File name:

winipbin.zip

Full analysis: https://app.any.run/tasks/d9fe395c-b0b6-451b-b6ae-ddfbde36a841
Verdict: Malicious activity
Analysis date: January 07, 2025, 20:23:28
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
arch-exec
arch-scr
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=deflate
MD5:

1DC8A249C00987EC743627428CCAA3FD

SHA1:

1CF0778476D2384F6194438AE7FAC665BFEAE2D7

SHA256:

DFF4D3A86A123F1FE1947075B01E64E869D7618B6A2A90D0B4F3A851D69790F0

SSDEEP:

98304:gIf2KVm9DJNCaBzHP9rC66Rgp2VWGM0K+D88Jic0g9fLf7cyetbNZC0N8lrp+MJ/:qlvYOwXcPpLxhyK5Xqybsuvm

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • WinRAR.exe (PID: 6548)
    • Executes application which crashes

      • wlcnthr.exe (PID: 7128)
  • INFO

    • Checks supported languages

      • mrstch.exe (PID: 4428)
      • wlcnthr.exe (PID: 7128)
      • mxcrsc32.exe (PID: 2996)
      • mrstch.exe (PID: 7088)
    • The process uses the downloaded file

      • WinRAR.exe (PID: 6548)
    • Checks proxy server information

      • WerFault.exe (PID: 4160)
    • Reads the computer name

      • mrstch.exe (PID: 4428)
      • mxcrsc32.exe (PID: 2996)
      • mrstch.exe (PID: 7088)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 6548)
    • The sample compiled with english language support

      • WinRAR.exe (PID: 6548)
    • Creates files or folders in the user directory

      • WerFault.exe (PID: 4160)
    • Reads the software policy settings

      • WerFault.exe (PID: 4160)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2023:04:05 10:17:32
ZipCRC: 0x01c47918
ZipCompressedSize: 182790
ZipUncompressedSize: 383512
ZipFileName: winipbin\bissima.dll
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
142
Monitored processes
10
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe wlcnthr.exe werfault.exe mrstch.exe no specs mrstch.exe conhost.exe no specs mxcrsc32.exe no specs mrstch.exe no specs mrstch.exe conhost.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2996"C:\Users\admin\AppData\Local\Temp\Rar$EXa6548.27885\winipbin\mxcrsc32.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa6548.27885\winipbin\mxcrsc32.exeWinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Version:
9.0.47350.18
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa6548.27885\winipbin\mxcrsc32.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
4024\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exemrstch.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
4160C:\WINDOWS\system32\WerFault.exe -u -p 7128 -s 536C:\Windows\System32\WerFault.exe
wlcnthr.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
4224"C:\Users\admin\AppData\Local\Temp\Rar$EXa6548.26049\winipbin\mrstch.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa6548.26049\winipbin\mrstch.exeWinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Version:
9.0.47350.18
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa6548.26049\winipbin\mrstch.exe
c:\windows\system32\ntdll.dll
4428"C:\Users\admin\AppData\Local\Temp\Rar$EXa6548.26049\winipbin\mrstch.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa6548.26049\winipbin\mrstch.exe
WinRAR.exe
User:
admin
Integrity Level:
HIGH
Exit code:
1
Version:
9.0.47350.18
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa6548.26049\winipbin\mrstch.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
6548"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\winipbin.zipC:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
6948"C:\Users\admin\AppData\Local\Temp\Rar$EXa6548.34540\winipbin\mrstch.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa6548.34540\winipbin\mrstch.exeWinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Version:
9.0.47350.18
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa6548.34540\winipbin\mrstch.exe
c:\windows\system32\ntdll.dll
7088"C:\Users\admin\AppData\Local\Temp\Rar$EXa6548.34540\winipbin\mrstch.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa6548.34540\winipbin\mrstch.exe
WinRAR.exe
User:
admin
Integrity Level:
HIGH
Exit code:
1
Version:
9.0.47350.18
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa6548.34540\winipbin\mrstch.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\shlwapi.dll
7092\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exemrstch.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
7128"C:\Users\admin\AppData\Local\Temp\Rar$EXa6548.23793\winipbin\wlcnthr.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa6548.23793\winipbin\wlcnthr.exe
WinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221225477
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa6548.23793\winipbin\wlcnthr.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
Total events
6 046
Read events
6 038
Write events
8
Delete events
0

Modification events

(PID) Process:(6548) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(6548) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(6548) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(6548) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\winipbin.zip
(PID) Process:(6548) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(6548) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(6548) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(6548) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
Executable files
64
Suspicious files
17
Text files
10
Unknown types
1

Dropped files

PID
Process
Filename
Type
6548WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa6548.23793\winipbin\cmproxfr.dllexecutable
MD5:2C56E306FF5D45933D5E1856ED76162C
SHA256:E4023597BB293484257B7A09C93B3FE74E72AFA7B2FB4620D25938764D5A6E07
6548WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa6548.23793\winipbin\mxcrsc32.exeexecutable
MD5:9CBAA55FF889CE8F97ED799B106DEC3A
SHA256:8BDACF7D67D17A2FD7132F86DA680632C75EFCAA0E6C14CDE2F6609AA7E3A82B
6548WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa6548.23793\winipbin\supportch.crxbinary
MD5:3362631438785E1C2DE91844A2D8611A
SHA256:FAA807BE6A79F18E1385D5E5C47942DB4772013C04000A47020573A736A2A25C
6548WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa6548.23793\winipbin\quasima.dllexecutable
MD5:DB2285BC8335D56463BE82048A855465
SHA256:602837ABDC044B35DE3A4184C84845FEC831A702FCC036C9798AE90EC6850E7D
6548WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa6548.23793\winipbin\mrstch.exeexecutable
MD5:AB2810F57F440BB4F00B26A1E7FFFA4C
SHA256:25E1D50B833BC38F38EDAA8BD8292472279F9A562B6996E623306BC60DF43FEA
6548WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa6548.23793\winipbin\quasimo.dllexecutable
MD5:64D63E539E4A8E930A622C11E57FABAF
SHA256:853E29F0C19D8ED725F2E45E33B73B50F274C73BB94F361FB3BEF443E73854F7
6548WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa6548.23793\winipbin\rcxaemap.dllexecutable
MD5:76F0BC4DB749203D1BBEC07505846B99
SHA256:9BC7AAA093B04CB9F5B79E8A93E0FECF1EBEA26D04FB8B7106A98949B082CAB5
6548WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa6548.23793\winipbin\mossimo.dllexecutable
MD5:286371126743F7981E7AABA8D3A03499
SHA256:91A13BCEE21584B2A31DBDDF45B8087E86522B5AACC0C7EE4E1A730C46182AF0
6548WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa6548.23793\winipbin\bissimo.dllexecutable
MD5:5F935191D567DB44F58DE09A3559359C
SHA256:E8E7F11F250C9DBF92AFA8AC699F34A45DA4C5FAEA0A01B1FCE35F56FC06102E
6548WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa6548.23793\winipbin\bissima.dllexecutable
MD5:3667532C417E81E72C18F97FEDC9C933
SHA256:57CA746D955E65241340054E5AC0FD92FB971E5A79AC179358C3A4A00BD04173
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
9
TCP/UDP connections
35
DNS requests
21
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
4712
MoUsoCoreWorker.exe
GET
200
2.16.241.19:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
6328
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
4712
MoUsoCoreWorker.exe
GET
200
184.30.230.103:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
3524
SIHClient.exe
GET
200
184.30.230.103:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
4160
WerFault.exe
GET
200
2.16.168.11:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
4160
WerFault.exe
GET
200
184.30.230.103:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
1176
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
3524
SIHClient.exe
GET
200
184.30.230.103:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
5064
SearchApp.exe
2.23.227.215:443
www.bing.com
Ooredoo Q.S.C.
QA
unknown
4712
MoUsoCoreWorker.exe
2.16.241.19:80
crl.microsoft.com
Akamai International B.V.
DE
unknown
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
4712
MoUsoCoreWorker.exe
184.30.230.103:80
www.microsoft.com
AKAMAI-AS
US
unknown
4
System
192.168.100.255:138
whitelisted
1176
svchost.exe
20.190.160.20:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1176
svchost.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
1076
svchost.exe
23.56.254.14:443
go.microsoft.com
Mobile Telecommunications Company
KW
unknown

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 51.124.78.146
  • 51.104.136.2
whitelisted
google.com
  • 142.250.185.206
whitelisted
www.bing.com
  • 2.23.227.215
  • 2.23.227.208
whitelisted
crl.microsoft.com
  • 2.16.241.19
  • 2.16.241.12
  • 2.16.168.11
  • 2.16.168.12
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
www.microsoft.com
  • 184.30.230.103
whitelisted
login.live.com
  • 20.190.160.20
  • 40.126.32.74
  • 20.190.160.17
  • 40.126.32.72
  • 40.126.32.138
  • 20.190.160.22
  • 40.126.32.134
  • 40.126.32.68
whitelisted
go.microsoft.com
  • 23.56.254.14
whitelisted
slscr.update.microsoft.com
  • 20.12.23.50
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 52.165.164.15
whitelisted

Threats

No threats detected
No debug info