| File name: | idm.6.42.32_with_patch.rar |
| Full analysis: | https://app.any.run/tasks/05d6a913-f8a6-4a2a-b43e-ae2ee5fcfa58 |
| Verdict: | Malicious activity |
| Threats: | Stealers are a group of malicious software that are intended for gaining unauthorized access to users’ information and transferring it to the attacker. The stealer malware category includes various types of programs that focus on their particular kind of data, including files, passwords, and cryptocurrency. Stealers are capable of spying on their targets by recording their keystrokes and taking screenshots. This type of malware is primarily distributed as part of phishing campaigns. |
| Analysis date: | April 18, 2025, 14:48:49 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-rar |
| File info: | RAR archive data, v5 |
| MD5: | C94317F91C856D432E7789AA82BF6414 |
| SHA1: | 538434CAB3DBCFCFDA0F7E2DCD4923D0E6A31F6D |
| SHA256: | 4016514CD74A3580F33DE0012ABD8AE1ABDF6446A488AFC2B7A64AD2F1513448 |
| SSDEEP: | 98304:Gv9o/VhIaDiLe+CtFKHXAV/Z8Vc1Az2mYyY8jYRqLOh8jD3RXt4N/J6TKak7pxiS:EinESnAHqZJdpM1mudnho9mR3a |
| .rar | | | RAR compressed archive (v5.0) (61.5) |
|---|---|---|
| .rar | | | RAR compressed archive (gen) (38.4) |
| FileVersion: | RAR v5 |
|---|---|
| CompressedSize: | 3628352 |
| UncompressedSize: | 3628343 |
| OperatingSystem: | Win32 |
| ArchivedFileName: | IDM 6.42.32 Patch.rar |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 348 | C:\Users\admin\AppData\Local\Temp\wtmpd\t15447.exe i9dCxZ5SjH | C:\Users\admin\AppData\Local\Temp\wtmpd\t15447.exe | — | cmd.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 576 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3256.6.1335965278\1287632213" -childID 5 -isForBrowser -prefsHandle 1464 -prefMapHandle 3164 -prefsLen 29349 -prefMapSize 244371 -jsInitHandle 892 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {fd334935-08fd-44fc-ba07-e58374fbd64d} 3256 "\\.\pipe\gecko-crash-server-pipe.3256" 3244 1a0a79b0 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Version: 115.0.2 Modules
| |||||||||||||||
| 704 | "C:\Program Files\Internet Download Manager\idmBroker.exe" -RegServer | C:\Program Files\Internet Download Manager\idmBroker.exe | — | IDM1.tmp | |||||||||||
User: admin Company: Internet Download Manager, Tonec Inc. Integrity Level: HIGH Description: Broker for reading of IDM settings Exit code: 0 Version: 6, 35, 9, 1 Modules
| |||||||||||||||
| 1072 | C:\Windows\system32\cmd.exe /c ""C:\Users\admin\AppData\Local\Temp\wtmpd\t15421.bat" "C:\Users\admin\Desktop\IDM 6.42.32 Patch.exe" " | C:\Windows\System32\cmd.exe | — | IDM 6.42.32 Patch.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 1124 | "C:\Users\admin\Desktop\IDM 6.42.32 Patch.exe" | C:\Users\admin\Desktop\IDM 6.42.32 Patch.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: HIGH Modules
| |||||||||||||||
| 1324 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3256.5.875245593\781427180" -childID 4 -isForBrowser -prefsHandle 1948 -prefMapHandle 1876 -prefsLen 36100 -prefMapSize 244371 -jsInitHandle 892 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {1e3b455e-5a04-47b2-b2ee-86c111f89069} 3256 "\\.\pipe\gecko-crash-server-pipe.3256" 3392 192549b0 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Version: 115.0.2 Modules
| |||||||||||||||
| 1396 | "C:\Program Files\Mozilla Firefox\firefox.exe" https://www.internetdownloadmanager.com/support/installffextfrommozillasite.html | C:\Program Files\Mozilla Firefox\firefox.exe | — | IDMan.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: HIGH Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 1396 | "C:\Users\admin\Desktop\IDM 6.42.32 Patch.exe" | C:\Users\admin\Desktop\IDM 6.42.32 Patch.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 3221226540 Modules
| |||||||||||||||
| 1416 | "C:\Users\admin\Desktop\idman642build28.exe" | C:\Users\admin\Desktop\idman642build28.exe | explorer.exe | ||||||||||||
User: admin Company: Tonec Inc. Integrity Level: HIGH Description: Internet Download Manager installer Exit code: 0 Version: 6, 42, 28, 1 Modules
| |||||||||||||||
| 1592 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3256.3.1310669352\447199199" -childID 2 -isForBrowser -prefsHandle 2620 -prefMapHandle 2616 -prefsLen 34441 -prefMapSize 244371 -jsInitHandle 892 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {a7c7f101-9203-4c7d-897c-d84002a5371c} 3256 "\\.\pipe\gecko-crash-server-pipe.3256" 2632 176ba9b0 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Version: 115.0.2 Modules
| |||||||||||||||
| (PID) Process: | (2108) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (2108) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (2108) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2108) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (2108) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip | |||
| (PID) Process: | (2108) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\omni_23_10_2024_.zip | |||
| (PID) Process: | (2108) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\idm.6.42.32_with_patch.rar | |||
| (PID) Process: | (2108) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (2108) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (2108) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2384 | IDM1.tmp | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Download Manager\IDM Help.lnk | binary | |
MD5:FDE6B0DED58B610091D78D8FBDB14981 | SHA256:744C9A6BD0006A0A98D019909FD675F514CF4047C7B9E6788E47915E4A96A67C | |||
| 2384 | IDM1.tmp | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Download Manager\license.lnk | binary | |
MD5:A2AF162C1D3A1ED01CAA5994DEB5EC59 | SHA256:1F1FF073BEBA8FFDEAEE162B0A60A2CEEBBC405448EB2D5BE3062052B9686BCD | |||
| 2384 | IDM1.tmp | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Download Manager\TUTORIALS.lnk | binary | |
MD5:46E1A3E98D2C8E05CCB9B09CE776AE06 | SHA256:BE6654766739EE67DEEAF13DE1546BB0C5236855D8B0EEF82CC3761FF7846A5E | |||
| 2384 | IDM1.tmp | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Internet Download Manager\license.lnk | binary | |
MD5:97C1922E73F4E8909CEA59E99A364CB6 | SHA256:9B367CDFAE9A79550DA84092A11919EEC4A4719CB858576CB4DD2BE44361C146 | |||
| 2384 | IDM1.tmp | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Internet Download Manager\IDM Help.lnk | binary | |
MD5:D571A1862875B82DB535417A832C940E | SHA256:3D9F01E4ABE4F68C012980215512FA82D5AE430AAAA9CD46D08B542ADC7EFC47 | |||
| 2108 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb2108.5606\idman642build28.exe | executable | |
MD5:BD146DC9B93E39A11ED1BA7AB5429898 | SHA256:F34CDED028D1F729FD872EF8BC813FAC24CC1A955A9C06D98F7A43A5A0D75D06 | |||
| 2384 | IDM1.tmp | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Download Manager\Uninstall IDM.lnk | binary | |
MD5:CE399777E9023283C9B710B232E27EA6 | SHA256:FFC393E5F7D7DA55335C2F72DE1C0A231CAE647FDEE6B0B7BE870726767BB74D | |||
| 2384 | IDM1.tmp | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Internet Download Manager\Uninstall IDM.lnk | binary | |
MD5:2EE1D54606680A76A8EC838F83D68678 | SHA256:02ED86605DE87E19E7095C6C7D07827B6DA6034F96A1959303910E6A2CC26DD5 | |||
| 2384 | IDM1.tmp | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Internet Download Manager\Internet Download Manager.lnk | binary | |
MD5:12F251F3C3EEDA593CF25CE62A3A5841 | SHA256:8A84B5661AF219489205B2F327E16C8EBF3A71F2A095132384EC8452819A286E | |||
| 2384 | IDM1.tmp | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Download Manager\Internet Download Manager.lnk | binary | |
MD5:51911FC1E67AFE2AE93FE5F456D3EE9B | SHA256:DE124A56429691A4D5248A76813B107236B8E05AC7BA2C5F2648393040711818 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2356 | IDMan.exe | GET | 200 | 88.221.110.91:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?19454423c030c89d | unknown | — | — | whitelisted |
3256 | firefox.exe | POST | 200 | 2.22.242.225:80 | http://r11.o.lencr.org/ | unknown | — | — | whitelisted |
3256 | firefox.exe | POST | 200 | 172.217.18.99:80 | http://o.pki.goog/we2 | unknown | — | — | whitelisted |
3256 | firefox.exe | POST | 200 | 172.217.18.99:80 | http://o.pki.goog/we2 | unknown | — | — | whitelisted |
3256 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/canonical.html | unknown | — | — | whitelisted |
3256 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/success.txt?ipv4 | unknown | — | — | whitelisted |
3256 | firefox.exe | POST | 200 | 18.173.205.76:80 | http://ocsps.ssl.com/ | unknown | — | — | whitelisted |
3256 | firefox.exe | POST | 200 | 18.173.205.76:80 | http://ocsps.ssl.com/ | unknown | — | — | whitelisted |
3256 | firefox.exe | POST | 200 | 2.22.242.121:80 | http://r10.o.lencr.org/ | unknown | — | — | whitelisted |
3256 | firefox.exe | POST | 200 | 172.217.18.99:80 | http://o.pki.goog/we2 | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 224.0.0.252:5355 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | whitelisted |
2356 | IDMan.exe | 88.221.110.91:80 | ctldl.windowsupdate.com | Akamai International B.V. | DE | whitelisted |
3256 | firefox.exe | 169.61.27.133:443 | secure.internetdownloadmanager.com | SOFTLAYER | US | whitelisted |
3256 | firefox.exe | 34.107.221.82:80 | detectportal.firefox.com | GOOGLE | US | whitelisted |
3256 | firefox.exe | 34.36.137.203:443 | contile.services.mozilla.com | GOOGLE-CLOUD-PLATFORM | US | whitelisted |
3256 | firefox.exe | 18.173.205.76:80 | ocsps.ssl.com | — | US | whitelisted |
3256 | firefox.exe | 2.22.242.225:80 | r11.o.lencr.org | Akamai International B.V. | DE | whitelisted |
Domain | IP | Reputation |
|---|---|---|
google.com |
| whitelisted |
ctldl.windowsupdate.com |
| whitelisted |
test.internetdownloadmanager.com |
| whitelisted |
secure.internetdownloadmanager.com |
| whitelisted |
www.internetdownloadmanager.com |
| whitelisted |
mirror3.internetdownloadmanager.com |
| whitelisted |
mirror5.internetdownloadmanager.com |
| whitelisted |
registeridm.com |
| unknown |
detectportal.firefox.com |
| whitelisted |
prod.detectportal.prod.cloudops.mozgcp.net |
| whitelisted |