File name:

Win 10 Tweaker Pro 15.2 MOD Portable.7z

Full analysis: https://app.any.run/tasks/0c95ae8f-aeb6-4a68-89cf-974e9c4cbb74
Verdict: Malicious activity
Analysis date: November 16, 2019, 22:26:04
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-7z-compressed
File info: 7-zip archive data, version 0.4
MD5:

826234122DBDC122DC2423BEEF43881C

SHA1:

BEE7CDD4DCD850D74B9D62B3D0AA8D619DF230FA

SHA256:

4107A9C527BF648B942554C8AE69F80BB32FC635301F2B1440143686DB99095A

SSDEEP:

12288:SVrYqg0buhfUn7b8bI2dToz4TOQwImaUAdE1WcZCppvWgZNiyqNSqC6yUbhjhM+Q:SvbbuJQh2dskVTUAShqpxZqNSMjM+LjY

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • Win10TweakerPort.exe (PID: 1956)
      • Win10TweakerPort.exe (PID: 2476)
      • Win10TweakerNoF8Port.exe (PID: 1296)
      • Win10TweakerNoF8Port.exe (PID: 2200)
    • Uses Task Scheduler to run other applications

      • cmd.exe (PID: 3356)
      • cmd.exe (PID: 3808)
      • cmd.exe (PID: 3836)
      • cmd.exe (PID: 2864)
    • Loads the Task Scheduler COM API

      • schtasks.exe (PID: 1536)
      • schtasks.exe (PID: 184)
      • schtasks.exe (PID: 2152)
      • schtasks.exe (PID: 444)
    • Changes settings of System certificates

      • Win 10 Tweaker.exe (PID: 2820)
  • SUSPICIOUS

    • Application launched itself

      • Win10TweakerPort.exe (PID: 1956)
      • Win10TweakerNoF8Port.exe (PID: 1296)
    • Executable content was dropped or overwritten

      • Win10TweakerPort.exe (PID: 1956)
      • Win10TweakerPort.exe (PID: 2476)
      • Win10TweakerNoF8Port.exe (PID: 1296)
      • Win10TweakerNoF8Port.exe (PID: 2200)
    • Writes to a desktop.ini file (may be used to cloak folders)

      • WinRAR.exe (PID: 2524)
      • Win10TweakerPort.exe (PID: 2476)
      • Win10TweakerNoF8Port.exe (PID: 2200)
    • Reads Environment values

      • Win 10 Tweaker.exe (PID: 2992)
      • Win 10 Tweaker.exe (PID: 2820)
    • Reads CPU info

      • Win 10 Tweaker.exe (PID: 2992)
      • Win 10 Tweaker.exe (PID: 2820)
    • Starts CMD.EXE for commands execution

      • Win 10 Tweaker.exe (PID: 2992)
      • Win 10 Tweaker.exe (PID: 2820)
    • Starts application with an unusual extension

      • cmd.exe (PID: 3356)
      • cmd.exe (PID: 3808)
      • cmd.exe (PID: 3836)
      • cmd.exe (PID: 2864)
    • Reads mouse settings

      • Win 10 Tweaker.exe (PID: 2992)
      • Win 10 Tweaker.exe (PID: 2820)
    • Uses NETSH.EXE for network configuration

      • cmd.exe (PID: 3940)
      • cmd.exe (PID: 2096)
    • Uses TASKKILL.EXE to kill process

      • cmd.exe (PID: 1800)
    • Executes PowerShell scripts

      • Win 10 Tweaker.exe (PID: 2992)
      • Win 10 Tweaker.exe (PID: 2820)
    • Creates files in the user directory

      • powershell.exe (PID: 3408)
      • powershell.exe (PID: 332)
      • Win 10 Tweaker.exe (PID: 2820)
    • Reads Internet Cache Settings

      • Win 10 Tweaker.exe (PID: 2820)
    • Adds / modifies Windows certificates

      • Win 10 Tweaker.exe (PID: 2820)
    • Reads internet explorer settings

      • Win 10 Tweaker.exe (PID: 2820)
  • INFO

    • Manual execution by user

      • Win10TweakerPort.exe (PID: 1956)
      • Win10TweakerNoF8Port.exe (PID: 1296)
    • Reads the hosts file

      • Win 10 Tweaker.exe (PID: 2992)
      • Win 10 Tweaker.exe (PID: 2820)
    • Reads settings of System Certificates

      • Win 10 Tweaker.exe (PID: 2820)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.7z | 7-Zip compressed archive (v0.4) (57.1)
.7z | 7-Zip compressed archive (gen) (42.8)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
80
Monitored processes
27
Malicious processes
6
Suspicious processes
4

Behavior graph

Click at the process to see the details
start winrar.exe no specs win10tweakerport.exe win10tweakerport.exe win 10 tweaker.exe no specs cmd.exe no specs chcp.com no specs schtasks.exe no specs cmd.exe no specs chcp.com no specs schtasks.exe no specs cmd.exe no specs netsh.exe no specs powershell.exe no specs cmd.exe no specs taskkill.exe no specs win10tweakernof8port.exe win10tweakernof8port.exe win 10 tweaker.exe cmd.exe no specs chcp.com no specs schtasks.exe no specs cmd.exe no specs chcp.com no specs schtasks.exe no specs cmd.exe no specs netsh.exe no specs powershell.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
184schtasks /TN \Microsoft\Windows\MemoryDiagnostic\CorruptionDetectorC:\Windows\system32\schtasks.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Manages scheduled tasks
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\schtasks.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
332"powershell" -command Get-PhysicalDisk | select FriendlyName,MediaTypeC:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeWin 10 Tweaker.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows PowerShell
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\atl.dll
c:\windows\system32\user32.dll
444schtasks /TN \Microsoft\Windows\MemoryDiagnostic\CorruptionDetectorC:\Windows\system32\schtasks.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Manages scheduled tasks
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\schtasks.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
1152netsh int ipv6 isatap show stateC:\Windows\system32\netsh.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Network Command Shell
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\netsh.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\credui.dll
c:\windows\system32\user32.dll
1212chcp 65001 C:\Windows\system32\chcp.comcmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Change CodePage Utility
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\chcp.com
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ulib.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
1296"C:\Users\admin\Desktop\Win 10 Tweaker Pro 15.2 MOD Portable\Win10TweakerNoF8Port.exe" C:\Users\admin\Desktop\Win 10 Tweaker Pro 15.2 MOD Portable\Win10TweakerNoF8Port.exe
explorer.exe
User:
admin
Company:
Zeka
Integrity Level:
MEDIUM
Description:
Win 10 Tweaker Portable
Exit code:
0
Version:
2.2.1.0
Modules
Images
c:\users\admin\desktop\win 10 tweaker pro 15.2 mod portable\win10tweakernof8port.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
1536schtasks /TN \Microsoft\Windows\Maintenance\WinSATC:\Windows\system32\schtasks.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Manages scheduled tasks
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\schtasks.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
1800"C:\Windows\System32\cmd.exe" /c taskkill /f /pid "2992"C:\Windows\System32\cmd.exeWin 10 Tweaker.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1880taskkill /f /pid "2992"C:\Windows\system32\taskkill.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Terminates Processes
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskkill.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
1956"C:\Users\admin\Desktop\Win 10 Tweaker Pro 15.2 MOD Portable\Win10TweakerPort.exe" C:\Users\admin\Desktop\Win 10 Tweaker Pro 15.2 MOD Portable\Win10TweakerPort.exe
explorer.exe
User:
admin
Company:
Zeka
Integrity Level:
MEDIUM
Description:
Win 10 Tweaker Portable
Exit code:
1223
Version:
2.2.1.0
Modules
Images
c:\users\admin\desktop\win 10 tweaker pro 15.2 mod portable\win10tweakerport.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
Total events
10 421
Read events
10 129
Write events
290
Delete events
2

Modification events

(PID) Process:(2524) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2524) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2524) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2524) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Win 10 Tweaker Pro 15.2 MOD Portable.7z
(PID) Process:(2524) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2524) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2524) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2524) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2476) Win10TweakerPort.exeKey:HKEY_CURRENT_USER\Software\Win 10 Tweaker
Operation:writeName:First Run
Value:
true
(PID) Process:(2476) Win10TweakerPort.exeKey:HKEY_CURRENT_USER\Software\Win 10 Tweaker
Operation:writeName:Auto Update
Value:
false
Executable files
10
Suspicious files
5
Text files
18
Unknown types
1

Dropped files

PID
Process
Filename
Type
2524WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2524.19831\Win 10 Tweaker Pro 15.2 MOD Portable\App\AppInfo\appicon.ico
MD5:
SHA256:
2524WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2524.19831\Win 10 Tweaker Pro 15.2 MOD Portable\App\AppInfo\appinfo.ini
MD5:
SHA256:
2524WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2524.19831\Win 10 Tweaker Pro 15.2 MOD Portable\App\AppInfo\Launcher\Win10TweakerNoF8Port.ini
MD5:
SHA256:
2524WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2524.19831\Win 10 Tweaker Pro 15.2 MOD Portable\App\AppInfo\Launcher\Win10TweakerPort.ini
MD5:
SHA256:
2524WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2524.19831\Win 10 Tweaker Pro 15.2 MOD Portable\App\DefaultData\settings\Win10Tweaker.reg
MD5:
SHA256:
2524WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2524.19831\Win 10 Tweaker Pro 15.2 MOD Portable\desktop.ini
MD5:
SHA256:
2524WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2524.19831\Win 10 Tweaker Pro 15.2 MOD Portable\Внимание.txt
MD5:
SHA256:
2524WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2524.19831\Win 10 Tweaker Pro 15.2 MOD Portable\Описание.txt
MD5:
SHA256:
2524WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2524.19831\Win 10 Tweaker Pro 15.2 MOD Portable\App\Tweaker\Win 10 Tweaker.exe
MD5:
SHA256:
2524WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2524.19831\Win 10 Tweaker Pro 15.2 MOD Portable\Win10TweakerNoF8Port.exe
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
3
DNS requests
2
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2820
Win 10 Tweaker.exe
216.58.207.36:443
www.google.com
Google Inc.
US
whitelisted
2820
Win 10 Tweaker.exe
87.236.16.98:443
jailbreakvideo.ru
Beget Ltd
RU
suspicious

DNS requests

Domain
IP
Reputation
www.google.com
  • 216.58.207.36
malicious
jailbreakvideo.ru
  • 87.236.16.98
suspicious

Threats

No threats detected
No debug info