File name:

WinRAR_Portable_Multiversion_32-64-bit_Multilingual_Online.exe

Full analysis: https://app.any.run/tasks/a044acfa-97cf-462b-bcb0-e310e1c16ed7
Verdict: Malicious activity
Analysis date: January 17, 2024, 08:47:38
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
MD5:

412A212B183133E5AC07E6DD91F2A4B9

SHA1:

390EE78F5C46C791327EECBE9EC598A597D9EA49

SHA256:

C0A23D596B9FC0CEBDD5422B64217B09DAC515E292A2DA1087F5B9128933FE4E

SSDEEP:

12288:lnGll+1SgE3fV5VG/8ThAd5a2DePqd78mLvrXB:lnGll+1SN3t50/8ThAd5a2DaS78mnR

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • WinRAR_Portable_Multiversion_32-64-bit_Multilingual_Online.exe (PID: 2036)
      • UnRAR.exe (PID: 1608)
      • WinRARPortable.exe (PID: 2388)
      • UnRAR.exe (PID: 1832)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR_Portable_Multiversion_32-64-bit_Multilingual_Online.exe (PID: 2036)
      • UnRAR.exe (PID: 1608)
      • UnRAR.exe (PID: 1832)
      • WinRARPortable.exe (PID: 2388)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • WinRAR_Portable_Multiversion_32-64-bit_Multilingual_Online.exe (PID: 2036)
      • WinRARPortable.exe (PID: 2388)
    • Drops 7-zip archiver for unpacking

      • UnRAR.exe (PID: 1608)
      • UnRAR.exe (PID: 1832)
    • The process creates files with name similar to system file names

      • WinRAR_Portable_Multiversion_32-64-bit_Multilingual_Online.exe (PID: 2036)
      • WinRARPortable.exe (PID: 2388)
    • Reads settings of System Certificates

      • WinRAR_Portable_Multiversion_32-64-bit_Multilingual_Online.exe (PID: 2036)
    • Reads the Internet Settings

      • WinRAR_Portable_Multiversion_32-64-bit_Multilingual_Online.exe (PID: 2036)
      • WinRARPortable.exe (PID: 2388)
    • Starts application with an unusual extension

      • WinRAR_Portable_Multiversion_32-64-bit_Multilingual_Online.exe (PID: 2036)
    • Checks Windows Trust Settings

      • WinRAR_Portable_Multiversion_32-64-bit_Multilingual_Online.exe (PID: 2036)
    • Process requests binary or script from the Internet

      • WinRAR_Portable_Multiversion_32-64-bit_Multilingual_Online.exe (PID: 2036)
    • Reads security settings of Internet Explorer

      • WinRAR_Portable_Multiversion_32-64-bit_Multilingual_Online.exe (PID: 2036)
  • INFO

    • Reads the computer name

      • WinRAR_Portable_Multiversion_32-64-bit_Multilingual_Online.exe (PID: 2036)
      • UnRAR.exe (PID: 1608)
      • UnRAR.exe (PID: 1832)
      • WinRARPortable.exe (PID: 2388)
      • WinRAR.exe (PID: 2732)
    • Create files in a temporary directory

      • WinRAR_Portable_Multiversion_32-64-bit_Multilingual_Online.exe (PID: 2036)
      • WinRARPortable.exe (PID: 2388)
    • Checks supported languages

      • nsCD43.tmp (PID: 1044)
      • WinRAR_Portable_Multiversion_32-64-bit_Multilingual_Online.exe (PID: 2036)
      • nsD795.tmp (PID: 1576)
      • UnRAR.exe (PID: 1608)
      • UnRAR.exe (PID: 1832)
      • WinRARPortable.exe (PID: 2388)
      • WinRAR.exe (PID: 2732)
    • Creates files or folders in the user directory

      • WinRAR_Portable_Multiversion_32-64-bit_Multilingual_Online.exe (PID: 2036)
    • Checks proxy server information

      • WinRAR_Portable_Multiversion_32-64-bit_Multilingual_Online.exe (PID: 2036)
    • Reads the machine GUID from the registry

      • WinRAR_Portable_Multiversion_32-64-bit_Multilingual_Online.exe (PID: 2036)
      • WinRARPortable.exe (PID: 2388)
      • WinRAR.exe (PID: 2732)
    • Manual execution by a user

      • WinRARPortable.exe (PID: 2464)
      • WinRARPortable.exe (PID: 2388)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | NSIS - Nullsoft Scriptable Install System (94.8)
.exe | Win32 Executable MS Visual C++ (generic) (3.4)
.dll | Win32 Dynamic Link Library (generic) (0.7)
.exe | Win32 Executable (generic) (0.5)
.exe | Generic Win/DOS Executable (0.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2009:12:05 23:50:46+01:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 23552
InitializedDataSize: 119808
UninitializedDataSize: 1024
EntryPoint: 0x323c
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 0.0.0.0
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Windows, Latin1
Comments: 24/01/2022 13:28:09
CompanyName: PortableAppZ.blogspot.com
FileDescription: WinRAR Portable
FileVersion: 0.0.0.0
InternalName: WinRAR Portable
LegalCopyright: Bernat
LegalTrademarks: PortableAppZ is a Trademark of Bernat
OriginalFileName: WinRARPortable.exe
ProductName: WinRAR Portable
ProductVersion: 0.0.0.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
50
Monitored processes
8
Malicious processes
6
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar_portable_multiversion_32-64-bit_multilingual_online.exe nscd43.tmp no specs unrar.exe nsd795.tmp no specs unrar.exe winrarportable.exe no specs winrarportable.exe winrar.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1044"C:\Users\admin\AppData\Local\Temp\nsoF82E.tmp\nsCD43.tmp" "C:\Users\admin\AppData\Local\Temp\WinRARPortableTemp\UnRAR.exe" x -inul -y "C:\Users\admin\AppData\Local\Temp\WinRARPortableTemp\winrar-x32-624es.exe" "C:\Users\admin\Desktop\WinRARPortable\App\WinRAR\"C:\Users\admin\AppData\Local\Temp\nsoF82E.tmp\nsCD43.tmpWinRAR_Portable_Multiversion_32-64-bit_Multilingual_Online.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\nsof82e.tmp\nscd43.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
1576"C:\Users\admin\AppData\Local\Temp\nsoF82E.tmp\nsD795.tmp" "C:\Users\admin\AppData\Local\Temp\WinRARPortableTemp\UnRAR.exe" x -inul -y "C:\Users\admin\AppData\Local\Temp\WinRARPortableTemp\winrar-x64-624es.exe" "C:\Users\admin\Desktop\WinRARPortable\App\WinRAR-x64\"C:\Users\admin\AppData\Local\Temp\nsoF82E.tmp\nsD795.tmpWinRAR_Portable_Multiversion_32-64-bit_Multilingual_Online.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\nsof82e.tmp\nsd795.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
1608"C:\Users\admin\AppData\Local\Temp\WinRARPortableTemp\UnRAR.exe" x -inul -y "C:\Users\admin\AppData\Local\Temp\WinRARPortableTemp\winrar-x32-624es.exe" "C:\Users\admin\Desktop\WinRARPortable\App\WinRAR\"C:\Users\admin\AppData\Local\Temp\WinRARPortableTemp\UnRAR.exe
nsCD43.tmp
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
Command line RAR
Exit code:
0
Version:
6.1.0
Modules
Images
c:\users\admin\appdata\local\temp\winrarportabletemp\unrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
1832"C:\Users\admin\AppData\Local\Temp\WinRARPortableTemp\UnRAR.exe" x -inul -y "C:\Users\admin\AppData\Local\Temp\WinRARPortableTemp\winrar-x64-624es.exe" "C:\Users\admin\Desktop\WinRARPortable\App\WinRAR-x64\"C:\Users\admin\AppData\Local\Temp\WinRARPortableTemp\UnRAR.exe
nsD795.tmp
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
Command line RAR
Exit code:
0
Version:
6.1.0
Modules
Images
c:\users\admin\appdata\local\temp\winrarportabletemp\unrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2036"C:\Users\admin\AppData\Local\Temp\WinRAR_Portable_Multiversion_32-64-bit_Multilingual_Online.exe" C:\Users\admin\AppData\Local\Temp\WinRAR_Portable_Multiversion_32-64-bit_Multilingual_Online.exe
explorer.exe
User:
admin
Company:
PortableAppZ.blogspot.com
Integrity Level:
MEDIUM
Description:
WinRAR Portable
Exit code:
0
Version:
0.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\winrar_portable_multiversion_32-64-bit_multilingual_online.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
2388"C:\Users\admin\Desktop\WinRARPortable\WinRARPortable.exe" C:\Users\admin\Desktop\WinRARPortable\WinRARPortable.exe
explorer.exe
User:
admin
Company:
PortableAppZ.blogspot.com
Integrity Level:
HIGH
Description:
WinRAR Portable
Exit code:
0
Version:
0.0.0.0
Modules
Images
c:\users\admin\desktop\winrarportable\winrarportable.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
2464"C:\Users\admin\Desktop\WinRARPortable\WinRARPortable.exe" C:\Users\admin\Desktop\WinRARPortable\WinRARPortable.exeexplorer.exe
User:
admin
Company:
PortableAppZ.blogspot.com
Integrity Level:
MEDIUM
Description:
WinRAR Portable
Exit code:
3221226540
Version:
0.0.0.0
Modules
Images
c:\users\admin\desktop\winrarportable\winrarportable.exe
c:\windows\system32\ntdll.dll
2732"C:\Users\admin\Desktop\WinRARPortable\App\WinRAR\WinRAR.exe" C:\Users\admin\Desktop\WinRARPortable\App\WinRAR\WinRAR.exeWinRARPortable.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
HIGH
Description:
WinRAR archiver
Exit code:
0
Version:
6.24.0
Modules
Images
c:\users\admin\desktop\winrarportable\app\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
Total events
6 277
Read events
6 236
Write events
41
Delete events
0

Modification events

(PID) Process:(2036) WinRAR_Portable_Multiversion_32-64-bit_Multilingual_Online.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2036) WinRAR_Portable_Multiversion_32-64-bit_Multilingual_Online.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer
Operation:writeName:Browse For Folder Width
Value:
318
(PID) Process:(2036) WinRAR_Portable_Multiversion_32-64-bit_Multilingual_Online.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer
Operation:writeName:Browse For Folder Height
Value:
288
(PID) Process:(2036) WinRAR_Portable_Multiversion_32-64-bit_Multilingual_Online.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(2036) WinRAR_Portable_Multiversion_32-64-bit_Multilingual_Online.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
460000005B010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(2036) WinRAR_Portable_Multiversion_32-64-bit_Multilingual_Online.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2036) WinRAR_Portable_Multiversion_32-64-bit_Multilingual_Online.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(2036) WinRAR_Portable_Multiversion_32-64-bit_Multilingual_Online.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(2036) WinRAR_Portable_Multiversion_32-64-bit_Multilingual_Online.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(2036) WinRAR_Portable_Multiversion_32-64-bit_Multilingual_Online.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
Executable files
45
Suspicious files
16
Text files
36
Unknown types
1

Dropped files

PID
Process
Filename
Type
2036WinRAR_Portable_Multiversion_32-64-bit_Multilingual_Online.exeC:\Users\admin\AppData\Local\Temp\nsoF82E.tmp\Dialer.dllexecutable
MD5:8286932178460462A328D2BAE8C7B0A5
SHA256:05DD0895A332E490E697CDD0830B227836E852A83201FE893F3929271B63DD6C
2036WinRAR_Portable_Multiversion_32-64-bit_Multilingual_Online.exeC:\Users\admin\AppData\Local\Temp\WinRARPortableTemp\UnRAR.exeexecutable
MD5:C2C3C8ACA86401A9B731A03AB17BA6B6
SHA256:A240F9FA689CC691F9082D60043FFA492491DAECADF8B5E6A14201BFA20EC4ED
2036WinRAR_Portable_Multiversion_32-64-bit_Multilingual_Online.exeC:\Users\admin\AppData\Local\Temp\nsoF82E.tmp\FindProcDLL.dllexecutable
MD5:75E7351A0F836B8659E6F315683C29F7
SHA256:7FFC549E7F679A08C77FA230654B77CDFFB3444296BB7C6B8B5769DB374B61EE
2036WinRAR_Portable_Multiversion_32-64-bit_Multilingual_Online.exeC:\Users\admin\AppData\Local\Temp\nsoF82E.tmp\modern-wizard.bmpimage
MD5:340ACA2BC234B6A8AD72E39B0EB8E6D1
SHA256:12ED859375141B5A83EF2E2A0EA322DB78C4E04FE4BC431FDEF53E123427A919
2036WinRAR_Portable_Multiversion_32-64-bit_Multilingual_Online.exeC:\Users\admin\AppData\Local\Temp\nsoF82E.tmp\INetC.dllexecutable
MD5:92EC4DD8C0DDD8C4305AE1684AB65FB0
SHA256:5520208A33E6409C129B4EA1270771F741D95AFE5B048C2A1E6A2CC2AD829934
2036WinRAR_Portable_Multiversion_32-64-bit_Multilingual_Online.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506compressed
MD5:AC05D27423A85ADC1622C714F2CB6184
SHA256:C6456E12E5E53287A547AF4103E0397CB9697E466CF75844312DC296D43D144D
2036WinRAR_Portable_Multiversion_32-64-bit_Multilingual_Online.exeC:\Users\admin\AppData\Local\Temp\nsoF82E.tmp\LangDLL.dllexecutable
MD5:5332704764C0D40A9EC16704F44BF8EC
SHA256:A6F77CB1D88188921082517EEC62ADE66C992181F4CF125CBBEC2179ACE636CB
2036WinRAR_Portable_Multiversion_32-64-bit_Multilingual_Online.exeC:\Users\admin\AppData\Local\Temp\nsoF82E.tmp\w7tbp.dllexecutable
MD5:9A3031CC4CEF0DBA236A28EECDF0AFB5
SHA256:53BB519E3293164947AC7CBD7E612F637D77A7B863E3534BA1A7E39B350D3C00
2036WinRAR_Portable_Multiversion_32-64-bit_Multilingual_Online.exeC:\Users\admin\AppData\Local\Temp\nsoF82E.tmp\ioSpecial.initext
MD5:E2D5070BC28DB1AC745613689FF86067
SHA256:D95AED234F932A1C48A2B1B0D98C60CA31F962310C03158E2884AB4DDD3EA1E0
2036WinRAR_Portable_Multiversion_32-64-bit_Multilingual_Online.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B6D447E232B07CFF79F3061CC6F1C80Cbinary
MD5:900BC892E96B4AED25BC97ADE900685B
SHA256:26D3759781C0A3CFF326D8A236AA876C6C833761BC5D4558BC6FBAEA66766E10
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
11
DNS requests
5
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2036
WinRAR_Portable_Multiversion_32-64-bit_Multilingual_Online.exe
GET
200
23.32.238.219:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?4e0ed24d28caab86
unknown
compressed
65.2 Kb
unknown
2036
WinRAR_Portable_Multiversion_32-64-bit_Multilingual_Online.exe
GET
301
51.195.68.162:80
http://www.rarlab.com/rar/winrar-x32-624es.exe
unknown
unknown
2036
WinRAR_Portable_Multiversion_32-64-bit_Multilingual_Online.exe
GET
200
23.32.238.219:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?5b924521a13e9248
unknown
compressed
4.66 Kb
unknown
1080
svchost.exe
GET
304
23.32.238.184:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?a414549a770d7263
unknown
unknown
2036
WinRAR_Portable_Multiversion_32-64-bit_Multilingual_Online.exe
GET
200
23.53.40.154:80
http://r3.o.lencr.org/MFMwUTBPME0wSzAJBgUrDgMCGgUABBRI2smg%2ByvTLU%2Fw3mjS9We3NfmzxAQUFC6zF7dYVsuuUAlA5h%2BvnYsUwsYCEgQ%2B1B16a6OTUBBQaqVmUwYF%2FA%3D%3D
unknown
binary
503 b
unknown
2036
WinRAR_Portable_Multiversion_32-64-bit_Multilingual_Online.exe
GET
200
23.192.153.142:80
http://x1.c.lencr.org/
unknown
binary
717 b
unknown
2036
WinRAR_Portable_Multiversion_32-64-bit_Multilingual_Online.exe
GET
301
51.195.68.162:80
http://www.rarlab.com/rar/winrar-x64-624es.exe
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
2036
WinRAR_Portable_Multiversion_32-64-bit_Multilingual_Online.exe
51.195.68.162:80
www.rarlab.com
OVH SAS
FR
unknown
2036
WinRAR_Portable_Multiversion_32-64-bit_Multilingual_Online.exe
51.195.68.162:443
www.rarlab.com
OVH SAS
FR
unknown
2036
WinRAR_Portable_Multiversion_32-64-bit_Multilingual_Online.exe
23.32.238.219:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown
2036
WinRAR_Portable_Multiversion_32-64-bit_Multilingual_Online.exe
23.192.153.142:80
x1.c.lencr.org
AKAMAI-AS
GB
unknown
2036
WinRAR_Portable_Multiversion_32-64-bit_Multilingual_Online.exe
23.53.40.154:80
r3.o.lencr.org
Akamai International B.V.
DE
unknown
1080
svchost.exe
23.32.238.184:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown

DNS requests

Domain
IP
Reputation
www.rarlab.com
  • 51.195.68.162
unknown
ctldl.windowsupdate.com
  • 23.32.238.219
  • 23.32.238.234
  • 23.32.238.210
  • 23.32.238.211
  • 23.32.238.216
  • 23.32.238.224
  • 23.32.238.225
  • 23.32.238.218
  • 23.32.238.235
  • 23.32.238.184
  • 23.32.238.185
  • 23.32.238.203
  • 23.32.238.209
  • 23.32.238.195
  • 23.32.238.202
whitelisted
x1.c.lencr.org
  • 23.192.153.142
whitelisted
r3.o.lencr.org
  • 23.53.40.154
  • 23.53.40.161
shared

Threats

PID
Process
Class
Message
2036
WinRAR_Portable_Multiversion_32-64-bit_Multilingual_Online.exe
Potentially Bad Traffic
ET USER_AGENTS Observed Suspicious UA (NSIS_Inetc (Mozilla))
2036
WinRAR_Portable_Multiversion_32-64-bit_Multilingual_Online.exe
Potentially Bad Traffic
ET USER_AGENTS Observed Suspicious UA (NSIS_Inetc (Mozilla))
No debug info