| File name: | Internet Download Manager 6.42 Build 3 Silent Install mshaz1000.exe |
| Full analysis: | https://app.any.run/tasks/dad51fcb-0d81-49ab-a037-6a13bdb29e6a |
| Verdict: | Malicious activity |
| Analysis date: | May 16, 2025, 18:10:02 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed, 3 sections |
| MD5: | 8455FF7C944189CA42161FFB36838848 |
| SHA1: | 39DC2E48639A8843DAEDD709D07E521F114A820B |
| SHA256: | 44ACFC6B249D38C56C2533781D5CC538339D57C361D8D9A947E2CA2C7765F7E0 |
| SSDEEP: | 98304:DR9QXByu08/oJyYZUmqmgSRT5rhe4fA4+NN84Y7VhhNXydfbRKzSbdnUfNwYRdf4://VxWn0Jyw5DjsZ6ZhiNiDqt/upc |
| .exe | | | Generic Win/DOS Executable (50) |
|---|---|---|
| .exe | | | DOS Executable Generic (49.9) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2012:12:31 00:38:51+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 8 |
| CodeSize: | 65536 |
| InitializedDataSize: | 147456 |
| UninitializedDataSize: | 233472 |
| EntryPoint: | 0x48a70 |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 6.42.3.0 |
| ProductVersionNumber: | 6.42.3.0 |
| FileFlagsMask: | 0x0000 |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Unknown |
| FileSubtype: | - |
| LanguageCode: | Russian |
| CharacterSet: | Unicode |
| CompanyName: | mshaz1000 |
| FileDescription: | Internet Download Manager 6.42 Build 3 |
| LegalCopyright: | - |
| LegalTrademarks: | - |
| InternalName: | - |
| ProductName: | - |
| OriginalFileName: | - |
| FileVersion: | 6.42.3 |
| ProductVersion: | 6.42.3 |
| Comments: | - |
| PrivateBuild: | - |
| SpecialBuild: | - |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 116 | "C:\Windows\System32\net.exe" start IDMWFP | C:\Windows\System32\net.exe | — | Uninstall.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Net Command Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 148 | regini "permdel.txt" | C:\Windows\System32\regini.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Registry Initializer Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 608 | reg delete "HKCU\Software\DownloadManager" /v "FName" /F | C:\Windows\System32\reg.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Registry Console Tool Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 752 | "C:\Users\admin\AppData\Local\Temp\is-KK7H7.tmp\Internet.tmp" /SL5="$40154,14763386,64512,C:\Users\admin\AppData\Local\Temp\7ZipSfx.000\Internet.exe" /SILENT, /VERYSILENT /SUPPRESSMSGBOXES /MERGETASKS=desktopicon,fileassoc | C:\Users\admin\AppData\Local\Temp\is-KK7H7.tmp\Internet.tmp | Internet.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: Setup/Uninstall Version: 51.52.0.0 Modules
| |||||||||||||||
| 764 | reg delete "HKCU\Software\Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}" /F | C:\Windows\System32\reg.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Registry Console Tool Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 780 | "C:\Windows\regedit.exe" /S "C:\Users\admin\AppData\Local\Temp\7ZipSfx.000\settings.reg" | C:\Windows\regedit.exe | Internet.tmp | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Registry Editor Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 848 | reg delete "HKLM\Software\Classes\CLSID\{07999AC3-058B-40BF-984F-69EB1E554CA7}" /F | C:\Windows\System32\reg.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Registry Console Tool Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 948 | regini "permdel.txt" | C:\Windows\System32\regini.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Registry Initializer Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 960 | C:\Windows\system32\net1 start IDMWFP | C:\Windows\System32\net1.exe | — | net.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Net Command Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 972 | "C:\Windows\system32\regsvr32.exe" /s "C:\Program Files\Internet Download Manager\downlWithIDM.dll" | C:\Windows\System32\regsvr32.exe | — | Internet.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft(C) Register Server Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (752) Internet.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | Owner |
Value: F002000058688AC48DC6DB01 | |||
| (PID) Process: | (752) Internet.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | SessionHash |
Value: BFD20241053D9D36CDA572323C74B10579F8C7EB4AF2B7AD63360AC329841F9B | |||
| (PID) Process: | (752) Internet.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | Sequence |
Value: 1 | |||
| (PID) Process: | (2396) Internet Download Manager 6.42 Build 3 Silent Install mshaz1000.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (2396) Internet Download Manager 6.42 Build 3 Silent Install mshaz1000.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (2396) Internet Download Manager 6.42 Build 3 Silent Install mshaz1000.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (2396) Internet Download Manager 6.42 Build 3 Silent Install mshaz1000.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (752) Internet.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | RegFiles0000 |
Value: C:\Program Files\Internet Download Manager\KGIDM.dll | |||
| (PID) Process: | (752) Internet.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | RegFilesHash |
Value: D417D3D1471BEE61704FA5545100EDCE1A3953CDFF92EB15B3F0867C2D35D164 | |||
| (PID) Process: | (3856) regsvr32.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{98D060EC-53AF-4F61-8180-43C507C9FF94}\TypeLib |
| Operation: | write | Name: | Version |
Value: 1.0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2396 | Internet Download Manager 6.42 Build 3 Silent Install mshaz1000.exe | C:\Users\admin\AppData\Local\Temp\7ZipSfx.000\Internet.exe | executable | |
MD5:1003BC34AAB3D2662E1B2E9A9BB4E26B | SHA256:57C2B8BA95EF42383CF4BB48BC7E0BFA1A773CC7098CD4A7D7B33BB022D0BACB | |||
| 752 | Internet.tmp | C:\Program Files\Internet Download Manager\is-EJ6MC.tmp | executable | |
MD5:B51A9AFE694FE53BCA3AE78B3CC16639 | SHA256:4AE0AA62B7F84F92A1BD52DC43F50485F1E0C6BF4F6D672943F75D4DB5A7A13A | |||
| 752 | Internet.tmp | C:\Users\admin\AppData\Local\Temp\is-26VSK.tmp\ISTask.dll | executable | |
MD5:86A1311D51C00B278CB7F27796EA442E | SHA256:E916BDF232744E00CBD8D608168A019C9F41A68A7E8390AA48CFB525276C483D | |||
| 2396 | Internet Download Manager 6.42 Build 3 Silent Install mshaz1000.exe | C:\Users\admin\AppData\Local\Temp\7ZipSfx.000\Reg.reg | text | |
MD5:409BF1F8D615B5B53D7C4C7FC30C59FA | SHA256:521088BBED90A170E194922CBE505F91C313B3F899E02ED379FB271506541284 | |||
| 752 | Internet.tmp | C:\Program Files\Internet Download Manager\unins000.exe | executable | |
MD5:B51A9AFE694FE53BCA3AE78B3CC16639 | SHA256:4AE0AA62B7F84F92A1BD52DC43F50485F1E0C6BF4F6D672943F75D4DB5A7A13A | |||
| 752 | Internet.tmp | C:\Users\admin\AppData\Local\Temp\is-26VSK.tmp\MetroBlue.vsf | binary | |
MD5:295D085196B3DA13BFCD53373F82F8EE | SHA256:CBDC95EB9E7269E0C3E3BDDFD37B0918962795D80BDBA932E46EA16FF5E6CDBF | |||
| 752 | Internet.tmp | C:\Program Files\Internet Download Manager\is-51VKI.tmp | executable | |
MD5:44EC23233850A7268A0F1621CC24760C | SHA256:499C0C30160EC6CD302A8AEAB777C0E44DEA8EDFF6B111AF8D0041DFE4B66840 | |||
| 752 | Internet.tmp | C:\Users\admin\AppData\Local\Temp\is-26VSK.tmp\is-U0HSC.tmp | text | |
MD5:0BB8F20436AFB6421DD5BFE3CDCB4F94 | SHA256:CC424E1B87501BDE3D757E1EF3426FE4BDEE47860928783131812AAFEE310FF1 | |||
| 752 | Internet.tmp | C:\Users\admin\AppData\Local\Temp\is-26VSK.tmp\VclStylesInno.dll | executable | |
MD5:B0CA93CEB050A2FEFF0B19E65072BBB5 | SHA256:0E93313F42084D804B9AC4BE53D844E549CFCAF19E6F276A3B0F82F01B9B2246 | |||
| 752 | Internet.tmp | C:\Program Files\Internet Download Manager\is-EUAGD.tmp | binary | |
MD5:4B9506B675606F1003D9EF635A48DB06 | SHA256:B46D8878E0CBD7A7A2F12DE909CD94CF424FA07838A39434146F772784481137 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 224.0.0.252:5355 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | whitelisted |
Domain | IP | Reputation |
|---|---|---|
google.com |
| whitelisted |
Process | Message |
|---|---|
regedit.exe | REGEDIT: CreateFile failed, GetLastError() = 2
|
regedit.exe | REGEDIT: CreateFile failed, GetLastError() = 2
|