File name:

PhoenixUSBPro.rar

Full analysis: https://app.any.run/tasks/f1c24048-43a9-4dcc-a24b-bef38f2e3760
Verdict: Malicious activity
Analysis date: March 17, 2021, 22:10:57
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v4, os: Win32
MD5:

43DE8498A155B6623246B52E747AB236

SHA1:

3070F4C34221499F50E0F0B2A5F0D3EE4BE408C9

SHA256:

C229F5C08CE7EDC89B128D8715D5D465D45AC51B4AC7F9C055E7726F3DAA50CA

SSDEEP:

98304:ZewtJTt5r/y0VDt0M2KEETbsKBNV5TmARqvEPHPUjhdUSxx1q:ZeaRTr7z91rVgAMvFdhe

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops executable file immediately after starts

      • WinRAR.exe (PID: 2560)
    • Loads dropped or rewritten executable

      • SearchProtocolHost.exe (PID: 3112)
      • explorer.exe (PID: 656)
      • PhoenixUSBPro.exe (PID: 680)
      • UpdateVerEx.exe (PID: 2452)
    • Application was dropped or rewritten from another process

      • PhoenixUSBPro.exe (PID: 680)
      • PhoenixUSBPro.exe (PID: 2416)
      • UpdateVerEx.exe (PID: 2452)
  • SUSPICIOUS

    • Creates files in the user directory

      • explorer.exe (PID: 656)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2560)
    • Drops a file with too old compile date

      • WinRAR.exe (PID: 2560)
    • Drops a file that was compiled in debug mode

      • WinRAR.exe (PID: 2560)
  • INFO

    • Manual execution by user

      • WinRAR.exe (PID: 2540)
      • WinRAR.exe (PID: 2560)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v-4.x) (58.3)
.rar | RAR compressed archive (gen) (41.6)

EXIF

ZIP

CompressedSize: 41460
UncompressedSize: 126976
OperatingSystem: Win32
ModifyDate: 2019:11:06 14:28:26
PackingMethod: Normal
ArchivedFileName: PhoenixUSBPro\AWCtrl.dll
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
49
Monitored processes
8
Malicious processes
5
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe no specs winrar.exe no specs winrar.exe searchprotocolhost.exe no specs explorer.exe no specs phoenixusbpro.exe no specs phoenixusbpro.exe updateverex.exe

Process information

PID
CMD
Path
Indicators
Parent process
656C:\Windows\Explorer.EXEC:\Windows\explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\winanr.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
680"C:\Users\admin\Desktop\PhoenixUSBPro\PhoenixUSBPro.exe" C:\Users\admin\Desktop\PhoenixUSBPro\PhoenixUSBPro.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Description:
PhoenixUSBPro Microsoft 基础类应用程序
Exit code:
0
Version:
1, 0, 0, 1
Modules
Images
c:\users\admin\desktop\phoenixusbpro\phoenixusbpro.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2416"C:\Users\admin\Desktop\PhoenixUSBPro\PhoenixUSBPro.exe" C:\Users\admin\Desktop\PhoenixUSBPro\PhoenixUSBPro.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
PhoenixUSBPro Microsoft 基础类应用程序
Exit code:
3221226540
Version:
1, 0, 0, 1
Modules
Images
c:\users\admin\desktop\phoenixusbpro\phoenixusbpro.exe
c:\systemroot\system32\ntdll.dll
2452"C:\Users\admin\Desktop\PhoenixUSBPro\UpdateVerEx.exe" C:\Users\admin\Desktop\PhoenixUSBPro\UpdateVerEx.exe
PhoenixUSBPro.exe
User:
admin
Company:
AllWinner CO.LTD
Integrity Level:
HIGH
Description:
UpdateVer
Exit code:
0
Version:
1.0.0.1
Modules
Images
c:\users\admin\desktop\phoenixusbpro\updateverex.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\psapi.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
2540"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\PhoenixUSBPro.rar"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2560"C:\Program Files\WinRAR\WinRAR.exe" x -iext -ow -ver -- "C:\Users\admin\Desktop\PhoenixUSBPro.rar" C:\Users\admin\Desktop\C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3112"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe2_ Global\UsGthrCtrlFltPipeMssGthrPipe2 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" C:\Windows\System32\SearchProtocolHost.exeSearchIndexer.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Windows Search Protocol Host
Exit code:
0
Version:
7.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\searchprotocolhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3840"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\PhoenixUSBPro.rar"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
Total events
4 493
Read events
4 307
Write events
185
Delete events
1

Modification events

(PID) Process:(3840) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3840) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2540) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2540) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(656) explorer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
Operation:writeName:{7P5N40RS-N0SO-4OSP-874N-P0S2R0O9SN8R}\JvaENE\JvaENE.rkr
Value:
00000000020000000000000097060000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF30A501797A1BD70100000000
(PID) Process:(656) explorer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
Operation:writeName:HRZR_PGYFRFFVBA
Value:
000000006B0000009D000000D87546001000000034000000869716007B00460033003800420046003400300034002D0031004400340033002D0034003200460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E0065007800650000001CE5A3009B62D0760B7C6697FEFFFFFFFA53CB76F5F3C774E6F4C774245C13E1A8E5A300C110000000000000C00001000000000000000000A8E5A30024E5A3003851CB76C0000100820200000100000000000000000000006CE5A300D150CB76C00001008202000001000000E850CB7667CD0EE182020000E8A21C000000000000000000000000003CE5A300D0E5A300A8E7A3009B62D076FB786697FEFFFFFFE850CB762A00C874C000010082020000010000000000000000000000E8A21C0054FFC774C000010001000000FFFFFFFFFFFFFFFF90C5CB7641C6CB764E00000000000000000000000000000074E5A30011000000483D1700403D170003EE66971CA31C00FEC5CB7640E6000007C90EE1F4E5A3008291167740E6A300944C00002BC90EE108E6A300B69C1677984CCE024C06000020E6A3000848CE022CE6A30011000000483D1700403D170020E6A3002848CE0290E60000F3CA0EE140E6A3008291167790E6A30044E6A3002795167700000000944CCE026CE6A300CD941677944CCE0218E7A3000848CE02E1941677000000000848CE0218E7A30074E6A3001000000034000000869716007B00460033003800420046003400300034002D0031004400340033002D0034003200460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E0065007800650000001CE5A3009B62D0760B7C6697FEFFFFFFFA53CB76F5F3C774E6F4C774245C13E1A8E5A300C110000000000000C00001000000000000000000A8E5A30024E5A3003851CB76C0000100820200000100000000000000000000006CE5A300D150CB76C00001008202000001000000E850CB7667CD0EE182020000E8A21C000000000000000000000000003CE5A300D0E5A300A8E7A3009B62D076FB786697FEFFFFFFE850CB762A00C874C000010082020000010000000000000000000000E8A21C0054FFC774C000010001000000FFFFFFFFFFFFFFFF90C5CB7641C6CB764E00000000000000000000000000000074E5A30011000000483D1700403D170003EE66971CA31C00FEC5CB7640E6000007C90EE1F4E5A3008291167740E6A300944C00002BC90EE108E6A300B69C1677984CCE024C06000020E6A3000848CE022CE6A30011000000483D1700403D170020E6A3002848CE0290E60000F3CA0EE140E6A3008291167790E6A30044E6A3002795167700000000944CCE026CE6A300CD941677944CCE0218E7A3000848CE02E1941677000000000848CE0218E7A30074E6A3001000000034000000869716007B00460033003800420046003400300034002D0031004400340033002D0034003200460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E0065007800650000001CE5A3009B62D0760B7C6697FEFFFFFFFA53CB76F5F3C774E6F4C774245C13E1A8E5A300C110000000000000C00001000000000000000000A8E5A30024E5A3003851CB76C0000100820200000100000000000000000000006CE5A300D150CB76C00001008202000001000000E850CB7667CD0EE182020000E8A21C000000000000000000000000003CE5A300D0E5A300A8E7A3009B62D076FB786697FEFFFFFFE850CB762A00C874C000010082020000010000000000000000000000E8A21C0054FFC774C000010001000000FFFFFFFFFFFFFFFF90C5CB7641C6CB764E00000000000000000000000000000074E5A30011000000483D1700403D170003EE66971CA31C00FEC5CB7640E6000007C90EE1F4E5A3008291167740E6A300944C00002BC90EE108E6A300B69C1677984CCE024C06000020E6A3000848CE022CE6A30011000000483D1700403D170020E6A3002848CE0290E60000F3CA0EE140E6A3008291167790E6A30044E6A3002795167700000000944CCE026CE6A300CD941677944CCE0218E7A3000848CE02E1941677000000000848CE0218E7A30074E6A300
(PID) Process:(3840) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\13D\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3840) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\13D\52C64B7E
Operation:writeName:@C:\Windows\system32\NetworkExplorer.dll,-1
Value:
Network
(PID) Process:(3840) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\PhoenixUSBPro.rar
(PID) Process:(3840) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
Executable files
46
Suspicious files
4
Text files
18
Unknown types
17

Dropped files

PID
Process
Filename
Type
656explorer.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\1b4dd67f29cb1962.automaticDestinations-msautomaticdestinations-ms
MD5:
SHA256:
656explorer.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\PhoenixUSBPro.rar.lnklnk
MD5:
SHA256:
656explorer.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\290532160612e071.automaticDestinations-msautomaticdestinations-ms
MD5:
SHA256:
2560WinRAR.exeC:\Users\admin\Desktop\PhoenixUSBPro\drvinstaller_X86.exeexecutable
MD5:7FE202816C386C6A1DEE20E9F4EAF438
SHA256:437E4C3CA2780D3D11E14019FDFDD738F0202DCF83514CB0D09E7CC6FAAACF10
2560WinRAR.exeC:\Users\admin\Desktop\PhoenixUSBPro\checkver.ulfout
MD5:A962B391ADE07033D089605F4D5C315E
SHA256:A4D0B5550CF49AFFAEA0FA7D65249DE6AABDBF69695726DCBD3786DBA6134A37
2560WinRAR.exeC:\Users\admin\Desktop\PhoenixUSBPro\compress.dllexecutable
MD5:23EA964BFB27FF637643DD8E4AED0F05
SHA256:1001018ACEEB3D67DF4F6E3BDDE464A0CB1F10E75F0A7AB506F20EA7A1C85F2C
2560WinRAR.exeC:\Users\admin\Desktop\PhoenixUSBPro\common_fun.lhsout
MD5:3688587FAE964ACCA3E4A74BB2F423A7
SHA256:23DA883B7BBC5EC996E5B8A3DC511A3A9DEB01FF35E9D07049BB92C5F3ABC8FE
2560WinRAR.exeC:\Users\admin\Desktop\PhoenixUSBPro\AwPluginVector.dllexecutable
MD5:E86408FA024A379D59B7F0A5AD1B5547
SHA256:3FD9D74BE097CE7FB3FA647BA6A2DCC787D03614A8E7318E2FA147B822458B51
2560WinRAR.exeC:\Users\admin\Desktop\PhoenixUSBPro\AWCtrl.dllexecutable
MD5:BFF71057C554C29FA13DBED10E676BDE
SHA256:A732C6D87D56CB1C44C944A97B6FF4A015057A4B9D5E86521E009162646B5D5C
2560WinRAR.exeC:\Users\admin\Desktop\PhoenixUSBPro\bg.PNGimage
MD5:BF7306AE63DBB0A3AC76E60C9D04E8C6
SHA256:2C33D0BE8AEC70B34585326B3742888612C8BF80F315D08529D6506EC7565E68
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
1
DNS requests
0
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2452
UpdateVerEx.exe
GET
61.143.38.50:80
http://61.143.38.50/eStudio/VersionTab.ulf
CN
malicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
61.143.38.50:80
Guangdong
CN
malicious

DNS requests

No data

Threats

No threats detected
Process
Message
PhoenixUSBPro.exe
Init Load Device Record Size:7
PhoenixUSBPro.exe
Hello from OnInitDialog
UpdateVerEx.exe
Checkver:Current Version is 4000