File name:

lockscreen_08e922f7afd189d34d148640deae2bd60b3e4c39.7z

Full analysis: https://app.any.run/tasks/2ea0f90e-ec9d-4493-b54e-2fdac5962679
Verdict: Malicious activity
Analysis date: May 15, 2025, 19:02:10
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
arch-exec
Indicators:
MIME: application/x-7z-compressed
File info: 7-zip archive data, version 0.4
MD5:

2CDF895B60EE546F415FB0004A370CF8

SHA1:

B2FF5CC346FBAC949DA6CA104733D086A8EF48A1

SHA256:

E8AA015E4A4EFDE8241C652F81B45AB889BFAC87C33D5FD13C714259D9A474FD

SSDEEP:

768:gK7mKZgrHWe95Yp1juAgDVtG2hItJL8A+HzLB6weVE7ndlKQF4FdM90yxEqPTEK6:lCfJ4R23WJWF6w1XKQF4HyNTEQG3D

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • lockscreen_08e922f7afd189d34d148640deae2bd60b3e4c39.exe (PID: 3140)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • lockscreen_08e922f7afd189d34d148640deae2bd60b3e4c39.exe (PID: 3140)
    • Reads security settings of Internet Explorer

      • lockscreen_08e922f7afd189d34d148640deae2bd60b3e4c39.exe (PID: 3140)
      • firefox.exe (PID: 988)
    • Reads the Internet Settings

      • lockscreen_08e922f7afd189d34d148640deae2bd60b3e4c39.exe (PID: 3140)
      • firefox.exe (PID: 988)
    • Starts CMD.EXE for commands execution

      • lockscreen_08e922f7afd189d34d148640deae2bd60b3e4c39.exe (PID: 3140)
    • Executing commands from a ".bat" file

      • lockscreen_08e922f7afd189d34d148640deae2bd60b3e4c39.exe (PID: 3140)
    • Starts itself from another location

      • lockscreen_08e922f7afd189d34d148640deae2bd60b3e4c39.exe (PID: 3140)
    • There is functionality for taking screenshot (YARA)

      • firefox.exe (PID: 988)
  • INFO

    • Manual execution by a user

      • lockscreen_08e922f7afd189d34d148640deae2bd60b3e4c39.exe (PID: 3140)
    • Checks supported languages

      • lockscreen_08e922f7afd189d34d148640deae2bd60b3e4c39.exe (PID: 3140)
      • firefox.exe (PID: 988)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2060)
    • The sample compiled with english language support

      • WinRAR.exe (PID: 2060)
      • lockscreen_08e922f7afd189d34d148640deae2bd60b3e4c39.exe (PID: 3140)
    • Reads the computer name

      • lockscreen_08e922f7afd189d34d148640deae2bd60b3e4c39.exe (PID: 3140)
      • firefox.exe (PID: 988)
    • Reads the machine GUID from the registry

      • firefox.exe (PID: 988)
    • Checks proxy server information

      • firefox.exe (PID: 988)
    • Creates files or folders in the user directory

      • lockscreen_08e922f7afd189d34d148640deae2bd60b3e4c39.exe (PID: 3140)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.7z | 7-Zip compressed archive (v0.4) (57.1)
.7z | 7-Zip compressed archive (gen) (42.8)

EXIF

ZIP

FileVersion: 7z v0.04
ModifyDate: 2008:04:14 01:22:46+00:00
ArchivedFileName: lockscreen_08e922f7afd189d34d148640deae2bd60b3e4c39.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
44
Monitored processes
4
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe lockscreen_08e922f7afd189d34d148640deae2bd60b3e4c39.exe cmd.exe no specs firefox.exe

Process information

PID
CMD
Path
Indicators
Parent process
988"C:\Users\admin\AppData\Roaming\Mozilla\Firefox\firefox.exe" C:\Users\admin\AppData\Roaming\Mozilla\Firefox\firefox.exe
lockscreen_08e922f7afd189d34d148640deae2bd60b3e4c39.exe
User:
admin
Integrity Level:
HIGH
Modules
Images
c:\users\admin\appdata\roaming\mozilla\firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1120C:\Windows\system32\cmd.exe /c ""C:\Users\admin\Desktop\clear.bat" "C:\Windows\System32\cmd.exelockscreen_08e922f7afd189d34d148640deae2bd60b3e4c39.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
1
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2060"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\Desktop\lockscreen_08e922f7afd189d34d148640deae2bd60b3e4c39.7zC:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3140"C:\Users\admin\Desktop\lockscreen_08e922f7afd189d34d148640deae2bd60b3e4c39.exe" C:\Users\admin\Desktop\lockscreen_08e922f7afd189d34d148640deae2bd60b3e4c39.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\desktop\lockscreen_08e922f7afd189d34d148640deae2bd60b3e4c39.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
Total events
2 489
Read events
2 431
Write events
52
Delete events
6

Modification events

(PID) Process:(2060) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2060) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2060) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2060) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(2060) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(2060) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(2060) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\lockscreen_08e922f7afd189d34d148640deae2bd60b3e4c39.7z
(PID) Process:(2060) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2060) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2060) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
Executable files
2
Suspicious files
0
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
3140lockscreen_08e922f7afd189d34d148640deae2bd60b3e4c39.exeC:\Users\admin\Desktop\clear.battext
MD5:A4002AC882AB165E79138DD7B676C54C
SHA256:66635B7911D961062B8E81F621CD2EEA3220CAAA6CAD6C8661119EE3FC7715B4
3140lockscreen_08e922f7afd189d34d148640deae2bd60b3e4c39.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\firefox.exeexecutable
MD5:E1B7B9EC48EC1E8E10F4782369CD7BB9
SHA256:0EE033A956071FCF5035FD719309F85BCEFEC1F9C23E26AF7C9484F20F3A183F
2060WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb2060.5045\lockscreen_08e922f7afd189d34d148640deae2bd60b3e4c39.exeexecutable
MD5:E1B7B9EC48EC1E8E10F4782369CD7BB9
SHA256:0EE033A956071FCF5035FD719309F85BCEFEC1F9C23E26AF7C9484F20F3A183F
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
13
DNS requests
8
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
988
firefox.exe
POST
404
49.13.77.253:80
http://mpriagribik.com/
unknown
unknown
988
firefox.exe
POST
404
49.13.77.253:80
http://widowylucenti.info/
unknown
unknown
988
firefox.exe
POST
404
49.13.77.253:80
http://thijmsmawworm.info/
unknown
unknown
988
firefox.exe
POST
404
49.13.77.253:80
http://pilbeamcanar.info/
unknown
unknown
988
firefox.exe
POST
404
49.13.77.253:80
http://fowdensuljo.info/
unknown
unknown
988
firefox.exe
POST
404
49.13.77.253:80
http://ilanjihaemta.info/
unknown
unknown
988
firefox.exe
POST
404
49.13.77.253:80
http://saynerclecak.info/
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
224.0.0.252:5355
whitelisted
1080
svchost.exe
224.0.0.252:5355
whitelisted
4
System
192.168.100.255:138
whitelisted
988
firefox.exe
49.13.77.253:80
mpriagribik.com
Hetzner Online GmbH
DE
unknown

DNS requests

Domain
IP
Reputation
google.com
  • 216.58.206.46
whitelisted
mpriagribik.com
  • 49.13.77.253
unknown
widowylucenti.info
  • 49.13.77.253
unknown
thijmsmawworm.info
  • 49.13.77.253
unknown
pilbeamcanar.info
  • 49.13.77.253
unknown
ilanjihaemta.info
  • 49.13.77.253
unknown
fowdensuljo.info
  • 49.13.77.253
unknown
saynerclecak.info
  • 49.13.77.253
unknown

Threats

No threats detected
No debug info