| download: | Jawset%20TurbulenceFD%20v1.0%20Build%201437%20R20%20win%E4%B8%AD%E8%8B%B1%E4%B8%80%E9%94%AE%E5%AE%89%E8%A3%85%E7%89%88.rar |
| Full analysis: | https://app.any.run/tasks/1df56e4f-e8c8-46e0-a9a3-e841eff7f6a6 |
| Verdict: | Malicious activity |
| Analysis date: | September 30, 2020, 07:35:44 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-rar |
| File info: | RAR archive data, v5 |
| MD5: | AC69F98A3702B7405DB8BA32F3A1CAB9 |
| SHA1: | 62C36DFF9DCC10C4BBE8D0F4E20945C5BE0FAC0E |
| SHA256: | 73A82276DAC740D3264E9FAB4AB7B00BE676957BB05C1F4835A397B43743A31B |
| SSDEEP: | 196608:fDM5r+QYjsqG5Pj6IiQP/maSxiMzD/yP7bgUOX2pmQMke62hEO7vj28uqqjI:f3jor6/QHm/xiMzjGxOQmQghEaadE |
| .rar | | | RAR compressed archive (v5.0) (61.5) |
|---|---|---|
| .rar | | | RAR compressed archive (gen) (38.4) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 372 | "C:\Users\admin\AppData\Local\Temp\is-3HT03.tmp\aaaa.tmp" /SL5="$301A2,17842568,215040,C:\Users\admin\Desktop\fff\aaaa.exe" | C:\Users\admin\AppData\Local\Temp\is-3HT03.tmp\aaaa.tmp | aaaa.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: Setup/Uninstall Exit code: 1 Version: 51.52.0.0 Modules
| |||||||||||||||
| 844 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\775632b1-8162-436c-9da8-9102b4fe87bb.rar" | C:\Program Files\WinRAR\WinRAR.exe | — | explorer.exe | |||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.60.0 Modules
| |||||||||||||||
| 1240 | "C:\Users\admin\Desktop\fff\aaaa.exe" | C:\Users\admin\Desktop\fff\aaaa.exe | explorer.exe | ||||||||||||
User: admin Company: Integrity Level: HIGH Description: TurbulenceFD一键安装版 Setup Exit code: 1 Version: Modules
| |||||||||||||||
| 1724 | "C:\Users\admin\AppData\Local\Temp\is-GLC4S.tmp\aaaa.tmp" /SL5="$301A4,17842568,215040,C:\Users\admin\Desktop\fff\aaaa.exe" | C:\Users\admin\AppData\Local\Temp\is-GLC4S.tmp\aaaa.tmp | aaaa.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: Setup/Uninstall Exit code: 1 Version: 51.52.0.0 Modules
| |||||||||||||||
| 1748 | "C:\Users\admin\Desktop\fff\aaaa.exe" | C:\Users\admin\Desktop\fff\aaaa.exe | explorer.exe | ||||||||||||
User: admin Company: Integrity Level: HIGH Description: TurbulenceFD一键安装版 Setup Exit code: 1 Version: Modules
| |||||||||||||||
| 2104 | "C:\Users\admin\Desktop\fff\aaaa.exe" | C:\Users\admin\Desktop\fff\aaaa.exe | — | explorer.exe | |||||||||||
User: admin Company: Integrity Level: MEDIUM Description: TurbulenceFD一键安装版 Setup Exit code: 3221226540 Version: Modules
| |||||||||||||||
| 2892 | "C:\Users\admin\Desktop\fff\aaaa.exe" | C:\Users\admin\Desktop\fff\aaaa.exe | explorer.exe | ||||||||||||
User: admin Company: Integrity Level: HIGH Description: TurbulenceFD一键安装版 Setup Exit code: 1 Version: Modules
| |||||||||||||||
| 2960 | "C:\Users\admin\AppData\Local\Temp\is-IFLEK.tmp\aaaa.tmp" /SL5="$401A8,17842568,215040,C:\Users\admin\Desktop\fff\aaaa.exe" | C:\Users\admin\AppData\Local\Temp\is-IFLEK.tmp\aaaa.tmp | aaaa.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: Setup/Uninstall Exit code: 1 Version: 51.52.0.0 Modules
| |||||||||||||||
| 2964 | "C:\Users\admin\Desktop\TurbulenceFD中英一键安装版.exe" | C:\Users\admin\Desktop\TurbulenceFD中英一键安装版.exe | — | explorer.exe | |||||||||||
User: admin Company: Integrity Level: MEDIUM Description: TurbulenceFD一键安装版 Setup Exit code: 3221226540 Version: Modules
| |||||||||||||||
| 3036 | "C:\Users\admin\Desktop\fff\aaaa.exe" | C:\Users\admin\Desktop\fff\aaaa.exe | — | explorer.exe | |||||||||||
User: admin Company: Integrity Level: MEDIUM Description: TurbulenceFD一键安装版 Setup Exit code: 3221226540 Version: Modules
| |||||||||||||||
| (PID) Process: | (844) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (844) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (844) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\13B\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (844) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\775632b1-8162-436c-9da8-9102b4fe87bb.rar | |||
| (PID) Process: | (844) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (844) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (844) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (844) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (844) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\13B\52C64B7E |
| Operation: | write | Name: | @C:\Windows\System32\ieframe.dll,-10046 |
Value: Internet Shortcut | |||
| (PID) Process: | (844) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\13B\52C64B7E |
| Operation: | write | Name: | @C:\Windows\system32\notepad.exe,-469 |
Value: Text Document | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 844 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa844.48646\TurbulenceFD中英一键安装版.exe | — | |
MD5:— | SHA256:— | |||
| 844 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa844.48646\1.加入会员,海量资源免费获取.url | — | |
MD5:— | SHA256:— | |||
| 844 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa844.48646\2.C4DSKY.com 书生影视CG资源站.url | — | |
MD5:— | SHA256:— | |||
| 844 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa844.48646\3.书生官方淘宝店,感谢支持.url | — | |
MD5:— | SHA256:— | |||
| 844 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa844.48646\4.免责声明,使用前必看.txt | — | |
MD5:— | SHA256:— | |||
| 844 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa844.48646\更多资源\AE模板精选影视片头音乐合集Audio Jungle超级音效库.url | — | |
MD5:— | SHA256:— | |||
| 844 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa844.48646\更多资源\书生微信公众号,每天都有新鲜的行业干货与福利.jpg | — | |
MD5:— | SHA256:— | |||
| 844 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa844.48646\更多资源\更多优质软件,插件,素材,资源.url | — | |
MD5:— | SHA256:— | |||
| 2892 | aaaa.exe | C:\Users\admin\AppData\Local\Temp\is-GLC4S.tmp\aaaa.tmp | executable | |
MD5:— | SHA256:— | |||
| 1240 | aaaa.exe | C:\Users\admin\AppData\Local\Temp\is-3HT03.tmp\aaaa.tmp | executable | |
MD5:— | SHA256:— | |||