File name:

WinRAR 6.10 Final [32bit 64bit] Crack [Coder].zip

Full analysis: https://app.any.run/tasks/50c21458-0a2c-48ed-bc1b-a5601398ea03
Verdict: Malicious activity
Analysis date: January 26, 2022, 10:02:11
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v1.0 to extract
MD5:

8FB2EC5B7C7D25A0E74FD02582402702

SHA1:

8571D709C02E0404E624466ED0BE2C93BF3CAD85

SHA256:

E3432CE45E84491676EB2ADDEA9D64A3BF22AB72EAF9B454D4BC0A554D0FBF54

SSDEEP:

196608:hwDF5+kmfOJbSXOMVON7xvlogeSOatlUhD:ez+kmfqbSXSl7rtlU9

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • winrar-x32-610.exe (PID: 2332)
  • SUSPICIOUS

    • Drops a file with a compile date too recent

      • WinRAR.exe (PID: 3880)
      • winrar-x32-610.exe (PID: 2332)
    • Reads the computer name

      • WinRAR.exe (PID: 3880)
      • winrar-x32-610.exe (PID: 2332)
    • Checks supported languages

      • WinRAR.exe (PID: 3880)
      • winrar-x32-610.exe (PID: 2332)
    • Drops a file that was compiled in debug mode

      • WinRAR.exe (PID: 3880)
      • winrar-x32-610.exe (PID: 2332)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3880)
      • winrar-x32-610.exe (PID: 2332)
    • Reads Microsoft Outlook installation path

      • winrar-x32-610.exe (PID: 2332)
    • Reads internet explorer settings

      • winrar-x32-610.exe (PID: 2332)
    • Creates files in the program directory

      • winrar-x32-610.exe (PID: 2332)
  • INFO

    • Checks supported languages

      • rundll32.exe (PID: 3508)
    • Reads the computer name

      • rundll32.exe (PID: 3508)
    • Changes default file association

      • rundll32.exe (PID: 3508)
    • Manual execution by user

      • winrar-x32-610.exe (PID: 2332)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.xpi | Mozilla Firefox browser extension (66.6)
.zip | ZIP compressed archive (33.3)

EXIF

ZIP

ZipFileName: WinRAR 6.10 Final [32bit 64bit] Crack [Coder]/Coder.txt
ZipUncompressedSize: 191
ZipCompressedSize: 191
ZipCRC: 0xaf45f319
ZipModifyDate: 2022:01:26 09:37:13
ZipCompression: None
ZipBitFlag: 0x0800
ZipRequiredVersion: 10
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
43
Monitored processes
3
Malicious processes
1
Suspicious processes
1

Behavior graph

Click at the process to see the details
start rundll32.exe no specs winrar.exe winrar-x32-610.exe

Process information

PID
CMD
Path
Indicators
Parent process
2332"C:\Users\admin\Desktop\WinRAR 6.10 Final [32bit 64bit] Crack [Coder]\Setup file for 32bit\winrar-x32-610.exe" C:\Users\admin\Desktop\WinRAR 6.10 Final [32bit 64bit] Crack [Coder]\Setup file for 32bit\winrar-x32-610.exe
Explorer.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
HIGH
Description:
WinRAR archiver
Exit code:
9
Version:
6.10.0
Modules
Images
c:\users\admin\desktop\winrar 6.10 final [32bit 64bit] crack [coder]\setup file for 32bit\winrar-x32-610.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.24542_none_5c0717c7a00ddc6d\gdiplus.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\usp10.dll
3508"C:\Windows\system32\rundll32.exe" C:\Windows\system32\shell32.dll,OpenAs_RunDLL "C:\Users\admin\AppData\Local\Temp\WinRAR 6.10 Final [32bit 64bit] Crack [Coder].zip.xpi"C:\Windows\system32\rundll32.exeExplorer.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imagehlp.dll
3880"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\WinRAR 6.10 Final [32bit 64bit] Crack [Coder].zip.xpi"C:\Program Files\WinRAR\WinRAR.exe
rundll32.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
Total events
6 316
Read events
6 196
Write events
119
Delete events
1

Modification events

(PID) Process:(3508) rundll32.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
Operation:writeName:C:\Windows\eHome\ehshell.exe
Value:
Windows Media Center
(PID) Process:(3508) rundll32.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe
Value:
Firefox
(PID) Process:(3508) rundll32.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
Operation:writeName:C:\Windows\system32\mspaint.exe
Value:
Paint
(PID) Process:(3508) rundll32.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
Operation:writeName:C:\Windows\system32\NOTEPAD.EXE
Value:
Notepad
(PID) Process:(3508) rundll32.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
Operation:writeName:C:\PROGRA~1\MICROS~1\Office14\OIS.EXE
Value:
Microsoft Office 2010
(PID) Process:(3508) rundll32.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
Operation:writeName:C:\Program Files\Opera\Opera.exe
Value:
Opera Internet Browser
(PID) Process:(3508) rundll32.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
Operation:writeName:C:\Program Files\Windows Photo Viewer\PhotoViewer.dll
Value:
Windows Photo Viewer
(PID) Process:(3508) rundll32.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
Operation:writeName:C:\Program Files\VideoLAN\VLC\vlc.exe
Value:
VLC media player
(PID) Process:(3508) rundll32.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
Operation:writeName:C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Value:
Microsoft Word
(PID) Process:(3508) rundll32.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
Executable files
12
Suspicious files
0
Text files
10
Unknown types
1

Dropped files

PID
Process
Filename
Type
3880WinRAR.exeC:\Users\admin\Desktop\WinRAR 6.10 Final [32bit 64bit] Crack [Coder]\Coder.txttext
MD5:
SHA256:
2332winrar-x32-610.exeC:\Program Files\WinRAR\License.txttext
MD5:672064CF19DB0B083B981CF0BE7662B0
SHA256:9FC8AA33CCAFA04C1CE4C0A61047B341297D720ADAB1B77F67B5FE59F43BB59F
2332winrar-x32-610.exeC:\Program Files\WinRAR\Order.htmhtml
MD5:5C336DE3B3D794322AD9E5915E3A509F
SHA256:BCE29EF3B95306CB7B304FB8C3039BE7157356D9F9D4E7E1C6BFBF02A117F48F
2332winrar-x32-610.exeC:\Program Files\WinRAR\Uninstall.exeexecutable
MD5:1E4ECDB0CA5F73B79DA4DDDD0FD1AE66
SHA256:431B365B4E95E0C7A864F9B6F97D5A30911CC1FCC14CDB97887D262A51E52C67
2332winrar-x32-610.exeC:\Program Files\WinRAR\Descript.iontext
MD5:3FB658E292A09D2303B6D84FAF079E0C
SHA256:FA7BFC756E502CA814F927130574CBB472FC8B9C608F98B470409E7D8D1AD30D
2332winrar-x32-610.exeC:\Program Files\WinRAR\RarExt64.dllexecutable
MD5:02FFB00705D8269227B0318E6082035D
SHA256:8A310437F8BD6DEA569783353DAD2E1AA9400A93FBD2C8D708DA67E16FE0925F
3880WinRAR.exeC:\Users\admin\Desktop\WinRAR 6.10 Final [32bit 64bit] Crack [Coder]\Setup file for 64bit\winrar-x64-610.exeexecutable
MD5:
SHA256:
2332winrar-x32-610.exeC:\Program Files\WinRAR\Rar.exeexecutable
MD5:53E8EF208EC4F687A4E728013872D49B
SHA256:E7ADF9D8F3A83A8130E21E122F29FBFE096A4F80F71CB1E3A57B45562B548880
2332winrar-x32-610.exeC:\Program Files\WinRAR\WhatsNew.txttext
MD5:8E1B3621B868F50FC8FE45991056E970
SHA256:0AFA8DBC79BB7CEDAD30E5EF62888028949F63A9603D66664B6D7922FB0BFF09
2332winrar-x32-610.exeC:\Program Files\WinRAR\Default.SFXexecutable
MD5:EEE3A229DA26073CB80240F32EBE70D3
SHA256:E1F5ADC2FBE9C783DCB68D3DF79DA423FBE450AB21A18E9985E64EC1CEFF1AD3
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info