analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

ValyseOfficialRelease1.4.1-b.2.zip

Full analysis: https://app.any.run/tasks/d7fa7110-e9b0-412e-ab6d-d40950bc3fa4
Verdict: Malicious activity
Analysis date: April 01, 2023, 15:53:23
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

5A0901DFDB36813E50F9A779A6841D1F

SHA1:

385087AA72B713CC19190C7D364062020DC976D8

SHA256:

C1EAB41CFDB38CB9E3C7DAB2BCAA8F80AEEB7A1D17485853C6D9624EF6A44185

SSDEEP:

196608:qOBYd/QUPKCBFcHyxu1GHbnqVHJHfPhgNtMmfYdHgDK+E98Fh:qOBsPP35vHkHhgTMmAdHgDYw

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Valyse Launcher.exe (PID: 3636)
      • Valyse Launcher.exe (PID: 2772)
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    • Reads the computer name

      • Valyse Launcher.exe (PID: 3636)
      • Valyse Launcher.exe (PID: 2772)
    • Checks supported languages

      • Valyse Launcher.exe (PID: 3636)
      • Valyse Launcher.exe (PID: 2772)
    • Reads the machine GUID from the registry

      • Valyse Launcher.exe (PID: 2772)
      • Valyse Launcher.exe (PID: 3636)
    • The process checks LSA protection

      • Valyse Launcher.exe (PID: 2772)
      • Valyse Launcher.exe (PID: 3636)
    • Manual execution by a user

      • Valyse Launcher.exe (PID: 3636)
      • Valyse Launcher.exe (PID: 2772)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2664)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2023:03:09 00:45:04
ZipCRC: 0xd892f8c6
ZipCompressedSize: 10204512
ZipUncompressedSize: 10306048
ZipFileName: Valyse Launcher.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
38
Monitored processes
3
Malicious processes
1
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe valyse launcher.exe no specs valyse launcher.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2664"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\ValyseOfficialRelease1.4.1-b.2.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
2772"C:\Users\admin\Desktop\Valyse\Valyse Launcher.exe" C:\Users\admin\Desktop\Valyse\Valyse Launcher.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
ValyseLauncher
Exit code:
1
Version:
1.0.0.0
Modules
Images
c:\windows\system32\ntdll.dll
c:\users\admin\desktop\valyse\valyse launcher.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\mscoree.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
3636"C:\Users\admin\Desktop\Valyse\Valyse Launcher.exe" C:\Users\admin\Desktop\Valyse\Valyse Launcher.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
ValyseLauncher
Version:
1.0.0.0
Modules
Images
c:\windows\system32\ntdll.dll
c:\users\admin\desktop\valyse\valyse launcher.exe
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
Total events
3 064
Read events
3 048
Write events
16
Delete events
0

Modification events

(PID) Process:(2664) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16D\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2664) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(2664) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(2664) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(2664) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2664) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2664) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2664) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
Executable files
2
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
2664WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2664.41129\Valyse Launcher.exeexecutable
MD5:0FD78804897C07936D54739B8E65FB49
SHA256:4205B5EDDC13A65524AD26863CE048CA67EA2CCA3BAE20DDCC73D7CCE926F8C7
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info