| File name: | RedFox AnyDVD HD 7.6.9.2.rar |
| Full analysis: | https://app.any.run/tasks/c1e314a8-d0b1-4e90-9697-df6f5c092bad |
| Verdict: | Malicious activity |
| Analysis date: | December 21, 2024, 17:35:33 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-rar |
| File info: | RAR archive data, v5 |
| MD5: | 6C74580E2B08FB9CD4391ADC2CDFA108 |
| SHA1: | BEDB3EDCD54580395ED76AA8D242B1DECD54990D |
| SHA256: | 7BF7A27603E727C0AEDFD9ACBA7A519087CDA2A78D29CE27F96E718657B35757 |
| SSDEEP: | 98304:+92M9lPYY9MX4rlifP2mbkl/77+jJxMjXM8xnRmH/O4YnJMizFar6XcKWTjN6crp:+F4Yas+c1IYrR3VtsYSzldMcF |
| .rar | | | RAR compressed archive (v5.0) (61.5) |
|---|---|---|
| .rar | | | RAR compressed archive (gen) (38.4) |
| FileVersion: | RAR v5 |
|---|---|
| CompressedSize: | 239 |
| UncompressedSize: | 240 |
| OperatingSystem: | Win32 |
| ArchivedFileName: | RedFox AnyDVD HD 7.6.9.2/Key/11710348-HD.AnyDVDHD |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 372 | "C:\Program Files (x86)\SlySoft\AnyDVD\SetRegACL.exe" Software\Microsoft\Windows\CurrentVersion\Explorer\DriveIcons 64 | C:\Program Files (x86)\SlySoft\AnyDVD\SetRegACL.exe | — | nst68A1.tmp | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 2928 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | setacl.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2940 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa6840.35442\RedFox AnyDVD HD 7.6.9.2\SetupAnyDVD7692.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa6840.35442\RedFox AnyDVD HD 7.6.9.2\SetupAnyDVD7692.exe | WinRAR.exe | ||||||||||||
User: admin Integrity Level: HIGH Modules
| |||||||||||||||
| 3208 | "C:\Users\admin\AppData\Local\Temp\nst6AB4.tmp\SetACL.exe" "MACHINE\SOFTWARE\SlySoft\AnyDVD\Status" /registry /grant S-1-5-32-545 /full /sid /silent | C:\Users\admin\AppData\Local\Temp\nst6AB4.tmp\setacl.exe | — | nst68A1.tmp | |||||||||||
User: admin Company: Helge Klein Integrity Level: HIGH Description: SetACL Exit code: 0 Version: 0, 9, 0, 4 Modules
| |||||||||||||||
| 3220 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa6840.35442\RedFox AnyDVD HD 7.6.9.2\SetupAnyDVD7692.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa6840.35442\RedFox AnyDVD HD 7.6.9.2\SetupAnyDVD7692.exe | — | WinRAR.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 3221226540 Modules
| |||||||||||||||
| 3988 | "C:\Program Files (x86)\SlySoft\AnyDVD\AnyDVD.exe" -c | C:\Program Files (x86)\SlySoft\AnyDVD\AnyDVD.exe | — | nst68A1.tmp | |||||||||||
User: admin Company: RedFox Integrity Level: HIGH Description: AnyDVD Application Version: 7.6.9.2 Modules
| |||||||||||||||
| 4516 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | SetRegACL.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 5460 | "C:\Program Files (x86)\SlySoft\AnyDVD\AnyDVDtray.exe" -c | C:\Program Files (x86)\SlySoft\AnyDVD\AnyDVDtray.exe | — | AnyDVD.exe | |||||||||||
User: admin Company: RedFox Integrity Level: HIGH Description: AnyDVD Application Exit code: 10 Version: 7.6.9.2 Modules
| |||||||||||||||
| 6388 | nst68A1.tmp /DOIT | C:\Users\admin\AppData\Local\Temp\nst6891.tmp\nst68A1.tmp | SetupAnyDVD7692.exe | ||||||||||||
User: admin Integrity Level: HIGH Modules
| |||||||||||||||
| 6404 | "C:\Users\admin\AppData\Local\Temp\nst6AB4.tmp\SetACL.exe" "C:\ProgramData\SlySoft" /dir /grant S-1-5-32-545 /full /sid /silent | C:\Users\admin\AppData\Local\Temp\nst6AB4.tmp\setacl.exe | — | nst68A1.tmp | |||||||||||
User: admin Company: Helge Klein Integrity Level: HIGH Description: SetACL Exit code: 0 Version: 0, 9, 0, 4 Modules
| |||||||||||||||
| (PID) Process: | (6840) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\preferences.zip | |||
| (PID) Process: | (6840) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\chromium_ext.zip | |||
| (PID) Process: | (6840) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\omni_23_10_2024_.zip | |||
| (PID) Process: | (6840) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\RedFox AnyDVD HD 7.6.9.2.rar | |||
| (PID) Process: | (6840) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (6840) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (6840) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (6840) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (6840) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\MainWin |
| Operation: | write | Name: | Placement |
Value: 2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF3D0000002D000000FD03000016020000 | |||
| (PID) Process: | (6840) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\ArcColumnWidths |
| Operation: | write | Name: | name |
Value: 256 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6388 | nst68A1.tmp | C:\Users\admin\AppData\Local\Temp\nst6AB4.tmp\Language\AnyDVDbr.lng | binary | |
MD5:BB64F654EF32C93F3BE2A7FC6229F591 | SHA256:0866626AD5C985B454261C1BF8BA4E7CFB47EA23C93588EB9006473B4311A3E2 | |||
| 6388 | nst68A1.tmp | C:\Users\admin\AppData\Local\Temp\nst6AB4.tmp\AnyDVDtray.exe | executable | |
MD5:2C1165E00C0C8C0264E2DB4702399A10 | SHA256:56B667309900B331887F9B9B9A67ED653EFFD5E4FE730F9F01F2804620A555AE | |||
| 6840 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa6840.35442\RedFox AnyDVD HD 7.6.9.2\Key\11710348-HD.AnyDVDHD | text | |
MD5:91D8F27DF3BAD971D32410B665B74895 | SHA256:1A8E307AB90F117FB142DE6450994EA1731252D35AEE34851B6695D57AF68A96 | |||
| 6840 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa6840.35442\RedFox AnyDVD HD 7.6.9.2\SetupAnyDVD7692.exe | executable | |
MD5:58ABC125B3AF981129A0E27EBE26C322 | SHA256:D9477055AB397EECDA419DEFFFAB789AA42A703DCD8B06E369BE47893F10CE6B | |||
| 2940 | SetupAnyDVD7692.exe | C:\Users\admin\AppData\Local\Temp\nst6891.tmp\nst68A1.tmp | executable | |
MD5:58ABC125B3AF981129A0E27EBE26C322 | SHA256:D9477055AB397EECDA419DEFFFAB789AA42A703DCD8B06E369BE47893F10CE6B | |||
| 6388 | nst68A1.tmp | C:\Users\admin\AppData\Local\Temp\nst6AB4.tmp\Language\AnyDVDde.lng | binary | |
MD5:DA372A007E291ADD2A1DB9EC4C686F8B | SHA256:346E53CA0DC5108E5F67A2F7781AAD315C194A501A16AFF084740211081204B3 | |||
| 6388 | nst68A1.tmp | C:\Users\admin\AppData\Local\Temp\nst6AB4.tmp\InstallHelp.dll | executable | |
MD5:95E69C3058EEDF7C848CFBED4A89E99B | SHA256:4647E65063EF6A3CF205749CF4AB13E7CE20CB3735214B7BA9DD709086F41617 | |||
| 6388 | nst68A1.tmp | C:\Users\admin\AppData\Local\Temp\nst6AB4.tmp\Language\AnyDVDar.lng | binary | |
MD5:190C524604AE9F4990EBE3E75DD22165 | SHA256:E341E499210D134D754F942A684CBEEFC44DDA5BCFF2D10B3BBFBB9470F665DE | |||
| 6388 | nst68A1.tmp | C:\Users\admin\AppData\Local\Temp\nst6AB4.tmp\Language\AnyDVDca.lng | binary | |
MD5:EA0FF2410D300EF62ADF0CFFFDAC36CE | SHA256:7ACB4887E4CB4065E2BD924F1C74AA429C77C874190263E80969F47D5F24E7AB | |||
| 6388 | nst68A1.tmp | C:\Users\admin\AppData\Local\Temp\nst6AB4.tmp\Language\AnyDVDcz.lng | binary | |
MD5:9F5C1E5E74877510B5381D369AE488AA | SHA256:19D59763515B7FF72BC72EFEBD52BA3C2E8499AACB2603221DAE62004B9B705A | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | GET | 200 | 2.16.164.59:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
— | — | GET | 200 | 2.16.164.59:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
— | — | GET | 200 | 88.221.169.152:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
— | — | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D | unknown | — | — | whitelisted |
— | — | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
— | — | GET | 200 | 88.221.169.152:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
— | — | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
— | — | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
6612 | backgroundTaskHost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
— | — | 2.16.164.59:80 | crl.microsoft.com | Akamai International B.V. | NL | whitelisted |
— | — | 88.221.169.152:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
5064 | SearchApp.exe | 2.23.209.149:443 | www.bing.com | Akamai International B.V. | GB | whitelisted |
— | — | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1176 | svchost.exe | 20.190.160.17:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
1076 | svchost.exe | 184.28.89.167:443 | go.microsoft.com | AKAMAI-AS | US | whitelisted |
1488 | svchost.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
www.bing.com |
| whitelisted |
google.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
login.live.com |
| whitelisted |
go.microsoft.com |
| whitelisted |
arc.msn.com |
| whitelisted |
fd.api.iris.microsoft.com |
| whitelisted |