File name:

Resident.Evil.Requiem.HYPERVISOR.V2-KIRIGIRI.rar

Full analysis: https://app.any.run/tasks/e3c65d52-45d4-4ba6-9e7e-5a9c3a9cf34a
Verdict: Malicious activity
Analysis date: March 01, 2026, 13:09:56
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
arch-exec
arch-doc
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

68340E026E713F23131ABF0B68CC3AED

SHA1:

12AA4B349056217704600337A3B2E19AB1AFAF5B

SHA256:

F28EC304A07D51CFD9CC4A7CDF2CA6081BCB343FFA6F96225A75D532BE94463C

SSDEEP:

98304:Mk2wVIXN6UYhVC/7dNU/it9A9CkQPu0eGRniuf6BU3QVacqZZLXtoZD4H3F9v1QR:wVWMKHhUZatKsm8C3OlRdFjYI

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • steamclient_loader_x64.exe (PID: 5304)
      • steamclient_loader_x64.exe (PID: 2336)
      • steamclient_loader_x64.exe (PID: 3440)
      • steamclient_loader_x64.exe (PID: 1784)
  • SUSPICIOUS

    • Drops a system driver (possible attempt to evade defenses)

      • WinRAR.exe (PID: 9092)
  • INFO

    • The sample compiled with english language support

      • WinRAR.exe (PID: 9092)
    • Reads the computer name

      • steamclient_loader_x64.exe (PID: 2336)
      • steamclient_loader_x64.exe (PID: 3440)
    • Reads security settings of Internet Explorer

      • WinRAR.exe (PID: 9092)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 9092)
    • Checks supported languages

      • steamclient_loader_x64.exe (PID: 3440)
      • steamclient_loader_x64.exe (PID: 2336)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)

EXIF

ZIP

FileVersion: RAR v5
CompressedSize: 86008
UncompressedSize: 179408
OperatingSystem: Win32
ArchivedFileName: amd_ags_x64.org
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
154
Monitored processes
6
Malicious processes
1
Suspicious processes
4

Behavior graph

Click at the process to see the details
start winrar.exe steamclient_loader_x64.exe no specs steamclient_loader_x64.exe steamclient_loader_x64.exe no specs steamclient_loader_x64.exe slui.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1784"C:\Users\admin\AppData\Local\Temp\Rar$EXa9092.26665\steamclient_loader_x64.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa9092.26665\steamclient_loader_x64.exeWinRAR.exe
User:
admin
Company:
GSE
Integrity Level:
MEDIUM
Description:
GSE
Exit code:
3221226540
Version:
08.56.38.63
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa9092.26665\steamclient_loader_x64.exe
c:\windows\system32\ntdll.dll
2336"C:\Users\admin\AppData\Local\Temp\Rar$EXa9092.24379\steamclient_loader_x64.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa9092.24379\steamclient_loader_x64.exe
WinRAR.exe
User:
admin
Company:
GSE
Integrity Level:
HIGH
Description:
GSE
Exit code:
1
Version:
08.56.38.63
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa9092.24379\steamclient_loader_x64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
3440"C:\Users\admin\AppData\Local\Temp\Rar$EXa9092.26665\steamclient_loader_x64.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa9092.26665\steamclient_loader_x64.exe
WinRAR.exe
User:
admin
Company:
GSE
Integrity Level:
HIGH
Description:
GSE
Exit code:
1
Version:
08.56.38.63
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa9092.26665\steamclient_loader_x64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
5304"C:\Users\admin\AppData\Local\Temp\Rar$EXa9092.24379\steamclient_loader_x64.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa9092.24379\steamclient_loader_x64.exeWinRAR.exe
User:
admin
Company:
GSE
Integrity Level:
MEDIUM
Description:
GSE
Exit code:
3221226540
Version:
08.56.38.63
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa9092.24379\steamclient_loader_x64.exe
c:\windows\system32\ntdll.dll
8380C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
9092"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\Resident.Evil.Requiem.HYPERVISOR.V2-KIRIGIRI.rarC:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
Total events
5 582
Read events
5 572
Write events
10
Delete events
0

Modification events

(PID) Process:(9092) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(9092) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(9092) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(9092) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(9092) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Downloads\chromium_build 1.zip
(PID) Process:(9092) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Resident.Evil.Requiem.HYPERVISOR.V2-KIRIGIRI.rar
(PID) Process:(9092) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(9092) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(9092) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(9092) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
Executable files
38
Suspicious files
2
Text files
14
Unknown types
0

Dropped files

PID
Process
Filename
Type
9092WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa9092.24379\kdserial.dllexecutable
MD5:C3EDE4D9AA30B30EFFD25CC1CDEEF8A1
SHA256:D7CE65448E021AF0233CAA3B27B0EDA5DC9E3C4B461B917D5378DB38A790B363
9092WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa9092.24379\hyperkd.sysexecutable
MD5:A3A24945BF08B74B9E375C130966D6D2
SHA256:B5F5F93190ECF89F94FEAFFDD77F25FCD9B922160A705763E4C875A88A91CB0C
9092WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa9092.24379\steamclient_loader_x64.exeexecutable
MD5:E3901B3D2889DCF02F3FB9174F806F94
SHA256:551A28422E1CD119140AAD059F9D44237EBF8C850037EF4FF4522A02627B3D65
9092WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa9092.24379\coldclient\steamclient64.dllexecutable
MD5:8C4A558F0A3DDC511C4DA97DFB304392
SHA256:CA54CAD7913279985734945907973F5B37C957D69FDAAF46A058470DE12AA55B
9092WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa9092.24379\coldclient\steam_settings\configs.user.initext
MD5:9026EA52B22C80BF7C6E5FB4DDA04324
SHA256:6910FA848124F4858C8A3C97F0348556BE9F46360845A39046ED337288DCDEA3
9092WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa9092.24379\coldclient\steam_settings\steam_interfaces.txttext
MD5:B160E3F00EEFC9AB4DDEEDAED51266E0
SHA256:F851B4BD9AF4CA83F9374A9CEC31079327628876D854606E9EF9CFE78CFDBB7B
9092WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa9092.24379\ColdClientLoader.initext
MD5:915D5BDC21D829E44B4D6AE242585CD2
SHA256:44E451D5E560B541A98CA186F8617520F23E99DEF31B5A861E94877B3CDCE2A4
9092WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa9092.24379\hyperevade.dllexecutable
MD5:0E156D2E7E3C3132171D4AC2711F9BA5
SHA256:0AFAD063E2BCB59871EF4232D733E4CA8B7B710AE63EEF917A528040DDB30CE9
9092WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa9092.24379\hyperlog.dllexecutable
MD5:F28AA9B5C7598806BCC6B78F29DAAB8C
SHA256:587EC95AED2E1707129CF958010B77D1AF4EAFF98AE06F0CC6EDACF130F9AC4A
9092WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa9092.24379\amd_ags_x64.orgexecutable
MD5:9352802FAE8E6FF020AFD9257F33AF23
SHA256:B27B070CA39DC37984FB3DDE0187515D36094E72CB881D7A99BD1055BEFD8DA2
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
20
TCP/UDP connections
25
DNS requests
18
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6768
MoUsoCoreWorker.exe
GET
304
40.127.240.158:443
https://settings-win.data.microsoft.com/settings/v3.0/OneSettings/Client?OSVersionFull=10.0.19045.4046.amd64fre.vb_release.191206-1406&LocalDeviceID=s%3ABAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&FlightRing=Retail&AttrDataVer=186&OSUILocale=en-US&OSSkuId=48&App=WOSC&AppVer=&IsFlightingEnabled=0&TelemetryLevel=1&DeviceFamily=Windows.Desktop
US
whitelisted
5512
svchost.exe
GET
304
40.127.240.158:443
https://settings-win.data.microsoft.com/settings/v3.0/WSD/UpdateHealthTools?os=Windows&osVer=10.0.19041.1.amd64fre.vb_release.191206-&sku=48&deviceClass=Windows.Desktop&locale=en-US&deviceId=s:BAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&sampleId=s:95271487&appVer=10.0.19041.3626&FlightRing=Retail&TelemetryLevel=1&HidOverGattReg=C%3A%5CWINDOWS%5CSystem32%5CDriverStore%5CFileRepository%5Chidbthle.inf_amd64_9610b4821fdf82a5%5CMicrosoft.Bluetooth.Profiles.HidOverGatt.dll&AppVer=&ProcessorIdentifier=AMD64%20Family%2023%20Model%201%20Stepping%202&OEMModel=DELL&UpdateOfferedDays=4294967295&ProcessorManufacturer=AuthenticAMD&InstallDate=1661339444&OEMModelBaseBoard=&BranchReadinessLevel=CB&OEMSubModel=J5CR&IsCloudDomainJoined=0&DeferFeatureUpdatePeriodInDays=30&IsDeviceRetailDemo=0&FlightingBranchName=&OSUILocale=en-US&DeviceFamily=Windows.Desktop&WuClientVer=10.0.19041.3996&UninstallActive=1&IsFlightingEnabled=0&OSSkuId=48&ProcessorClockSpeed=3094&TotalPhysicalRAM=6144&SecureBootCapable=0&App=SedimentPack&ProcessorCores=6&CurrentBranch=vb_release&InstallLanguage=en-US&DeferQualityUpdatePeriodInDays=0&OEMName_Uncleaned=DELL&TPMVersion=0&PrimaryDiskTotalCapacity=262144&InstallationType=Client&AttrDataVer=186&ProcessorModel=AMD%20Ryzen%205%203500%206-Core%20Processor&IsEdgeWithChromiumInstalled=1&OSVersion=10.0.19045.4046&IsMDMEnrolled=0&ActivationChannel=Retail&FirmwareVersion=A.40&TrendInstalledKey=1&OSArchitecture=AMD64&DefaultUserRegion=244&UpdateManagementGroup=2
US
whitelisted
3404
SIHClient.exe
GET
304
74.178.76.128:443
https://slscr.update.microsoft.com/SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.4046/0?CH=686&L=en-US&P=&PT=0x30&WUA=10.0.19041.3996&MK=DELL&MD=DELL
US
whitelisted
3404
SIHClient.exe
GET
200
135.233.95.135:443
https://fe3cr.delivery.mp.microsoft.com/clientwebservice/ping
US
whitelisted
3404
SIHClient.exe
GET
200
74.178.76.128:443
https://slscr.update.microsoft.com/sls/ping
US
whitelisted
3404
SIHClient.exe
GET
304
74.178.76.128:443
https://slscr.update.microsoft.com/SLS/%7BE7A50285-D08D-499D-9FF8-180FDC2332BC%7D/x64/10.0.19045.4046/0?CH=686&L=en-US&P=&PT=0x30&WUA=10.0.19041.3996&MK=DELL&MD=DELL
US
whitelisted
GET
200
172.66.2.5:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAjTxtAB8my1oj8MfWpz%2F7Y%3D
US
binary
313 b
whitelisted
GET
200
204.79.197.203:80
http://oneocsp.microsoft.com/ocsp/MFQwUjBQME4wTDAJBgUrDgMCGgUABBQ3L3%2F%2Fa6ADK8NraY2GXzVaYrHG4AQUb6t%2B2v%2BXQ3LsO2d33oJhNYhHQoUCEzMAAAAGb6JMMcOVb6sAAAAAAAY%3D
US
binary
959 b
whitelisted
356
svchost.exe
POST
200
20.190.159.75:443
https://login.live.com/RST2.srf
US
xml
10.3 Kb
whitelisted
356
svchost.exe
POST
200
20.190.159.75:443
https://login.live.com/RST2.srf
US
xml
11.1 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
Not routed
whitelisted
5512
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
7600
RUXIMICS.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
6768
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
2.23.227.215:443
www.bing.com
AKAMAI-ASN1
NL
whitelisted
172.66.2.5:80
ocsp.digicert.com
CLOUDFLARENET
US
whitelisted
204.79.197.203:80
oneocsp.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
172.211.123.248:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:138
Not routed
whitelisted
356
svchost.exe
20.190.159.75:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 51.124.78.146
whitelisted
self.events.data.microsoft.com
  • 13.89.178.27
whitelisted
www.bing.com
  • 2.23.227.215
  • 2.23.227.208
whitelisted
ocsp.digicert.com
  • 172.66.2.5
  • 162.159.142.9
whitelisted
oneocsp.microsoft.com
  • 204.79.197.203
whitelisted
google.com
  • 172.217.168.78
whitelisted
client.wns.windows.com
  • 172.211.123.248
whitelisted
login.live.com
  • 20.190.159.75
  • 40.126.31.3
  • 20.190.159.130
  • 20.190.159.4
  • 40.126.31.131
  • 20.190.159.129
  • 20.190.159.64
  • 40.126.31.69
whitelisted
crl.microsoft.com
  • 2.16.164.49
  • 2.16.164.120
whitelisted
www.microsoft.com
  • 23.59.18.102
whitelisted

Threats

PID
Process
Class
Message
5512
svchost.exe
Unknown Traffic
ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW)
No debug info