| File name: | acad.fas |
| Full analysis: | https://app.any.run/tasks/bf3fed7a-e567-424e-a922-5918e1132133 |
| Verdict: | No threats detected |
| Analysis date: | May 29, 2018, 17:19:31 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/octet-stream |
| File info: | data |
| MD5: | 3D2A33A471932A78BF807BA532D5A279 |
| SHA1: | 95E2E6BC7A2D184687838CD14BB02BFD18B9E981 |
| SHA256: | 555BD5CC82206821CF6A746C1125C0314A8D1D5B6D990D9F8EF76E293C1A10A9 |
| SSDEEP: | 48:SnW3t9yiFo3tJ9AMbs5WJZGZasuyBgKQTmkiY6N/fkoVW:1n+X9AM1JaafyB1qhN6N/7W |
| .fas | | | AutoCAD Fast-load AutoLISP (FAS4) (100) |
|---|
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1396 | "C:\Windows\system32\NOTEPAD.EXE" C:\Users\admin\AppData\Local\Temp\acad.fas | C:\Windows\system32\NOTEPAD.EXE | — | rundll32.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Notepad Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1968 | "C:\Windows\system32\rundll32.exe" C:\Windows\system32\shell32.dll,OpenAs_RunDLL C:\Users\admin\AppData\Local\Temp\acad.fas | C:\Windows\system32\rundll32.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows host process (Rundll32) Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (1968) rundll32.exe | Key: | HKEY_CLASSES_ROOT\fas_auto_file |
| Operation: | write | Name: | |
Value: | |||
| (PID) Process: | (1968) rundll32.exe | Key: | HKEY_CLASSES_ROOT\.fas |
| Operation: | write | Name: | |
Value: fas_auto_file | |||
| (PID) Process: | (1968) rundll32.exe | Key: | HKEY_CLASSES_ROOT\fas_auto_file\shell\edit\command |
| Operation: | write | Name: | |
Value: %SystemRoot%\system32\NOTEPAD.EXE %1 | |||
| (PID) Process: | (1968) rundll32.exe | Key: | HKEY_CLASSES_ROOT\fas_auto_file\shell\open\command |
| Operation: | write | Name: | |
Value: %SystemRoot%\system32\NOTEPAD.EXE %1 | |||
| (PID) Process: | (1968) rundll32.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.fas\OpenWithList |
| Operation: | write | Name: | a |
Value: NOTEPAD.EXE | |||
| (PID) Process: | (1968) rundll32.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.fas\OpenWithList |
| Operation: | write | Name: | MRUList |
Value: a | |||
| (PID) Process: | (1968) rundll32.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.fas\OpenWithProgids |
| Operation: | write | Name: | fas_auto_file |
Value: | |||
| (PID) Process: | (1968) rundll32.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\93\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||