File name:

pooler-cpuminer-2.5.0-win32.rar

Full analysis: https://app.any.run/tasks/8ee6551a-3a71-463d-a9b4-4c3106130c79
Verdict: Suspicious activity
Analysis date: August 21, 2018, 11:58:06
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

1F4DD0C43C1134D41ED6447F8B9ECC49

SHA1:

A7AFFF8E2AF993B926DECC85B6C36C967A39F282

SHA256:

C78FE41FC3C116F58FBDBFABE9F67615FC1FC9E645323A14692D4E7182235C7B

SSDEEP:

6144:I+zlSVYCDWASDhKOBq37BHBBIdcazV39ljaqPPOkpzxj7MXOXGPKYiyvej27joLi:JlSCl0Oq7BsdcMVtljJnj7KpKYGj2YLi

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • minerd.exe (PID: 768)
      • minerd.exe (PID: 1652)
      • minerd.exe (PID: 2556)
    • Loads dropped or rewritten executable

      • minerd.exe (PID: 768)
      • minerd.exe (PID: 1652)
      • minerd.exe (PID: 2556)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 1572)
  • INFO

    • Dropped object may contain URL's

      • WinRAR.exe (PID: 1572)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
39
Monitored processes
4
Malicious processes
0
Suspicious processes
4

Behavior graph

Click at the process to see the details
drop and start drop and start drop and start start winrar.exe minerd.exe no specs minerd.exe no specs minerd.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
768"C:\Users\admin\AppData\Local\Temp\Rar$EXa1572.42810\pooler-cpuminer-2.5.0-win32\minerd.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa1572.42810\pooler-cpuminer-2.5.0-win32\minerd.exeWinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
1
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa1572.42810\pooler-cpuminer-2.5.0-win32\minerd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\temp\rar$exa1572.42810\pooler-cpuminer-2.5.0-win32\libcurl-4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ws2_32.dll
1572"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\pooler-cpuminer-2.5.0-win32.rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
1652"C:\Users\admin\AppData\Local\Temp\Rar$EXa1572.42869\pooler-cpuminer-2.5.0-win32\minerd.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa1572.42869\pooler-cpuminer-2.5.0-win32\minerd.exeWinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
1
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa1572.42869\pooler-cpuminer-2.5.0-win32\minerd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\temp\rar$exa1572.42869\pooler-cpuminer-2.5.0-win32\libcurl-4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ws2_32.dll
2556"C:\Users\admin\AppData\Local\Temp\Rar$EXa1572.43928\pooler-cpuminer-2.5.0-win32\minerd.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa1572.43928\pooler-cpuminer-2.5.0-win32\minerd.exeWinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
1
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa1572.43928\pooler-cpuminer-2.5.0-win32\minerd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\temp\rar$exa1572.43928\pooler-cpuminer-2.5.0-win32\libcurl-4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ws2_32.dll
Total events
436
Read events
424
Write events
12
Delete events
0

Modification events

(PID) Process:(1572) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(1572) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(1572) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\59\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1572) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\pooler-cpuminer-2.5.0-win32.rar
(PID) Process:(1572) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(1572) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(1572) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(1572) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(1572) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(1572) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
Executable files
12
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
1572WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa1572.42810\pooler-cpuminer-2.5.0-win32\minerd.exeexecutable
MD5:D299DFEF00859284869C183540F8E381
SHA256:BCA59846AB83BC5BF5D9B956A8A4C2EC1F7525CA1BC2211D43BF8732158434FD
1572WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa1572.42810\pooler-cpuminer-2.5.0-win32\libcurl-4.dllexecutable
MD5:5B7AC25ACD989D7B8A34356C9756BAAE
SHA256:647C3B3EE1831BD4FF7352420998252FF829C1EC6422DF424B0A5B94A9B0F2AB
1572WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa1572.42810\pooler-cpuminer-2.5.0-win32\zlib1.dllexecutable
MD5:AF80FCB8F710F36157CBCB9385BA241C
SHA256:4A7DBFC031B1D84D153B418175C366B47C91BE0C587389C23E10A4B93FD7B9D6
1572WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa1572.43928\pooler-cpuminer-2.5.0-win32\zlib1.dllexecutable
MD5:AF80FCB8F710F36157CBCB9385BA241C
SHA256:4A7DBFC031B1D84D153B418175C366B47C91BE0C587389C23E10A4B93FD7B9D6
1572WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa1572.42810\pooler-cpuminer-2.5.0-win32\libwinpthread-1.dllexecutable
MD5:033B8B7A02840C53F11B116F829F5EE8
SHA256:B9A5F5E2B12A102259F1564610E120A719AFDC6B21577DDEFB76FEC0D6DFEC0F
1572WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa1572.42869\pooler-cpuminer-2.5.0-win32\libcurl-4.dllexecutable
MD5:5B7AC25ACD989D7B8A34356C9756BAAE
SHA256:647C3B3EE1831BD4FF7352420998252FF829C1EC6422DF424B0A5B94A9B0F2AB
1572WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa1572.42869\pooler-cpuminer-2.5.0-win32\libwinpthread-1.dllexecutable
MD5:033B8B7A02840C53F11B116F829F5EE8
SHA256:B9A5F5E2B12A102259F1564610E120A719AFDC6B21577DDEFB76FEC0D6DFEC0F
1572WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa1572.42869\pooler-cpuminer-2.5.0-win32\zlib1.dllexecutable
MD5:AF80FCB8F710F36157CBCB9385BA241C
SHA256:4A7DBFC031B1D84D153B418175C366B47C91BE0C587389C23E10A4B93FD7B9D6
1572WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa1572.43928\pooler-cpuminer-2.5.0-win32\libwinpthread-1.dllexecutable
MD5:033B8B7A02840C53F11B116F829F5EE8
SHA256:B9A5F5E2B12A102259F1564610E120A719AFDC6B21577DDEFB76FEC0D6DFEC0F
1572WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa1572.43928\pooler-cpuminer-2.5.0-win32\libcurl-4.dllexecutable
MD5:5B7AC25ACD989D7B8A34356C9756BAAE
SHA256:647C3B3EE1831BD4FF7352420998252FF829C1EC6422DF424B0A5B94A9B0F2AB
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info