| File name: | Internet.Download.Manager.6.39.2.Portable.zip |
| Full analysis: | https://app.any.run/tasks/ce5d3db2-51f5-422a-a633-f9edbab8255b |
| Verdict: | Malicious activity |
| Analysis date: | August 02, 2022, 08:10:44 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract |
| MD5: | D5C2A09D57A26276D4387B5F42F09A3D |
| SHA1: | EE8893666EB4AC2B38A599412705FF9602940B9C |
| SHA256: | 5528B9F01904ACF7D943537C3CA6E9AE7048E7AC72F2CBC53AA7BC55BA933CEE |
| SSDEEP: | 393216:yKppp+j87LP6D9joXgGJxvihhikCu2CHAVDvylZDwqS5:yK9P6+gGOEj0KmzXS5 |
| .xpi | | | Mozilla Firefox browser extension (42.1) |
|---|---|---|
| .zip | | | ZIP compressed archive (21) |
| ZipFileName: | App/IDM/ |
|---|---|
| ZipUncompressedSize: | - |
| ZipCompressedSize: | - |
| ZipCRC: | 0x00000000 |
| ZipModifyDate: | 2021:09:30 09:08:15 |
| ZipCompression: | None |
| ZipBitFlag: | - |
| ZipRequiredVersion: | 20 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2688 | "C:\Users\admin\Desktop\InternetDownloadManagerPortable.exe" | C:\Users\admin\Desktop\InternetDownloadManagerPortable.exe | Explorer.EXE | ||||||||||||
User: admin Company: cwer.ws/portable Integrity Level: HIGH Description: Internet Download Manager Portable Exit code: 0 Version: 2019.11.02.0 Modules
| |||||||||||||||
| 3000 | "C:\Users\admin\Desktop\InternetDownloadManagerPortable.exe" | C:\Users\admin\Desktop\InternetDownloadManagerPortable.exe | — | Explorer.EXE | |||||||||||
User: admin Company: cwer.ws/portable Integrity Level: MEDIUM Description: Internet Download Manager Portable Exit code: 3221226540 Version: 2019.11.02.0 Modules
| |||||||||||||||
| 3940 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\Internet.Download.Manager.6.39.2.Portable.zip" | C:\Program Files\WinRAR\WinRAR.exe | Explorer.EXE | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| (PID) Process: | (3940) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (3940) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (3940) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3940) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip | |||
| (PID) Process: | (3940) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (3940) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop\Internet.Download.Manager.6.39.2.Portable.zip | |||
| (PID) Process: | (3940) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (3940) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (3940) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (3940) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2688 | InternetDownloadManagerPortable.exe | C:\Users\admin\AppData\Local\Temp\nsq74DB.tmp | binary | |
MD5:— | SHA256:— | |||
| 2688 | InternetDownloadManagerPortable.exe | C:\Users\admin\Desktop\Data\InternetDownloadManagerPortable.reg | text | |
MD5:— | SHA256:— | |||
| 3940 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3940.2303\App\IDM\downlWithIDM64.dll | executable | |
MD5:13C99CBF0E66D5A8003A650C5642CA30 | SHA256:8A51ECE1C4C8BCB8C56CA10CB9D97BFF0DFE75052412A8D8D970A5EB6933427B | |||
| 3940 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3940.2303\App\IDM\idm.chm | chm | |
MD5:FCB00D68D1C47922342092BAA89E9988 | SHA256:478F04559E82C51391F66ED7C2A2A8C63276AED3FBDFDBC42FDAC24B959B1A9C | |||
| 3940 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3940.2303\App\IDM\idmantypeinfo.tlb | tlb | |
MD5:60ADB0AD984D5C3A4289CED459913963 | SHA256:D421D11EF7CF2B766CA6FBC8E837912B2100339C686D48CA56F650649F7B9343 | |||
| 3940 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3940.2303\App\IDM\idmbrbtn64.dll | executable | |
MD5:A7CBA293419E7DF6305A09F3C9E4FA59 | SHA256:5E0C0CE1F95869B87FE7DFEE6954F99C0D22954BF5092AD7F15D1DC3981869AC | |||
| 3940 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3940.2303\App\IDM\grabber.chm | chm | |
MD5:4B9506B675606F1003D9EF635A48DB06 | SHA256:B46D8878E0CBD7A7A2F12DE909CD94CF424FA07838A39434146F772784481137 | |||
| 3940 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3940.2303\App\IDM\idmbrbtn.dll | executable | |
MD5:4A6BDBEA26C536B38AAAF7C33826982B | SHA256:495A608060661354F08591D28361BAED6855E694DA5BC6FB0A72CE4A3C0AF091 | |||
| 3940 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3940.2303\App\IDM\idmcchandler2_64.dll | executable | |
MD5:5012EA14F13DD58FFEB14553824D8EBB | SHA256:59AC02F5A0644BF56B7AD7E2B48FC8F89083F8CFE12A0A93F63163A5573A876F | |||
| 3940 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3940.2303\App\IDM\idmBroker.exe | executable | |
MD5:E2F17E16E2B1888A64398900999E9663 | SHA256:97810E0B3838A7DCA94D73A8B9E170107642B064713C084C231DE6632CB68A9C | |||