File name:

YouAreAnIdiot.zip

Full analysis: https://app.any.run/tasks/9193287a-f812-4a71-802c-57c006d98d6a
Verdict: Malicious activity
Analysis date: June 02, 2025, 17:39:28
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
auto
generic
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=deflate
MD5:

F4A383E62A25D228307665ED7A1D4C49

SHA1:

086B1B9104EAD4C20A57BD9714F2AC4E1238FBEB

SHA256:

BE33925D8657D7335A65E04D1C5E77D2EBA561EBD68B37C93B81229253C616E5

SSDEEP:

6144:O7MYLvGo4O8Nq7G5iGoLGG5KIiCrCk1GbmJkRvcA:eMYqoD7GklX5Kymk1km5A

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • GENERIC has been found (auto)

      • WinRAR.exe (PID: 4892)
  • SUSPICIOUS

    • Executes application which crashes

      • YouAreAnIdiot.exe (PID: 5728)
      • YouAreAnIdiot.exe (PID: 7384)
      • YouAreAnIdiot.exe (PID: 5576)
      • YouAreAnIdiot.exe (PID: 2148)
      • YouAreAnIdiot.exe (PID: 7848)
      • YouAreAnIdiot.exe (PID: 3192)
      • YouAreAnIdiot.exe (PID: 7636)
      • YouAreAnIdiot.exe (PID: 4016)
      • YouAreAnIdiot.exe (PID: 7340)
      • YouAreAnIdiot.exe (PID: 7724)
      • YouAreAnIdiot.exe (PID: 896)
      • YouAreAnIdiot.exe (PID: 5556)
    • Reads security settings of Internet Explorer

      • WinRAR.exe (PID: 4892)
    • Starts CMD.EXE for commands execution

      • WinRAR.exe (PID: 4892)
    • Executing commands from a ".bat" file

      • WinRAR.exe (PID: 4892)
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 4892)
    • Checks supported languages

      • YouAreAnIdiot.exe (PID: 5728)
      • YouAreAnIdiot.exe (PID: 7384)
      • YouAreAnIdiot.exe (PID: 5576)
      • YouAreAnIdiot.exe (PID: 7636)
      • MpCmdRun.exe (PID: 7896)
      • YouAreAnIdiot.exe (PID: 7848)
      • YouAreAnIdiot.exe (PID: 2148)
    • Reads the computer name

      • YouAreAnIdiot.exe (PID: 5728)
      • YouAreAnIdiot.exe (PID: 7384)
      • YouAreAnIdiot.exe (PID: 5576)
      • YouAreAnIdiot.exe (PID: 7636)
      • YouAreAnIdiot.exe (PID: 2148)
      • YouAreAnIdiot.exe (PID: 7848)
      • MpCmdRun.exe (PID: 7896)
    • Reads the machine GUID from the registry

      • YouAreAnIdiot.exe (PID: 5728)
      • YouAreAnIdiot.exe (PID: 7384)
      • YouAreAnIdiot.exe (PID: 5576)
      • YouAreAnIdiot.exe (PID: 7636)
      • YouAreAnIdiot.exe (PID: 2148)
      • YouAreAnIdiot.exe (PID: 7848)
    • Creates files or folders in the user directory

      • WerFault.exe (PID: 5164)
      • WerFault.exe (PID: 7908)
      • WerFault.exe (PID: 7892)
      • WerFault.exe (PID: 7452)
      • WerFault.exe (PID: 2432)
    • Create files in a temporary directory

      • MpCmdRun.exe (PID: 7896)
    • Manual execution by a user

      • YouAreAnIdiot.exe (PID: 7340)
      • YouAreAnIdiot.exe (PID: 7724)
      • YouAreAnIdiot.exe (PID: 4016)
      • YouAreAnIdiot.exe (PID: 896)
      • YouAreAnIdiot.exe (PID: 5556)
      • YouAreAnIdiot.exe (PID: 3192)
    • Reads the software policy settings

      • slui.exe (PID: 7316)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 788
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2021:07:30 22:55:24
ZipCRC: 0x0e322587
ZipCompressedSize: 6047
ZipUncompressedSize: 17408
ZipFileName: AxInterop.ShockwaveFlashObjects.dll
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
175
Monitored processes
32
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start #GENERIC winrar.exe sppextcomobj.exe no specs slui.exe youareanidiot.exe werfault.exe no specs youareanidiot.exe werfault.exe no specs youareanidiot.exe werfault.exe no specs youareanidiot.exe werfault.exe no specs youareanidiot.exe werfault.exe no specs cmd.exe no specs conhost.exe no specs mpcmdrun.exe no specs youareanidiot.exe werfault.exe no specs slui.exe youareanidiot.exe werfault.exe no specs youareanidiot.exe werfault.exe no specs youareanidiot.exe werfault.exe no specs openwith.exe no specs youareanidiot.exe werfault.exe no specs youareanidiot.exe werfault.exe no specs youareanidiot.exe werfault.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
896"C:\Users\admin\Desktop\YouAreAnIdiot.exe" C:\Users\admin\Desktop\YouAreAnIdiot.exe
explorer.exe
User:
admin
Company:
Microsoft
Integrity Level:
HIGH
Description:
Microsoft Word 2010
Exit code:
3762504530
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\youareanidiot.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
1760C:\WINDOWS\SysWOW64\WerFault.exe -u -p 7340 -s 1500C:\Windows\SysWOW64\WerFault.exeYouAreAnIdiot.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\combase.dll
2108C:\WINDOWS\SysWOW64\WerFault.exe -u -p 4016 -s 1496C:\Windows\SysWOW64\WerFault.exeYouAreAnIdiot.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\combase.dll
2148"C:\Users\admin\AppData\Local\Temp\Rar$EXa4892.31732\YouAreAnIdiot.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa4892.31732\YouAreAnIdiot.exe
WinRAR.exe
User:
admin
Company:
Microsoft
Integrity Level:
MEDIUM
Description:
Microsoft Word 2010
Exit code:
3762504530
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa4892.31732\youareanidiot.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
2284C:\WINDOWS\SysWOW64\WerFault.exe -u -p 5576 -s 1524C:\Windows\SysWOW64\WerFault.exeYouAreAnIdiot.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\combase.dll
2432C:\WINDOWS\SysWOW64\WerFault.exe -u -p 7848 -s 1528C:\Windows\SysWOW64\WerFault.exeYouAreAnIdiot.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\combase.dll
3192"C:\Users\admin\Desktop\YouAreAnIdiot.exe" C:\Users\admin\Desktop\YouAreAnIdiot.exe
explorer.exe
User:
admin
Company:
Microsoft
Integrity Level:
MEDIUM
Description:
Microsoft Word 2010
Exit code:
3762504530
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\youareanidiot.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
3872C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
4016"C:\Users\admin\Desktop\YouAreAnIdiot.exe" C:\Users\admin\Desktop\YouAreAnIdiot.exe
explorer.exe
User:
admin
Company:
Microsoft
Integrity Level:
MEDIUM
Description:
Microsoft Word 2010
Exit code:
3762504530
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\youareanidiot.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\advapi32.dll
4892"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\YouAreAnIdiot.zipC:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
Total events
26 502
Read events
26 463
Write events
30
Delete events
9

Modification events

(PID) Process:(4892) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(4892) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(4892) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(4892) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\YouAreAnIdiot.zip
(PID) Process:(4892) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(4892) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(4892) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(4892) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(4892) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Viewer
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF9C0000009C0000005C04000085020000
(PID) Process:(4892) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\VirusScan
Operation:writeName:DefScanner
Value:
Windows Defender
Executable files
25
Suspicious files
0
Text files
26
Unknown types
12

Dropped files

PID
Process
Filename
Type
5164WerFault.exeC:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_YouAreAnIdiot.ex_9b3d17d4ec13b96ffaebee7e96e914a172a86ce8_74378ff6_5f8fcc52-b36b-44eb-93b3-df703ad3529c\Report.wer
MD5:
SHA256:
5164WerFault.exeC:\Users\admin\AppData\Local\CrashDumps\YouAreAnIdiot.exe.5728.dmp
MD5:
SHA256:
7908WerFault.exeC:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_YouAreAnIdiot.ex_9b3d17d4ec13b96ffaebee7e96e914a172a86ce8_74378ff6_729a0877-41f7-4ef1-89ac-0d8ec4b9719f\Report.wer
MD5:
SHA256:
7908WerFault.exeC:\Users\admin\AppData\Local\CrashDumps\YouAreAnIdiot.exe.7384.dmp
MD5:
SHA256:
2284WerFault.exeC:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_YouAreAnIdiot.ex_9b3d17d4ec13b96ffaebee7e96e914a172a86ce8_74378ff6_d66db1e8-5b61-4831-947c-fd47c7de416e\Report.wer
MD5:
SHA256:
2284WerFault.exeC:\Users\admin\AppData\Local\CrashDumps\YouAreAnIdiot.exe.5576.dmp
MD5:
SHA256:
5164WerFault.exeC:\ProgramData\Microsoft\Windows\WER\Temp\WER18FE.tmp.dmpdmp
MD5:97D61CA13CEF13A51BD7C35E1E2DFC45
SHA256:6B90F631E0DC277DD545D4DAA23C1EC218BBDF9A21F9B601820F5F6F5A52CE1E
7908WerFault.exeC:\ProgramData\Microsoft\Windows\WER\Temp\WER4CA1.tmp.dmpdmp
MD5:1FDA09676B6BA7891711CD7F6E707F6D
SHA256:C0D90AAAD65259859B06BFAFCF688CCF7F713C5EB46E813FA1FB22375BACCE69
5164WerFault.exeC:\ProgramData\Microsoft\Windows\WER\Temp\WER1A87.tmp.xmlxml
MD5:046CEF2A8019DD205B0AC10D7BF14941
SHA256:AFBDDB6166938125B18E71E04D65A2CC4617CB0E4F79F30D1D2B7E2E6D4EF8FE
4892WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa4892.30243\Interop.ShockwaveFlashObjects.dllexecutable
MD5:E869D1D4545C212D9068A090A370DED3
SHA256:63AF704211A03F6FF6530EBFCA095B6C97636AB66E5A6DE80D167B19C3C30C66
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
30
DNS requests
12
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5496
MoUsoCoreWorker.exe
GET
200
2.16.253.202:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
23.48.23.143:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
6544
svchost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6132
SIHClient.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
6132
SIHClient.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
6544
svchost.exe
40.126.31.0:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
4.231.128.59:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5496
MoUsoCoreWorker.exe
23.48.23.143:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
472
svchost.exe
4.231.128.59:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5496
MoUsoCoreWorker.exe
2.16.253.202:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
6544
svchost.exe
20.190.159.130:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
6544
svchost.exe
184.30.131.245:80
ocsp.digicert.com
AKAMAI-AS
US
whitelisted
472
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.185.238
whitelisted
crl.microsoft.com
  • 23.48.23.143
  • 23.48.23.156
whitelisted
www.microsoft.com
  • 2.16.253.202
  • 2.23.246.101
whitelisted
ocsp.digicert.com
  • 184.30.131.245
whitelisted
settings-win.data.microsoft.com
  • 51.124.78.146
whitelisted
client.wns.windows.com
  • 172.211.123.250
whitelisted
slscr.update.microsoft.com
  • 4.175.87.197
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 13.95.31.18
whitelisted
activation-v2.sls.microsoft.com
  • 40.91.76.224
whitelisted

Threats

No threats detected
No debug info