File name:

Internet.Download.Manager.6.39.2.Portable.zip

Full analysis: https://app.any.run/tasks/ce5d3db2-51f5-422a-a633-f9edbab8255b
Verdict: Malicious activity
Analysis date: August 02, 2022, 08:10:44
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

D5C2A09D57A26276D4387B5F42F09A3D

SHA1:

EE8893666EB4AC2B38A599412705FF9602940B9C

SHA256:

5528B9F01904ACF7D943537C3CA6E9AE7048E7AC72F2CBC53AA7BC55BA933CEE

SSDEEP:

393216:yKppp+j87LP6D9joXgGJxvihhikCu2CHAVDvylZDwqS5:yK9P6+gGOEj0KmzXS5

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • InternetDownloadManagerPortable.exe (PID: 3000)
      • InternetDownloadManagerPortable.exe (PID: 2688)
    • Drops executable file immediately after starts

      • InternetDownloadManagerPortable.exe (PID: 2688)
      • WinRAR.exe (PID: 3940)
    • Loads dropped or rewritten executable

      • InternetDownloadManagerPortable.exe (PID: 2688)
  • SUSPICIOUS

    • Reads the computer name

      • WinRAR.exe (PID: 3940)
      • InternetDownloadManagerPortable.exe (PID: 2688)
    • Checks supported languages

      • WinRAR.exe (PID: 3940)
      • InternetDownloadManagerPortable.exe (PID: 2688)
    • Drops a file with a compile date too recent

      • InternetDownloadManagerPortable.exe (PID: 2688)
      • WinRAR.exe (PID: 3940)
    • Executable content was dropped or overwritten

      • InternetDownloadManagerPortable.exe (PID: 2688)
      • WinRAR.exe (PID: 3940)
    • Creates or modifies windows services

      • InternetDownloadManagerPortable.exe (PID: 2688)
  • INFO

    • Manual execution by user

      • InternetDownloadManagerPortable.exe (PID: 3000)
      • InternetDownloadManagerPortable.exe (PID: 2688)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.xpi | Mozilla Firefox browser extension (42.1)
.zip | ZIP compressed archive (21)

EXIF

ZIP

ZipFileName: App/IDM/
ZipUncompressedSize: -
ZipCompressedSize: -
ZipCRC: 0x00000000
ZipModifyDate: 2021:09:30 09:08:15
ZipCompression: None
ZipBitFlag: -
ZipRequiredVersion: 20
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
40
Monitored processes
3
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe internetdownloadmanagerportable.exe no specs internetdownloadmanagerportable.exe

Process information

PID
CMD
Path
Indicators
Parent process
2688"C:\Users\admin\Desktop\InternetDownloadManagerPortable.exe" C:\Users\admin\Desktop\InternetDownloadManagerPortable.exe
Explorer.EXE
User:
admin
Company:
cwer.ws/portable
Integrity Level:
HIGH
Description:
Internet Download Manager Portable
Exit code:
0
Version:
2019.11.02.0
Modules
Images
c:\users\admin\desktop\internetdownloadmanagerportable.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\user32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
3000"C:\Users\admin\Desktop\InternetDownloadManagerPortable.exe" C:\Users\admin\Desktop\InternetDownloadManagerPortable.exeExplorer.EXE
User:
admin
Company:
cwer.ws/portable
Integrity Level:
MEDIUM
Description:
Internet Download Manager Portable
Exit code:
3221226540
Version:
2019.11.02.0
Modules
Images
c:\users\admin\desktop\internetdownloadmanagerportable.exe
c:\windows\system32\ntdll.dll
3940"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\Internet.Download.Manager.6.39.2.Portable.zip"C:\Program Files\WinRAR\WinRAR.exe
Explorer.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
Total events
950
Read events
862
Write events
78
Delete events
10

Modification events

(PID) Process:(3940) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3940) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3940) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3940) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(3940) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(3940) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\Internet.Download.Manager.6.39.2.Portable.zip
(PID) Process:(3940) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3940) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3940) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3940) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
Executable files
53
Suspicious files
10
Text files
153
Unknown types
14

Dropped files

PID
Process
Filename
Type
2688InternetDownloadManagerPortable.exeC:\Users\admin\AppData\Local\Temp\nsq74DB.tmpbinary
MD5:
SHA256:
2688InternetDownloadManagerPortable.exeC:\Users\admin\Desktop\Data\InternetDownloadManagerPortable.regtext
MD5:
SHA256:
3940WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3940.1741\InternetDownloadManagerPortable.exeexecutable
MD5:1D9B7BB85E74CABAFAAC8BAF2FC3DB99
SHA256:C1DBFCD749BAA5A588E5ECC9CD05C14B6D224B7C0867117C519F9F1EA13811E0
3940WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3940.2303\App\IDM\idm.chmchm
MD5:FCB00D68D1C47922342092BAA89E9988
SHA256:478F04559E82C51391F66ED7C2A2A8C63276AED3FBDFDBC42FDAC24B959B1A9C
3940WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3940.2303\App\IDM\downlWithIDM.dllexecutable
MD5:B94D0711637B322B8AA1FB96250C86B6
SHA256:38AC192D707F3EC697DD5FE01A0C6FC424184793DF729F427C0CF5DFAB6705FE
2688InternetDownloadManagerPortable.exeC:\Users\admin\AppData\Local\Temp\nsq74DC.tmp\System.dllexecutable
MD5:FBE295E5A1ACFBD0A6271898F885FE6A
SHA256:A1390A78533C47E55CC364E97AF431117126D04A7FAED49390210EA3E89DD0E1
3940WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3940.2303\App\IDM\defexclist.txttext
MD5:A62792690DD91E037DCA14BA3DCEA5D8
SHA256:3EED4504CF60A193D0D40682A0EB5C5216BE3FF4A8261088772AB2F0C7B4A1E7
3940WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3940.2303\App\IDM\grabber.chmchm
MD5:4B9506B675606F1003D9EF635A48DB06
SHA256:B46D8878E0CBD7A7A2F12DE909CD94CF424FA07838A39434146F772784481137
3940WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3940.2303\App\IDM\idmantypeinfo.tlbtlb
MD5:60ADB0AD984D5C3A4289CED459913963
SHA256:D421D11EF7CF2B766CA6FBC8E837912B2100339C686D48CA56F650649F7B9343
3940WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3940.2303\App\IDM\downlWithIDM64.dllexecutable
MD5:13C99CBF0E66D5A8003A650C5642CA30
SHA256:8A51ECE1C4C8BCB8C56CA10CB9D97BFF0DFE75052412A8D8D970A5EB6933427B
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info