File name:

Win 10 Tweaker 15.2 Pro-RSLOAD.NET-.zip

Full analysis: https://app.any.run/tasks/c0b7819b-7742-4186-844c-82d643b22ab2
Verdict: Malicious activity
Analysis date: November 16, 2019, 22:20:44
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

F03B189A54332A0A3FF9C3D06FF73D42

SHA1:

E220ADC35F1991266665C7ECB83455698236A024

SHA256:

19CA365A1DB3A7DADB58D705841E45401FB1C92BE99958ABD394B258891716FE

SSDEEP:

49152:4IoifIqVMtnLGL5BK5NA39o+4Vdx/yFmi597c2Hi27lsFVUDzNx0aaBA5FEXgmy:JoifPVM8BkONoryFmi5eEmFVUP70akfc

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Repair Win 10 Tweaker v5.0.exe (PID: 1856)
      • Repair Win 10 Tweaker v5.0.exe (PID: 3508)
      • Win 10 Tweaker 14.3.exe (PID: 3932)
      • Win 10 Tweaker 14.3.exe (PID: 3264)
    • Loads dropped or rewritten executable

      • SearchProtocolHost.exe (PID: 3488)
      • Repair Win 10 Tweaker v5.0.exe (PID: 3508)
    • Uses Task Scheduler to run other applications

      • cmd.exe (PID: 956)
      • cmd.exe (PID: 1504)
    • Loads the Task Scheduler COM API

      • schtasks.exe (PID: 2788)
      • schtasks.exe (PID: 3848)
  • SUSPICIOUS

    • Low-level read access rights to disk partition

      • Repair Win 10 Tweaker v5.0.exe (PID: 3508)
    • Executable content was dropped or overwritten

      • Repair Win 10 Tweaker v5.0.exe (PID: 3508)
      • WinRAR.exe (PID: 2160)
    • Starts CMD.EXE for commands execution

      • Repair Win 10 Tweaker v5.0.exe (PID: 3508)
      • Win 10 Tweaker 14.3.exe (PID: 3932)
    • Starts CMD.EXE for self-deleting

      • Repair Win 10 Tweaker v5.0.exe (PID: 3508)
    • Reads Environment values

      • Win 10 Tweaker 14.3.exe (PID: 3932)
    • Starts application with an unusual extension

      • cmd.exe (PID: 956)
      • cmd.exe (PID: 1504)
    • Reads CPU info

      • Win 10 Tweaker 14.3.exe (PID: 3932)
    • Executes PowerShell scripts

      • Win 10 Tweaker 14.3.exe (PID: 3932)
    • Reads mouse settings

      • Win 10 Tweaker 14.3.exe (PID: 3932)
    • Uses NETSH.EXE for network configuration

      • cmd.exe (PID: 3116)
    • Creates files in the user directory

      • powershell.exe (PID: 324)
    • Uses ATTRIB.EXE to modify file attributes

      • cmd.exe (PID: 3768)
    • Uses TASKKILL.EXE to kill process

      • cmd.exe (PID: 2552)
  • INFO

    • Manual execution by user

      • Repair Win 10 Tweaker v5.0.exe (PID: 1856)
      • NOTEPAD.EXE (PID: 2588)
      • Repair Win 10 Tweaker v5.0.exe (PID: 3508)
      • Win 10 Tweaker 14.3.exe (PID: 3264)
      • Win 10 Tweaker 14.3.exe (PID: 3932)
    • Reads the hosts file

      • Win 10 Tweaker 14.3.exe (PID: 3932)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2019:05:28 15:26:11
ZipCRC: 0xb44ac292
ZipCompressedSize: 274705
ZipUncompressedSize: 302592
ZipFileName: Repair Win 10 Tweaker v5.0.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
73
Monitored processes
22
Malicious processes
3
Suspicious processes
2

Behavior graph

Click at the process to see the details
start winrar.exe notepad.exe no specs repair win 10 tweaker v5.0.exe no specs repair win 10 tweaker v5.0.exe searchprotocolhost.exe no specs regini.exe no specs cmd.exe no specs timeout.exe no specs win 10 tweaker 14.3.exe no specs win 10 tweaker 14.3.exe cmd.exe no specs chcp.com no specs powershell.exe no specs schtasks.exe no specs cmd.exe no specs chcp.com no specs schtasks.exe no specs cmd.exe no specs netsh.exe no specs attrib.exe no specs cmd.exe no specs taskkill.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
324"powershell" -command Get-PhysicalDisk | select FriendlyName,MediaTypeC:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeWin 10 Tweaker 14.3.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows PowerShell
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\atl.dll
c:\windows\system32\user32.dll
956"cmd.exe" /c chcp 65001 & schtasks /TN \Microsoft\Windows\Maintenance\WinSATC:\Windows\system32\cmd.exeWin 10 Tweaker 14.3.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
1
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1012chcp 65001 C:\Windows\system32\chcp.comcmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Change CodePage Utility
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\chcp.com
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ulib.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1504"cmd.exe" /c chcp 65001 & schtasks /TN \Microsoft\Windows\MemoryDiagnostic\CorruptionDetectorC:\Windows\system32\cmd.exeWin 10 Tweaker 14.3.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
1
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\lpk.dll
1856"C:\Users\admin\Desktop\Repair Win 10 Tweaker v5.0.exe" C:\Users\admin\Desktop\Repair Win 10 Tweaker v5.0.exeexplorer.exe
User:
admin
Company:
JailbaitVideo
Integrity Level:
MEDIUM
Description:
Repair Win 10 Tweaker
Exit code:
3221226540
Version:
5.00
Modules
Images
c:\users\admin\desktop\repair win 10 tweaker v5.0.exe
c:\systemroot\system32\ntdll.dll
1928chcp 65001 C:\Windows\system32\chcp.comcmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Change CodePage Utility
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\chcp.com
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ulib.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2160"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Win 10 Tweaker 15.2 Pro-RSLOAD.NET-.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2352taskkill /f /pid "3932"C:\Windows\system32\taskkill.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Terminates Processes
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskkill.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
2552"C:\Windows\System32\cmd.exe" /c taskkill /f /pid "3932"C:\Windows\System32\cmd.exeWin 10 Tweaker 14.3.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2588"C:\Windows\system32\NOTEPAD.EXE" C:\Users\admin\Desktop\Читать.txtC:\Windows\system32\NOTEPAD.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\notepad.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
Total events
6 479
Read events
6 252
Write events
226
Delete events
1

Modification events

(PID) Process:(2160) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2160) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2160) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2160) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Win 10 Tweaker 15.2 Pro-RSLOAD.NET-.zip
(PID) Process:(2160) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2160) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2160) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2160) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3488) SearchProtocolHost.exeKey:HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\12B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3488) SearchProtocolHost.exeKey:HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\12B\52C64B7E
Operation:writeName:@C:\Windows\system32\notepad.exe,-469
Value:
Text Document
Executable files
7
Suspicious files
4
Text files
4
Unknown types
0

Dropped files

PID
Process
Filename
Type
3508Repair Win 10 Tweaker v5.0.exeC:\Users\admin\AppData\Local\Temp\song.xm
MD5:
SHA256:
324powershell.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\KPQ53JC4PG19FGR1M66U.temp
MD5:
SHA256:
2160WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2160.37373\Repair Win 10 Tweaker v5.0.exeexecutable
MD5:
SHA256:
2160WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2160.37373\W10T.KeyGen.DBF.exeexecutable
MD5:
SHA256:
2160WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2160.37373\Читать.txttext
MD5:
SHA256:
2160WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2160.37373\Win 10 Tweaker\Win 10 Tweaker 14.3.exeexecutable
MD5:
SHA256:
2160WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2160.37373\Win 10 Tweaker\Win 10 Tweaker 13.0.exeexecutable
MD5:
SHA256:
2160WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2160.37373\Win 10 Tweaker\Win 10 Tweaker 12.4.exeexecutable
MD5:
SHA256:
3508Repair Win 10 Tweaker v5.0.exeC:\Users\admin\AppData\Local\Temp\res.txttext
MD5:
SHA256:
324powershell.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms~RF3a4b57.TMPbinary
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info