File name: | IDM.6.41.b.6.kuyhAa.Me.zip |
Full analysis: | https://app.any.run/tasks/1d6acf1a-bdf7-472e-b888-157116acbc86 |
Verdict: | Malicious activity |
Analysis date: | November 18, 2023, 14:09:47 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | application/zip |
File info: | Zip archive data, at least v1.0 to extract |
MD5: | 0C8B3D98D53ACF1D91C51D6E90BD0F69 |
SHA1: | 0D07E9D1A687C051038DF5ED187C8D2A22FBA17C |
SHA256: | 2996715BFB4E60F7806C999EF805A6576DD290AE46109F988E892CB1BE99342B |
SSDEEP: | 196608:aZHoB3CFU5Ho0bkszT5f8E/IH/pG2SY8s/JQA:agjookMT5f8E/E0zYZ/CA |
.zip | | | ZIP compressed archive (100) |
---|
ZipRequiredVersion: | 10 |
---|---|
ZipBitFlag: | - |
ZipCompression: | None |
ZipModifyDate: | 2022:12:03 05:56:40 |
ZipCRC: | 0x00000000 |
ZipCompressedSize: | - |
ZipUncompressedSize: | - |
ZipFileName: | IDM.6.41.b.6.kuyhAa.Me/ |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
608 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="4044.0.174610699\1253650564" -parentBuildID 20230710165010 -prefsHandle 1120 -prefMapHandle 1112 -prefsLen 28523 -prefMapSize 244195 -appDir "C:\Program Files\Mozilla Firefox\browser" - {0cec4591-e526-4732-9cb9-93e9ee98d943} 4044 "\\.\pipe\gecko-crash-server-pipe.4044" 1192 d6a8ca0 gpu | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 1 Version: 115.0.2 Modules
| |||||||||||||||
680 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="4044.7.123600962\100977427" -childID 6 -isForBrowser -prefsHandle 2092 -prefMapHandle 1992 -prefsLen 29366 -prefMapSize 244195 -jsInitHandle 924 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {0ce3e244-6888-444f-ba3d-3753afc0776f} 4044 "\\.\pipe\gecko-crash-server-pipe.4044" 2376 217b6e00 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
856 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="4044.3.539058290\878515058" -childID 2 -isForBrowser -prefsHandle 2936 -prefMapHandle 2928 -prefsLen 34225 -prefMapSize 244195 -jsInitHandle 924 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {4baeb056-833d-4790-b0c4-df23362cfd87} 4044 "\\.\pipe\gecko-crash-server-pipe.4044" 2948 1f39bc90 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
856 | "C:\Program Files\Internet Download Manager\IDMan.exe" | C:\Program Files\Internet Download Manager\IDMan.exe | — | explorer.exe | |||||||||||
User: admin Company: Tonec Inc. Integrity Level: MEDIUM Description: Internet Download Manager (IDM) Exit code: 0 Version: 6, 41, 6, 2 Modules
| |||||||||||||||
1272 | "C:\Program Files\Internet Download Manager\IDMan.exe" -Embedding | C:\Program Files\Internet Download Manager\IDMan.exe | svchost.exe | ||||||||||||
User: admin Company: Tonec Inc. Integrity Level: MEDIUM Description: Internet Download Manager (IDM) Exit code: 3489660927 Version: 6, 41, 6, 2 Modules
| |||||||||||||||
1576 | "C:\Program Files\Internet Download Manager\MediumILStart.exe" | C:\Program Files\Internet Download Manager\MediumILStart.exe | — | IDMan.exe | |||||||||||
User: admin Company: Internet Download Manager, Tonec Inc. Integrity Level: MEDIUM Description: IDM module Exit code: 0 Version: 6, 35, 9, 1 Modules
| |||||||||||||||
1876 | "C:\Program Files\Internet Download Manager\IEMonitor.exe" | C:\Program Files\Internet Download Manager\IEMonitor.exe | — | IDMan.exe | |||||||||||
User: admin Company: Tonec Inc. Integrity Level: MEDIUM Description: Internet Download Manager agent for click monitoring in IE-based browsers Exit code: 0 Version: 6, 37, 8, 1 Modules
| |||||||||||||||
1892 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="4044.1.2078969166\348885928" -parentBuildID 20230710165010 -prefsHandle 1432 -prefMapHandle 1428 -prefsLen 28600 -prefMapSize 244195 -appDir "C:\Program Files\Mozilla Firefox\browser" - {f3866181-7215-488d-93b3-7de6099e0d4c} 4044 "\\.\pipe\gecko-crash-server-pipe.4044" 1444 d61b1a0 socket | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
2516 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="4044.6.684837045\1710777205" -childID 5 -isForBrowser -prefsHandle 4012 -prefMapHandle 3988 -prefsLen 34332 -prefMapSize 244195 -jsInitHandle 924 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {2436d682-facf-4cd1-b35d-385423a80320} 4044 "\\.\pipe\gecko-crash-server-pipe.4044" 3924 217b63f0 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
2584 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="4044.4.308190640\304194261" -childID 3 -isForBrowser -prefsHandle 3532 -prefMapHandle 2880 -prefsLen 29209 -prefMapSize 244195 -jsInitHandle 924 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {2e5c1fb2-d524-400d-8aba-fe3d68b40076} 4044 "\\.\pipe\gecko-crash-server-pipe.4044" 3540 1c55a9b0 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
|
(PID) Process: | (3448) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\17A\52C64B7E |
Operation: | write | Name: | LanguageList |
Value: en-US | |||
(PID) Process: | (3448) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip | |||
(PID) Process: | (3448) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
(PID) Process: | (3448) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop\phacker.zip | |||
(PID) Process: | (3448) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | name |
Value: 120 | |||
(PID) Process: | (3448) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | size |
Value: 80 | |||
(PID) Process: | (3448) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | type |
Value: 120 | |||
(PID) Process: | (3448) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | mtime |
Value: 100 | |||
(PID) Process: | (3644) IDM1.tmp | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager |
Operation: | write | Name: | PendingFileRenameOperations |
Value: \??\C:\Users\admin\AppData\Local\Temp\IDM_Setup_Temp\IDM1.tmp | |||
(PID) Process: | (3644) IDM1.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{AC746233-E9D3-49CD-862F-068F7B7CCCA4} |
Operation: | write | Name: | RunAs |
Value: Interactive User |
PID | Process | Filename | Type | |
---|---|---|---|---|
3644 | IDM1.tmp | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Download Manager\license.lnk | binary | |
MD5:7C77E437785E8E3A34718B0377A85163 | SHA256:C80D5E3476E76C789BE2ACD06B1F0A8F26D658DB086F2033D6B842156E33FDD0 | |||
3448 | WinRAR.exe | C:\Users\admin\Desktop\IDM.6.41.b.6.kuyhAa.Me\Settings.Anti.Notif.Update.reg | text | |
MD5:D4C096EDA260A707434CC0DE137ABBDF | SHA256:9CABC1743B35B773F09FFF97DA60EA49323FA56284768B1FC9D9D7A22E944423 | |||
3448 | WinRAR.exe | C:\Users\admin\Desktop\IDM.6.41.b.6.kuyhAa.Me\Jamu\Lokasi Paste Crack.lnk | binary | |
MD5:FF6CDB9B107C6CEE39C536882C77537D | SHA256:D6A11EDB519C1509008FE2EF4F42AD894D89EFE612D96FC04252818295E835F2 | |||
3448 | WinRAR.exe | C:\Users\admin\Desktop\IDM.6.41.b.6.kuyhAa.Me\Langkah Menggunakan Jamu.txt | text | |
MD5:D63EC2EBFBC5BFFECD2FF3979FCDD993 | SHA256:04EA321AE4D5CC20B139D665132DA0450667193DA5ECB456E028C91172CF9E86 | |||
3448 | WinRAR.exe | C:\Users\admin\Desktop\IDM.6.41.b.6.kuyhAa.Me\Jamu\kuyhAa.Me.url | text | |
MD5:B6F5CE7267C50CF195B1AE2A8EAEC913 | SHA256:ED77A3BC71138AB5CCD49ABA225514AC860B7251EE16DB3A2B91FD4719F9D291 | |||
3644 | IDM1.tmp | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Internet Download Manager\Internet Download Manager.lnk | binary | |
MD5:E72D40C05CB1B90FB857C8E98B698935 | SHA256:DFF61D64D951287C6CC7FB5E1BD242EB311202F3705677A4AC2683C45422E3BA | |||
3644 | IDM1.tmp | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Download Manager\TUTORIALS.lnk | binary | |
MD5:A2E04B9526BAF9AFA32BDA747E6EFF77 | SHA256:9E177C57C7C7454AE3F4A97153919BC88863FFEC2F90FCAB107D2818E980F303 | |||
3448 | WinRAR.exe | C:\Users\admin\Desktop\IDM.6.41.b.6.kuyhAa.Me\www.kuyhaa.me.url | text | |
MD5:020A2175CD00353419BA86941FAF6ECB | SHA256:0FAD91A7D23B2A63EB58C402D7D2609CC11932F9DF35B69A3EC45783737CFF35 | |||
3644 | IDM1.tmp | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Download Manager\Uninstall IDM.lnk | binary | |
MD5:502B252609C6BEB3EB09EDE6DDCDB58C | SHA256:65B246D4891C803FD880D80B7E8DD8D2155590F221518D4BBBC356843DBA40AD | |||
3644 | IDM1.tmp | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Internet Download Manager\license.lnk | binary | |
MD5:81185ECC2CF6158CE35A8A50743B83C2 | SHA256:17E74B263AE03B47CED345BEC25A3ECA090CEFD9694D915BE91DDFF37FE4CF0E |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
4044 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/success.txt?ipv4 | unknown | text | 8 b | — |
3900 | IDMan.exe | GET | 200 | 93.184.221.240:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?66b6c19a6dca6cb7 | unknown | compressed | 61.6 Kb | — |
4044 | firefox.exe | POST | 200 | 142.250.186.35:80 | http://ocsp.pki.goog/gts1c3 | unknown | binary | 472 b | — |
4044 | firefox.exe | POST | 200 | 2.16.2.73:80 | http://r3.o.lencr.org/ | unknown | binary | 503 b | — |
4044 | firefox.exe | POST | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/ | unknown | binary | 471 b | — |
4044 | firefox.exe | POST | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/ | unknown | binary | 471 b | — |
4044 | firefox.exe | POST | 200 | 18.245.65.219:80 | http://ocsp.r2m02.amazontrust.com/ | unknown | binary | 471 b | — |
4044 | firefox.exe | POST | 200 | 2.16.2.73:80 | http://r3.o.lencr.org/ | unknown | binary | 503 b | — |
4044 | firefox.exe | POST | 200 | 2.16.2.73:80 | http://r3.o.lencr.org/ | unknown | binary | 503 b | — |
4044 | firefox.exe | POST | 200 | 142.250.186.35:80 | http://ocsp.pki.goog/gts1c3 | unknown | binary | 472 b | — |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | unknown |
— | — | 224.0.0.252:5355 | — | — | — | unknown |
2588 | svchost.exe | 239.255.255.250:1900 | — | — | — | unknown |
4 | System | 192.168.100.255:138 | — | — | — | unknown |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
3900 | IDMan.exe | 93.184.221.240:80 | ctldl.windowsupdate.com | EDGECAST | GB | unknown |
4044 | firefox.exe | 169.61.27.133:443 | secure.internetdownloadmanager.com | SOFTLAYER | US | unknown |
4044 | firefox.exe | 34.107.221.82:80 | detectportal.firefox.com | GOOGLE | US | unknown |
4044 | firefox.exe | 34.117.237.239:443 | contile.services.mozilla.com | GOOGLE-CLOUD-PLATFORM | US | unknown |
4044 | firefox.exe | 44.209.32.107:443 | spocs.getpocket.com | AMAZON-AES | US | unknown |
Domain | IP | Reputation |
---|---|---|
ctldl.windowsupdate.com |
| unknown |
test.internetdownloadmanager.com |
| unknown |
secure.internetdownloadmanager.com |
| unknown |
www.internetdownloadmanager.com |
| unknown |
mirror3.internetdownloadmanager.com |
| unknown |
mirror5.internetdownloadmanager.com |
| unknown |
registeridm.com |
| unknown |
detectportal.firefox.com |
| unknown |
prod.detectportal.prod.cloudops.mozgcp.net |
| unknown |
example.org |
| unknown |
PID | Process | Class | Message |
---|---|---|---|
— | — | Potential Corporate Privacy Violation | ET POLICY Outgoing Basic Auth Base64 HTTP Password detected unencrypted |