| File name: | R2R-WAIFU.v1.1.0-R2R.rar |
| Full analysis: | https://app.any.run/tasks/5077e476-ec7f-431b-bf0f-635a6c94569c |
| Verdict: | Malicious activity |
| Analysis date: | April 21, 2021, 09:31:42 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-rar |
| File info: | RAR archive data, v5 |
| MD5: | 5669542AE4FE20CDD5793EF59BC9B6ED |
| SHA1: | 8AB824DB5277177621989F0964E8BBBBDE027735 |
| SHA256: | BEA5CBACD0AA060F634AC1BCD3D7405511F6BB1FB2003B269CA89A63FC5F4AB7 |
| SSDEEP: | 24576:1m/xa6JFNDNRXQofyVl3eLOoVT5L05Is7YOCbVP3x652vgx:1Gaav6LO6o9h0WOCB3xi2Ix |
| .rar | | | RAR compressed archive (v5.0) (61.5) |
|---|---|---|
| .rar | | | RAR compressed archive (gen) (38.4) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2020 | "C:\Users\admin\Desktop\TEAM.R2R.R2R-WAIFU.v1.1.0-R2R\Setup R2R-WAIFU v1.1.0.exe" | C:\Users\admin\Desktop\TEAM.R2R.R2R-WAIFU.v1.1.0-R2R\Setup R2R-WAIFU v1.1.0.exe | explorer.exe | ||||||||||||
User: admin Company: TEAM R2R Integrity Level: MEDIUM Description: R2R-WAIFU Setup Exit code: 0 Version: 1.1.0 Modules
| |||||||||||||||
| 2612 | "C:\Program Files\WinRAR\WinRAR.exe" x -iext -ow -ver -- "C:\Users\admin\Desktop\TEAM.R2R.R2R-WAIFU.v1.1.0-R2R\r2r-8777.rar" C:\Users\admin\Desktop\TEAM.R2R.R2R-WAIFU.v1.1.0-R2R\ | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.60.0 Modules
| |||||||||||||||
| 2728 | "C:\Users\admin\AppData\Local\Temp\is-L2MVF.tmp\Setup R2R-WAIFU v1.1.0.tmp" /SL5="$301E0,552632,237056,C:\Users\admin\Desktop\TEAM.R2R.R2R-WAIFU.v1.1.0-R2R\Setup R2R-WAIFU v1.1.0.exe" /SPAWNWND=$20212 /NOTIFYWND=$50184 | C:\Users\admin\AppData\Local\Temp\is-L2MVF.tmp\Setup R2R-WAIFU v1.1.0.tmp | Setup R2R-WAIFU v1.1.0.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: Setup/Uninstall Exit code: 3221225547 Version: 51.1052.0.0 Modules
| |||||||||||||||
| 2844 | "C:\Users\admin\Desktop\TEAM.R2R.R2R-WAIFU.v1.1.0-R2R\Setup R2R-WAIFU v1.1.0.exe" /SPAWNWND=$20212 /NOTIFYWND=$50184 | C:\Users\admin\Desktop\TEAM.R2R.R2R-WAIFU.v1.1.0-R2R\Setup R2R-WAIFU v1.1.0.exe | Setup R2R-WAIFU v1.1.0.tmp | ||||||||||||
User: admin Company: TEAM R2R Integrity Level: HIGH Description: R2R-WAIFU Setup Exit code: 0 Version: 1.1.0 Modules
| |||||||||||||||
| 3468 | "C:\Users\admin\AppData\Local\Temp\is-101QF.tmp\Setup R2R-WAIFU v1.1.0.tmp" /SL5="$50184,552632,237056,C:\Users\admin\Desktop\TEAM.R2R.R2R-WAIFU.v1.1.0-R2R\Setup R2R-WAIFU v1.1.0.exe" | C:\Users\admin\AppData\Local\Temp\is-101QF.tmp\Setup R2R-WAIFU v1.1.0.tmp | — | Setup R2R-WAIFU v1.1.0.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 Modules
| |||||||||||||||
| 3620 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\R2R-WAIFU.v1.1.0-R2R.rar" | C:\Program Files\WinRAR\WinRAR.exe | — | explorer.exe | |||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.60.0 Modules
| |||||||||||||||
| (PID) Process: | (3620) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (3620) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (3620) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\13C\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3620) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\13C\52C64B7E |
| Operation: | write | Name: | @C:\Windows\system32\NetworkExplorer.dll,-1 |
Value: Network | |||
| (PID) Process: | (3620) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\R2R-WAIFU.v1.1.0-R2R.rar | |||
| (PID) Process: | (3620) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (3620) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (3620) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (3620) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (2612) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3620 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3620.36481\TEAM.R2R.R2R-WAIFU.v1.1.0-R2R\r2r-8777.rar | — | |
MD5:— | SHA256:— | |||
| 3620 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3620.36481\TEAM.R2R.R2R-WAIFU.v1.1.0-R2R\r2r-8777.sfv | — | |
MD5:— | SHA256:— | |||
| 3620 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3620.36481\TEAM.R2R.R2R-WAIFU.v1.1.0-R2R\R2R.nfo | — | |
MD5:— | SHA256:— | |||
| 2728 | Setup R2R-WAIFU v1.1.0.tmp | C:\Program Files\TEAM R2R\R2R-WAIFU\is-CSV6K.tmp | — | |
MD5:— | SHA256:— | |||
| 2728 | Setup R2R-WAIFU v1.1.0.tmp | C:\Program Files\TEAM R2R\R2R-WAIFU\is-GQJ98.tmp | — | |
MD5:— | SHA256:— | |||
| 2728 | Setup R2R-WAIFU v1.1.0.tmp | C:\Program Files\TEAM R2R\R2R-WAIFU\is-A60VK.tmp | — | |
MD5:— | SHA256:— | |||
| 2728 | Setup R2R-WAIFU v1.1.0.tmp | C:\Windows\system32\is-C4RTP.tmp | — | |
MD5:— | SHA256:— | |||
| 2728 | Setup R2R-WAIFU v1.1.0.tmp | C:\Windows\system32\is-EHQRQ.tmp | — | |
MD5:— | SHA256:— | |||
| 2728 | Setup R2R-WAIFU v1.1.0.tmp | C:\Users\admin\AppData\Local\Temp\is-M2R7O.tmp\R2RINNO.dll | executable | |
MD5:0F8BBAB51C5F70093B7ED7DD825D68E8 | SHA256:7FC4FA7F5CEA34DF0A6733527081886CFB1C49B369DF2DB454DE87CC4E70BDB5 | |||
| 2728 | Setup R2R-WAIFU v1.1.0.tmp | C:\Program Files\TEAM R2R\R2R-WAIFU\changelog.txt | text | |
MD5:— | SHA256:— | |||