File name:

33.rar

Full analysis: https://app.any.run/tasks/951b9c60-a959-4816-9087-75cf667936b4
Verdict: Malicious activity
Analysis date: May 27, 2020, 06:06:13
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

8B750A823FE2993FDA4E2E1258D70CE2

SHA1:

02E6F7E37F8C21BE2B2CF3BCA0E9D791A136B9C1

SHA256:

D557034D13057B1CB23F7B88F360771201555DC218988356336CC33C9AC8E2F2

SSDEEP:

24576:95tYdgn6Jbtqr25IMZE/TkEv35fcUTtYFYCTsXocClD2mgQ0IfDkXzF2hvmT:TSdgn6Jbcr2OQOYOUUpJCTs4cfIrkXE6

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • EMV Reader Writer Software V8.exe (PID: 2956)
      • EMV Reader Writer Software V8.exe (PID: 3856)
      • emv.exe (PID: 2180)
      • SynTPHelper.exe (PID: 2736)
      • EMV Reader Writer Software V8.exe (PID: 2860)
      • tmp2.exe (PID: 4060)
      • tmp1.jpg (PID: 2476)
      • SynTPHelper.exe (PID: 4032)
    • Changes the autorun value in the registry

      • tmp2.exe (PID: 4060)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 1920)
      • EMV Reader Writer Software V8.exe (PID: 3856)
      • SynTPHelper.exe (PID: 2736)
      • tmp2.exe (PID: 4060)
      • EMV Reader Writer Software V8.exe (PID: 2860)
    • Creates files in the Windows directory

      • SynTPHelper.exe (PID: 2736)
    • Starts itself from another location

      • SynTPHelper.exe (PID: 2736)
      • tmp2.exe (PID: 4060)
    • Starts CMD.EXE for commands execution

      • EMV Reader Writer Software V8.exe (PID: 2860)
    • Starts application with an unusual extension

      • cmd.exe (PID: 1780)
    • Creates files in the user directory

      • tmp2.exe (PID: 4060)
  • INFO

    • Manual execution by user

      • EMV Reader Writer Software V8.exe (PID: 3856)
      • EMV Reader Writer Software V8.exe (PID: 2956)
    • Dropped object may contain Bitcoin addresses

      • EMV Reader Writer Software V8.exe (PID: 2860)
      • EMV Reader Writer Software V8.exe (PID: 3856)
      • tmp2.exe (PID: 4060)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
50
Monitored processes
11
Malicious processes
3
Suspicious processes
4

Behavior graph

Click at the process to see the details
start drop and start drop and start drop and start drop and start winrar.exe emv reader writer  software v8.exe no specs emv reader writer  software v8.exe syntphelper.exe emv reader writer  software v8.exe cmd.exe no specs tmp1.jpg no specs cmd.exe no specs tmp2.exe emv.exe no specs syntphelper.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1780C:\Windows\system32\cmd.exe /c start %temp%\tmp1.jpgC:\Windows\system32\cmd.exeEMV Reader Writer Software V8.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1920"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\33.rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
c:\windows\system32\comdlg32.dll
2180"C:\Users\admin\AppData\Local\Drpbx\emv.exe" C:\Users\admin\AppData\Local\Temp\tmp2.exeC:\Users\admin\AppData\Local\Drpbx\emv.exetmp2.exe
User:
admin
Integrity Level:
HIGH
Description:
Chip Writer
Exit code:
0
Version:
37.0.2.5583
Modules
Images
c:\users\admin\appdata\local\drpbx\emv.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2464C:\Windows\system32\cmd.exe /c start %temp%\tmp2.exeC:\Windows\system32\cmd.exeEMV Reader Writer Software V8.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2476C:\Users\admin\AppData\Local\Temp\tmp1.jpg C:\Users\admin\AppData\Local\Temp\tmp1.jpgcmd.exe
User:
admin
Company:
Microsoft
Integrity Level:
HIGH
Description:
EMV Reader Writer Software V8
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\tmp1.jpg
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2736"C:\Users\admin\AppData\Local\Temp\SynTPHelper.exe" C:\Users\admin\AppData\Local\Temp\SynTPHelper.exe
EMV Reader Writer Software V8.exe
User:
admin
Company:
Synaptics Incorporated
Integrity Level:
HIGH
Description:
Synaptics Pointing Device Helper
Exit code:
0
Version:
19.2.17.59 26Apr17
Modules
Images
c:\users\admin\appdata\local\temp\syntphelper.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2860"C:\Users\admin\AppData\Local\Temp\EMV Reader Writer Software V8.exe" C:\Users\admin\AppData\Local\Temp\EMV Reader Writer Software V8.exe
EMV Reader Writer Software V8.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\emv reader writer software v8.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\apphelp.dll
2956"C:\Users\admin\Desktop\33\EMV Reader Writer\EMV Reader Writer Software V8.exe" C:\Users\admin\Desktop\33\EMV Reader Writer\EMV Reader Writer Software V8.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\desktop\33\emv reader writer\emv reader writer software v8.exe
c:\systemroot\system32\ntdll.dll
3856"C:\Users\admin\Desktop\33\EMV Reader Writer\EMV Reader Writer Software V8.exe" C:\Users\admin\Desktop\33\EMV Reader Writer\EMV Reader Writer Software V8.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\desktop\33\emv reader writer\emv reader writer software v8.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
4032"C:\Windows\SynTPHelper.exe" C:\Windows\SynTPHelper.exeSynTPHelper.exe
User:
admin
Company:
Synaptics Incorporated
Integrity Level:
HIGH
Description:
Synaptics Pointing Device Helper
Exit code:
0
Version:
19.2.17.59 26Apr17
Modules
Images
c:\windows\syntphelper.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
Total events
1 202
Read events
1 166
Write events
36
Delete events
0

Modification events

(PID) Process:(1920) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(1920) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(1920) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12D\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1920) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12D\52C64B7E
Operation:writeName:@C:\Windows\system32\NetworkExplorer.dll,-1
Value:
Network
(PID) Process:(1920) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\33.rar
(PID) Process:(1920) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(1920) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(1920) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(1920) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(1920) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\DialogEditHistory\ExtrPath
Operation:writeName:0
Value:
C:\Users\admin\Desktop
Executable files
8
Suspicious files
0
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
1920WinRAR.exeC:\Users\admin\Desktop\33\EMV Reader Writer\EmvManual.rtf
MD5:
SHA256:
1920WinRAR.exeC:\Users\admin\Desktop\33\EMV Reader Writer\Licente Key.txttext
MD5:
SHA256:
3856EMV Reader Writer Software V8.exeC:\Users\admin\AppData\Local\Temp\SynTPHelper.exeexecutable
MD5:00291C15181BAA184B62938CB519BA4C
SHA256:C4820B44454F5072937047AF8FA53CABE7E21D3FDF0464581A70594B9F2A7F73
1920WinRAR.exeC:\Users\admin\Desktop\33\EMV Reader Writer\EMV Reader Writer Software V8.exeexecutable
MD5:35D2469A266AD4CF08EE723CA74B843D
SHA256:9A696E11BCDD0D59577C43613D983DAAD607EA2FE0B2562F9359C23643CDA18B
3856EMV Reader Writer Software V8.exeC:\Users\admin\AppData\Local\Temp\EMV Reader Writer Software V8.exeexecutable
MD5:A03920EC643F26A5D38676C953E6F4F6
SHA256:A1DE7BC1D00660B7416E91442BCB89DCB8A05351EB22F03F89258D9077E69A80
2736SynTPHelper.exeC:\Windows\SynTPHelper.exeexecutable
MD5:00291C15181BAA184B62938CB519BA4C
SHA256:C4820B44454F5072937047AF8FA53CABE7E21D3FDF0464581A70594B9F2A7F73
4060tmp2.exeC:\Users\admin\AppData\Roaming\Frfx\emv.exeexecutable
MD5:913157F29B94106F5B6DB18D04EB3C41
SHA256:CC4CD74A7DB7EDD8A16DA7FF6FCCF491BF61CC19AC73AAE5843C56821D09272F
4060tmp2.exeC:\Users\admin\AppData\Local\Drpbx\emv.exeexecutable
MD5:913157F29B94106F5B6DB18D04EB3C41
SHA256:CC4CD74A7DB7EDD8A16DA7FF6FCCF491BF61CC19AC73AAE5843C56821D09272F
2860EMV Reader Writer Software V8.exeC:\Users\admin\AppData\Local\Temp\tmp2.exeexecutable
MD5:913157F29B94106F5B6DB18D04EB3C41
SHA256:CC4CD74A7DB7EDD8A16DA7FF6FCCF491BF61CC19AC73AAE5843C56821D09272F
2860EMV Reader Writer Software V8.exeC:\Users\admin\AppData\Local\Temp\tmp1.jpgexecutable
MD5:C9A3CCF95369F53CD448FAC94FF4E3B8
SHA256:DC32698C13DE42E87913C6D90939186A56CA4586E0397DF52ED85E47443CEEF4
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info