File name: | Native Instruments - Kontakt 7 v7.3.2 (bobdule).rar |
Full analysis: | https://app.any.run/tasks/6a683d4f-d9f8-4cc2-8652-6daabf268bc6 |
Verdict: | Malicious activity |
Analysis date: | June 20, 2023, 11:30:04 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | application/x-rar |
File info: | RAR archive data, v5 |
MD5: | A05D07F9535C0A099879CE1834D38D26 |
SHA1: | 7E18110B23CACDC0E57CC7F2D01F4FBB6D17125D |
SHA256: | 3E855E6C8AA21587DAE35AE1A309763204DF6C9F7228E43B5397630036447EFD |
SSDEEP: | 196608:eovaokLkySNcMKzd9bRTRyvLHy8TqYwO8BjGveIVJexpr1/nJmxl97WvQUE3/lTv:9vaL91TRf8elOHW+gG7CGlTXIqm/pi |
.rar | | | RAR compressed archive (v5.0) (61.5) |
---|---|---|
.rar | | | RAR compressed archive (gen) (38.4) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
676 | "C:\Users\admin\Desktop\Kontakt 7.3.2 Patcher.exe" | C:\Users\admin\Desktop\Kontakt 7.3.2 Patcher.exe | explorer.exe | ||||||||||||
User: admin Company: Native Instruments Integrity Level: HIGH Description: Kontakt 7.3.2 Full Options Patcher Exit code: 3221225547 Version: 7.3.2.0 Modules
| |||||||||||||||
1464 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa2544.15121\Native Instruments - Kontakt 7 v7.3.2 (bobdule)\Kontakt 7.3.2 Patcher.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa2544.15121\Native Instruments - Kontakt 7 v7.3.2 (bobdule)\Kontakt 7.3.2 Patcher.exe | WinRAR.exe | ||||||||||||
User: admin Company: Native Instruments Integrity Level: HIGH Description: Kontakt 7.3.2 Full Options Patcher Exit code: 0 Version: 7.3.2.0 Modules
| |||||||||||||||
2468 | "C:\Users\admin\Desktop\Kontakt 7.3.2 Patcher.exe" | C:\Users\admin\Desktop\Kontakt 7.3.2 Patcher.exe | — | explorer.exe | |||||||||||
User: admin Company: Native Instruments Integrity Level: MEDIUM Description: Kontakt 7.3.2 Full Options Patcher Exit code: 3221226540 Version: 7.3.2.0 Modules
| |||||||||||||||
2544 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Native Instruments - Kontakt 7 v7.3.2 (bobdule).rar" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
2988 | "C:\Users\admin\Desktop\Kontakt 7.3.2 Patcher.exe" | C:\Users\admin\Desktop\Kontakt 7.3.2 Patcher.exe | explorer.exe | ||||||||||||
User: admin Company: Native Instruments Integrity Level: HIGH Description: Kontakt 7.3.2 Full Options Patcher Exit code: 0 Version: 7.3.2.0 Modules
| |||||||||||||||
3568 | "C:\Users\admin\Desktop\Kontakt 7.3.2 Patcher.exe" | C:\Users\admin\Desktop\Kontakt 7.3.2 Patcher.exe | — | explorer.exe | |||||||||||
User: admin Company: Native Instruments Integrity Level: MEDIUM Description: Kontakt 7.3.2 Full Options Patcher Exit code: 3221226540 Version: 7.3.2.0 Modules
| |||||||||||||||
3740 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa2544.15121\Native Instruments - Kontakt 7 v7.3.2 (bobdule)\Kontakt 7.3.2 Patcher.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa2544.15121\Native Instruments - Kontakt 7 v7.3.2 (bobdule)\Kontakt 7.3.2 Patcher.exe | — | WinRAR.exe | |||||||||||
User: admin Company: Native Instruments Integrity Level: MEDIUM Description: Kontakt 7.3.2 Full Options Patcher Exit code: 3221226540 Version: 7.3.2.0 Modules
|
(PID) Process: | (2544) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\16D\52C64B7E |
Operation: | write | Name: | LanguageList |
Value: en-US | |||
(PID) Process: | (2544) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip | |||
(PID) Process: | (2544) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
(PID) Process: | (2544) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop\phacker.zip | |||
(PID) Process: | (2544) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | name |
Value: 120 | |||
(PID) Process: | (2544) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | size |
Value: 80 | |||
(PID) Process: | (2544) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | type |
Value: 120 | |||
(PID) Process: | (2544) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | mtime |
Value: 100 | |||
(PID) Process: | (676) Kontakt 7.3.2 Patcher.exe | Key: | HKEY_CURRENT_USER\Software\Native Instruments\ALSupport |
Operation: | write | Name: | ExecutablePath |
Value: C:\Program Files\Native Instruments\Kontakt 7\Kontakt_Button.exe | |||
(PID) Process: | (676) Kontakt 7.3.2 Patcher.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU |
Operation: | write | Name: | NodeSlots |
Value: 0202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202 |
PID | Process | Filename | Type | |
---|---|---|---|---|
2544 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2544.15121\Native Instruments - Kontakt 7 v7.3.2 (bobdule)\Kontakt 7.3.2 Patcher.exe | executable | |
MD5:BE86CFE58D023B4D97918510848157AD | SHA256:05D6EAEF21EB9F501216602BA7449C2EE973BDE6CB3989F706102968C25DBC76 | |||
2544 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2544.15121\Native Instruments - Kontakt 7 v7.3.2 (bobdule)\Rutracker.nfo | text | |
MD5:96D222EC4DF8178BFB5E1CE269221976 | SHA256:BBFE3A060FBD016CA47EE5A64EEEBF20F780C419738EF8574BAD6039B9B793CF | |||
2544 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2544.10668\Native Instruments - Kontakt 7 v7.3.2 (bobdule)\Kontakt 7.3.2 Patcher.exe | executable | |
MD5:BE86CFE58D023B4D97918510848157AD | SHA256:05D6EAEF21EB9F501216602BA7449C2EE973BDE6CB3989F706102968C25DBC76 |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1476 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
1076 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |