File name: | cdbxp_setup_4.5.4.5000.zip |
Full analysis: | https://app.any.run/tasks/19f87148-00a3-4f3f-863f-94eb82840fd5 |
Verdict: | Malicious activity |
Analysis date: | March 31, 2023, 20:06:52 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | application/zip |
File info: | Zip archive data, at least v2.0 to extract |
MD5: | 9ED5FFD35F1738EED6E9825967790F5A |
SHA1: | E0C3A0FCBEA120EF350E56F708920F07B5582E34 |
SHA256: | 5A41BB5DEB8383AB3501B48F42BCFF885DB87F287A539D2DDEB62BA4746FF65F |
SSDEEP: | 98304:v5K8at9Ch9cbPALTJGaSjETASO08GZi56EtNiBEzQxe/bqITMBwMOCOJsh9plkJX:v5KChaAXzSCAMK5LNitNqYo9O9Orj |
.zip | | | ZIP compressed archive (100) |
---|
ZipFileName: | cdbxp_setup_4.5.4.5000.exe |
---|---|
ZipUncompressedSize: | 5644000 |
ZipCompressedSize: | 5304939 |
ZipCRC: | 0xf5bf506c |
ZipModifyDate: | 2014:08:19 16:11:12 |
ZipCompression: | Deflated |
ZipBitFlag: | - |
ZipRequiredVersion: | 20 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
2368 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\cdbxp_setup_4.5.4.5000.zip" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
4060 | "C:\Users\admin\Desktop\cdbxp_setup_4.5.4.5000.exe" | C:\Users\admin\Desktop\cdbxp_setup_4.5.4.5000.exe | explorer.exe | ||||||||||||
User: admin Company: Canneverbe Limited Integrity Level: MEDIUM Description: CDBurnerXP Exit code: 0 Version: 4.5.4.5000 Modules
| |||||||||||||||
1540 | "C:\Users\admin\AppData\Local\Temp\is-219KA.tmp\cdbxp_setup_4.5.4.5000.tmp" /SL5="$50128,4977608,525312,C:\Users\admin\Desktop\cdbxp_setup_4.5.4.5000.exe" | C:\Users\admin\AppData\Local\Temp\is-219KA.tmp\cdbxp_setup_4.5.4.5000.tmp | — | cdbxp_setup_4.5.4.5000.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: Setup/Uninstall Exit code: 0 Version: 51.1051.0.0 Modules
| |||||||||||||||
2404 | "C:\Users\admin\Desktop\cdbxp_setup_4.5.4.5000.exe" /SPAWNWND=$90130 /NOTIFYWND=$50128 | C:\Users\admin\Desktop\cdbxp_setup_4.5.4.5000.exe | cdbxp_setup_4.5.4.5000.tmp | ||||||||||||
User: admin Company: Canneverbe Limited Integrity Level: HIGH Description: CDBurnerXP Exit code: 0 Version: 4.5.4.5000 Modules
| |||||||||||||||
3144 | "C:\Users\admin\AppData\Local\Temp\is-G5TRB.tmp\cdbxp_setup_4.5.4.5000.tmp" /SL5="$A0140,4977608,525312,C:\Users\admin\Desktop\cdbxp_setup_4.5.4.5000.exe" /SPAWNWND=$90130 /NOTIFYWND=$50128 | C:\Users\admin\AppData\Local\Temp\is-G5TRB.tmp\cdbxp_setup_4.5.4.5000.tmp | cdbxp_setup_4.5.4.5000.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: Setup/Uninstall Exit code: 0 Version: 51.1051.0.0 Modules
| |||||||||||||||
3000 | RunDll32.exe "C:\Users\admin\AppData\Local\Temp\is-6DU3H.tmp\OCSetupHlp.dll",_OCPID176OpenCandy2@16 3144,04079C7C6F1F4ECFA0C7AED6DF2CF79F,415CAB7D453A4F7CB1B492DF8AF89410,1B457B32E8F04B149801BA6843020ADC | C:\Windows\System32\rundll32.exe | — | cdbxp_setup_4.5.4.5000.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows host process (Rundll32) Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
1208 | "C:\Windows\system32\regsvr32.exe" /s "C:\Program Files\CDBurnerXP\StarBurnX15.dll" | C:\Windows\System32\regsvr32.exe | cdbxp_setup_4.5.4.5000.tmp | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft(C) Register Server Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
3420 | "Reg.exe" Copy HKCU\SOFTWARE\CDBurnerXP "HKCU\SOFTWARE\Canneverbe Limited\CDBurnerXP" /s /f | C:\Windows\System32\reg.exe | — | cdbxp_setup_4.5.4.5000.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Registry Console Tool Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
3552 | "Reg.exe" Delete HKCU\SOFTWARE\CDBurnerXP /f | C:\Windows\System32\reg.exe | — | cdbxp_setup_4.5.4.5000.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Registry Console Tool Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
2396 | "C:\Windows\system32\regsvr32.exe" /s "C:\Program Files\CDBurnerXP\StarBurnX15.dll" | C:\Windows\System32\regsvr32.exe | cdbxp_setup_4.5.4.5000.tmp | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft(C) Register Server Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
|
(PID) Process: | (2368) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\16D\52C64B7E |
Operation: | write | Name: | LanguageList |
Value: en-US | |||
(PID) Process: | (2368) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip | |||
(PID) Process: | (2368) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
(PID) Process: | (2368) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop\phacker.zip | |||
(PID) Process: | (2368) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | name |
Value: 120 | |||
(PID) Process: | (2368) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | size |
Value: 80 | |||
(PID) Process: | (2368) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | type |
Value: 120 | |||
(PID) Process: | (2368) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | mtime |
Value: 100 | |||
(PID) Process: | (2368) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU |
Operation: | write | Name: | NodeSlots |
Value: 0202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202 | |||
(PID) Process: | (2368) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU |
Operation: | write | Name: | MRUListEx |
Value: 0C000000000000000B00000001000000020000000D00000007000000060000000A0000000900000008000000030000000500000004000000FFFFFFFF |
PID | Process | Filename | Type | |
---|---|---|---|---|
2368 | WinRAR.exe | C:\Users\admin\Desktop\cdbxp_setup_4.5.4.5000.exe | executable | |
MD5:C9D490C5E267FE9AE8B35A30451B3B0B | SHA256:E7C7DE9C5A78E67740CC849FCD9D2CC760BE1688FFB045D6DD38A0EB286DEFAE | |||
2404 | cdbxp_setup_4.5.4.5000.exe | C:\Users\admin\AppData\Local\Temp\is-G5TRB.tmp\cdbxp_setup_4.5.4.5000.tmp | executable | |
MD5:60176F68FE54E7BF1768B661A997DCA7 | SHA256:3A411D770671AE1AC2FA430CE954EA3F9C907A0CA0E60B674C63DCF6F78B1659 | |||
3144 | cdbxp_setup_4.5.4.5000.tmp | C:\Program Files\CDBurnerXP\is-N9QOT.tmp | executable | |
MD5:FC8007495A4105259F24C845369AB38F | SHA256:55742EB60D8EFC194D800BFB543CF363E5A18403998EC9F6C55177FDF9429132 | |||
3144 | cdbxp_setup_4.5.4.5000.tmp | C:\Program Files\CDBurnerXP\bassflac.dll | executable | |
MD5:B82D5B3867506593A17DC3C860C6B57E | SHA256:53E2BFC9CC5347FDCD07B2C43833C4CA1FE7EB978265841147549F1F33C6ADCD | |||
3144 | cdbxp_setup_4.5.4.5000.tmp | C:\Users\admin\AppData\Local\Temp\is-6DU3H.tmp\_isetup\_shfoldr.dll | executable | |
MD5:92DC6EF532FBB4A5C3201469A5B5EB63 | SHA256:9884E9D1B4F8A873CCBD81F8AD0AE257776D2348D027D811A56475E028360D87 | |||
3144 | cdbxp_setup_4.5.4.5000.tmp | C:\Program Files\CDBurnerXP\basswma.dll | executable | |
MD5:7B52BE6D702AA590DB57A0E135F81C45 | SHA256:9B5A8B323D2D1209A5696EAF521669886F028CE1ECDBB49D1610C09A22746330 | |||
3144 | cdbxp_setup_4.5.4.5000.tmp | C:\Users\admin\AppData\Local\Temp\is-6DU3H.tmp\OCSetupHlp.dll | executable | |
MD5:7B4C4AD3576852B7B3A1AC321D2CDE0E | SHA256:8DD4D9A707286C7B440EED0B6B014C8E8728E99BE0B8F254D5BDD37D1DCFDF91 | |||
4060 | cdbxp_setup_4.5.4.5000.exe | C:\Users\admin\AppData\Local\Temp\is-219KA.tmp\cdbxp_setup_4.5.4.5000.tmp | executable | |
MD5:60176F68FE54E7BF1768B661A997DCA7 | SHA256:3A411D770671AE1AC2FA430CE954EA3F9C907A0CA0E60B674C63DCF6F78B1659 | |||
3144 | cdbxp_setup_4.5.4.5000.tmp | C:\Program Files\CDBurnerXP\is-6QVJR.tmp | executable | |
MD5:7B52BE6D702AA590DB57A0E135F81C45 | SHA256:9B5A8B323D2D1209A5696EAF521669886F028CE1ECDBB49D1610C09A22746330 | |||
3144 | cdbxp_setup_4.5.4.5000.tmp | C:\Program Files\CDBurnerXP\is-8L791.tmp | executable | |
MD5:8005750EC63EB5292884AD6183AE2E77 | SHA256:DF9F56C4DA160101567B0526845228EE481EE7D2F98391696FA27FE41F8ACF15 |
Domain | IP | Reputation |
---|---|---|
api.opencandy.com |
| whitelisted |
update.cdburnerxp.se |
| unknown |
update.cdburnerxp.org |
| unknown |
Process | Message |
---|---|
regsvr32.exe | HKCR
{
NoRemove AppID
{
'{3DD7EA49-B5E1-4493-895D-C73562138FC0}' = s 'StarBurnXLib'
'StarBurnX12.DLL'
{
val AppID = s '{3DD7EA49-B5E1-4493-895D-C73562138FC0}'
'Version' = s '[!output TYPELIB_VERSION_MAJOR].[!output TYPELIB_VERSION_MINOR]'
}
}
}
|
regsvr32.exe | HKCR
{
StarBurnX.DriveSpeed.15 = s 'DriveSpeed Class'
{
CLSID = s '{E0EEE430-80D8-42D7-8D83-F046AECD7536}'
}
StarBurnX.DriveSpeed = s 'DriveSpeed Class'
{
CLSID = s '{E0EEE430-80D8-42D7-8D83-F046AECD7536}'
CurVer = s 'StarBurnX.DriveSpeed.15'
}
NoRemove CLSID
{
ForceRemove {E0EEE430-80D8-42D7-8D83-F046AECD7536} = s 'DriveSpeed Class'
{
ProgID = s 'StarBurnX.DriveSpeed.15'
VersionIndependentProgID = s 'StarBurnX.DriveSpeed'
ForceRemove 'Programmable'
InprocServer32 = s 'C:\Program Files\CDBurnerXP\StarBurnX15.dll'
{
val ThreadingModel = s 'Free'
}
'TypeLib' = s '{93CBA48A-1C58-4648-B22D-8F3588CB8D95}'
'Version' = s '15.0'
}
}
}
|
regsvr32.exe | HKCR
{
NoRemove AppID
{
'{3DD7EA49-B5E1-4493-895D-C73562138FC0}' = s 'StarBurnXLib'
'StarBurnX12.DLL'
{
val AppID = s '{3DD7EA49-B5E1-4493-895D-C73562138FC0}'
'Version' = s '[!output TYPELIB_VERSION_MAJOR].[!output TYPELIB_VERSION_MINOR]'
}
}
}
|
regsvr32.exe | HKCR
{
StarBurnX.DriveSpeed.15 = s 'DriveSpeed Class'
{
CLSID = s '{E0EEE430-80D8-42D7-8D83-F046AECD7536}'
}
StarBurnX.DriveSpeed = s 'DriveSpeed Class'
{
CLSID = s '{E0EEE430-80D8-42D7-8D83-F046AECD7536}'
CurVer = s 'StarBurnX.DriveSpeed.15'
}
NoRemove CLSID
{
ForceRemove {E0EEE430-80D8-42D7-8D83-F046AECD7536} = s 'DriveSpeed Class'
{
ProgID = s 'StarBurnX.DriveSpeed.15'
VersionIndependentProgID = s 'StarBurnX.DriveSpeed'
ForceRemove 'Programmable'
InprocServer32 = s 'C:\Program Files\CDBurnerXP\StarBurnX15.dll'
{
val ThreadingModel = s 'Free'
}
'TypeLib' = s '{93CBA48A-1C58-4648-B22D-8F3588CB8D95}'
'Version' = s '15.0'
}
}
}
|
regsvr32.exe | HKCR
{
StarBurnX.DriveSpeeds.15 = s 'DriveSpeeds Class'
{
CLSID = s '{7169A231-64EC-4702-98AB-05ABB6D882A9}'
}
StarBurnX.DriveSpeeds = s 'DriveSpeeds Class'
{
CLSID = s '{7169A231-64EC-4702-98AB-05ABB6D882A9}'
CurVer = s 'StarBurnX.DriveSpeeds.15'
}
NoRemove CLSID
{
ForceRemove {7169A231-64EC-4702-98AB-05ABB6D882A9} = s 'DriveSpeeds Class'
{
ProgID = s 'StarBurnX.DriveSpeeds.15'
VersionIndependentProgID = s 'StarBurnX.DriveSpeeds'
ForceRemove 'Programmable'
InprocServer32 = s 'C:\Program Files\CDBurnerXP\StarBurnX15.dll'
{
val ThreadingModel = s 'Free'
}
'TypeLib' = s '{93CBA48A-1C58-4648-B22D-8F3588CB8D95}'
'Version' = s '15.0'
}
}
}
|
regsvr32.exe | HKCR
{
StarBurnX.DriveSpeeds.15 = s 'DriveSpeeds Class'
{
CLSID = s '{7169A231-64EC-4702-98AB-05ABB6D882A9}'
}
StarBurnX.DriveSpeeds = s 'DriveSpeeds Class'
{
CLSID = s '{7169A231-64EC-4702-98AB-05ABB6D882A9}'
CurVer = s 'StarBurnX.DriveSpeeds.15'
}
NoRemove CLSID
{
ForceRemove {7169A231-64EC-4702-98AB-05ABB6D882A9} = s 'DriveSpeeds Class'
{
ProgID = s 'StarBurnX.DriveSpeeds.15'
VersionIndependentProgID = s 'StarBurnX.DriveSpeeds'
ForceRemove 'Programmable'
InprocServer32 = s 'C:\Program Files\CDBurnerXP\StarBurnX15.dll'
{
val ThreadingModel = s 'Free'
}
'TypeLib' = s '{93CBA48A-1C58-4648-B22D-8F3588CB8D95}'
'Version' = s '15.0'
}
}
}
|
regsvr32.exe | HKCR
{
StarBurnX.DriveInfo.15 = s 'DriveInfo Class'
{
CLSID = s '{996C8DFD-8CE6-43B2-9414-CB6132485363}'
}
StarBurnX.DriveInfo = s 'DriveInfo Class'
{
CLSID = s '{996C8DFD-8CE6-43B2-9414-CB6132485363}'
CurVer = s 'StarBurnX.DriveInfo.15'
}
NoRemove CLSID
{
ForceRemove {996C8DFD-8CE6-43B2-9414-CB6132485363} = s 'DriveInfo Class'
{
ProgID = s 'StarBurnX.DriveInfo.15'
VersionIndependentProgID = s 'StarBurnX.DriveInfo'
ForceRemove 'Programmable'
InprocServer32 = s 'C:\Program Files\CDBurnerXP\StarBurnX15.dll'
{
val ThreadingModel = s 'Free'
}
'TypeLib' = s '{93CBA48A-1C58-4648-B22D-8F3588CB8D95}'
'Version' = s '15.0'
}
}
}
|
regsvr32.exe | HKCR
{
StarBurnX.DriveInfo.15 = s 'DriveInfo Class'
{
CLSID = s '{996C8DFD-8CE6-43B2-9414-CB6132485363}'
}
StarBurnX.DriveInfo = s 'DriveInfo Class'
{
CLSID = s '{996C8DFD-8CE6-43B2-9414-CB6132485363}'
CurVer = s 'StarBurnX.DriveInfo.15'
}
NoRemove CLSID
{
ForceRemove {996C8DFD-8CE6-43B2-9414-CB6132485363} = s 'DriveInfo Class'
{
ProgID = s 'StarBurnX.DriveInfo.15'
VersionIndependentProgID = s 'StarBurnX.DriveInfo'
ForceRemove 'Programmable'
InprocServer32 = s 'C:\Program Files\CDBurnerXP\StarBurnX15.dll'
{
val ThreadingModel = s 'Free'
}
'TypeLib' = s '{93CBA48A-1C58-4648-B22D-8F3588CB8D95}'
'Version' = s '15.0'
}
}
}
|
regsvr32.exe | HKCR
{
StarBurnX.Track.15 = s 'Track Class'
{
CLSID = s '{F750BC9F-72CE-45C6-9D1F-BFEFB0765918}'
}
StarBurnX.Track = s 'Track Class'
{
CLSID = s '{F750BC9F-72CE-45C6-9D1F-BFEFB0765918}'
CurVer = s 'StarBurnX.Track.15'
}
NoRemove CLSID
{
ForceRemove {F750BC9F-72CE-45C6-9D1F-BFEFB0765918} = s 'Track Class'
{
ProgID = s 'StarBurnX.Track.15'
VersionIndependentProgID = s 'StarBurnX.Track'
ForceRemove 'Programmable'
InprocServer32 = s 'C:\Program Files\CDBurnerXP\StarBurnX15.dll'
{
val ThreadingModel = s 'Free'
}
'TypeLib' = s '{93CBA48A-1C58-4648-B22D-8F3588CB8D95}'
'Version' = s '15.0'
}
}
}
|
regsvr32.exe | HKCR
{
StarBurnX.Track.15 = s 'Track Class'
{
CLSID = s '{F750BC9F-72CE-45C6-9D1F-BFEFB0765918}'
}
StarBurnX.Track = s 'Track Class'
{
CLSID = s '{F750BC9F-72CE-45C6-9D1F-BFEFB0765918}'
CurVer = s 'StarBurnX.Track.15'
}
NoRemove CLSID
{
ForceRemove {F750BC9F-72CE-45C6-9D1F-BFEFB0765918} = s 'Track Class'
{
ProgID = s 'StarBurnX.Track.15'
VersionIndependentProgID = s 'StarBurnX.Track'
ForceRemove 'Programmable'
InprocServer32 = s 'C:\Program Files\CDBurnerXP\StarBurnX15.dll'
{
val ThreadingModel = s 'Free'
}
'TypeLib' = s '{93CBA48A-1C58-4648-B22D-8F3588CB8D95}'
'Version' = s '15.0'
}
}
}
|