File name:

The Invincible RUNE.rar

Full analysis: https://app.any.run/tasks/dcf51950-7fef-4edc-8a82-03273e09a524
Verdict: Malicious activity
Analysis date: February 04, 2024, 00:03:26
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

ACA2D24554D16CF6CB57428A93F85A57

SHA1:

0AA7CFD7468BB3EBB5973F861A6FDD6D18B837DE

SHA256:

EBC2770363AC8F629F1EA47E4A325908D3471B4F4EF9FA2976F142D51680C84A

SSDEEP:

98304:LIYMUyxFpdUgy7hoFS80xMt8cl6GWjDQY2vaC0joDgdsnxFtQ108u8xZTTGgJE18:qpZK502UBo

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • setup.exe (PID: 3012)
      • setup.tmp (PID: 3052)
      • WinRAR.exe (PID: 268)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • setup.tmp (PID: 3052)
    • Reads the Windows owner or organization settings

      • setup.tmp (PID: 3052)
    • Executable content was dropped or overwritten

      • setup.exe (PID: 3012)
      • setup.tmp (PID: 3052)
  • INFO

    • Checks supported languages

      • setup.exe (PID: 3012)
      • setup.tmp (PID: 3052)
    • Manual execution by a user

      • setup.exe (PID: 668)
      • setup.exe (PID: 3012)
      • rundll32.exe (PID: 3708)
      • notepad.exe (PID: 1492)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 268)
    • Create files in a temporary directory

      • setup.exe (PID: 3012)
      • setup.tmp (PID: 3052)
    • Reads the computer name

      • setup.tmp (PID: 3052)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
48
Monitored processes
6
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe setup.exe no specs setup.exe setup.tmp rundll32.exe no specs notepad.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
268"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\The Invincible RUNE.rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
668"C:\Users\admin\Desktop\The Invincible RUNE\setup.exe" C:\Users\admin\Desktop\The Invincible RUNE\setup.exeexplorer.exe
User:
admin
Company:
Integrity Level:
MEDIUM
Description:
The Invincible Setup
Exit code:
3221226540
Version:
Modules
Images
c:\users\admin\desktop\the invincible rune\setup.exe
c:\windows\system32\ntdll.dll
1492"C:\Windows\system32\NOTEPAD.EXE" C:\Users\admin\Desktop\The Invincible RUNE\RUNE\Engine\Binaries\ThirdParty\Steamworks\Steamv152\Win64\steam_emu.iniC:\Windows\System32\notepad.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\notepad.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3012"C:\Users\admin\Desktop\The Invincible RUNE\setup.exe" C:\Users\admin\Desktop\The Invincible RUNE\setup.exe
explorer.exe
User:
admin
Company:
Integrity Level:
HIGH
Description:
The Invincible Setup
Exit code:
2
Version:
Modules
Images
c:\users\admin\desktop\the invincible rune\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
3052"C:\Users\admin\AppData\Local\Temp\is-N4CGP.tmp\setup.tmp" /SL5="$160150,6123582,153088,C:\Users\admin\Desktop\The Invincible RUNE\setup.exe" C:\Users\admin\AppData\Local\Temp\is-N4CGP.tmp\setup.tmp
setup.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
2
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-n4cgp.tmp\setup.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
3708"C:\Windows\system32\rundll32.exe" C:\Windows\system32\shell32.dll,OpenAs_RunDLL C:\Users\admin\Desktop\The Invincible RUNE\RUNE\Engine\Binaries\ThirdParty\Steamworks\Steamv152\Win64\steam_api64.dllC:\Windows\System32\rundll32.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
Total events
1 038
Read events
1 012
Write events
22
Delete events
4

Modification events

(PID) Process:(268) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(268) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(268) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(268) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(268) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(268) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(268) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(268) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(268) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(268) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000
Executable files
10
Suspicious files
0
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
268WinRAR.exeC:\Users\admin\Desktop\The Invincible RUNE\setup.exeexecutable
MD5:E8BACB683574D60C8330888B6AFDA8F0
SHA256:636C6693B62F3711B1DABB4BBECD2C7845BE351158E62F7DE1274076CDCB5E9B
268WinRAR.exeC:\Users\admin\Desktop\The Invincible RUNE\RUNE\Engine\Binaries\ThirdParty\Steamworks\Steamv152\Win64\steam_api64.dllexecutable
MD5:E98E357C5712D35FCF1AE53C99CBC6A9
SHA256:C269EF26736F907C637BA33F146A318D5E154824C47D3FC8937781EA8829DCC8
3012setup.exeC:\Users\admin\AppData\Local\Temp\is-N4CGP.tmp\setup.tmpexecutable
MD5:D95556420B65C52783E8CF422B62611A
SHA256:E153BDE25D0A3F8180ACF43A69AF32EE2FA220751709A09DFE3EB84BF2F71600
268WinRAR.exeC:\Users\admin\Desktop\The Invincible RUNE\RUNE\Engine\Binaries\ThirdParty\Steamworks\Steamv152\Win64\steam_emu.initext
MD5:9E06E9C7BA974E664EC2306F03AB7BB7
SHA256:D679AD70A20622423EA485053B5D89440DCF589E9BC96ED5218D140FA33A12B0
268WinRAR.exeC:\Users\admin\Desktop\The Invincible RUNE\RUNE\Engine\Binaries\ThirdParty\Steamworks\Steamv152\Win64\steam_api64.rneexecutable
MD5:B6CD19B7A73152E24B5ED22DA8112C63
SHA256:0F16CEF53BBA8CE21056ECB49AA254EB407759A7AB1095452730695D7D8199A4
3052setup.tmpC:\Users\admin\AppData\Local\Temp\is-VGPTL.tmp\_isetup\_shfoldr.dllexecutable
MD5:92DC6EF532FBB4A5C3201469A5B5EB63
SHA256:9884E9D1B4F8A873CCBD81F8AD0AE257776D2348D027D811A56475E028360D87
3052setup.tmpC:\Users\admin\AppData\Local\Temp\is-VGPTL.tmp\VclStylesInno.dllexecutable
MD5:64101D65027ABE80025028AF0CFDB6B3
SHA256:C2DEBFB2A38BC839365F000878FA4561DDEBF4955616FEEB812D5ADF3094B721
3052setup.tmpC:\Users\admin\AppData\Local\Temp\is-VGPTL.tmp\ISDone.dllexecutable
MD5:DCE6D68DA86F44BA0CB70FA7718E2E84
SHA256:B9BDC4A0309AA47613A7B5A680C55839AA7BA28E28F96E6B9316D4D5FE1DBE9D
3052setup.tmpC:\Users\admin\AppData\Local\Temp\is-VGPTL.tmp\BASS.dllexecutable
MD5:C0B11A7E60F69241DDCB278722AB962F
SHA256:A8D979460E970E84EACCE36B8A68AE5F6B9CC0FE16E05A6209B4EAD52B81B021
3052setup.tmpC:\Users\admin\AppData\Local\Temp\is-VGPTL.tmp\bp.dllexecutable
MD5:70CD1D226553F3C0546664D76373FE67
SHA256:65A7E7FB213007BA2E285BB2C3E2DF1A553990A2A3E26A0A6591F01CE6C87BC0
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown

DNS requests

No data

Threats

No threats detected
No debug info