File name:

VB Decompiler Pro Crack.rar

Full analysis: https://app.any.run/tasks/35f1aebc-febf-4233-b2bb-16eb080ed79b
Verdict: Malicious activity
Analysis date: February 07, 2022, 12:19:16
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v4, os: Win32
MD5:

38AA4541D097F58A083E98BB906079C8

SHA1:

831273E820EEC369DB5292086AC7B918EBEEA028

SHA256:

1B93582627643FC62605862FD0DB4AD1BD015CA656AECD895E76476EBF2CA271

SSDEEP:

196608:1TchAsYeBrLnjxRT6r/xAWEdMt6CMiWIwT+qog:1Tch3pbjxNMAWml+wT+Q

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • VB Decompiler Portable.exe (PID: 2044)
    • Loads dropped or rewritten executable

      • VB Decompiler Portable.exe (PID: 2044)
  • SUSPICIOUS

    • Reads the computer name

      • WinRAR.exe (PID: 3628)
      • VB Decompiler Portable.exe (PID: 2044)
    • Checks supported languages

      • WinRAR.exe (PID: 3628)
      • VB Decompiler Portable.exe (PID: 2044)
    • Drops a file that was compiled in debug mode

      • WinRAR.exe (PID: 3628)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3628)
    • Drops a file with too old compile date

      • WinRAR.exe (PID: 3628)
  • INFO

    • Manual execution by user

      • VB Decompiler Portable.exe (PID: 2044)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v-4.x) (58.3)
.rar | RAR compressed archive (gen) (41.6)

EXIF

ZIP

ArchivedFileName: VB.Decompiler.Pro. Portable\colors\help.ini
PackingMethod: Stored
ModifyDate: 2006:03:05 16:53:21
OperatingSystem: Win32
UncompressedSize: 197
CompressedSize: 261
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
37
Monitored processes
2
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe vb decompiler portable.exe

Process information

PID
CMD
Path
Indicators
Parent process
2044"C:\Users\admin\AppData\Local\Temp\VB Decompiler Pro Crack\VB.Decompiler.Pro. Portable\VB Decompiler Portable.exe" C:\Users\admin\AppData\Local\Temp\VB Decompiler Pro Crack\VB.Decompiler.Pro. Portable\VB Decompiler Portable.exe
Explorer.EXE
User:
admin
Company:
DotFix Software
Integrity Level:
MEDIUM
Description:
Decompiler for p-code and native code files
Exit code:
0
Version:
10.1.0.0
Modules
Images
c:\windows\system32\ntdll.dll
c:\users\admin\appdata\local\temp\vb decompiler pro crack\vb.decompiler.pro. portable\vb decompiler portable.exe
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3628"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\VB Decompiler Pro Crack.rar"C:\Program Files\WinRAR\WinRAR.exe
Explorer.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
Total events
1 121
Read events
1 078
Write events
43
Delete events
0

Modification events

(PID) Process:(3628) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3628) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3628) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3628) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(3628) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(3628) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\VB Decompiler Pro Crack.rar
(PID) Process:(3628) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3628) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3628) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3628) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
Executable files
15
Suspicious files
4
Text files
45
Unknown types
11

Dropped files

PID
Process
Filename
Type
3628WinRAR.exeC:\Users\admin\AppData\Local\Temp\VB Decompiler Pro Crack\VB.Decompiler.Pro. Portable\Help_de.chmchm
MD5:19C251FE00C6CD3BA4C5902B2C14CEF4
SHA256:CEE905D31329F5DF426411E9623BD9FDFAF41A80C3E0C3D6D407FFB1712A4A55
3628WinRAR.exeC:\Users\admin\AppData\Local\Temp\VB Decompiler Pro Crack\VB.Decompiler.Pro. Portable\colors\hiew.iniini
MD5:993E16F8AB6E4A727D8A90BCC52C3FD1
SHA256:78DE9880FB19386F8DF09C5790E4432F3CC352EA43ED1CEA1F04F25576A43223
3628WinRAR.exeC:\Users\admin\AppData\Local\Temp\VB Decompiler Pro Crack\VB.Decompiler.Pro. Portable\Help_eng.chmchm
MD5:B02A889E9CF85DC376EC9DB7FE4D7471
SHA256:1E765458FED1A8D6EEA0FFF5EAC5C725EEA9D6EBE5848C2145E5C55A4E56CB77
3628WinRAR.exeC:\Users\admin\AppData\Local\Temp\VB Decompiler Pro Crack\VB.Decompiler.Pro. Portable\colors\help.iniini
MD5:B0FA941304BCE4085167C39418A78200
SHA256:9C6DE245A8289ED641ED39DA6CA4AE5B358C5EDBE9FA1BBED007EFB8E8EF77BF
3628WinRAR.exeC:\Users\admin\AppData\Local\Temp\VB Decompiler Pro Crack\VB.Decompiler.Pro. Portable\Help_chs.chmchm
MD5:E9B57E0D8BF8A1C1950DD8EEBDDF7F66
SHA256:2F271A6736C9226AC2DDB0E8D552D5EB06EF33CEBFEB18FED83330F484395244
3628WinRAR.exeC:\Users\admin\AppData\Local\Temp\VB Decompiler Pro Crack\VB.Decompiler.Pro. Portable\lang\German.lngtext
MD5:FCF6A81C8C51BAFF366B1AD3EA3E29EE
SHA256:253E65AA18876D364F9FCBC230D36AAE322F90F04EF8184A310EC464F80CAE63
3628WinRAR.exeC:\Users\admin\AppData\Local\Temp\VB Decompiler Pro Crack\VB.Decompiler.Pro. Portable\Help_pr.chmchm
MD5:7595F2CD62F2B1F9E842682B4BBFBA6B
SHA256:5763C40D75021FA175C0C2E16EEACD9C44A9575B2E2980927D888AEF40EC2E13
3628WinRAR.exeC:\Users\admin\AppData\Local\Temp\VB Decompiler Pro Crack\VB.Decompiler.Pro. Portable\Help_cz.chmchm
MD5:7641F8B29012664C6D59ECD9A128F916
SHA256:7366C80B214B6DD4E38BB49C7D58E1A553EDAFB232602F03F32ADD0EB076416D
3628WinRAR.exeC:\Users\admin\AppData\Local\Temp\VB Decompiler Pro Crack\VB.Decompiler.Pro. Portable\lang\English.lngtext
MD5:74692CBE0CD85E7EF995FAD75C4995E6
SHA256:4D7027DB0C4CC440952EDE5F23644990483654BC38AF8EFD97652BF06D4E22C8
3628WinRAR.exeC:\Users\admin\AppData\Local\Temp\VB Decompiler Pro Crack\VB.Decompiler.Pro. Portable\Help_idn.chmchm
MD5:37A9B81180E75366E5BEDB5765FC42CF
SHA256:6DED1B602F3A3C92731C7D0629687AD863624AFD65A49EB6BF5F7519993550E4
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
Process
Message
VB Decompiler Portable.exe
%s------------------------------------------------ --- WinLicense Professional --- --- (c)2012 Oreans Technologies --- ------------------------------------------------