File name: | KPortScan 3.0.rar |
Full analysis: | https://app.any.run/tasks/8d351d59-3b9d-4dad-a27c-455c21aba287 |
Verdict: | Malicious activity |
Analysis date: | June 12, 2020, 15:53:53 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | application/x-rar |
File info: | RAR archive data, v4, os: Win32 |
MD5: | 04B6966F8CA0920E9739B5543EE78B0B |
SHA1: | E4D14FF6E546827EBCB18C502BF2A46F75D1B32D |
SHA256: | 3C06B17527E56F49BDB09CD00C6FBE44963F6DB1E2CA65A31FAE7671C8C5B732 |
SSDEEP: | 98304:KG/DoT2s3IXaIA8LGZs70fQ/tTa54jlYl7HmCWBLphI+6Y0xrbF:KG/Do38hZ5FMQlYrWzyfRF |
.rar | | | RAR compressed archive (v-4.x) (58.3) |
---|---|---|
.rar | | | RAR compressed archive (gen) (41.6) |
CompressedSize: | 39 |
---|---|
UncompressedSize: | - |
OperatingSystem: | Win32 |
ModifyDate: | 2013:11:25 00:39:04 |
PackingMethod: | Stored |
ArchivedFileName: | KPortScan 3.0 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
2248 | "C:\Users\admin\Desktop\KPortScan 3.0\KPortScan3.exe" | C:\Users\admin\Desktop\KPortScan 3.0\KPortScan3.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
2868 | "C:\Users\admin\Desktop\KPortScan 3.0\KPortScan3.exe" | C:\Users\admin\Desktop\KPortScan 3.0\KPortScan3.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 3221225477 Modules
| |||||||||||||||
3020 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\KPortScan 3.0.rar" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.60.0 Modules
| |||||||||||||||
3556 | C:\Windows\system32\WerFault.exe -u -p 2868 -s 624 | C:\Windows\system32\WerFault.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Problem Reporting Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
|
(PID) Process: | (3020) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
Operation: | write | Name: | ShellExtBMP |
Value: | |||
(PID) Process: | (3020) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
Operation: | write | Name: | ShellExtIcon |
Value: | |||
(PID) Process: | (3020) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\12F\52C64B7E |
Operation: | write | Name: | LanguageList |
Value: en-US | |||
(PID) Process: | (3020) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\12F\52C64B7E |
Operation: | write | Name: | @C:\Windows\system32\NetworkExplorer.dll,-1 |
Value: Network | |||
(PID) Process: | (3020) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\KPortScan 3.0.rar | |||
(PID) Process: | (3020) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | name |
Value: 120 | |||
(PID) Process: | (3020) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | size |
Value: 80 | |||
(PID) Process: | (3020) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | type |
Value: 120 | |||
(PID) Process: | (3020) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | mtime |
Value: 100 | |||
(PID) Process: | (3020) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface |
Operation: | write | Name: | ShowPassword |
Value: 0 |
PID | Process | Filename | Type | |
---|---|---|---|---|
3556 | WerFault.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_KPortScan3.exe_1db9f0211b157a683ce96c7a51baef47c2528258_0df084de\Report.wer | binary | |
MD5:— | SHA256:— | |||
3556 | WerFault.exe | C:\Users\admin\AppData\Local\CrashDumps\KPortScan3.exe.2868.dmp | dmp | |
MD5:— | SHA256:— | |||
3020 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb3020.9205\KPortScan 3.0\KPortScan3.exe | executable | |
MD5:C0A8AF17A2912A08A20D65FE85191C28 | SHA256:080C6108C3BD0F8A43D5647DB36DC434032842339F0BA38AD1FF62F72999C4E5 | |||
3020 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb3020.9205\KPortScan 3.0\QtNetwork4.dll | executable | |
MD5:5C6AFAE60414546CEF0A9B759DA93912 | SHA256:99757EC661FD7DE3B22FB641F25CF1565AAE13DAF8D31C6686C6C7CBD2BE6FC9 | |||
3020 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb3020.9205\KPortScan 3.0\QtCore4.dll | executable | |
MD5:438717377B9DF0F53F283C9E4AA722CC | SHA256:A679CF46E128D028DE22FB9ED8432E5107E53F8E7E6FB7F5E169B3EEAB8F000A | |||
3020 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb3020.9205\KPortScan 3.0\QtGui4.dll | executable | |
MD5:37957FACC9AFBDFBD119C8372C9CF0E3 | SHA256:BF52FEC00B4F640D07BEA3850096CC77983FCA518BBEC8122997B7CA561205F1 |
Process | Message |
---|---|
KPortScan3.exe | QMetaObject::connectSlotsByName: No matching signal for on_result(QString,int,bool)
|
KPortScan3.exe | QMetaObject::connectSlotsByName: No matching signal for on_finished()
|
KPortScan3.exe | QMetaObject::connectSlotsByName: No matching signal for on_scanFinished()
|
KPortScan3.exe | QMetaObject::connectSlotsByName: No matching signal for on_timeout()
|
KPortScan3.exe | QMetaObject::connectSlotsByName: No matching signal for on_stop()
|
KPortScan3.exe | QMetaObject::connectSlotsByName: No matching signal for on_loadFinished(QNetworkReply*)
|
KPortScan3.exe | QMetaObject::connectSlotsByName: No matching signal for on_scanDiapFinished()
|
KPortScan3.exe | QMetaObject::connectSlotsByName: No matching signal for on_scanFinished()
|
KPortScan3.exe | QMetaObject::connectSlotsByName: No matching signal for on_result(QStri냦ы쿅䃑ǖ끚ыQMetaObject::connectSlotsByName: No matching signal for on_timeout()
|
KPortScan3.exe | QMetaObject::connectSlotsByName: No matching signal for on_timeout()
|