File name:

PowerISO 8.6.0 + Keygen.zip

Full analysis: https://app.any.run/tasks/89ceeef3-6cff-493a-9442-dc104ca1b589
Verdict: Malicious activity
Analysis date: January 09, 2024, 16:28:48
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v1.0 to extract
MD5:

4EA72F387B212AD3543189E8E013B2E9

SHA1:

6A4214C73AE13FAF7AECE219FCCF0F7AC87B36DB

SHA256:

67F48FCDAC12448A16FFB2DCE569D558EA0B8FD7B86262E1F486B115E96A5F3A

SSDEEP:

98304:Uz7E/A4GPEeApOA0LO8tJBPxBbtAa/8fAo70fjeK/hIdqYOrOfG8JPwRhZJzzV57:5q/Sfy/xxe7rnyzc7O

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Registers / Runs the DLL via REGSVR32.EXE

      • PowerISO8-Full.exe (PID: 452)
    • Creates a writable file in the system directory

      • PowerISO8-Full.exe (PID: 452)
  • SUSPICIOUS

    • The process creates files with name similar to system file names

      • PowerISO8-x64-Full.exe (PID: 2300)
      • PowerISO8-Full.exe (PID: 452)
    • Reads the Internet Settings

      • PowerISO8-Full.exe (PID: 452)
    • Drops a system driver (possible attempt to evade defenses)

      • PowerISO8-Full.exe (PID: 452)
    • Creates files in the driver directory

      • PowerISO8-Full.exe (PID: 452)
  • INFO

    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 2044)
      • PowerISO8-Full.exe (PID: 452)
      • PowerISO8-x64-Full.exe (PID: 2300)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • PowerISO8-x64-Full.exe (PID: 2300)
      • PowerISO8-Full.exe (PID: 452)
    • Checks supported languages

      • PowerISO8-x64-Full.exe (PID: 2300)
      • PowerISO8-Full.exe (PID: 452)
      • PWRISOVM.EXE (PID: 2404)
      • PowerISO_Keygen.exe (PID: 1056)
    • Reads the computer name

      • PowerISO8-x64-Full.exe (PID: 2300)
      • PowerISO8-Full.exe (PID: 452)
      • PowerISO_Keygen.exe (PID: 1056)
    • Manual execution by a user

      • PowerISO8-x64-Full.exe (PID: 2300)
      • PowerISO8-Full.exe (PID: 452)
      • PowerISO8-Full.exe (PID: 632)
      • msedge.exe (PID: 1956)
      • PowerISO_Keygen.exe (PID: 1056)
      • PowerISO8-x64-Full.exe (PID: 1808)
    • Create files in a temporary directory

      • PowerISO8-x64-Full.exe (PID: 2300)
      • PowerISO8-Full.exe (PID: 452)
    • Reads Environment values

      • PowerISO8-Full.exe (PID: 452)
    • Application launched itself

      • msedge.exe (PID: 1956)
      • msedge.exe (PID: 1424)
    • Creates files in the program directory

      • PowerISO8-Full.exe (PID: 452)
    • Drops 7-zip archiver for unpacking

      • PowerISO8-Full.exe (PID: 452)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 10
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2024:01:09 19:15:10
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: PowerISO 8.6.0 + Keygen/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
67
Monitored processes
21
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe no specs poweriso8-x64-full.exe no specs poweriso8-x64-full.exe poweriso8-full.exe no specs poweriso8-full.exe regsvr32.exe no specs regsvr32.exe no specs pwrisovm.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs poweriso_keygen.exe

Process information

PID
CMD
Path
Indicators
Parent process
452"C:\Users\admin\Desktop\PowerISO 8.6.0 + Keygen\Setup\PowerISO8-Full.exe" C:\Users\admin\Desktop\PowerISO 8.6.0 + Keygen\Setup\PowerISO8-Full.exe
explorer.exe
User:
admin
Company:
Power Software Ltd
Integrity Level:
HIGH
Description:
PowerISO Setup
Exit code:
0
Version:
8.6.0.0
Modules
Images
c:\users\admin\desktop\poweriso 8.6.0 + keygen\setup\poweriso8-full.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
632"C:\Users\admin\Desktop\PowerISO 8.6.0 + Keygen\Setup\PowerISO8-Full.exe" C:\Users\admin\Desktop\PowerISO 8.6.0 + Keygen\Setup\PowerISO8-Full.exeexplorer.exe
User:
admin
Company:
Power Software Ltd
Integrity Level:
MEDIUM
Description:
PowerISO Setup
Exit code:
3221226540
Version:
8.6.0.0
Modules
Images
c:\users\admin\desktop\poweriso 8.6.0 + keygen\setup\poweriso8-full.exe
c:\windows\system32\ntdll.dll
920"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1268 --field-trial-handle=1188,i,7340443019582765372,16946456480304796340,131072 /prefetch:2C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1000"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1388 --field-trial-handle=1188,i,7340443019582765372,16946456480304796340,131072 /prefetch:3C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1056"C:\Users\admin\Desktop\PowerISO 8.6.0 + Keygen\Keygen\Keygen.v1.1b_Kindly\PowerISO_Keygen.exe" C:\Users\admin\Desktop\PowerISO 8.6.0 + Keygen\Keygen\Keygen.v1.1b_Kindly\PowerISO_Keygen.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\desktop\poweriso 8.6.0 + keygen\keygen\keygen.v1.1b_kindly\poweriso_keygen.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
1424"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --single-argument http://www.poweriso.com/thankyou.htmC:\Program Files\Microsoft\Edge\Application\msedge.exePowerISO8-Full.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1808"C:\Users\admin\Desktop\PowerISO 8.6.0 + Keygen\Setup\PowerISO8-x64-Full.exe" C:\Users\admin\Desktop\PowerISO 8.6.0 + Keygen\Setup\PowerISO8-x64-Full.exeexplorer.exe
User:
admin
Company:
Power Software Ltd
Integrity Level:
MEDIUM
Description:
PowerISO Setup
Exit code:
3221226540
Version:
8.6.0.0
Modules
Images
c:\users\admin\desktop\poweriso 8.6.0 + keygen\setup\poweriso8-x64-full.exe
c:\windows\system32\ntdll.dll
1932"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=1628 --field-trial-handle=1184,i,17049038142062802273,14795315947864136726,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1956"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --flag-switches-begin --flag-switches-end --do-not-de-elevate http://www.poweriso.com/thankyou.htmC:\Program Files\Microsoft\Edge\Application\msedge.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2044"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\PowerISO 8.6.0 + Keygen.zip"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
Total events
3 421
Read events
3 365
Write events
51
Delete events
5

Modification events

(PID) Process:(2044) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2044) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(2044) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(2044) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(2044) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(2044) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2044) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2044) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2044) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(452) PowerISO8-Full.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.iso
Operation:delete keyName:(default)
Value:
Executable files
19
Suspicious files
92
Text files
37
Unknown types
3

Dropped files

PID
Process
Filename
Type
2300PowerISO8-x64-Full.exeC:\Users\admin\AppData\Local\Temp\nsv56A8.tmp
MD5:
SHA256:
2044WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2044.23576\PowerISO 8.6.0 + Keygen\HaxNode.Net.urlurl
MD5:D2DBDD8CC5165FF6E4122B9F15B82EE9
SHA256:CB92547DBACFB6D6C102C2C0ED1D280C6AEA32210F280A85CE01BCEAC765C91E
452PowerISO8-Full.exeC:\Users\admin\AppData\Local\Temp\nsd7732.tmpexecutable
MD5:E2399827F98C20DFF849BAF9703B76EE
SHA256:EE90EE53CACAAB34EB38CF4A130AC2196B02BC16E46BA99752129C01E329978D
452PowerISO8-Full.exeC:\Windows\system32\Drivers\scdemu.sysexecutable
MD5:4B5579223186E2E1AB4A24B608FDC949
SHA256:C7B58DA9FD4CF2F7F83F92B2E98437A2420150FEC6E58C2BD84C82EDD2DA9A8E
2044WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2044.23576\PowerISO 8.6.0 + Keygen\Setup\PowerISO8-x64-Full.exeexecutable
MD5:C6FE072CA5A1E86865B620354658F9DD
SHA256:45724CAE16F5604C9D509724266AD49B716A33D72ECF420030209ED7228D4910
452PowerISO8-Full.exeC:\Program Files\PowerISO\Lang\TradChinese.lngbinary
MD5:52CF4BA46679FC398E6C48D9A2E0B9CF
SHA256:2659DF8E77660B90B842BF5BDE4390C7B1E371ABF27A62C28B0AF20CFA37FBFB
452PowerISO8-Full.exeC:\Program Files\PowerISO\Lang\Italian.lngbinary
MD5:766381F22083BA756B40BD27DEF353CC
SHA256:5112942389D0981C36797F1451FA336B5CEF488CE49B9CC6B5D46CFA9357C1E3
452PowerISO8-Full.exeC:\Program Files\PowerISO\Lang\Polish.lngbinary
MD5:A197D6AAE21B87F4CCA43D754ED77BA4
SHA256:F927648298D7BF84A70B37261ECB9967903F8549CDAE05ADF625F664F78C2FAC
452PowerISO8-Full.exeC:\Program Files\PowerISO\Lang\french.lngbinary
MD5:954A71EDC863A82E95A6492B3131A185
SHA256:7054A1889423B617471D98B37B8A13942CCC064BA1369C6139F2A2D431625721
452PowerISO8-Full.exeC:\Users\admin\AppData\Local\Temp\nsj6C25.tmp\System.dllexecutable
MD5:8CF2AC271D7679B1D68EEFC1AE0C5618
SHA256:6950991102462D84FDC0E3B0AE30C95AF8C192F77CE3D78E8D54E6B22F7C09BA
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
18
DNS requests
16
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2972
msedge.exe
GET
200
216.92.201.29:80
http://www.poweriso.com/thankyou.htm
unknown
html
4.17 Kb
unknown
2972
msedge.exe
GET
200
216.92.201.29:80
http://www.poweriso.com/images/blank.gif
unknown
image
46 b
unknown
2972
msedge.exe
GET
216.92.201.29:80
http://www.poweriso.com/images/thank-you-logo.gif
unknown
unknown
2972
msedge.exe
GET
200
216.92.201.29:80
http://www.poweriso.com/images/check.gif
unknown
image
1.02 Kb
unknown
2972
msedge.exe
GET
200
216.92.201.29:80
http://www.poweriso.com/images/thank-you-bg1.gif
unknown
image
1.03 Kb
unknown
2972
msedge.exe
GET
200
216.92.201.29:80
http://www.poweriso.com/images/thank-you-bg.gif
unknown
image
11.5 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
1956
msedge.exe
239.255.255.250:1900
whitelisted
2972
msedge.exe
13.107.42.16:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
2972
msedge.exe
204.79.197.239:443
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
2972
msedge.exe
216.92.201.29:80
www.poweriso.com
PAIR-NETWORKS
US
unknown
2972
msedge.exe
20.105.95.163:443
nav-edge.smartscreen.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
2972
msedge.exe
20.103.180.120:443
data-edge.smartscreen.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
unknown
2972
msedge.exe
23.53.43.152:443
www.bing.com
Akamai International B.V.
DE
unknown

DNS requests

Domain
IP
Reputation
www.poweriso.com
  • 216.92.201.29
unknown
config.edge.skype.com
  • 13.107.42.16
whitelisted
edge.microsoft.com
  • 204.79.197.239
  • 13.107.21.239
whitelisted
nav-edge.smartscreen.microsoft.com
  • 20.105.95.163
whitelisted
data-edge.smartscreen.microsoft.com
  • 20.103.180.120
whitelisted
www.googletagmanager.com
  • 172.217.18.8
whitelisted
www.bing.com
  • 23.53.43.152
  • 23.37.226.105
  • 23.37.226.88
  • 23.37.226.81
  • 23.53.43.121
  • 23.37.226.106
  • 23.37.226.97
whitelisted

Threats

No threats detected
No debug info