File name:

Virus.Win32.HLLP.Shodi.a-00bb742477598c60267cbe3826ab1b64c52d30d34be270590010a75fe11efec8.7z

Full analysis: https://app.any.run/tasks/103fa5dd-69c5-489d-93b7-84bd408ceed5
Verdict: Malicious activity
Analysis date: March 06, 2025, 17:22:53
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
arch-exec
Indicators:
MIME: application/x-7z-compressed
File info: 7-zip archive data, version 0.4
MD5:

75CD64DC85C701C8CC1EB8E28D074BE7

SHA1:

9744E0489EFD996C6015F27696E4FE0A56818399

SHA256:

BE0D0664FC9EEFFB7F2DE7B93DE7575F333600F195CBE5C8E8169C5371E28367

SSDEEP:

24576:PNmrZ3CJHkneLQCg5WDZWsA3jCfVdKUVRa+rnmVfcn7vfdEq2ClsnW694M1J31Hm:PQrhcHkneLQCg5WNWsAzCfVdKUVRa+rj

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Generic archive extractor

      • WinRAR.exe (PID: 2848)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • Virus.Win32.HLLP.Shodi.a-00bb742477598c60267cbe3826ab1b64c52d30d34be270590010a75fe11efec8.exe (PID: 1028)
      • setup.exe (PID: 3520)
      • setup.usa (PID: 2544)
      • setup.exe (PID: 2992)
      • setup.usa (PID: 2976)
    • Starts application with an unusual extension

      • setup.exe (PID: 3520)
      • setup.exe (PID: 2992)
    • Executable content was dropped or overwritten

      • setup.exe (PID: 3520)
      • Virus.Win32.HLLP.Shodi.a-00bb742477598c60267cbe3826ab1b64c52d30d34be270590010a75fe11efec8.exe (PID: 1028)
      • setup.usa (PID: 2544)
      • setup.exe (PID: 2992)
      • setup.usa (PID: 2976)
    • Reads settings of System Certificates

      • setup.usa (PID: 2544)
    • Reads security settings of Internet Explorer

      • setup.usa (PID: 2544)
      • setup.usa (PID: 2976)
    • Reads the Internet Settings

      • setup.usa (PID: 2544)
    • Searches for installed software

      • setup.usa (PID: 2544)
  • INFO

    • Checks supported languages

      • Virus.Win32.HLLP.Shodi.a-00bb742477598c60267cbe3826ab1b64c52d30d34be270590010a75fe11efec8.exe (PID: 1028)
      • setup.exe (PID: 3520)
      • setup.usa (PID: 2544)
      • setup.usa (PID: 2976)
    • Manual execution by a user

      • Virus.Win32.HLLP.Shodi.a-00bb742477598c60267cbe3826ab1b64c52d30d34be270590010a75fe11efec8.exe (PID: 1028)
      • setup.exe (PID: 4004)
      • setup.exe (PID: 3520)
      • explorer.exe (PID: 2844)
      • setup.exe (PID: 3212)
      • setup.exe (PID: 2992)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2848)
    • Reads Microsoft Office registry keys

      • setup.usa (PID: 2544)
      • setup.usa (PID: 2976)
    • Reads the software policy settings

      • setup.usa (PID: 2544)
    • Reads the machine GUID from the registry

      • setup.usa (PID: 2544)
      • setup.usa (PID: 2976)
    • Reads the computer name

      • setup.usa (PID: 2544)
    • The sample compiled with english language support

      • setup.usa (PID: 2544)
      • setup.usa (PID: 2976)
    • Create files in a temporary directory

      • setup.usa (PID: 2544)
      • setup.usa (PID: 2976)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.7z | 7-Zip compressed archive (v0.4) (57.1)
.7z | 7-Zip compressed archive (gen) (42.8)

EXIF

ZIP

FileVersion: 7z v0.04
ModifyDate: 2021:10:26 12:12:32+00:00
ArchivedFileName: Virus.Win32.HLLP.Shodi.a-00bb742477598c60267cbe3826ab1b64c52d30d34be270590010a75fe11efec8.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
59
Monitored processes
9
Malicious processes
3
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe virus.win32.hllp.shodi.a-00bb742477598c60267cbe3826ab1b64c52d30d34be270590010a75fe11efec8.exe explorer.exe no specs setup.exe no specs setup.exe setup.usa setup.exe no specs setup.exe setup.usa

Process information

PID
CMD
Path
Indicators
Parent process
1028"C:\Users\admin\Desktop\Virus.Win32.HLLP.Shodi.a-00bb742477598c60267cbe3826ab1b64c52d30d34be270590010a75fe11efec8.exe" C:\Users\admin\Desktop\Virus.Win32.HLLP.Shodi.a-00bb742477598c60267cbe3826ab1b64c52d30d34be270590010a75fe11efec8.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Modules
Images
c:\users\admin\desktop\virus.win32.hllp.shodi.a-00bb742477598c60267cbe3826ab1b64c52d30d34be270590010a75fe11efec8.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imm32.dll
2544"C:\MSOCache\All Users\{90140000-003D-0000-0000-0000000FF1CE}-C\setup.usa"C:\MSOCache\All Users\{90140000-003D-0000-0000-0000000FF1CE}-C\setup.usa
setup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Setup Bootstrapper
Exit code:
1602
Version:
14.0.4755.1000
Modules
Images
c:\msocache\all users\{90140000-003d-0000-0000-0000000ff1ce}-c\setup.usa
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
2844"C:\Windows\explorer.exe" C:\Windows\explorer.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2848"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\Desktop\Virus.Win32.HLLP.Shodi.a-00bb742477598c60267cbe3826ab1b64c52d30d34be270590010a75fe11efec8.7zC:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2976"C:\MSOCache\All Users\{90140000-003D-0000-0000-0000000FF1CE}-C\setup.usa"C:\MSOCache\All Users\{90140000-003D-0000-0000-0000000FF1CE}-C\setup.usa
setup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Setup Bootstrapper
Version:
14.0.4755.1000
Modules
Images
c:\msocache\all users\{90140000-003d-0000-0000-0000000ff1ce}-c\setup.usa
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
2992"C:\MSOCache\All Users\{90140000-003D-0000-0000-0000000FF1CE}-C\setup.exe" C:\MSOCache\All Users\{90140000-003D-0000-0000-0000000FF1CE}-C\setup.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\msocache\all users\{90140000-003d-0000-0000-0000000ff1ce}-c\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\apphelp.dll
3212"C:\MSOCache\All Users\{90140000-003D-0000-0000-0000000FF1CE}-C\setup.exe" C:\MSOCache\All Users\{90140000-003D-0000-0000-0000000FF1CE}-C\setup.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\msocache\all users\{90140000-003d-0000-0000-0000000ff1ce}-c\setup.exe
c:\windows\system32\ntdll.dll
3520"C:\MSOCache\All Users\{90140000-003D-0000-0000-0000000FF1CE}-C\setup.exe" C:\MSOCache\All Users\{90140000-003D-0000-0000-0000000FF1CE}-C\setup.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\msocache\all users\{90140000-003d-0000-0000-0000000ff1ce}-c\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\apphelp.dll
4004"C:\MSOCache\All Users\{90140000-003D-0000-0000-0000000FF1CE}-C\setup.exe" C:\MSOCache\All Users\{90140000-003D-0000-0000-0000000FF1CE}-C\setup.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\msocache\all users\{90140000-003d-0000-0000-0000000ff1ce}-c\setup.exe
c:\windows\system32\ntdll.dll
Total events
19 883
Read events
19 808
Write events
75
Delete events
0

Modification events

(PID) Process:(2848) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2848) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2848) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2848) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(2848) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(2848) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(2848) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\Virus.Win32.HLLP.Shodi.a-00bb742477598c60267cbe3826ab1b64c52d30d34be270590010a75fe11efec8.7z
(PID) Process:(2848) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2848) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2848) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
Executable files
60
Suspicious files
2
Text files
4
Unknown types
0

Dropped files

PID
Process
Filename
Type
1028Virus.Win32.HLLP.Shodi.a-00bb742477598c60267cbe3826ab1b64c52d30d34be270590010a75fe11efec8.exeC:\MSOCache\All Users\{90140000-006E-0407-0000-0000000FF1CE}-C\dwtrig20.usaexecutable
MD5:C87E561258F2F8650CEF999BF643A731
SHA256:A1DFA6639BEF3CB4E41175C43730D46A51393942EAD826337CA9541AC210C67B
1028Virus.Win32.HLLP.Shodi.a-00bb742477598c60267cbe3826ab1b64c52d30d34be270590010a75fe11efec8.exeC:\Users\admin\Desktop\Virus.Win32.HLLP.Shodi.a-00bb742477598c60267cbe3826ab1b64c52d30d34be270590010a75fe11efec8.usaexecutable
MD5:110B3C0E76CBD41C7B590C951B8E97F4
SHA256:E4362DA23F3381874718A33A263A2592C6BDE8388E7E3BBF0D6A2D8C3268D9FE
1028Virus.Win32.HLLP.Shodi.a-00bb742477598c60267cbe3826ab1b64c52d30d34be270590010a75fe11efec8.exeC:\MSOCache\All Users\{90140000-003D-0000-0000-0000000FF1CE}-C\setup.usaexecutable
MD5:4D92F518527353C0DB88A70FDDCFD390
SHA256:97E6F3FC1A9163F10B6502509D55BF75EE893967FB35F318954797E8AB4D4D9C
1028Virus.Win32.HLLP.Shodi.a-00bb742477598c60267cbe3826ab1b64c52d30d34be270590010a75fe11efec8.exeC:\MSOCache\All Users\{90140000-003D-0000-0000-0000000FF1CE}-C\ose.exeexecutable
MD5:1F0BA52E19ED456D49F8451E4DD24126
SHA256:8EA87B56B044F7D22751B0C42291897B1F5FFC813E1CDC2A6211214F4F25ECA3
1028Virus.Win32.HLLP.Shodi.a-00bb742477598c60267cbe3826ab1b64c52d30d34be270590010a75fe11efec8.exeC:\MSOCache\All Users\{90140000-006E-040C-0000-0000000FF1CE}-C\DW20.usaexecutable
MD5:A41E524F8D45F0074FD07805FF0C9B12
SHA256:082329648337E5BA7377FED9D8A178809F37EECB8D795B93CCA4EC07D8640FF7
2848WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb2848.9121\Virus.Win32.HLLP.Shodi.a-00bb742477598c60267cbe3826ab1b64c52d30d34be270590010a75fe11efec8.exeexecutable
MD5:1C9DE5E74B9CCECE9B9D394E1E6245B1
SHA256:00BB742477598C60267CBE3826AB1B64C52D30D34BE270590010A75FE11EFEC8
1028Virus.Win32.HLLP.Shodi.a-00bb742477598c60267cbe3826ab1b64c52d30d34be270590010a75fe11efec8.exeC:\MSOCache\All Users\{90140000-003D-0000-0000-0000000FF1CE}-C\ose.usaexecutable
MD5:9D10F99A6712E28F8ACD5641E3A7EA6B
SHA256:70964A0ED9011EA94044E15FA77EDD9CF535CC79ED8E03A3721FF007E69595CC
1028Virus.Win32.HLLP.Shodi.a-00bb742477598c60267cbe3826ab1b64c52d30d34be270590010a75fe11efec8.exeC:\MSOCache\All Users\{90140000-003D-0000-0000-0000000FF1CE}-C\setup.exeexecutable
MD5:C1B5129084AFDD963CCB448841EC3074
SHA256:5291DACC162904204FB313E9CF97C1923A2BDACD9FDB1E23738231AF383B452A
1028Virus.Win32.HLLP.Shodi.a-00bb742477598c60267cbe3826ab1b64c52d30d34be270590010a75fe11efec8.exeC:\MSOCache\All Users\{90140000-006E-0407-0000-0000000FF1CE}-C\DW20.usaexecutable
MD5:A41E524F8D45F0074FD07805FF0C9B12
SHA256:082329648337E5BA7377FED9D8A178809F37EECB8D795B93CCA4EC07D8640FF7
1028Virus.Win32.HLLP.Shodi.a-00bb742477598c60267cbe3826ab1b64c52d30d34be270590010a75fe11efec8.exeC:\MSOCache\All Users\{90140000-006E-0407-0000-0000000FF1CE}-C\dwtrig20.exeexecutable
MD5:1F4B49D2878823F1586C081D0BAE1F0F
SHA256:D122D1E58010749A58F0E0BC0BBC1B39725B1FF21C017D100F845407EE634FAB
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
5
DNS requests
1
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
whitelisted
4
System
192.168.100.255:138
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.185.78
whitelisted

Threats

No threats detected
No debug info