| File name: | Pak-Urdu-Installer.exe.7z |
| Full analysis: | https://app.any.run/tasks/8fc6ae1f-ebac-4d71-8d29-1598dbe88ae2 |
| Verdict: | Malicious activity |
| Analysis date: | January 24, 2024, 09:06:30 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-7z-compressed |
| File info: | 7-zip archive data, version 0.4 |
| MD5: | C681FCA59134BC7ABC90DDF0A60C3146 |
| SHA1: | 3587732ACAB8BBCA55D9E21049E2688F7F4F43D1 |
| SHA256: | 62E5854CBAE58E95D43E88E9AEC8EEC6D046034EDBCEF91995E3A99E4C837787 |
| SSDEEP: | 98304:5yDgTupiG7Cboy+kKTG28GaGz1zFMXas9QzqwYqHuGS1CWJ4vKGoXhli2umGp61z:+4btQdYwgdJ3DTrzZFOlS |
| .7z | | | 7-Zip compressed archive (v0.4) (57.1) |
|---|---|---|
| .7z | | | 7-Zip compressed archive (gen) (42.8) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 448 | C:\Windows\system32\DllHost.exe /Processid:{F32D97DF-E3E5-4CB9-9E3E-0EB5B4E49801} | C:\Windows\System32\dllhost.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: COM Surrogate Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 748 | C:\Windows\system32\DllHost.exe /Processid:{F32D97DF-E3E5-4CB9-9E3E-0EB5B4E49801} | C:\Windows\System32\dllhost.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: COM Surrogate Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 784 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3724 --field-trial-handle=1332,i,7749133116851180624,9215595140839280939,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1432 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --use-gl=angle --use-angle=swiftshader-webgl --mojo-platform-channel-handle=1484 --field-trial-handle=1332,i,7749133116851180624,9215595140839280939,131072 /prefetch:2 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1632 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3876 --field-trial-handle=1332,i,7749133116851180624,9215595140839280939,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 2044 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=asset_store.mojom.AssetStoreService --lang=en-US --service-sandbox-type=asset_store_service --mojo-platform-channel-handle=3396 --field-trial-handle=1332,i,7749133116851180624,9215595140839280939,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 2240 | "C:\Users\admin\Desktop\Pak-Urdu-Installer.exe" | C:\Users\admin\Desktop\Pak-Urdu-Installer.exe | — | explorer.exe | |||||||||||
User: admin Company: Macrovision Corporation Integrity Level: MEDIUM Description: Setup.exe Exit code: 3221226540 Version: 14.0.162 Modules
| |||||||||||||||
| 2528 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --single-argument C:\Program Files\mBILALm.com\Pak Urdu Installer\pak-urdu-installer.html | C:\Program Files\Microsoft\Edge\Application\msedge.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 2556 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" "--metrics-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=109.0.5414.149 "--annotation=exe=C:\Program Files\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win32 "--annotation=prod=Microsoft Edge" --annotation=ver=109.0.1518.115 --initial-client-data=0xc8,0xcc,0xd0,0x9c,0xd8,0x6b88f598,0x6b88f5a8,0x6b88f5b4 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 2568 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\Pak-Urdu-Installer.exe.7z" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| (PID) Process: | (2568) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2568) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip | |||
| (PID) Process: | (2568) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\phacker.zip | |||
| (PID) Process: | (2568) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (2568) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip | |||
| (PID) Process: | (2568) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (2568) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (2568) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (2568) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (2908) Pak-Urdu-Installer.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SystemRestore |
| Operation: | write | Name: | SrCreateRp (Enter) |
Value: 40000000000000003811FC442B2FDA01740A0000480C0000D5070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2908 | Pak-Urdu-Installer.exe | C:\Users\admin\AppData\Local\Temp\{876F8479-5394-4E4D-8579-64C3E9159EE1}\Disk1\data1.cab | compressed | |
MD5:8ED7876FDF8CF01951D656BC71258799 | SHA256:4A158672D36A046679A9AD3D02F488B6754231DE2416A8D01CD51716CE836C86 | |||
| 2908 | Pak-Urdu-Installer.exe | C:\Users\admin\AppData\Local\Temp\{876F8479-5394-4E4D-8579-64C3E9159EE1}\Disk1\setup.exe | executable | |
MD5:6F58A1D8E7B031C6F2A60BA04D1A0B7D | SHA256:B7A82904D92B096CB6AB537365F9C7F24B1ECEFAA6EA7974C24E8102B1746F4B | |||
| 2908 | Pak-Urdu-Installer.exe | C:\Users\admin\AppData\Local\Temp\{876F8479-5394-4E4D-8579-64C3E9159EE1}\setup.ini | ini | |
MD5:FF42DC95867C05F2A127CB62902DAE7A | SHA256:872FB544B20FCB8D573550BC07B4C74D6FB2B98EDFB5549171E7180D71115243 | |||
| 2908 | Pak-Urdu-Installer.exe | C:\Users\admin\AppData\Local\Temp\{876F8479-5394-4E4D-8579-64C3E9159EE1}\Disk1\ISSetup.dll | executable | |
MD5:6C48E05107EB494620AB0DC96D3C5B80 | SHA256:13223E7FBEB3DAC968DE77E6BE974A36F86DC07884CC0E80EABF8B817CCB4A04 | |||
| 2908 | Pak-Urdu-Installer.exe | C:\Users\admin\AppData\Local\Temp\{876F8479-5394-4E4D-8579-64C3E9159EE1}\Disk1\setup.inx | binary | |
MD5:908EB36F695E2E0C941026915B17F1FE | SHA256:F5A8AECB937F41D7F7E30B745082F1D8E593D671E8AEC4082DFD1877C80ECDE9 | |||
| 2908 | Pak-Urdu-Installer.exe | C:\Users\admin\AppData\Local\Temp\{ABC37400-45FE-40F7-9094-FC1A0E313B50}\{0A16D0C9-265C-4AA8-B4B5-E503BD36FCD0}\license.rtf | text | |
MD5:E7EB45E877C8CB80F56E9DBC9504E757 | SHA256:2301902EC24434DD7475A3823902851B4BC66D23B25281392E4E310223F7A706 | |||
| 2908 | Pak-Urdu-Installer.exe | C:\Users\admin\AppData\Local\Temp\{876F8479-5394-4E4D-8579-64C3E9159EE1}\Disk1\_Setup.dll | executable | |
MD5:6FD5033F836DBC81FDA60620D9C0BA52 | SHA256:E6BFFEA778B079DECB73A492115DE691EC64902B89B2ADAC67AE282708C58676 | |||
| 2908 | Pak-Urdu-Installer.exe | C:\Users\admin\AppData\Local\Temp\{876F8479-5394-4E4D-8579-64C3E9159EE1}\_Setup.dll | executable | |
MD5:6FD5033F836DBC81FDA60620D9C0BA52 | SHA256:E6BFFEA778B079DECB73A492115DE691EC64902B89B2ADAC67AE282708C58676 | |||
| 2908 | Pak-Urdu-Installer.exe | C:\Users\admin\AppData\Local\Temp\{ABC37400-45FE-40F7-9094-FC1A0E313B50}\{0A16D0C9-265C-4AA8-B4B5-E503BD36FCD0}\licede87.rra | text | |
MD5:E7EB45E877C8CB80F56E9DBC9504E757 | SHA256:2301902EC24434DD7475A3823902851B4BC66D23B25281392E4E310223F7A706 | |||
| 2908 | Pak-Urdu-Installer.exe | C:\Users\admin\AppData\Local\Temp\{ABC37400-45FE-40F7-9094-FC1A0E313B50}\{0A16D0C9-265C-4AA8-B4B5-E503BD36FCD0}\Fontdea6.rra | text | |
MD5:00F313E3E007599349A0C4D81C7807C4 | SHA256:766EE687D90B0217EB41CB85ACA04375BDC24DB986A33536631F864B7CE1A08A | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
3364 | msedge.exe | 13.107.42.16:443 | config.edge.skype.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
2528 | msedge.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
3364 | msedge.exe | 204.79.197.239:443 | edge.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | unknown |
3364 | msedge.exe | 152.199.21.175:443 | msedgeextensions.sf.tlu.dl.delivery.mp.microsoft.com | EDGECAST | DE | whitelisted |
3364 | msedge.exe | 104.126.37.163:443 | www.bing.com | Akamai International B.V. | DE | unknown |
2528 | msedge.exe | 224.0.0.251:5353 | — | — | — | unknown |
3364 | msedge.exe | 52.182.143.208:443 | self.events.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | unknown |
Domain | IP | Reputation |
|---|---|---|
config.edge.skype.com |
| whitelisted |
edge.microsoft.com |
| whitelisted |
msedgeextensions.sf.tlu.dl.delivery.mp.microsoft.com |
| whitelisted |
www.bing.com |
| whitelisted |
self.events.data.microsoft.com |
| whitelisted |