File name:

Kaspersky Trial Reset 2019 (KRT CLUB 2.1.2.69).rar

Full analysis: https://app.any.run/tasks/9425bb1b-d4db-448e-b464-9115de0576c2
Verdict: Malicious activity
Analysis date: December 01, 2018, 19:26:31
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

2CD2D6B97FFC502235699C1409895BF2

SHA1:

9D6BFC8069EEFB59E30B849BA1F011A43A8F1929

SHA256:

EDFC1FFFF6DF37CF1711FDAC4DD79CC6D663A3353315E03A96FC8CCC6AB79209

SSDEEP:

393216:yVYGqHJ7uP6qJsTzbTT4NBvGTb0swRotF:LPHJ74nsnENkr5F

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • KRT_CLUB_2.1.2.69.exe (PID: 3656)
      • KRT_CLUB_2.1.2.69.exe (PID: 3004)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2796)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
39
Monitored processes
5
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe no specs explorer.exe no specs winrar.exe krt_club_2.1.2.69.exe no specs krt_club_2.1.2.69.exe

Process information

PID
CMD
Path
Indicators
Parent process
2796"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Downloads\Kaspersky Trial Reset 2019 (KRT CLUB 2.1.2.69).rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3004"C:\Users\admin\Desktop\KRT_CLUB_2.1.2.69.exe" C:\Users\admin\Desktop\KRT_CLUB_2.1.2.69.exe
explorer.exe
User:
admin
Company:
Collective Intelligence and ML
Integrity Level:
HIGH
Description:
KRT_CLUB
Exit code:
0
Version:
2.1.2.69
Modules
Images
c:\users\admin\desktop\krt_club_2.1.2.69.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\winmm.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3240"C:\Windows\explorer.exe" C:\Windows\explorer.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\explorer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3332"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Downloads\Kaspersky Trial Reset 2019 (KRT CLUB 2.1.2.69).rar"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3656"C:\Users\admin\Desktop\KRT_CLUB_2.1.2.69.exe" C:\Users\admin\Desktop\KRT_CLUB_2.1.2.69.exeexplorer.exe
User:
admin
Company:
Collective Intelligence and ML
Integrity Level:
MEDIUM
Description:
KRT_CLUB
Exit code:
3221226540
Version:
2.1.2.69
Modules
Images
c:\users\admin\desktop\krt_club_2.1.2.69.exe
c:\systemroot\system32\ntdll.dll
Total events
886
Read events
846
Write events
40
Delete events
0

Modification events

(PID) Process:(3332) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3332) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3332) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3332) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Downloads\Kaspersky Trial Reset 2019 (KRT CLUB 2.1.2.69).rar
(PID) Process:(3332) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3332) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3332) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3332) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2796) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2796) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
Executable files
1
Suspicious files
0
Text files
9
Unknown types
0

Dropped files

PID
Process
Filename
Type
2796WinRAR.exeC:\Users\admin\Desktop\Languages\Russian.lngtext
MD5:78D512AB108912E582F4516DC75ED26C
SHA256:7335C7F5498241607621B393FB7220F5038BB196F8CE5F25DDC718C3C71D70BA
2796WinRAR.exeC:\Users\admin\Desktop\Languages\Hungarian.lngtext
MD5:058D3DEEC59D5470D27F003CF2B9293E
SHA256:C2F7466A02DAD01D8495BE2423C9A790BC642C3896DE38424750EC2DB1BA3238
2796WinRAR.exeC:\Users\admin\Desktop\Languages\Portuguese.lngtext
MD5:C7A581300D657985137047B75C0CD2DC
SHA256:7113EF5A5CF6A2AE9E6A2D322527001F26111B6B2753B5A40944F99BC3B23513
2796WinRAR.exeC:\Users\admin\Desktop\Languages\Vietnamese.lngtext
MD5:9B8EF7DD9054F12664B3DD98429DA259
SHA256:F1719A51050406B43D351CEC91F3F2D507ACC635241F04760786A2A8136A5216
2796WinRAR.exeC:\Users\admin\Desktop\Languages\French.lngtext
MD5:6EC12384CCE54FED315AA38309A54760
SHA256:CB9DC7EF7FCEB84DA908BE8A1C71049C4CADF76B8809ADDF1ACD1B2F345E17AC
2796WinRAR.exeC:\Users\admin\Desktop\Languages\German.lngtext
MD5:6B5A137F8D1A3CEBF27652859249610D
SHA256:9AD162C961553D4919025285CA89BADBA145D2BA451808ADE5447A3D0972AE91
2796WinRAR.exeC:\Users\admin\Desktop\KRT_CLUB.initext
MD5:D568AAE0592F013029AE1151F8EE3181
SHA256:1318BC67C341D467F7BA505A8F84A22C3513D7F2A0D6E54408FB48D7D6A29FBF
2796WinRAR.exeC:\Users\admin\Desktop\Languages\English.lngtext
MD5:2EC021580A069E4976B8756E93206EE9
SHA256:2243DA9F2D20A6B3A5AE534E403628CF86DBD67F8A3AAD06A9352DA480BF8400
2796WinRAR.exeC:\Users\admin\Desktop\Languages\Spanish.lngtext
MD5:394DF7EFA1D86B732EA09D9F7BDEFB46
SHA256:D2EEEC8F3C8269D8E6B1CFA85348EF359DE19B308CC881FA1E4F0BCFAFE037AC
2796WinRAR.exeC:\Users\admin\Desktop\KRT_CLUB_2.1.2.69.exeexecutable
MD5:406C4EB70CAAE4851C0E7458A8FD6FF7
SHA256:C0CADF50D7AB8817BEF943810FAF57FCC4E7AB35B4E1D8C5734BB2743888B8A1
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info