File name:

unknown_122eeabd8dda2f813207ad370e94108bbec509b8.7z

Full analysis: https://app.any.run/tasks/6d87c3a7-1e61-4b2b-bc84-1f8676f726e7
Verdict: Malicious activity
Analysis date: May 15, 2025, 19:11:07
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
arch-exec
Indicators:
MIME: application/x-7z-compressed
File info: 7-zip archive data, version 0.4
MD5:

006357F01A4A7A47915CB07345FF8861

SHA1:

9A0F513E698242EF0055646B754B886659EB92A2

SHA256:

E613A944CD3722C77BD3B1E400CFB7A08A08D5CDBDBDA411DC15353F362C666E

SSDEEP:

1536:zPuwluQ7Yw672WTshhbujOwm3a0JKhOKACzOxXpJ4tuRCT+z1Isv5DhE:SwkYYJSWkbFa0J7CzGZ4uRCT+z6UDK

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Generic archive extractor

      • WinRAR.exe (PID: 1744)
    • Changes the autorun value in the registry

      • unknown_122eeabd8dda2f813207ad370e94108bbec509b8.exe (PID: 1504)
  • SUSPICIOUS

    • Application launched itself

      • unknown_122eeabd8dda2f813207ad370e94108bbec509b8.exe (PID: 988)
      • hostrun.exe (PID: 2204)
    • Executable content was dropped or overwritten

      • unknown_122eeabd8dda2f813207ad370e94108bbec509b8.exe (PID: 1504)
    • Reads security settings of Internet Explorer

      • unknown_122eeabd8dda2f813207ad370e94108bbec509b8.exe (PID: 1504)
      • hostrun.exe (PID: 2764)
    • Reads the Internet Settings

      • unknown_122eeabd8dda2f813207ad370e94108bbec509b8.exe (PID: 1504)
      • hostrun.exe (PID: 2764)
    • Executing commands from a ".bat" file

      • unknown_122eeabd8dda2f813207ad370e94108bbec509b8.exe (PID: 1504)
    • Starts CMD.EXE for commands execution

      • unknown_122eeabd8dda2f813207ad370e94108bbec509b8.exe (PID: 1504)
    • Starts itself from another location

      • unknown_122eeabd8dda2f813207ad370e94108bbec509b8.exe (PID: 1504)
    • There is functionality for taking screenshot (YARA)

      • hostrun.exe (PID: 2764)
  • INFO

    • The sample compiled with english language support

      • WinRAR.exe (PID: 1744)
      • unknown_122eeabd8dda2f813207ad370e94108bbec509b8.exe (PID: 1504)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 1744)
    • Creates files or folders in the user directory

      • unknown_122eeabd8dda2f813207ad370e94108bbec509b8.exe (PID: 1504)
    • Checks supported languages

      • unknown_122eeabd8dda2f813207ad370e94108bbec509b8.exe (PID: 988)
      • unknown_122eeabd8dda2f813207ad370e94108bbec509b8.exe (PID: 1504)
      • hostrun.exe (PID: 2204)
      • hostrun.exe (PID: 2764)
    • Reads the computer name

      • unknown_122eeabd8dda2f813207ad370e94108bbec509b8.exe (PID: 1504)
      • hostrun.exe (PID: 2764)
    • Manual execution by a user

      • unknown_122eeabd8dda2f813207ad370e94108bbec509b8.exe (PID: 988)
    • Reads the machine GUID from the registry

      • hostrun.exe (PID: 2764)
    • Checks proxy server information

      • hostrun.exe (PID: 2764)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.7z | 7-Zip compressed archive (v0.4) (57.1)
.7z | 7-Zip compressed archive (gen) (42.8)

EXIF

ZIP

FileVersion: 7z v0.04
ModifyDate: 2008:04:14 01:22:46+00:00
ArchivedFileName: unknown_122eeabd8dda2f813207ad370e94108bbec509b8.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
45
Monitored processes
6
Malicious processes
1
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe unknown_122eeabd8dda2f813207ad370e94108bbec509b8.exe unknown_122eeabd8dda2f813207ad370e94108bbec509b8.exe cmd.exe no specs hostrun.exe no specs hostrun.exe

Process information

PID
CMD
Path
Indicators
Parent process
676C:\Windows\system32\cmd.exe /c ""C:\Users\admin\Desktop\clean.bat" "C:\Windows\System32\cmd.exeunknown_122eeabd8dda2f813207ad370e94108bbec509b8.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
1
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
988"C:\Users\admin\Desktop\unknown_122eeabd8dda2f813207ad370e94108bbec509b8.exe" C:\Users\admin\Desktop\unknown_122eeabd8dda2f813207ad370e94108bbec509b8.exe
explorer.exe
User:
admin
Company:
The Pidgin developer community
Integrity Level:
HIGH
Description:
Pidgin
Exit code:
0
Version:
2.10.0
Modules
Images
c:\users\admin\desktop\unknown_122eeabd8dda2f813207ad370e94108bbec509b8.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvbvm60.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
1504C:\Users\admin\Desktop\unknown_122eeabd8dda2f813207ad370e94108bbec509b8.exeC:\Users\admin\Desktop\unknown_122eeabd8dda2f813207ad370e94108bbec509b8.exe
unknown_122eeabd8dda2f813207ad370e94108bbec509b8.exe
User:
admin
Company:
The Pidgin developer community
Integrity Level:
HIGH
Description:
Pidgin
Exit code:
0
Version:
2.10.0
Modules
Images
c:\users\admin\desktop\unknown_122eeabd8dda2f813207ad370e94108bbec509b8.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
1744"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\Desktop\unknown_122eeabd8dda2f813207ad370e94108bbec509b8.7zC:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2204"C:\Users\admin\AppData\Roaming\Microsoft\hostrun.exe" C:\Users\admin\AppData\Roaming\Microsoft\hostrun.exeunknown_122eeabd8dda2f813207ad370e94108bbec509b8.exe
User:
admin
Company:
The Pidgin developer community
Integrity Level:
HIGH
Description:
Pidgin
Exit code:
0
Version:
2.10.0
Modules
Images
c:\users\admin\appdata\roaming\microsoft\hostrun.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvbvm60.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
2764C:\Users\admin\AppData\Roaming\Microsoft\hostrun.exeC:\Users\admin\AppData\Roaming\Microsoft\hostrun.exe
hostrun.exe
User:
admin
Company:
The Pidgin developer community
Integrity Level:
HIGH
Description:
Pidgin
Version:
2.10.0
Modules
Images
c:\users\admin\appdata\roaming\microsoft\hostrun.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
Total events
2 959
Read events
2 901
Write events
52
Delete events
6

Modification events

(PID) Process:(1744) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(1744) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(1744) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1744) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(1744) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(1744) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(1744) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\unknown_122eeabd8dda2f813207ad370e94108bbec509b8.7z
(PID) Process:(1744) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(1744) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(1744) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
Executable files
2
Suspicious files
0
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
1744WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb1744.8866\unknown_122eeabd8dda2f813207ad370e94108bbec509b8.exeexecutable
MD5:964EA81E821AEA3CA7048BED4C64C2E1
SHA256:DB6FF8160FB19DA15D059A742652BBB2079D640A214EAAA87D4C03C1BD362768
1504unknown_122eeabd8dda2f813207ad370e94108bbec509b8.exeC:\Users\admin\Desktop\clean.battext
MD5:E979EED54210E0EA5279D59B870145E0
SHA256:C33D99729B1AC197540624C7EE831127A11277C75B541CD421FDA74A37D8FEB1
1504unknown_122eeabd8dda2f813207ad370e94108bbec509b8.exeC:\Users\admin\AppData\Roaming\Microsoft\hostrun.exeexecutable
MD5:964EA81E821AEA3CA7048BED4C64C2E1
SHA256:DB6FF8160FB19DA15D059A742652BBB2079D640A214EAAA87D4C03C1BD362768
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
9
DNS requests
4
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2764
hostrun.exe
POST
404
49.13.77.253:80
http://banduman.ru/index.php
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
224.0.0.252:5355
whitelisted
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
whitelisted
2764
hostrun.exe
49.13.77.253:80
banduman.ru
Hetzner Online GmbH
DE
unknown

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.185.174
whitelisted
banduman.ru
  • 49.13.77.253
unknown
banduman44.ru
  • 49.13.77.253
unknown
banduman55.ru
  • 49.13.77.253
unknown

Threats

No threats detected
No debug info