| File name: | Native Instruments - Kontakt 7 v7.3.2 (bobdule).rar |
| Full analysis: | https://app.any.run/tasks/6a683d4f-d9f8-4cc2-8652-6daabf268bc6 |
| Verdict: | Malicious activity |
| Analysis date: | June 20, 2023, 11:30:04 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-rar |
| File info: | RAR archive data, v5 |
| MD5: | A05D07F9535C0A099879CE1834D38D26 |
| SHA1: | 7E18110B23CACDC0E57CC7F2D01F4FBB6D17125D |
| SHA256: | 3E855E6C8AA21587DAE35AE1A309763204DF6C9F7228E43B5397630036447EFD |
| SSDEEP: | 196608:eovaokLkySNcMKzd9bRTRyvLHy8TqYwO8BjGveIVJexpr1/nJmxl97WvQUE3/lTv:9vaL91TRf8elOHW+gG7CGlTXIqm/pi |
| .rar | | | RAR compressed archive (v5.0) (61.5) |
|---|---|---|
| .rar | | | RAR compressed archive (gen) (38.4) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 676 | "C:\Users\admin\Desktop\Kontakt 7.3.2 Patcher.exe" | C:\Users\admin\Desktop\Kontakt 7.3.2 Patcher.exe | explorer.exe | ||||||||||||
User: admin Company: Native Instruments Integrity Level: HIGH Description: Kontakt 7.3.2 Full Options Patcher Exit code: 3221225547 Version: 7.3.2.0 Modules
| |||||||||||||||
| 1464 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa2544.15121\Native Instruments - Kontakt 7 v7.3.2 (bobdule)\Kontakt 7.3.2 Patcher.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa2544.15121\Native Instruments - Kontakt 7 v7.3.2 (bobdule)\Kontakt 7.3.2 Patcher.exe | WinRAR.exe | ||||||||||||
User: admin Company: Native Instruments Integrity Level: HIGH Description: Kontakt 7.3.2 Full Options Patcher Exit code: 0 Version: 7.3.2.0 Modules
| |||||||||||||||
| 2468 | "C:\Users\admin\Desktop\Kontakt 7.3.2 Patcher.exe" | C:\Users\admin\Desktop\Kontakt 7.3.2 Patcher.exe | — | explorer.exe | |||||||||||
User: admin Company: Native Instruments Integrity Level: MEDIUM Description: Kontakt 7.3.2 Full Options Patcher Exit code: 3221226540 Version: 7.3.2.0 Modules
| |||||||||||||||
| 2544 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Native Instruments - Kontakt 7 v7.3.2 (bobdule).rar" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| 2988 | "C:\Users\admin\Desktop\Kontakt 7.3.2 Patcher.exe" | C:\Users\admin\Desktop\Kontakt 7.3.2 Patcher.exe | explorer.exe | ||||||||||||
User: admin Company: Native Instruments Integrity Level: HIGH Description: Kontakt 7.3.2 Full Options Patcher Exit code: 0 Version: 7.3.2.0 Modules
| |||||||||||||||
| 3568 | "C:\Users\admin\Desktop\Kontakt 7.3.2 Patcher.exe" | C:\Users\admin\Desktop\Kontakt 7.3.2 Patcher.exe | — | explorer.exe | |||||||||||
User: admin Company: Native Instruments Integrity Level: MEDIUM Description: Kontakt 7.3.2 Full Options Patcher Exit code: 3221226540 Version: 7.3.2.0 Modules
| |||||||||||||||
| 3740 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa2544.15121\Native Instruments - Kontakt 7 v7.3.2 (bobdule)\Kontakt 7.3.2 Patcher.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa2544.15121\Native Instruments - Kontakt 7 v7.3.2 (bobdule)\Kontakt 7.3.2 Patcher.exe | — | WinRAR.exe | |||||||||||
User: admin Company: Native Instruments Integrity Level: MEDIUM Description: Kontakt 7.3.2 Full Options Patcher Exit code: 3221226540 Version: 7.3.2.0 Modules
| |||||||||||||||
| (PID) Process: | (2544) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\16D\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2544) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip | |||
| (PID) Process: | (2544) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (2544) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop\phacker.zip | |||
| (PID) Process: | (2544) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (2544) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (2544) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (2544) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (676) Kontakt 7.3.2 Patcher.exe | Key: | HKEY_CURRENT_USER\Software\Native Instruments\ALSupport |
| Operation: | write | Name: | ExecutablePath |
Value: C:\Program Files\Native Instruments\Kontakt 7\Kontakt_Button.exe | |||
| (PID) Process: | (676) Kontakt 7.3.2 Patcher.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU |
| Operation: | write | Name: | NodeSlots |
Value: 0202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2544 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2544.15121\Native Instruments - Kontakt 7 v7.3.2 (bobdule)\Rutracker.nfo | text | |
MD5:96D222EC4DF8178BFB5E1CE269221976 | SHA256:BBFE3A060FBD016CA47EE5A64EEEBF20F780C419738EF8574BAD6039B9B793CF | |||
| 2544 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2544.10668\Native Instruments - Kontakt 7 v7.3.2 (bobdule)\Kontakt 7.3.2 Patcher.exe | executable | |
MD5:BE86CFE58D023B4D97918510848157AD | SHA256:05D6EAEF21EB9F501216602BA7449C2EE973BDE6CB3989F706102968C25DBC76 | |||
| 2544 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2544.15121\Native Instruments - Kontakt 7 v7.3.2 (bobdule)\Kontakt 7.3.2 Patcher.exe | executable | |
MD5:BE86CFE58D023B4D97918510848157AD | SHA256:05D6EAEF21EB9F501216602BA7449C2EE973BDE6CB3989F706102968C25DBC76 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1476 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
1076 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |