File name:

Internet Download Manager 6.42 Build 3 Silent Install mshaz1000.exe

Full analysis: https://app.any.run/tasks/dad51fcb-0d81-49ab-a037-6a13bdb29e6a
Verdict: Malicious activity
Analysis date: May 16, 2025, 18:10:02
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
upx
inno
installer
delphi
idm
tool
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed, 3 sections
MD5:

8455FF7C944189CA42161FFB36838848

SHA1:

39DC2E48639A8843DAEDD709D07E521F114A820B

SHA256:

44ACFC6B249D38C56C2533781D5CC538339D57C361D8D9A947E2CA2C7765F7E0

SSDEEP:

98304:DR9QXByu08/oJyYZUmqmgSRT5rhe4fA4+NN84Y7VhhNXydfbRKzSbdnUfNwYRdf4://VxWn0Jyw5DjsZ6ZhiNiDqt/upc

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Registers / Runs the DLL via REGSVR32.EXE

      • Internet.tmp (PID: 752)
    • Changes the autorun value in the registry

      • rundll32.exe (PID: 3372)
    • Starts NET.EXE for service management

      • Uninstall.exe (PID: 3792)
      • net.exe (PID: 116)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • Internet Download Manager 6.42 Build 3 Silent Install mshaz1000.exe (PID: 2396)
      • Uninstall.exe (PID: 3792)
    • Executable content was dropped or overwritten

      • Internet Download Manager 6.42 Build 3 Silent Install mshaz1000.exe (PID: 2396)
      • Internet.exe (PID: 1800)
      • Internet.tmp (PID: 752)
      • rundll32.exe (PID: 3372)
    • Reads the Internet Settings

      • Internet Download Manager 6.42 Build 3 Silent Install mshaz1000.exe (PID: 2396)
      • runonce.exe (PID: 3600)
      • Uninstall.exe (PID: 3792)
      • IDMan.exe (PID: 1488)
    • Reads the Windows owner or organization settings

      • Internet.tmp (PID: 752)
    • Process drops legitimate windows executable

      • Internet.tmp (PID: 752)
    • Drops a system driver (possible attempt to evade defenses)

      • Internet.tmp (PID: 752)
      • rundll32.exe (PID: 3372)
    • There is functionality for taking screenshot (YARA)

      • Internet Download Manager 6.42 Build 3 Silent Install mshaz1000.exe (PID: 2396)
      • IDMan.exe (PID: 1488)
    • Creates/Modifies COM task schedule object

      • regsvr32.exe (PID: 3856)
      • regsvr32.exe (PID: 972)
      • regsvr32.exe (PID: 2832)
      • regsvr32.exe (PID: 3116)
      • regsvr32.exe (PID: 1440)
      • Uninstall.exe (PID: 3792)
      • IDMan.exe (PID: 1488)
    • Starts CMD.EXE for commands execution

      • Internet.tmp (PID: 752)
    • Uses RUNDLL32.EXE to load library

      • Uninstall.exe (PID: 3792)
      • Internet.tmp (PID: 752)
    • Creates or modifies Windows services

      • Uninstall.exe (PID: 3792)
    • Uses REG/REGEDIT.EXE to modify registry

      • cmd.exe (PID: 3124)
      • Internet.tmp (PID: 752)
    • Executing commands from a ".bat" file

      • Internet.tmp (PID: 752)
    • Uses TASKKILL.EXE to kill process

      • Internet.tmp (PID: 752)
  • INFO

    • Checks supported languages

      • Internet Download Manager 6.42 Build 3 Silent Install mshaz1000.exe (PID: 2396)
      • Internet.tmp (PID: 752)
      • Internet.exe (PID: 1800)
      • Uninstall.exe (PID: 3792)
      • IDMan.exe (PID: 1488)
      • idmBroker.exe (PID: 1332)
    • Create files in a temporary directory

      • Internet.exe (PID: 1800)
      • Internet Download Manager 6.42 Build 3 Silent Install mshaz1000.exe (PID: 2396)
      • Internet.tmp (PID: 752)
      • IDMan.exe (PID: 1488)
    • The sample compiled with russian language support

      • Internet Download Manager 6.42 Build 3 Silent Install mshaz1000.exe (PID: 2396)
      • Internet.tmp (PID: 752)
    • Reads the computer name

      • Internet Download Manager 6.42 Build 3 Silent Install mshaz1000.exe (PID: 2396)
      • Internet.tmp (PID: 752)
      • Uninstall.exe (PID: 3792)
      • IDMan.exe (PID: 1488)
    • The sample compiled with english language support

      • Internet.tmp (PID: 752)
      • rundll32.exe (PID: 3372)
    • Creates files in the program directory

      • Internet.tmp (PID: 752)
      • IDMan.exe (PID: 1488)
    • UPX packer has been detected

      • Internet Download Manager 6.42 Build 3 Silent Install mshaz1000.exe (PID: 2396)
    • Compiled with Borland Delphi (YARA)

      • Internet.tmp (PID: 752)
    • Creates files or folders in the user directory

      • Internet.tmp (PID: 752)
      • IDMan.exe (PID: 1488)
    • Creates a software uninstall entry

      • Internet.tmp (PID: 752)
    • Detects InnoSetup installer (YARA)

      • Internet.exe (PID: 1800)
      • Internet.tmp (PID: 752)
    • Creates files in the driver directory

      • rundll32.exe (PID: 3372)
    • Reads the time zone

      • runonce.exe (PID: 3600)
    • Reads security settings of Internet Explorer

      • runonce.exe (PID: 3600)
    • Disables trace logs

      • IDMan.exe (PID: 1488)
    • INTERNETDOWNLOADMANAGER mutex has been found

      • IDMan.exe (PID: 1488)
    • Reads the machine GUID from the registry

      • IDMan.exe (PID: 1488)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic Win/DOS Executable (50)
.exe | DOS Executable Generic (49.9)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2012:12:31 00:38:51+00:00
ImageFileCharacteristics: No relocs, Executable, 32-bit
PEType: PE32
LinkerVersion: 8
CodeSize: 65536
InitializedDataSize: 147456
UninitializedDataSize: 233472
EntryPoint: 0x48a70
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 6.42.3.0
ProductVersionNumber: 6.42.3.0
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Unknown
FileSubtype: -
LanguageCode: Russian
CharacterSet: Unicode
CompanyName: mshaz1000
FileDescription: Internet Download Manager 6.42 Build 3
LegalCopyright: -
LegalTrademarks: -
InternalName: -
ProductName: -
OriginalFileName: -
FileVersion: 6.42.3
ProductVersion: 6.42.3
Comments: -
PrivateBuild: -
SpecialBuild: -
No data.
screenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
149
Monitored processes
109
Malicious processes
6
Suspicious processes
1

Behavior graph

Click at the process to see the details
start internet download manager 6.42 build 3 silent install mshaz1000.exe internet.exe internet.tmp regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs cmd.exe no specs regini.exe no specs regini.exe no specs regini.exe no specs regini.exe no specs regini.exe no specs regini.exe no specs regini.exe no specs regini.exe no specs regini.exe no specs regini.exe no specs regini.exe no specs regini.exe no specs regini.exe no specs regini.exe no specs regini.exe no specs regini.exe no specs regini.exe no specs regini.exe no specs regini.exe no specs regini.exe no specs regini.exe no specs regini.exe no specs regini.exe no specs regini.exe no specs regini.exe no specs regini.exe no specs regini.exe no specs regini.exe no specs regini.exe no specs regini.exe no specs regini.exe no specs regini.exe no specs regini.exe no specs regini.exe no specs regini.exe no specs regini.exe no specs regini.exe no specs regini.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs regedit.exe rundll32.exe no specs uninstall.exe no specs rundll32.exe runonce.exe no specs grpconv.exe no specs net.exe no specs net1.exe no specs idmbroker.exe no specs taskkill.exe no specs regedit.exe no specs regedit.exe taskkill.exe no specs idman.exe no specs internet download manager 6.42 build 3 silent install mshaz1000.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
116"C:\Windows\System32\net.exe" start IDMWFPC:\Windows\System32\net.exeUninstall.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Net Command
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\net.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\netutils.dll
c:\windows\system32\browcli.dll
148regini "permdel.txt"C:\Windows\System32\regini.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Registry Initializer
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\regini.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
608reg delete "HKCU\Software\DownloadManager" /v "FName" /FC:\Windows\System32\reg.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Registry Console Tool
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\reg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
752"C:\Users\admin\AppData\Local\Temp\is-KK7H7.tmp\Internet.tmp" /SL5="$40154,14763386,64512,C:\Users\admin\AppData\Local\Temp\7ZipSfx.000\Internet.exe" /SILENT, /VERYSILENT /SUPPRESSMSGBOXES /MERGETASKS=desktopicon,fileassocC:\Users\admin\AppData\Local\Temp\is-KK7H7.tmp\Internet.tmp
Internet.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Version:
51.52.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-kk7h7.tmp\internet.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
764reg delete "HKCU\Software\Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}" /FC:\Windows\System32\reg.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Registry Console Tool
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\reg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
780"C:\Windows\regedit.exe" /S "C:\Users\admin\AppData\Local\Temp\7ZipSfx.000\settings.reg"C:\Windows\regedit.exe
Internet.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Registry Editor
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\regedit.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
848reg delete "HKLM\Software\Classes\CLSID\{07999AC3-058B-40BF-984F-69EB1E554CA7}" /FC:\Windows\System32\reg.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Registry Console Tool
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\reg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
948regini "permdel.txt"C:\Windows\System32\regini.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Registry Initializer
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\regini.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
960C:\Windows\system32\net1 start IDMWFPC:\Windows\System32\net1.exenet.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Net Command
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\net1.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dsrole.dll
c:\windows\system32\netutils.dll
972"C:\Windows\system32\regsvr32.exe" /s "C:\Program Files\Internet Download Manager\downlWithIDM.dll"C:\Windows\System32\regsvr32.exeInternet.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
6 539
Read events
6 184
Write events
250
Delete events
105

Modification events

(PID) Process:(752) Internet.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
F002000058688AC48DC6DB01
(PID) Process:(752) Internet.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:SessionHash
Value:
BFD20241053D9D36CDA572323C74B10579F8C7EB4AF2B7AD63360AC329841F9B
(PID) Process:(752) Internet.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Sequence
Value:
1
(PID) Process:(2396) Internet Download Manager 6.42 Build 3 Silent Install mshaz1000.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2396) Internet Download Manager 6.42 Build 3 Silent Install mshaz1000.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(2396) Internet Download Manager 6.42 Build 3 Silent Install mshaz1000.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(2396) Internet Download Manager 6.42 Build 3 Silent Install mshaz1000.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(752) Internet.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:RegFiles0000
Value:
C:\Program Files\Internet Download Manager\KGIDM.dll
(PID) Process:(752) Internet.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:RegFilesHash
Value:
D417D3D1471BEE61704FA5545100EDCE1A3953CDFF92EB15B3F0867C2D35D164
(PID) Process:(3856) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{98D060EC-53AF-4F61-8180-43C507C9FF94}\TypeLib
Operation:writeName:Version
Value:
1.0
Executable files
97
Suspicious files
89
Text files
729
Unknown types
1

Dropped files

PID
Process
Filename
Type
1800Internet.exeC:\Users\admin\AppData\Local\Temp\is-KK7H7.tmp\Internet.tmpexecutable
MD5:4A6C1B37772B488D1BDFF1EB6E589118
SHA256:109E48992F332DDDE3F2FF8EA6459F11EFF3D7968DAB4951DC96ED7507F1BBF6
752Internet.tmpC:\Program Files\Internet Download Manager\is-EJ6MC.tmpexecutable
MD5:B51A9AFE694FE53BCA3AE78B3CC16639
SHA256:4AE0AA62B7F84F92A1BD52DC43F50485F1E0C6BF4F6D672943F75D4DB5A7A13A
2396Internet Download Manager 6.42 Build 3 Silent Install mshaz1000.exeC:\Users\admin\AppData\Local\Temp\7ZipSfx.000\Internet.exeexecutable
MD5:1003BC34AAB3D2662E1B2E9A9BB4E26B
SHA256:57C2B8BA95EF42383CF4BB48BC7E0BFA1A773CC7098CD4A7D7B33BB022D0BACB
752Internet.tmpC:\Users\admin\AppData\Local\Temp\is-26VSK.tmp\_isetup\_shfoldr.dllexecutable
MD5:92DC6EF532FBB4A5C3201469A5B5EB63
SHA256:9884E9D1B4F8A873CCBD81F8AD0AE257776D2348D027D811A56475E028360D87
2396Internet Download Manager 6.42 Build 3 Silent Install mshaz1000.exeC:\Users\admin\AppData\Local\Temp\7ZipSfx.000\Reg.regtext
MD5:409BF1F8D615B5B53D7C4C7FC30C59FA
SHA256:521088BBED90A170E194922CBE505F91C313B3F899E02ED379FB271506541284
752Internet.tmpC:\Program Files\Internet Download Manager\defexclist.txttext
MD5:A4F4CC7C56FCDD15B24940135EAEE001
SHA256:13CC5076572FCFDF10EEF7A1A33BEC318F8428E331A0824EEBB692770AA00008
752Internet.tmpC:\Users\admin\AppData\Local\Temp\is-26VSK.tmp\VclStylesInno.dllexecutable
MD5:B0CA93CEB050A2FEFF0B19E65072BBB5
SHA256:0E93313F42084D804B9AC4BE53D844E549CFCAF19E6F276A3B0F82F01B9B2246
752Internet.tmpC:\Users\admin\AppData\Local\Temp\is-26VSK.tmp\MetroBlue.vsfbinary
MD5:295D085196B3DA13BFCD53373F82F8EE
SHA256:CBDC95EB9E7269E0C3E3BDDFD37B0918962795D80BDBA932E46EA16FF5E6CDBF
752Internet.tmpC:\Users\admin\AppData\Local\Temp\is-26VSK.tmp\_isetup\_RegDLL.tmpexecutable
MD5:0EE914C6F0BB93996C75941E1AD629C6
SHA256:4DC09BAC0613590F1FAC8771D18AF5BE25A1E1CB8FDBF4031AA364F3057E74A2
752Internet.tmpC:\Users\admin\AppData\Local\Temp\is-26VSK.tmp\WizardForm.BitmapImage1.bmpimage
MD5:48386BC24D46A3FAC0056AB765A597A1
SHA256:55E4D15D42D4983C2D3A4E0ABD07EFF703929FAE4DD33115F008BE346D501036
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
5
DNS requests
1
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
224.0.0.252:5355
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 172.217.16.206
whitelisted

Threats

No threats detected
Process
Message
regedit.exe
REGEDIT: CreateFile failed, GetLastError() = 2
regedit.exe
REGEDIT: CreateFile failed, GetLastError() = 2