| File name: | FreePDF_XP.zip |
| Full analysis: | https://app.any.run/tasks/6068c400-59fd-40bb-8ab7-9934a0cd3a38 |
| Verdict: | Malicious activity |
| Analysis date: | February 20, 2019, 08:28:43 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract |
| MD5: | 027024DDD6FC9E14A08AEDB47EE3BA9D |
| SHA1: | DAD0EA068EBFB70FC3C36C8D954C6D9A261FF548 |
| SHA256: | 4B827BD5B0118333D17BDE0E2EFFF7252E6D55AE26D2F2DF4F4136E23061248F |
| SSDEEP: | 24576:Q6rqE9eCHKOxuYO4zdDcc6MN26DacB63YdlhGfdDzryD6FREgBMOe4k:lFoEKOxuYO4ec6MN52cB84lhcLnv+V4k |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 20 |
|---|---|
| ZipBitFlag: | - |
| ZipCompression: | Deflated |
| ZipModifyDate: | 2010:06:17 21:56:22 |
| ZipCRC: | 0x0e0e8053 |
| ZipCompressedSize: | 3445 |
| ZipUncompressedSize: | 8400 |
| ZipFileName: | FreePDF_XP/Bosnian.lan |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1192 | C:\Windows\System32\spoolsv.exe | C:\Windows\System32\spoolsv.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Spooler SubSystem App Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1328 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa2976.48476\FreePDF_XP\redrun.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa2976.48476\FreePDF_XP\redrun.exe | — | WinRAR.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 1 Modules
| |||||||||||||||
| 1712 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa2976.46680\FreePDF_XP\freepdf.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa2976.46680\FreePDF_XP\freepdf.exe | — | WinRAR.exe | |||||||||||
User: admin Company: shbox Integrity Level: MEDIUM Description: FreePDF - PS nach PDF Konverter Exit code: 3221225781 Version: 4.00.0028 Modules
| |||||||||||||||
| 2176 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa2976.47069\FreePDF_XP\fpucnfg.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa2976.47069\FreePDF_XP\fpucnfg.exe | — | WinRAR.exe | |||||||||||
User: admin Company: . Integrity Level: MEDIUM Description: Nonadministrative FreePDF settings Exit code: 3221225781 Version: 4.00.0028 Modules
| |||||||||||||||
| 2212 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa2976.41123\FreePDF_XP\setup.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa2976.41123\FreePDF_XP\setup.exe | — | WinRAR.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 3221226540 Modules
| |||||||||||||||
| 2240 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa2976.36131\FreePDF_XP\fpconfig.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa2976.36131\FreePDF_XP\fpconfig.exe | WinRAR.exe | ||||||||||||
User: admin Company: . Integrity Level: HIGH Description: Setup for administrative FreePDF settings Exit code: 3221225781 Version: 4.00.0024 Modules
| |||||||||||||||
| 2700 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa2976.40348\FreePDF_XP\unredmon.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa2976.40348\FreePDF_XP\unredmon.exe | — | WinRAR.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 1 Modules
| |||||||||||||||
| 2892 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa2976.41123\FreePDF_XP\setup.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa2976.41123\FreePDF_XP\setup.exe | WinRAR.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 2976 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\FreePDF_XP.zip" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.60.0 Modules
| |||||||||||||||
| 3192 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa2976.39444\FreePDF_XP\redrun.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa2976.39444\FreePDF_XP\redrun.exe | — | WinRAR.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 1 Modules
| |||||||||||||||
| (PID) Process: | (2976) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (2976) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (2976) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2976) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\FreePDF_XP.zip | |||
| (PID) Process: | (2976) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (2976) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (2976) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (2976) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (2976) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
| (PID) Process: | (2976) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2976 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2976.36131\FreePDF_XP\English for translation.lan | text | |
MD5:32C61535B14AC005725DE4D4BE75C31F | SHA256:62A127BCE283F8A0B1A5C823E4582D7BA5244C707973DAA3BDCC6C769C1C60A6 | |||
| 2976 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2976.36131\FreePDF_XP\Bosnian.lan | text | |
MD5:9B030E66BE0F232FB31F353B982DB537 | SHA256:95293CA581EB5C30BE8C988C609B96B774CF34883612F84D925DD6C6C42196BC | |||
| 2976 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2976.36131\FreePDF_XP\Chinese simplified.lan | text | |
MD5:3BDDA27DF0AA61B134458DCA41968334 | SHA256:1C63535E81F55D0E73B1D9B288F8DD43E6595798AA54B4E1C47659DCD1E231D1 | |||
| 2976 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2976.36131\FreePDF_XP\fpsetup.exe | executable | |
MD5:88731A1EA5DA487692F3B6B50031D22D | SHA256:60063F044215840F95A02DEE6F1870CAE23D5C6FA48A0F247DD855C5104663E0 | |||
| 2976 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2976.36131\FreePDF_XP\fpjoin.exe | executable | |
MD5:AEC4F71000833C264C86863D8AB14502 | SHA256:FC407E0D8C0FFFB317031704936A86648B5DB6899803A78A077AAFB5F92E3106 | |||
| 2976 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2976.36131\FreePDF_XP\FreePDFen.pdf | ||
MD5:831B2172A2CFB2447D65BB8D0153E824 | SHA256:DAD7DCEDC10178E79FFABAC78D3D7766BB09EBE257753E8611CAB7DAC07DBF89 | |||
| 2976 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2976.36131\FreePDF_XP\freepdf.exe | executable | |
MD5:C7CFA2BE173514676586EA0BA7D17C9C | SHA256:31B6675387690A8953B335F1129F7D956BB6DA953103ADBA06B431A72B5E3CB2 | |||
| 2976 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2976.36131\FreePDF_XP\freepdfxp.inf | binary | |
MD5:2322B9E9A7435CEAD8569E9AC9D62296 | SHA256:CA7D1261E33A6CB83F859EBD5D5D66307D42A8CAAFCB0ACD9BECBEC42552AD5B | |||
| 2976 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2976.36131\FreePDF_XP\freepdfxp.ppd | text | |
MD5:5E16479637E41F88EC1D2927EE86A1AA | SHA256:0D74173E8FC1DE2DE2078C04FD07B1B81D32B283B01D455EFCB6A635A99B33B9 | |||
| 2976 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2976.36131\FreePDF_XP\Español.lan | text | |
MD5:054437E9E7A0BDC2BBC83956522AB9A9 | SHA256:77E742032B6F0B4209896625CB88D26AEA1BD509E9DCE6524A102A28A20AB20E | |||