: Look for variations of Rar$Scan[Number].bat .
Malware analysis ibso9p0sjp44crzm.7z Malicious activity | ANY.RUN 20882 rar
: WinRAR.exe spawning cmd.exe to run .bat scripts from temporary folders. : Look for variations of Rar$Scan[Number]
: The analysis shows a file named Rar$Scan19941.bat being launched from the 20882 directory via cmd.exe . 20882 rar