File name:

Total Commander v8.51a Final Ml_Rus (DC 20.01.2015).rar

Full analysis: https://app.any.run/tasks/55c41506-c62d-47c1-9446-7a701e787b07
Verdict: Malicious activity
Analysis date: June 17, 2021, 10:05:49
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v4, os: Win32
MD5:

29331BFB37DA41FECAB7D8EE8E06B816

SHA1:

B6D4CA1DDB156C86A30FE431E62FECA36887FF00

SHA256:

D1444837980900BCBBA335654E7BC58B8B64ADA4C833C376528E30C43AF42B64

SSDEEP:

393216:hoZRCv8+Pm5nqH2fsUILkdL6G0/Tr1MPLkvxV/VN:h2Lh6GsXk8f1MP09b

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • tcmd851ax32.exe (PID: 2976)
      • tcmd851ax32.exe (PID: 4012)
      • tcmd851ax32_64.exe (PID: 2812)
      • tcmd851ax32_64.exe (PID: 2348)
      • TOTALCMD.EXE (PID: 2600)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2344)
      • tcmd851ax32_64.exe (PID: 2348)
    • Checks supported languages

      • WinRAR.exe (PID: 2344)
      • tcmd851ax32.exe (PID: 4012)
      • TOTALCMD.EXE (PID: 2600)
      • tcmd851ax32_64.exe (PID: 2348)
    • Drops a file with too old compile date

      • tcmd851ax32_64.exe (PID: 2348)
    • Reads the computer name

      • tcmd851ax32.exe (PID: 4012)
      • WinRAR.exe (PID: 2344)
      • TOTALCMD.EXE (PID: 2600)
      • tcmd851ax32_64.exe (PID: 2348)
    • Creates a software uninstall entry

      • tcmd851ax32_64.exe (PID: 2348)
      • tcmd851ax32.exe (PID: 4012)
    • Creates files in the Windows directory

      • tcmd851ax32.exe (PID: 4012)
    • Drops a file with a compile date too recent

      • tcmd851ax32.exe (PID: 4012)
      • tcmd851ax32_64.exe (PID: 2348)
    • Creates files in the user directory

      • tcmd851ax32_64.exe (PID: 2348)
    • Drops a file that was compiled in debug mode

      • tcmd851ax32_64.exe (PID: 2348)
  • INFO

    • Manual execution by user

      • tcmd851ax32_64.exe (PID: 2812)
      • tcmd851ax32.exe (PID: 4012)
      • tcmd851ax32.exe (PID: 2976)
      • tcmd851ax32_64.exe (PID: 2348)
      • TOTALCMD.EXE (PID: 2600)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v-4.x) (58.3)
.rar | RAR compressed archive (gen) (41.6)

EXIF

ZIP

ArchivedFileName: Total Commander v8.51a Final Ml_Rus (DC 20.01.2015)\About the program.txt
PackingMethod: Normal
ModifyDate: 2021:06:15 13:42:29
OperatingSystem: Win32
UncompressedSize: 9126
CompressedSize: 2671
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
47
Monitored processes
6
Malicious processes
3
Suspicious processes
2

Behavior graph

Click at the process to see the details
start winrar.exe tcmd851ax32_64.exe no specs tcmd851ax32_64.exe tcmd851ax32.exe no specs tcmd851ax32.exe totalcmd.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2344"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Total Commander v8.51a Final Ml_Rus (DC 20.01.2015).rar"C:\Program Files\WinRAR\WinRAR.exe
Explorer.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\comdlg32.dll
2348"C:\Users\admin\Desktop\Total Commander v8.51a Final Ml_Rus (DC 20.01.2015)\tcmd851ax32_64.exe" C:\Users\admin\Desktop\Total Commander v8.51a Final Ml_Rus (DC 20.01.2015)\tcmd851ax32_64.exe
Explorer.EXE
User:
admin
Company:
Ghisler Software GmbH
Integrity Level:
HIGH
Description:
Total Commander Installer
Exit code:
0
Version:
8.5
Modules
Images
c:\users\admin\desktop\total commander v8.51a final ml_rus (dc 20.01.2015)\tcmd851ax32_64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2600"C:\totalcmd\TOTALCMD.EXE" C:\totalcmd\TOTALCMD.EXEExplorer.EXE
User:
admin
Company:
Ghisler Software GmbH
Integrity Level:
MEDIUM
Description:
Total Commander 32 bit
Exit code:
0
Version:
8.51a
Modules
Images
c:\windows\system32\ntdll.dll
c:\totalcmd\totalcmd.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\user32.dll
c:\windows\system32\msvcrt.dll
2812"C:\Users\admin\Desktop\Total Commander v8.51a Final Ml_Rus (DC 20.01.2015)\tcmd851ax32_64.exe" C:\Users\admin\Desktop\Total Commander v8.51a Final Ml_Rus (DC 20.01.2015)\tcmd851ax32_64.exeExplorer.EXE
User:
admin
Company:
Ghisler Software GmbH
Integrity Level:
MEDIUM
Description:
Total Commander Installer
Exit code:
3221226540
Version:
8.5
Modules
Images
c:\users\admin\desktop\total commander v8.51a final ml_rus (dc 20.01.2015)\tcmd851ax32_64.exe
c:\windows\system32\ntdll.dll
2976"C:\Users\admin\Desktop\Total Commander v8.51a Final Ml_Rus (DC 20.01.2015)\tcmd851ax32.exe" C:\Users\admin\Desktop\Total Commander v8.51a Final Ml_Rus (DC 20.01.2015)\tcmd851ax32.exeExplorer.EXE
User:
admin
Company:
Ghisler Software GmbH
Integrity Level:
MEDIUM
Description:
Total Commander Installer
Exit code:
3221226540
Version:
8.5
Modules
Images
c:\users\admin\desktop\total commander v8.51a final ml_rus (dc 20.01.2015)\tcmd851ax32.exe
c:\windows\system32\ntdll.dll
4012"C:\Users\admin\Desktop\Total Commander v8.51a Final Ml_Rus (DC 20.01.2015)\tcmd851ax32.exe" C:\Users\admin\Desktop\Total Commander v8.51a Final Ml_Rus (DC 20.01.2015)\tcmd851ax32.exe
Explorer.EXE
User:
admin
Company:
Ghisler Software GmbH
Integrity Level:
HIGH
Description:
Total Commander Installer
Exit code:
0
Version:
8.5
Modules
Images
c:\users\admin\desktop\total commander v8.51a final ml_rus (dc 20.01.2015)\tcmd851ax32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
Total events
2 112
Read events
2 075
Write events
37
Delete events
0

Modification events

(PID) Process:(2344) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2344) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2344) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2344) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(2344) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Total Commander v8.51a Final Ml_Rus (DC 20.01.2015).rar
(PID) Process:(2344) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2344) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2344) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2344) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2348) tcmd851ax32_64.exeKey:HKEY_CURRENT_USER\Software\Ghisler\Total Commander
Operation:writeName:IniFileName
Value:
%APPDATA%\GHISLER\wincmd.ini
Executable files
35
Suspicious files
4
Text files
63
Unknown types
12

Dropped files

PID
Process
Filename
Type
2344WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2344.20822\Total Commander v8.51a Final Ml_Rus (DC 20.01.2015)\About the program.txttext
MD5:
SHA256:
2344WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2344.20822\Total Commander v8.51a Final Ml_Rus (DC 20.01.2015)\Readme.txttext
MD5:
SHA256:
2344WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2344.20822\Total Commander v8.51a Final Ml_Rus (DC 20.01.2015)\tcmd851ax32.exeexecutable
MD5:
SHA256:
2344WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2344.20822\Total Commander v8.51a Final Ml_Rus (DC 20.01.2015)\tcmd851ax64.exeexecutable
MD5:
SHA256:
2348tcmd851ax32_64.exeC:\totalcmd\TOTALCMD.CHMchm
MD5:
SHA256:
2344WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2344.20822\Total Commander v8.51a Final Ml_Rus (DC 20.01.2015)\tcmd851ax32_64.exeexecutable
MD5:
SHA256:
2348tcmd851ax32_64.exeC:\totalcmd\REGISTER.RTFtext
MD5:
SHA256:
2344WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2344.20822\Total Commander v8.51a Final Ml_Rus (DC 20.01.2015)\wincmd.keybinary
MD5:33679C9A71C277EC734204EE8AB00C5D
SHA256:0B4BDB27FA03B2C441349A940D81D699CBAF8B719168823C8F8B0AB403848F9C
2348tcmd851ax32_64.exeC:\totalcmd\LANGUAGE\WCMD_CZ.LNGtext
MD5:FC4FA4462AD69DA72E08206D2D4F5A73
SHA256:571F2BF238075A24F3A4121F768262FCD03C23841E191BD12B8EC94F9A1015BC
2348tcmd851ax32_64.exeC:\Users\admin\AppData\Roaming\GHISLER\wincmd.initext
MD5:926EB45A00D3C2C4AFEF6CE8AC07691B
SHA256:BF16FB4BAC9923E4327E3DD4F8398F0996B7395509123830F52A9B6EF66E3467
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info