File name:

Navicat Keygen Patch v5.6.0 DFoX.7z

Full analysis: https://app.any.run/tasks/c8e29b53-4e25-43cf-a89c-f6d77ceb55db
Verdict: No threats detected
Analysis date: November 08, 2020, 10:13:57
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-7z-compressed
File info: 7-zip archive data, version 0.4
MD5:

C9FD5D90E9A8028B6BAF7F175CFA196E

SHA1:

65D566BC8AFBFCEEF6D64CB78701B53340C51A70

SHA256:

66A5A4F4B9FD4E38B69641E53A1A15721EBDACB58450D058E47E1CA006DCF370

SSDEEP:

98304:EuS1pvbC6JTmcREjq9rp7Fs7LER8ry9XGB62ixPP:VS1pvzJT7+jsrBFsXEsAGBS

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Navicat Keygen Patch v5.6.0 DFoX.exe (PID: 2360)
      • Navicat Keygen Patch v5.6.0 DFoX.exe (PID: 1856)
  • SUSPICIOUS

    • Reads internet explorer settings

      • Navicat Keygen Patch v5.6.0 DFoX.exe (PID: 2360)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2088)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.7z | 7-Zip compressed archive (v0.4) (57.1)
.7z | 7-Zip compressed archive (gen) (42.8)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
41
Monitored processes
3
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
drop and start drop and start start winrar.exe navicat keygen patch v5.6.0 dfox.exe no specs navicat keygen patch v5.6.0 dfox.exe

Process information

PID
CMD
Path
Indicators
Parent process
1856"C:\Users\admin\AppData\Local\Temp\Rar$EXa2088.29474\Navicat Keygen Patch v5.6.0 DFoX.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa2088.29474\Navicat Keygen Patch v5.6.0 DFoX.exeWinRAR.exe
User:
admin
Company:
DeltaFoX
Integrity Level:
MEDIUM
Description:
Navicat_Keygen_Patch_By_DFoX
Exit code:
3221226540
Version:
5.6.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2088.29474\navicat keygen patch v5.6.0 dfox.exe
c:\systemroot\system32\ntdll.dll
2088"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Navicat Keygen Patch v5.6.0 DFoX.7z"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2360"C:\Users\admin\AppData\Local\Temp\Rar$EXa2088.29474\Navicat Keygen Patch v5.6.0 DFoX.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa2088.29474\Navicat Keygen Patch v5.6.0 DFoX.exe
WinRAR.exe
User:
admin
Company:
DeltaFoX
Integrity Level:
HIGH
Description:
Navicat_Keygen_Patch_By_DFoX
Exit code:
0
Version:
5.6.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2088.29474\navicat keygen patch v5.6.0 dfox.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
Total events
1 016
Read events
963
Write events
52
Delete events
1

Modification events

(PID) Process:(2088) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2088) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2088) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\13B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2088) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Navicat Keygen Patch v5.6.0 DFoX.7z
(PID) Process:(2088) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2088) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2088) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2088) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2088) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(2088) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
Executable files
1
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
2088WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2088.29474\Navicat Keygen Patch v5.6.0 DFoX.exeexecutable
MD5:BBD42379463775CF6D2E66DF630D7923
SHA256:BA312D716CE7F96F5074AEC5B5D5DB5C1E322A3A67F475DED8434F170CE7E54F
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info