| File name: | SWUpdaterSetup.exe.zip |
| Full analysis: | https://app.any.run/tasks/c24750e8-22cc-453f-b3e9-2f71699babcb |
| Verdict: | Malicious activity |
| Analysis date: | April 20, 2021, 13:21:40 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract |
| MD5: | 35A8428702B610F07CDB3D7EA6DCD09A |
| SHA1: | 9C2AB526D579AF7E263728A8E99E10F8643D922F |
| SHA256: | 1B018C05E31982E0BEFCB5E479A9EDDB17E59A4526291892592CDFF44A5116CA |
| SSDEEP: | 24576:iPcrqUrXCWd1VbUtTTPH9rjwDerk9MSV13ZZSXyOygGSV:e6vd3bGT7drMrpZSiOESV |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipFileName: | SWUpdaterSetup.exe |
|---|---|
| ZipUncompressedSize: | 912232 |
| ZipCompressedSize: | 840058 |
| ZipCRC: | 0xcfb05aa4 |
| ZipModifyDate: | 2021:04:19 13:10:16 |
| ZipCompression: | Deflated |
| ZipBitFlag: | 0x0009 |
| ZipRequiredVersion: | 20 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1704 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\SWUpdaterSetup.exe.zip" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.60.0 Modules
| |||||||||||||||
| 2188 | "C:\Users\admin\AppData\Local\Temp\Rar$EXb1704.25660\SWUpdaterSetup.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXb1704.25660\SWUpdaterSetup.exe | WinRAR.exe | ||||||||||||
User: admin Company: Wavesor Software Integrity Level: MEDIUM Description: Wavesor SWUpdater Setup Exit code: 2147747664 Version: 1.3.107.0 Modules
| |||||||||||||||
| (PID) Process: | (1704) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (1704) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (1704) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\13D\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (1704) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\13D\52C64B7E |
| Operation: | write | Name: | @C:\Windows\system32\NetworkExplorer.dll,-1 |
Value: Network | |||
| (PID) Process: | (1704) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\SWUpdaterSetup.exe.zip | |||
| (PID) Process: | (1704) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (1704) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (1704) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (1704) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (1704) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface |
| Operation: | write | Name: | ShowPassword |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2188 | SWUpdaterSetup.exe | C:\Users\admin\AppData\Local\Temp\GUTF47B.tmp | — | |
MD5:— | SHA256:— | |||
| 1704 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb1704.25660\SWUpdaterSetup.exe | executable | |
MD5:— | SHA256:— | |||
| 2188 | SWUpdaterSetup.exe | C:\Users\admin\AppData\Local\Temp\GUMF47A.tmp\psuser_64.dll | executable | |
MD5:B3546DAD5DF693BD9B9F939EE40ECCC8 | SHA256:4D8D87649AA77047FE5ADD176A1A686F2D274F5B49E0DB1B144B6BC5CD9FD08F | |||
| 2188 | SWUpdaterSetup.exe | C:\Users\admin\AppData\Local\Temp\GUMF47A.tmp\SWUpdaterBroker.exe | executable | |
MD5:503A0CB9637DD685AEACBD219EC778D1 | SHA256:6634888AD7FF974888C8F6DE1D5FE82BFFFE70FB02A21886EF3CF8AF6FABCDC6 | |||
| 2188 | SWUpdaterSetup.exe | C:\Users\admin\AppData\Local\Temp\GUMF47A.tmp\SWUpdaterOnDemand.exe | executable | |
MD5:1D35414DDF16972137822372937F8719 | SHA256:ED8226E9DC79049E69F970E46DADC9EA912C606DC3B51A4EDE5EC1A17599A808 | |||
| 2188 | SWUpdaterSetup.exe | C:\Users\admin\AppData\Local\Temp\GUMF47A.tmp\psmachine.dll | executable | |
MD5:58C1234BA4B59F88A76B8F7B37295748 | SHA256:8AEDD7F006845A63D382B1B86DCA921931AD8E7A813B3ADE92AC193377D0D171 | |||
| 2188 | SWUpdaterSetup.exe | C:\Users\admin\AppData\Local\Temp\GUMF47A.tmp\SWUpdaterComRegisterShell64.exe | executable | |
MD5:B6AC081FFACBEE5F49E120F1443E3B26 | SHA256:BF27695A23C59ACC6602CBA85A0F2B7639FD4924D7AB25B42F44A7C63283869A | |||
| 2188 | SWUpdaterSetup.exe | C:\Users\admin\AppData\Local\Temp\GUMF47A.tmp\psuser.dll | executable | |
MD5:C55AC99DD5FD370D519F3B00811933A9 | SHA256:E4CA4C9ACB3B2C9827380ACAE2714538719D433AE9813A2A91A07C24D2CA6577 | |||
| 2188 | SWUpdaterSetup.exe | C:\Users\admin\AppData\Local\Temp\GUMF47A.tmp\psmachine_64.dll | executable | |
MD5:F322B90E5F98E9B05F24F6F5459FB4ED | SHA256:104631AF23A0222C5AC27194832CFCD5BA672803F94DB7A2B8C17A08794E2FBC | |||
| 2188 | SWUpdaterSetup.exe | C:\Users\admin\AppData\Local\Temp\GUMF47A.tmp\SWUpdaterCrashHandler64.exe | executable | |
MD5:B5030DA2A444884AD543F1FFAB2D5C22 | SHA256:A8B234CDC44C5583A48A07CA0413054CAEDDBEED73200A78B239A93AE6821F70 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 192.168.100.151:137 | — | — | — | malicious |