analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

nothing.rar

Full analysis: https://app.any.run/tasks/d7539b14-2bb9-4df3-b024-52423ac2290a
Verdict: Malicious activity
Threats:

Ransomware is a type of malicious software that locks users out of their system or data using different methods to force them to pay a ransom. Most often, such programs encrypt files on an infected machine and demand a fee to be paid in exchange for the decryption key. Additionally, such programs can be used to steal sensitive information from the compromised computer and even conduct DDoS attacks against affected organizations to pressure them into paying.

Analysis date: January 24, 2022, 19:52:18
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
ransomware
Indicators:
MIME: application/x-rar
File info: RAR archive data, v4, os: Win32
MD5:

4A948741E4A1B028AE12F6814AB739FD

SHA1:

6AA002048F4CC4DE7C7DCBAC4344BDEE42E0A660

SHA256:

D4620659E5C0FDE631CA681EA392BCF474E01E5CB27C16711F23BB46EEA9D669

SSDEEP:

24576:fKAU1JpMO8B3IPytLwj1XXJo7gUe/V4y6cCJ0HMy:VWJzPydw5QgBp20HMy

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • nothing.exe (PID: 2092)
      • nothing.exe (PID: 2476)
      • nothing.exe (PID: 3912)
      • nothing.exe (PID: 2248)
      • nothing.exe (PID: 3012)
      • nothing.exe (PID: 1340)
      • nothing.exe (PID: 2732)
      • nothing.exe (PID: 2316)
      • nothing.exe (PID: 1408)
      • nothing.exe (PID: 2600)
      • nothing.exe (PID: 1296)
      • nothing.exe (PID: 2044)
      • nothing.exe (PID: 3284)
      • nothing.exe (PID: 3564)
  • SUSPICIOUS

    • Reads the computer name

      • WinRAR.exe (PID: 1536)
      • nothing.exe (PID: 2476)
      • powershell.exe (PID: 2568)
      • WinRAR.exe (PID: 3816)
      • nothing.exe (PID: 3012)
      • nothing.exe (PID: 2248)
      • nothing.exe (PID: 1408)
      • nothing.exe (PID: 2732)
      • nothing.exe (PID: 1296)
      • nothing.exe (PID: 3564)
    • Checks supported languages

      • WinRAR.exe (PID: 1536)
      • nothing.exe (PID: 2476)
      • powershell.exe (PID: 2568)
      • WinRAR.exe (PID: 3816)
      • notepad++.exe (PID: 2728)
      • nothing.exe (PID: 3012)
      • nothing.exe (PID: 2248)
      • nothing.exe (PID: 1408)
      • nothing.exe (PID: 2732)
      • nothing.exe (PID: 1296)
      • nothing.exe (PID: 3564)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 1536)
      • WinRAR.exe (PID: 3816)
    • Drops a file with a compile date too recent

      • WinRAR.exe (PID: 1536)
      • WinRAR.exe (PID: 3816)
    • Reads the date of Windows installation

      • powershell.exe (PID: 2568)
    • PowerShell script executed

      • powershell.exe (PID: 2568)
    • Creates files in the user directory

      • powershell.exe (PID: 2568)
    • Creates files like Ransomware instruction

      • powershell.exe (PID: 2568)
    • Uses RUNDLL32.EXE to load library

      • control.exe (PID: 2256)
  • INFO

    • Manual execution by user

      • nothing.exe (PID: 2092)
      • nothing.exe (PID: 2476)
      • powershell.exe (PID: 2568)
      • rundll32.exe (PID: 2240)
      • WinRAR.exe (PID: 3816)
      • nothing.exe (PID: 2248)
      • nothing.exe (PID: 1340)
      • notepad++.exe (PID: 2728)
      • nothing.exe (PID: 2600)
      • nothing.exe (PID: 1408)
      • nothing.exe (PID: 2732)
      • nothing.exe (PID: 2316)
      • nothing.exe (PID: 1296)
      • nothing.exe (PID: 2044)
      • nothing.exe (PID: 3284)
      • control.exe (PID: 2256)
      • nothing.exe (PID: 3564)
    • Checks Windows Trust Settings

      • powershell.exe (PID: 2568)
    • Checks supported languages

      • rundll32.exe (PID: 2240)
      • control.exe (PID: 2256)
      • rundll32.exe (PID: 2980)
    • Reads Microsoft Office registry keys

      • powershell.exe (PID: 2568)
    • Reads the computer name

      • control.exe (PID: 2256)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v-4.x) (58.3)
.rar | RAR compressed archive (gen) (41.6)

EXIF

ZIP

ArchivedFileName: nothing.exe
PackingMethod: Normal
ModifyDate: 2022:01:24 16:41:04
OperatingSystem: Win32
UncompressedSize: 842240
CompressedSize: 806112
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
90
Monitored processes
21
Malicious processes
5
Suspicious processes
4

Behavior graph

Click at the process to see the details
start drop and start drop and start winrar.exe nothing.exe no specs nothing.exe powershell.exe no specs rundll32.exe no specs winrar.exe nothing.exe no specs nothing.exe notepad++.exe nothing.exe no specs nothing.exe nothing.exe no specs nothing.exe nothing.exe no specs nothing.exe control.exe no specs rundll32.exe no specs nothing.exe no specs nothing.exe nothing.exe no specs nothing.exe

Process information

PID
CMD
Path
Indicators
Parent process
1536"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\nothing.rar"C:\Program Files\WinRAR\WinRAR.exe
Explorer.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
2092"C:\Users\admin\Desktop\nothing.exe" C:\Users\admin\Desktop\nothing.exeExplorer.EXE
User:
admin
Integrity Level:
MEDIUM
Description:
PURPLE
Exit code:
3221226540
Version:
1.0.0.0
2476"C:\Users\admin\Desktop\nothing.exe" C:\Users\admin\Desktop\nothing.exe
Explorer.EXE
User:
admin
Integrity Level:
HIGH
Description:
PURPLE
Exit code:
3762504530
Version:
1.0.0.0
2568"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" "-file" "C:\Users\admin\AppData\Local\Temp\5d4a7967-576a-48ad-b3af-fe5cf83ed17e.ps1"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeExplorer.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows PowerShell
Exit code:
0
Version:
10.0.14409.1005 (rs1_srvoob.161208-1155)
2240"C:\Windows\system32\rundll32.exe" C:\Windows\system32\shell32.dll,OpenAs_RunDLL C:\Users\admin\AppData\Local\Temp\oj5ynezb.xg2C:\Windows\system32\rundll32.exeExplorer.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
3816"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\nothing.rar"C:\Program Files\WinRAR\WinRAR.exe
Explorer.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
3912"C:\Users\admin\AppData\Local\Temp\Rar$EXa3816.24534\nothing.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3816.24534\nothing.exeWinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Description:
PURPLE
Exit code:
3221226540
Version:
1.0.0.0
3012"C:\Users\admin\AppData\Local\Temp\Rar$EXa3816.24534\nothing.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3816.24534\nothing.exe
WinRAR.exe
User:
admin
Integrity Level:
HIGH
Description:
PURPLE
Exit code:
3762504530
Version:
1.0.0.0
2728"C:\Program Files\Notepad++\notepad++.exe" "C:\Users\admin\AppData\Local\Temp\Rar$EXa3816.24534\nothing.exe"C:\Program Files\Notepad++\notepad++.exe
Explorer.EXE
User:
admin
Company:
Integrity Level:
MEDIUM
Description:
Notepad++ : a free (GNU) source code editor
Exit code:
0
Version:
7.91
1340"C:\Users\admin\AppData\Local\Temp\Rar$EXa3816.24534\nothing.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3816.24534\nothing.exeExplorer.EXE
User:
admin
Integrity Level:
MEDIUM
Description:
PURPLE
Exit code:
3221226540
Version:
1.0.0.0
Total events
4 696
Read events
4 568
Write events
128
Delete events
0

Modification events

(PID) Process:(1536) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(1536) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(1536) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1536) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(1536) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(1536) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\nothing.rar
(PID) Process:(1536) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(1536) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(1536) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(1536) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
Executable files
2
Suspicious files
30
Text files
28
Unknown types
14

Dropped files

PID
Process
Filename
Type
2568powershell.exeC:\Users\admin\Desktop\assspecial.pngimage
MD5:25DF2E531C1DD4733CE788523E178AD3
SHA256:01D7EC5C6EF313A631501B96FD4C91AC8AD5DA5E9BEE7CABDA42F566984B32B9
2568powershell.exeC:\Users\admin\Desktop\marketdecision.pngimage
MD5:92644291AC680C308C2ACCBDD0DC1455
SHA256:C45206534AA07269288E46DF4F0356C1DC93B69F12E4F55EED19A2F8F90D24EA
2568powershell.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms~RF15c03c.TMPbinary
MD5:CCFCF369F751CE8DA0370D84E52A7EED
SHA256:53922490C3F5A04667EC3605A01AF2A4F4F265782D1BCA519F63ACAD413F2ED9
1536WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1536.10270\nothing.exeexecutable
MD5:E5475ED04BE2E9D1FFBE027C382B1106
SHA256:E96448C3956A52675D76C57B4FE1D0B80C3D67D1963CDA6FAB855DAC46EA577F
2568powershell.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\sportsactivity.jpg.lnklnk
MD5:0BAA94B30D3B03169D42CDB258D9C2C8
SHA256:283A63E7FCC9217A77A84794E94791D6874A868908DC73DF956242FC7E34901A
2568powershell.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-msbinary
MD5:EC4A4757376BB385B2E54F62C4531B64
SHA256:00CFDAAA4B0807DBE052E5532DE1DE92D40406747F086F08847F9A5E77BB5662
2568powershell.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\6HX61YSXQZMSE8OTVK81.tempbinary
MD5:EC4A4757376BB385B2E54F62C4531B64
SHA256:00CFDAAA4B0807DBE052E5532DE1DE92D40406747F086F08847F9A5E77BB5662
2568powershell.exeC:\Users\admin\Desktop\windact.jpgimage
MD5:7388789F2BDAA47E24DA692E77F0C1E3
SHA256:2E74FCD88CEF0CCFF958CFC8F85AC12AB0D96B7401AB39D4ACDA575F386CED43
2568powershell.exeC:\Users\admin\Desktop\hashow.rtftext
MD5:C682C0F3CF2C3D796224A50E6743747E
SHA256:830439E90A10766C44B0016D746120DDD1DA8D34BBA4D18B903188DF5AA38459
2568powershell.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\sizemenu.rtf.lnklnk
MD5:074001EE01D3FCD1B38C56EC8A17770B
SHA256:A814009335046F67D89314A5E213EE071C861BD94BCB3DFFCF193465F2668ED9
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
Process
Message
notepad++.exe
VerifyLibrary: C:\Program Files\Notepad++\SciLexer.dll
notepad++.exe
VerifyLibrary: certificate revocation checking is disabled
notepad++.exe
ED255D9151912E40DF048A56288E969A8D0DAFA3
notepad++.exe
VerifyLibrary: C:\Program Files\Notepad++\updater\gup.exe
notepad++.exe
VerifyLibrary: certificate revocation checking is disabled
notepad++.exe
ED255D9151912E40DF048A56288E969A8D0DAFA3
notepad++.exe
VerifyLibrary: C:\Program Files\Notepad++\plugins\Config\nppPluginList.dll
notepad++.exe
VerifyLibrary: certificate revocation checking is disabled
notepad++.exe
ED255D9151912E40DF048A56288E969A8D0DAFA3
notepad++.exe
VerifyLibrary: C:\Program Files\Notepad++\updater\gup.exe