File name:

winipbin.zip

Full analysis: https://app.any.run/tasks/d9fe395c-b0b6-451b-b6ae-ddfbde36a841
Verdict: Malicious activity
Analysis date: January 07, 2025, 20:23:28
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
arch-exec
arch-scr
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=deflate
MD5:

1DC8A249C00987EC743627428CCAA3FD

SHA1:

1CF0778476D2384F6194438AE7FAC665BFEAE2D7

SHA256:

DFF4D3A86A123F1FE1947075B01E64E869D7618B6A2A90D0B4F3A851D69790F0

SSDEEP:

98304:gIf2KVm9DJNCaBzHP9rC66Rgp2VWGM0K+D88Jic0g9fLf7cyetbNZC0N8lrp+MJ/:qlvYOwXcPpLxhyK5Xqybsuvm

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • WinRAR.exe (PID: 6548)
    • Executes application which crashes

      • wlcnthr.exe (PID: 7128)
  • INFO

    • The sample compiled with english language support

      • WinRAR.exe (PID: 6548)
    • The process uses the downloaded file

      • WinRAR.exe (PID: 6548)
    • Checks supported languages

      • mrstch.exe (PID: 4428)
      • wlcnthr.exe (PID: 7128)
      • mxcrsc32.exe (PID: 2996)
      • mrstch.exe (PID: 7088)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 6548)
    • Checks proxy server information

      • WerFault.exe (PID: 4160)
    • Reads the computer name

      • mrstch.exe (PID: 4428)
      • mxcrsc32.exe (PID: 2996)
      • mrstch.exe (PID: 7088)
    • Creates files or folders in the user directory

      • WerFault.exe (PID: 4160)
    • Reads the software policy settings

      • WerFault.exe (PID: 4160)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2023:04:05 10:17:32
ZipCRC: 0x01c47918
ZipCompressedSize: 182790
ZipUncompressedSize: 383512
ZipFileName: winipbin\bissima.dll
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
142
Monitored processes
10
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe wlcnthr.exe werfault.exe mrstch.exe no specs mrstch.exe conhost.exe no specs mxcrsc32.exe no specs mrstch.exe no specs mrstch.exe conhost.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2996"C:\Users\admin\AppData\Local\Temp\Rar$EXa6548.27885\winipbin\mxcrsc32.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa6548.27885\winipbin\mxcrsc32.exeWinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Version:
9.0.47350.18
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa6548.27885\winipbin\mxcrsc32.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
4024\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exemrstch.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
4160C:\WINDOWS\system32\WerFault.exe -u -p 7128 -s 536C:\Windows\System32\WerFault.exe
wlcnthr.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
4224"C:\Users\admin\AppData\Local\Temp\Rar$EXa6548.26049\winipbin\mrstch.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa6548.26049\winipbin\mrstch.exeWinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Version:
9.0.47350.18
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa6548.26049\winipbin\mrstch.exe
c:\windows\system32\ntdll.dll
4428"C:\Users\admin\AppData\Local\Temp\Rar$EXa6548.26049\winipbin\mrstch.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa6548.26049\winipbin\mrstch.exe
WinRAR.exe
User:
admin
Integrity Level:
HIGH
Exit code:
1
Version:
9.0.47350.18
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa6548.26049\winipbin\mrstch.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
6548"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\winipbin.zipC:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
6948"C:\Users\admin\AppData\Local\Temp\Rar$EXa6548.34540\winipbin\mrstch.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa6548.34540\winipbin\mrstch.exeWinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Version:
9.0.47350.18
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa6548.34540\winipbin\mrstch.exe
c:\windows\system32\ntdll.dll
7088"C:\Users\admin\AppData\Local\Temp\Rar$EXa6548.34540\winipbin\mrstch.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa6548.34540\winipbin\mrstch.exe
WinRAR.exe
User:
admin
Integrity Level:
HIGH
Exit code:
1
Version:
9.0.47350.18
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa6548.34540\winipbin\mrstch.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\shlwapi.dll
7092\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exemrstch.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
7128"C:\Users\admin\AppData\Local\Temp\Rar$EXa6548.23793\winipbin\wlcnthr.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa6548.23793\winipbin\wlcnthr.exe
WinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221225477
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa6548.23793\winipbin\wlcnthr.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
Total events
6 046
Read events
6 038
Write events
8
Delete events
0

Modification events

(PID) Process:(6548) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(6548) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(6548) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(6548) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\winipbin.zip
(PID) Process:(6548) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(6548) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(6548) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(6548) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
Executable files
64
Suspicious files
17
Text files
10
Unknown types
1

Dropped files

PID
Process
Filename
Type
6548WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa6548.23793\winipbin\mrstch.exeexecutable
MD5:AB2810F57F440BB4F00B26A1E7FFFA4C
SHA256:25E1D50B833BC38F38EDAA8BD8292472279F9A562B6996E623306BC60DF43FEA
6548WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa6548.23793\winipbin\quasima.dllexecutable
MD5:DB2285BC8335D56463BE82048A855465
SHA256:602837ABDC044B35DE3A4184C84845FEC831A702FCC036C9798AE90EC6850E7D
6548WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa6548.23793\winipbin\rcxaemap.dllexecutable
MD5:76F0BC4DB749203D1BBEC07505846B99
SHA256:9BC7AAA093B04CB9F5B79E8A93E0FECF1EBEA26D04FB8B7106A98949B082CAB5
6548WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa6548.23793\winipbin\bissima.dllexecutable
MD5:3667532C417E81E72C18F97FEDC9C933
SHA256:57CA746D955E65241340054E5AC0FD92FB971E5A79AC179358C3A4A00BD04173
6548WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa6548.23793\winipbin\supported.appxcompressed
MD5:F008BC32FC6BC8A22447D25B701BF27B
SHA256:2F209301BB2DB49A84BD8C22CA101FE9207C9E8E53BF8DCE3987BF1549148F41
6548WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa6548.23793\winipbin\quasimo.dllexecutable
MD5:64D63E539E4A8E930A622C11E57FABAF
SHA256:853E29F0C19D8ED725F2E45E33B73B50F274C73BB94F361FB3BEF443E73854F7
6548WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa6548.23793\winipbin\mxcrsc32.exeexecutable
MD5:9CBAA55FF889CE8F97ED799B106DEC3A
SHA256:8BDACF7D67D17A2FD7132F86DA680632C75EFCAA0E6C14CDE2F6609AA7E3A82B
6548WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa6548.23793\winipbin\supportch.crxbinary
MD5:3362631438785E1C2DE91844A2D8611A
SHA256:FAA807BE6A79F18E1385D5E5C47942DB4772013C04000A47020573A736A2A25C
6548WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa6548.23793\winipbin\supportch.xmltext
MD5:79F507DDED6E083686C5154BB0852E8E
SHA256:BBF25CAA2DBAA401CFD81338939F0C98CAA13773E893298FE890583C2551A282
6548WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa6548.23793\winipbin\svrltwp.dllexecutable
MD5:BE0FA47190543AE42A448B804D4C9CD3
SHA256:0E2704FCF02EC561C00AFE1D7DD50675A86CEC89D3E435D58F7203BCE75474A9
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
9
TCP/UDP connections
35
DNS requests
21
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4712
MoUsoCoreWorker.exe
GET
200
2.16.241.19:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
4712
MoUsoCoreWorker.exe
GET
200
184.30.230.103:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
1176
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
4160
WerFault.exe
GET
200
2.16.168.11:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
6328
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
4160
WerFault.exe
GET
200
184.30.230.103:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
3524
SIHClient.exe
GET
200
184.30.230.103:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
3524
SIHClient.exe
GET
200
184.30.230.103:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
5064
SearchApp.exe
2.23.227.215:443
www.bing.com
Ooredoo Q.S.C.
QA
unknown
4712
MoUsoCoreWorker.exe
2.16.241.19:80
crl.microsoft.com
Akamai International B.V.
DE
unknown
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
4712
MoUsoCoreWorker.exe
184.30.230.103:80
www.microsoft.com
AKAMAI-AS
US
unknown
4
System
192.168.100.255:138
whitelisted
1176
svchost.exe
20.190.160.20:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1176
svchost.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
1076
svchost.exe
23.56.254.14:443
go.microsoft.com
Mobile Telecommunications Company
KW
unknown

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 51.124.78.146
  • 51.104.136.2
whitelisted
google.com
  • 142.250.185.206
whitelisted
www.bing.com
  • 2.23.227.215
  • 2.23.227.208
whitelisted
crl.microsoft.com
  • 2.16.241.19
  • 2.16.241.12
  • 2.16.168.11
  • 2.16.168.12
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
www.microsoft.com
  • 184.30.230.103
whitelisted
login.live.com
  • 20.190.160.20
  • 40.126.32.74
  • 20.190.160.17
  • 40.126.32.72
  • 40.126.32.138
  • 20.190.160.22
  • 40.126.32.134
  • 40.126.32.68
whitelisted
go.microsoft.com
  • 23.56.254.14
whitelisted
slscr.update.microsoft.com
  • 20.12.23.50
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 52.165.164.15
whitelisted

Threats

No threats detected
No debug info