File name:

Resident.Evil.Requiem.HYPERVISOR.V2-KIRIGIRI.rar

Full analysis: https://app.any.run/tasks/e6b67e88-3952-4873-8a9a-4a04a54a259e
Verdict: Malicious activity
Analysis date: March 01, 2026, 12:13:48
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
arch-exec
arch-doc
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

68340E026E713F23131ABF0B68CC3AED

SHA1:

12AA4B349056217704600337A3B2E19AB1AFAF5B

SHA256:

F28EC304A07D51CFD9CC4A7CDF2CA6081BCB343FFA6F96225A75D532BE94463C

SSDEEP:

98304:Mk2wVIXN6UYhVC/7dNU/it9A9CkQPu0eGRniuf6BU3QVacqZZLXtoZD4H3F9v1QR:wVWMKHhUZatKsm8C3OlRdFjYI

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • steamclient_loader_x64.exe (PID: 5356)
      • steamclient_loader_x64.exe (PID: 8156)
      • steamclient_loader_x64.exe (PID: 5108)
  • SUSPICIOUS

    • Drops a system driver (possible attempt to evade defenses)

      • WinRAR.exe (PID: 5168)
  • INFO

    • Manual execution by a user

      • steamclient_loader_x64.exe (PID: 8156)
      • steamclient_loader_x64.exe (PID: 5356)
      • steamclient_loader_x64.exe (PID: 5108)
      • watchdog.exe (PID: 1136)
      • watchdog.exe (PID: 5604)
      • EfiDSEFix.exe (PID: 7448)
    • The sample compiled with english language support

      • WinRAR.exe (PID: 5168)
    • Generic archive extractor

      • WinRAR.exe (PID: 5168)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 5168)
    • Reads the computer name

      • steamclient_loader_x64.exe (PID: 5356)
      • steamclient_loader_x64.exe (PID: 5108)
    • Checks supported languages

      • steamclient_loader_x64.exe (PID: 5356)
      • steamclient_loader_x64.exe (PID: 5108)
      • watchdog.exe (PID: 1136)
      • watchdog.exe (PID: 5604)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)

EXIF

ZIP

FileVersion: RAR v5
CompressedSize: 86008
UncompressedSize: 179408
OperatingSystem: Win32
ArchivedFileName: amd_ags_x64.org
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
157
Monitored processes
9
Malicious processes
0
Suspicious processes
3

Behavior graph

Click at the process to see the details
start winrar.exe steamclient_loader_x64.exe no specs steamclient_loader_x64.exe steamclient_loader_x64.exe watchdog.exe no specs watchdog.exe no specs slui.exe no specs efidsefix.exe no specs conhost.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1136"C:\Users\admin\Desktop\watchdog.exe" C:\Users\admin\Desktop\watchdog.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\watchdog.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
1932C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
5108"C:\Users\admin\Desktop\steamclient_loader_x64.exe" C:\Users\admin\Desktop\steamclient_loader_x64.exe
explorer.exe
User:
admin
Company:
GSE
Integrity Level:
HIGH
Description:
GSE
Exit code:
1
Version:
08.56.38.63
Modules
Images
c:\users\admin\desktop\steamclient_loader_x64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
5168"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\Resident.Evil.Requiem.HYPERVISOR.V2-KIRIGIRI.rarC:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
5356"C:\Users\admin\Desktop\steamclient_loader_x64.exe" C:\Users\admin\Desktop\steamclient_loader_x64.exe
explorer.exe
User:
admin
Company:
GSE
Integrity Level:
HIGH
Description:
GSE
Exit code:
1
Version:
08.56.38.63
Modules
Images
c:\users\admin\desktop\steamclient_loader_x64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
5604"C:\Users\admin\Desktop\watchdog.exe" C:\Users\admin\Desktop\watchdog.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\watchdog.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
7448"C:\Users\admin\Desktop\EfiGuard\EfiDSEFix.exe" C:\Users\admin\Desktop\EfiGuard\EfiDSEFix.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\efiguard\efidsefix.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
8156"C:\Users\admin\Desktop\steamclient_loader_x64.exe" C:\Users\admin\Desktop\steamclient_loader_x64.exeexplorer.exe
User:
admin
Company:
GSE
Integrity Level:
MEDIUM
Description:
GSE
Exit code:
3221226540
Version:
08.56.38.63
Modules
Images
c:\users\admin\desktop\steamclient_loader_x64.exe
c:\windows\system32\ntdll.dll
9076\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeEfiDSEFix.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
2 153
Read events
2 145
Write events
8
Delete events
0

Modification events

(PID) Process:(5168) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(5168) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(5168) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Downloads\chromium_build 1.zip
(PID) Process:(5168) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Resident.Evil.Requiem.HYPERVISOR.V2-KIRIGIRI.rar
(PID) Process:(5168) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(5168) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(5168) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(5168) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
Executable files
19
Suspicious files
1
Text files
7
Unknown types
0

Dropped files

PID
Process
Filename
Type
5168WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa5168.38158\amd_ags_x64.orgexecutable
MD5:9352802FAE8E6FF020AFD9257F33AF23
SHA256:B27B070CA39DC37984FB3DDE0187515D36094E72CB881D7A99BD1055BEFD8DA2
5168WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa5168.38158\ColdClientLoader.initext
MD5:915D5BDC21D829E44B4D6AE242585CD2
SHA256:44E451D5E560B541A98CA186F8617520F23E99DEF31B5A861E94877B3CDCE2A4
5168WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa5168.38158\hyperkd.sysexecutable
MD5:A3A24945BF08B74B9E375C130966D6D2
SHA256:B5F5F93190ECF89F94FEAFFDD77F25FCD9B922160A705763E4C875A88A91CB0C
5168WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa5168.38158\KIRIGIRI.dllexecutable
MD5:1098656BFCADD7AE22A3D3647926307C
SHA256:EB246D275A07D4E4F44579B9C6879F1A52382F22B4FE2440583ED217D4EC4C70
5168WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa5168.38158\kdserial.dllexecutable
MD5:C3EDE4D9AA30B30EFFD25CC1CDEEF8A1
SHA256:D7CE65448E021AF0233CAA3B27B0EDA5DC9E3C4B461B917D5378DB38A790B363
5168WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa5168.38158\hyperevade.dllexecutable
MD5:0E156D2E7E3C3132171D4AC2711F9BA5
SHA256:0AFAD063E2BCB59871EF4232D733E4CA8B7B710AE63EEF917A528040DDB30CE9
5168WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa5168.38158\coldclient\steamclient64.dllexecutable
MD5:8C4A558F0A3DDC511C4DA97DFB304392
SHA256:CA54CAD7913279985734945907973F5B37C957D69FDAAF46A058470DE12AA55B
5168WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa5168.38158\coldclient\steam_settings\steam_interfaces.txttext
MD5:B160E3F00EEFC9AB4DDEEDAED51266E0
SHA256:F851B4BD9AF4CA83F9374A9CEC31079327628876D854606E9EF9CFE78CFDBB7B
5168WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa5168.38158\coldclient\steam_settings\configs.main.initext
MD5:47A31FC4B75A0642C7CC5675FE8FB4F1
SHA256:5DD219DF4B0BB37C07ECD90CCF5215ED182E229D5D7D24B6BA31429CE46C91D4
5168WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa5168.38158\coldclient\steam_settings\configs.app.initext
MD5:7F43980C384FA5CF5FA0D1A421031135
SHA256:51DE7A34D85F958880F1D6787143E6B157D70FC81842D726C026E962D302BF43
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
16
TCP/UDP connections
21
DNS requests
16
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5780
svchost.exe
GET
304
51.124.78.146:443
https://settings-win.data.microsoft.com/settings/v3.0/WSD/UpdateHealthTools?os=Windows&osVer=10.0.19041.1.amd64fre.vb_release.191206-&sku=48&deviceClass=Windows.Desktop&locale=en-US&deviceId=s:BAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&sampleId=s:95271487&appVer=10.0.19041.3626&FlightRing=Retail&TelemetryLevel=1&HidOverGattReg=C%3A%5CWINDOWS%5CSystem32%5CDriverStore%5CFileRepository%5Chidbthle.inf_amd64_9610b4821fdf82a5%5CMicrosoft.Bluetooth.Profiles.HidOverGatt.dll&AppVer=&ProcessorIdentifier=AMD64%20Family%2023%20Model%201%20Stepping%202&OEMModel=DELL&UpdateOfferedDays=4294967295&ProcessorManufacturer=AuthenticAMD&InstallDate=1661339444&OEMModelBaseBoard=&BranchReadinessLevel=CB&OEMSubModel=J5CR&IsCloudDomainJoined=0&DeferFeatureUpdatePeriodInDays=30&IsDeviceRetailDemo=0&FlightingBranchName=&OSUILocale=en-US&DeviceFamily=Windows.Desktop&WuClientVer=10.0.19041.3996&UninstallActive=1&IsFlightingEnabled=0&OSSkuId=48&ProcessorClockSpeed=3094&TotalPhysicalRAM=6144&SecureBootCapable=0&App=SedimentPack&ProcessorCores=6&CurrentBranch=vb_release&InstallLanguage=en-US&DeferQualityUpdatePeriodInDays=0&OEMName_Uncleaned=DELL&TPMVersion=0&PrimaryDiskTotalCapacity=262144&InstallationType=Client&AttrDataVer=186&ProcessorModel=AMD%20Ryzen%205%203500%206-Core%20Processor&IsEdgeWithChromiumInstalled=1&OSVersion=10.0.19045.4046&IsMDMEnrolled=0&ActivationChannel=Retail&FirmwareVersion=A.40&TrendInstalledKey=1&OSArchitecture=AMD64&DefaultUserRegion=244&UpdateManagementGroup=2
US
whitelisted
6768
MoUsoCoreWorker.exe
GET
304
51.124.78.146:443
https://settings-win.data.microsoft.com/settings/v3.0/OneSettings/Client?OSVersionFull=10.0.19045.4046.amd64fre.vb_release.191206-1406&LocalDeviceID=s%3ABAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&FlightRing=Retail&AttrDataVer=186&OSUILocale=en-US&OSSkuId=48&App=WOSC&AppVer=&IsFlightingEnabled=0&TelemetryLevel=1&DeviceFamily=Windows.Desktop
US
whitelisted
468
SIHClient.exe
GET
304
20.165.94.63:443
https://slscr.update.microsoft.com/SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.4046/0?CH=686&L=en-US&P=&PT=0x30&WUA=10.0.19041.3996&MK=DELL&MD=DELL
US
whitelisted
468
SIHClient.exe
GET
200
135.233.95.135:443
https://fe3cr.delivery.mp.microsoft.com/clientwebservice/ping
US
whitelisted
468
SIHClient.exe
GET
200
20.165.94.63:443
https://slscr.update.microsoft.com/sls/ping
US
whitelisted
468
SIHClient.exe
GET
304
20.165.94.63:443
https://slscr.update.microsoft.com/SLS/%7BE7A50285-D08D-499D-9FF8-180FDC2332BC%7D/x64/10.0.19045.4046/0?CH=686&L=en-US&P=&PT=0x30&WUA=10.0.19041.3996&MK=DELL&MD=DELL
US
whitelisted
5780
svchost.exe
GET
200
51.124.78.146:443
https://settings-win.data.microsoft.com/settings/v3.0/WSD/WaaSAssessment?os=Windows&osVer=10.0.19041.1.amd64fre.vb_release.191206-&ring=Retail&sku=48&deviceClass=Windows.Desktop&locale=en-US&deviceId=BAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&FlightRing=Retail&TelemetryLevel=1&HidOverGattReg=C%3A%5CWINDOWS%5CSystem32%5CDriverStore%5CFileRepository%5Chidbthle.inf_amd64_9610b4821fdf82a5%5CMicrosoft.Bluetooth.Profiles.HidOverGatt.dll&AppVer=10.0&ProcessorIdentifier=AMD64%20Family%2023%20Model%201%20Stepping%202&OEMModel=DELL&UpdateOfferedDays=4294967295&ProcessorManufacturer=AuthenticAMD&InstallDate=1661339444&OEMModelBaseBoard=&BranchReadinessLevel=CB&OEMSubModel=J5CR&IsCloudDomainJoined=0&DeferFeatureUpdatePeriodInDays=30&IsDeviceRetailDemo=0&FlightingBranchName=&OSUILocale=en-US&DeviceFamily=Windows.Desktop&WuClientVer=10.0.19041.3996&UninstallActive=1&IsFlightingEnabled=0&OSSkuId=48&ProcessorClockSpeed=3094&TotalPhysicalRAM=6144&SecureBootCapable=0&App=WaaSAssessment&ProcessorCores=6&CurrentBranch=vb_release&InstallLanguage=en-US&DeferQualityUpdatePeriodInDays=0&ServicingBranch=CB&OEMName_Uncleaned=DELL&TPMVersion=0&PrimaryDiskTotalCapacity=262144&InstallationType=Client&AttrDataVer=186&ProcessorModel=AMD%20Ryzen%205%203500%206-Core%20Processor&IsEdgeWithChromiumInstalled=1&OSVersion=10.0.19045.4046&IsMDMEnrolled=0&ActivationChannel=Retail&HonorWUfBDeferrals=0&FirmwareVersion=A.40&TrendInstalledKey=1&OSArchitecture=AMD64&DefaultUserRegion=244&UpdateManagementGroup=2
US
5.70 Kb
whitelisted
5780
svchost.exe
GET
200
2.16.164.120:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
NL
binary
825 b
whitelisted
5780
svchost.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
US
binary
814 b
whitelisted
356
svchost.exe
POST
200
40.126.32.140:443
https://login.live.com/RST2.srf
US
binary
11.1 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
Not routed
whitelisted
5780
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
7236
RUXIMICS.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
6768
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:138
Not routed
whitelisted
5780
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
5780
svchost.exe
2.16.164.120:80
crl.microsoft.com
AKAMAI-ASN1
NL
whitelisted
5780
svchost.exe
88.221.169.152:80
www.microsoft.com
AKAMAI-AS
US
whitelisted
3412
svchost.exe
172.211.123.248:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
6768
MoUsoCoreWorker.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 51.124.78.146
whitelisted
self.events.data.microsoft.com
  • 20.42.73.24
whitelisted
google.com
  • 142.251.37.14
whitelisted
crl.microsoft.com
  • 2.16.164.120
  • 2.16.164.49
whitelisted
www.microsoft.com
  • 88.221.169.152
  • 72.246.29.11
whitelisted
client.wns.windows.com
  • 172.211.123.248
whitelisted
login.live.com
  • 40.126.32.140
  • 40.126.32.134
  • 20.190.160.132
  • 20.190.160.14
  • 20.190.160.67
  • 20.190.160.128
  • 20.190.160.66
  • 20.190.160.3
whitelisted
ocsp.digicert.com
  • 184.30.131.245
whitelisted
slscr.update.microsoft.com
  • 20.165.94.63
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 135.233.95.135
whitelisted

Threats

PID
Process
Class
Message
5780
svchost.exe
Unknown Traffic
ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW)
No debug info