File name:

fsdfsdfsd.rar

Full analysis: https://app.any.run/tasks/a35565a1-6c93-4c7b-8d6a-27a247c8df39
Verdict: Malicious activity
Analysis date: December 06, 2023, 10:53:47
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

8A04766637CDEC1397FD0430BCA80427

SHA1:

DC98C8A4F823BFDEB09B95203C9ADF108A75B981

SHA256:

D6D57A0FE2037C9B26F54DFCD4E1D55AC9F476F46C72E88E0BFBBC4C4B1A0852

SSDEEP:

98304:/cG1RzLZIrAuzNsb6QaU8ESX68vyiT2BmLhgXVCDFl11r4/FQhOcOGKeclJqBU0k:+3aqW7mrDPnm

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • eyeBeam.exe (PID: 3216)
      • is-AP499.tmp (PID: 3940)
      • is-0VD36.exe (PID: 2044)
      • unins000.exe (PID: 3100)
      • _iu14D2N.tmp (PID: 3116)
      • eyeBeam.exe (PID: 3368)
      • is-RAI2S.tmp (PID: 3380)
      • eyeBeam.exe (PID: 2364)
      • is-2G61A.tmp (PID: 2372)
    • Changes the autorun value in the registry

      • _iu14D2N.tmp (PID: 3116)
  • SUSPICIOUS

    • Reads the Windows owner or organization settings

      • is-AP499.tmp (PID: 3940)
      • _iu14D2N.tmp (PID: 3116)
      • is-RAI2S.tmp (PID: 3380)
      • is-2G61A.tmp (PID: 2372)
    • Process drops legitimate windows executable

      • is-AP499.tmp (PID: 3940)
      • _iu14D2N.tmp (PID: 3116)
      • is-RAI2S.tmp (PID: 3380)
      • is-2G61A.tmp (PID: 2372)
    • The process drops C-runtime libraries

      • is-AP499.tmp (PID: 3940)
      • is-RAI2S.tmp (PID: 3380)
    • The process executes via Task Scheduler

      • sipnotify.exe (PID: 1460)
      • ctfmon.exe (PID: 1716)
    • Reads the Internet Settings

      • sipnotify.exe (PID: 1460)
      • runonce.exe (PID: 2028)
      • is-RAI2S.tmp (PID: 3380)
    • Starts itself from another location

      • unins000.exe (PID: 3100)
    • Starts application with an unusual extension

      • unins000.exe (PID: 3100)
    • Reads settings of System Certificates

      • sipnotify.exe (PID: 1460)
    • Searches for installed software

      • is-2G61A.tmp (PID: 2372)
  • INFO

    • Create files in a temporary directory

      • is-AP499.tmp (PID: 3940)
      • eyeBeam.exe (PID: 3216)
      • unins000.exe (PID: 3100)
      • _iu14D2N.tmp (PID: 3116)
      • is-RAI2S.tmp (PID: 3380)
      • eyeBeam.exe (PID: 3368)
      • is-2G61A.tmp (PID: 2372)
      • eyeBeam.exe (PID: 2364)
    • Checks supported languages

      • eyeBeam.exe (PID: 3216)
      • is-AP499.tmp (PID: 3940)
      • is-0VD36.exe (PID: 2044)
      • IMEKLMG.EXE (PID: 2036)
      • IMEKLMG.EXE (PID: 1944)
      • eyeBeam.exe (PID: 2020)
      • wmpnscfg.exe (PID: 2520)
      • _iu14D2N.tmp (PID: 3116)
      • unins000.exe (PID: 3100)
      • wmpnscfg.exe (PID: 2472)
      • is-RAI2S.tmp (PID: 3380)
      • eyeBeam.exe (PID: 3368)
      • eyeBeam.exe (PID: 2364)
      • is-2G61A.tmp (PID: 2372)
      • eyeBeam.exe (PID: 3472)
    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 3048)
    • Manual execution by a user

      • eyeBeam.exe (PID: 3216)
      • eyeBeam.exe (PID: 2600)
      • runonce.exe (PID: 2028)
      • IMEKLMG.EXE (PID: 1944)
      • IMEKLMG.EXE (PID: 2036)
      • eyeBeam.exe (PID: 2020)
      • unins000.exe (PID: 3000)
      • wmpnscfg.exe (PID: 2520)
      • unins000.exe (PID: 3100)
      • notepad.exe (PID: 2836)
      • wmpnscfg.exe (PID: 2472)
      • eyeBeam.exe (PID: 3268)
      • eyeBeam.exe (PID: 3368)
      • eyeBeam.exe (PID: 948)
      • eyeBeam.exe (PID: 2364)
    • Reads the computer name

      • is-AP499.tmp (PID: 3940)
      • eyeBeam.exe (PID: 3216)
      • IMEKLMG.EXE (PID: 2036)
      • IMEKLMG.EXE (PID: 1944)
      • eyeBeam.exe (PID: 2020)
      • wmpnscfg.exe (PID: 2472)
      • wmpnscfg.exe (PID: 2520)
      • _iu14D2N.tmp (PID: 3116)
      • is-RAI2S.tmp (PID: 3380)
      • eyeBeam.exe (PID: 3472)
    • Creates files in the program directory

      • is-AP499.tmp (PID: 3940)
      • is-RAI2S.tmp (PID: 3380)
    • Reads the time zone

      • runonce.exe (PID: 2028)
    • Process checks are UAC notifies on

      • IMEKLMG.EXE (PID: 2036)
      • IMEKLMG.EXE (PID: 1944)
    • Reads CPU info

      • eyeBeam.exe (PID: 2020)
      • eyeBeam.exe (PID: 3472)
    • Reads security settings of Internet Explorer

      • sipnotify.exe (PID: 1460)
    • Reads the machine GUID from the registry

      • eyeBeam.exe (PID: 2020)
      • wmpnscfg.exe (PID: 2472)
      • wmpnscfg.exe (PID: 2520)
      • eyeBeam.exe (PID: 3472)
    • Creates files or folders in the user directory

      • eyeBeam.exe (PID: 2020)
      • eyeBeam.exe (PID: 3472)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
125
Monitored processes
24
Malicious processes
7
Suspicious processes
2

Behavior graph

Click at the process to see the details
start winrar.exe no specs eyebeam.exe no specs eyebeam.exe is-ap499.tmp no specs sipnotify.exe ctfmon.exe no specs runonce.exe is-0vd36.exe no specs imeklmg.exe no specs imeklmg.exe no specs eyebeam.exe wmpnscfg.exe no specs wmpnscfg.exe no specs notepad.exe no specs unins000.exe no specs unins000.exe _iu14d2n.tmp eyebeam.exe no specs eyebeam.exe is-rai2s.tmp no specs eyebeam.exe eyebeam.exe no specs eyebeam.exe is-2g61a.tmp no specs

Process information

PID
CMD
Path
Indicators
Parent process
948"C:\Users\admin\Desktop\eyeBeam.exe" C:\Users\admin\Desktop\eyeBeam.exeexplorer.exe
User:
admin
Company:
CounterPath Solutions Inc.
Integrity Level:
MEDIUM
Description:
eyeBeam Setup
Exit code:
3221226540
Version:
Modules
Images
c:\users\admin\desktop\eyebeam.exe
c:\windows\system32\ntdll.dll
1460C:\Windows\system32\sipnotify.exe -LogonOrUnlockC:\Windows\System32\sipnotify.exe
taskeng.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
sipnotify
Exit code:
0
Version:
6.1.7602.20480 (win7sp1_ldr_escrow.191010-1716)
Modules
Images
c:\windows\system32\sipnotify.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1716C:\Windows\System32\ctfmon.exe C:\Windows\System32\ctfmon.exetaskeng.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
CTF Loader
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ctfmon.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msctfmonitor.dll
c:\windows\system32\msctf.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
1944"C:\Program Files\Common Files\microsoft shared\IME14\SHARED\IMEKLMG.EXE" /SetPreload /KOR /LogC:\Program Files\Common Files\microsoft shared\IME14\SHARED\IMEKLMG.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Office IME 2010
Exit code:
1
Version:
14.0.4734.1000
Modules
Images
c:\program files\common files\microsoft shared\ime14\shared\imeklmg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\userenv.dll
2020"C:\Program Files\CounterPath\eyeBeam 1.5\eyeBeam.exe" C:\Program Files\CounterPath\eyeBeam 1.5\eyeBeam.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\program files\counterpath\eyebeam 1.5\eyebeam.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2028runonce.exe /ExplorerC:\Windows\System32\runonce.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Run Once Wrapper
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\runonce.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2036"C:\Program Files\Common Files\microsoft shared\IME14\SHARED\IMEKLMG.EXE" /SetPreload /JPN /LogC:\Program Files\Common Files\microsoft shared\IME14\SHARED\IMEKLMG.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Office IME 2010
Exit code:
1
Version:
14.0.4734.1000
Modules
Images
c:\program files\common files\microsoft shared\ime14\shared\imeklmg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\userenv.dll
2044"C:\Windows\is-0VD36.exe" /REGC:\Windows\is-0VD36.exerunonce.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.42.0.0
Modules
Images
c:\windows\is-0vd36.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
2364"C:\Users\admin\Desktop\eyeBeam.exe" C:\Users\admin\Desktop\eyeBeam.exe
explorer.exe
User:
admin
Company:
CounterPath Solutions Inc.
Integrity Level:
HIGH
Description:
eyeBeam Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\desktop\eyebeam.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
2372"C:\Users\admin\AppData\Local\Temp\is-D8I7P.tmp\is-2G61A.tmp" /SL4 $801BE "C:\Users\admin\Desktop\eyeBeam.exe" 6044273 52224 C:\Users\admin\AppData\Local\Temp\is-D8I7P.tmp\is-2G61A.tmpeyeBeam.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.42.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-d8i7p.tmp\is-2g61a.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
Total events
10 709
Read events
10 567
Write events
66
Delete events
76

Modification events

(PID) Process:(3048) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\17F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3048) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(3048) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(3048) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(3048) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3048) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3048) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3048) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3048) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000
(PID) Process:(3048) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\General
Operation:writeName:LastFolder
Value:
C:\Users\admin\Desktop
Executable files
88
Suspicious files
13
Text files
69
Unknown types
0

Dropped files

PID
Process
Filename
Type
3048WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3048.2591\EyeBeam Licence.txttext
MD5:04C85DE790ED6AAC07C98980084DC2D2
SHA256:72FFE84E830B80742BACF131A9A7F7E0C89881CE93B7F73C5A7C1996AB30B70B
3940is-AP499.tmpC:\Users\admin\AppData\Local\Temp\is-1JLFI.tmp\_isetup\_shfoldr.dllexecutable
MD5:92DC6EF532FBB4A5C3201469A5B5EB63
SHA256:9884E9D1B4F8A873CCBD81F8AD0AE257776D2348D027D811A56475E028360D87
3216eyeBeam.exeC:\Users\admin\AppData\Local\Temp\is-K55C5.tmp\is-AP499.tmpexecutable
MD5:036EF63E2F9B138A42D6ADB54EC0CD1E
SHA256:71B487F0523F213004766402B22BF86FA0EF9891E940D2A4CB12EBA6627E7CC6
3940is-AP499.tmpC:\Program Files\CounterPath\eyeBeam 1.5\is-PV8C5.tmpexecutable
MD5:86F1895AE8C5E8B17D99ECE768A70732
SHA256:8094AF5EE310714CAEBCCAEEE7769FFB08048503BA478B879EDFEF5F1A24FEFE
3048WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3048.2591\eyeBeam.exeexecutable
MD5:4C316518A39D0C4E6FCB38118459B8A7
SHA256:FF9003FBE397722FE8CC33DE05A1AE1A6ADB447C313F6DC0E3C07B6532D19857
3940is-AP499.tmpC:\Users\admin\AppData\Local\Temp\is-1JLFI.tmp\psvince.dllexecutable
MD5:A4E5C512B047A6D9DC38549161CAC4DE
SHA256:C7F1E7E866834D9024F97C2B145C09D106E447E8ABD65A10A1732116D178E44E
3940is-AP499.tmpC:\Program Files\CounterPath\eyeBeam 1.5\is-2IHS3.tmpimage
MD5:5A77AB01BB917BB0F539B07614A6135F
SHA256:16C1B2FA5AD3D758B51E1757B3AB6A1DD1E79391703010E7793CBC4B8F85E55F
3940is-AP499.tmpC:\Program Files\CounterPath\eyeBeam 1.5\is-L0MSJ.tmpexecutable
MD5:A4E5C512B047A6D9DC38549161CAC4DE
SHA256:C7F1E7E866834D9024F97C2B145C09D106E447E8ABD65A10A1732116D178E44E
3940is-AP499.tmpC:\Program Files\CounterPath\eyeBeam 1.5\eyeBeam.exeexecutable
MD5:14291C7B098A5A41C610F18EAF511A68
SHA256:02A80E536084C318BE2C06866623C8D4297DA39AFF5E08915CFB809A361AB629
3940is-AP499.tmpC:\Program Files\CounterPath\eyeBeam 1.5\is-OBBBF.tmpexecutable
MD5:0642A05567EFA37A76AA3488DA86CB47
SHA256:6396C44397F1780F644E9317F3321B18A5CB026DCF751281B35CC4A07D2A3CF1
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
14
DNS requests
5
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1460
sipnotify.exe
HEAD
200
23.199.215.176:80
http://query.prod.cms.rt.microsoft.com/cms/api/am/binary/RE2JgkA?v=133463336713750000
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
2588
svchost.exe
239.255.255.250:1900
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
1100
svchost.exe
224.0.0.252:5355
unknown
1460
sipnotify.exe
23.199.215.176:80
query.prod.cms.rt.microsoft.com
AKAMAI-AS
DE
unknown
2688
svchost.exe
239.255.255.250:1900
whitelisted
2020
eyeBeam.exe
141.193.213.21:443
upgrades.counterpath.com
Cloudflare London, LLC
US
whitelisted
1412
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1412
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown

DNS requests

Domain
IP
Reputation
query.prod.cms.rt.microsoft.com
  • 23.199.215.176
whitelisted
upgrades.counterpath.com
  • 141.193.213.21
  • 141.193.213.20
unknown
settings-win.data.microsoft.com
  • 51.104.136.2
  • 40.127.240.158
whitelisted
dns.msftncsi.com
  • 131.107.255.255
shared

Threats

No threats detected
No debug info