File name:

MacKeeper.3.21.2.dmg

Full analysis: https://app.any.run/tasks/b84e1ac0-5602-4cd3-9a89-672c18e94163
Verdict: No threats detected
Analysis date: June 08, 2018, 14:15:02
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
MIME: application/x-iso9660-image
File info: ISO 9660 CD-ROM filesystem data 'MacKeeper Installer'
MD5:

64BD265F48A239B697F02C70E8773B5A

SHA1:

5028FAFA64875734058873D2CFD862939591C37E

SHA256:

2DA3A0AB2793C5AB8D42F502FFA882B041378B33B9CD0D68833E0FF64F7F34C5

SSDEEP:

24576:cgJUYu9ih8vsuWotjiZkYfpYnqGOB8v+uWot0QwXT39GobCxwABncJ:8X5jiZnMpzj0/D39kyOc

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.iso | ISO 9660 CD image (27.6)
.atn | Photoshop Action (27.1)
. | null bytes (21.9)
.gmc | Game Music Creator Music (6.1)
. | MacBinary 1 header (5.5)

EXIF

ISO

System: LINUX
VolumeName: MacKeeper Installer
VolumeBlockCount: 839
VolumeBlockSize: 2048
RootDirectoryCreateDate: 2018:06:08 10:14:10-04:00
Software: GENISOIMAGE ISO 9660/HFS FILESYSTEM CREATOR (C) 1993 E.YOUNGDALE (C) 1997-2006 J.PEARSON/J.SCHILLING (C) 2006-2007 CDRKIT TEAM
VolumeCreateDate: 2018:06:08 10:14:10.00-04:00
VolumeModifyDate: 2018:06:08 10:14:10.00-04:00
VolumeEffectiveDate: 2018:06:08 10:14:10.00-04:00

Composite

VolumeSize: 1678 kB
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
32
Monitored processes
2
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start 7zfm.exe no specs PhotoViewer.dll no specs

Process information

PID
CMD
Path
Indicators
Parent process
3100"C:\Program Files\7-Zip\7zFM.exe" "C:\Users\admin\AppData\Local\Temp\MacKeeper.3.21.2.dmg"C:\Program Files\7-Zip\7zFM.exeexplorer.exe
User:
admin
Company:
Igor Pavlov
Integrity Level:
MEDIUM
Description:
7-Zip File Manager
Exit code:
0
Version:
16.04
Modules
Images
c:\program files\7-zip\7zfm.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3736C:\Windows\system32\DllHost.exe /Processid:{76D0CB12-7604-4048-B83C-1005C7DDC503}C:\Windows\system32\DllHost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
COM Surrogate
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\dllhost.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
Total events
743
Read events
729
Write events
14
Delete events
0

Modification events

(PID) Process:(3100) 7zFM.exeKey:HKEY_CURRENT_USER\Software\7-Zip\FM\Columns
Operation:writeName:7-Zip.Iso
Value:
0100000004000000010000000400000001000000BF0000000700000001000000640000000800000001000000640000000C00000001000000640000003500000001000000640000003600000001000000640000001F0000000100000064000000200000000100000064000000
(PID) Process:(3100) 7zFM.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached
Operation:writeName:{FFE2A43C-56B9-4BF5-9A79-CC6D4285608A} {00000122-0000-0000-C000-000000000046} 0xFFFF
Value:
0100000000000000A2D4803733FFD301
(PID) Process:(3100) 7zFM.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Direct3D\MostRecentApplication
Operation:writeName:Name
Value:
7zFM.exe
(PID) Process:(3736) DllHost.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Direct3D\MostRecentApplication
Operation:writeName:Name
Value:
DllHost.exe
(PID) Process:(3736) DllHost.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows Photo Viewer\Viewer
Operation:writeName:MainWndPos
Value:
6000000034000000A00400008002000000000000
(PID) Process:(3100) 7zFM.exeKey:HKEY_CURRENT_USER\Software\7-Zip\FM
Operation:writeName:FolderShortcuts
Value:
(PID) Process:(3100) 7zFM.exeKey:HKEY_CURRENT_USER\Software\7-Zip\FM
Operation:writeName:FolderHistory
Value:
43003A005C00550073006500720073005C00610064006D0069006E005C0041007000700044006100740061005C004C006F00630061006C005C00540065006D0070005C004D00610063004B00650065007000650072002E0033002E00320031002E0032002E0064006D0067005C002E006200610063006B00670072006F0075006E0064005C00000043003A005C00550073006500720073005C00610064006D0069006E005C0041007000700044006100740061005C004C006F00630061006C005C00540065006D0070005C004D00610063004B00650065007000650072002E0033002E00320031002E0032002E0064006D0067005C000000
(PID) Process:(3100) 7zFM.exeKey:HKEY_CURRENT_USER\Software\7-Zip\FM
Operation:writeName:PanelPath0
Value:
C:\Users\admin\AppData\Local\Temp\
(PID) Process:(3100) 7zFM.exeKey:HKEY_CURRENT_USER\Software\7-Zip\FM
Operation:writeName:FlatViewArc0
Value:
0
(PID) Process:(3100) 7zFM.exeKey:HKEY_CURRENT_USER\Software\7-Zip\FM
Operation:writeName:PanelPath1
Value:
Executable files
0
Suspicious files
0
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
31007zFM.exeC:\Users\admin\AppData\Local\Temp\7zOC1CA2554\background.tiffimage
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info