File name:

fsdfsdfsd.rar

Full analysis: https://app.any.run/tasks/a35565a1-6c93-4c7b-8d6a-27a247c8df39
Verdict: Malicious activity
Analysis date: December 06, 2023, 10:53:47
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

8A04766637CDEC1397FD0430BCA80427

SHA1:

DC98C8A4F823BFDEB09B95203C9ADF108A75B981

SHA256:

D6D57A0FE2037C9B26F54DFCD4E1D55AC9F476F46C72E88E0BFBBC4C4B1A0852

SSDEEP:

98304:/cG1RzLZIrAuzNsb6QaU8ESX68vyiT2BmLhgXVCDFl11r4/FQhOcOGKeclJqBU0k:+3aqW7mrDPnm

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • eyeBeam.exe (PID: 3216)
      • is-AP499.tmp (PID: 3940)
      • is-0VD36.exe (PID: 2044)
      • unins000.exe (PID: 3100)
      • _iu14D2N.tmp (PID: 3116)
      • eyeBeam.exe (PID: 3368)
      • is-RAI2S.tmp (PID: 3380)
      • eyeBeam.exe (PID: 2364)
      • is-2G61A.tmp (PID: 2372)
    • Changes the autorun value in the registry

      • _iu14D2N.tmp (PID: 3116)
  • SUSPICIOUS

    • Reads the Windows owner or organization settings

      • is-AP499.tmp (PID: 3940)
      • is-RAI2S.tmp (PID: 3380)
      • _iu14D2N.tmp (PID: 3116)
      • is-2G61A.tmp (PID: 2372)
    • Process drops legitimate windows executable

      • is-AP499.tmp (PID: 3940)
      • _iu14D2N.tmp (PID: 3116)
      • is-RAI2S.tmp (PID: 3380)
      • is-2G61A.tmp (PID: 2372)
    • The process drops C-runtime libraries

      • is-AP499.tmp (PID: 3940)
      • is-RAI2S.tmp (PID: 3380)
    • The process executes via Task Scheduler

      • sipnotify.exe (PID: 1460)
      • ctfmon.exe (PID: 1716)
    • Reads the Internet Settings

      • sipnotify.exe (PID: 1460)
      • runonce.exe (PID: 2028)
      • is-RAI2S.tmp (PID: 3380)
    • Starts application with an unusual extension

      • unins000.exe (PID: 3100)
    • Reads settings of System Certificates

      • sipnotify.exe (PID: 1460)
    • Starts itself from another location

      • unins000.exe (PID: 3100)
    • Searches for installed software

      • is-2G61A.tmp (PID: 2372)
  • INFO

    • Checks supported languages

      • eyeBeam.exe (PID: 3216)
      • is-AP499.tmp (PID: 3940)
      • is-0VD36.exe (PID: 2044)
      • IMEKLMG.EXE (PID: 2036)
      • IMEKLMG.EXE (PID: 1944)
      • eyeBeam.exe (PID: 2020)
      • wmpnscfg.exe (PID: 2520)
      • _iu14D2N.tmp (PID: 3116)
      • unins000.exe (PID: 3100)
      • wmpnscfg.exe (PID: 2472)
      • eyeBeam.exe (PID: 3368)
      • is-RAI2S.tmp (PID: 3380)
      • eyeBeam.exe (PID: 3472)
      • eyeBeam.exe (PID: 2364)
      • is-2G61A.tmp (PID: 2372)
    • Manual execution by a user

      • eyeBeam.exe (PID: 3216)
      • eyeBeam.exe (PID: 2600)
      • runonce.exe (PID: 2028)
      • IMEKLMG.EXE (PID: 2036)
      • IMEKLMG.EXE (PID: 1944)
      • eyeBeam.exe (PID: 2020)
      • wmpnscfg.exe (PID: 2520)
      • notepad.exe (PID: 2836)
      • unins000.exe (PID: 3100)
      • wmpnscfg.exe (PID: 2472)
      • unins000.exe (PID: 3000)
      • eyeBeam.exe (PID: 3268)
      • eyeBeam.exe (PID: 3368)
      • eyeBeam.exe (PID: 2364)
      • eyeBeam.exe (PID: 948)
    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 3048)
    • Create files in a temporary directory

      • eyeBeam.exe (PID: 3216)
      • is-AP499.tmp (PID: 3940)
      • unins000.exe (PID: 3100)
      • _iu14D2N.tmp (PID: 3116)
      • is-RAI2S.tmp (PID: 3380)
      • eyeBeam.exe (PID: 3368)
      • eyeBeam.exe (PID: 2364)
      • is-2G61A.tmp (PID: 2372)
    • Creates files in the program directory

      • is-AP499.tmp (PID: 3940)
      • is-RAI2S.tmp (PID: 3380)
    • Reads the computer name

      • eyeBeam.exe (PID: 3216)
      • is-AP499.tmp (PID: 3940)
      • IMEKLMG.EXE (PID: 2036)
      • IMEKLMG.EXE (PID: 1944)
      • eyeBeam.exe (PID: 2020)
      • wmpnscfg.exe (PID: 2472)
      • wmpnscfg.exe (PID: 2520)
      • _iu14D2N.tmp (PID: 3116)
      • is-RAI2S.tmp (PID: 3380)
      • eyeBeam.exe (PID: 3472)
    • Reads the time zone

      • runonce.exe (PID: 2028)
    • Reads security settings of Internet Explorer

      • sipnotify.exe (PID: 1460)
    • Process checks are UAC notifies on

      • IMEKLMG.EXE (PID: 2036)
      • IMEKLMG.EXE (PID: 1944)
    • Reads CPU info

      • eyeBeam.exe (PID: 2020)
      • eyeBeam.exe (PID: 3472)
    • Reads the machine GUID from the registry

      • wmpnscfg.exe (PID: 2472)
      • wmpnscfg.exe (PID: 2520)
      • eyeBeam.exe (PID: 2020)
      • eyeBeam.exe (PID: 3472)
    • Creates files or folders in the user directory

      • eyeBeam.exe (PID: 2020)
      • eyeBeam.exe (PID: 3472)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
125
Monitored processes
24
Malicious processes
7
Suspicious processes
2

Behavior graph

Click at the process to see the details
start winrar.exe no specs eyebeam.exe no specs eyebeam.exe is-ap499.tmp no specs sipnotify.exe ctfmon.exe no specs runonce.exe is-0vd36.exe no specs imeklmg.exe no specs imeklmg.exe no specs eyebeam.exe wmpnscfg.exe no specs wmpnscfg.exe no specs notepad.exe no specs unins000.exe no specs unins000.exe _iu14d2n.tmp eyebeam.exe no specs eyebeam.exe is-rai2s.tmp no specs eyebeam.exe eyebeam.exe no specs eyebeam.exe is-2g61a.tmp no specs

Process information

PID
CMD
Path
Indicators
Parent process
948"C:\Users\admin\Desktop\eyeBeam.exe" C:\Users\admin\Desktop\eyeBeam.exeexplorer.exe
User:
admin
Company:
CounterPath Solutions Inc.
Integrity Level:
MEDIUM
Description:
eyeBeam Setup
Exit code:
3221226540
Version:
Modules
Images
c:\users\admin\desktop\eyebeam.exe
c:\windows\system32\ntdll.dll
1460C:\Windows\system32\sipnotify.exe -LogonOrUnlockC:\Windows\System32\sipnotify.exe
taskeng.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
sipnotify
Exit code:
0
Version:
6.1.7602.20480 (win7sp1_ldr_escrow.191010-1716)
Modules
Images
c:\windows\system32\sipnotify.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1716C:\Windows\System32\ctfmon.exe C:\Windows\System32\ctfmon.exetaskeng.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
CTF Loader
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ctfmon.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msctfmonitor.dll
c:\windows\system32\msctf.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
1944"C:\Program Files\Common Files\microsoft shared\IME14\SHARED\IMEKLMG.EXE" /SetPreload /KOR /LogC:\Program Files\Common Files\microsoft shared\IME14\SHARED\IMEKLMG.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Office IME 2010
Exit code:
1
Version:
14.0.4734.1000
Modules
Images
c:\program files\common files\microsoft shared\ime14\shared\imeklmg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\userenv.dll
2020"C:\Program Files\CounterPath\eyeBeam 1.5\eyeBeam.exe" C:\Program Files\CounterPath\eyeBeam 1.5\eyeBeam.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\program files\counterpath\eyebeam 1.5\eyebeam.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2028runonce.exe /ExplorerC:\Windows\System32\runonce.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Run Once Wrapper
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\runonce.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2036"C:\Program Files\Common Files\microsoft shared\IME14\SHARED\IMEKLMG.EXE" /SetPreload /JPN /LogC:\Program Files\Common Files\microsoft shared\IME14\SHARED\IMEKLMG.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Office IME 2010
Exit code:
1
Version:
14.0.4734.1000
Modules
Images
c:\program files\common files\microsoft shared\ime14\shared\imeklmg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\userenv.dll
2044"C:\Windows\is-0VD36.exe" /REGC:\Windows\is-0VD36.exerunonce.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.42.0.0
Modules
Images
c:\windows\is-0vd36.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
2364"C:\Users\admin\Desktop\eyeBeam.exe" C:\Users\admin\Desktop\eyeBeam.exe
explorer.exe
User:
admin
Company:
CounterPath Solutions Inc.
Integrity Level:
HIGH
Description:
eyeBeam Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\desktop\eyebeam.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
2372"C:\Users\admin\AppData\Local\Temp\is-D8I7P.tmp\is-2G61A.tmp" /SL4 $801BE "C:\Users\admin\Desktop\eyeBeam.exe" 6044273 52224 C:\Users\admin\AppData\Local\Temp\is-D8I7P.tmp\is-2G61A.tmpeyeBeam.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.42.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-d8i7p.tmp\is-2g61a.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
Total events
10 709
Read events
10 567
Write events
66
Delete events
76

Modification events

(PID) Process:(3048) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\17F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3048) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(3048) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(3048) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(3048) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3048) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3048) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3048) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3048) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000
(PID) Process:(3048) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\General
Operation:writeName:LastFolder
Value:
C:\Users\admin\Desktop
Executable files
88
Suspicious files
13
Text files
69
Unknown types
0

Dropped files

PID
Process
Filename
Type
3940is-AP499.tmpC:\Users\admin\AppData\Local\Temp\is-1JLFI.tmp\psvince.dllexecutable
MD5:A4E5C512B047A6D9DC38549161CAC4DE
SHA256:C7F1E7E866834D9024F97C2B145C09D106E447E8ABD65A10A1732116D178E44E
3940is-AP499.tmpC:\Program Files\CounterPath\eyeBeam 1.5\eyeBeam.exeexecutable
MD5:14291C7B098A5A41C610F18EAF511A68
SHA256:02A80E536084C318BE2C06866623C8D4297DA39AFF5E08915CFB809A361AB629
3940is-AP499.tmpC:\Program Files\CounterPath\eyeBeam 1.5\is-PPAT0.tmpexecutable
MD5:561FA2ABB31DFA8FAB762145F81667C2
SHA256:DF96156F6A548FD6FE5672918DE5AE4509D3C810A57BFFD2A91DE45A3ED5B23B
3940is-AP499.tmpC:\Program Files\CounterPath\eyeBeam 1.5\uninstall.icoimage
MD5:5A77AB01BB917BB0F539B07614A6135F
SHA256:16C1B2FA5AD3D758B51E1757B3AB6A1DD1E79391703010E7793CBC4B8F85E55F
3940is-AP499.tmpC:\Program Files\CounterPath\eyeBeam 1.5\is-UO7QF.tmpexecutable
MD5:14291C7B098A5A41C610F18EAF511A68
SHA256:02A80E536084C318BE2C06866623C8D4297DA39AFF5E08915CFB809A361AB629
3940is-AP499.tmpC:\Program Files\CounterPath\eyeBeam 1.5\is-2IHS3.tmpimage
MD5:5A77AB01BB917BB0F539B07614A6135F
SHA256:16C1B2FA5AD3D758B51E1757B3AB6A1DD1E79391703010E7793CBC4B8F85E55F
3940is-AP499.tmpC:\Program Files\CounterPath\eyeBeam 1.5\is-L0MSJ.tmpexecutable
MD5:A4E5C512B047A6D9DC38549161CAC4DE
SHA256:C7F1E7E866834D9024F97C2B145C09D106E447E8ABD65A10A1732116D178E44E
3940is-AP499.tmpC:\Program Files\CounterPath\eyeBeam 1.5\psvince.dllexecutable
MD5:A4E5C512B047A6D9DC38549161CAC4DE
SHA256:C7F1E7E866834D9024F97C2B145C09D106E447E8ABD65A10A1732116D178E44E
3940is-AP499.tmpC:\Program Files\CounterPath\eyeBeam 1.5\is-7ML7C.tmpexecutable
MD5:9ACBFD87E94D7BECDE2B9253E0165309
SHA256:828D5492244861493C4C1F18B1CF885187C43220AF969BBF3BFAB4F8AE56FC83
3940is-AP499.tmpC:\Program Files\CounterPath\eyeBeam 1.5\is-PV8C5.tmpexecutable
MD5:86F1895AE8C5E8B17D99ECE768A70732
SHA256:8094AF5EE310714CAEBCCAEEE7769FFB08048503BA478B879EDFEF5F1A24FEFE
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
14
DNS requests
5
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1460
sipnotify.exe
HEAD
200
23.199.215.176:80
http://query.prod.cms.rt.microsoft.com/cms/api/am/binary/RE2JgkA?v=133463336713750000
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
unknown
4
System
192.168.100.255:137
unknown
2588
svchost.exe
239.255.255.250:1900
unknown
1080
svchost.exe
224.0.0.252:5355
unknown
1100
svchost.exe
224.0.0.252:5355
unknown
1460
sipnotify.exe
23.199.215.176:80
query.prod.cms.rt.microsoft.com
AKAMAI-AS
DE
unknown
2688
svchost.exe
239.255.255.250:1900
unknown
2020
eyeBeam.exe
141.193.213.21:443
upgrades.counterpath.com
Cloudflare London, LLC
US
unknown
1412
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
1412
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown

DNS requests

Domain
IP
Reputation
query.prod.cms.rt.microsoft.com
  • 23.199.215.176
unknown
upgrades.counterpath.com
  • 141.193.213.21
  • 141.193.213.20
unknown
settings-win.data.microsoft.com
  • 51.104.136.2
  • 40.127.240.158
unknown
dns.msftncsi.com
  • 131.107.255.255
unknown

Threats

No threats detected
No debug info