analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

test.rar

Full analysis: https://app.any.run/tasks/3ec86459-b30a-4477-a7d7-42ca4749a855
Verdict: Malicious activity
Analysis date: March 14, 2019, 17:06:08
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/octet-stream
File info: ACE archive data version 20, from Win/32, version 20 to extract, contains AV-String (unregistered), solid
MD5:

7E708BC0122A480F1D350C4BAD2A9497

SHA1:

30284DC85276AC3654FC468EE42518110BB95285

SHA256:

D79A28A766206292EA87CE835CA98DE2C84EACDCA891E3F42019B5892B61836C

SSDEEP:

6144:uzyGb3MWl8spY9wCnFveTmURmag05gfzDVlVXg:cjMRspGwQveT405GpX

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Writes to a start menu file

      • msconfig.exe (PID: 3324)
    • Changes the autorun value in the registry

      • msconfig.exe (PID: 3324)
  • SUSPICIOUS

    • Creates files in the Windows directory

      • msconfig.exe (PID: 3324)
    • Removes files from Windows directory

      • msconfig.exe (PID: 3324)
    • Creates files in the user directory

      • msconfig.exe (PID: 3324)
    • Low-level read access rights to disk partition

      • msconfig.exe (PID: 3324)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.ace | ACE compressed archive (100)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
38
Monitored processes
3
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe no specs msconfig.exe no specs msconfig.exe

Process information

PID
CMD
Path
Indicators
Parent process
3480"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\test.rar"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
1073807364
Version:
5.60.0
2256"C:\Windows\system32\msconfig.exe" C:\Windows\system32\msconfig.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
System Configuration Utility
Exit code:
3221226540
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
3324"C:\Windows\system32\msconfig.exe" C:\Windows\system32\msconfig.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
System Configuration Utility
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Total events
863
Read events
456
Write events
0
Delete events
0

Modification events

No data
Executable files
0
Suspicious files
0
Text files
0
Unknown types
7

Dropped files

PID
Process
Filename
Type
3324msconfig.exe\\?\Volume{e1a82db3-a9f0-11e7-b142-806e6f6e6963}\Boot\BCD
MD5:
SHA256:
3324msconfig.exe\\?\Volume{e1a82db3-a9f0-11e7-b142-806e6f6e6963}\Boot\BCD.LOG
MD5:
SHA256:
3324msconfig.exeC:\Windows\pss\boot.backuphiv
MD5:177531DA37D2209E39C91DDFCDC226FC
SHA256:D5C1B519DC99E1D1062B1D019648DCFF776FE8454BA725F589EF6ADCFF77CCBF
3324msconfig.exeC:\Windows\pss\boot.backup.LOGlog
MD5:A010DB9959972B9DFA7962C3AF3DFE47
SHA256:FEE0D12CD0A43DB226A164BDF199D1B880F49C010C0A393471C0B8E513CE0C1E
3324msconfig.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnklnk
MD5:A29336CE3EFA12A21F505F05CD61BBB9
SHA256:D797517A3D77E95A1E6FFD29448EB85C3CA2F16BD1AFC057AC5803EE3D91382D
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info