File name:

winipbin.zip

Full analysis: https://app.any.run/tasks/d9fe395c-b0b6-451b-b6ae-ddfbde36a841
Verdict: Malicious activity
Analysis date: January 07, 2025, 20:23:28
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
arch-exec
arch-scr
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=deflate
MD5:

1DC8A249C00987EC743627428CCAA3FD

SHA1:

1CF0778476D2384F6194438AE7FAC665BFEAE2D7

SHA256:

DFF4D3A86A123F1FE1947075B01E64E869D7618B6A2A90D0B4F3A851D69790F0

SSDEEP:

98304:gIf2KVm9DJNCaBzHP9rC66Rgp2VWGM0K+D88Jic0g9fLf7cyetbNZC0N8lrp+MJ/:qlvYOwXcPpLxhyK5Xqybsuvm

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executes application which crashes

      • wlcnthr.exe (PID: 7128)
    • Reads security settings of Internet Explorer

      • WinRAR.exe (PID: 6548)
  • INFO

    • The process uses the downloaded file

      • WinRAR.exe (PID: 6548)
    • The sample compiled with english language support

      • WinRAR.exe (PID: 6548)
    • Reads the computer name

      • mrstch.exe (PID: 4428)
      • mxcrsc32.exe (PID: 2996)
      • mrstch.exe (PID: 7088)
    • Checks proxy server information

      • WerFault.exe (PID: 4160)
    • Reads the software policy settings

      • WerFault.exe (PID: 4160)
    • Checks supported languages

      • mxcrsc32.exe (PID: 2996)
      • wlcnthr.exe (PID: 7128)
      • mrstch.exe (PID: 7088)
      • mrstch.exe (PID: 4428)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 6548)
    • Creates files or folders in the user directory

      • WerFault.exe (PID: 4160)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2023:04:05 10:17:32
ZipCRC: 0x01c47918
ZipCompressedSize: 182790
ZipUncompressedSize: 383512
ZipFileName: winipbin\bissima.dll
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
142
Monitored processes
10
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe wlcnthr.exe werfault.exe mrstch.exe no specs mrstch.exe conhost.exe no specs mxcrsc32.exe no specs mrstch.exe no specs mrstch.exe conhost.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2996"C:\Users\admin\AppData\Local\Temp\Rar$EXa6548.27885\winipbin\mxcrsc32.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa6548.27885\winipbin\mxcrsc32.exeWinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Version:
9.0.47350.18
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa6548.27885\winipbin\mxcrsc32.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
4024\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exemrstch.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
4160C:\WINDOWS\system32\WerFault.exe -u -p 7128 -s 536C:\Windows\System32\WerFault.exe
wlcnthr.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
4224"C:\Users\admin\AppData\Local\Temp\Rar$EXa6548.26049\winipbin\mrstch.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa6548.26049\winipbin\mrstch.exeWinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Version:
9.0.47350.18
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa6548.26049\winipbin\mrstch.exe
c:\windows\system32\ntdll.dll
4428"C:\Users\admin\AppData\Local\Temp\Rar$EXa6548.26049\winipbin\mrstch.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa6548.26049\winipbin\mrstch.exe
WinRAR.exe
User:
admin
Integrity Level:
HIGH
Exit code:
1
Version:
9.0.47350.18
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa6548.26049\winipbin\mrstch.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
6548"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\winipbin.zipC:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
6948"C:\Users\admin\AppData\Local\Temp\Rar$EXa6548.34540\winipbin\mrstch.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa6548.34540\winipbin\mrstch.exeWinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Version:
9.0.47350.18
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa6548.34540\winipbin\mrstch.exe
c:\windows\system32\ntdll.dll
7088"C:\Users\admin\AppData\Local\Temp\Rar$EXa6548.34540\winipbin\mrstch.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa6548.34540\winipbin\mrstch.exe
WinRAR.exe
User:
admin
Integrity Level:
HIGH
Exit code:
1
Version:
9.0.47350.18
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa6548.34540\winipbin\mrstch.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\shlwapi.dll
7092\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exemrstch.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
7128"C:\Users\admin\AppData\Local\Temp\Rar$EXa6548.23793\winipbin\wlcnthr.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa6548.23793\winipbin\wlcnthr.exe
WinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221225477
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa6548.23793\winipbin\wlcnthr.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
Total events
6 046
Read events
6 038
Write events
8
Delete events
0

Modification events

(PID) Process:(6548) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(6548) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(6548) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(6548) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\winipbin.zip
(PID) Process:(6548) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(6548) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(6548) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(6548) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
Executable files
64
Suspicious files
17
Text files
10
Unknown types
1

Dropped files

PID
Process
Filename
Type
6548WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa6548.23793\winipbin\bissima.dllexecutable
MD5:3667532C417E81E72C18F97FEDC9C933
SHA256:57CA746D955E65241340054E5AC0FD92FB971E5A79AC179358C3A4A00BD04173
6548WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa6548.23793\winipbin\mossimo.dllexecutable
MD5:286371126743F7981E7AABA8D3A03499
SHA256:91A13BCEE21584B2A31DBDDF45B8087E86522B5AACC0C7EE4E1A730C46182AF0
6548WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa6548.23793\winipbin\cmproxfr.dllexecutable
MD5:2C56E306FF5D45933D5E1856ED76162C
SHA256:E4023597BB293484257B7A09C93B3FE74E72AFA7B2FB4620D25938764D5A6E07
6548WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa6548.23793\winipbin\rcxaemap.dllexecutable
MD5:76F0BC4DB749203D1BBEC07505846B99
SHA256:9BC7AAA093B04CB9F5B79E8A93E0FECF1EBEA26D04FB8B7106A98949B082CAB5
6548WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa6548.23793\winipbin\mxcrsc32.exeexecutable
MD5:9CBAA55FF889CE8F97ED799B106DEC3A
SHA256:8BDACF7D67D17A2FD7132F86DA680632C75EFCAA0E6C14CDE2F6609AA7E3A82B
6548WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa6548.23793\winipbin\supportch.xmltext
MD5:79F507DDED6E083686C5154BB0852E8E
SHA256:BBF25CAA2DBAA401CFD81338939F0C98CAA13773E893298FE890583C2551A282
6548WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa6548.23793\winipbin\eanipw.dllexecutable
MD5:1C41FCD0A1723327A24553E48C7D3679
SHA256:9CC1ABA05B13BC99439A08469F497AD8FC154E1B7A1F879454A57599AA6F373C
6548WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa6548.23793\winipbin\svrltmgr64.dllexecutable
MD5:200E965669EECDB53CF4D8C478115871
SHA256:90046E8984C8F3FC0BBF9B62F734FB7716FF5916191594588DC490FDF1065BA3
6548WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa6548.23793\winipbin\quasima.dllexecutable
MD5:DB2285BC8335D56463BE82048A855465
SHA256:602837ABDC044B35DE3A4184C84845FEC831A702FCC036C9798AE90EC6850E7D
6548WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa6548.23793\winipbin\svrltmgr.dllexecutable
MD5:2CA6C5E723938B6017A46BEBEA76CE8B
SHA256:BC83EA7395C955C7CFEE883E39782CEE3599B1601A9D8C260334A15FCE0715F1
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
9
TCP/UDP connections
35
DNS requests
21
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4712
MoUsoCoreWorker.exe
GET
200
2.16.241.19:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
4712
MoUsoCoreWorker.exe
GET
200
184.30.230.103:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
4160
WerFault.exe
GET
200
2.16.168.11:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
1176
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
3524
SIHClient.exe
GET
200
184.30.230.103:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
6328
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
4160
WerFault.exe
GET
200
184.30.230.103:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
3524
SIHClient.exe
GET
200
184.30.230.103:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
5064
SearchApp.exe
2.23.227.215:443
www.bing.com
Ooredoo Q.S.C.
QA
unknown
4712
MoUsoCoreWorker.exe
2.16.241.19:80
crl.microsoft.com
Akamai International B.V.
DE
unknown
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
4712
MoUsoCoreWorker.exe
184.30.230.103:80
www.microsoft.com
AKAMAI-AS
US
unknown
4
System
192.168.100.255:138
whitelisted
1176
svchost.exe
20.190.160.20:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1176
svchost.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
1076
svchost.exe
23.56.254.14:443
go.microsoft.com
Mobile Telecommunications Company
KW
unknown

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 51.124.78.146
  • 51.104.136.2
whitelisted
google.com
  • 142.250.185.206
whitelisted
www.bing.com
  • 2.23.227.215
  • 2.23.227.208
whitelisted
crl.microsoft.com
  • 2.16.241.19
  • 2.16.241.12
  • 2.16.168.11
  • 2.16.168.12
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
www.microsoft.com
  • 184.30.230.103
whitelisted
login.live.com
  • 20.190.160.20
  • 40.126.32.74
  • 20.190.160.17
  • 40.126.32.72
  • 40.126.32.138
  • 20.190.160.22
  • 40.126.32.134
  • 40.126.32.68
whitelisted
go.microsoft.com
  • 23.56.254.14
whitelisted
slscr.update.microsoft.com
  • 20.12.23.50
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 52.165.164.15
whitelisted

Threats

No threats detected
No debug info