analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

Phison MPALL v3.60.0B PS2251 Formatter _www.flashdrive-repair.com.rar

Full analysis: https://app.any.run/tasks/ae607f2a-e740-47ec-be1a-4c14e7d521ab
Verdict: Malicious activity
Analysis date: September 26, 2019, 03:27:32
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v4, os: Win32
MD5:

2E9065C062CF9983414B7F0C4BDB3525

SHA1:

DE7E1AFDC450C2F6FCC4CB850E78C6F9A9DC4255

SHA256:

C092D1F1A198F00033711A39189EEDE9A889CD4E56F9423018076E4820D61650

SSDEEP:

49152:BHfXw/L6CHm+S/OJ1x64afXw7AsaCo+tldyhZvUXBW1j3qBm:RCJHPoKA2jgPUXMR3qI

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • SearchProtocolHost.exe (PID: 1476)
      • MPALL_F2_v360_0B.exe (PID: 3148)
    • Application was dropped or rewritten from another process

      • MPALL_F2_v360_0B.exe (PID: 3148)
  • SUSPICIOUS

    • Creates files in the Windows directory

      • MPALL_F2_v360_0B.exe (PID: 3148)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3308)
      • MPALL_F2_v360_0B.exe (PID: 3148)
  • INFO

    • Manual execution by user

      • MPALL_F2_v360_0B.exe (PID: 3148)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v-4.x) (58.3)
.rar | RAR compressed archive (gen) (41.6)

EXIF

ZIP

ArchivedFileName: Phison MPALL v3.60.0B PS2251 Formatter _www.flashdrive-repair.com\Flash Drive Repair.URL
PackingMethod: Stored
ModifyDate: 2014:02:08 13:56:16
OperatingSystem: Win32
UncompressedSize: 60
CompressedSize: 174
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
37
Monitored processes
4
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe searchprotocolhost.exe no specs mpall_f2_v360_0b.exe regini.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
3308"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Phison MPALL v3.60.0B PS2251 Formatter _www.flashdrive-repair.com.rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
1476"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe4_ Global\UsGthrCtrlFltPipeMssGthrPipe4 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" C:\Windows\System32\SearchProtocolHost.exeSearchIndexer.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Windows Search Protocol Host
Exit code:
0
Version:
7.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\searchprotocolhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3148"C:\Users\admin\Desktop\Phison MPALL v3.60.0B PS2251 Formatter _www.flashdrive-repair.com\MPALL_F2_v360_0B.exe" C:\Users\admin\Desktop\Phison MPALL v3.60.0B PS2251 Formatter _www.flashdrive-repair.com\MPALL_F2_v360_0B.exe
explorer.exe
User:
admin
Company:
Best Company
Integrity Level:
MEDIUM
Description:
Build by VC
Version:
2.0.1.6
Modules
Images
c:\users\admin\desktop\phison mpall v3.60.0b ps2251 formatter _www.flashdrive-repair.com\mpall_f2_v360_0b.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\desktop\phison mpall v3.60.0b ps2251 formatter _www.flashdrive-repair.com\inpout32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\setupapi.dll
3624regini.exe C:\Windows\temp\MPALL\ug.iniC:\Windows\system32\regini.exeMPALL_F2_v360_0B.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Registry Initializer
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\regini.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
Total events
834
Read events
807
Write events
27
Delete events
0

Modification events

(PID) Process:(3308) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3308) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3308) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\72\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3308) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Phison MPALL v3.60.0B PS2251 Formatter _www.flashdrive-repair.com.rar
(PID) Process:(3308) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3308) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3308) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3308) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3308) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\DialogEditHistory\ExtrPath
Operation:writeName:0
Value:
C:\Users\admin\Desktop
(PID) Process:(1476) SearchProtocolHost.exeKey:HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\72\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
Executable files
9
Suspicious files
0
Text files
12
Unknown types
0

Dropped files

PID
Process
Filename
Type
3308WinRAR.exeC:\Users\admin\Desktop\Phison MPALL v3.60.0B PS2251 Formatter _www.flashdrive-repair.com\HubMapping.initext
MD5:EC887F320DC47822E0DF032949F20B1F
SHA256:357CDAAC6733BCB0F37BE6051364E71A6E1F76147D3E49A475C8B676323D6F9A
3308WinRAR.exeC:\Users\admin\Desktop\Phison MPALL v3.60.0B PS2251 Formatter _www.flashdrive-repair.com\Reports\my_flash\F1\LOGFILE-07-03-2013_my_flash-2235.txttext
MD5:2E37BD8211875A9D1CD5FCF0C7F0B88D
SHA256:C8E4FCA1DBB5DE9D14CB9718F36C95515087F05F915E777C1E2D8C5E19268C5F
3148MPALL_F2_v360_0B.exeC:\Windows\temp\MPALL\filter.infini
MD5:C949BEEBC6A9B74C72027F0C15A40AE4
SHA256:6AF1B415D4B85AD1485B2D4C5844B456DBE2D0CEF5873172E6A8C8744186C871
3308WinRAR.exeC:\Users\admin\Desktop\Phison MPALL v3.60.0B PS2251 Formatter _www.flashdrive-repair.com\Reports\my_flash\F1\2235-my_flash-TC.logtext
MD5:6C87755DBCE91064AB6424B97B0B3AE9
SHA256:392E21FA4A7065AF6AE14558861B3AF6FBA2F9301257169E2D895ADFF1FBB9F2
3308WinRAR.exeC:\Users\admin\Desktop\Phison MPALL v3.60.0B PS2251 Formatter _www.flashdrive-repair.com\Reports\my_flash\F1\Result-07-03-2013-my_flash-2235.txttext
MD5:FCD1C9F6CCB9BA66C2BE689AD481A91E
SHA256:F3BEC9E45CEA27CD208C181EDAA667C0150DA1E013081A5A363D0701D59E6C73
3148MPALL_F2_v360_0B.exeC:\Windows\temp\MPALL\usblowerfilter.sysexecutable
MD5:BDBD8CBF6CD29E474336132CDEF5CE66
SHA256:C8B8256DC115A0E73DA54430281B35FBB4AB5F74643143AD1717BE5F5D1488EE
3148MPALL_F2_v360_0B.exeC:\Windows\temp\MPALL\regini.exeexecutable
MD5:87BDB691598FB4A2806BD2CB6783A678
SHA256:E2B1A586EFF0EF6290C0325BC70DF2585749947DE67D430722EDC92EEDFC5964
3308WinRAR.exeC:\Users\admin\Desktop\Phison MPALL v3.60.0B PS2251 Formatter _www.flashdrive-repair.com\Reports\my_flash\F1\Result-06-03-2013-my_flash-2235.txttext
MD5:960C419E841AA1F1C13B9DD85E6BF913
SHA256:CEE91853BB2B322CF37897D3205519926CD868FFC51127F1B5AF869A5D8DFF7E
3308WinRAR.exeC:\Users\admin\Desktop\Phison MPALL v3.60.0B PS2251 Formatter _www.flashdrive-repair.com\MPALL_F1_8400_v360_0B.exeexecutable
MD5:FCDEF1EB699981DCC8247BD520E7B5F9
SHA256:9F9D613C7E2C12456B00E78CE0914F64E28DD1277119AF60752DE0FB774965FF
3308WinRAR.exeC:\Users\admin\Desktop\Phison MPALL v3.60.0B PS2251 Formatter _www.flashdrive-repair.com\phison-mpall-formatter-v3.60.0B- PS2251-format-firmware-tool-utility.pngimage
MD5:217F6A2BB25D1F51EC3831CA7D7A5EDD
SHA256:8C03C43A81A719F9B3CDC4C64D37E2AA1893A6BC1FEEC47DC0AFD7A7B61943BF
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
Process
Message
MPALL_F2_v360_0B.exe
LockPort
MPALL_F2_v360_0B.exe
****CMPProgramDlg::GetVarFromIni
MPALL_F2_v360_0B.exe
W7 GetMACaddress start
MPALL_F2_v360_0B.exe
W7 GetMacAddress [04AF]
MPALL_F2_v360_0B.exe
Create Fail 1
MPALL_F2_v360_0B.exe
Create Fail 1
MPALL_F2_v360_0B.exe
Get ini File 0