File name:

thinsoft 32 Bits V.2.00.672.zip

Full analysis: https://app.any.run/tasks/1e72694f-1c11-4b62-a370-fedf33b820c8
Verdict: Malicious activity
Analysis date: July 15, 2023, 00:52:14
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

60904D4967093F9D786B78484E810C9D

SHA1:

959D2D27B1BA096E2C203815BBF0C05FB35823D0

SHA256:

6C69370F2958FE68C8DAC2D2516583488BCA1F137D16D73DEB33C793F161233A

SSDEEP:

196608:KVbuBuolx6lIs98QI9Sbdka9xhqWE2Z8lNxB2SbbVCoJO3s0UjcRLsRuL4a7Tt:uqAo6Ge899Sa63v5ZG9bbbkoWnoHent

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • thinsoft 32 Bits V.2.00.672.exe (PID: 4020)
      • thinsoft 32 Bits V.2.00.672.exe (PID: 2828)
      • thinsoft 32 Bits V.2.00.672.exe (PID: 2540)
      • thinsoft 32 Bits V.2.00.672.exe (PID: 3860)
    • Loads dropped or rewritten executable

      • thinsoft 32 Bits V.2.00.672.tmp (PID: 3200)
      • thinsoft 32 Bits V.2.00.672.tmp (PID: 1640)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • thinsoft 32 Bits V.2.00.672.exe (PID: 4020)
      • thinsoft 32 Bits V.2.00.672.exe (PID: 2828)
      • thinsoft 32 Bits V.2.00.672.tmp (PID: 3200)
      • thinsoft 32 Bits V.2.00.672.exe (PID: 2540)
      • thinsoft 32 Bits V.2.00.672.tmp (PID: 1640)
      • thinsoft 32 Bits V.2.00.672.exe (PID: 3860)
    • Reads the Windows owner or organization settings

      • thinsoft 32 Bits V.2.00.672.tmp (PID: 3200)
      • thinsoft 32 Bits V.2.00.672.tmp (PID: 1640)
  • INFO

    • Checks supported languages

      • thinsoft 32 Bits V.2.00.672.exe (PID: 4020)
      • thinsoft 32 Bits V.2.00.672.tmp (PID: 3556)
      • thinsoft 32 Bits V.2.00.672.exe (PID: 2828)
      • thinsoft 32 Bits V.2.00.672.tmp (PID: 3200)
      • thinsoft 32 Bits V.2.00.672.exe (PID: 3860)
      • thinsoft 32 Bits V.2.00.672.exe (PID: 2540)
      • thinsoft 32 Bits V.2.00.672.tmp (PID: 3384)
      • thinsoft 32 Bits V.2.00.672.tmp (PID: 1640)
    • Reads the computer name

      • thinsoft 32 Bits V.2.00.672.tmp (PID: 3556)
      • thinsoft 32 Bits V.2.00.672.tmp (PID: 3200)
      • thinsoft 32 Bits V.2.00.672.tmp (PID: 3384)
      • thinsoft 32 Bits V.2.00.672.tmp (PID: 1640)
    • Application was dropped or rewritten from another process

      • thinsoft 32 Bits V.2.00.672.tmp (PID: 3556)
      • thinsoft 32 Bits V.2.00.672.tmp (PID: 3200)
      • thinsoft 32 Bits V.2.00.672.tmp (PID: 3384)
      • thinsoft 32 Bits V.2.00.672.tmp (PID: 1640)
    • Create files in a temporary directory

      • thinsoft 32 Bits V.2.00.672.exe (PID: 4020)
      • thinsoft 32 Bits V.2.00.672.exe (PID: 2828)
      • thinsoft 32 Bits V.2.00.672.tmp (PID: 3200)
      • thinsoft 32 Bits V.2.00.672.exe (PID: 2540)
      • thinsoft 32 Bits V.2.00.672.tmp (PID: 1640)
      • thinsoft 32 Bits V.2.00.672.exe (PID: 3860)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3468)
    • The process checks LSA protection

      • thinsoft 32 Bits V.2.00.672.tmp (PID: 3556)
      • thinsoft 32 Bits V.2.00.672.tmp (PID: 3384)
    • Manual execution by a user

      • thinsoft 32 Bits V.2.00.672.exe (PID: 3860)
    • [YARA] Network interface manipulation strings were found

      • thinsoft 32 Bits V.2.00.672.tmp (PID: 1640)
      • thinsoft 32 Bits V.2.00.672.tmp (PID: 3200)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipFileName: activating/Keymaker 32.exe
ZipUncompressedSize: 64000
ZipCompressedSize: 51061
ZipCRC: 0x58b1e8fb
ZipModifyDate: 2012:05:08 13:07:00
ZipCompression: Deflated
ZipBitFlag: -
ZipRequiredVersion: 20
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
51
Monitored processes
9
Malicious processes
9
Suspicious processes
0

Behavior graph

Click at the process to see the details
drop and start start drop and start drop and start drop and start drop and start winrar.exe thinsoft 32 bits v.2.00.672.exe thinsoft 32 bits v.2.00.672.tmp no specs thinsoft 32 bits v.2.00.672.exe thinsoft 32 bits v.2.00.672.tmp thinsoft 32 bits v.2.00.672.exe thinsoft 32 bits v.2.00.672.tmp no specs thinsoft 32 bits v.2.00.672.exe thinsoft 32 bits v.2.00.672.tmp

Process information

PID
CMD
Path
Indicators
Parent process
1640"C:\Users\admin\AppData\Local\Temp\is-AP32Q.tmp\thinsoft 32 Bits V.2.00.672.tmp" /SL5="$301C6,6340718,52224,C:\Users\admin\Desktop\thinsoft 32 Bits V.2.00.672.exe" /SPAWNWND=$301C8 /NOTIFYWND=$301CE C:\Users\admin\AppData\Local\Temp\is-AP32Q.tmp\thinsoft 32 Bits V.2.00.672.tmp
thinsoft 32 Bits V.2.00.672.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.52.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-ap32q.tmp\thinsoft 32 bits v.2.00.672.tmp
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
2540"C:\Users\admin\Desktop\thinsoft 32 Bits V.2.00.672.exe" /SPAWNWND=$301C8 /NOTIFYWND=$301CE C:\Users\admin\Desktop\thinsoft 32 Bits V.2.00.672.exe
thinsoft 32 Bits V.2.00.672.tmp
User:
admin
Company:
ThinSoft Pte. Ltd.
Integrity Level:
HIGH
Description:
BeTwin VS Setup
Exit code:
0
Version:
2.00.672
Modules
Images
c:\users\admin\desktop\thinsoft 32 bits v.2.00.672.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
2828"C:\Users\admin\AppData\Local\Temp\Rar$EXa3468.34612\thinsoft 32 Bits V.2.00.672.exe" /SPAWNWND=$3017A /NOTIFYWND=$40126 C:\Users\admin\AppData\Local\Temp\Rar$EXa3468.34612\thinsoft 32 Bits V.2.00.672.exe
thinsoft 32 Bits V.2.00.672.tmp
User:
admin
Company:
ThinSoft Pte. Ltd.
Integrity Level:
HIGH
Description:
BeTwin VS Setup
Exit code:
0
Version:
2.00.672
Modules
Images
c:\windows\system32\kernel32.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\temp\rar$exa3468.34612\thinsoft 32 bits v.2.00.672.exe
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\oleaut32.dll
3200"C:\Users\admin\AppData\Local\Temp\is-VMD5G.tmp\thinsoft 32 Bits V.2.00.672.tmp" /SL5="$4017C,6340718,52224,C:\Users\admin\AppData\Local\Temp\Rar$EXa3468.34612\thinsoft 32 Bits V.2.00.672.exe" /SPAWNWND=$3017A /NOTIFYWND=$40126 C:\Users\admin\AppData\Local\Temp\is-VMD5G.tmp\thinsoft 32 Bits V.2.00.672.tmp
thinsoft 32 Bits V.2.00.672.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.52.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-vmd5g.tmp\thinsoft 32 bits v.2.00.672.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
3384"C:\Users\admin\AppData\Local\Temp\is-IUQ4P.tmp\thinsoft 32 Bits V.2.00.672.tmp" /SL5="$301CE,6340718,52224,C:\Users\admin\Desktop\thinsoft 32 Bits V.2.00.672.exe" C:\Users\admin\AppData\Local\Temp\is-IUQ4P.tmp\thinsoft 32 Bits V.2.00.672.tmpthinsoft 32 Bits V.2.00.672.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.52.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-iuq4p.tmp\thinsoft 32 bits v.2.00.672.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
3468"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\thinsoft 32 Bits V.2.00.672.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\windows\system32\ntdll.dll
c:\program files\winrar\winrar.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3556"C:\Users\admin\AppData\Local\Temp\is-MSJ33.tmp\thinsoft 32 Bits V.2.00.672.tmp" /SL5="$40126,6340718,52224,C:\Users\admin\AppData\Local\Temp\Rar$EXa3468.34612\thinsoft 32 Bits V.2.00.672.exe" C:\Users\admin\AppData\Local\Temp\is-MSJ33.tmp\thinsoft 32 Bits V.2.00.672.tmpthinsoft 32 Bits V.2.00.672.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.52.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-msj33.tmp\thinsoft 32 bits v.2.00.672.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
3860"C:\Users\admin\Desktop\thinsoft 32 Bits V.2.00.672.exe" C:\Users\admin\Desktop\thinsoft 32 Bits V.2.00.672.exe
explorer.exe
User:
admin
Company:
ThinSoft Pte. Ltd.
Integrity Level:
MEDIUM
Description:
BeTwin VS Setup
Exit code:
0
Version:
2.00.672
Modules
Images
c:\windows\system32\ntdll.dll
c:\users\admin\desktop\thinsoft 32 bits v.2.00.672.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\user32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
4020"C:\Users\admin\AppData\Local\Temp\Rar$EXa3468.34612\thinsoft 32 Bits V.2.00.672.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3468.34612\thinsoft 32 Bits V.2.00.672.exe
WinRAR.exe
User:
admin
Company:
ThinSoft Pte. Ltd.
Integrity Level:
MEDIUM
Description:
BeTwin VS Setup
Exit code:
0
Version:
2.00.672
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3468.34612\thinsoft 32 bits v.2.00.672.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\sechost.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
Total events
1 993
Read events
1 977
Write events
16
Delete events
0

Modification events

(PID) Process:(3468) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\178\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3468) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(3468) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(3468) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(3468) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3468) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3468) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3468) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3468) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3468) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
Executable files
17
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
3468WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3468.34612\thinsoft 32 Bits V.2.00.672.exeexecutable
MD5:1F272E6A7B64807801451463CCA4E237
SHA256:27F8D2B348003AB65732D01B682A1692303E9FAF21996E1DBE544D8C38E628FF
3468WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3468.34612\thinsoft 64 Bits V.2.00.672.exeexecutable
MD5:39EC128A4F354D7C27FC612F5DB3844C
SHA256:D826D1D55E0D2D849BBA87434306CB6C8CC79BE35803DE52025D2F6D7888617E
3200thinsoft 32 Bits V.2.00.672.tmpC:\Users\admin\AppData\Local\Temp\is-U2TD4.tmp\ConfigWizard.dllexecutable
MD5:F4B7136F82E1EB571A907ED86D9FABDE
SHA256:281FA634D7D4D4F114482D9CD2915ECDA2138AD7C2603BA0F0149ED5EB0B6C21
3200thinsoft 32 Bits V.2.00.672.tmpC:\Users\admin\AppData\Local\Temp\is-U2TD4.tmp\SetupHelp.dllexecutable
MD5:100D3C20DFE088519F010AD378085777
SHA256:3878070270785D38F20C175E4D3AA2423F008F5B0AC87A412C279953271A3A7F
4020thinsoft 32 Bits V.2.00.672.exeC:\Users\admin\AppData\Local\Temp\is-MSJ33.tmp\thinsoft 32 Bits V.2.00.672.tmpexecutable
MD5:11B54040FE8F40D6665AA0E4916DE804
SHA256:BC321A39E2B61AD75422041EED5E841318AC23567B2CA73F3D49CE09A8632DD1
3200thinsoft 32 Bits V.2.00.672.tmpC:\Users\admin\AppData\Local\Temp\is-U2TD4.tmp\_isetup\_shfoldr.dllexecutable
MD5:92DC6EF532FBB4A5C3201469A5B5EB63
SHA256:9884E9D1B4F8A873CCBD81F8AD0AE257776D2348D027D811A56475E028360D87
2828thinsoft 32 Bits V.2.00.672.exeC:\Users\admin\AppData\Local\Temp\is-VMD5G.tmp\thinsoft 32 Bits V.2.00.672.tmpexecutable
MD5:11B54040FE8F40D6665AA0E4916DE804
SHA256:BC321A39E2B61AD75422041EED5E841318AC23567B2CA73F3D49CE09A8632DD1
3468WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3468.35353\thinsoft 32 Bits V.2.00.672.exeexecutable
MD5:1F272E6A7B64807801451463CCA4E237
SHA256:27F8D2B348003AB65732D01B682A1692303E9FAF21996E1DBE544D8C38E628FF
2540thinsoft 32 Bits V.2.00.672.exeC:\Users\admin\AppData\Local\Temp\is-AP32Q.tmp\thinsoft 32 Bits V.2.00.672.tmpexecutable
MD5:11B54040FE8F40D6665AA0E4916DE804
SHA256:BC321A39E2B61AD75422041EED5E841318AC23567B2CA73F3D49CE09A8632DD1
3200thinsoft 32 Bits V.2.00.672.tmpC:\Users\admin\AppData\Local\Temp\is-U2TD4.tmp\_isetup\_RegDLL.tmpexecutable
MD5:0EE914C6F0BB93996C75941E1AD629C6
SHA256:4DC09BAC0613590F1FAC8771D18AF5BE25A1E1CB8FDBF4031AA364F3057E74A2
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
3
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
2640
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:138
whitelisted

DNS requests

No data

Threats

No threats detected
No debug info