File name:

CPUID HWMonitor Pro 1.42 _.rar

Full analysis: https://app.any.run/tasks/453bad89-d44b-4d79-8ef3-2a03d0d8a0c0
Verdict: No threats detected
Analysis date: November 11, 2020, 02:15:46
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

05EFD96D85D30CF4CCEBFB6A22FA28B9

SHA1:

88680DCC56A40398A97D6395FC0521A7A0FFDA65

SHA256:

525F2294C8CD26EFB916D30DCFD3B4A0CB2A41085C265427AD3A434D4DA1A3D0

SSDEEP:

49152:l4C/V/Mtts2504Q4bKfy+ksSCg3BSv7fQcJLL0Wb+rwQbQ:l4Cd2l0zUC+67fNJ7bPQU

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • Patch-HWMonitor.Pro.1.3x.exe (PID: 3708)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • Patch-HWMonitor.Pro.1.3x.exe (PID: 3708)
      • hwmonitor-pro_1.42.exe (PID: 2592)
      • hwmonitor-pro_1.42.tmp (PID: 2944)
  • INFO

    • Application was dropped or rewritten from another process

      • hwmonitor-pro_1.42.tmp (PID: 2944)
    • Manual execution by user

      • hwmonitor-pro_1.42.exe (PID: 2592)
      • Patch-HWMonitor.Pro.1.3x.exe (PID: 3708)
    • Creates files in the program directory

      • hwmonitor-pro_1.42.tmp (PID: 2944)
    • Creates a software uninstall entry

      • hwmonitor-pro_1.42.tmp (PID: 2944)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
46
Monitored processes
4
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start drop and start winrar.exe no specs hwmonitor-pro_1.42.exe hwmonitor-pro_1.42.tmp patch-hwmonitor.pro.1.3x.exe

Process information

PID
CMD
Path
Indicators
Parent process
2592"C:\Users\admin\Desktop\CPUID HWMonitor Pro 1.42-With Crack\Setup\hwmonitor-pro_1.42.exe" C:\Users\admin\Desktop\CPUID HWMonitor Pro 1.42-With Crack\Setup\hwmonitor-pro_1.42.exe
explorer.exe
User:
admin
Company:
CPUID, Inc.
Integrity Level:
HIGH
Description:
CPUID HWMonitor Pro Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\desktop\cpuid hwmonitor pro 1.42-with crack\setup\hwmonitor-pro_1.42.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
c:\windows\system32\oleaut32.dll
2844"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\CPUID HWMonitor Pro 1.42 _.rar"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2944"C:\Users\admin\AppData\Local\Temp\is-F81DG.tmp\hwmonitor-pro_1.42.tmp" /SL5="$60182,1486247,58368,C:\Users\admin\Desktop\CPUID HWMonitor Pro 1.42-With Crack\Setup\hwmonitor-pro_1.42.exe" C:\Users\admin\AppData\Local\Temp\is-F81DG.tmp\hwmonitor-pro_1.42.tmp
hwmonitor-pro_1.42.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.52.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-f81dg.tmp\hwmonitor-pro_1.42.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
3708"C:\Users\admin\Desktop\CPUID HWMonitor Pro 1.42-With Crack\Patch\Patch-HWMonitor.Pro.1.3x.exe" C:\Users\admin\Desktop\CPUID HWMonitor Pro 1.42-With Crack\Patch\Patch-HWMonitor.Pro.1.3x.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\desktop\cpuid hwmonitor pro 1.42-with crack\patch\patch-hwmonitor.pro.1.3x.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\temp\dup2patcher.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
Total events
684
Read events
629
Write events
49
Delete events
6

Modification events

(PID) Process:(2844) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2844) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2844) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\13B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2844) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\CPUID HWMonitor Pro 1.42 _.rar
(PID) Process:(2844) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2844) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2844) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2844) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2844) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000
(PID) Process:(2844) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\General
Operation:writeName:LastFolder
Value:
C:\Users\admin\AppData\Local\Temp
Executable files
5
Suspicious files
2
Text files
0
Unknown types
4

Dropped files

PID
Process
Filename
Type
2844WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2844.29809\CPUID HWMonitor Pro 1.42-With Crack\Instructions.txt
MD5:
SHA256:
2844WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2844.29809\CPUID HWMonitor Pro 1.42-With Crack\Patch\Patch-HWMonitor.Pro.1.3x.exe
MD5:
SHA256:
2844WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2844.29809\CPUID HWMonitor Pro 1.42-With Crack\Setup\hwmonitor-pro_1.42.exe
MD5:
SHA256:
2944hwmonitor-pro_1.42.tmpC:\Program Files\CPUID\HWMonitorPro\is-RCL15.tmp
MD5:
SHA256:
2944hwmonitor-pro_1.42.tmpC:\Program Files\CPUID\HWMonitorPro\is-16H9L.tmp
MD5:
SHA256:
2944hwmonitor-pro_1.42.tmpC:\Program Files\CPUID\HWMonitorPro\is-C93CG.tmp
MD5:
SHA256:
2944hwmonitor-pro_1.42.tmpC:\Program Files\CPUID\HWMonitorPro\unins000.datdat
MD5:
SHA256:
2944hwmonitor-pro_1.42.tmpC:\Program Files\CPUID\HWMonitorPro\HWMonitorPro.exeexecutable
MD5:
SHA256:
2944hwmonitor-pro_1.42.tmpC:\ProgramData\Microsoft\Windows\Start Menu\Programs\CPUID\HWMonitorPro\HWMonitorPro EULA.lnklnk
MD5:
SHA256:
2944hwmonitor-pro_1.42.tmpC:\ProgramData\Microsoft\Windows\Start Menu\Programs\CPUID\HWMonitorPro\HWMonitorPro.lnklnk
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info