File name:

Windows.Loader.v2.2.2.7z

Full analysis: https://app.any.run/tasks/70188dcc-7f1f-4bab-9f48-e81488cbc1b9
Verdict: Malicious activity
Analysis date: January 30, 2024, 04:16:47
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-7z-compressed
File info: 7-zip archive data, version 0.4
MD5:

FD64B9F2A79750BE569AC05AFB93699C

SHA1:

316ED5F0E63C48694F3F04F64DB2E39BF5A64CF5

SHA256:

DBF673B8D007957C25655D3B38323CB6A96A545051ED92F4138885E3EA5D0A21

SSDEEP:

49152:j6l4LjcDEklpcdLQByTfxi1VvEQJUY7NKjvSNrXVKBhZTQMNDJxbLF1qhowIYujt:j6lm2HWEoATEAUcNvtFKnF9xnfS3IYuJ

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 268)
  • SUSPICIOUS

    • Reads the BIOS version

      • Windows Loader.exe (PID: 2508)
  • INFO

    • Manual execution by a user

      • Windows Loader.exe (PID: 2508)
      • Windows Loader.exe (PID: 2204)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 268)
    • Reads Environment values

      • Windows Loader.exe (PID: 2508)
    • Reads the machine GUID from the registry

      • Windows Loader.exe (PID: 2508)
    • Reads product name

      • Windows Loader.exe (PID: 2508)
    • Checks supported languages

      • Windows Loader.exe (PID: 2508)
    • Reads the computer name

      • Windows Loader.exe (PID: 2508)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.7z | 7-Zip compressed archive (v0.4) (57.1)
.7z | 7-Zip compressed archive (gen) (42.8)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
44
Monitored processes
3
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe windows loader.exe no specs windows loader.exe

Process information

PID
CMD
Path
Indicators
Parent process
268"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Windows.Loader.v2.2.2.7z"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2204"C:\Users\admin\Desktop\Windows.Loader.v2.2.2\Windows Loader.exe" C:\Users\admin\Desktop\Windows.Loader.v2.2.2\Windows Loader.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\desktop\windows.loader.v2.2.2\windows loader.exe
c:\windows\system32\ntdll.dll
2508"C:\Users\admin\Desktop\Windows.Loader.v2.2.2\Windows Loader.exe" C:\Users\admin\Desktop\Windows.Loader.v2.2.2\Windows Loader.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\desktop\windows.loader.v2.2.2\windows loader.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\gdi32.dll
Total events
1 194
Read events
1 184
Write events
10
Delete events
0

Modification events

(PID) Process:(268) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(268) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(268) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(268) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(268) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(268) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(268) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(268) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(268) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
Executable files
1
Suspicious files
0
Text files
3
Unknown types
0

Dropped files

PID
Process
Filename
Type
268WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa268.21481\Windows.Loader.v2.2.2\Read me.txttext
MD5:3E83D11DCD0D1DC8B6CF531353CF9E81
SHA256:B5FCBF4B91C436640AAB0E8106F942CD47080BF799A22D747B5CF898BD13475C
268WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa268.21481\Windows.Loader.v2.2.2\Windows Loader.exeexecutable
MD5:323C0FD51071400B51EEDB1BE90A8188
SHA256:2F2ABA1E074F5F4BAA08B524875461889F8F04D4FFC43972AC212E286022AB94
268WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa268.21481\Windows.Loader.v2.2.2\checksums(1).md5text
MD5:CAB45D50BE4C1FC788D29593464B1F35
SHA256:C083F57AC4D8A5EAF9BC934F08204A691FA9E4FD275F90AAADFD195A4EEF820F
268WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa268.21481\Windows.Loader.v2.2.2\Keys.initext
MD5:3BA4950BCF43B1C7B714A1D93B57EA86
SHA256:1384C5FD758A1BD8C9372594503E22D71B0877D332886A1B7D50CB86C4A0A13C
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown

DNS requests

No data

Threats

No threats detected
No debug info