| File name: | Connectify Hotspot 2015.0.4.34734.rar |
| Full analysis: | https://app.any.run/tasks/d29b0edc-f0e7-44a1-b6e2-53157690adc3 |
| Verdict: | Malicious activity |
| Analysis date: | April 29, 2025, 04:31:55 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-rar |
| File info: | RAR archive data, v2.0, os: Win32, flags: FirstVolume |
| MD5: | 2079F5A8853799D89053DBAD70BCA117 |
| SHA1: | 68231CBB623DB494596E73F41B6D4FB999C9B774 |
| SHA256: | 03337D17D4344D7DE4D26E8CFF02AEC17F8C851B813A4C0C6293D76FFEB53878 |
| SSDEEP: | 98304:r/dUwrSJF8GUby7k7hS0w/yx/EyCooLn65r5wIGZ79fhSBK+CoNoFUsXhGKyW/iW:+FJPg33KNKQjMzaKH6EruLuo |
| .rar | | | RAR compressed archive (v-4.x) (58.3) |
|---|---|---|
| .rar | | | RAR compressed archive (gen) (41.6) |
| FileVersion: | RAR v4 |
|---|---|
| CompressedSize: | 10318821 |
| UncompressedSize: | 10318768 |
| OperatingSystem: | Win32 |
| ModifyDate: | 2015:04:28 09:06:12 |
| PackingMethod: | Stored |
| ArchivedFileName: | Connectify2015Installer.exe |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 700 | "icacls" C:\ProgramData\Connectify /T /Q /C /grant Everyone:(F) | C:\Windows\System32\icacls.exe | — | Connectifyd.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 848 | "C:\Users\admin\AppData\Local\Temp\nsc466C.tmp\ns8003.tmp" C:\Windows\system32\schtasks.exe /delete /TN "ConnectifyInstallerTask" /F | C:\Users\admin\AppData\Local\Temp\nsc466C.tmp\ns8003.tmp | — | Connectify2015Installer.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 1 Modules
| |||||||||||||||
| 872 | "C:\Users\admin\AppData\Local\Temp\Connectify\5\ConnectifyShutdown" | C:\Users\admin\AppData\Local\Temp\Connectify\5\ConnectifyShutdown.exe | — | ns6C88.tmp | |||||||||||
User: admin Company: Connectify Integrity Level: HIGH Description: Connectify Shutdown App Exit code: 0 Version: 2015.0.5.34877 Modules
| |||||||||||||||
| 984 | "C:\Users\admin\AppData\Local\Temp\nsc466C.tmp\ns6467.tmp" "C:\Users\admin\AppData\Local\Temp\Connectify\5\GlobalAtomTable.exe" Check Connectify | C:\Users\admin\AppData\Local\Temp\nsc466C.tmp\ns6467.tmp | — | Connectify2015Installer.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 1032 | "C:\Users\admin\AppData\Local\Temp\nsc466C.tmp\nsDD0B.tmp" "C:\Users\admin\AppData\Local\Temp\Connectify\5\GlobalAtomTable.exe" Set Connectify | C:\Users\admin\AppData\Local\Temp\nsc466C.tmp\nsDD0B.tmp | — | Connectify2015Installer.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 2 Modules
| |||||||||||||||
| 1124 | "Exes\i386\snetcfg.exe" -v -u nt_cnnctfy2 | C:\Users\admin\AppData\Local\Temp\Connectify\DriverSwitcher\976\Exes\i386\snetcfg.exe | — | DriverSwitcher.exe | |||||||||||
User: admin Company: Windows (R) Win 7 DDK provider Integrity Level: HIGH Description: network config sample Exit code: 1 Version: 6.1.7600.16385 built by: WinDDK Modules
| |||||||||||||||
| 1404 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa2448.44073\Connectify2015Installer.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa2448.44073\Connectify2015Installer.exe | WinRAR.exe | ||||||||||||
User: admin Company: Connectify Integrity Level: MEDIUM Description: Connectify 2015 Exit code: 1223 Version: 2015.0.5.34877 Modules
| |||||||||||||||
| 1460 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa2448.44073\Connectify2015Installer.exe" /UAC:40182 /NCRC | C:\Users\admin\AppData\Local\Temp\Rar$EXa2448.44073\Connectify2015Installer.exe | Connectify2015Installer.exe | ||||||||||||
User: admin Company: Connectify Integrity Level: HIGH Description: Connectify 2015 Exit code: 1223 Version: 2015.0.5.34877 Modules
| |||||||||||||||
| 1628 | "C:\Users\admin\AppData\Local\Temp\Connectify\5\GlobalAtomTable.exe" Set Connectify | C:\Users\admin\AppData\Local\Temp\Connectify\5\GlobalAtomTable.exe | — | nsDB35.tmp | |||||||||||
User: admin Company: Connectify Integrity Level: HIGH Exit code: 0 Version: 2015.0.5.34877 Modules
| |||||||||||||||
| 1632 | "C:\Program Files\Connectify\ConnectifyService.exe" | C:\Program Files\Connectify\ConnectifyService.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Connectify Integrity Level: SYSTEM Version: 2015.0.5.34877 Modules
| |||||||||||||||
| (PID) Process: | (2448) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (2448) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip | |||
| (PID) Process: | (2448) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\omni_23_10_2024_.zip | |||
| (PID) Process: | (2448) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\Connectify Hotspot 2015.0.4.34734.rar | |||
| (PID) Process: | (2448) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (2448) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (2448) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (2448) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (2448) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (2448) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1460 | Connectify2015Installer.exe | C:\Users\admin\AppData\Local\Temp\Connectify\5\Analytics.exe | executable | |
MD5:E940D9CBB97A254946B7DEBCD64EA258 | SHA256:F1E94BE7CB362B7D5F2BD5DEDB732187F19B4EA1278B41911ED6439F27B285E6 | |||
| 1404 | Connectify2015Installer.exe | C:\Users\admin\AppData\Local\Temp\nsi3B60.tmp\modern-header.bmp | image | |
MD5:F50B6CEE1BE90D50AF582E57528C7000 | SHA256:E83DC2CA1239E62D979C02CA8A8B394573BF50C650AAF4D38799E97D618FECA4 | |||
| 1460 | Connectify2015Installer.exe | C:\Users\admin\AppData\Local\Temp\nsc466C.tmp\modern-wizard.bmp | image | |
MD5:AE43624C14859150EDFB54B4024AFF46 | SHA256:D5B56046F10941E6659277D46FFD4A0D327DB24BE3174D6A8E7AE0660DA874E9 | |||
| 1404 | Connectify2015Installer.exe | C:\Users\admin\AppData\Local\Temp\nsi3B60.tmp\System.dll | executable | |
MD5:C17103AE9072A06DA581DEC998343FC1 | SHA256:DC58D8AD81CACB0C1ED72E33BFF8F23EA40B5252B5BB55D393A0903E6819AE2F | |||
| 1404 | Connectify2015Installer.exe | C:\Users\admin\AppData\Local\Temp\nsi3B60.tmp\UAC.dll | executable | |
MD5:7F56C0D6A8733DEC142814ED5A58B0EE | SHA256:86445396775370AFF5834F10BDA25E505B6F89EFC69A04FE1CE46F5D128BE73F | |||
| 1460 | Connectify2015Installer.exe | C:\Users\admin\AppData\Local\Temp\nsc466C.tmp\modern-header.bmp | image | |
MD5:F50B6CEE1BE90D50AF582E57528C7000 | SHA256:E83DC2CA1239E62D979C02CA8A8B394573BF50C650AAF4D38799E97D618FECA4 | |||
| 1460 | Connectify2015Installer.exe | C:\Users\admin\AppData\Local\Temp\nsc466C.tmp\System.dll | executable | |
MD5:C17103AE9072A06DA581DEC998343FC1 | SHA256:DC58D8AD81CACB0C1ED72E33BFF8F23EA40B5252B5BB55D393A0903E6819AE2F | |||
| 1460 | Connectify2015Installer.exe | C:\Users\admin\AppData\Local\Temp\nsc466C.tmp\md5dll.dll | executable | |
MD5:7059F133EA2316B9E7E39094A52A8C34 | SHA256:32C3D36F38E7E8A8BAFD4A53663203EF24A10431BDA16AF9E353C7D5D108610F | |||
| 1460 | Connectify2015Installer.exe | C:\Users\admin\AppData\Local\Temp\nsc466C.tmp\UAC.dll | executable | |
MD5:7F56C0D6A8733DEC142814ED5A58B0EE | SHA256:86445396775370AFF5834F10BDA25E505B6F89EFC69A04FE1CE46F5D128BE73F | |||
| 1460 | Connectify2015Installer.exe | C:\Users\admin\AppData\Local\Temp\Connectify\5\Connectify.exe | executable | |
MD5:CAA085B96AD81F2370A9ED4E1E4B8380 | SHA256:A74A5AF7EFEA32714787279D1090679E2FF174F7C3903E07722534BAB3F570CE | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2532 | Analytics.exe | GET | 200 | 142.250.184.238:80 | http://www.google-analytics.com/__utm.gif?utmwv=4.4sa&utmn=1927071427&utmhn=connectify.connectify.me&utmp=Installer%2fInit%2f2015.0.5.34877%2fNone&utmac=UA-742036-6&utmcc=__utma%3D999.1953585644.999.999.999111111111111.1%3B%2B__utmz%3D999.999.999.999.utmcsr%3Ddispatch_%7Cutmccn%3D(referral)%7Cutmcmd%3Dreferral%7Cutmcct%3DInstaller%2fInit%2f2015.0.5.34877%2fNone%3B&utmul=en&utmdebug=ON | unknown | — | — | whitelisted |
3752 | Analytics.exe | GET | 200 | 142.250.184.238:80 | http://www.google-analytics.com/__utm.gif?utmwv=4.4sa&utmn=402600594&utmhn=connectify.connectify.me&utmp=Installer%2fStart%2f2015.0.5.34877%2fNone&utmac=UA-742036-6&utmcc=__utma%3D999.1953585644.999.999.999111111111111.1%3B%2B__utmz%3D999.999.999.999.utmcsr%3Ddispatch_%7Cutmccn%3D(referral)%7Cutmcmd%3Dreferral%7Cutmcct%3DInstaller%2fStart%2f2015.0.5.34877%2fNone%3B&utmul=en&utmdebug=ON | unknown | — | — | whitelisted |
1980 | Analytics.exe | GET | 200 | 142.250.184.238:80 | http://www.google-analytics.com/__utm.gif?utmwv=4.4sa&utmn=609938169&utmhn=connectify.connectify.me&utmp=Installer%2fSuccess%2f2015.0.5.34877%2fNone&utmac=UA-742036-6&utmcc=__utma%3D999.1953585644.999.999.999111111111111.1%3B%2B__utmz%3D999.999.999.999.utmcsr%3Ddispatch_%7Cutmccn%3D(referral)%7Cutmcmd%3Dreferral%7Cutmcct%3DInstaller%2fSuccess%2f2015.0.5.34877%2fNone%3B&utmul=en&utmdebug=ON | unknown | — | — | whitelisted |
2840 | Analytics.exe | GET | 200 | 142.250.184.238:80 | http://www.google-analytics.com/__utm.gif?utmwv=4.4sa&utmn=431537628&utmhn=connectify.connectify.me&utmp=Installer%2fDriver%2fReboot%2f2015.0.5.34877%2fNone&utmac=UA-742036-6&utmcc=__utma%3D999.1953585644.999.999.999111111111111.1%3B%2B__utmz%3D999.999.999.999.utmcsr%3Ddispatch_%7Cutmccn%3D(referral)%7Cutmcmd%3Dreferral%7Cutmcct%3DInstaller%2fDriver%2fReboot%2f2015.0.5.34877%2fNone%3B&utmul=en&utmdebug=ON | unknown | — | — | whitelisted |
2164 | sipnotify.exe | HEAD | 503 | 104.102.43.250:80 | http://query.prod.cms.rt.microsoft.com/cms/api/am/binary/RE2JgkA?v=133903785778750000 | unknown | — | — | whitelisted |
1704 | Connectifyd.exe | GET | 301 | 104.22.77.194:80 | http://updates.connectify.me/settings.php?cnnctfy=1&v=2015.0.5.34877&maj=2015&min=0&bug=5&rev=34877&osPlatform=win7&osServicePack=1.0&osVersion=6.1.7601.65536&d=0&ref=dispatch_&uuid=58F6227FDE8204EC47EA96D8899BE4E3&machName=USER-PC&l=1&ls=2&e=0&disL=1&disLs=2&disE=0 | unknown | — | — | whitelisted |
1704 | Connectifyd.exe | GET | 301 | 104.22.77.194:80 | http://updates.connectify.me/dialerkeys.php?cnnctfy=1&v=2015.0.5.34877&maj=2015&min=0&bug=5&rev=34877&osPlatform=win7&osServicePack=1.0&osVersion=6.1.7601.65536&d=0&ref=dispatch_&uuid=58F6227FDE8204EC47EA96D8899BE4E3&machName=USER-PC&l=1&ls=2&e=0&disL=1&disLs=2&disE=0 | unknown | — | — | whitelisted |
2552 | Connectify.exe | GET | 200 | 52.216.42.165:80 | http://data.connectify.me/driver.dat | unknown | — | — | whitelisted |
1704 | Connectifyd.exe | GET | 200 | 142.250.186.174:80 | http://www.google-analytics.com/__utm.gif?utmwv=4.4sa&utmn=1558101917&utmhn=connectify.connectify.me&utmt=event&utme=5(UI*Tab*Settings)&utmac=UA-742036-9&utmcc=__utma%3D999.1953585644.999.999.999.1%3B%2B__utmz%3D999.999.999.999.utmcsr%3Ddispatch_%7Cutmccn%3D(referral)%7Cutmcmd%3Dreferral%7Cutmcct%3DUI%2fTab%2fSettings%3B&utmul=en&utmdebug=ON | unknown | — | — | whitelisted |
1704 | Connectifyd.exe | GET | 200 | 142.250.186.174:80 | http://www.google-analytics.com/__utm.gif?utmwv=4.4sa&utmn=1558101917&utmhn=connectify.connectify.me&utmt=event&utme=5(UI*Tab*Settings)&utmac=UA-742036-9&utmcc=__utma%3D999.1953585644.999.999.999.1%3B%2B__utmz%3D999.999.999.999.utmcsr%3Ddispatch_%7Cutmccn%3D(referral)%7Cutmcmd%3Dreferral%7Cutmcct%3DUI%2fTab%2fSettings%3B&utmul=en&utmdebug=ON | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 224.0.0.252:5355 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
2532 | Analytics.exe | 142.250.184.238:80 | www.google-analytics.com | GOOGLE | US | whitelisted |
3752 | Analytics.exe | 142.250.184.238:80 | www.google-analytics.com | GOOGLE | US | whitelisted |
2840 | Analytics.exe | 142.250.184.238:80 | www.google-analytics.com | GOOGLE | US | whitelisted |
1980 | Analytics.exe | 142.250.184.238:80 | www.google-analytics.com | GOOGLE | US | whitelisted |
1152 | svchost.exe | 224.0.0.252:5355 | — | — | — | whitelisted |
1484 | svchost.exe | 239.255.255.250:3702 | — | — | — | whitelisted |
Domain | IP | Reputation |
|---|---|---|
google.com |
| whitelisted |
www.google-analytics.com |
| whitelisted |
updates.connectify.me |
| whitelisted |
query.prod.cms.rt.microsoft.com |
| whitelisted |
data.connectify.me |
| whitelisted |
d1.connectify.me |
| whitelisted |
ctldl.windowsupdate.com |
| whitelisted |
news.connectify.me |
| whitelisted |
c.pki.goog |
| whitelisted |