| File name: | Windows.Loader.v2.2.2.7z |
| Full analysis: | https://app.any.run/tasks/70188dcc-7f1f-4bab-9f48-e81488cbc1b9 |
| Verdict: | Malicious activity |
| Analysis date: | January 30, 2024, 04:16:47 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-7z-compressed |
| File info: | 7-zip archive data, version 0.4 |
| MD5: | FD64B9F2A79750BE569AC05AFB93699C |
| SHA1: | 316ED5F0E63C48694F3F04F64DB2E39BF5A64CF5 |
| SHA256: | DBF673B8D007957C25655D3B38323CB6A96A545051ED92F4138885E3EA5D0A21 |
| SSDEEP: | 49152:j6l4LjcDEklpcdLQByTfxi1VvEQJUY7NKjvSNrXVKBhZTQMNDJxbLF1qhowIYujt:j6lm2HWEoATEAUcNvtFKnF9xnfS3IYuJ |
| .7z | | | 7-Zip compressed archive (v0.4) (57.1) |
|---|---|---|
| .7z | | | 7-Zip compressed archive (gen) (42.8) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 268 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Windows.Loader.v2.2.2.7z" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| 2204 | "C:\Users\admin\Desktop\Windows.Loader.v2.2.2\Windows Loader.exe" | C:\Users\admin\Desktop\Windows.Loader.v2.2.2\Windows Loader.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 3221226540 Modules
| |||||||||||||||
| 2508 | "C:\Users\admin\Desktop\Windows.Loader.v2.2.2\Windows Loader.exe" | C:\Users\admin\Desktop\Windows.Loader.v2.2.2\Windows Loader.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| (PID) Process: | (268) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (268) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip | |||
| (PID) Process: | (268) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\phacker.zip | |||
| (PID) Process: | (268) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (268) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip | |||
| (PID) Process: | (268) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (268) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (268) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (268) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 268 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa268.21481\Windows.Loader.v2.2.2\Read me.txt | text | |
MD5:3E83D11DCD0D1DC8B6CF531353CF9E81 | SHA256:B5FCBF4B91C436640AAB0E8106F942CD47080BF799A22D747B5CF898BD13475C | |||
| 268 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa268.21481\Windows.Loader.v2.2.2\Windows Loader.exe | executable | |
MD5:323C0FD51071400B51EEDB1BE90A8188 | SHA256:2F2ABA1E074F5F4BAA08B524875461889F8F04D4FFC43972AC212E286022AB94 | |||
| 268 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa268.21481\Windows.Loader.v2.2.2\checksums(1).md5 | text | |
MD5:CAB45D50BE4C1FC788D29593464B1F35 | SHA256:C083F57AC4D8A5EAF9BC934F08204A691FA9E4FD275F90AAADFD195A4EEF820F | |||
| 268 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa268.21481\Windows.Loader.v2.2.2\Keys.ini | text | |
MD5:3BA4950BCF43B1C7B714A1D93B57EA86 | SHA256:1384C5FD758A1BD8C9372594503E22D71B0877D332886A1B7D50CB86C4A0A13C | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |