File name:

CH341A programm v1.34 By DS Helping Hand.rar

Full analysis: https://app.any.run/tasks/de39a261-303b-4c2c-a88c-3658cfe8a83e
Verdict: Malicious activity
Analysis date: December 11, 2024, 05:09:02
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
xor-url
generic
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

F095F104C8C1CE86A48DF0E876120911

SHA1:

76FEA0D48D904F97F7D2D564E7E61305120ACC25

SHA256:

E1F373452AE0282F0F86CA19370730D212F9663B8A2DDB538D009FB14FDB8461

SSDEEP:

98304:57W+I9PJcpX4fgmRoVzlu08vPvBkcEvEDPWG1AcQr+OvP+V54SwCzCyHaTjRyc7A:sdbCtF4Rqi

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • XORed URL has been found (YARA)

      • CH341A.EXE (PID: 6216)
  • SUSPICIOUS

    • There is functionality for taking screenshot (YARA)

      • CH341A.EXE (PID: 6216)
    • Reads security settings of Internet Explorer

      • WinRAR.exe (PID: 6656)
  • INFO

    • The sample compiled with english language support

      • WinRAR.exe (PID: 6656)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 6656)
    • The process uses the downloaded file

      • WinRAR.exe (PID: 6656)
    • Reads the computer name

      • CH341A.EXE (PID: 6216)
    • Checks supported languages

      • CH341A.EXE (PID: 6216)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)

EXIF

ZIP

FileVersion: RAR v5
CompressedSize: 295938
UncompressedSize: 1544192
OperatingSystem: Win32
ArchivedFileName: CH341A programm v1.34/BoxedAppSDK.dll
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
127
Monitored processes
2
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe #XOR-URL ch341a.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
6216"C:\Users\admin\AppData\Local\Temp\Rar$EXa6656.9712\CH341A programm v1.34\CH341A.EXE" C:\Users\admin\AppData\Local\Temp\Rar$EXa6656.9712\CH341A programm v1.34\CH341A.EXE
WinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Description:
CH341A编程器
Version:
1.34
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa6656.9712\ch341a programm v1.34\ch341a.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\oleaut32.dll
6656"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\CH341A programm v1.34 By DS Helping Hand.rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
Total events
2 257
Read events
2 249
Write events
8
Delete events
0

Modification events

(PID) Process:(6656) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(6656) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(6656) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(6656) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\CH341A programm v1.34 By DS Helping Hand.rar
(PID) Process:(6656) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(6656) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(6656) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(6656) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
Executable files
5
Suspicious files
1
Text files
7
Unknown types
0

Dropped files

PID
Process
Filename
Type
6656WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa6656.9712\CH341A programm v1.34\Languages\Italiano.iniini
MD5:E9B83C0958BDA48A6BD73FE00CFE135E
SHA256:6C52211E8B03E4290818B852FEBB6A83DA42118DEB756B5A1AD41B36F87A5882
6656WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa6656.9712\CH341A programm v1.34\BoxedAppSDK.dllexecutable
MD5:7C6FEFBDEBCBBE2DB932C0221614567F
SHA256:E4811DBE3B8FB7940158E335437E75A5225E4DE6EDCEE4ABF4FAE5CA0EA106E0
6656WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa6656.9712\CH341A programm v1.34\Languages\English.iniini
MD5:40E58823AB0871C3139D5108D48FED2E
SHA256:716CA898C95A3F26551FA87C86B231C40D8E8B29AAA1D3AE3AE9803002F2E310
6656WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa6656.9712\CH341A programm v1.34\Languages\ChineseTrad.iniini
MD5:ECCFCFA1E37BB5392C28082440DAAE14
SHA256:92C95468FCEDABE6631A193F910E0389C50A9D861AD29B1B013E9D3202314FAF
6656WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa6656.9712\CH341A programm v1.34\Config.iniini
MD5:8FF49A0B3E85A6E57C07B78A489BD697
SHA256:90A1D15A8512FFDC5EEA9DF5C12987A3D3FCFB86E943DB8A68722B3853B307E6
6656WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa6656.9712\CH341A programm v1.34\CH341A.DLLexecutable
MD5:922C1CDF120F4AA0096C2B16B10A35BF
SHA256:04273D1AF6705F1D960B47D2666FBFCB529DBA04A0E9B9358324EB688118AC1C
6656WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa6656.9712\CH341A programm v1.34\CH341A.EXEexecutable
MD5:D7F6285B820C28EC61EC424E41870916
SHA256:2E470AF5606097DBCDA8B32CBBF5F4F32426F6D0DB4C474834404013936F64CE
6656WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa6656.9712\CH341A programm v1.34\Languages\Russian.initext
MD5:C3242293F344D2917EE6C1282ADC8395
SHA256:602F5866E6C86178D2C552727AE312FDFF7DDA9C1D3BCD3D368236735B938038
6656WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa6656.9712\CH341A programm v1.34\SPI.dllexecutable
MD5:FB91412B1E660BBDEEF933C2266E42D8
SHA256:C0866E0ED968BE1C6E354AF564E4F7220CC42CF236CC379880204A7F0997CB2F
6656WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa6656.9712\CH341A programm v1.34\DataBase.Datbinary
MD5:FF56018A1C068CAF2EAAA6AF9D991DD6
SHA256:DE1A47EDFDD93F679028EB4279CEE3279C12A071846C03988B258159CD7C2A45
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
11
TCP/UDP connections
35
DNS requests
18
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4712
MoUsoCoreWorker.exe
GET
200
2.16.164.106:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
2.16.164.106:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
640
svchost.exe
GET
200
2.16.164.106:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5064
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
1176
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
640
svchost.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
4712
MoUsoCoreWorker.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
6348
SIHClient.exe
GET
200
2.23.181.156:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2.16.164.106:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
4712
MoUsoCoreWorker.exe
2.16.164.106:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
640
svchost.exe
2.16.164.106:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
4712
MoUsoCoreWorker.exe
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
640
svchost.exe
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
  • 20.73.194.208
whitelisted
crl.microsoft.com
  • 2.16.164.106
  • 2.16.164.49
whitelisted
google.com
  • 142.250.184.206
whitelisted
www.microsoft.com
  • 95.101.149.131
  • 2.23.181.156
whitelisted
www.bing.com
  • 2.19.96.120
  • 2.19.96.115
  • 2.19.96.112
  • 2.19.96.121
  • 2.19.96.106
  • 2.19.96.99
  • 2.19.96.104
  • 2.19.96.96
  • 2.19.96.90
whitelisted
login.live.com
  • 40.126.32.133
  • 20.190.160.22
  • 20.190.160.17
  • 40.126.32.76
  • 40.126.32.134
  • 40.126.32.136
  • 40.126.32.140
  • 40.126.32.68
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
go.microsoft.com
  • 184.28.89.167
whitelisted
arc.msn.com
  • 20.103.156.88
whitelisted
fd.api.iris.microsoft.com
  • 20.103.156.88
whitelisted

Threats

No threats detected
No debug info