File name:

STATION220_2025-03-24_16_40_22.444.zip

Full analysis: https://app.any.run/tasks/63c129f5-6d17-4fb8-8db4-c59d4da88138
Verdict: Malicious activity
Analysis date: March 24, 2025, 17:08:54
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
auto
generic
Indicators:
MIME: application/zip
File info: Zip archive data, at least v4.5 to extract, compression method=deflate
MD5:

2AB2FDF20692D2E978EB9BDF90F9B4D5

SHA1:

34E4245280B874B1E907A5886FA01CA3D937F61E

SHA256:

F26E024BD304C11FAC3772064405919CB634980761247696D24B685492683176

SSDEEP:

384:NlWKpP8kdua+805eW6NuKah31yl3h0SGHD0SW8V1N/WM:NcKP8ffoBap1S3h0LY4/WM

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • GENERIC has been found (auto)

      • WinRAR.exe (PID: 6036)
  • SUSPICIOUS

    • Executes application which crashes

      • Updater.exe (PID: 7948)
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 6036)
    • Reads the computer name

      • Updater.exe (PID: 7948)
    • Disables trace logs

      • Updater.exe (PID: 7948)
    • Reads the machine GUID from the registry

      • Updater.exe (PID: 7948)
    • Checks supported languages

      • Updater.exe (PID: 7948)
    • Reads Environment values

      • Updater.exe (PID: 7948)
    • Checks proxy server information

      • Updater.exe (PID: 7948)
    • Creates files or folders in the user directory

      • WerFault.exe (PID: 1184)
    • Reads the software policy settings

      • slui.exe (PID: 7296)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: 0x0801
ZipCompression: Deflated
ZipModifyDate: 1980:00:00 00:00:00
ZipCRC: 0x7b638707
ZipCompressedSize: 13478
ZipUncompressedSize: 20776
ZipFileName: Device/HarddiskVolume3/Users/FranciscoC/AppData/Local/ZipThis/Updater.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
143
Monitored processes
6
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start #GENERIC winrar.exe sppextcomobj.exe no specs slui.exe updater.exe werfault.exe no specs slui.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1184C:\WINDOWS\system32\WerFault.exe -u -p 7948 -s 1636C:\Windows\System32\WerFault.exeUpdater.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\oleaut32.dll
6036"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\STATION220_2025-03-24_16_40_22.444.zipC:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
6184C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
7212C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
7296"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exe
SppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
7948"C:\Users\admin\AppData\Local\Temp\Rar$EXb6036.45573\Device\HarddiskVolume3\Users\FranciscoC\AppData\Local\ZipThis\Updater.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXb6036.45573\Device\HarddiskVolume3\Users\FranciscoC\AppData\Local\ZipThis\Updater.exe
WinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Updater
Exit code:
3762504530
Version:
5.345.34.36
Modules
Images
c:\users\admin\appdata\local\temp\rar$exb6036.45573\device\harddiskvolume3\users\franciscoc\appdata\local\zipthis\updater.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
Total events
6 498
Read events
6 475
Write events
23
Delete events
0

Modification events

(PID) Process:(6036) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(6036) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(6036) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(6036) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\STATION220_2025-03-24_16_40_22.444.zip
(PID) Process:(6036) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(6036) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(6036) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(6036) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(6036) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface
Operation:writeName:ShowPassword
Value:
1
(PID) Process:(7948) Updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Updater_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
Executable files
2
Suspicious files
1
Text files
2
Unknown types
0

Dropped files

PID
Process
Filename
Type
1184WerFault.exeC:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_Updater.exe_2cfbf10f45461e0b8d5fc35257df33a8a3b758a_76bcebfe_f19f3895-2adb-489d-8e25-6c9803091b3e\Report.wer
MD5:
SHA256:
1184WerFault.exeC:\Users\admin\AppData\Local\CrashDumps\Updater.exe.7948.dmp
MD5:
SHA256:
6036WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb6036.45573\manifest.jsontext
MD5:F49CB0A0B5D9F9FCC67650E7B0FF17B8
SHA256:DD81AF38893AED98D0EDD603646C9BA7D62F8F1C6B5825B2A8E4196804B6CCE1
1184WerFault.exeC:\ProgramData\Microsoft\Windows\WER\Temp\WER4EFA.tmp.xmlxml
MD5:AA3D5C231E9D3EC369679EB82BF7E200
SHA256:8341A149BEEAE287557652EF8EE595B3F7B7AFD68F5CDC80C46CEAE758516D59
1184WerFault.exeC:\ProgramData\Microsoft\Windows\WER\Temp\WER4EBA.tmp.WERInternalMetadata.xmlxml
MD5:A9EB3AF5598E663B5E33FE16A52BF1ED
SHA256:8BAA4F59AB6F305D0681CFACB641875F029EAA22FD1BB39FDE3D20532E0E9DB3
6036WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb6036.45573\Device\HarddiskVolume3\Users\FranciscoC\AppData\Local\ZipThis\Updater.exeexecutable
MD5:8F3972F98564FC9D1E3E5A3840A0DA85
SHA256:CBDFE04B8F754E5E6150936EE604F0A478B79C6D0466EE155775EAD575ADEA90
1184WerFault.exeC:\ProgramData\Microsoft\Windows\WER\Temp\WER4A73.tmp.dmpbinary
MD5:81A4CEE2444770CC27C4B5A4025DC76A
SHA256:A5C797F355F825CA3E927768CB3725A1875086EDB0EBC9C44430ADEDAD975311
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
25
DNS requests
17
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5496
MoUsoCoreWorker.exe
GET
200
23.48.23.166:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
7252
backgroundTaskHost.exe
GET
200
23.63.118.230:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
8152
SIHClient.exe
GET
200
2.19.217.218:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
6544
svchost.exe
GET
200
23.63.118.230:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
8152
SIHClient.exe
GET
200
2.19.217.218:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
51.104.136.2:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5496
MoUsoCoreWorker.exe
23.48.23.166:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
2104
svchost.exe
51.104.136.2:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3216
svchost.exe
40.113.103.199:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6544
svchost.exe
20.190.159.75:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6544
svchost.exe
23.63.118.230:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
2112
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
7252
backgroundTaskHost.exe
20.223.35.26:443
arc.msn.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.184.238
whitelisted
crl.microsoft.com
  • 23.48.23.166
  • 23.48.23.169
  • 23.48.23.162
  • 23.48.23.183
  • 23.48.23.168
  • 23.48.23.177
  • 23.48.23.173
  • 23.48.23.181
  • 23.48.23.174
whitelisted
client.wns.windows.com
  • 40.113.103.199
whitelisted
login.live.com
  • 20.190.159.75
  • 20.190.159.129
  • 40.126.31.69
  • 20.190.159.0
  • 40.126.31.67
  • 20.190.159.4
  • 20.190.159.2
  • 40.126.31.131
whitelisted
ocsp.digicert.com
  • 23.63.118.230
whitelisted
settings-win.data.microsoft.com
  • 51.124.78.146
whitelisted
arc.msn.com
  • 20.223.35.26
whitelisted
can.thisilient.com
  • 45.33.84.9
unknown
slscr.update.microsoft.com
  • 20.12.23.50
whitelisted
www.microsoft.com
  • 2.19.217.218
whitelisted

Threats

No threats detected
No debug info