| File name: | openhardwaremonitor-v0.9.6.zip |
| Full analysis: | https://app.any.run/tasks/730837c1-bded-483b-b6d8-d5637d3f6c35 |
| Verdict: | Malicious activity |
| Analysis date: | May 19, 2025, 17:42:26 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract, compression method=store |
| MD5: | 6F649C4615A01A4911283F2FECC00211 |
| SHA1: | BE8214DE9EBE3B9DC7470F3F10321AA2043F20F0 |
| SHA256: | 5E238C36AE5F8A8AB9AA5E6FA3C568967D61953393384C7C8FD6370F8BC86B85 |
| SSDEEP: | 12288:X1lKssKgSWgd+8RzGs4VcyB/kMNikz6FXSTjKTe9IAaV:X1Qssi+8R54vhtNf+FpxAq |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 20 |
|---|---|
| ZipBitFlag: | - |
| ZipCompression: | None |
| ZipModifyDate: | 2020:12:27 16:06:36 |
| ZipCRC: | 0x00000000 |
| ZipCompressedSize: | - |
| ZipUncompressedSize: | - |
| ZipFileName: | OpenHardwareMonitor/ |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1388 | "C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\openhardwaremonitor-v0.9.6.zip | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Version: 5.91.0 Modules
| |||||||||||||||
| 2980 | "C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEvent | C:\Windows\System32\slui.exe | — | SppExtComObj.Exe | |||||||||||
User: NETWORK SERVICE Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows Activation Client Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 3100 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa1388.37094\OpenHardwareMonitor\OpenHardwareMonitor.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa1388.37094\OpenHardwareMonitor\OpenHardwareMonitor.exe | WinRAR.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: Open Hardware Monitor Version: 0.9.6.0 Modules
| |||||||||||||||
| 4180 | C:\WINDOWS\system32\SppExtComObj.exe -Embedding | C:\Windows\System32\SppExtComObj.Exe | — | svchost.exe | |||||||||||
User: NETWORK SERVICE Company: Microsoft Corporation Integrity Level: SYSTEM Description: KMS Connection Broker Version: 10.0.19041.3996 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 4724 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | csc.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 5212 | "C:\WINDOWS\system32\WBEM\mofcomp.exe" C:\WINDOWS\system32\WBEM\Framework\root\OpenHardwareMonitor\OpenHardwareMonitor_SN__Version_0.9.6.0.mof | C:\Windows\System32\wbem\mofcomp.exe | — | OpenHardwareMonitor.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: The Managed Object Format (MOF) Compiler Exit code: 0 Version: 10.0.19041.3758 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 5528 | "C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe" /noconfig /fullpaths @"C:\Users\admin\AppData\Local\Temp\yndrf012\yndrf012.cmdline" | C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe | OpenHardwareMonitor.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Visual C# Command Line Compiler Exit code: 0 Version: 4.8.9037.0 built by: NET481REL1 Modules
| |||||||||||||||
| 5796 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa1388.37094\OpenHardwareMonitor\OpenHardwareMonitor.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa1388.37094\OpenHardwareMonitor\OpenHardwareMonitor.exe | — | WinRAR.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: Open Hardware Monitor Exit code: 3221226540 Version: 0.9.6.0 Modules
| |||||||||||||||
| 6872 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | mofcomp.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6872 | C:\Windows\Microsoft.NET\Framework64\v4.0.30319\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 "/OUT:C:\Users\admin\AppData\Local\Temp\RES1AA9.tmp" "c:\Users\admin\AppData\Local\Temp\yndrf012\CSC21E2547BAAC14FE4B386AA9724F357D.TMP" | C:\Windows\Microsoft.NET\Framework64\v4.0.30319\cvtres.exe | — | csc.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft® Resource File To COFF Object Conversion Utility Exit code: 0 Version: 14.32.31326.0 Modules
| |||||||||||||||
| (PID) Process: | (1388) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\preferences.zip | |||
| (PID) Process: | (1388) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\chromium_ext.zip | |||
| (PID) Process: | (1388) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\omni_23_10_2024_.zip | |||
| (PID) Process: | (1388) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\openhardwaremonitor-v0.9.6.zip | |||
| (PID) Process: | (1388) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (1388) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (1388) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (1388) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1388 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa1388.37094\OpenHardwareMonitor\OpenHardwareMonitor.exe | executable | |
MD5:A261F824AB957A5331AF53C7722FA2DE | SHA256:EC767A74C5659A05BDB7AC10BD42C2EA6D44FA946286029B2866AED476AD83BC | |||
| 1388 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa1388.37094\OpenHardwareMonitor\OxyPlot.WindowsForms.dll | executable | |
MD5:689121CA3540A36B3829FD887635756F | SHA256:C92CFE4026EF2319C84AAB392F274EBDEB135DB85123FF0E44EDF4A99B05C7D0 | |||
| 5528 | csc.exe | C:\Users\admin\AppData\Local\Temp\yndrf012\yndrf012.out | text | |
MD5:D0C786911ABB44D84DFACB0362275A49 | SHA256:E713B30349ADB8B89EBF2F9CCD6211462728879FC5D5CF7BB5CE23D42EE8CE22 | |||
| 3100 | OpenHardwareMonitor.exe | C:\Users\admin\AppData\Local\Temp\yndrf012\yndrf012.cmdline | text | |
MD5:770F01EFD42567EEF96DB4ECB0307B41 | SHA256:751EC5985FAA393DABF2029F6B5A3114317299EA2F7BC1E562FD2C0B756B164D | |||
| 3100 | OpenHardwareMonitor.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa1388.37094\OpenHardwareMonitor\OpenHardwareMonitorLib.sys | executable | |
MD5:0C0195C48B6B8582FA6F6373032118DA | SHA256:11BD2C9F9E2397C9A16E0990E4ED2CF0679498FE0FD418A3DFDAC60B5C160EE5 | |||
| 5212 | mofcomp.exe | C:\Users\admin\AppData\Local\Temp\tmp1922.tmp | binary | |
MD5:3B4622B7740BCC231247AFF66F47006D | SHA256:322974E6E9462B3F4C692FB23B6EC1F95DD683FFEAD6E6D30EB56DE6E94910E0 | |||
| 5528 | csc.exe | C:\Users\admin\AppData\Local\Temp\yndrf012\CSC21E2547BAAC14FE4B386AA9724F357D.TMP | binary | |
MD5:32583FFF0DF15F96B99CCFC2F7103FB0 | SHA256:FCA80271080D5EA150AC337078A8EA0CA80D0D64C64CC25552AF790766E7BC82 | |||
| 6872 | cvtres.exe | C:\Users\admin\AppData\Local\Temp\RES1AA9.tmp | binary | |
MD5:3E2C9B342584F160F4FF6FD87A2B141F | SHA256:D4801B7F68EC5DACD496BE10C04FEC7BF6552E4DBAD43CF8A9EA33D0CAC8C4B7 | |||
| 3100 | OpenHardwareMonitor.exe | C:\Windows\System32\wbem\Framework\root\OpenHardwareMonitor\OpenHardwareMonitor_SN__Version_0.9.6.0.mof | binary | |
MD5:166B0F824F4182DA753478C46F28FAE0 | SHA256:400C466FAB6C3DE04295EF5BC5D51EBB8648E1AFEC93C1B42E43F2306F16BC40 | |||
| 5528 | csc.exe | C:\Users\admin\AppData\Local\Temp\yndrf012\yndrf012.dll | executable | |
MD5:A6302DDEB445DF23EFAEA9E46EBC0146 | SHA256:CDF7C602D35AC4FB60A26D75D3BC2634E1F66287603AE74893F781FCBBB197BD | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | GET | 200 | 2.17.147.64:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
— | — | GET | 200 | 2.17.190.73:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
— | — | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
7648 | SIHClient.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
7648 | SIHClient.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
— | — | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
— | — | 2.17.147.64:80 | crl.microsoft.com | Akamai International B.V. | CZ | whitelisted |
— | — | 184.30.21.171:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
6544 | svchost.exe | 40.126.31.131:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
— | — | 2.17.190.73:80 | ocsp.digicert.com | AKAMAI-AS | DE | whitelisted |
3216 | svchost.exe | 172.211.123.250:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | FR | unknown |
5496 | MoUsoCoreWorker.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
1616 | svchost.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |
fe3cr.delivery.mp.microsoft.com |
| whitelisted |
nexusrules.officeapps.live.com |
| whitelisted |