General Info

File name

zvuki_prirodi.exe

Full analysis
https://app.any.run/tasks/5148e4d7-59eb-4c0a-bff5-2c8a503acc77
Verdict
Malicious activity
Analysis date
4/14/2019, 20:34:50
OS:
Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:

installer

Indicators:

MIME:
application/x-dosexec
File info:
PE32 executable (GUI) Intel 80386, for MS Windows
MD5

3ae5d44682e075d8e75d78845e804bf0

SHA1

4eab142ffd0cc46f8d3f15e4b28ea066bfeb7968

SHA256

613e937880b599d06ef140cf5c205ced69568e0177f4e8f8bc30af46197dd3cc

SSDEEP

98304:QX40ZzkqoSEazwxMGYDmDf74bPd8lK9B7GEjMHIGaHPIM7b0/cPkJ+YurZB:OrZzWSrzwxCojQZ2IjYcMfu9B

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distored by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.

Software environment set and analysis options

Launch configuration

Task duration
60 seconds
Additional time used
none
Fakenet option
off
Heavy Evaision option
off
MITM proxy
off
Route via Tor
off
Network geolocation
off
Privacy
Public submission
Autoconfirmation of UAC
on

Software preset

  • Internet Explorer 8.0.7601.17514
  • Adobe Acrobat Reader DC MUI (15.023.20070)
  • Adobe Flash Player 26 ActiveX (26.0.0.131)
  • Adobe Flash Player 26 NPAPI (26.0.0.131)
  • Adobe Flash Player 26 PPAPI (26.0.0.131)
  • Adobe Refresh Manager (1.8.0)
  • CCleaner (5.35)
  • FileZilla Client 3.36.0 (3.36.0)
  • Google Chrome (73.0.3683.75)
  • Google Update Helper (1.3.33.23)
  • Java 8 Update 92 (8.0.920.14)
  • Java Auto Updater (2.8.92.14)
  • Microsoft .NET Framework 4.6.1 (4.6.01055)
  • Microsoft Office Access MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Access Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Excel MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office OneNote MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Outlook MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office PowerPoint MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Professional 2010 (14.0.6029.1000)
  • Microsoft Office Proof (English) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (French) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Spanish) 2010 (14.0.6029.1000)
  • Microsoft Office Proofing (English) 2010 (14.0.6029.1000)
  • Microsoft Office Publisher MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Single Image 2010 (14.0.6029.1000)
  • Microsoft Office Word MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (9.0.30729.6161)
  • Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (10.0.40219)
  • Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (12.0.30501.0)
  • Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2017 Redistributable (x86) - 14.15.26706 (14.15.26706.0)
  • Microsoft Visual C++ 2017 x86 Additional Runtime - 14.15.26706 (14.15.26706)
  • Microsoft Visual C++ 2017 x86 Minimum Runtime - 14.15.26706 (14.15.26706)
  • Mozilla Firefox 65.0.2 (x86 en-US) (65.0.2)
  • Notepad++ (32-bit x86) (7.5.1)
  • Opera 12.15 (12.15.1748)
  • Skype version 8.29 (8.29)
  • VLC media player (2.2.6)
  • WinRAR 5.60 (32-bit) (5.60.0)

Hotfixes

  • Client LanguagePack Package
  • Client Refresh LanguagePack Package
  • CodecPack Basic Package
  • Foundation Package
  • IE Troubleshooters Package
  • InternetExplorer Optional Package
  • KB2534111
  • KB2999226
  • KB976902
  • LocalPack AU Package
  • LocalPack CA Package
  • LocalPack GB Package
  • LocalPack US Package
  • LocalPack ZA Package
  • ProfessionalEdition
  • UltimateEdition

Behavior activities

MALICIOUS SUSPICIOUS INFO
Loads the Task Scheduler COM API
  • schtasks.exe (PID: 3492)
  • schtasks.exe (PID: 1336)
Loads dropped or rewritten executable
  • VkontakteDJ.exe (PID: 2184)
Uses Task Scheduler to run other applications
  • VkontakteDJ.exe (PID: 2184)
  • zvuki_prirodi.tmp (PID: 3384)
Application was dropped or rewritten from another process
  • VkontakteDJ.exe (PID: 2184)
Modifies the open verb of a shell class
  • VkontakteDJ.exe (PID: 2184)
Creates files in the user directory
  • VkontakteDJ.exe (PID: 2184)
  • zvuki_prirodi.tmp (PID: 3384)
Reads Windows owner or organization settings
  • zvuki_prirodi.tmp (PID: 3384)
Executable content was dropped or overwritten
  • zvuki_prirodi.tmp (PID: 3384)
  • zvuki_prirodi.exe (PID: 2812)
  • zvuki_prirodi.exe (PID: 2916)
Reads the Windows organization settings
  • zvuki_prirodi.tmp (PID: 3384)
Application was dropped or rewritten from another process
  • downloader.exe (PID: 2480)
  • zvuki_prirodi.tmp (PID: 2612)
  • zvuki_prirodi.tmp (PID: 3384)
Creates files in the program directory
  • zvuki_prirodi.tmp (PID: 3384)
Creates a software uninstall entry
  • zvuki_prirodi.tmp (PID: 3384)

Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Static information

TRiD
.exe
|   Inno Setup installer (67.7%)
.exe
|   Win32 EXE PECompact compressed (generic) (25.6%)
.exe
|   Win32 Executable (generic) (2.7%)
.exe
|   Win16/32 Executable Delphi generic (1.2%)
.exe
|   Generic Win/DOS Executable (1.2%)
EXIF
EXE
MachineType:
Intel 386 or later, and compatibles
TimeStamp:
2019:03:07 07:30:01+01:00
PEType:
PE32
LinkerVersion:
2.25
CodeSize:
682496
InitializedDataSize:
174592
UninitializedDataSize:
null
EntryPoint:
0xa7ed0
OSVersion:
6
ImageVersion:
6
SubsystemVersion:
6
Subsystem:
Windows GUI
FileVersionNumber:
1.5.0.17
ProductVersionNumber:
1.5.0.17
FileFlagsMask:
0x003f
FileFlags:
(none)
FileOS:
Win32
ObjectFileType:
Executable application
FileSubtype:
null
LanguageCode:
Neutral
CharacterSet:
Unicode
Comments:
This installation was built with Inno Setup.
CompanyName:
VK loader
FileDescription:
VK loader Setup
FileVersion:
1.5.0.17
LegalCopyright:
OriginalFileName:
ProductName:
VK loader
ProductVersion:
3
Summary
Architecture:
IMAGE_FILE_MACHINE_I386
Subsystem:
IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date:
07-Mar-2019 06:30:01
Detected languages
English - United States
Comments:
This installation was built with Inno Setup.
CompanyName:
VK loader
FileDescription:
VK loader Setup
FileVersion:
1.5.0.17
LegalCopyright:
null
OriginalFileName:
null
ProductName:
VK loader
ProductVersion:
3
DOS Header
Magic number:
MZ
Bytes on last page of file:
0x0050
Pages in file:
0x0002
Relocations:
0x0000
Size of header:
0x0004
Min extra paragraphs:
0x000F
Max extra paragraphs:
0xFFFF
Initial SS value:
0x0000
Initial SP value:
0x00B8
Checksum:
0x0000
Initial IP value:
0x0000
Initial CS value:
0x0000
Overlay number:
0x001A
OEM identifier:
0x0000
OEM information:
0x0000
Address of NE header:
0x00000100
PE Headers
Signature:
PE
Machine:
IMAGE_FILE_MACHINE_I386
Number of sections:
10
Time date stamp:
07-Mar-2019 06:30:01
Pointer to Symbol Table:
0x00000000
Number of symbols:
0
Size of Optional Header:
0x00E0
Characteristics
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_BYTES_REVERSED_HI
IMAGE_FILE_BYTES_REVERSED_LO
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED
Sections
Name Virtual Address Virtual Size Raw Size Charateristics Entropy
.text 0x00001000 0x000A50E0 0x000A5200 IMAGE_SCN_CNT_CODE,IMAGE_SCN_MEM_EXECUTE,IMAGE_SCN_MEM_READ 6.36825
.itext 0x000A7000 0x00001668 0x00001800 IMAGE_SCN_CNT_CODE,IMAGE_SCN_MEM_EXECUTE,IMAGE_SCN_MEM_READ 5.95049
.data 0x000A9000 0x000037A4 0x00003800 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 5.02787
.bss 0x000AD000 0x0000676C 0x00000000 IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 0
.idata 0x000B4000 0x00000F1C 0x00001000 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 4.79161
.didata 0x000B5000 0x000001A4 0x00000200 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 2.74582
.edata 0x000B6000 0x0000009A 0x00000200 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ 1.88107
.tls 0x000B7000 0x00000018 0x00000000 IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 0
.rdata 0x000B8000 0x0000005D 0x00000200 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ 1.36974
.rsrc 0x000B9000 0x00025A48 0x00025C00 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ 3.15892
Resources
1

2

3

4

5

6

4086

4087

4088

4089

4090

4091

4092

4093

4094

4095

4096

11111

DVCLAL

PACKAGEINFO

MAINICON

Imports
    kernel32.dll

    comctl32.dll

    version.dll

    user32.dll

    oleaut32.dll

    netapi32.dll

    advapi32.dll

    kernel32.dll (delay-loaded)

Exports
    dbkFCallWrapperAddr

    __dbk_fcall_wrapper

    TMethodImplementationIntercept

Screenshots

Processes

Total processes
44
Monitored processes
8
Malicious processes
3
Suspicious processes
2

Behavior graph

+
drop and start start drop and start drop and start drop and start zvuki_prirodi.exe zvuki_prirodi.tmp no specs zvuki_prirodi.exe zvuki_prirodi.tmp schtasks.exe no specs downloader.exe vkontaktedj.exe schtasks.exe no specs
Specs description
Program did not start
Integrity level elevation
Task сontains an error or was rebooted
Process has crashed
Task contains several apps running
Executable file was dropped
Debug information is available
Process was injected
Network attacks were detected
Application downloaded the executable file
Actions similar to stealing personal data
Behavior similar to exploiting the vulnerability
Inspected object has sucpicious PE structure
File is detected by antivirus software
CPU overrun
RAM overrun
Process starts the services
Process was added to the startup
Behavior similar to spam
Low-level access to the HDD
Probably Tor was used
System was rebooted
Connects to the network
Known threat

Process information

Click at the process to see the details.

PID
2916
CMD
"C:\Users\admin\AppData\Local\Temp\zvuki_prirodi.exe"
Path
C:\Users\admin\AppData\Local\Temp\zvuki_prirodi.exe
Indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Version:
Company
VK loader
Description
VK loader Setup
Version
1.5.0.17
Modules
Image
c:\users\admin\appdata\local\temp\zvuki_prirodi.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\version.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\propsys.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\comres.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\shell32.dll
c:\users\admin\appdata\local\temp\is-1l14t.tmp\zvuki_prirodi.tmp

PID
2612
CMD
"C:\Users\admin\AppData\Local\Temp\is-1L14T.tmp\zvuki_prirodi.tmp" /SL5="$30112,5905353,858112,C:\Users\admin\AppData\Local\Temp\zvuki_prirodi.exe"
Path
C:\Users\admin\AppData\Local\Temp\is-1L14T.tmp\zvuki_prirodi.tmp
Indicators
No indicators
Parent process
zvuki_prirodi.exe
User
admin
Integrity Level
MEDIUM
Version:
Company
Description
Setup/Uninstall
Version
51.1052.0.0
Modules
Image
c:\users\admin\appdata\local\temp\is-1l14t.tmp\zvuki_prirodi.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\version.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\propsys.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\comres.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\winsta.dll
c:\windows\system32\shdocvw.dll

PID
2812
CMD
"C:\Users\admin\AppData\Local\Temp\zvuki_prirodi.exe" /SPAWNWND=$30134 /NOTIFYWND=$30112
Path
C:\Users\admin\AppData\Local\Temp\zvuki_prirodi.exe
Indicators
Parent process
zvuki_prirodi.tmp
User
admin
Integrity Level
HIGH
Version:
Company
VK loader
Description
VK loader Setup
Version
1.5.0.17
Modules
Image
c:\users\admin\appdata\local\temp\zvuki_prirodi.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\version.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\propsys.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\comres.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\shell32.dll
c:\users\admin\appdata\local\temp\is-jmhgr.tmp\zvuki_prirodi.tmp

PID
3384
CMD
"C:\Users\admin\AppData\Local\Temp\is-JMHGR.tmp\zvuki_prirodi.tmp" /SL5="$3011E,5905353,858112,C:\Users\admin\AppData\Local\Temp\zvuki_prirodi.exe" /SPAWNWND=$30134 /NOTIFYWND=$30112
Path
C:\Users\admin\AppData\Local\Temp\is-JMHGR.tmp\zvuki_prirodi.tmp
Indicators
Parent process
zvuki_prirodi.exe
User
admin
Integrity Level
HIGH
Version:
Company
Description
Setup/Uninstall
Version
51.1052.0.0
Modules
Image
c:\users\admin\appdata\local\temp\is-jmhgr.tmp\zvuki_prirodi.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\version.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\propsys.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\comres.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\winsta.dll
c:\windows\system32\shfolder.dll
c:\windows\system32\rstrtmgr.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\imageres.dll
c:\program files\common files\microsoft shared\ink\tiptsf.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\credssp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\linkinfo.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\slc.dll
c:\programdata\vk loader\vkontaktedj.exe
c:\programdata\vk loader\unins000.exe
c:\users\admin\appdata\local\temp\is-pg6ei.tmp\downloader.exe

PID
1336
CMD
"schtasks.exe" /Create /TN VKDJ /SC ONLOGON /TR "C:\ProgramData\VK loader\VkontakteDJ.exe /H" /F /DELAY 0001:00 /RL HIGHEST
Path
C:\Windows\system32\schtasks.exe
Indicators
No indicators
Parent process
zvuki_prirodi.tmp
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Manages scheduled tasks
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\schtasks.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ktmw32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\version.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\taskschd.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\xmllite.dll

PID
2480
CMD
"C:\Users\admin\AppData\Local\Temp\is-PG6EI.tmp\downloader.exe" --partner vkontakte-dj-elements --distr /quiet /msicl "VID=566 YAHOMEPAGE=y YAQSEARCH=y YABM=y YABROWSER=y
Path
C:\Users\admin\AppData\Local\Temp\is-PG6EI.tmp\downloader.exe
Indicators
Parent process
zvuki_prirodi.tmp
User
admin
Integrity Level
HIGH
Version:
Company
Description
Setup Downloader
Version
0.1.0.32
Modules
Image
c:\users\admin\appdata\local\temp\is-pg6ei.tmp\downloader.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\wininet.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\version.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\wship6.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\msxml3.dll

PID
2184
CMD
"C:\ProgramData\VK loader\VkontakteDJ.exe"
Path
C:\ProgramData\VK loader\VkontakteDJ.exe
Indicators
Parent process
zvuki_prirodi.tmp
User
admin
Integrity Level
HIGH
Version:
Company
Description
VKDJ, Player
Version
3.96.0.0
Modules
Image
c:\programdata\vk loader\vkontaktedj.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\version.dll
c:\windows\system32\olepro32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\winmm.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\profapi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\windowscodecs.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ehstorshell.dll
c:\windows\system32\propsys.dll
c:\windows\system32\cscui.dll
c:\windows\system32\cscdll.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\slc.dll
c:\windows\system32\imageres.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\psapi.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\napinsp.dll
c:\windows\system32\pnrpnsp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\winrnr.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\wshtcpip.dll
c:\programdata\vk loader\libeay32.dll
c:\programdata\vk loader\ssleay32.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll

PID
3492
CMD
"C:\Windows\System32\schtasks.exe" /Create /TN VKDJ /SC ONLOGON /TR "C:\ProgramData\VK loader\VkontakteDJ.exe /H" /F /DELAY 0001:00 /RL HIGHEST
Path
C:\Windows\System32\schtasks.exe
Indicators
No indicators
Parent process
VkontakteDJ.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Manages scheduled tasks
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\schtasks.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ktmw32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\version.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\taskschd.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\xmllite.dll

Registry activity

Total events
705
Read events
645
Write events
53
Delete events
7

Modification events

PID
Process
Operation
Key
Name
Value
3384
zvuki_prirodi.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Owner
380D0000A0ED37CBF0F2D401
3384
zvuki_prirodi.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
SessionHash
3EEB73856BBBA21327039E7727D7B4945370E791328026452D77B16D312DB652
3384
zvuki_prirodi.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Sequence
1
3384
zvuki_prirodi.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
RegFiles0000
C:\ProgramData\VK loader\VkontakteDJ.exe
3384
zvuki_prirodi.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
RegFilesHash
91600B7A3B20826EA37E2A3D91655746F5807750A164DDFDF2B46DE818D6DF3F
3384
zvuki_prirodi.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{9AEC3BBC-8DD9-4715-9FC8-1457D682A004}_is1
Inno Setup: Setup Version
6.0.1-beta (u)
3384
zvuki_prirodi.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{9AEC3BBC-8DD9-4715-9FC8-1457D682A004}_is1
Inno Setup: App Path
C:\ProgramData\VK loader
3384
zvuki_prirodi.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{9AEC3BBC-8DD9-4715-9FC8-1457D682A004}_is1
InstallLocation
C:\ProgramData\VK loader\
3384
zvuki_prirodi.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{9AEC3BBC-8DD9-4715-9FC8-1457D682A004}_is1
Inno Setup: Icon Group
VK loader
3384
zvuki_prirodi.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{9AEC3BBC-8DD9-4715-9FC8-1457D682A004}_is1
Inno Setup: User
admin
3384
zvuki_prirodi.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{9AEC3BBC-8DD9-4715-9FC8-1457D682A004}_is1
Inno Setup: Language
english
3384
zvuki_prirodi.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{9AEC3BBC-8DD9-4715-9FC8-1457D682A004}_is1
DisplayName
VK loader (32-bit)
3384
zvuki_prirodi.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{9AEC3BBC-8DD9-4715-9FC8-1457D682A004}_is1
UninstallString
"C:\ProgramData\VK loader\unins000.exe"
3384
zvuki_prirodi.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{9AEC3BBC-8DD9-4715-9FC8-1457D682A004}_is1
QuietUninstallString
"C:\ProgramData\VK loader\unins000.exe" /SILENT
3384
zvuki_prirodi.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{9AEC3BBC-8DD9-4715-9FC8-1457D682A004}_is1
DisplayVersion
3
3384
zvuki_prirodi.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{9AEC3BBC-8DD9-4715-9FC8-1457D682A004}_is1
Publisher
VK loader
3384
zvuki_prirodi.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{9AEC3BBC-8DD9-4715-9FC8-1457D682A004}_is1
URLInfoAbout
http://vkdj.org
3384
zvuki_prirodi.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{9AEC3BBC-8DD9-4715-9FC8-1457D682A004}_is1
HelpLink
http://vkdj.org
3384
zvuki_prirodi.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{9AEC3BBC-8DD9-4715-9FC8-1457D682A004}_is1
URLUpdateInfo
http://vkdj.org
3384
zvuki_prirodi.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{9AEC3BBC-8DD9-4715-9FC8-1457D682A004}_is1
NoModify
1
3384
zvuki_prirodi.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{9AEC3BBC-8DD9-4715-9FC8-1457D682A004}_is1
NoRepair
1
3384
zvuki_prirodi.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{9AEC3BBC-8DD9-4715-9FC8-1457D682A004}_is1
InstallDate
20190414
3384
zvuki_prirodi.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{9AEC3BBC-8DD9-4715-9FC8-1457D682A004}_is1
MajorVersion
3
3384
zvuki_prirodi.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{9AEC3BBC-8DD9-4715-9FC8-1457D682A004}_is1
MinorVersion
0
3384
zvuki_prirodi.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{9AEC3BBC-8DD9-4715-9FC8-1457D682A004}_is1
VersionMajor
3
3384
zvuki_prirodi.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{9AEC3BBC-8DD9-4715-9FC8-1457D682A004}_is1
VersionMinor
0
3384
zvuki_prirodi.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{9AEC3BBC-8DD9-4715-9FC8-1457D682A004}_is1
EstimatedSize
11201
3384
zvuki_prirodi.tmp
delete key
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
2480
downloader.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\downloader_RASAPI32
EnableFileTracing
0
2480
downloader.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\downloader_RASAPI32
EnableConsoleTracing
0
2480
downloader.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\downloader_RASAPI32
FileTracingMask
4294901760
2480
downloader.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\downloader_RASAPI32
ConsoleTracingMask
4294901760
2480
downloader.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\downloader_RASAPI32
MaxFileSize
1048576
2480
downloader.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\downloader_RASAPI32
FileDirectory
%windir%\tracing
2480
downloader.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\downloader_RASMANCS
EnableFileTracing
0
2480
downloader.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\downloader_RASMANCS
EnableConsoleTracing
0
2480
downloader.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\downloader_RASMANCS
FileTracingMask
4294901760
2480
downloader.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\downloader_RASMANCS
ConsoleTracingMask
4294901760
2480
downloader.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\downloader_RASMANCS
MaxFileSize
1048576
2480
downloader.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\downloader_RASMANCS
FileDirectory
%windir%\tracing
2480
downloader.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
2480
downloader.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
4600000071000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
2480
downloader.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
2480
downloader.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
2184
VkontakteDJ.exe
write
HKEY_CURRENT_USER\Software\Vkontakte.dj
UniqID
{B1D89BFF-3BAE-42C2-B7DF-8F7D73530810}
2184
VkontakteDJ.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
2184
VkontakteDJ.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
2184
VkontakteDJ.exe
write
HKEY_CLASSES_ROOT\VKDJFile\DefaultIcon
C:\ProgramData\VK loader\VkontakteDJ.exe, 0
2184
VkontakteDJ.exe
write
HKEY_CLASSES_ROOT\VKDJFile\shell\open\command
"C:\ProgramData\VK loader\VkontakteDJ.exe" "%l"
2184
VkontakteDJ.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp3\OpenWithProgids
2184
VkontakteDJ.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp3
2184
VkontakteDJ.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp4\OpenWithProgids
2184
VkontakteDJ.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp4
2184
VkontakteDJ.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m3u\OpenWithProgids
2184
VkontakteDJ.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m3u
2184
VkontakteDJ.exe
write
HKEY_CLASSES_ROOT\.vkdj
VKDJFile

Files activity

Executable files
8
Suspicious files
1
Text files
4
Unknown types
5

Dropped files

PID
Process
Filename
Type
2916
zvuki_prirodi.exe
C:\Users\admin\AppData\Local\Temp\is-1L14T.tmp\zvuki_prirodi.tmp
executable
MD5: 738a48bfbc9dda2bcbd48606188311b8
SHA256: 5b8c393b576430a9320f7751ab2643c098a9b05da8df2d75b4136afd8402d2dc
3384
zvuki_prirodi.tmp
C:\ProgramData\VK loader\ssleay32.dll
executable
MD5: d4c0d211332dec5b8c11899e97f1d27c
SHA256: 4906d6651d4c21e209f6e6ac781c5924ac18facf099f8d3f1a9b5eb9498d7565
3384
zvuki_prirodi.tmp
C:\ProgramData\VK loader\libeay32.dll
executable
MD5: c1b41ce18f8065a5b0ce66a4fba48794
SHA256: 3b6cfd63d6489e5c7358a0ab5075231f843adbde7f9a3379d8af2d8b9e101322
3384
zvuki_prirodi.tmp
C:\ProgramData\VK loader\gdiplus.dll
executable
MD5: 871c903a90c45ca08a9d42803916c3f7
SHA256: f1da32183b3da19f75fa4ef0974a64895266b16d119bbb1da9fe63867dba0645
3384
zvuki_prirodi.tmp
C:\ProgramData\VK loader\VkontakteDJ.exe
executable
MD5: 4ff9ff229d48ab1adda339f9092e182a
SHA256: e5fbb404bdeab03d04290b0044a57576d6f4f05eb5c0818a4db859fcd5e5f8c9
3384
zvuki_prirodi.tmp
C:\ProgramData\VK loader\unins000.exe
executable
MD5: 56efb80c0d57d8fc3562f2deeee036b8
SHA256: 58ab9b1fb7602483515b2219cae1b5fa5367539f4aeb6a0fe2b66c30a8437936
2812
zvuki_prirodi.exe
C:\Users\admin\AppData\Local\Temp\is-JMHGR.tmp\zvuki_prirodi.tmp
executable
MD5: 738a48bfbc9dda2bcbd48606188311b8
SHA256: 5b8c393b576430a9320f7751ab2643c098a9b05da8df2d75b4136afd8402d2dc
3384
zvuki_prirodi.tmp
C:\Users\admin\AppData\Local\Temp\is-PG6EI.tmp\downloader.exe
executable
MD5: 7df933c48f70841613a9f0092b5e4a31
SHA256: 8e553e9aa721db167bdeaf7748bb09d4f497e3a469fd09b6a995ea25d378f1fb
3384
zvuki_prirodi.tmp
C:\Users\admin\AppData\Roaming\VKDJ\skins\dark_skin.zip
compressed
MD5: d564c5c1f049f5ef7098d9c244274ae7
SHA256: 12fab1a6e2fac6292dd8cc4aaf6ac61854622fdf10c188f06a70367c3b8a3767
2480
downloader.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\H6QNMHE9\info[1].rss
xml
MD5: dffff0fc603e40c5b7148fd1c124d3f0
SHA256: aee9419891ff17bf12613f1f3d54c758859c7886cfd4ffcaa35642d5dabfdafc
3384
zvuki_prirodi.tmp
C:\Users\admin\AppData\Local\Temp\is-PG6EI.tmp\is-QGBIU.tmp
––
MD5:  ––
SHA256:  ––
3384
zvuki_prirodi.tmp
C:\Users\admin\AppData\Roaming\VKDJ\skins\is-2S9DM.tmp
––
MD5:  ––
SHA256:  ––
3384
zvuki_prirodi.tmp
C:\ProgramData\VK loader\unins000.dat
dat
MD5: a4d4f338acb2ebbd2fde5b2fe71152c5
SHA256: e82b99fe4d47d1827b8496e4a1ac79c7ebf75fdd7aaba78f4e7531552b106c61
3384
zvuki_prirodi.tmp
C:\ProgramData\VK loader\is-FMHS3.tmp
––
MD5:  ––
SHA256:  ––
3384
zvuki_prirodi.tmp
C:\Users\admin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\VK loader.lnk
lnk
MD5: 5ead3feebcecb51e218d875052268dae
SHA256: 71b8f9da91aaccfed099a6fbeb9354e722f96ea32b5345291537f43e666fb325
3384
zvuki_prirodi.tmp
C:\ProgramData\VK loader\is-GJJNR.tmp
––
MD5:  ––
SHA256:  ––
3384
zvuki_prirodi.tmp
C:\ProgramData\VK loader\History.txt
text
MD5: 58633c512413b4030d9de3afbafcfeac
SHA256: d398a046312fa811570d1e420b5920817f62d818da343a523ff77b099a50c39a
3384
zvuki_prirodi.tmp
C:\ProgramData\VK loader\is-1D8A1.tmp
––
MD5:  ––
SHA256:  ––
3384
zvuki_prirodi.tmp
C:\Users\admin\Desktop\VK loader.lnk
lnk
MD5: adf2c40b0babae9c067b72f8703d5331
SHA256: 5c9c4f8bd67c867acc78152ea5d81ee6fe39f9997db213fb7448c630dd82ea4a
3384
zvuki_prirodi.tmp
C:\ProgramData\VK loader\is-5TERN.tmp
––
MD5:  ––
SHA256:  ––
3384
zvuki_prirodi.tmp
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VK loader\Uninstall VK loader.lnk
lnk
MD5: 83c69f6af9640dab465826321b29c853
SHA256: c8566b91a1ff49b98edf3659e997c7643a0a3e03ffc12d57e9749a4c1718a815
3384
zvuki_prirodi.tmp
C:\ProgramData\VK loader\is-TN0VG.tmp
––
MD5:  ––
SHA256:  ––
3384
zvuki_prirodi.tmp
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VK loader\VK loader.lnk
lnk
MD5: 6ff42195106ab0f407d7deddf475d45d
SHA256: b0f3def8c84a16172df1eb09bbaa6d869156d1bb266056077c58fdf0bcca78de
3384
zvuki_prirodi.tmp
C:\ProgramData\VK loader\is-8AGJG.tmp
––
MD5:  ––
SHA256:  ––
3384
zvuki_prirodi.tmp
C:\Users\admin\AppData\Local\Temp\is-PG6EI.tmp\Logo Y.bmp
image
MD5: cd27ca4630048317a85b4100982c7150
SHA256: 5a2b9897df59d25b4870ee5148003983e9317a5066c2c496b4efc056b2224e7a
3384
zvuki_prirodi.tmp
C:\Users\admin\AppData\Local\Temp\is-PG6EI.tmp\is-KUSFD.tmp
––
MD5:  ––
SHA256:  ––
2480
downloader.exe
C:\Users\admin\AppData\Local\Temp\7F4987FB1A6E43d69E3E94B29EB75926\seed.txt
text
MD5: 0314c9b108b8c39f1cf878ed93fdd5ae
SHA256: aafee1a675603cc425b2f1798cba53f2489066cd54c54fa3fa07c081b5082659

Find more information of the staic content and download it at the full report

Network activity

HTTP(S) requests
7
TCP/UDP connections
7
DNS requests
6
Threats
3

HTTP requests

PID Process Method HTTP Code IP URL CN Type Size Reputation
3384 zvuki_prirodi.tmp GET 200 54.36.175.115:80 http://dj-updates.com/client.config/?app=vk_downloader&format=xml&uid=60E846AE-54A4-421F-9FE0-BC3989560BA6-29eeb6c8cd5601d403794080122f43a3&version=1.5&w_info=cl_downloader&advert_key=ZWMwMDAxMDBiNDAwMTJkNzAwMDAxMmIzMDAxMmIzMDAxMmIzZjM5ZTFiNzcxZQ==_vk_vk FR
xml
malicious
2480 downloader.exe GET 302 5.45.205.241:80 http://downloader.yandex.net/yandex-pack/downloader/info.rss RU
––
––
whitelisted
2480 downloader.exe GET 200 37.140.166.230:80 http://cache-default06h.cdn.yandex.net/downloader.yandex.net/yandex-pack/downloader/info.rss RU
xml
whitelisted
2480 downloader.exe GET 302 5.45.205.241:80 http://downloader.yandex.net/yandex-pack/vkontakte-dj-elements/YandexPackSetup.exe RU
––
––
whitelisted
2480 downloader.exe GET –– 37.140.166.226:80 http://cache-default02h.cdn.yandex.net/downloader.yandex.net/yandex-pack/vkontakte-dj-elements/YandexPackSetup.exe RU
––
––
whitelisted
2184 VkontakteDJ.exe GET 200 54.36.175.115:80 http://dj-updates.com/download/VKontakteDJ-Updates.txt?version=3.96&bar=0&fr=absent&key={B1D89BFF-3BAE-42C2-B7DF-8F7D73530810}&newkey=019B9211963829E1145BBE092778F98B&newkey2=42366F19D5EEC1AF5206B46E735D4211-C4BA3647-60C53A74A89C1BE33548D917DD14E255&advert_key=ZWMwMDAxMDBiNDAwMTJkNzAwMDAxMmIzMDAxMmIzMDAxMmIzZjM5ZTFiNzcxZQ==&ffclid=0&ieclid=0&chclid=0&opclid=0&browser=ie&csrtmm=&random=uygznvyzjy&setup=1 FR
html
malicious
–– –– GET –– 87.240.129.133:80 http://vk.com/ RU
––
––
whitelisted

Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID Process IP ASN CN Reputation
3384 zvuki_prirodi.tmp 54.36.175.115:80 OVH SAS FR malicious
2480 downloader.exe 5.45.205.241:80 YANDEX LLC RU whitelisted
2480 downloader.exe 37.140.166.230:80 YANDEX LLC RU whitelisted
2480 downloader.exe 37.140.166.226:80 YANDEX LLC RU whitelisted
2184 VkontakteDJ.exe 54.36.175.115:80 OVH SAS FR malicious
–– –– 87.240.129.133:80 VKontakte Ltd RU malicious

DNS requests

Domain IP Reputation
dj-updates.com 54.36.175.115
malicious
downloader.yandex.net 5.45.205.241
5.45.205.244
5.45.205.245
5.45.205.242
5.45.205.243
whitelisted
cache-default06h.cdn.yandex.net 37.140.166.230
whitelisted
cache-default02h.cdn.yandex.net 37.140.166.226
whitelisted
vk.com 87.240.129.133
87.240.182.224
87.240.190.67
87.240.129.71
87.240.129.72
whitelisted

Threats

PID Process Class Message
2480 downloader.exe Potential Corporate Privacy Violation ET POLICY PE EXE or DLL Windows file download HTTP
2480 downloader.exe Generic Protocol Command Decode SURICATA STREAM excessive retransmissions

1 ETPRO signatures available at the full report

Debug output strings

No debug info.