| File name: | winaerotweaker.zip |
| Full analysis: | https://app.any.run/tasks/1d54a6d9-6a18-4fd6-8e83-2306186d42c9 |
| Verdict: | Malicious activity |
| Analysis date: | November 01, 2023, 14:36:10 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract |
| MD5: | BF982C18BF19FDEA302D12D99CC14483 |
| SHA1: | 79F9C93636E024A86508E82CDBEBBA4EC129C139 |
| SHA256: | 370095778B69F763AF03E553F5A83B192C7183D098CB0D87350F66FB525573B8 |
| SSDEEP: | 98304:PpA9q6ssUcCvuoKU+TyRTtyopLcxO7fiKiQMtA+Oh+EX4PLfKMxLKkqY9UlH6E4U:qB61oBA |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 20 |
|---|---|
| ZipBitFlag: | 0x0002 |
| ZipCompression: | Deflated |
| ZipModifyDate: | 2023:06:16 12:29:34 |
| ZipCRC: | 0x68b2f9ca |
| ZipCompressedSize: | 226 |
| ZipUncompressedSize: | 471 |
| ZipFileName: | SilentSetup.cmd |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 960 | "C:\Users\admin\Desktop\WinaeroTweaker-1.55.0.0-setup.exe" /SPAWNWND=$13012E /NOTIFYWND=$3045C /SP- /VERYSILENT | C:\Users\admin\Desktop\WinaeroTweaker-1.55.0.0-setup.exe | WinaeroTweaker-1.55.0.0-setup.tmp | ||||||||||||
User: admin Company: Winaero Integrity Level: HIGH Description: Winaero Tweaker Exit code: 0 Version: 1.55.0.0 Modules
| |||||||||||||||
| 1032 | WinaeroTweaker-1.55.0.0-setup.exe /SP- /VERYSILENT | C:\Users\admin\Desktop\WinaeroTweaker-1.55.0.0-setup.exe | — | cmd.exe | |||||||||||
User: admin Company: Winaero Integrity Level: MEDIUM Description: Winaero Tweaker Exit code: 0 Version: 1.55.0.0 Modules
| |||||||||||||||
| 1248 | "C:\Users\admin\AppData\Local\Temp\is-TBD0L.tmp\WinaeroTweaker-1.55.0.0-setup.tmp" /SL5="$3045C,3507132,832000,C:\Users\admin\Desktop\WinaeroTweaker-1.55.0.0-setup.exe" /SP- /VERYSILENT | C:\Users\admin\AppData\Local\Temp\is-TBD0L.tmp\WinaeroTweaker-1.55.0.0-setup.tmp | — | WinaeroTweaker-1.55.0.0-setup.exe | |||||||||||
User: admin Company: Winaero Integrity Level: MEDIUM Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 Modules
| |||||||||||||||
| 1440 | sc.exe config wuauserv start= demand | C:\Windows\System32\sc.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: A tool to aid in developing services for WindowsNT Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2084 | "C:\Windows\System32\cmd.exe" /c taskkill /im winaerotweakerhelper.exe /f | C:\Windows\System32\cmd.exe | — | WinaeroTweaker-1.55.0.0-setup.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 128 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 2216 | "C:\Program Files\Winaero Tweaker\WinaeroTweaker.exe" | C:\Program Files\Winaero Tweaker\WinaeroTweaker.exe | — | explorer.exe | |||||||||||
User: admin Company: https://winaero.com Integrity Level: MEDIUM Description: WinaeroTweaker Exit code: 0 Version: 1.55.0.0 Modules
| |||||||||||||||
| 2224 | "C:\Windows\System32\cmd.exe" /c taskkill /im winaerotweaker.exe /f | C:\Windows\System32\cmd.exe | — | WinaeroTweaker-1.55.0.0-setup.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 128 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 2296 | C:\Windows\system32\cmd.exe /c ""C:\Users\admin\Desktop\SilentSetup.cmd" " | C:\Windows\System32\cmd.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 3064 | "C:\Program Files\Winaero Tweaker\WinaeroTweakerHelper.exe" - | C:\Program Files\Winaero Tweaker\WinaeroTweakerHelper.exe | — | WinaeroTweaker.exe | |||||||||||
User: admin Company: http://winaero.com Integrity Level: HIGH Description: Winaero Tweaker 32bit support process Exit code: 0 Version: 1.1.0.0 Modules
| |||||||||||||||
| 3076 | "C:\Windows\System32\cmd.exe" /c sc.exe config wuauserv start= demand | C:\Windows\System32\cmd.exe | — | WinaeroTweaker.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| (PID) Process: | (3372) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\178\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3372) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip | |||
| (PID) Process: | (3372) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (3372) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop\phacker.zip | |||
| (PID) Process: | (3372) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (3372) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (3372) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (3372) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (3372) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin |
| Operation: | write | Name: | Placement |
Value: 2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000 | |||
| (PID) Process: | (3372) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\General |
| Operation: | write | Name: | LastFolder |
Value: C:\Users\admin\Desktop | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3812 | WinaeroTweaker-1.55.0.0-setup.tmp | C:\Program Files\Winaero Tweaker\Elevator.exe | executable | |
MD5:DF2708F6C7B1D60CFCF071142519A834 | SHA256:4AAB16C2765C4BBD729D41617ED6FBA08893CC3C71C9D250B3CBCBD600114749 | |||
| 3812 | WinaeroTweaker-1.55.0.0-setup.tmp | C:\Program Files\Winaero Tweaker\no_tab_explorer.exe | executable | |
MD5:FB6E5BD898E6D6369F29A3FE0EDA0198 | SHA256:100AC04E146983684553D9FEDC8442E7B0C619A832A1CF414F2482334ED472C9 | |||
| 3372 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3372.39193\SilentSetup.cmd | text | |
MD5:197BEF36215F7D3A3863D1331BB5A18C | SHA256:85AE2F1E32A5F46A1F6E3DD4B9C3F5641B6748560D1F5C62EC1024B324E3E1E9 | |||
| 3812 | WinaeroTweaker-1.55.0.0-setup.tmp | C:\Program Files\Winaero Tweaker\unins000.exe | executable | |
MD5:052A74D2B5F148905F95967688F799C5 | SHA256:D3F40D26CC6DE2E992466DA8EEE55417787E0451B852690BDFA9623B3BB4C36F | |||
| 3812 | WinaeroTweaker-1.55.0.0-setup.tmp | C:\Program Files\Winaero Tweaker\is-MSE6V.tmp | executable | |
MD5:052A74D2B5F148905F95967688F799C5 | SHA256:D3F40D26CC6DE2E992466DA8EEE55417787E0451B852690BDFA9623B3BB4C36F | |||
| 1032 | WinaeroTweaker-1.55.0.0-setup.exe | C:\Users\admin\AppData\Local\Temp\is-TBD0L.tmp\WinaeroTweaker-1.55.0.0-setup.tmp | executable | |
MD5:86703BD9DE2D284E858A60A09E5B9ADC | SHA256:74B32D4954EE2AA19E9D6C71F9797889F4BA6D838A5D50C5C8AE298BD89D702C | |||
| 960 | WinaeroTweaker-1.55.0.0-setup.exe | C:\Users\admin\AppData\Local\Temp\is-QNT3V.tmp\WinaeroTweaker-1.55.0.0-setup.tmp | executable | |
MD5:86703BD9DE2D284E858A60A09E5B9ADC | SHA256:74B32D4954EE2AA19E9D6C71F9797889F4BA6D838A5D50C5C8AE298BD89D702C | |||
| 3812 | WinaeroTweaker-1.55.0.0-setup.tmp | C:\Users\admin\AppData\Local\Temp\is-7OU3A.tmp\_isetup\_iscrypt.dll | executable | |
MD5:A69559718AB506675E907FE49DEB71E9 | SHA256:2F6294F9AA09F59A574B5DCD33BE54E16B39377984F3D5658CDA44950FA0F8FC | |||
| 3812 | WinaeroTweaker-1.55.0.0-setup.tmp | C:\Program Files\Winaero Tweaker\is-KDBD7.tmp | executable | |
MD5:23C3E2111BE79604C718B474500213B8 | SHA256:0C4B4FB9C424A158939D4CFA492E16226EDFAEA1DFE6B5C242B833C4DCB9EA5D | |||
| 3812 | WinaeroTweaker-1.55.0.0-setup.tmp | C:\Program Files\Winaero Tweaker\WinaeroTweaker.exe | executable | |
MD5:23C3E2111BE79604C718B474500213B8 | SHA256:0C4B4FB9C424A158939D4CFA492E16226EDFAEA1DFE6B5C242B833C4DCB9EA5D | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3116 | WinaeroTweaker.exe | GET | 200 | 67.27.235.254:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?ece396c6e641254f | unknown | compressed | 61.6 Kb | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1088 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
2656 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
3116 | WinaeroTweaker.exe | 68.183.112.81:443 | winaero.com | DIGITALOCEAN-ASN | US | unknown |
3116 | WinaeroTweaker.exe | 67.27.235.254:80 | ctldl.windowsupdate.com | LEVEL3 | US | unknown |
Domain | IP | Reputation |
|---|---|---|
winaero.com |
| whitelisted |
ctldl.windowsupdate.com |
| whitelisted |