File name:

842e75f3b013d7a85031778707b75a70.zip

Full analysis: https://app.any.run/tasks/00b7adf6-14e1-4c9f-baba-90333825bf9b
Verdict: No threats detected
Analysis date: December 27, 2019, 17:14:31
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

336815D102F45127F37EFEF8E3A4FE83

SHA1:

E5B61963FB428FAB7CACB69B8742BE81F00585D7

SHA256:

E479D133C6630FE71356BD08BAB0DB80D0F9F7A7EFD1BF8FAAB81C6BFCAC95F9

SSDEEP:

98304:PhO4vOqvww0p7J8slxRNIQOBizujMZ0MP4c6foDYk9kFbjgVyZU:PhO6roJDrRWjKUML6fE9SFQVqU

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • hasplms.exe (PID: 2172)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 964)
  • INFO

    • Manual execution by user

      • hasplms.exe (PID: 2172)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2013:03:15 12:52:04
ZipCRC: 0xbe6e3905
ZipCompressedSize: 12496
ZipUncompressedSize: 21448
ZipFileName: aksclass.sys
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
37
Monitored processes
2
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe hasplms.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
964"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\842e75f3b013d7a85031778707b75a70.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2172"C:\Users\admin\Desktop\hasplms.exe" C:\Users\admin\Desktop\hasplms.exeexplorer.exe
User:
admin
Company:
SafeNet Inc.
Integrity Level:
MEDIUM
Description:
Sentinel LDK License Manager Service
Exit code:
1
Version:
14.1.1.31592
Modules
Images
c:\users\admin\desktop\hasplms.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\advapi32.dll
Total events
468
Read events
436
Write events
32
Delete events
0

Modification events

(PID) Process:(964) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(964) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(964) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(964) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\842e75f3b013d7a85031778707b75a70.zip
(PID) Process:(964) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(964) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(964) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(964) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(964) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E
Operation:writeName:@cryptext.dll,-6145
Value:
Security Catalog
(PID) Process:(964) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E
Operation:writeName:@C:\Windows\System32\setupapi.dll,-2000
Value:
Setup Information
Executable files
11
Suspicious files
1
Text files
0
Unknown types
2

Dropped files

PID
Process
Filename
Type
964WinRAR.exeC:\Users\admin\Desktop\akshhl.sysexecutable
MD5:053B204554F104CB5DC3D94B61BDA458
SHA256:72EB2556AA4B83489D2908ADC40DEB2E5ACE98D7A6112E9395F46924BD60501E
964WinRAR.exeC:\Users\admin\Desktop\aksusb4.dllexecutable
MD5:E05C996F43C48DE8FEAF2F258D2DDE32
SHA256:AA9952675303BD437569FAEF3FC94A5A89EA059371FCC898D3FC322BCB8C0D73
964WinRAR.exeC:\Users\admin\Desktop\aksfridge.sysexecutable
MD5:2C3ACA835E99CAD1FF36E33D66AFBAA7
SHA256:7381FA422C8C921FB0A94CF6D4A37B1A43AFD814CFA97351763881A83E074056
964WinRAR.exeC:\Users\admin\Desktop\aksusb.sysexecutable
MD5:A25C21F6C040832B016F592B50F0259F
SHA256:DA3C0B928FB6F2F1007C4BE389AAD06F34A869E53659BDE29F47168B70E35397
964WinRAR.exeC:\Users\admin\Desktop\akshhl30.dllexecutable
MD5:73E3F7CEC83120CCDECD2D3172B64F91
SHA256:55AF059E2BABDDA4B65B7C2044105557BF5FA8DE8A8BCE9C55CD76FEFB5FCB42
964WinRAR.exeC:\Users\admin\Desktop\aksusb.PNFpnf
MD5:C4ABC6BA1B890E91F5BBD9B14A2523B8
SHA256:3ED09A7D45176FF9FDD30F169360351B8DCE0F4495610A023920E3847EDB1396
964WinRAR.exeC:\Users\admin\Desktop\aksdf.sysexecutable
MD5:DB262BADD56D97652D5E726B7C2ED9DF
SHA256:55BB0857C9F5BBD47DDC598BA67F276EB264F1FE225A06C6546BF1556DDF60D4
964WinRAR.exeC:\Users\admin\Desktop\aksclass.sysexecutable
MD5:A6C6F0718E7F7B6C1D045D5A34AB6E9A
SHA256:FD76344B77DF6E56081C7AF1D1E9BE7C6A43833937E9AC429A94308F53FD4545
964WinRAR.exeC:\Users\admin\Desktop\aksusb.infbinary
MD5:842E75F3B013D7A85031778707B75A70
SHA256:D34B8CC73F97D4B4042040A402C82375FAC99BBBA3E6CD9B801B114696F7AA89
964WinRAR.exeC:\Users\admin\Desktop\akshsp52.dllexecutable
MD5:C6C641A5DFB0C8893E36D498CA5103A7
SHA256:B70E1E9D06B02651B04E060E5DB14E0C2DDE1FA37A4176833B6C25B3C862CB1C
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info