File name:

WinRuler.zip

Full analysis: https://app.any.run/tasks/8910435b-8059-4b53-90c7-a925436fbf22
Verdict: Suspicious activity
Analysis date: September 10, 2018, 16:15:44
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

25C2015AAF2601880D33759FCE776315

SHA1:

557638B8F5C51A5279CBA7932312DE6BAF9CEC08

SHA256:

F43A0407942A9FE8EF2D3CE151C101A8E81EE7A02CDE581502B7F065A4F33D30

SSDEEP:

12288:IOn4yLihBw0Ev1jtH894xu5DlE2NERP0uAIxJo6mmoqovRn:IOhABwxH84u8JNo6meox

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • WinRuler.exe (PID: 1072)
    • Application was dropped or rewritten from another process

      • WinRuler.exe (PID: 1072)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2412)
      • WinRuler.exe (PID: 1072)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: 0x0002
ZipCompression: Deflated
ZipModifyDate: 2010:03:15 21:31:24
ZipCRC: 0x19e936fc
ZipCompressedSize: 668426
ZipUncompressedSize: 976831
ZipFileName: WinRuler.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
33
Monitored processes
2
Malicious processes
1
Suspicious processes
1

Behavior graph

Click at the process to see the details
drop and start start winrar.exe winruler.exe

Process information

PID
CMD
Path
Indicators
Parent process
1072"C:\Users\admin\AppData\Local\Temp\Rar$EXa2412.36852\WinRuler.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa2412.36852\WinRuler.exe
WinRAR.exe
User:
admin
Company:
Kummailil
Integrity Level:
MEDIUM
Description:
A semitransparent on-screen ruler
Exit code:
0
Version:
2.2.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2412.36852\winruler.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
2412"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\WinRuler.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
Total events
758
Read events
746
Write events
12
Delete events
0

Modification events

(PID) Process:(2412) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2412) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2412) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2412) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\WinRuler.zip
(PID) Process:(2412) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2412) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2412) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2412) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2412) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(2412) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
Executable files
5
Suspicious files
0
Text files
2
Unknown types
0

Dropped files

PID
Process
Filename
Type
2412WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2412.36852\WinRuler.exeexecutable
MD5:
SHA256:
1072WinRuler.exeC:\Users\admin\AppData\Local\Temp\nsw130A.tmp\StartMenu.dllexecutable
MD5:4E96F412A8CC653053D5D918DF6B0836
SHA256:E4A54BFC327986A89165BDEF361069810AAA985C3ABECD442C786725FABAF977
1072WinRuler.exeC:\Users\admin\AppData\Local\Temp\nsw130A.tmp\modern-wizard.bmpimage
MD5:CBE40FD2B1EC96DAEDC65DA172D90022
SHA256:3AD2DC318056D0A2024AF1804EA741146CFC18CC404649A44610CBF8B2056CF2
1072WinRuler.exeC:\Users\admin\AppData\Local\Temp\nsw130A.tmp\UserInfo.dllexecutable
MD5:1E8E11F465AFDABE97F529705786B368
SHA256:7D099352C82612AB27DDFD7310C1AA049B58128FB04EA6EA55816A40A6F6487B
1072WinRuler.exeC:\Users\admin\AppData\Local\Temp\nsw130A.tmp\nsDialogs.dllexecutable
MD5:AB73C0C2A23F913EABDC4CB24B75CBAD
SHA256:3D0060C5C9400A487DBEFE4AC132DD96B07D3A4BA3BADAB46A7410A667C93457
1072WinRuler.exeC:\Users\admin\AppData\Local\Temp\nsw130A.tmp\System.dllexecutable
MD5:00A0194C20EE912257DF53BFE258EE4A
SHA256:DC4DA2CCADB11099076926B02764B2B44AD8F97CD32337421A4CC21A3F5448F3
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info