| File name: | winaerotweaker.zip |
| Full analysis: | https://app.any.run/tasks/1d54a6d9-6a18-4fd6-8e83-2306186d42c9 |
| Verdict: | Malicious activity |
| Analysis date: | November 01, 2023, 14:36:10 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract |
| MD5: | BF982C18BF19FDEA302D12D99CC14483 |
| SHA1: | 79F9C93636E024A86508E82CDBEBBA4EC129C139 |
| SHA256: | 370095778B69F763AF03E553F5A83B192C7183D098CB0D87350F66FB525573B8 |
| SSDEEP: | 98304:PpA9q6ssUcCvuoKU+TyRTtyopLcxO7fiKiQMtA+Oh+EX4PLfKMxLKkqY9UlH6E4U:qB61oBA |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 20 |
|---|---|
| ZipBitFlag: | 0x0002 |
| ZipCompression: | Deflated |
| ZipModifyDate: | 2023:06:16 12:29:34 |
| ZipCRC: | 0x68b2f9ca |
| ZipCompressedSize: | 226 |
| ZipUncompressedSize: | 471 |
| ZipFileName: | SilentSetup.cmd |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 960 | "C:\Users\admin\Desktop\WinaeroTweaker-1.55.0.0-setup.exe" /SPAWNWND=$13012E /NOTIFYWND=$3045C /SP- /VERYSILENT | C:\Users\admin\Desktop\WinaeroTweaker-1.55.0.0-setup.exe | WinaeroTweaker-1.55.0.0-setup.tmp | ||||||||||||
User: admin Company: Winaero Integrity Level: HIGH Description: Winaero Tweaker Exit code: 0 Version: 1.55.0.0 Modules
| |||||||||||||||
| 1032 | WinaeroTweaker-1.55.0.0-setup.exe /SP- /VERYSILENT | C:\Users\admin\Desktop\WinaeroTweaker-1.55.0.0-setup.exe | — | cmd.exe | |||||||||||
User: admin Company: Winaero Integrity Level: MEDIUM Description: Winaero Tweaker Exit code: 0 Version: 1.55.0.0 Modules
| |||||||||||||||
| 1248 | "C:\Users\admin\AppData\Local\Temp\is-TBD0L.tmp\WinaeroTweaker-1.55.0.0-setup.tmp" /SL5="$3045C,3507132,832000,C:\Users\admin\Desktop\WinaeroTweaker-1.55.0.0-setup.exe" /SP- /VERYSILENT | C:\Users\admin\AppData\Local\Temp\is-TBD0L.tmp\WinaeroTweaker-1.55.0.0-setup.tmp | — | WinaeroTweaker-1.55.0.0-setup.exe | |||||||||||
User: admin Company: Winaero Integrity Level: MEDIUM Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 Modules
| |||||||||||||||
| 1440 | sc.exe config wuauserv start= demand | C:\Windows\System32\sc.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: A tool to aid in developing services for WindowsNT Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2084 | "C:\Windows\System32\cmd.exe" /c taskkill /im winaerotweakerhelper.exe /f | C:\Windows\System32\cmd.exe | — | WinaeroTweaker-1.55.0.0-setup.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 128 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 2216 | "C:\Program Files\Winaero Tweaker\WinaeroTweaker.exe" | C:\Program Files\Winaero Tweaker\WinaeroTweaker.exe | — | explorer.exe | |||||||||||
User: admin Company: https://winaero.com Integrity Level: MEDIUM Description: WinaeroTweaker Exit code: 0 Version: 1.55.0.0 Modules
| |||||||||||||||
| 2224 | "C:\Windows\System32\cmd.exe" /c taskkill /im winaerotweaker.exe /f | C:\Windows\System32\cmd.exe | — | WinaeroTweaker-1.55.0.0-setup.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 128 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 2296 | C:\Windows\system32\cmd.exe /c ""C:\Users\admin\Desktop\SilentSetup.cmd" " | C:\Windows\System32\cmd.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 3064 | "C:\Program Files\Winaero Tweaker\WinaeroTweakerHelper.exe" - | C:\Program Files\Winaero Tweaker\WinaeroTweakerHelper.exe | — | WinaeroTweaker.exe | |||||||||||
User: admin Company: http://winaero.com Integrity Level: HIGH Description: Winaero Tweaker 32bit support process Exit code: 0 Version: 1.1.0.0 Modules
| |||||||||||||||
| 3076 | "C:\Windows\System32\cmd.exe" /c sc.exe config wuauserv start= demand | C:\Windows\System32\cmd.exe | — | WinaeroTweaker.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| (PID) Process: | (3372) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\178\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3372) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip | |||
| (PID) Process: | (3372) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (3372) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop\phacker.zip | |||
| (PID) Process: | (3372) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (3372) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (3372) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (3372) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (3372) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin |
| Operation: | write | Name: | Placement |
Value: 2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000 | |||
| (PID) Process: | (3372) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\General |
| Operation: | write | Name: | LastFolder |
Value: C:\Users\admin\Desktop | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3812 | WinaeroTweaker-1.55.0.0-setup.tmp | C:\Program Files\Winaero Tweaker\WinaeroControls.dll | executable | |
MD5:E5EE2251D3CE665D15579D31F7504BF5 | SHA256:632D7523E50A34C2A201C7D263B87CB4D96696BE91D6573A2A7BA964C9E573EA | |||
| 3812 | WinaeroTweaker-1.55.0.0-setup.tmp | C:\Program Files\Winaero Tweaker\WinaeroTweaker.exe | executable | |
MD5:23C3E2111BE79604C718B474500213B8 | SHA256:0C4B4FB9C424A158939D4CFA492E16226EDFAEA1DFE6B5C242B833C4DCB9EA5D | |||
| 3812 | WinaeroTweaker-1.55.0.0-setup.tmp | C:\Program Files\Winaero Tweaker\is-KDBD7.tmp | executable | |
MD5:23C3E2111BE79604C718B474500213B8 | SHA256:0C4B4FB9C424A158939D4CFA492E16226EDFAEA1DFE6B5C242B833C4DCB9EA5D | |||
| 3812 | WinaeroTweaker-1.55.0.0-setup.tmp | C:\Program Files\Winaero Tweaker\is-30NUA.tmp | executable | |
MD5:DF2708F6C7B1D60CFCF071142519A834 | SHA256:4AAB16C2765C4BBD729D41617ED6FBA08893CC3C71C9D250B3CBCBD600114749 | |||
| 3812 | WinaeroTweaker-1.55.0.0-setup.tmp | C:\Program Files\Winaero Tweaker\WinaeroTweakerHelper.exe | executable | |
MD5:8E0AEC38406AFACFF9487529ADD32C74 | SHA256:C789872A6141E19F9CB71ABB8260C8303A2AC48DFD86F36912A4649800A78D39 | |||
| 3812 | WinaeroTweaker-1.55.0.0-setup.tmp | C:\Program Files\Winaero Tweaker\is-1FCH3.tmp | executable | |
MD5:BB3935CACCEA6DC73487045C7640AE7A | SHA256:A921DD143B295DFF3F4C1343A085980A50006A55797E239AB8AC1C0DA64E1BBE | |||
| 3812 | WinaeroTweaker-1.55.0.0-setup.tmp | C:\Users\admin\AppData\Local\Temp\is-7OU3A.tmp\_isetup\_iscrypt.dll | executable | |
MD5:A69559718AB506675E907FE49DEB71E9 | SHA256:2F6294F9AA09F59A574B5DCD33BE54E16B39377984F3D5658CDA44950FA0F8FC | |||
| 3812 | WinaeroTweaker-1.55.0.0-setup.tmp | C:\Program Files\Winaero Tweaker\Elevator.exe | executable | |
MD5:DF2708F6C7B1D60CFCF071142519A834 | SHA256:4AAB16C2765C4BBD729D41617ED6FBA08893CC3C71C9D250B3CBCBD600114749 | |||
| 3812 | WinaeroTweaker-1.55.0.0-setup.tmp | C:\Program Files\Winaero Tweaker\is-8UDKE.tmp | executable | |
MD5:8E0AEC38406AFACFF9487529ADD32C74 | SHA256:C789872A6141E19F9CB71ABB8260C8303A2AC48DFD86F36912A4649800A78D39 | |||
| 3812 | WinaeroTweaker-1.55.0.0-setup.tmp | C:\Program Files\Winaero Tweaker\is-VTUCU.tmp | executable | |
MD5:FB6E5BD898E6D6369F29A3FE0EDA0198 | SHA256:100AC04E146983684553D9FEDC8442E7B0C619A832A1CF414F2482334ED472C9 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3116 | WinaeroTweaker.exe | GET | 200 | 67.27.235.254:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?ece396c6e641254f | unknown | compressed | 61.6 Kb | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1088 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
2656 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
3116 | WinaeroTweaker.exe | 68.183.112.81:443 | winaero.com | DIGITALOCEAN-ASN | US | unknown |
3116 | WinaeroTweaker.exe | 67.27.235.254:80 | ctldl.windowsupdate.com | LEVEL3 | US | unknown |
Domain | IP | Reputation |
|---|---|---|
winaero.com |
| whitelisted |
ctldl.windowsupdate.com |
| whitelisted |