analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

CREIS_ClientV2.1.rar

Full analysis: https://app.any.run/tasks/22ea22e4-0f77-443c-955a-d94a1dc38659
Verdict: Malicious activity
Analysis date: April 25, 2019, 09:06:27
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v4, os: Win32
MD5:

9650A4C73C655E9B1177A506AEF37BBD

SHA1:

AD7C0D12CA265C5D22F5C56A1CA964A0DD365C7C

SHA256:

EFEC3B7D87E69E351E3A3C431A79E53A5432D89713C173EB637CA72071EC9E13

SSDEEP:

12288:nQ4rp1IdY+BlatxKXCrcnF2ZByPgRUvCRoCVg+cd+4w8rpIwS7epMgsKIX:nQ4rTeYWlaZ02ZBykqwvhcdnHFA7zgsZ

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • CREIS_ClientV2.1.exe (PID: 1936)
    • Application was dropped or rewritten from another process

      • CREIS_ClientV2.1.exe (PID: 1936)
      • CREIS_ClientV2.1.exe (PID: 3176)
      • Soufun_Creisdata_Landers.exe (PID: 3680)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 916)
      • CREIS_ClientV2.1.exe (PID: 1936)
    • Creates files in the user directory

      • CREIS_ClientV2.1.exe (PID: 1936)
    • Creates a software uninstall entry

      • CREIS_ClientV2.1.exe (PID: 1936)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v-4.x) (58.3)
.rar | RAR compressed archive (gen) (41.6)

EXIF

ZIP

CompressedSize: 732137
UncompressedSize: 846415
OperatingSystem: Win32
ModifyDate: 2018:01:08 16:27:08
PackingMethod: Normal
ArchivedFileName: CREIS_ClientV2.1.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
39
Monitored processes
5
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
drop and start drop and start start drop and start winrar.exe creis_clientv2.1.exe no specs creis_clientv2.1.exe soufun_creisdata_landers.exe presentationfontcache.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
916"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\CREIS_ClientV2.1.rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.60.0
3176"C:\Users\admin\AppData\Local\Temp\Rar$EXa916.22535\CREIS_ClientV2.1.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa916.22535\CREIS_ClientV2.1.exeWinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
1936"C:\Users\admin\AppData\Local\Temp\Rar$EXa916.22535\CREIS_ClientV2.1.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa916.22535\CREIS_ClientV2.1.exe
WinRAR.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
3680"C:\Users\admin\AppData\local\CREISÖÐÖ¸´óÊý¾Ý¿Í»§¶Ë\CREISÖÐÖ¸´óÊý¾Ý\Soufun_Creisdata_Landers.exe" C:\Users\admin\AppData\local\CREISÖÐÖ¸´óÊý¾Ý¿Í»§¶Ë\CREISÖÐÖ¸´óÊý¾Ý\Soufun_Creisdata_Landers.exe
CREIS_ClientV2.1.exe
User:
admin
Integrity Level:
HIGH
Description:
Industry_Landers_CN
Version:
2.1.0.0
2344C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exeC:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exeservices.exe
User:
LOCAL SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
PresentationFontCache.exe
Version:
3.0.6920.4902 built by: NetFXw7
Total events
854
Read events
815
Write events
39
Delete events
0

Modification events

(PID) Process:(916) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(916) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(916) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\62\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(916) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\CREIS_ClientV2.1.rar
(PID) Process:(916) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(916) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(916) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(916) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(916) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\DialogEditHistory\ExtrPath
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\CREIS_ClientV2.1
(PID) Process:(916) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
Executable files
7
Suspicious files
0
Text files
63
Unknown types
3

Dropped files

PID
Process
Filename
Type
1936CREIS_ClientV2.1.exeC:\Users\admin\AppData\Local\Temp\nsx880A.tmp\modern-header.bmpimage
MD5:EB59E405A4749D0F97BBB50DEF424308
SHA256:B999346ED4B201C221E41827655C2CE14C4A2D0336D9EDF42168FD1603D62730
916WinRAR.exeC:\Users\admin\AppData\Local\Temp\CREIS_ClientV2.1\CREIS_ClientV2.1.exeexecutable
MD5:8A63B225229AC617C54D3E2A99B097C2
SHA256:A73DD1D11BC147557278AE1F936E68EBF172EF9F93456558EEDE311A0D99D349
1936CREIS_ClientV2.1.exeC:\Users\admin\AppData\Local\Temp\nsx880A.tmp\ioSpecial.initext
MD5:7737D12C9B59168FC6CA003AE47A6551
SHA256:1F64FC232D01CCC8DADCC2BEEB42D4E4182C2E778B8ED67D0DB6524580CB3835
1936CREIS_ClientV2.1.exeC:\Users\admin\AppData\local\CREISÖÐÖ¸´óÊý¾Ý¿Í»§¶Ë\CREISÖÐÖ¸´óÊý¾Ý\config.xmlxml
MD5:B3415D79D8629005919087473687D2B8
SHA256:CD18C2EBBEF3B8CC93E3578A8199041ABA51F78F5AA52777E1E47CD81DCF4365
1936CREIS_ClientV2.1.exeC:\Users\admin\AppData\local\CREISÖÐÖ¸´óÊý¾Ý¿Í»§¶Ë\CREISÖÐÖ¸´óÊý¾Ý\Soufun_Creisdata_Landers.exeexecutable
MD5:3C2BB940FEC7CC9A1696D97AB1751871
SHA256:D8D96A15F52CAD42756F075218EE0BC3122FBFDB90A2BCD31562DDC7FC54649B
1936CREIS_ClientV2.1.exeC:\Users\admin\AppData\local\CREISÖÐÖ¸´óÊý¾Ý¿Í»§¶Ë\CREISÖÐÖ¸´óÊý¾Ý\img\bg.pngimage
MD5:49A63229A7D2731B3A1F538FA23B603C
SHA256:616E429B482EC26C1696150C02EC69A531455D4E56FEA55A4A9A37B10343334F
1936CREIS_ClientV2.1.exeC:\Users\admin\AppData\local\CREISÖÐÖ¸´óÊý¾Ý¿Í»§¶Ë\CREISÖÐÖ¸´óÊý¾Ý\AutoUpdater.exeexecutable
MD5:AA84A954C2AC864F8F422DF66A87C96D
SHA256:421EA811967415369BC27A1470E26E78BAED6F804E829DDA2D072C4921C8263F
1936CREIS_ClientV2.1.exeC:\Users\admin\AppData\local\CREISÖÐÖ¸´óÊý¾Ý¿Í»§¶Ë\CREISÖÐÖ¸´óÊý¾Ý\img\256.icoimage
MD5:FB5E4B7988AAD4473BA3D2B90B4D2D0D
SHA256:48FC7200CB9EB14F3B92A819414FBEBF53879639B16EE3686ECD8A0FFD2A9FB4
916WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa916.22535\CREIS_ClientV2.1.exeexecutable
MD5:8A63B225229AC617C54D3E2A99B097C2
SHA256:A73DD1D11BC147557278AE1F936E68EBF172EF9F93456558EEDE311A0D99D349
1936CREIS_ClientV2.1.exeC:\Users\admin\AppData\local\CREISÖÐÖ¸´óÊý¾Ý¿Í»§¶Ë\CREISÖÐÖ¸´óÊý¾Ý\Soufun_Creisdata_Landers.exe.configxml
MD5:A210314E0783204D085AB1B46AC5A7BB
SHA256:6373BEBB185D180D068EC64527267E57ABDC2FE008C1FC158E903CFCD0B02C6D
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
1
DNS requests
1
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3680
Soufun_Creisdata_Landers.exe
GET
200
163.171.136.65:80
http://js.soufunimg.com/industry/creisdata/Update/Landers_CN/update.xml?v=20190425100713
US
xml
285 b
malicious
3680
Soufun_Creisdata_Landers.exe
GET
200
163.171.136.65:80
http://js.soufunimg.com/industry/creisdata/Update/Landers_CN/update.xml?v=20190425100713
US
xml
285 b
malicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3680
Soufun_Creisdata_Landers.exe
163.171.136.65:80
js.soufunimg.com
US
unknown

DNS requests

Domain
IP
Reputation
js.soufunimg.com
  • 163.171.136.65
malicious

Threats

No threats detected
No debug info