| File name: | [@exp_0day]RF_SCreater_3.3.3.rar |
| Full analysis: | https://app.any.run/tasks/93607a1c-bdae-4835-926b-904cd675ff52 |
| Verdict: | No threats detected |
| Analysis date: | September 26, 2019, 17:22:15 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-rar |
| File info: | RAR archive data, v5 |
| MD5: | C1D6917F2E48DF2FC653793BC8839979 |
| SHA1: | 1A73E1C3D15E0D297A1CAEA1416C9E9F17D9264E |
| SHA256: | 32974F1FDC7CFACCD7334C228A9F52C6FBDE2A59DF50066B68CB82BC675F3F6A |
| SSDEEP: | 98304:b4sAdDItkVIR5y4fUejc+irT9ul3D4cVLiV:b4xCWqViHS3D4L |
| .rar | | | RAR compressed archive (v5.0) (61.5) |
|---|---|---|
| .rar | | | RAR compressed archive (gen) (38.4) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1884 | "C:\Users\admin\AppData\Local\Temp\Rar$EXb3212.13452\_38Z0SNYJJ_RF_SCreater_3.3.3\RF_SCreater.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXb3212.13452\_38Z0SNYJJ_RF_SCreater_3.3.3\RF_SCreater.exe | — | WinRAR.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 2760 | "C:\Users\admin\AppData\Local\Temp\Rar$EXb3212.6574\_38Z0SNYJJ_RF_SCreater_3.3.3\RF_SCreater.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXb3212.6574\_38Z0SNYJJ_RF_SCreater_3.3.3\RF_SCreater.exe | — | WinRAR.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 3212 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\[@exp_0day]RF_SCreater_3.3.3.rar" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.60.0 Modules
| |||||||||||||||
| (PID) Process: | (3212) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (3212) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (3212) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\72\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3212) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\[@exp_0day]RF_SCreater_3.3.3.rar | |||
| (PID) Process: | (3212) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (3212) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (3212) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (3212) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (3212) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface |
| Operation: | write | Name: | ShowPassword |
Value: 1 | |||
| (PID) Process: | (3212) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3212 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb3212.6574\_38Z0SNYJJ_RF_SCreater_3.3.3\Admin\17032009-23.jpg | image | |
MD5:CFD8642B921F1F996CC21FA0BB77B1B4 | SHA256:927C4527235379B5E7BCA0A4CA6382C0511C2AABD6BD3D64653E6E08C0733C9E | |||
| 3212 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb3212.6574\_38Z0SNYJJ_RF_SCreater_3.3.3\Admin\17032009-24.jpg | image | |
MD5:75EFE20A23DEAC82CD5964B969AA033E | SHA256:0A8852FC3BB5FF70CD682B9EE7A1CCBD538D54C7BD54255AE4BA7BFDFDD6BDD5 | |||
| 3212 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb3212.6574\_38Z0SNYJJ_RF_SCreater_3.3.3\Admin\17032009-21.jpg | image | |
MD5:A2B69AC673BA46FEEDD54DE4A6CCEB12 | SHA256:7177EA49EF553CEC5AEF4F2859388020A2B76EE37D5808207EF63428E5EB057F | |||
| 3212 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb3212.6574\_38Z0SNYJJ_RF_SCreater_3.3.3\Admin\17032009-18.jpg | image | |
MD5:B18928892BED3B38535A6FD310B3F009 | SHA256:9DBEDD46033C3B9D96E0184BEB4D868CB8A156149618D91BBC76239161F99E64 | |||
| 3212 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb3212.6574\_38Z0SNYJJ_RF_SCreater_3.3.3\Admin\17032009-20.jpg | image | |
MD5:7703EB18B535904CD18F52AA16955B73 | SHA256:F07187A7A4321BFE480C64E4647D05A9C1B5ADA5BA9A7D98FDF951AA1FB17ED2 | |||
| 3212 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb3212.6574\_38Z0SNYJJ_RF_SCreater_3.3.3\Admin\17032009-27.jpg | image | |
MD5:516A1FFC186D23DCC2B5C1FD604AB7DA | SHA256:3AA484494E50F518AC3E73070FCE608FFF5B107D921C52FE50132C8C3FC482D1 | |||
| 3212 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb3212.6574\_38Z0SNYJJ_RF_SCreater_3.3.3\Admin\17032009-25.jpg | image | |
MD5:C5905112D47D0BD9367B4A4D9AACC4A7 | SHA256:CA453A3969DE13DA2053D328FDA3DAA0AFE6EE146F611E05C4747DC14699497C | |||
| 3212 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb3212.6574\_38Z0SNYJJ_RF_SCreater_3.3.3\Admin\17032009-28.jpg | image | |
MD5:F2CA35195BD270510F1EDB0FFCA8451B | SHA256:7422169321EABF5422310C8527E6D917FC8701C1D513A4D9FADC0EC78068BBEE | |||
| 3212 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb3212.6574\_38Z0SNYJJ_RF_SCreater_3.3.3\Admin\17032009-30.jpg | image | |
MD5:53500273BB94ABAEB804E02A782A7D7E | SHA256:26FBD5A5E5159A769C14B21C9F4A8022707F68114EC79DD231B126D731BC6491 | |||
| 3212 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb3212.6574\_38Z0SNYJJ_RF_SCreater_3.3.3\Admin\17032009-15.jpg | image | |
MD5:F3D062B00623758849470A03EEBC9C7A | SHA256:6994556634B04FF871DE585830CBEADBFEDB2D1C8EE0879220A8EC3DDA2303C7 | |||