File name:

PhoenixUSBPro.rar

Full analysis: https://app.any.run/tasks/f1c24048-43a9-4dcc-a24b-bef38f2e3760
Verdict: Malicious activity
Analysis date: March 17, 2021, 22:10:57
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v4, os: Win32
MD5:

43DE8498A155B6623246B52E747AB236

SHA1:

3070F4C34221499F50E0F0B2A5F0D3EE4BE408C9

SHA256:

C229F5C08CE7EDC89B128D8715D5D465D45AC51B4AC7F9C055E7726F3DAA50CA

SSDEEP:

98304:ZewtJTt5r/y0VDt0M2KEETbsKBNV5TmARqvEPHPUjhdUSxx1q:ZeaRTr7z91rVgAMvFdhe

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • SearchProtocolHost.exe (PID: 3112)
      • explorer.exe (PID: 656)
      • PhoenixUSBPro.exe (PID: 680)
      • UpdateVerEx.exe (PID: 2452)
    • Drops executable file immediately after starts

      • WinRAR.exe (PID: 2560)
    • Application was dropped or rewritten from another process

      • PhoenixUSBPro.exe (PID: 2416)
      • PhoenixUSBPro.exe (PID: 680)
      • UpdateVerEx.exe (PID: 2452)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2560)
    • Creates files in the user directory

      • explorer.exe (PID: 656)
    • Drops a file with too old compile date

      • WinRAR.exe (PID: 2560)
    • Drops a file that was compiled in debug mode

      • WinRAR.exe (PID: 2560)
  • INFO

    • Manual execution by user

      • WinRAR.exe (PID: 2560)
      • WinRAR.exe (PID: 2540)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v-4.x) (58.3)
.rar | RAR compressed archive (gen) (41.6)

EXIF

ZIP

CompressedSize: 41460
UncompressedSize: 126976
OperatingSystem: Win32
ModifyDate: 2019:11:06 14:28:26
PackingMethod: Normal
ArchivedFileName: PhoenixUSBPro\AWCtrl.dll
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
49
Monitored processes
8
Malicious processes
5
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe no specs winrar.exe no specs winrar.exe searchprotocolhost.exe no specs explorer.exe no specs phoenixusbpro.exe no specs phoenixusbpro.exe updateverex.exe

Process information

PID
CMD
Path
Indicators
Parent process
656C:\Windows\Explorer.EXEC:\Windows\explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\winanr.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
680"C:\Users\admin\Desktop\PhoenixUSBPro\PhoenixUSBPro.exe" C:\Users\admin\Desktop\PhoenixUSBPro\PhoenixUSBPro.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Description:
PhoenixUSBPro Microsoft 基础类应用程序
Exit code:
0
Version:
1, 0, 0, 1
Modules
Images
c:\users\admin\desktop\phoenixusbpro\phoenixusbpro.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2416"C:\Users\admin\Desktop\PhoenixUSBPro\PhoenixUSBPro.exe" C:\Users\admin\Desktop\PhoenixUSBPro\PhoenixUSBPro.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
PhoenixUSBPro Microsoft 基础类应用程序
Exit code:
3221226540
Version:
1, 0, 0, 1
Modules
Images
c:\users\admin\desktop\phoenixusbpro\phoenixusbpro.exe
c:\systemroot\system32\ntdll.dll
2452"C:\Users\admin\Desktop\PhoenixUSBPro\UpdateVerEx.exe" C:\Users\admin\Desktop\PhoenixUSBPro\UpdateVerEx.exe
PhoenixUSBPro.exe
User:
admin
Company:
AllWinner CO.LTD
Integrity Level:
HIGH
Description:
UpdateVer
Exit code:
0
Version:
1.0.0.1
Modules
Images
c:\users\admin\desktop\phoenixusbpro\updateverex.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\psapi.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
2540"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\PhoenixUSBPro.rar"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2560"C:\Program Files\WinRAR\WinRAR.exe" x -iext -ow -ver -- "C:\Users\admin\Desktop\PhoenixUSBPro.rar" C:\Users\admin\Desktop\C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3112"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe2_ Global\UsGthrCtrlFltPipeMssGthrPipe2 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" C:\Windows\System32\SearchProtocolHost.exeSearchIndexer.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Windows Search Protocol Host
Exit code:
0
Version:
7.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\searchprotocolhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3840"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\PhoenixUSBPro.rar"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
Total events
4 493
Read events
4 307
Write events
185
Delete events
1

Modification events

(PID) Process:(3840) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3840) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2540) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2540) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(656) explorer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
Operation:writeName:{7P5N40RS-N0SO-4OSP-874N-P0S2R0O9SN8R}\JvaENE\JvaENE.rkr
Value:
00000000020000000000000097060000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF30A501797A1BD70100000000
(PID) Process:(656) explorer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
Operation:writeName:HRZR_PGYFRFFVBA
Value:
000000006B0000009D000000D87546001000000034000000869716007B00460033003800420046003400300034002D0031004400340033002D0034003200460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E0065007800650000001CE5A3009B62D0760B7C6697FEFFFFFFFA53CB76F5F3C774E6F4C774245C13E1A8E5A300C110000000000000C00001000000000000000000A8E5A30024E5A3003851CB76C0000100820200000100000000000000000000006CE5A300D150CB76C00001008202000001000000E850CB7667CD0EE182020000E8A21C000000000000000000000000003CE5A300D0E5A300A8E7A3009B62D076FB786697FEFFFFFFE850CB762A00C874C000010082020000010000000000000000000000E8A21C0054FFC774C000010001000000FFFFFFFFFFFFFFFF90C5CB7641C6CB764E00000000000000000000000000000074E5A30011000000483D1700403D170003EE66971CA31C00FEC5CB7640E6000007C90EE1F4E5A3008291167740E6A300944C00002BC90EE108E6A300B69C1677984CCE024C06000020E6A3000848CE022CE6A30011000000483D1700403D170020E6A3002848CE0290E60000F3CA0EE140E6A3008291167790E6A30044E6A3002795167700000000944CCE026CE6A300CD941677944CCE0218E7A3000848CE02E1941677000000000848CE0218E7A30074E6A3001000000034000000869716007B00460033003800420046003400300034002D0031004400340033002D0034003200460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E0065007800650000001CE5A3009B62D0760B7C6697FEFFFFFFFA53CB76F5F3C774E6F4C774245C13E1A8E5A300C110000000000000C00001000000000000000000A8E5A30024E5A3003851CB76C0000100820200000100000000000000000000006CE5A300D150CB76C00001008202000001000000E850CB7667CD0EE182020000E8A21C000000000000000000000000003CE5A300D0E5A300A8E7A3009B62D076FB786697FEFFFFFFE850CB762A00C874C000010082020000010000000000000000000000E8A21C0054FFC774C000010001000000FFFFFFFFFFFFFFFF90C5CB7641C6CB764E00000000000000000000000000000074E5A30011000000483D1700403D170003EE66971CA31C00FEC5CB7640E6000007C90EE1F4E5A3008291167740E6A300944C00002BC90EE108E6A300B69C1677984CCE024C06000020E6A3000848CE022CE6A30011000000483D1700403D170020E6A3002848CE0290E60000F3CA0EE140E6A3008291167790E6A30044E6A3002795167700000000944CCE026CE6A300CD941677944CCE0218E7A3000848CE02E1941677000000000848CE0218E7A30074E6A3001000000034000000869716007B00460033003800420046003400300034002D0031004400340033002D0034003200460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E0065007800650000001CE5A3009B62D0760B7C6697FEFFFFFFFA53CB76F5F3C774E6F4C774245C13E1A8E5A300C110000000000000C00001000000000000000000A8E5A30024E5A3003851CB76C0000100820200000100000000000000000000006CE5A300D150CB76C00001008202000001000000E850CB7667CD0EE182020000E8A21C000000000000000000000000003CE5A300D0E5A300A8E7A3009B62D076FB786697FEFFFFFFE850CB762A00C874C000010082020000010000000000000000000000E8A21C0054FFC774C000010001000000FFFFFFFFFFFFFFFF90C5CB7641C6CB764E00000000000000000000000000000074E5A30011000000483D1700403D170003EE66971CA31C00FEC5CB7640E6000007C90EE1F4E5A3008291167740E6A300944C00002BC90EE108E6A300B69C1677984CCE024C06000020E6A3000848CE022CE6A30011000000483D1700403D170020E6A3002848CE0290E60000F3CA0EE140E6A3008291167790E6A30044E6A3002795167700000000944CCE026CE6A300CD941677944CCE0218E7A3000848CE02E1941677000000000848CE0218E7A30074E6A300
(PID) Process:(3840) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\13D\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3840) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\13D\52C64B7E
Operation:writeName:@C:\Windows\system32\NetworkExplorer.dll,-1
Value:
Network
(PID) Process:(3840) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\PhoenixUSBPro.rar
(PID) Process:(3840) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
Executable files
46
Suspicious files
4
Text files
18
Unknown types
17

Dropped files

PID
Process
Filename
Type
656explorer.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\290532160612e071.automaticDestinations-msautomaticdestinations-ms
MD5:
SHA256:
656explorer.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\1b4dd67f29cb1962.automaticDestinations-msautomaticdestinations-ms
MD5:
SHA256:
656explorer.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\PhoenixUSBPro.rar.lnklnk
MD5:
SHA256:
2560WinRAR.exeC:\Users\admin\Desktop\PhoenixUSBPro\common_fun.lhsout
MD5:3688587FAE964ACCA3E4A74BB2F423A7
SHA256:23DA883B7BBC5EC996E5B8A3DC511A3A9DEB01FF35E9D07049BB92C5F3ABC8FE
2560WinRAR.exeC:\Users\admin\Desktop\PhoenixUSBPro\bg.PNGimage
MD5:BF7306AE63DBB0A3AC76E60C9D04E8C6
SHA256:2C33D0BE8AEC70B34585326B3742888612C8BF80F315D08529D6506EC7565E68
2560WinRAR.exeC:\Users\admin\Desktop\PhoenixUSBPro\drvinstaller_X64.exeexecutable
MD5:289D9BA8B0C3E83B05B3036F73FE65A4
SHA256:AF79841A6E03CC8DE1ED1FEFC6FA6B9C84DECF6B9BF83EB0A6601A641878D689
2560WinRAR.exeC:\Users\admin\Desktop\PhoenixUSBPro\drvinstaller_IA64.exeexecutable
MD5:634431312B6F0ACA8EAFFCFBD1482105
SHA256:262A39E3D27BD09272651EBCEA61538F00FEF4EEA3FDDB0814FC2F6F7CE8886F
2560WinRAR.exeC:\Users\admin\Desktop\PhoenixUSBPro\drvinstaller_X86.exeexecutable
MD5:7FE202816C386C6A1DEE20E9F4EAF438
SHA256:437E4C3CA2780D3D11E14019FDFDD738F0202DCF83514CB0D09E7CC6FAAACF10
2560WinRAR.exeC:\Users\admin\Desktop\PhoenixUSBPro\Dbgview.exeexecutable
MD5:BAACA87FE5AC99E0F1442B54E03056F4
SHA256:1244BD02A203BEC1B1E0AB85ED8ED83501EC4D17E613F1934951ABEB7956ABB0
2560WinRAR.exeC:\Users\admin\Desktop\PhoenixUSBPro\dbgview.chmchm
MD5:C7517AF60D377F3FEAAE84DBC279E0E9
SHA256:E439D04D29C173AD2B4FFBAA74CE6D2312F0ED9D92EF34ABDBC58D41B9B0A1CC
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
1
DNS requests
0
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2452
UpdateVerEx.exe
GET
61.143.38.50:80
http://61.143.38.50/eStudio/VersionTab.ulf
CN
malicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
61.143.38.50:80
Guangdong
CN
malicious

DNS requests

No data

Threats

No threats detected
Process
Message
PhoenixUSBPro.exe
Init Load Device Record Size:7
PhoenixUSBPro.exe
Hello from OnInitDialog
UpdateVerEx.exe
Checkver:Current Version is 4000