File name:

winrar-x64-713.exe

Full analysis: https://app.any.run/tasks/8fda9ec7-8adc-44c0-8132-607948cc3289
Verdict: Malicious activity
Analysis date: August 05, 2025, 19:09:45
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32+ executable (GUI) x86-64, for MS Windows, 8 sections
MD5:

53EF4972D65304468D2519AA692001C8

SHA1:

095036F9669230CB69B42EB5E6D91FDBE46AB61E

SHA256:

DBC951B4AB01646888B2A91DA73A94DD920054C2F27C8CFEACAE3EBA298E71B0

SSDEEP:

98304:UdtrhhyAtLkgf5A+ibt2CYzceyrDiy9/eYvYOHWoFlVV7cBchF5/XkKOyrNtM4Xg:U+14vKpQb

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • winrar-x64-713.exe (PID: 6408)
    • Reads Microsoft Outlook installation path

      • winrar-x64-713.exe (PID: 6408)
    • Reads Internet Explorer settings

      • winrar-x64-713.exe (PID: 6408)
    • Reads the date of Windows installation

      • winrar-x64-713.exe (PID: 6408)
    • Executable content was dropped or overwritten

      • winrar-x64-713.exe (PID: 6408)
    • Drops 7-zip archiver for unpacking

      • winrar-x64-713.exe (PID: 6408)
    • Creates/Modifies COM task schedule object

      • Uninstall.exe (PID: 620)
    • Searches for installed software

      • Uninstall.exe (PID: 620)
    • Creates a software uninstall entry

      • Uninstall.exe (PID: 620)
  • INFO

    • Checks proxy server information

      • winrar-x64-713.exe (PID: 6408)
    • Reads the computer name

      • winrar-x64-713.exe (PID: 6408)
      • Uninstall.exe (PID: 620)
    • The sample compiled with english language support

      • winrar-x64-713.exe (PID: 6408)
    • Checks supported languages

      • winrar-x64-713.exe (PID: 6408)
      • Uninstall.exe (PID: 620)
    • Creates files in the program directory

      • winrar-x64-713.exe (PID: 6408)
      • Uninstall.exe (PID: 620)
    • Process checks computer location settings

      • winrar-x64-713.exe (PID: 6408)
    • The sample compiled with russian language support

      • winrar-x64-713.exe (PID: 6408)
    • Creates files or folders in the user directory

      • Uninstall.exe (PID: 620)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (87.3)
.exe | Generic Win/DOS Executable (6.3)
.exe | DOS Executable Generic (6.3)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2025:07:28 09:26:39+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 14.44
CodeSize: 257024
InitializedDataSize: 286208
UninitializedDataSize: -
EntryPoint: 0x261f0
OSVersion: 6.1
ImageVersion: -
SubsystemVersion: 6.1
Subsystem: Windows GUI
FileVersionNumber: 7.13.0.0
ProductVersionNumber: 7.13.0.0
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
ProductName: WinRAR
CompanyName: Alexander Roshal
FileDescription: WinRAR
FileVersion: 7.13.0
ProductVersion: 7.13.0
InternalName: WinRAR
LegalCopyright: Copyright © Alexander Roshal 1993-2025
OriginalFileName: WinRAR.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
141
Monitored processes
4
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar-x64-713.exe uninstall.exe no specs slui.exe no specs winrar-x64-713.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
620"C:\Program Files\WinRAR\uninstall.exe" /setupC:\Program Files\WinRAR\Uninstall.exewinrar-x64-713.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
HIGH
Description:
Uninstall WinRAR
Exit code:
0
Version:
7.13.0
Modules
Images
c:\program files\winrar\uninstall.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
4948"C:\Users\admin\AppData\Local\Temp\winrar-x64-713.exe" C:\Users\admin\AppData\Local\Temp\winrar-x64-713.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR
Exit code:
3221226540
Version:
7.13.0
Modules
Images
c:\users\admin\appdata\local\temp\winrar-x64-713.exe
c:\windows\system32\ntdll.dll
4948C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
6408"C:\Users\admin\AppData\Local\Temp\winrar-x64-713.exe" C:\Users\admin\AppData\Local\Temp\winrar-x64-713.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
HIGH
Description:
WinRAR
Exit code:
0
Version:
7.13.0
Modules
Images
c:\users\admin\appdata\local\temp\winrar-x64-713.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
1 335
Read events
1 250
Write events
81
Delete events
4

Modification events

(PID) Process:(6408) winrar-x64-713.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(6408) winrar-x64-713.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(6408) winrar-x64-713.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(6408) winrar-x64-713.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\LowRegistry
Operation:delete valueName:AddToFavoritesInitialSelection
Value:
(PID) Process:(6408) winrar-x64-713.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\LowRegistry
Operation:delete valueName:AddToFeedsInitialSelection
Value:
(PID) Process:(6408) winrar-x64-713.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR SFX
Operation:writeName:C%%Program Files%WinRAR
Value:
C:\Program Files\WinRAR
(PID) Process:(620) Uninstall.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Setup\.rar
Operation:writeName:Set
Value:
1
(PID) Process:(620) Uninstall.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Setup\.zip
Operation:writeName:Set
Value:
1
(PID) Process:(620) Uninstall.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Setup\.cab
Operation:writeName:Set
Value:
1
(PID) Process:(620) Uninstall.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Setup\.arj
Operation:writeName:Set
Value:
1
Executable files
13
Suspicious files
1
Text files
11
Unknown types
10

Dropped files

PID
Process
Filename
Type
6408winrar-x64-713.exe
MD5:
SHA256:
6408winrar-x64-713.exeC:\Program Files\WinRAR\Rar.txttext
MD5:2D72961DB876B6EECD97D87C76A76144
SHA256:6DD26A6A89A4C14E27B347B2A82510405A42CBD4B8441B2AB57712C3E06EF122
6408winrar-x64-713.exeC:\Program Files\WinRAR\Order.htmhtml
MD5:BA699B5D3B89E076E11E58894AD9370C
SHA256:4F4FF8C72C11793E61CE52443810EEA9DF1FD67622FDFBCF80832E05D8A25CB5
6408winrar-x64-713.exeC:\Program Files\WinRAR\License.txttext
MD5:672064CF19DB0B083B981CF0BE7662B0
SHA256:9FC8AA33CCAFA04C1CE4C0A61047B341297D720ADAB1B77F67B5FE59F43BB59F
6408winrar-x64-713.exeC:\Program Files\WinRAR\Rar.exeexecutable
MD5:10913ED85C79C1DAFBBBFF343C73471B
SHA256:A7A155934662984A5063D8D9215DC5E226AA12F4E04FCA932574EA075E32DD3A
6408winrar-x64-713.exeC:\Program Files\WinRAR\RarFiles.lsttext
MD5:6CC00DFAE2BE18311BB961F4E07BB18E
SHA256:9CC712F36C3B6DBF8970DE9522ED9A44A2C018BAC291193A89AECF9567A3C7C9
6408winrar-x64-713.exeC:\Program Files\WinRAR\7zxa.dllexecutable
MD5:120508BCF2E91C722B832B7AC7772A01
SHA256:3C7EA2144B1738B30E3C2E1BA952684EB43C704A5AE82A4DD492D607A42C517C
6408winrar-x64-713.exeC:\Program Files\WinRAR\RarExtInstaller.exeexecutable
MD5:6B5EA97F14A6332C110FB37C32D22D97
SHA256:267E3F3F4FA5201F980063B289A6140423480B8BA9D6361B5D06A76AF709D011
6408winrar-x64-713.exeC:\Program Files\WinRAR\RarExt.dllexecutable
MD5:49FD5E4A41745BBF95973B7638BA7C9A
SHA256:01EAAB6A082AB12F9227568D841405BF4764F1AA93CFDA285EDACEE5B81DEDAC
6408winrar-x64-713.exeC:\Program Files\WinRAR\Uninstall.exeexecutable
MD5:7C7FADFC3884853FE0141609FDB1E624
SHA256:39BAA167DE334FEF185AE8B97E8C709A307EED08E80FE115577C59A05200A13A
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
21
DNS requests
15
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1268
svchost.exe
GET
200
23.48.23.54:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
1268
svchost.exe
GET
200
23.32.97.216:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
3540
svchost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
4080
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
4080
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
1268
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5944
MoUsoCoreWorker.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
828
RUXIMICS.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
1268
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1268
svchost.exe
23.48.23.54:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
1268
svchost.exe
23.32.97.216:80
www.microsoft.com
AKAMAI-AS
SE
whitelisted
5944
MoUsoCoreWorker.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
3540
svchost.exe
40.126.32.134:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
  • 40.127.240.158
  • 51.124.78.146
whitelisted
google.com
  • 172.217.16.206
whitelisted
crl.microsoft.com
  • 23.48.23.54
  • 23.48.23.5
  • 23.48.23.67
  • 23.48.23.44
  • 23.48.23.49
  • 23.48.23.53
  • 23.48.23.66
  • 23.48.23.63
  • 23.48.23.55
whitelisted
www.microsoft.com
  • 23.32.97.216
  • 95.101.149.131
whitelisted
login.live.com
  • 40.126.32.134
  • 20.190.160.64
  • 40.126.32.140
  • 20.190.160.67
  • 20.190.160.131
  • 20.190.160.132
  • 20.190.160.3
  • 40.126.32.133
whitelisted
ocsp.digicert.com
  • 184.30.131.245
whitelisted
slscr.update.microsoft.com
  • 20.12.23.50
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 20.242.39.171
whitelisted
self.events.data.microsoft.com
  • 20.189.173.25
whitelisted
activation-v2.sls.microsoft.com
  • 40.91.76.224
whitelisted

Threats

No threats detected
No debug info