SHA256:03EA0C4C9D22E8DFA135F7550BBCB8B0ED8D84E8A154100D64F211BAA6FF5594
2044WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2044.282\创世v1\创世v1.iniini
MD5:78CDBFE45999972A304C7C5964BC42DF
SHA256:5CCF7E78ABEA94EB1B5D828EB4552169703E280F8011EC66649BC093E01FE81A
2044WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2044.282\创世v1\附_文件捆绑器\附_文件捆绑器.exeexecutable
MD5:1D803902994F6B7FF7950AF00B5F421B
SHA256:C632F01C8DB75F2B86FC6AD079361B735349BA80C69C3948CFCFBAFFA54FDBB3
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown

DNS requests

No data

Threats

No threats detected
Process
Message
创世v1.exe
--0--
创世v1.exe
CIOCPServer=01F6D6C0
创世v1.exe
LC 1652 AllocateContext
创世v1.exe
LC 1836 OnClientReading
创世v1.exe
EC 1652 AllocateContext
创世v1.exe
LC 1652 OnAccept
创世v1.exe
EC 1836 OnClientReading
创世v1.exe
EC 1652 OnAccept
创世v1.exe
EC 784 Send
创世v1.exe
·¢ËÍÍê³É Çå¿ÕBuffer