File name: | ChilledWindows.exe.zip |
Full analysis: | https://app.any.run/tasks/49f2a7c6-3385-4f8d-99f5-add15e118d96 |
Verdict: | No threats detected |
Analysis date: | May 03, 2018, 12:11:34 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | application/zip |
File info: | Zip archive data, at least v2.0 to extract |
MD5: | 293C8958EFF7FE7D60E7D37EFC3E76D9 |
SHA1: | 76CC9A70EDB88927FE6E0E21F0A0CA2E5C2D4E05 |
SHA256: | 65B17A9371158451E0534CC68962956F2CFAADDC5EC2A17E0A304401C83A954D |
SSDEEP: | 98304:/wlRowHsj9t+00T+X2VO5UyjDpV28b+rK4GiPPZxhXt:iwRtO8Z/2NrhGiPxxhXt |
.zip | | | ZIP compressed archive (100) |
---|
ZipFileName: | ChilledWindows.exe |
---|---|
ZipUncompressedSize: | 4578304 |
ZipCompressedSize: | 4396139 |
ZipCRC: | 0xc13279ae |
ZipModifyDate: | 2018:05:03 14:08:09 |
ZipCompression: | Deflated |
ZipBitFlag: | 0x0001 |
ZipRequiredVersion: | 788 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
3520 | "C:\Program Files\7-Zip\7zFM.exe" "C:\Users\admin\Desktop\ChilledWindows.exe.zip" | C:\Program Files\7-Zip\7zFM.exe | explorer.exe | ||||||||||||
User: admin Company: Igor Pavlov Integrity Level: MEDIUM Description: 7-Zip File Manager Version: 16.04 Modules
| |||||||||||||||
2824 | "C:\Users\admin\AppData\Local\Temp\7zO0CD45E8F\ChilledWindows.exe" | C:\Users\admin\AppData\Local\Temp\7zO0CD45E8F\ChilledWindows.exe | — | 7zFM.exe | |||||||||||
User: admin Company: GAMELASTER Integrity Level: MEDIUM Description: ChilledWindows Exit code: 3221225547 Version: 1.0.0.0 Modules
| |||||||||||||||
1792 | "C:\Windows\system32\taskmgr.exe" /4 | C:\Windows\system32\taskmgr.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Task Manager Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
|
(PID) Process: | (3520) 7zFM.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
(PID) Process: | (3520) 7zFM.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | AutoDetect |
Value: 1 | |||
(PID) Process: | (2824) ChilledWindows.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Direct3D\MostRecentApplication |
Operation: | write | Name: | Name |
Value: ChilledWindows.exe | |||
(PID) Process: | (2824) ChilledWindows.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
(PID) Process: | (2824) ChilledWindows.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | AutoDetect |
Value: 1 | |||
(PID) Process: | (2824) ChilledWindows.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences |
Operation: | write | Name: | LastScreensaverSetThreadExecutionState |
Value: 2147483648 | |||
(PID) Process: | (2824) ChilledWindows.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences |
Operation: | write | Name: | LastScreensaverState |
Value: 4 | |||
(PID) Process: | (2824) ChilledWindows.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences |
Operation: | write | Name: | AutoMetadataCurrentDownloadCount |
Value: 0 | |||
(PID) Process: | (2824) ChilledWindows.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences |
Operation: | write | Name: | AutoMetadataCurrent500ServerErrorCount |
Value: 0 | |||
(PID) Process: | (2824) ChilledWindows.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences |
Operation: | write | Name: | AutoMetadataCurrent503ServerErrorCount |
Value: 0 |
PID | Process | Filename | Type | |
---|---|---|---|---|
2824 | ChilledWindows.exe | C:\Users\admin\AppData\Local\Microsoft\Media Player\CurrentDatabase_372.wmdb | binary | |
MD5:87D5CF4AB3B643B0B603C66ECEFF9C01 | SHA256:1B9106FE6BD6FE70A57A709CB942D15BB6C2EFE26EFA5EB4F931F32D5737EC97 | |||
3520 | 7zFM.exe | C:\Users\admin\AppData\Local\Temp\7zO0CD45E8F\ChilledWindows.exe | executable | |
MD5:6A4853CD0584DC90067E15AFB43C4962 | SHA256:CCB9502BF8BA5BECF8B758CA04A5625C30B79E2D10D2677CC43AE4253E1288EC | |||
2824 | ChilledWindows.exe | C:\Users\admin\AppData\Local\Temp\7zO0CD45E8F\chilledwindows.mp4 | m4v | |
MD5:698DDCAEC1EDCF1245807627884EDF9C | SHA256:CDE975F975D21EDB2E5FAA505205AB8A2C5A565BA1FF8585D1F0E372B2A1D78B |