File name:

PowerISO 8.6.0 + Keygen.zip

Full analysis: https://app.any.run/tasks/89ceeef3-6cff-493a-9442-dc104ca1b589
Verdict: Malicious activity
Analysis date: January 09, 2024, 16:28:48
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v1.0 to extract
MD5:

4EA72F387B212AD3543189E8E013B2E9

SHA1:

6A4214C73AE13FAF7AECE219FCCF0F7AC87B36DB

SHA256:

67F48FCDAC12448A16FFB2DCE569D558EA0B8FD7B86262E1F486B115E96A5F3A

SSDEEP:

98304:Uz7E/A4GPEeApOA0LO8tJBPxBbtAa/8fAo70fjeK/hIdqYOrOfG8JPwRhZJzzV57:5q/Sfy/xxe7rnyzc7O

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Creates a writable file in the system directory

      • PowerISO8-Full.exe (PID: 452)
    • Registers / Runs the DLL via REGSVR32.EXE

      • PowerISO8-Full.exe (PID: 452)
  • SUSPICIOUS

    • The process creates files with name similar to system file names

      • PowerISO8-x64-Full.exe (PID: 2300)
      • PowerISO8-Full.exe (PID: 452)
    • Creates files in the driver directory

      • PowerISO8-Full.exe (PID: 452)
    • Reads the Internet Settings

      • PowerISO8-Full.exe (PID: 452)
    • Drops a system driver (possible attempt to evade defenses)

      • PowerISO8-Full.exe (PID: 452)
  • INFO

    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 2044)
      • PowerISO8-x64-Full.exe (PID: 2300)
      • PowerISO8-Full.exe (PID: 452)
    • Manual execution by a user

      • PowerISO8-x64-Full.exe (PID: 2300)
      • PowerISO8-Full.exe (PID: 452)
      • PowerISO8-x64-Full.exe (PID: 1808)
      • PowerISO8-Full.exe (PID: 632)
      • msedge.exe (PID: 1956)
      • PowerISO_Keygen.exe (PID: 1056)
    • Checks supported languages

      • PowerISO8-x64-Full.exe (PID: 2300)
      • PowerISO8-Full.exe (PID: 452)
      • PowerISO_Keygen.exe (PID: 1056)
      • PWRISOVM.EXE (PID: 2404)
    • Create files in a temporary directory

      • PowerISO8-x64-Full.exe (PID: 2300)
      • PowerISO8-Full.exe (PID: 452)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • PowerISO8-x64-Full.exe (PID: 2300)
      • PowerISO8-Full.exe (PID: 452)
    • Reads the computer name

      • PowerISO8-Full.exe (PID: 452)
      • PowerISO_Keygen.exe (PID: 1056)
      • PowerISO8-x64-Full.exe (PID: 2300)
    • Reads Environment values

      • PowerISO8-Full.exe (PID: 452)
    • Application launched itself

      • msedge.exe (PID: 1424)
      • msedge.exe (PID: 1956)
    • Creates files in the program directory

      • PowerISO8-Full.exe (PID: 452)
    • Drops 7-zip archiver for unpacking

      • PowerISO8-Full.exe (PID: 452)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 10
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2024:01:09 19:15:10
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: PowerISO 8.6.0 + Keygen/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
67
Monitored processes
21
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe no specs poweriso8-x64-full.exe no specs poweriso8-x64-full.exe poweriso8-full.exe no specs poweriso8-full.exe regsvr32.exe no specs regsvr32.exe no specs pwrisovm.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs poweriso_keygen.exe

Process information

PID
CMD
Path
Indicators
Parent process
452"C:\Users\admin\Desktop\PowerISO 8.6.0 + Keygen\Setup\PowerISO8-Full.exe" C:\Users\admin\Desktop\PowerISO 8.6.0 + Keygen\Setup\PowerISO8-Full.exe
explorer.exe
User:
admin
Company:
Power Software Ltd
Integrity Level:
HIGH
Description:
PowerISO Setup
Exit code:
0
Version:
8.6.0.0
Modules
Images
c:\users\admin\desktop\poweriso 8.6.0 + keygen\setup\poweriso8-full.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
632"C:\Users\admin\Desktop\PowerISO 8.6.0 + Keygen\Setup\PowerISO8-Full.exe" C:\Users\admin\Desktop\PowerISO 8.6.0 + Keygen\Setup\PowerISO8-Full.exeexplorer.exe
User:
admin
Company:
Power Software Ltd
Integrity Level:
MEDIUM
Description:
PowerISO Setup
Exit code:
3221226540
Version:
8.6.0.0
Modules
Images
c:\users\admin\desktop\poweriso 8.6.0 + keygen\setup\poweriso8-full.exe
c:\windows\system32\ntdll.dll
920"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1268 --field-trial-handle=1188,i,7340443019582765372,16946456480304796340,131072 /prefetch:2C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1000"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1388 --field-trial-handle=1188,i,7340443019582765372,16946456480304796340,131072 /prefetch:3C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1056"C:\Users\admin\Desktop\PowerISO 8.6.0 + Keygen\Keygen\Keygen.v1.1b_Kindly\PowerISO_Keygen.exe" C:\Users\admin\Desktop\PowerISO 8.6.0 + Keygen\Keygen\Keygen.v1.1b_Kindly\PowerISO_Keygen.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\desktop\poweriso 8.6.0 + keygen\keygen\keygen.v1.1b_kindly\poweriso_keygen.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
1424"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --single-argument http://www.poweriso.com/thankyou.htmC:\Program Files\Microsoft\Edge\Application\msedge.exePowerISO8-Full.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1808"C:\Users\admin\Desktop\PowerISO 8.6.0 + Keygen\Setup\PowerISO8-x64-Full.exe" C:\Users\admin\Desktop\PowerISO 8.6.0 + Keygen\Setup\PowerISO8-x64-Full.exeexplorer.exe
User:
admin
Company:
Power Software Ltd
Integrity Level:
MEDIUM
Description:
PowerISO Setup
Exit code:
3221226540
Version:
8.6.0.0
Modules
Images
c:\users\admin\desktop\poweriso 8.6.0 + keygen\setup\poweriso8-x64-full.exe
c:\windows\system32\ntdll.dll
1932"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=1628 --field-trial-handle=1184,i,17049038142062802273,14795315947864136726,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1956"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --flag-switches-begin --flag-switches-end --do-not-de-elevate http://www.poweriso.com/thankyou.htmC:\Program Files\Microsoft\Edge\Application\msedge.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2044"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\PowerISO 8.6.0 + Keygen.zip"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
Total events
3 421
Read events
3 365
Write events
51
Delete events
5

Modification events

(PID) Process:(2044) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2044) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(2044) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(2044) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(2044) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(2044) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2044) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2044) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2044) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(452) PowerISO8-Full.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.iso
Operation:delete keyName:(default)
Value:
Executable files
19
Suspicious files
92
Text files
37
Unknown types
3

Dropped files

PID
Process
Filename
Type
2300PowerISO8-x64-Full.exeC:\Users\admin\AppData\Local\Temp\nsv56A8.tmp
MD5:
SHA256:
2044WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2044.23576\PowerISO 8.6.0 + Keygen\Keygen\Keygen.v1.1b_Kindly.zipcompressed
MD5:475A08F8195E174497A28145EF84EAE9
SHA256:C2BFA725C12B6E6E2904CC708D43233CE13D7B096178EEC44492C49EF518DB9E
452PowerISO8-Full.exeC:\Program Files\PowerISO\Lang\Polish.lngbinary
MD5:A197D6AAE21B87F4CCA43D754ED77BA4
SHA256:F927648298D7BF84A70B37261ECB9967903F8549CDAE05ADF625F664F78C2FAC
452PowerISO8-Full.exeC:\Program Files\PowerISO\Lang\Arabic.lngbinary
MD5:DF394959EB900BC4500324B7E1A674F1
SHA256:566220BD0BADC31C82CEEDCE53CB17B8C009E2AE5C1DF4E32690274D3511B014
452PowerISO8-Full.exeC:\Program Files\PowerISO\Lang\Italian.lngbinary
MD5:766381F22083BA756B40BD27DEF353CC
SHA256:5112942389D0981C36797F1451FA336B5CEF488CE49B9CC6B5D46CFA9357C1E3
452PowerISO8-Full.exeC:\Program Files\PowerISO\Lang\french.lngbinary
MD5:954A71EDC863A82E95A6492B3131A185
SHA256:7054A1889423B617471D98B37B8A13942CCC064BA1369C6139F2A2D431625721
452PowerISO8-Full.exeC:\Program Files\PowerISO\Lang\TradChinese.lngbinary
MD5:52CF4BA46679FC398E6C48D9A2E0B9CF
SHA256:2659DF8E77660B90B842BF5BDE4390C7B1E371ABF27A62C28B0AF20CFA37FBFB
452PowerISO8-Full.exeC:\Program Files\PowerISO\Lang\Korean.lngbinary
MD5:CF3C23B6632A79B68C369A7151A0A8F2
SHA256:3B99082A2333C4E875122961DD25CE992C06F4ADD5EAC103421FE61BF2788488
2044WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2044.23576\PowerISO 8.6.0 + Keygen\Setup\PowerISO8-Full.exeexecutable
MD5:ED93081A8D504DF16D63710E3A90CA96
SHA256:C1EF9C71D869DFD9F5AD0DD41D987E6C16E615D1AE6E48926D9E7DB8A39F9FE3
452PowerISO8-Full.exeC:\Users\admin\AppData\Local\Temp\nsj6C25.tmp\modern-header.bmpimage
MD5:CA2542B0E66E48D7E3F361C8EEF8F720
SHA256:4566DFCC153CBA168A02EEBC5DDD9D82832CF463EBB8ECB4EC2F269F9F85AECA
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
18
DNS requests
16
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2972
msedge.exe
GET
200
216.92.201.29:80
http://www.poweriso.com/images/blank.gif
unknown
image
46 b
unknown
2972
msedge.exe
GET
200
216.92.201.29:80
http://www.poweriso.com/images/thank-you-bg1.gif
unknown
image
1.03 Kb
unknown
2972
msedge.exe
GET
216.92.201.29:80
http://www.poweriso.com/images/thank-you-logo.gif
unknown
unknown
2972
msedge.exe
GET
200
216.92.201.29:80
http://www.poweriso.com/thankyou.htm
unknown
html
4.17 Kb
unknown
2972
msedge.exe
GET
200
216.92.201.29:80
http://www.poweriso.com/images/check.gif
unknown
image
1.02 Kb
unknown
2972
msedge.exe
GET
200
216.92.201.29:80
http://www.poweriso.com/images/thank-you-bg.gif
unknown
image
11.5 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
1956
msedge.exe
239.255.255.250:1900
whitelisted
2972
msedge.exe
13.107.42.16:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
2972
msedge.exe
204.79.197.239:443
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
2972
msedge.exe
216.92.201.29:80
www.poweriso.com
PAIR-NETWORKS
US
unknown
2972
msedge.exe
20.105.95.163:443
nav-edge.smartscreen.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
2972
msedge.exe
20.103.180.120:443
data-edge.smartscreen.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
unknown
2972
msedge.exe
23.53.43.152:443
www.bing.com
Akamai International B.V.
DE
unknown

DNS requests

Domain
IP
Reputation
www.poweriso.com
  • 216.92.201.29
unknown
config.edge.skype.com
  • 13.107.42.16
whitelisted
edge.microsoft.com
  • 204.79.197.239
  • 13.107.21.239
whitelisted
nav-edge.smartscreen.microsoft.com
  • 20.105.95.163
whitelisted
data-edge.smartscreen.microsoft.com
  • 20.103.180.120
whitelisted
www.googletagmanager.com
  • 172.217.18.8
whitelisted
www.bing.com
  • 23.53.43.152
  • 23.37.226.105
  • 23.37.226.88
  • 23.37.226.81
  • 23.53.43.121
  • 23.37.226.106
  • 23.37.226.97
whitelisted

Threats

No threats detected
No debug info