File name: | R2R-WAIFU.v1.1.0-R2R.rar |
Full analysis: | https://app.any.run/tasks/5077e476-ec7f-431b-bf0f-635a6c94569c |
Verdict: | Malicious activity |
Analysis date: | April 21, 2021, 09:31:42 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | application/x-rar |
File info: | RAR archive data, v5 |
MD5: | 5669542AE4FE20CDD5793EF59BC9B6ED |
SHA1: | 8AB824DB5277177621989F0964E8BBBBDE027735 |
SHA256: | BEA5CBACD0AA060F634AC1BCD3D7405511F6BB1FB2003B269CA89A63FC5F4AB7 |
SSDEEP: | 24576:1m/xa6JFNDNRXQofyVl3eLOoVT5L05Is7YOCbVP3x652vgx:1Gaav6LO6o9h0WOCB3xi2Ix |
.rar | | | RAR compressed archive (v5.0) (61.5) |
---|---|---|
.rar | | | RAR compressed archive (gen) (38.4) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
2020 | "C:\Users\admin\Desktop\TEAM.R2R.R2R-WAIFU.v1.1.0-R2R\Setup R2R-WAIFU v1.1.0.exe" | C:\Users\admin\Desktop\TEAM.R2R.R2R-WAIFU.v1.1.0-R2R\Setup R2R-WAIFU v1.1.0.exe | explorer.exe | ||||||||||||
User: admin Company: TEAM R2R Integrity Level: MEDIUM Description: R2R-WAIFU Setup Exit code: 0 Version: 1.1.0 Modules
| |||||||||||||||
2612 | "C:\Program Files\WinRAR\WinRAR.exe" x -iext -ow -ver -- "C:\Users\admin\Desktop\TEAM.R2R.R2R-WAIFU.v1.1.0-R2R\r2r-8777.rar" C:\Users\admin\Desktop\TEAM.R2R.R2R-WAIFU.v1.1.0-R2R\ | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.60.0 Modules
| |||||||||||||||
2728 | "C:\Users\admin\AppData\Local\Temp\is-L2MVF.tmp\Setup R2R-WAIFU v1.1.0.tmp" /SL5="$301E0,552632,237056,C:\Users\admin\Desktop\TEAM.R2R.R2R-WAIFU.v1.1.0-R2R\Setup R2R-WAIFU v1.1.0.exe" /SPAWNWND=$20212 /NOTIFYWND=$50184 | C:\Users\admin\AppData\Local\Temp\is-L2MVF.tmp\Setup R2R-WAIFU v1.1.0.tmp | Setup R2R-WAIFU v1.1.0.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: Setup/Uninstall Exit code: 3221225547 Version: 51.1052.0.0 Modules
| |||||||||||||||
2844 | "C:\Users\admin\Desktop\TEAM.R2R.R2R-WAIFU.v1.1.0-R2R\Setup R2R-WAIFU v1.1.0.exe" /SPAWNWND=$20212 /NOTIFYWND=$50184 | C:\Users\admin\Desktop\TEAM.R2R.R2R-WAIFU.v1.1.0-R2R\Setup R2R-WAIFU v1.1.0.exe | Setup R2R-WAIFU v1.1.0.tmp | ||||||||||||
User: admin Company: TEAM R2R Integrity Level: HIGH Description: R2R-WAIFU Setup Exit code: 0 Version: 1.1.0 Modules
| |||||||||||||||
3468 | "C:\Users\admin\AppData\Local\Temp\is-101QF.tmp\Setup R2R-WAIFU v1.1.0.tmp" /SL5="$50184,552632,237056,C:\Users\admin\Desktop\TEAM.R2R.R2R-WAIFU.v1.1.0-R2R\Setup R2R-WAIFU v1.1.0.exe" | C:\Users\admin\AppData\Local\Temp\is-101QF.tmp\Setup R2R-WAIFU v1.1.0.tmp | — | Setup R2R-WAIFU v1.1.0.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 Modules
| |||||||||||||||
3620 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\R2R-WAIFU.v1.1.0-R2R.rar" | C:\Program Files\WinRAR\WinRAR.exe | — | explorer.exe | |||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.60.0 Modules
|
(PID) Process: | (3620) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
Operation: | write | Name: | ShellExtBMP |
Value: | |||
(PID) Process: | (3620) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
Operation: | write | Name: | ShellExtIcon |
Value: | |||
(PID) Process: | (3620) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\13C\52C64B7E |
Operation: | write | Name: | LanguageList |
Value: en-US | |||
(PID) Process: | (3620) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\13C\52C64B7E |
Operation: | write | Name: | @C:\Windows\system32\NetworkExplorer.dll,-1 |
Value: Network | |||
(PID) Process: | (3620) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\R2R-WAIFU.v1.1.0-R2R.rar | |||
(PID) Process: | (3620) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | name |
Value: 120 | |||
(PID) Process: | (3620) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | size |
Value: 80 | |||
(PID) Process: | (3620) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | type |
Value: 120 | |||
(PID) Process: | (3620) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | mtime |
Value: 100 | |||
(PID) Process: | (2612) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
Operation: | write | Name: | ShellExtBMP |
Value: |
PID | Process | Filename | Type | |
---|---|---|---|---|
3620 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3620.36481\TEAM.R2R.R2R-WAIFU.v1.1.0-R2R\r2r-8777.rar | — | |
MD5:— | SHA256:— | |||
3620 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3620.36481\TEAM.R2R.R2R-WAIFU.v1.1.0-R2R\r2r-8777.sfv | — | |
MD5:— | SHA256:— | |||
3620 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3620.36481\TEAM.R2R.R2R-WAIFU.v1.1.0-R2R\R2R.nfo | — | |
MD5:— | SHA256:— | |||
2728 | Setup R2R-WAIFU v1.1.0.tmp | C:\Program Files\TEAM R2R\R2R-WAIFU\is-CSV6K.tmp | — | |
MD5:— | SHA256:— | |||
2728 | Setup R2R-WAIFU v1.1.0.tmp | C:\Program Files\TEAM R2R\R2R-WAIFU\is-GQJ98.tmp | — | |
MD5:— | SHA256:— | |||
2728 | Setup R2R-WAIFU v1.1.0.tmp | C:\Program Files\TEAM R2R\R2R-WAIFU\is-A60VK.tmp | — | |
MD5:— | SHA256:— | |||
2728 | Setup R2R-WAIFU v1.1.0.tmp | C:\Windows\system32\is-C4RTP.tmp | — | |
MD5:— | SHA256:— | |||
2728 | Setup R2R-WAIFU v1.1.0.tmp | C:\Windows\system32\is-EHQRQ.tmp | — | |
MD5:— | SHA256:— | |||
2020 | Setup R2R-WAIFU v1.1.0.exe | C:\Users\admin\AppData\Local\Temp\is-101QF.tmp\Setup R2R-WAIFU v1.1.0.tmp | executable | |
MD5:— | SHA256:— | |||
2844 | Setup R2R-WAIFU v1.1.0.exe | C:\Users\admin\AppData\Local\Temp\is-L2MVF.tmp\Setup R2R-WAIFU v1.1.0.tmp | executable | |
MD5:— | SHA256:— |