File name:

2023-07-29-PPSA.rar

Full analysis: https://app.any.run/tasks/f3381c7c-d5d9-4a6c-b967-bb399f6cd83e
Verdict: Malicious activity
Analysis date: August 01, 2023, 12:48:15
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

0C0829F0C659803549FAF6A376FAEA9B

SHA1:

D11612DFAFEE52448680A259C74E6A74383E0DA3

SHA256:

C05FDD0390A697E2194E7C3EA1B152E2B0C319FCEBF22B5E0D2475CD0AB6A60B

SSDEEP:

12288:wuT4fL2D2gzBw4Wqc5X/dkCQnoeRNd202+WyDNBtw6AxldR9xQzJZN1zoHXbShQ/:wuT4fL2D2g9u5VkvHb202+/W6E9QzJb+

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Unusual execution from MS Office

      • EXCEL.EXE (PID: 3888)
  • SUSPICIOUS

    • Reads the Internet Settings

      • rundll32.exe (PID: 4012)
    • Write to the desktop.ini file (may be used to cloak folders)

      • WinRAR.exe (PID: 772)
  • INFO

    • Dropped object may contain TOR URL's

      • WinRAR.exe (PID: 772)
    • The dropped object may contain a URL to Tor Browser

      • WinRAR.exe (PID: 772)
    • Application launched itself

      • msedge.exe (PID: 2056)
    • The process checks LSA protection

      • DWWIN.EXE (PID: 3736)
    • Checks supported languages

      • DW20.EXE (PID: 1660)
    • Manual execution by a user

      • notepad.exe (PID: 2512)
      • EXCEL.EXE (PID: 3888)
      • rundll32.exe (PID: 4012)
    • Creates files or folders in the user directory

      • DWWIN.EXE (PID: 3736)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
55
Monitored processes
16
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe no specs notepad.exe no specs excel.exe no specs dw20.exe no specs dwwin.exe no specs rundll32.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
772"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\2023-07-29-PPSA.rar"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
1660"C:\PROGRA~1\COMMON~1\MICROS~1\DW\DW20.EXE" -x -s 1060C:\Program Files\Common Files\microsoft shared\DW\DW20.EXEEXCEL.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Application Error Reporting
Exit code:
0
Version:
14.0.6015.1000
Modules
Images
c:\windows\system32\ntdll.dll
c:\program files\common files\microsoft shared\dw\dw20.exe
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\version.dll
c:\windows\system32\secur32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
2056"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --single-argument http://go.microsoft.com/fwlink/?LinkId=57426&Ext=akiraC:\Program Files\Microsoft\Edge\Application\msedge.exe
rundll32.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\kernel32.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2072"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=asset_store.mojom.AssetStoreService --lang=en-US --service-sandbox-type=asset_store_service --mojo-platform-channel-handle=1488 --field-trial-handle=1396,i,14281639059713280450,5467343391745153553,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2316"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1268 --field-trial-handle=1396,i,14281639059713280450,5467343391745153553,131072 /prefetch:2C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ntdll.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
2512"C:\Windows\system32\NOTEPAD.EXE" C:\Users\admin\Desktop\2023-07-29-PPSA\1 PC\akira_readme.txtC:\Windows\System32\notepad.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\notepad.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\comdlg32.dll
3040"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=1632 --field-trial-handle=1396,i,14281639059713280450,5467343391745153553,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
3332"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3684 --field-trial-handle=1396,i,14281639059713280450,5467343391745153553,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\windows\system32\kernel32.dll
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
3336"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=2392 --field-trial-handle=1396,i,14281639059713280450,5467343391745153553,131072 /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
3524"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --use-gl=angle --use-angle=swiftshader-webgl --mojo-platform-channel-handle=1460 --field-trial-handle=1396,i,14281639059713280450,5467343391745153553,131072 /prefetch:2C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
Total events
3 313
Read events
3 250
Write events
59
Delete events
4

Modification events

(PID) Process:(772) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\178\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(772) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(772) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(772) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(772) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(772) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(772) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(772) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3888) EXCEL.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1033
Value:
On
(PID) Process:(3888) EXCEL.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1041
Value:
On
Executable files
6
Suspicious files
28
Text files
64
Unknown types
0

Dropped files

PID
Process
Filename
Type
772WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb772.9486\2023-07-29-PPSA\1 PC\desktop.initext
MD5:19F7EC0CD58F6839C50F939AF5E96FA9
SHA256:A7F4C853A4DD8856DFAA7C5449CD7CDA4B221DBC39F353B488BE1E45E12A54C9
772WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb772.9486\2023-07-29-PPSA\190-1-1-4\babyna.battext
MD5:F66CCAAD35D9106B3BFB2B2ACD71189A
SHA256:11BF4304AD79AB45CE5A3C9F46BF4C157CB2CC0274BAE096F39359AA487A9E60
772WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb772.9486\2023-07-29-PPSA\1 PC\akira_readme.txttext
MD5:E3E06976EFE25F9111737A414D780F4D
SHA256:58142AB62DEE28039339D32616E901328CE1E5831C2D052DA5E74179972A2332
3888EXCEL.EXEC:\Users\admin\AppData\Local\Temp\CVRF681.tmp.cvr
MD5:
SHA256:
772WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb772.9486\2023-07-29-PPSA\1 PC\Captura de pantalla 2023-07-31 094115.jpgimage
MD5:874DE99AE9AF94B00DB8104A309AB204
SHA256:B448C1F714BC8484A4718F42080D9AA39989B2BF24E8D859A5ED29B98648584A
3736DWWIN.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_EXCEL.EXE_c54ff7024add82f81a9c67eefc3453994968b7_0edf1052\Report.wer
MD5:
SHA256:
772WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb772.9486\2023-07-29-PPSA\1 PC\programdata\desktop.initext
MD5:19F7EC0CD58F6839C50F939AF5E96FA9
SHA256:A7F4C853A4DD8856DFAA7C5449CD7CDA4B221DBC39F353B488BE1E45E12A54C9
772WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb772.9486\2023-07-29-PPSA\06_INDICADORES DE GESTION_JUNIO_ 2018_PAPEL PRENSA.xlsdocument
MD5:0E3BCCC7CCFADC1BD912CE1120AB05CB
SHA256:7EAFA36E691D3588AEFDDB6836359589C1312B2FE220C6FB1494DBA63AA8D17C
772WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb772.9486\2023-07-29-PPSA\1 PC\programdata\babyna.zipcompressed
MD5:9FA9F399B6FB49BB8247DB9CBAEB4175
SHA256:93C2023528E5E7D4754476F502D7C78ED4394D955AA4E51A5F3127E834112AAE
772WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb772.9486\2023-07-29-PPSA\1 PC\programdata\babyna.battext
MD5:F66CCAAD35D9106B3BFB2B2ACD71189A
SHA256:11BF4304AD79AB45CE5A3C9F46BF4C157CB2CC0274BAE096F39359AA487A9E60
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
26
DNS requests
21
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3584
msedge.exe
GET
2.16.241.17:80
http://shell.windows.com/fileassoc/fileassoc.asp?Ext=akira
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2056
msedge.exe
239.255.255.250:1900
whitelisted
3584
msedge.exe
104.102.40.139:443
go.microsoft.com
AKAMAI-AS
DE
malicious
1088
svchost.exe
224.0.0.252:5355
unknown
3584
msedge.exe
204.79.197.239:443
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
3584
msedge.exe
184.86.251.26:443
www.bing.com
Akamai International B.V.
DE
suspicious
3584
msedge.exe
13.107.42.16:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
3584
msedge.exe
2.16.241.17:80
shell.windows.com
Akamai International B.V.
DE
suspicious
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
2640
svchost.exe
239.255.255.250:1900
whitelisted

DNS requests

Domain
IP
Reputation
go.microsoft.com
  • 104.102.40.139
whitelisted
edge.microsoft.com
  • 204.79.197.239
  • 13.107.21.239
whitelisted
config.edge.skype.com
  • 13.107.42.16
malicious
nav-edge.smartscreen.microsoft.com
  • 20.8.16.139
whitelisted
data-edge.smartscreen.microsoft.com
  • 20.31.42.83
whitelisted
shell.windows.com
  • 2.16.241.17
  • 2.16.241.10
whitelisted
www.bing.com
  • 184.86.251.26
  • 184.86.251.22
  • 184.86.251.4
  • 184.86.251.23
  • 184.86.251.30
  • 184.86.251.31
  • 184.86.251.25
  • 184.86.251.28
  • 184.86.251.24
whitelisted

Threats

No threats detected
No debug info