| File name: | Private exe Protector 5.0.0.5 Cracked by PCR KerBer.rar |
| Full analysis: | https://app.any.run/tasks/f45369d9-1c4c-4b1e-9d81-54b28f327c78 |
| Verdict: | Malicious activity |
| Analysis date: | September 07, 2018, 05:12:51 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-rar |
| File info: | RAR archive data, v4, os: Win32 |
| MD5: | 5138F767B3C48D5B171C901EC3B37475 |
| SHA1: | 3F42F48CA2EF968137F03CC7A8879A0CDE6719F1 |
| SHA256: | 1AF446161CD3873F212DDADB827A76B54E64FDD8A9D90A64C50110B4C6687D0D |
| SSDEEP: | 49152:ZhQTsM0t27VZqv4XxuC4ihFO2PgkXWUk+V5EswG4Wy:gIr2av4Bth8eg7UkYEs14z |
| .rar | | | RAR compressed archive (v-4.x) (58.3) |
|---|---|---|
| .rar | | | RAR compressed archive (gen) (41.6) |
| CompressedSize: | 55 |
|---|---|
| UncompressedSize: | - |
| OperatingSystem: | Win32 |
| ModifyDate: | 2015:08:15 06:39:27 |
| PackingMethod: | Stored |
| ArchivedFileName: | Private exe Protector 5.0.0.5 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 128 | "C:\Users\admin\Desktop\Private exe Protector 5.0.0.5\LicenseActivationCenter.exe" | C:\Users\admin\Desktop\Private exe Protector 5.0.0.5\LicenseActivationCenter.exe | — | Private exe Protector.exe | |||||||||||
User: admin Company: SetiSoft (c) Tech Integrity Level: MEDIUM Description: License Activation Center Exit code: 0 Version: 1.0.0.50108 Modules
| |||||||||||||||
| 1064 | "C:\Users\admin\Desktop\Private exe Protector 5.0.0.5\Private exe Protector.exe" | C:\Users\admin\Desktop\Private exe Protector 5.0.0.5\Private exe Protector.exe | — | explorer.exe | |||||||||||
User: admin Company: SetiSoft (c) Tech Integrity Level: MEDIUM Description: Private exe Protector Exit code: 0 Version: 5.0.0.5 Modules
| |||||||||||||||
| 1544 | "C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe12_ Global\UsGthrCtrlFltPipeMssGthrPipe12 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" | C:\Windows\System32\SearchProtocolHost.exe | — | SearchIndexer.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft Windows Search Protocol Host Exit code: 0 Version: 7.00.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1932 | "C:\Users\admin\Desktop\123.exe" | C:\Users\admin\Desktop\123.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 2440 | "C:\Users\admin\Desktop\Private exe Protector 5.0.0.5\LicenseActivationCenter.exe" | C:\Users\admin\Desktop\Private exe Protector 5.0.0.5\LicenseActivationCenter.exe | — | Private exe Protector.exe | |||||||||||
User: admin Company: SetiSoft (c) Tech Integrity Level: MEDIUM Description: License Activation Center Exit code: 0 Version: 1.0.0.50108 Modules
| |||||||||||||||
| 2652 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\Private exe Protector 5.0.0.5 Cracked by PCR KerBer.rar" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.60.0 Modules
| |||||||||||||||
| 3036 | "C:\Users\admin\Desktop\Private exe Protector 5.0.0.5\LicenseActivationCenter.exe" | C:\Users\admin\Desktop\Private exe Protector 5.0.0.5\LicenseActivationCenter.exe | — | explorer.exe | |||||||||||
User: admin Company: SetiSoft (c) Tech Integrity Level: MEDIUM Description: License Activation Center Exit code: 0 Version: 1.0.0.50108 Modules
| |||||||||||||||
| 3108 | "C:\Users\admin\Desktop\Private exe Protector 5.0.0.5\ppibuilder.exe" "C:\Users\admin\Desktop\123.exe" | C:\Users\admin\Desktop\Private exe Protector 5.0.0.5\ppibuilder.exe | Private exe Protector.exe | ||||||||||||
User: admin Company: The UPX Team http://upx.sf.net Integrity Level: MEDIUM Description: UPX executable packer Exit code: 0 Version: 3.91 (2013-09-30) Modules
| |||||||||||||||
| 3568 | "C:\Users\admin\Desktop\Private exe Protector 5.0.0.5\ppibuilder.exe" | C:\Users\admin\Desktop\Private exe Protector 5.0.0.5\ppibuilder.exe | — | explorer.exe | |||||||||||
User: admin Company: The UPX Team http://upx.sf.net Integrity Level: MEDIUM Description: UPX executable packer Exit code: 1 Version: 3.91 (2013-09-30) Modules
| |||||||||||||||
| (PID) Process: | (2652) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (2652) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (2652) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\59\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2652) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop\Private exe Protector 5.0.0.5 Cracked by PCR KerBer.rar | |||
| (PID) Process: | (2652) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (2652) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (2652) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (2652) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (2652) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface |
| Operation: | write | Name: | ShowPassword |
Value: 0 | |||
| (PID) Process: | (2652) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin |
| Operation: | write | Name: | Placement |
Value: 2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF2C0000002C000000EC03000021020000 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2652 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb2652.37500\123.exe | — | |
MD5:— | SHA256:— | |||
| 3036 | LicenseActivationCenter.exe | C:\Users\admin\Desktop\Private exe Protector 5.0.0.5\lac.db-journal | — | |
MD5:— | SHA256:— | |||
| 2440 | LicenseActivationCenter.exe | C:\Users\admin\Desktop\Private exe Protector 5.0.0.5\lac.db-journal | — | |
MD5:— | SHA256:— | |||
| 2440 | LicenseActivationCenter.exe | C:\Users\admin\AppData\Roaming\Private exe Protector\lac.config | xml | |
MD5:— | SHA256:— | |||
| 128 | LicenseActivationCenter.exe | C:\Users\admin\Desktop\Private exe Protector 5.0.0.5\lac.db-journal | — | |
MD5:— | SHA256:— | |||
| 2652 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb2652.37500\Private exe Protector 5.0.0.5\LicenseActivationCenter.exe.config | xml | |
MD5:33185AD9ACBD5E1620DE966E09E28580 | SHA256:9414EF32EB25EFF3D9DB0BBF3B75F951838088D09D0CD0FD608ED8FAEA59431C | |||
| 2440 | LicenseActivationCenter.exe | C:\Users\admin\Desktop\Private exe Protector 5.0.0.5\lac.db | sqlite | |
MD5:— | SHA256:— | |||
| 3036 | LicenseActivationCenter.exe | C:\Users\admin\AppData\Roaming\Private exe Protector\lac.config | xml | |
MD5:— | SHA256:— | |||
| 3108 | ppibuilder.exe | C:\Users\admin\Desktop\123.upx | — | |
MD5:— | SHA256:— | |||
| 3036 | LicenseActivationCenter.exe | C:\Users\admin\Desktop\Private exe Protector 5.0.0.5\lac.db | sqlite | |
MD5:— | SHA256:— | |||