File name:

Total Commander v8.51a Final Ml_Rus (DC 20.01.2015).rar

Full analysis: https://app.any.run/tasks/55c41506-c62d-47c1-9446-7a701e787b07
Verdict: Malicious activity
Analysis date: June 17, 2021, 10:05:49
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v4, os: Win32
MD5:

29331BFB37DA41FECAB7D8EE8E06B816

SHA1:

B6D4CA1DDB156C86A30FE431E62FECA36887FF00

SHA256:

D1444837980900BCBBA335654E7BC58B8B64ADA4C833C376528E30C43AF42B64

SSDEEP:

393216:hoZRCv8+Pm5nqH2fsUILkdL6G0/Tr1MPLkvxV/VN:h2Lh6GsXk8f1MP09b

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • tcmd851ax32_64.exe (PID: 2812)
      • tcmd851ax32_64.exe (PID: 2348)
      • TOTALCMD.EXE (PID: 2600)
      • tcmd851ax32.exe (PID: 2976)
      • tcmd851ax32.exe (PID: 4012)
  • SUSPICIOUS

    • Checks supported languages

      • WinRAR.exe (PID: 2344)
      • tcmd851ax32_64.exe (PID: 2348)
      • TOTALCMD.EXE (PID: 2600)
      • tcmd851ax32.exe (PID: 4012)
    • Reads the computer name

      • WinRAR.exe (PID: 2344)
      • tcmd851ax32_64.exe (PID: 2348)
      • TOTALCMD.EXE (PID: 2600)
      • tcmd851ax32.exe (PID: 4012)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2344)
      • tcmd851ax32_64.exe (PID: 2348)
    • Creates files in the user directory

      • tcmd851ax32_64.exe (PID: 2348)
    • Creates a software uninstall entry

      • tcmd851ax32_64.exe (PID: 2348)
      • tcmd851ax32.exe (PID: 4012)
    • Drops a file with a compile date too recent

      • tcmd851ax32_64.exe (PID: 2348)
      • tcmd851ax32.exe (PID: 4012)
    • Drops a file that was compiled in debug mode

      • tcmd851ax32_64.exe (PID: 2348)
    • Drops a file with too old compile date

      • tcmd851ax32_64.exe (PID: 2348)
    • Creates files in the Windows directory

      • tcmd851ax32.exe (PID: 4012)
  • INFO

    • Manual execution by user

      • tcmd851ax32_64.exe (PID: 2812)
      • tcmd851ax32_64.exe (PID: 2348)
      • TOTALCMD.EXE (PID: 2600)
      • tcmd851ax32.exe (PID: 4012)
      • tcmd851ax32.exe (PID: 2976)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v-4.x) (58.3)
.rar | RAR compressed archive (gen) (41.6)

EXIF

ZIP

ArchivedFileName: Total Commander v8.51a Final Ml_Rus (DC 20.01.2015)\About the program.txt
PackingMethod: Normal
ModifyDate: 2021:06:15 13:42:29
OperatingSystem: Win32
UncompressedSize: 9126
CompressedSize: 2671
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
47
Monitored processes
6
Malicious processes
3
Suspicious processes
2

Behavior graph

Click at the process to see the details
start winrar.exe tcmd851ax32_64.exe no specs tcmd851ax32_64.exe tcmd851ax32.exe no specs tcmd851ax32.exe totalcmd.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2344"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Total Commander v8.51a Final Ml_Rus (DC 20.01.2015).rar"C:\Program Files\WinRAR\WinRAR.exe
Explorer.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\comdlg32.dll
2348"C:\Users\admin\Desktop\Total Commander v8.51a Final Ml_Rus (DC 20.01.2015)\tcmd851ax32_64.exe" C:\Users\admin\Desktop\Total Commander v8.51a Final Ml_Rus (DC 20.01.2015)\tcmd851ax32_64.exe
Explorer.EXE
User:
admin
Company:
Ghisler Software GmbH
Integrity Level:
HIGH
Description:
Total Commander Installer
Exit code:
0
Version:
8.5
Modules
Images
c:\users\admin\desktop\total commander v8.51a final ml_rus (dc 20.01.2015)\tcmd851ax32_64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2600"C:\totalcmd\TOTALCMD.EXE" C:\totalcmd\TOTALCMD.EXEExplorer.EXE
User:
admin
Company:
Ghisler Software GmbH
Integrity Level:
MEDIUM
Description:
Total Commander 32 bit
Exit code:
0
Version:
8.51a
Modules
Images
c:\windows\system32\ntdll.dll
c:\totalcmd\totalcmd.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\user32.dll
c:\windows\system32\msvcrt.dll
2812"C:\Users\admin\Desktop\Total Commander v8.51a Final Ml_Rus (DC 20.01.2015)\tcmd851ax32_64.exe" C:\Users\admin\Desktop\Total Commander v8.51a Final Ml_Rus (DC 20.01.2015)\tcmd851ax32_64.exeExplorer.EXE
User:
admin
Company:
Ghisler Software GmbH
Integrity Level:
MEDIUM
Description:
Total Commander Installer
Exit code:
3221226540
Version:
8.5
Modules
Images
c:\users\admin\desktop\total commander v8.51a final ml_rus (dc 20.01.2015)\tcmd851ax32_64.exe
c:\windows\system32\ntdll.dll
2976"C:\Users\admin\Desktop\Total Commander v8.51a Final Ml_Rus (DC 20.01.2015)\tcmd851ax32.exe" C:\Users\admin\Desktop\Total Commander v8.51a Final Ml_Rus (DC 20.01.2015)\tcmd851ax32.exeExplorer.EXE
User:
admin
Company:
Ghisler Software GmbH
Integrity Level:
MEDIUM
Description:
Total Commander Installer
Exit code:
3221226540
Version:
8.5
Modules
Images
c:\users\admin\desktop\total commander v8.51a final ml_rus (dc 20.01.2015)\tcmd851ax32.exe
c:\windows\system32\ntdll.dll
4012"C:\Users\admin\Desktop\Total Commander v8.51a Final Ml_Rus (DC 20.01.2015)\tcmd851ax32.exe" C:\Users\admin\Desktop\Total Commander v8.51a Final Ml_Rus (DC 20.01.2015)\tcmd851ax32.exe
Explorer.EXE
User:
admin
Company:
Ghisler Software GmbH
Integrity Level:
HIGH
Description:
Total Commander Installer
Exit code:
0
Version:
8.5
Modules
Images
c:\users\admin\desktop\total commander v8.51a final ml_rus (dc 20.01.2015)\tcmd851ax32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
Total events
2 112
Read events
2 075
Write events
37
Delete events
0

Modification events

(PID) Process:(2344) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2344) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2344) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2344) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(2344) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Total Commander v8.51a Final Ml_Rus (DC 20.01.2015).rar
(PID) Process:(2344) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2344) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2344) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2344) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2348) tcmd851ax32_64.exeKey:HKEY_CURRENT_USER\Software\Ghisler\Total Commander
Operation:writeName:IniFileName
Value:
%APPDATA%\GHISLER\wincmd.ini
Executable files
35
Suspicious files
4
Text files
63
Unknown types
12

Dropped files

PID
Process
Filename
Type
2344WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2344.20822\Total Commander v8.51a Final Ml_Rus (DC 20.01.2015)\Readme.txttext
MD5:
SHA256:
2344WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2344.20822\Total Commander v8.51a Final Ml_Rus (DC 20.01.2015)\tcmd851ax32.exeexecutable
MD5:
SHA256:
2344WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2344.20822\Total Commander v8.51a Final Ml_Rus (DC 20.01.2015)\tcmd851ax64.exeexecutable
MD5:
SHA256:
2348tcmd851ax32_64.exeC:\totalcmd\REGISTER.RTFtext
MD5:
SHA256:
2344WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2344.20822\Total Commander v8.51a Final Ml_Rus (DC 20.01.2015)\tcmd851ax32_64.exeexecutable
MD5:
SHA256:
2344WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2344.20822\Total Commander v8.51a Final Ml_Rus (DC 20.01.2015)\About the program.txttext
MD5:
SHA256:
2344WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2344.20822\Total Commander v8.51a Final Ml_Rus (DC 20.01.2015)\wincmd.keybinary
MD5:33679C9A71C277EC734204EE8AB00C5D
SHA256:0B4BDB27FA03B2C441349A940D81D699CBAF8B719168823C8F8B0AB403848F9C
2348tcmd851ax32_64.exeC:\totalcmd\TOTALCMD.CHMchm
MD5:
SHA256:
2348tcmd851ax32_64.exeC:\totalcmd\SIZE!.TXTtext
MD5:9C46B722FA1FFAB6EAD573859ABB32BB
SHA256:2EA390F71ED637935463CFEB1E4B02BB83364A157E443644087E6D61DEAE12F7
2348tcmd851ax32_64.exeC:\totalcmd\LANGUAGE\WCMD_DAN.LNGtext
MD5:36E37A0500E8A26AABF10883FFBC70E6
SHA256:C072303A6D855938A2B08EA9EAAA2C3406B9293871D8C1E9374AC49B7259850E
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info