| File name: | Cracklock.3.9.45.rar |
| Full analysis: | https://app.any.run/tasks/d41a237b-8bbe-4b41-bb79-9da1680b0d83 |
| Verdict: | Malicious activity |
| Analysis date: | October 14, 2018, 00:03:39 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-rar |
| File info: | RAR archive data, v4, os: Win32 |
| MD5: | C8161762E900D36B96FF77EB323A9069 |
| SHA1: | E0E70D606824D5C4125B4EF4BFBC36A485B8BC6D |
| SHA256: | 795C2AEA78422765F5C50C5033A55F02C288EECB00EE570D6D9703E70123BDCF |
| SSDEEP: | 24576:aAk9GZyFoLPU9zNPRErH4MvAejZBPG/oo3B4hCq32sfNZW6R13J280VX71:l1ZluZErYMv1jZBO/ooxO53ZfNZdRfFg |
| .rar | | | RAR compressed archive (v-4.x) (58.3) |
|---|---|---|
| .rar | | | RAR compressed archive (gen) (41.6) |
| CompressedSize: | 1312972 |
|---|---|
| UncompressedSize: | 1338014 |
| OperatingSystem: | Win32 |
| ModifyDate: | 2018:10:14 02:02:09 |
| PackingMethod: | Normal |
| ArchivedFileName: | Cracklock.3.9.45.exe |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2444 | "C:\Users\admin\AppData\Local\Temp\is-RK1T6.tmp\Cracklock.3.9.45.tmp" /SL5="$902D8,1061748,53248,C:\Users\admin\Desktop\Cracklock.3.9.45.exe" /SPAWNWND=$E0262 /NOTIFYWND=$B02F0 | C:\Users\admin\AppData\Local\Temp\is-RK1T6.tmp\Cracklock.3.9.45.tmp | Cracklock.3.9.45.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: Setup/Uninstall Exit code: 0 Version: 51.49.0.0 Modules
| |||||||||||||||
| 2460 | "C:\Users\admin\Desktop\Cracklock.3.9.45.exe" /SPAWNWND=$E0262 /NOTIFYWND=$B02F0 | C:\Users\admin\Desktop\Cracklock.3.9.45.exe | Cracklock.3.9.45.tmp | ||||||||||||
User: admin Company: William Blum Integrity Level: HIGH Description: Cracklock Setup Exit code: 0 Version: 3.9.45 Modules
| |||||||||||||||
| 2564 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Cracklock.3.9.45.rar" | C:\Program Files\WinRAR\WinRAR.exe | — | explorer.exe | |||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.60.0 Modules
| |||||||||||||||
| 2596 | "C:\Program Files\Cracklock\Bin\CLMNGR.exe" -set-storage-appdata | C:\Program Files\Cracklock\Bin\CLMNGR.exe | — | Cracklock.3.9.45.tmp | |||||||||||
User: admin Company: William Blum Integrity Level: HIGH Description: Cracklock manager Exit code: 0 Version: 3.9.44 Modules
| |||||||||||||||
| 2700 | "C:\Users\admin\AppData\Local\Temp\is-5HGVI.tmp\Cracklock.3.9.45.tmp" /SL5="$B02F0,1061748,53248,C:\Users\admin\Desktop\Cracklock.3.9.45.exe" | C:\Users\admin\AppData\Local\Temp\is-5HGVI.tmp\Cracklock.3.9.45.tmp | — | Cracklock.3.9.45.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: Setup/Uninstall Exit code: 0 Version: 51.49.0.0 Modules
| |||||||||||||||
| 3036 | "C:\Program Files\Cracklock\Bin\CLMNGR.exe" -add-path | C:\Program Files\Cracklock\Bin\CLMNGR.exe | — | Cracklock.3.9.45.tmp | |||||||||||
User: admin Company: William Blum Integrity Level: HIGH Description: Cracklock manager Exit code: 0 Version: 3.9.44 Modules
| |||||||||||||||
| 3604 | "C:\Program Files\Cracklock\Bin\CLMNGR.exe" | C:\Program Files\Cracklock\Bin\CLMNGR.exe | — | Cracklock.3.9.45.tmp | |||||||||||
User: admin Company: William Blum Integrity Level: MEDIUM Description: Cracklock manager Exit code: 0 Version: 3.9.44 Modules
| |||||||||||||||
| 3704 | "C:\Users\admin\Desktop\Cracklock.3.9.45.exe" | C:\Users\admin\Desktop\Cracklock.3.9.45.exe | explorer.exe | ||||||||||||
User: admin Company: William Blum Integrity Level: MEDIUM Description: Cracklock Setup Exit code: 0 Version: 3.9.45 Modules
| |||||||||||||||
| 3820 | "C:\Program Files\Cracklock\Bin\CLMNGR.exe" -set-syswide | C:\Program Files\Cracklock\Bin\CLMNGR.exe | — | Cracklock.3.9.45.tmp | |||||||||||
User: admin Company: William Blum Integrity Level: HIGH Description: Cracklock manager Exit code: 0 Version: 3.9.44 Modules
| |||||||||||||||
| (PID) Process: | (2564) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (2564) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (2564) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2564) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\Cracklock.3.9.45.rar | |||
| (PID) Process: | (2564) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (2564) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (2564) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (2564) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (2564) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin |
| Operation: | write | Name: | Placement |
Value: 2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000 | |||
| (PID) Process: | (2564) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\General |
| Operation: | write | Name: | LastFolder |
Value: C:\Users\admin\AppData\Local\Temp | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2564 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2564.12652\Cracklock.3.9.45.exe | — | |
MD5:— | SHA256:— | |||
| 2444 | Cracklock.3.9.45.tmp | C:\Program Files\Cracklock\is-OOVMP.tmp | — | |
MD5:— | SHA256:— | |||
| 2444 | Cracklock.3.9.45.tmp | C:\Program Files\Cracklock\is-FDUU1.tmp | — | |
MD5:— | SHA256:— | |||
| 2444 | Cracklock.3.9.45.tmp | C:\Program Files\Cracklock\is-0F8RK.tmp | — | |
MD5:— | SHA256:— | |||
| 2444 | Cracklock.3.9.45.tmp | C:\Program Files\Cracklock\is-FH7DP.tmp | — | |
MD5:— | SHA256:— | |||
| 2444 | Cracklock.3.9.45.tmp | C:\Program Files\Cracklock\Bin\is-BA8VT.tmp | — | |
MD5:— | SHA256:— | |||
| 2444 | Cracklock.3.9.45.tmp | C:\Program Files\Cracklock\Bin\is-SJ4EM.tmp | — | |
MD5:— | SHA256:— | |||
| 2444 | Cracklock.3.9.45.tmp | C:\Program Files\Cracklock\Bin\is-ULNTQ.tmp | — | |
MD5:— | SHA256:— | |||
| 2444 | Cracklock.3.9.45.tmp | C:\Program Files\Cracklock\Bin\is-6VK3P.tmp | — | |
MD5:— | SHA256:— | |||
| 2444 | Cracklock.3.9.45.tmp | C:\Program Files\Cracklock\Bin\is-V3F4R.tmp | — | |
MD5:— | SHA256:— | |||