File name:

Hard.Disk.Sentinel.Pro.6.30.Portable.zip

Full analysis: https://app.any.run/tasks/4318108e-f267-4211-b00e-9fb19ac147c7
Verdict: Malicious activity
Analysis date: April 23, 2025, 05:26:40
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
arch-scr
arch-doc
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=store
MD5:

321E6262D5459D757A5EB12120FFDF9E

SHA1:

6F2730FFB967B54E657049F2D721891C22FFA3C4

SHA256:

D55CF001B1ED39D9047E2F705CD0C2CFAF82FEAE363D7265CAAA74D67E2D2AD6

SSDEEP:

393216:JQGSoAgQa4VE9sV1AQKPHfLKaetG7DZoZGijlKVcuu23D:DV4SuV1PKfjgEusijlhuZ3D

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Generic archive extractor

      • WinRAR.exe (PID: 1188)
  • SUSPICIOUS

    • Gets context to manipulate scheduled tasks (SCRIPT)

      • wscript.exe (PID: 5608)
    • Drops a system driver (possible attempt to evade defenses)

      • WinRAR.exe (PID: 1188)
    • Process drops legitimate windows executable

      • WinRAR.exe (PID: 1188)
    • Reads security settings of Internet Explorer

      • WinRAR.exe (PID: 1188)
    • Starts CMD.EXE for commands execution

      • WinRAR.exe (PID: 1188)
    • Executing commands from a ".bat" file

      • WinRAR.exe (PID: 1188)
  • INFO

    • Manual execution by a user

      • wscript.exe (PID: 5608)
      • notepad.exe (PID: 6300)
      • notepad.exe (PID: 2432)
      • notepad.exe (PID: 6620)
      • notepad.exe (PID: 864)
      • notepad.exe (PID: 2852)
      • notepad.exe (PID: 4112)
      • OpenWith.exe (PID: 920)
      • notepad.exe (PID: 6708)
      • notepad.exe (PID: 5600)
      • notepad.exe (PID: 5408)
      • notepad.exe (PID: 6656)
      • notepad.exe (PID: 5988)
      • OpenWith.exe (PID: 664)
      • rundll32.exe (PID: 2656)
    • Reads security settings of Internet Explorer

      • notepad.exe (PID: 2432)
      • notepad.exe (PID: 6300)
      • notepad.exe (PID: 6620)
      • notepad.exe (PID: 864)
      • notepad.exe (PID: 2852)
      • notepad.exe (PID: 4112)
      • notepad.exe (PID: 6708)
      • notepad.exe (PID: 5600)
      • notepad.exe (PID: 5408)
      • notepad.exe (PID: 6656)
      • notepad.exe (PID: 5988)
      • rundll32.exe (PID: 2656)
    • Reads Microsoft Office registry keys

      • OpenWith.exe (PID: 920)
      • OpenWith.exe (PID: 664)
    • The sample compiled with english language support

      • WinRAR.exe (PID: 1188)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 1188)
    • The sample compiled with french language support

      • WinRAR.exe (PID: 1188)
    • The sample compiled with russian language support

      • WinRAR.exe (PID: 1188)
    • The sample compiled with Italian language support

      • WinRAR.exe (PID: 1188)
    • The sample compiled with chinese language support

      • WinRAR.exe (PID: 1188)
    • The sample compiled with german language support

      • WinRAR.exe (PID: 1188)
    • The sample compiled with polish language support

      • WinRAR.exe (PID: 1188)
    • Checks supported languages

      • MpCmdRun.exe (PID: 5864)
    • Reads the computer name

      • MpCmdRun.exe (PID: 5864)
    • Create files in a temporary directory

      • MpCmdRun.exe (PID: 5864)
    • Checks proxy server information

      • slui.exe (PID: 4688)
    • Reads the software policy settings

      • slui.exe (PID: 4688)
    • Local mutex for internet shortcut management

      • rundll32.exe (PID: 2656)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2025:03:24 21:00:46
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: Hard.Disk.Sentinel.Pro.6.30.Portable/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
141
Monitored processes
20
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe wscript.exe no specs notepad.exe no specs notepad.exe no specs notepad.exe no specs notepad.exe no specs notepad.exe no specs notepad.exe no specs openwith.exe no specs rundll32.exe no specs openwith.exe no specs slui.exe cmd.exe no specs conhost.exe no specs mpcmdrun.exe no specs notepad.exe no specs notepad.exe no specs notepad.exe no specs notepad.exe no specs notepad.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
664"C:\WINDOWS\System32\OpenWith.exe" C:\Users\admin\Desktop\fipro.lngC:\Windows\System32\OpenWith.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Pick an app
Exit code:
2147943623
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\openwith.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
864"C:\WINDOWS\system32\NOTEPAD.EXE" C:\Users\admin\Desktop\DriveAddRemoveLog.txtC:\Windows\System32\notepad.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\notepad.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
920"C:\WINDOWS\System32\OpenWith.exe" C:\Users\admin\Desktop\plpro.lngC:\Windows\System32\OpenWith.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Pick an app
Exit code:
2147943623
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\openwith.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
1164C:\WINDOWS\system32\cmd.exe /c ""C:\Users\admin\AppData\Local\Temp\Rar$VR1188.41666\Rar$Scan89978.bat" "C:\Windows\System32\cmd.exeWinRAR.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\cmdext.dll
c:\windows\system32\advapi32.dll
1188"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\Desktop\Hard.Disk.Sentinel.Pro.6.30.Portable.zipC:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
2432"C:\WINDOWS\system32\NOTEPAD.EXE" C:\Users\admin\Desktop\hds_eula_en.txtC:\Windows\System32\notepad.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\notepad.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
2656"C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\ieframe.dll",OpenURL %lC:\Windows\System32\rundll32.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shcore.dll
c:\windows\system32\imagehlp.dll
2852"C:\WINDOWS\system32\NOTEPAD.EXE" C:\Users\admin\Desktop\winsched.txtC:\Windows\System32\notepad.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\notepad.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
4112"C:\WINDOWS\system32\NOTEPAD.EXE" C:\Users\admin\Desktop\hdsversion.txtC:\Windows\System32\notepad.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\notepad.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
4688C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
Total events
7 897
Read events
7 888
Write events
9
Delete events
0

Modification events

(PID) Process:(1188) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(1188) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(1188) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(1188) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\Hard.Disk.Sentinel.Pro.6.30.Portable.zip
(PID) Process:(1188) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(1188) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(1188) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(1188) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(1188) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\VirusScan
Operation:writeName:DefScanner
Value:
Windows Defender
Executable files
71
Suspicious files
20
Text files
72
Unknown types
0

Dropped files

PID
Process
Filename
Type
1188WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$VR1188.41666\Hard.Disk.Sentinel.Pro.6.30.Portable.zip\Hard.Disk.Sentinel.Pro.6.30.Portable\App\AppInfo\appinfo.initext
MD5:F184EAB29FEB9485903B4708CB3DA70F
SHA256:AE8A4EF9D98DDE2B70E336DF3DC227AAD25AE8CC7DBAA58F0E72B7F4F21F4B39
1188WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$VR1188.41666\Hard.Disk.Sentinel.Pro.6.30.Portable.zip\Hard.Disk.Sentinel.Pro.6.30.Portable\App\AppInfo\appicon.icoimage
MD5:9DAB286CD8FFF10040693F2BB95B87CE
SHA256:EDFBCE1C4D312B7275C7032AA39355D7EB519F4FB756B09C5AFCB091151EED61
1188WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$VR1188.41666\Hard.Disk.Sentinel.Pro.6.30.Portable.zip\Hard.Disk.Sentinel.Pro.6.30.Portable\App\Hard Disk Sentinel\bg.lngtext
MD5:46C5171E86C2E1F2966F0A9DE7DB8B51
SHA256:3F5349CA33CDAC2DA55CBB9D970246A15D7610B5BAC2CAE4569E1EB6B2E4E9A6
1188WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$VR1188.41666\Hard.Disk.Sentinel.Pro.6.30.Portable.zip\Hard.Disk.Sentinel.Pro.6.30.Portable\App\Hard Disk Sentinel\cnpro.lngtext
MD5:AF500208EDF73C0E96A829E8D3223573
SHA256:1930031F7664E1208065ACEBAD86F589F9A9448F0CCA99377A4C4574625F6C6A
1188WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$VR1188.41666\Hard.Disk.Sentinel.Pro.6.30.Portable.zip\Hard.Disk.Sentinel.Pro.6.30.Portable\App\Hard Disk Sentinel\bgpro.lngtext
MD5:227B56156641DB9C0D5AAEE7F18275B4
SHA256:8A8E7B9A30F6530F437DA57D6E3522CFC755143D77A458D7D077AA4237253F91
1188WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$VR1188.41666\Hard.Disk.Sentinel.Pro.6.30.Portable.zip\Hard.Disk.Sentinel.Pro.6.30.Portable\App\Hard Disk Sentinel\czpro.lngtext
MD5:5679C6BD2255EC9354CB8FF4A4FD7C44
SHA256:787B52EB9AB3576B14381504D9C4C3F56A177BF231D55FE640B1EDA1D62555DD
1188WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$VR1188.41666\Hard.Disk.Sentinel.Pro.6.30.Portable.zip\Hard.Disk.Sentinel.Pro.6.30.Portable\App\Hard Disk Sentinel\de.chmbinary
MD5:0B8AE0A31EC935B1797CC1C447AEADFB
SHA256:DFA63DE9AC88F1C8F3DB239801D1F78574418787B738561B80F15CC6B6854D70
1188WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$VR1188.41666\Hard.Disk.Sentinel.Pro.6.30.Portable.zip\Hard.Disk.Sentinel.Pro.6.30.Portable\App\Hard Disk Sentinel\109commandlib.dllexecutable
MD5:D05BE9E2ED17E21D8EC2A60E9DA711CD
SHA256:EC74FDE19A73E9EABB64E389D9A9F608569906F0F1A4A644902AB6D19812DDFF
1188WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$VR1188.41666\Hard.Disk.Sentinel.Pro.6.30.Portable.zip\Hard.Disk.Sentinel.Pro.6.30.Portable\App\Hard Disk Sentinel\da.lngtext
MD5:5D3315766F5D7729AE94F11ECB1747A0
SHA256:A5E558C4FA4124E712AC0CA2C16AFA142942C1042D17DD5A2D2F9210BB5EB552
1188WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$VR1188.41666\Hard.Disk.Sentinel.Pro.6.30.Portable.zip\Hard.Disk.Sentinel.Pro.6.30.Portable\App\Hard Disk Sentinel\dapro.lngtext
MD5:F982E07C101D1DFA63D0FF7F5F062FB0
SHA256:12A4FDCA5D2C1C969ABAF54E1A1175E19C872B3DBCDC165D1416743ECDD9075B
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
22
DNS requests
6
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2516
RUXIMICS.exe
GET
200
2.16.164.49:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
2516
RUXIMICS.exe
GET
200
23.219.150.101:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
POST
500
40.91.76.224:443
https://activation-v2.sls.microsoft.com/SLActivateProduct/SLActivateProduct.asmx?configextension=Retail
unknown
xml
512 b
whitelisted
POST
500
40.91.76.224:443
https://activation-v2.sls.microsoft.com/SLActivateProduct/SLActivateProduct.asmx?configextension=Retail
unknown
xml
512 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
2516
RUXIMICS.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
2516
RUXIMICS.exe
2.16.164.49:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
2516
RUXIMICS.exe
23.219.150.101:80
www.microsoft.com
AKAMAI-AS
CL
whitelisted
6044
slui.exe
20.83.72.98:443
activation-v2.sls.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4688
slui.exe
20.83.72.98:443
activation-v2.sls.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 4.231.128.59
whitelisted
google.com
  • 142.250.184.238
whitelisted
crl.microsoft.com
  • 2.16.164.49
  • 2.16.164.120
whitelisted
www.microsoft.com
  • 23.219.150.101
whitelisted
activation-v2.sls.microsoft.com
  • 20.83.72.98
whitelisted

Threats

No threats detected
No debug info