| File name: | ChilledWindows.exe.zip |
| Full analysis: | https://app.any.run/tasks/49f2a7c6-3385-4f8d-99f5-add15e118d96 |
| Verdict: | No threats detected |
| Analysis date: | May 03, 2018, 12:11:34 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract |
| MD5: | 293C8958EFF7FE7D60E7D37EFC3E76D9 |
| SHA1: | 76CC9A70EDB88927FE6E0E21F0A0CA2E5C2D4E05 |
| SHA256: | 65B17A9371158451E0534CC68962956F2CFAADDC5EC2A17E0A304401C83A954D |
| SSDEEP: | 98304:/wlRowHsj9t+00T+X2VO5UyjDpV28b+rK4GiPPZxhXt:iwRtO8Z/2NrhGiPxxhXt |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 788 |
|---|---|
| ZipBitFlag: | 0x0001 |
| ZipCompression: | Deflated |
| ZipModifyDate: | 2018:05:03 14:08:09 |
| ZipCRC: | 0xc13279ae |
| ZipCompressedSize: | 4396139 |
| ZipUncompressedSize: | 4578304 |
| ZipFileName: | ChilledWindows.exe |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1792 | "C:\Windows\system32\taskmgr.exe" /4 | C:\Windows\system32\taskmgr.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Task Manager Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2824 | "C:\Users\admin\AppData\Local\Temp\7zO0CD45E8F\ChilledWindows.exe" | C:\Users\admin\AppData\Local\Temp\7zO0CD45E8F\ChilledWindows.exe | — | 7zFM.exe | |||||||||||
User: admin Company: GAMELASTER Integrity Level: MEDIUM Description: ChilledWindows Exit code: 3221225547 Version: 1.0.0.0 Modules
| |||||||||||||||
| 3520 | "C:\Program Files\7-Zip\7zFM.exe" "C:\Users\admin\Desktop\ChilledWindows.exe.zip" | C:\Program Files\7-Zip\7zFM.exe | explorer.exe | ||||||||||||
User: admin Company: Igor Pavlov Integrity Level: MEDIUM Description: 7-Zip File Manager Exit code: 0 Version: 16.04 Modules
| |||||||||||||||
| (PID) Process: | (3520) 7zFM.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
| (PID) Process: | (3520) 7zFM.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 1 | |||
| (PID) Process: | (2824) ChilledWindows.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Direct3D\MostRecentApplication |
| Operation: | write | Name: | Name |
Value: ChilledWindows.exe | |||
| (PID) Process: | (2824) ChilledWindows.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
| (PID) Process: | (2824) ChilledWindows.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 1 | |||
| (PID) Process: | (2824) ChilledWindows.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences |
| Operation: | write | Name: | LastScreensaverSetThreadExecutionState |
Value: 2147483648 | |||
| (PID) Process: | (2824) ChilledWindows.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences |
| Operation: | write | Name: | LastScreensaverState |
Value: 4 | |||
| (PID) Process: | (2824) ChilledWindows.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences |
| Operation: | write | Name: | AutoMetadataCurrentDownloadCount |
Value: 0 | |||
| (PID) Process: | (2824) ChilledWindows.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences |
| Operation: | write | Name: | AutoMetadataCurrent500ServerErrorCount |
Value: 0 | |||
| (PID) Process: | (2824) ChilledWindows.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences |
| Operation: | write | Name: | AutoMetadataCurrent503ServerErrorCount |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2824 | ChilledWindows.exe | C:\Users\admin\AppData\Local\Microsoft\Media Player\CurrentDatabase_372.wmdb | binary | |
MD5:— | SHA256:— | |||
| 2824 | ChilledWindows.exe | C:\Users\admin\AppData\Local\Temp\7zO0CD45E8F\chilledwindows.mp4 | m4v | |
MD5:698DDCAEC1EDCF1245807627884EDF9C | SHA256:CDE975F975D21EDB2E5FAA505205AB8A2C5A565BA1FF8585D1F0E372B2A1D78B | |||
| 3520 | 7zFM.exe | C:\Users\admin\AppData\Local\Temp\7zO0CD45E8F\ChilledWindows.exe | executable | |
MD5:6A4853CD0584DC90067E15AFB43C4962 | SHA256:CCB9502BF8BA5BECF8B758CA04A5625C30B79E2D10D2677CC43AE4253E1288EC | |||