File name:

The Dark Pictures Anthology Man of Medan Türkçe Yama v1.0.7z

Full analysis: https://app.any.run/tasks/c700b232-ea52-4c0e-8f22-e56dca144f7d
Verdict: Malicious activity
Analysis date: April 18, 2020, 13:42:08
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-7z-compressed
File info: 7-zip archive data, version 0.4
MD5:

8A0EC44669BB611EDF2FDDA45A408797

SHA1:

7DFEC11EA43DDE411C79037DA405C9685B55B7CC

SHA256:

4E5B9071AD39F3F3F8CF2FAE7A7CF9D512532C0C168DA8DEA771526FCC6E4ED1

SSDEEP:

24576:SQBEQMcTTvX8L7IjTNkrZqpj7COviroexu44xHGHBiYXNRvH1+eH4zUdtq5/NgGp:SQlVs2x3XAHcSBTNCeHu2U

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • The Dark Pictures Anthology Man of Medan Türkçe Yama v1.0.exe (PID: 2756)
      • The Dark Pictures Anthology Man of Medan Türkçe Yama v1.0.exe (PID: 2228)
    • Loads dropped or rewritten executable

      • The Dark Pictures Anthology Man of Medan Türkçe Yama v1.0.exe (PID: 2756)
    • Actions looks like stealing of personal data

      • The Dark Pictures Anthology Man of Medan Türkçe Yama v1.0.exe (PID: 2756)
  • SUSPICIOUS

    • Reads Internet Cache Settings

      • The Dark Pictures Anthology Man of Medan Türkçe Yama v1.0.exe (PID: 2756)
    • Reads internet explorer settings

      • The Dark Pictures Anthology Man of Medan Türkçe Yama v1.0.exe (PID: 2756)
    • Executable content was dropped or overwritten

      • The Dark Pictures Anthology Man of Medan Türkçe Yama v1.0.exe (PID: 2756)
      • WinRAR.exe (PID: 3692)
  • INFO

    • Manual execution by user

      • The Dark Pictures Anthology Man of Medan Türkçe Yama v1.0.exe (PID: 2756)
      • The Dark Pictures Anthology Man of Medan Türkçe Yama v1.0.exe (PID: 2228)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.7z | 7-Zip compressed archive (v0.4) (57.1)
.7z | 7-Zip compressed archive (gen) (42.8)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
50
Monitored processes
3
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe the dark pictures anthology man of medan türkçe yama v1.0.exe no specs the dark pictures anthology man of medan türkçe yama v1.0.exe

Process information

PID
CMD
Path
Indicators
Parent process
2228"C:\Users\admin\Desktop\The Dark Pictures Anthology Man of Medan Türkçe Yama v1.0.exe" C:\Users\admin\Desktop\The Dark Pictures Anthology Man of Medan Türkçe Yama v1.0.exeexplorer.exe
User:
admin
Company:
Integrity Level:
MEDIUM
Description:
The Dark Pictures Anthology Man of Medan TR v1.00
Exit code:
3221226540
Version:
1.00
Modules
Images
c:\users\admin\desktop\the dark pictures anthology man of medan türkçe yama v1.0.exe
c:\systemroot\system32\ntdll.dll
2756"C:\Users\admin\Desktop\The Dark Pictures Anthology Man of Medan Türkçe Yama v1.0.exe" C:\Users\admin\Desktop\The Dark Pictures Anthology Man of Medan Türkçe Yama v1.0.exe
explorer.exe
User:
admin
Company:
Integrity Level:
HIGH
Description:
The Dark Pictures Anthology Man of Medan TR v1.00
Exit code:
0
Version:
1.00
Modules
Images
c:\users\admin\desktop\the dark pictures anthology man of medan türkçe yama v1.0.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\gdi32.dll
3692"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\The Dark Pictures Anthology Man of Medan Türkçe Yama v1.0.7z"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
Total events
1 358
Read events
1 104
Write events
250
Delete events
4

Modification events

(PID) Process:(3692) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3692) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3692) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3692) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\The Dark Pictures Anthology Man of Medan Türkçe Yama v1.0.7z
(PID) Process:(3692) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3692) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3692) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3692) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2756) The Dark Pictures Anthology Man of Medan Türkçe Yama v1.0.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(2756) The Dark Pictures Anthology Man of Medan Türkçe Yama v1.0.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
Executable files
6
Suspicious files
0
Text files
8
Unknown types
0

Dropped files

PID
Process
Filename
Type
2756The Dark Pictures Anthology Man of Medan Türkçe Yama v1.0.exeC:\Users\admin\AppData\Local\Temp\nsw2F72.tmp\nsyB433.tmp
MD5:
SHA256:
2756The Dark Pictures Anthology Man of Medan Türkçe Yama v1.0.exeC:\Users\admin\AppData\Local\Temp\nsw2F72.tmp\nsyB434.tmp
MD5:
SHA256:
2756The Dark Pictures Anthology Man of Medan Türkçe Yama v1.0.exeC:\Users\admin\AppData\Local\Temp\nsw2F72.tmp\banner.jpgimage
MD5:4B0C7375AC9F47DA6A6971509541DF30
SHA256:B7DF348B5E2C72873B960431EB7BC0F21FBA3F9AB2A2CAB44EC7A87B10CAFAFA
2756The Dark Pictures Anthology Man of Medan Türkçe Yama v1.0.exeC:\Users\admin\AppData\Local\Temp\nsw2F72.tmp\System.dllexecutable
MD5:C9473CB90D79A374B2BA6040CA16E45C
SHA256:B80A5CBA69D1853ED5979B0CA0352437BF368A5CFB86CB4528EDADD410E11352
3692WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3692.18956\The Dark Pictures Anthology Man of Medan Türkçe Yama v1.0.exeexecutable
MD5:F303988F045BCFE8992B0FFA87A0090F
SHA256:AB40BB8DF2671B9FD0BBC228D878D6A4EA36F88AF9FBA71E31C21D66EA7F3D91
2756The Dark Pictures Anthology Man of Medan Türkçe Yama v1.0.exeC:\Users\admin\AppData\Local\Temp\nsw2F72.tmp\oku\oku\oku.htmlhtml
MD5:EEDF858172DA67745B2967361FD80094
SHA256:B70D2D1CAA3A326926C0C0F3CD1C892BFCC333EB8805FAFB558149AAE1E92044
2756The Dark Pictures Anthology Man of Medan Türkçe Yama v1.0.exeC:\Users\admin\AppData\Local\Temp\nsw2F72.tmp\scroll.htmlhtml
MD5:5C53F8B687CB021B66CFA18203AF3857
SHA256:E92E7FE1E0081C538B93D91D5B352A8387CAF5352279DF1D13A3D115C35CA121
2756The Dark Pictures Anthology Man of Medan Türkçe Yama v1.0.exeC:\Users\admin\AppData\Local\Temp\nsw2F72.tmp\oku\oku.htmlhtml
MD5:EEDF858172DA67745B2967361FD80094
SHA256:B70D2D1CAA3A326926C0C0F3CD1C892BFCC333EB8805FAFB558149AAE1E92044
2756The Dark Pictures Anthology Man of Medan Türkçe Yama v1.0.exeC:\Users\admin\AppData\Local\Temp\nsw2F72.tmp\modern-wizard.bmpimage
MD5:25201290E03A2D3BCA029C748E9A8B32
SHA256:A83A202820BC8E870D84731AFD18BEC11B25166F1797280FC8FC16373187C4D6
2756The Dark Pictures Anthology Man of Medan Türkçe Yama v1.0.exeC:\Users\admin\AppData\Local\Temp\nsw2F72.tmp\oku\scroll.htmlhtml
MD5:5C53F8B687CB021B66CFA18203AF3857
SHA256:E92E7FE1E0081C538B93D91D5B352A8387CAF5352279DF1D13A3D115C35CA121
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info