| File name: | FreePDF_XP.zip |
| Full analysis: | https://app.any.run/tasks/6068c400-59fd-40bb-8ab7-9934a0cd3a38 |
| Verdict: | Malicious activity |
| Analysis date: | February 20, 2019, 08:28:43 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract |
| MD5: | 027024DDD6FC9E14A08AEDB47EE3BA9D |
| SHA1: | DAD0EA068EBFB70FC3C36C8D954C6D9A261FF548 |
| SHA256: | 4B827BD5B0118333D17BDE0E2EFFF7252E6D55AE26D2F2DF4F4136E23061248F |
| SSDEEP: | 24576:Q6rqE9eCHKOxuYO4zdDcc6MN26DacB63YdlhGfdDzryD6FREgBMOe4k:lFoEKOxuYO4ec6MN52cB84lhcLnv+V4k |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 20 |
|---|---|
| ZipBitFlag: | - |
| ZipCompression: | Deflated |
| ZipModifyDate: | 2010:06:17 21:56:22 |
| ZipCRC: | 0x0e0e8053 |
| ZipCompressedSize: | 3445 |
| ZipUncompressedSize: | 8400 |
| ZipFileName: | FreePDF_XP/Bosnian.lan |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1192 | C:\Windows\System32\spoolsv.exe | C:\Windows\System32\spoolsv.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Spooler SubSystem App Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1328 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa2976.48476\FreePDF_XP\redrun.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa2976.48476\FreePDF_XP\redrun.exe | — | WinRAR.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 1 Modules
| |||||||||||||||
| 1712 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa2976.46680\FreePDF_XP\freepdf.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa2976.46680\FreePDF_XP\freepdf.exe | — | WinRAR.exe | |||||||||||
User: admin Company: shbox Integrity Level: MEDIUM Description: FreePDF - PS nach PDF Konverter Exit code: 3221225781 Version: 4.00.0028 Modules
| |||||||||||||||
| 2176 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa2976.47069\FreePDF_XP\fpucnfg.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa2976.47069\FreePDF_XP\fpucnfg.exe | — | WinRAR.exe | |||||||||||
User: admin Company: . Integrity Level: MEDIUM Description: Nonadministrative FreePDF settings Exit code: 3221225781 Version: 4.00.0028 Modules
| |||||||||||||||
| 2212 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa2976.41123\FreePDF_XP\setup.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa2976.41123\FreePDF_XP\setup.exe | — | WinRAR.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 3221226540 Modules
| |||||||||||||||
| 2240 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa2976.36131\FreePDF_XP\fpconfig.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa2976.36131\FreePDF_XP\fpconfig.exe | WinRAR.exe | ||||||||||||
User: admin Company: . Integrity Level: HIGH Description: Setup for administrative FreePDF settings Exit code: 3221225781 Version: 4.00.0024 Modules
| |||||||||||||||
| 2700 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa2976.40348\FreePDF_XP\unredmon.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa2976.40348\FreePDF_XP\unredmon.exe | — | WinRAR.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 1 Modules
| |||||||||||||||
| 2892 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa2976.41123\FreePDF_XP\setup.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa2976.41123\FreePDF_XP\setup.exe | WinRAR.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 2976 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\FreePDF_XP.zip" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.60.0 Modules
| |||||||||||||||
| 3192 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa2976.39444\FreePDF_XP\redrun.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa2976.39444\FreePDF_XP\redrun.exe | — | WinRAR.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 1 Modules
| |||||||||||||||
| (PID) Process: | (2976) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (2976) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (2976) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2976) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\FreePDF_XP.zip | |||
| (PID) Process: | (2976) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (2976) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (2976) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (2976) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (2976) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
| (PID) Process: | (2976) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2976 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2976.36131\FreePDF_XP\Bosnian.lan | text | |
MD5:9B030E66BE0F232FB31F353B982DB537 | SHA256:95293CA581EB5C30BE8C988C609B96B774CF34883612F84D925DD6C6C42196BC | |||
| 2976 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2976.36131\FreePDF_XP\fpjoin.exe | executable | |
MD5:AEC4F71000833C264C86863D8AB14502 | SHA256:FC407E0D8C0FFFB317031704936A86648B5DB6899803A78A077AAFB5F92E3106 | |||
| 2976 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2976.36131\FreePDF_XP\English for translation.lan | text | |
MD5:32C61535B14AC005725DE4D4BE75C31F | SHA256:62A127BCE283F8A0B1A5C823E4582D7BA5244C707973DAA3BDCC6C769C1C60A6 | |||
| 2976 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2976.36131\FreePDF_XP\Chinese traditional.lan | text | |
MD5:FBD74D69CAE8D42FE42881974DF27CE2 | SHA256:0DB84608462B25C656C9DFD6BE8E2288C817275078536601A0146B16A3DD3030 | |||
| 2976 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2976.36131\FreePDF_XP\eBook.fpp | text | |
MD5:E8BB6DE33D82513DA205B81604772571 | SHA256:34F30E98AA7AD9EE881208D139215D798D12D21C976F9A0F34B4FA5F6020355D | |||
| 2976 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2976.36131\FreePDF_XP\Cesky.lan | text | |
MD5:CCA420EF94AABBA3CD8A4BBD47D7E5A7 | SHA256:89435CA7598F573CA0C8A40737E5F79DDCD86AAAF56A1D803C58EB60574826F8 | |||
| 2976 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2976.36131\FreePDF_XP\Chinese simplified.lan | text | |
MD5:3BDDA27DF0AA61B134458DCA41968334 | SHA256:1C63535E81F55D0E73B1D9B288F8DD43E6595798AA54B4E1C47659DCD1E231D1 | |||
| 2976 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2976.36131\FreePDF_XP\Español.lan | text | |
MD5:054437E9E7A0BDC2BBC83956522AB9A9 | SHA256:77E742032B6F0B4209896625CB88D26AEA1BD509E9DCE6524A102A28A20AB20E | |||
| 2976 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2976.36131\FreePDF_XP\fpassist.exe | executable | |
MD5:02753F61256257D97E5DB793D754E904 | SHA256:35709D754F102DCF1164E4720BC2C54355C0E8B35E6A329C36A76831DBA9663B | |||
| 2976 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2976.36131\FreePDF_XP\fpconfig.exe | executable | |
MD5:E25FB73DA162462FC61866F3AFD843B8 | SHA256:8EE8EEDADB87B659A1B949261A73C1D187DB64DE0487F49301CDB8C7EE3C7F53 | |||