File name:

Hard.Disk.Sentinel.Pro.6.30.Portable.zip

Full analysis: https://app.any.run/tasks/4318108e-f267-4211-b00e-9fb19ac147c7
Verdict: Malicious activity
Analysis date: April 23, 2025, 05:26:40
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
arch-scr
arch-doc
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=store
MD5:

321E6262D5459D757A5EB12120FFDF9E

SHA1:

6F2730FFB967B54E657049F2D721891C22FFA3C4

SHA256:

D55CF001B1ED39D9047E2F705CD0C2CFAF82FEAE363D7265CAAA74D67E2D2AD6

SSDEEP:

393216:JQGSoAgQa4VE9sV1AQKPHfLKaetG7DZoZGijlKVcuu23D:DV4SuV1PKfjgEusijlhuZ3D

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Generic archive extractor

      • WinRAR.exe (PID: 1188)
  • SUSPICIOUS

    • Gets context to manipulate scheduled tasks (SCRIPT)

      • wscript.exe (PID: 5608)
    • Process drops legitimate windows executable

      • WinRAR.exe (PID: 1188)
    • Drops a system driver (possible attempt to evade defenses)

      • WinRAR.exe (PID: 1188)
    • Reads security settings of Internet Explorer

      • WinRAR.exe (PID: 1188)
    • Starts CMD.EXE for commands execution

      • WinRAR.exe (PID: 1188)
    • Executing commands from a ".bat" file

      • WinRAR.exe (PID: 1188)
  • INFO

    • Reads security settings of Internet Explorer

      • notepad.exe (PID: 6300)
      • notepad.exe (PID: 2432)
      • notepad.exe (PID: 6620)
      • notepad.exe (PID: 864)
      • notepad.exe (PID: 2852)
      • notepad.exe (PID: 4112)
      • rundll32.exe (PID: 2656)
      • notepad.exe (PID: 6708)
      • notepad.exe (PID: 5600)
      • notepad.exe (PID: 5988)
      • notepad.exe (PID: 5408)
      • notepad.exe (PID: 6656)
    • Manual execution by a user

      • wscript.exe (PID: 5608)
      • notepad.exe (PID: 2432)
      • notepad.exe (PID: 6300)
      • notepad.exe (PID: 6620)
      • notepad.exe (PID: 864)
      • notepad.exe (PID: 2852)
      • notepad.exe (PID: 4112)
      • OpenWith.exe (PID: 664)
      • rundll32.exe (PID: 2656)
      • OpenWith.exe (PID: 920)
      • notepad.exe (PID: 6708)
      • notepad.exe (PID: 5600)
      • notepad.exe (PID: 5408)
      • notepad.exe (PID: 5988)
      • notepad.exe (PID: 6656)
    • Reads Microsoft Office registry keys

      • OpenWith.exe (PID: 664)
      • OpenWith.exe (PID: 920)
    • Local mutex for internet shortcut management

      • rundll32.exe (PID: 2656)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 1188)
    • The sample compiled with Italian language support

      • WinRAR.exe (PID: 1188)
    • The sample compiled with german language support

      • WinRAR.exe (PID: 1188)
    • The sample compiled with chinese language support

      • WinRAR.exe (PID: 1188)
    • The sample compiled with polish language support

      • WinRAR.exe (PID: 1188)
    • The sample compiled with english language support

      • WinRAR.exe (PID: 1188)
    • The sample compiled with french language support

      • WinRAR.exe (PID: 1188)
    • The sample compiled with russian language support

      • WinRAR.exe (PID: 1188)
    • Checks supported languages

      • MpCmdRun.exe (PID: 5864)
    • Create files in a temporary directory

      • MpCmdRun.exe (PID: 5864)
    • Reads the computer name

      • MpCmdRun.exe (PID: 5864)
    • Checks proxy server information

      • slui.exe (PID: 4688)
    • Reads the software policy settings

      • slui.exe (PID: 4688)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2025:03:24 21:00:46
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: Hard.Disk.Sentinel.Pro.6.30.Portable/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
141
Monitored processes
20
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe wscript.exe no specs notepad.exe no specs notepad.exe no specs notepad.exe no specs notepad.exe no specs notepad.exe no specs notepad.exe no specs openwith.exe no specs rundll32.exe no specs openwith.exe no specs slui.exe cmd.exe no specs conhost.exe no specs mpcmdrun.exe no specs notepad.exe no specs notepad.exe no specs notepad.exe no specs notepad.exe no specs notepad.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
664"C:\WINDOWS\System32\OpenWith.exe" C:\Users\admin\Desktop\fipro.lngC:\Windows\System32\OpenWith.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Pick an app
Exit code:
2147943623
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\openwith.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
864"C:\WINDOWS\system32\NOTEPAD.EXE" C:\Users\admin\Desktop\DriveAddRemoveLog.txtC:\Windows\System32\notepad.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\notepad.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
920"C:\WINDOWS\System32\OpenWith.exe" C:\Users\admin\Desktop\plpro.lngC:\Windows\System32\OpenWith.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Pick an app
Exit code:
2147943623
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\openwith.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
1164C:\WINDOWS\system32\cmd.exe /c ""C:\Users\admin\AppData\Local\Temp\Rar$VR1188.41666\Rar$Scan89978.bat" "C:\Windows\System32\cmd.exeWinRAR.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\cmdext.dll
c:\windows\system32\advapi32.dll
1188"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\Desktop\Hard.Disk.Sentinel.Pro.6.30.Portable.zipC:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
2432"C:\WINDOWS\system32\NOTEPAD.EXE" C:\Users\admin\Desktop\hds_eula_en.txtC:\Windows\System32\notepad.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\notepad.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
2656"C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\ieframe.dll",OpenURL %lC:\Windows\System32\rundll32.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shcore.dll
c:\windows\system32\imagehlp.dll
2852"C:\WINDOWS\system32\NOTEPAD.EXE" C:\Users\admin\Desktop\winsched.txtC:\Windows\System32\notepad.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\notepad.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
4112"C:\WINDOWS\system32\NOTEPAD.EXE" C:\Users\admin\Desktop\hdsversion.txtC:\Windows\System32\notepad.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\notepad.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
4688C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
Total events
7 897
Read events
7 888
Write events
9
Delete events
0

Modification events

(PID) Process:(1188) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(1188) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(1188) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(1188) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\Hard.Disk.Sentinel.Pro.6.30.Portable.zip
(PID) Process:(1188) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(1188) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(1188) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(1188) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(1188) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\VirusScan
Operation:writeName:DefScanner
Value:
Windows Defender
Executable files
71
Suspicious files
20
Text files
72
Unknown types
0

Dropped files

PID
Process
Filename
Type
1188WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$VR1188.41666\Hard.Disk.Sentinel.Pro.6.30.Portable.zip\Hard.Disk.Sentinel.Pro.6.30.Portable\App\AppInfo\appinfo.initext
MD5:F184EAB29FEB9485903B4708CB3DA70F
SHA256:AE8A4EF9D98DDE2B70E336DF3DC227AAD25AE8CC7DBAA58F0E72B7F4F21F4B39
1188WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$VR1188.41666\Hard.Disk.Sentinel.Pro.6.30.Portable.zip\Hard.Disk.Sentinel.Pro.6.30.Portable\App\Hard Disk Sentinel\afaapi.dllexecutable
MD5:7C935D1FCDAAF52D129354AA3A83E812
SHA256:6844C0B44970C2F81FCCF3BFE89201A4071408927B794EC46639987DD5A1E419
1188WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$VR1188.41666\Hard.Disk.Sentinel.Pro.6.30.Portable.zip\Hard.Disk.Sentinel.Pro.6.30.Portable\App\Hard Disk Sentinel\arpro.lngtext
MD5:FE00242D2347876D9688C771B4AE64D7
SHA256:C7AF5122EBB984A2C1FB1E580D7A1EAEEB5D7CE12D742EA902B06844ABCECEA9
1188WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$VR1188.41666\Hard.Disk.Sentinel.Pro.6.30.Portable.zip\Hard.Disk.Sentinel.Pro.6.30.Portable\App\Hard Disk Sentinel\109commandlib.dllexecutable
MD5:D05BE9E2ED17E21D8EC2A60E9DA711CD
SHA256:EC74FDE19A73E9EABB64E389D9A9F608569906F0F1A4A644902AB6D19812DDFF
1188WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$VR1188.41666\Hard.Disk.Sentinel.Pro.6.30.Portable.zip\Hard.Disk.Sentinel.Pro.6.30.Portable\App\Hard Disk Sentinel\bc_vbdll.dllexecutable
MD5:2942776DE4FBFE3AA7809648DEC131C9
SHA256:7E123A61A4A9E2E73933EC8E06A4B1BB4ACDD95F454640A11C58AAC417B2FF5D
1188WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$VR1188.41666\Hard.Disk.Sentinel.Pro.6.30.Portable.zip\Hard.Disk.Sentinel.Pro.6.30.Portable\App\Hard Disk Sentinel\ar.lngtext
MD5:B9A5304AE87C230B2BDBC0538A791992
SHA256:1B989B62C088F5966597A14F6E3409B481E6E8340EF044BE8DD0DB28D14071F1
1188WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$VR1188.41666\Hard.Disk.Sentinel.Pro.6.30.Portable.zip\Hard.Disk.Sentinel.Pro.6.30.Portable\App\Hard Disk Sentinel\be.lngtext
MD5:6BBDE5DA7E932156EB1B74C8B69E98E0
SHA256:FE83516E5E3466818CF50CE4C23D37A8EFFEBFF12D3EBD0E46888131FC7B7829
1188WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$VR1188.41666\Hard.Disk.Sentinel.Pro.6.30.Portable.zip\Hard.Disk.Sentinel.Pro.6.30.Portable\App\Hard Disk Sentinel\bepro.lngtext
MD5:C0765AE21CEF0093C9544BF84D20C67E
SHA256:83D490F8D358AC3D62C1A8081CD1AAAD874873F2019BAFBCE483E1B353CF1BD5
1188WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$VR1188.41666\Hard.Disk.Sentinel.Pro.6.30.Portable.zip\Hard.Disk.Sentinel.Pro.6.30.Portable\App\Hard Disk Sentinel\bg.lngtext
MD5:46C5171E86C2E1F2966F0A9DE7DB8B51
SHA256:3F5349CA33CDAC2DA55CBB9D970246A15D7610B5BAC2CAE4569E1EB6B2E4E9A6
1188WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$VR1188.41666\Hard.Disk.Sentinel.Pro.6.30.Portable.zip\Hard.Disk.Sentinel.Pro.6.30.Portable\App\AppInfo\Launcher\Hard DiskSentinelPortable.initext
MD5:B5D0483F61F0BECDEA240336E0AF4E25
SHA256:1E14FB09A0A175E360396C508A09505B4D8ED40465B38FF3EE73450E9AFCF338
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
22
DNS requests
6
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2516
RUXIMICS.exe
GET
200
23.219.150.101:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
2516
RUXIMICS.exe
GET
200
2.16.164.49:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
POST
500
40.91.76.224:443
https://activation-v2.sls.microsoft.com/SLActivateProduct/SLActivateProduct.asmx?configextension=Retail
unknown
xml
512 b
whitelisted
POST
500
40.91.76.224:443
https://activation-v2.sls.microsoft.com/SLActivateProduct/SLActivateProduct.asmx?configextension=Retail
unknown
xml
512 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
2516
RUXIMICS.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
2516
RUXIMICS.exe
2.16.164.49:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
2516
RUXIMICS.exe
23.219.150.101:80
www.microsoft.com
AKAMAI-AS
CL
whitelisted
6044
slui.exe
20.83.72.98:443
activation-v2.sls.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4688
slui.exe
20.83.72.98:443
activation-v2.sls.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 4.231.128.59
whitelisted
google.com
  • 142.250.184.238
whitelisted
crl.microsoft.com
  • 2.16.164.49
  • 2.16.164.120
whitelisted
www.microsoft.com
  • 23.219.150.101
whitelisted
activation-v2.sls.microsoft.com
  • 20.83.72.98
whitelisted

Threats

No threats detected
No debug info