File name:

Air Explorer Pro 5.4.3.7z

Full analysis: https://app.any.run/tasks/be9d6d02-b3d5-4b38-a65a-7a78db930dab
Verdict: Malicious activity
Analysis date: August 17, 2024, 14:11:28
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
opendir
netreactor
Indicators:
MIME: application/x-7z-compressed
File info: 7-zip archive data, version 0.3
MD5:

96CC7F6A324A403D1B09BA50009BCEBF

SHA1:

32AEF7658A21CC92A188A23C9C19E634C04A1EEC

SHA256:

C1AB44D5F5BA472483181F023F47019EE3BDDF142EB5C3BC3158A1A97CDAADCD

SSDEEP:

98304:9NUpcMOD+Yd6cKZHaqdcOHy6H8/P6/RF2P5ib8HpsspLn3ec7+e04/65ffSMPkdr:dDY2upBLjeYILuE2o2S

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • The process creates files with name similar to system file names

      • WinRAR.exe (PID: 6564)
      • AirExplorer-Installer 5.4.3.exe (PID: 6400)
    • Executable content was dropped or overwritten

      • AirExplorer-Installer 5.4.3.exe (PID: 6400)
    • Drops the executable file immediately after the start

      • AirExplorer-Installer 5.4.3.exe (PID: 6400)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • AirExplorer-Installer 5.4.3.exe (PID: 6400)
    • Reads security settings of Internet Explorer

      • ShellExperienceHost.exe (PID: 1656)
      • AirExplorer.exe (PID: 3276)
    • Changes Internet Explorer settings (feature browser emulation)

      • AirExplorer-Installer 5.4.3.exe (PID: 6400)
      • AirExplorer.exe (PID: 3276)
    • Creates a software uninstall entry

      • AirExplorer-Installer 5.4.3.exe (PID: 6400)
    • Process drops legitimate windows executable

      • AirExplorer-Installer 5.4.3.exe (PID: 6400)
    • Explorer used for Indirect Command Execution

      • explorer.exe (PID: 6972)
    • Checks Windows Trust Settings

      • AirExplorer.exe (PID: 3276)
  • INFO

    • Manual execution by a user

      • AirExplorer-Installer 5.4.3.exe (PID: 7020)
      • AirExplorer-Installer 5.4.3.exe (PID: 6400)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 6564)
    • Checks supported languages

      • AirExplorer-Installer 5.4.3.exe (PID: 6400)
      • ShellExperienceHost.exe (PID: 1656)
      • AirExplorer.exe (PID: 3276)
    • Reads the computer name

      • AirExplorer-Installer 5.4.3.exe (PID: 6400)
      • ShellExperienceHost.exe (PID: 1656)
      • AirExplorer.exe (PID: 3276)
    • Create files in a temporary directory

      • AirExplorer-Installer 5.4.3.exe (PID: 6400)
    • Creates files in the program directory

      • AirExplorer-Installer 5.4.3.exe (PID: 6400)
    • Reads security settings of Internet Explorer

      • explorer.exe (PID: 6468)
    • Reads Environment values

      • AirExplorer.exe (PID: 3276)
    • Disables trace logs

      • AirExplorer.exe (PID: 3276)
    • Reads the machine GUID from the registry

      • AirExplorer.exe (PID: 3276)
    • Checks proxy server information

      • AirExplorer.exe (PID: 3276)
    • Creates files or folders in the user directory

      • AirExplorer.exe (PID: 3276)
    • Reads the software policy settings

      • AirExplorer.exe (PID: 3276)
    • .NET Reactor protector has been detected

      • AirExplorer.exe (PID: 3276)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.7z | 7-Zip compressed archive (gen) (100)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
143
Monitored processes
8
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe rundll32.exe no specs airexplorer-installer 5.4.3.exe no specs airexplorer-installer 5.4.3.exe shellexperiencehost.exe no specs explorer.exe no specs explorer.exe no specs THREAT airexplorer.exe

Process information

PID
CMD
Path
Indicators
Parent process
1656"C:\WINDOWS\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe" -ServerName:App.AppXtk181tbxbce2qsex02s8tw7hfxa9xb3t.mcaC:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Shell Experience Host
Version:
10.0.19041.3758 (WinBuild.160101.0800)
Modules
Images
c:\windows\systemapps\shellexperiencehost_cw5n1h2txyewy\shellexperiencehost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\dxgi.dll
3276"C:\Program Files\AirExplorer\AirExplorer.exe" C:\Program Files\AirExplorer\AirExplorer.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Air Explorer
Version:
5.4.3.0
Modules
Images
c:\program files\airexplorer\airexplorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
6400"C:\Users\admin\Desktop\Air Explorer Pro 5.4.3\AirExplorer-Installer 5.4.3.exe" C:\Users\admin\Desktop\Air Explorer Pro 5.4.3\AirExplorer-Installer 5.4.3.exe
explorer.exe
User:
admin
Company:
Iniciativas Informaticas
Integrity Level:
HIGH
Exit code:
0
Version:
${Version}
Modules
Images
c:\users\admin\desktop\air explorer pro 5.4.3\airexplorer-installer 5.4.3.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
6468C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -EmbeddingC:\Windows\System32\rundll32.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shcore.dll
c:\windows\system32\imagehlp.dll
6468C:\WINDOWS\explorer.exe /factory,{75dff2b7-6936-4c06-a8bb-676a7b00b24b} -EmbeddingC:\Windows\explorer.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
1
Version:
10.0.19041.3758 (WinBuild.160101.0800)
Modules
Images
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\shcore.dll
6564"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Air Explorer Pro 5.4.3.7z"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
6972"C:\WINDOWS\explorer.exe" "C:\Program Files\AirExplorer\AirExplorer.exe"C:\Windows\explorer.exeAirExplorer-Installer 5.4.3.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Explorer
Exit code:
1
Version:
10.0.19041.3758 (WinBuild.160101.0800)
Modules
Images
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
7020"C:\Users\admin\Desktop\Air Explorer Pro 5.4.3\AirExplorer-Installer 5.4.3.exe" C:\Users\admin\Desktop\Air Explorer Pro 5.4.3\AirExplorer-Installer 5.4.3.exeexplorer.exe
User:
admin
Company:
Iniciativas Informaticas
Integrity Level:
MEDIUM
Exit code:
3221226540
Version:
${Version}
Modules
Images
c:\users\admin\desktop\air explorer pro 5.4.3\airexplorer-installer 5.4.3.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
Total events
15 659
Read events
15 614
Write events
45
Delete events
0

Modification events

(PID) Process:(6564) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(6564) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(6564) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface
Operation:writeName:ShowPassword
Value:
0
(PID) Process:(6564) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\GoogleChromeEnterpriseBundle64.zip
(PID) Process:(6564) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Air Explorer Pro 5.4.3.7z
(PID) Process:(6564) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(6564) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(6564) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(6564) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(6564) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\DialogEditHistory\ExtrPath
Operation:writeName:0
Value:
C:\Users\admin\Desktop
Executable files
30
Suspicious files
20
Text files
40
Unknown types
0

Dropped files

PID
Process
Filename
Type
6400AirExplorer-Installer 5.4.3.exeC:\Users\admin\AppData\Local\Temp\nsiC2DF.tmp\System.dllexecutable
MD5:8CF2AC271D7679B1D68EEFC1AE0C5618
SHA256:6950991102462D84FDC0E3B0AE30C95AF8C192F77CE3D78E8D54E6B22F7C09BA
6564WinRAR.exeC:\Users\admin\Desktop\Air Explorer Pro 5.4.3\Crack\AirExplorerCmd.exeexecutable
MD5:E6D4CCE69EF16649A28F3DED80F17CCF
SHA256:8CF859F337169A25C7B0A5D037373DB61802F790C317FD496377CB8C5D51CF20
6400AirExplorer-Installer 5.4.3.exeC:\Program Files\AirExplorer\KRBTabControl.dllexecutable
MD5:0E77E3D906A34215600C79B5F509E8E4
SHA256:FB247790D844A9B40A5C81C5526E975750A98F36F8B153F70EE72CF8CD8AB2C8
6400AirExplorer-Installer 5.4.3.exeC:\Users\admin\AppData\Local\Temp\nsiC2DF.tmp\LangDLL.dllexecutable
MD5:109B201717AB5EF9B5628A9F3EFEF36F
SHA256:20E642707EF82852BCF153254CB94B629B93EE89A8E8A03F838EEF6CBB493319
6400AirExplorer-Installer 5.4.3.exeC:\Users\admin\AppData\Local\Temp\nsiC2DF.tmp\modern-wizard.bmpimage
MD5:D4F9E3AE2BEE512281446A87C03528DE
SHA256:46F46315BD66AE6531D701ED02E1C9BDF364CEB67E43D9BC757BD7B5E8A1A898
6400AirExplorer-Installer 5.4.3.exeC:\Program Files\AirExplorer\Microsoft.WindowsAPICodePack.Shell.dllexecutable
MD5:6D8DEB7BE7360761FD43EC9DDCAA0811
SHA256:AA5D80CDC0DA52970031309B457E3E3FD505BB1AC13FB79801D15BFBB4A700B2
6400AirExplorer-Installer 5.4.3.exeC:\Program Files\AirExplorer\AirExplorerCmd.exeexecutable
MD5:A50926116B0FCBD94C8B3D09673DF3BD
SHA256:29ECF85E8933AC1DC54190A10800FCC9585AFF2EB475A535AF7A7719089E3FEF
6564WinRAR.exeC:\Users\admin\Desktop\Air Explorer Pro 5.4.3\Скачано с 1progs.com.urlbinary
MD5:37338CE4FE7F242E2C385F3789A57795
SHA256:EBFA6FFD55EF741785A722F9A281542CBD9CC3F64CA7E5BE2E431C9DDF056B80
6400AirExplorer-Installer 5.4.3.exeC:\Program Files\AirExplorer\AirExplorer.exeexecutable
MD5:41B47D2E695EAA8E9CC1AE15496754C8
SHA256:10ED15766860932BD834343582C9DB0186EBEC34A0F778D05B6E2EB8C7DEC08D
6400AirExplorer-Installer 5.4.3.exeC:\Program Files\AirExplorer\CircularProgressBar.dllexecutable
MD5:E3E063960755CB09EFD78B5D88349E98
SHA256:49CB487E04374BB027E54DA755F79FD6A2F2E9D328C4A95E43C1DDEC71F733A2
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
13
TCP/UDP connections
46
DNS requests
26
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5336
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
640
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
3276
AirExplorer.exe
GET
200
95.101.111.186:80
http://subca.ocsp-certum.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTYOkzrrCGQj08njZXbUQQpkoUmuQQUCHbNywf%2FJPbFze27kLzihDdGdfcCEBu1jyUq3yMASSjJrj1%2B7Sc%3D
unknown
whitelisted
6988
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
6772
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
3276
AirExplorer.exe
GET
200
95.101.111.162:80
http://ccsca2021.ocsp-certum.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRxypYNH69rICCzQBIRXN0YAFa3AAQU3XRdTADbe5%2BgdMqxbvc8wDLAcM0CEEscjPKw%2Bjzc1ISguR3v99g%3D
unknown
whitelisted
3276
AirExplorer.exe
GET
200
95.101.111.186:80
http://subca.ocsp-certum.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTYOkzrrCGQj08njZXbUQQpkoUmuQQUCHbNywf%2FJPbFze27kLzihDdGdfcCEBu1jyUq3yMASSjJrj1%2B7Sc%3D
unknown
whitelisted
3276
AirExplorer.exe
GET
200
95.101.111.151:80
http://crl.certum.pl/ctnca.crl
unknown
whitelisted
3276
AirExplorer.exe
GET
200
95.101.111.186:80
http://subca.ocsp-certum.com/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBRIH1V64SBkA%2BzJQVQ6VFBAcvLB3wQUtqFUOQLDoD%2BOirz61PgcptE6Dv0CEQCZo4AKJlU7ZavcboSms%2Bo5
unknown
whitelisted
3276
AirExplorer.exe
GET
200
104.18.38.233:80
http://ocsp.comodoca.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRTtU9uFqgVGHhJwXZyWCNXmVR5ngQUoBEKIz6W8Qfs4q8p74Klf9AwpLQCEDlyRDr5IrdR19NsEN0xNZU%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4936
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2120
MoUsoCoreWorker.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
3520
RUXIMICS.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
3888
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:137
whitelisted
4936
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5336
SearchApp.exe
104.126.37.130:443
www.bing.com
Akamai International B.V.
DE
unknown
5336
SearchApp.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
640
svchost.exe
20.190.159.2:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 4.231.128.59
  • 51.104.136.2
whitelisted
google.com
  • 142.250.185.174
whitelisted
www.bing.com
  • 104.126.37.130
  • 104.126.37.137
  • 104.126.37.128
  • 104.126.37.144
  • 104.126.37.131
  • 104.126.37.154
  • 104.126.37.170
  • 104.126.37.153
  • 104.126.37.162
  • 2.23.209.143
  • 2.23.209.130
  • 2.23.209.189
  • 2.23.209.141
  • 2.23.209.133
  • 2.23.209.187
  • 2.23.209.140
  • 2.23.209.135
  • 2.23.209.131
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
login.live.com
  • 20.190.159.2
  • 20.190.159.71
  • 20.190.159.4
  • 20.190.159.0
  • 20.190.159.68
  • 20.190.159.23
  • 40.126.31.69
  • 40.126.31.73
whitelisted
client.wns.windows.com
  • 40.113.110.67
  • 40.113.103.199
whitelisted
th.bing.com
  • 104.126.37.162
  • 104.126.37.128
  • 104.126.37.153
  • 104.126.37.131
  • 104.126.37.130
  • 104.126.37.170
  • 104.126.37.154
  • 104.126.37.144
  • 104.126.37.137
whitelisted
arc.msn.com
  • 20.223.36.55
whitelisted
slscr.update.microsoft.com
  • 20.12.23.50
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted

Threats

No threats detected
No debug info