File name:

VB Decompiler Pro Crack.rar

Full analysis: https://app.any.run/tasks/35f1aebc-febf-4233-b2bb-16eb080ed79b
Verdict: Malicious activity
Analysis date: February 07, 2022, 12:19:16
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v4, os: Win32
MD5:

38AA4541D097F58A083E98BB906079C8

SHA1:

831273E820EEC369DB5292086AC7B918EBEEA028

SHA256:

1B93582627643FC62605862FD0DB4AD1BD015CA656AECD895E76476EBF2CA271

SSDEEP:

196608:1TchAsYeBrLnjxRT6r/xAWEdMt6CMiWIwT+qog:1Tch3pbjxNMAWml+wT+Q

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • VB Decompiler Portable.exe (PID: 2044)
    • Loads dropped or rewritten executable

      • VB Decompiler Portable.exe (PID: 2044)
  • SUSPICIOUS

    • Checks supported languages

      • WinRAR.exe (PID: 3628)
      • VB Decompiler Portable.exe (PID: 2044)
    • Reads the computer name

      • WinRAR.exe (PID: 3628)
      • VB Decompiler Portable.exe (PID: 2044)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3628)
    • Drops a file with too old compile date

      • WinRAR.exe (PID: 3628)
    • Drops a file that was compiled in debug mode

      • WinRAR.exe (PID: 3628)
  • INFO

    • Manual execution by user

      • VB Decompiler Portable.exe (PID: 2044)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v-4.x) (58.3)
.rar | RAR compressed archive (gen) (41.6)

EXIF

ZIP

ArchivedFileName: VB.Decompiler.Pro. Portable\colors\help.ini
PackingMethod: Stored
ModifyDate: 2006:03:05 16:53:21
OperatingSystem: Win32
UncompressedSize: 197
CompressedSize: 261
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
37
Monitored processes
2
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe vb decompiler portable.exe

Process information

PID
CMD
Path
Indicators
Parent process
2044"C:\Users\admin\AppData\Local\Temp\VB Decompiler Pro Crack\VB.Decompiler.Pro. Portable\VB Decompiler Portable.exe" C:\Users\admin\AppData\Local\Temp\VB Decompiler Pro Crack\VB.Decompiler.Pro. Portable\VB Decompiler Portable.exe
Explorer.EXE
User:
admin
Company:
DotFix Software
Integrity Level:
MEDIUM
Description:
Decompiler for p-code and native code files
Exit code:
0
Version:
10.1.0.0
Modules
Images
c:\windows\system32\ntdll.dll
c:\users\admin\appdata\local\temp\vb decompiler pro crack\vb.decompiler.pro. portable\vb decompiler portable.exe
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3628"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\VB Decompiler Pro Crack.rar"C:\Program Files\WinRAR\WinRAR.exe
Explorer.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
Total events
1 121
Read events
1 078
Write events
43
Delete events
0

Modification events

(PID) Process:(3628) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3628) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3628) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3628) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(3628) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(3628) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\VB Decompiler Pro Crack.rar
(PID) Process:(3628) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3628) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3628) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3628) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
Executable files
15
Suspicious files
4
Text files
45
Unknown types
11

Dropped files

PID
Process
Filename
Type
3628WinRAR.exeC:\Users\admin\AppData\Local\Temp\VB Decompiler Pro Crack\VB.Decompiler.Pro. Portable\colors\help.iniini
MD5:B0FA941304BCE4085167C39418A78200
SHA256:9C6DE245A8289ED641ED39DA6CA4AE5B358C5EDBE9FA1BBED007EFB8E8EF77BF
3628WinRAR.exeC:\Users\admin\AppData\Local\Temp\VB Decompiler Pro Crack\VB.Decompiler.Pro. Portable\Force.dllexecutable
MD5:98D27490D840D82E96B95107DACD22C3
SHA256:4E5B4C13DCBBF448334D38465ECACDDEB6F2636D7029DACEDC5CE32143F46A6D
3628WinRAR.exeC:\Users\admin\AppData\Local\Temp\VB Decompiler Pro Crack\VB.Decompiler.Pro. Portable\colors\hiew.iniini
MD5:993E16F8AB6E4A727D8A90BCC52C3FD1
SHA256:78DE9880FB19386F8DF09C5790E4432F3CC352EA43ED1CEA1F04F25576A43223
3628WinRAR.exeC:\Users\admin\AppData\Local\Temp\VB Decompiler Pro Crack\VB.Decompiler.Pro. Portable\Help_esp.chmchm
MD5:EF0611480AA8B752BCAC557C4E7E9288
SHA256:93700CF7BF6AA858C5B6E65704AB50002500279C3CD2F43979993C9A711DAA30
3628WinRAR.exeC:\Users\admin\AppData\Local\Temp\VB Decompiler Pro Crack\VB.Decompiler.Pro. Portable\Help_jp.chmchm
MD5:0F40A073E318B5C261291B782DCD1BC6
SHA256:EFB18268DA9951334410CCE8532E716CA264E4C192FCE03725C7D50E2D1DAB27
3628WinRAR.exeC:\Users\admin\AppData\Local\Temp\VB Decompiler Pro Crack\VB.Decompiler.Pro. Portable\Help_de.chmchm
MD5:19C251FE00C6CD3BA4C5902B2C14CEF4
SHA256:CEE905D31329F5DF426411E9623BD9FDFAF41A80C3E0C3D6D407FFB1712A4A55
3628WinRAR.exeC:\Users\admin\AppData\Local\Temp\VB Decompiler Pro Crack\VB.Decompiler.Pro. Portable\Help_eng.chmchm
MD5:B02A889E9CF85DC376EC9DB7FE4D7471
SHA256:1E765458FED1A8D6EEA0FFF5EAC5C725EEA9D6EBE5848C2145E5C55A4E56CB77
3628WinRAR.exeC:\Users\admin\AppData\Local\Temp\VB Decompiler Pro Crack\VB.Decompiler.Pro. Portable\lang\Arabic.lngtext
MD5:C60B65352621BB24C3442D8142D27D9F
SHA256:704834600E73030AB02AB5A400699CC582B553AC79DE426D809385EDE559E9CD
3628WinRAR.exeC:\Users\admin\AppData\Local\Temp\VB Decompiler Pro Crack\VB.Decompiler.Pro. Portable\lang\English.lngtext
MD5:74692CBE0CD85E7EF995FAD75C4995E6
SHA256:4D7027DB0C4CC440952EDE5F23644990483654BC38AF8EFD97652BF06D4E22C8
3628WinRAR.exeC:\Users\admin\AppData\Local\Temp\VB Decompiler Pro Crack\VB.Decompiler.Pro. Portable\lang\French.lngtext
MD5:42CD1C159BDC1C9377FC3D7E5F8E00FA
SHA256:8C33DE22D74BD7C0F3ADDBAA4A6EFD31D7A77DC348A10FBC1A14266C59AC4A3C
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
Process
Message
VB Decompiler Portable.exe
%s------------------------------------------------ --- WinLicense Professional --- --- (c)2012 Oreans Technologies --- ------------------------------------------------