| File name: | RedFox AnyDVD HD 7.6.9.2.rar |
| Full analysis: | https://app.any.run/tasks/c1e314a8-d0b1-4e90-9697-df6f5c092bad |
| Verdict: | Malicious activity |
| Analysis date: | December 21, 2024, 17:35:33 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-rar |
| File info: | RAR archive data, v5 |
| MD5: | 6C74580E2B08FB9CD4391ADC2CDFA108 |
| SHA1: | BEDB3EDCD54580395ED76AA8D242B1DECD54990D |
| SHA256: | 7BF7A27603E727C0AEDFD9ACBA7A519087CDA2A78D29CE27F96E718657B35757 |
| SSDEEP: | 98304:+92M9lPYY9MX4rlifP2mbkl/77+jJxMjXM8xnRmH/O4YnJMizFar6XcKWTjN6crp:+F4Yas+c1IYrR3VtsYSzldMcF |
| .rar | | | RAR compressed archive (v5.0) (61.5) |
|---|---|---|
| .rar | | | RAR compressed archive (gen) (38.4) |
| FileVersion: | RAR v5 |
|---|---|
| CompressedSize: | 239 |
| UncompressedSize: | 240 |
| OperatingSystem: | Win32 |
| ArchivedFileName: | RedFox AnyDVD HD 7.6.9.2/Key/11710348-HD.AnyDVDHD |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 372 | "C:\Program Files (x86)\SlySoft\AnyDVD\SetRegACL.exe" Software\Microsoft\Windows\CurrentVersion\Explorer\DriveIcons 64 | C:\Program Files (x86)\SlySoft\AnyDVD\SetRegACL.exe | — | nst68A1.tmp | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 2928 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | setacl.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2940 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa6840.35442\RedFox AnyDVD HD 7.6.9.2\SetupAnyDVD7692.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa6840.35442\RedFox AnyDVD HD 7.6.9.2\SetupAnyDVD7692.exe | WinRAR.exe | ||||||||||||
User: admin Integrity Level: HIGH Modules
| |||||||||||||||
| 3208 | "C:\Users\admin\AppData\Local\Temp\nst6AB4.tmp\SetACL.exe" "MACHINE\SOFTWARE\SlySoft\AnyDVD\Status" /registry /grant S-1-5-32-545 /full /sid /silent | C:\Users\admin\AppData\Local\Temp\nst6AB4.tmp\setacl.exe | — | nst68A1.tmp | |||||||||||
User: admin Company: Helge Klein Integrity Level: HIGH Description: SetACL Exit code: 0 Version: 0, 9, 0, 4 Modules
| |||||||||||||||
| 3220 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa6840.35442\RedFox AnyDVD HD 7.6.9.2\SetupAnyDVD7692.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa6840.35442\RedFox AnyDVD HD 7.6.9.2\SetupAnyDVD7692.exe | — | WinRAR.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 3221226540 Modules
| |||||||||||||||
| 3988 | "C:\Program Files (x86)\SlySoft\AnyDVD\AnyDVD.exe" -c | C:\Program Files (x86)\SlySoft\AnyDVD\AnyDVD.exe | — | nst68A1.tmp | |||||||||||
User: admin Company: RedFox Integrity Level: HIGH Description: AnyDVD Application Version: 7.6.9.2 Modules
| |||||||||||||||
| 4516 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | SetRegACL.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 5460 | "C:\Program Files (x86)\SlySoft\AnyDVD\AnyDVDtray.exe" -c | C:\Program Files (x86)\SlySoft\AnyDVD\AnyDVDtray.exe | — | AnyDVD.exe | |||||||||||
User: admin Company: RedFox Integrity Level: HIGH Description: AnyDVD Application Exit code: 10 Version: 7.6.9.2 Modules
| |||||||||||||||
| 6388 | nst68A1.tmp /DOIT | C:\Users\admin\AppData\Local\Temp\nst6891.tmp\nst68A1.tmp | SetupAnyDVD7692.exe | ||||||||||||
User: admin Integrity Level: HIGH Modules
| |||||||||||||||
| 6404 | "C:\Users\admin\AppData\Local\Temp\nst6AB4.tmp\SetACL.exe" "C:\ProgramData\SlySoft" /dir /grant S-1-5-32-545 /full /sid /silent | C:\Users\admin\AppData\Local\Temp\nst6AB4.tmp\setacl.exe | — | nst68A1.tmp | |||||||||||
User: admin Company: Helge Klein Integrity Level: HIGH Description: SetACL Exit code: 0 Version: 0, 9, 0, 4 Modules
| |||||||||||||||
| (PID) Process: | (6840) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\preferences.zip | |||
| (PID) Process: | (6840) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\chromium_ext.zip | |||
| (PID) Process: | (6840) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\omni_23_10_2024_.zip | |||
| (PID) Process: | (6840) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\RedFox AnyDVD HD 7.6.9.2.rar | |||
| (PID) Process: | (6840) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (6840) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (6840) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (6840) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (6840) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\MainWin |
| Operation: | write | Name: | Placement |
Value: 2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF3D0000002D000000FD03000016020000 | |||
| (PID) Process: | (6840) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\ArcColumnWidths |
| Operation: | write | Name: | name |
Value: 256 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6388 | nst68A1.tmp | C:\Users\admin\AppData\Local\Temp\nst6AB4.tmp\Language\AnyDVDcz.lng | binary | |
MD5:9F5C1E5E74877510B5381D369AE488AA | SHA256:19D59763515B7FF72BC72EFEBD52BA3C2E8499AACB2603221DAE62004B9B705A | |||
| 6388 | nst68A1.tmp | C:\Users\admin\AppData\Local\Temp\nst6AB4.tmp\Language\AnyDVDfr.lng | binary | |
MD5:E1E2315B76B8320E200F3B4E029BBC5D | SHA256:9C1C171F6A839E1D269DBA21424D41821B58261C39183F3492E9CCC5BBA5F868 | |||
| 6388 | nst68A1.tmp | C:\Users\admin\AppData\Local\Temp\nst6AB4.tmp\Language\AnyDVDel.lng | binary | |
MD5:665BE015DC370EF1A7C5C7ECAD2F2A83 | SHA256:2128932DFA8B0EF86BFBB002664327268B0D50743180836E91FC665EF796841B | |||
| 6388 | nst68A1.tmp | C:\Users\admin\AppData\Local\Temp\nst6AB4.tmp\Language\AnyDVDar.lng | binary | |
MD5:190C524604AE9F4990EBE3E75DD22165 | SHA256:E341E499210D134D754F942A684CBEEFC44DDA5BCFF2D10B3BBFBB9470F665DE | |||
| 6388 | nst68A1.tmp | C:\Users\admin\AppData\Local\Temp\nst6AB4.tmp\InstallHelp.dll | executable | |
MD5:95E69C3058EEDF7C848CFBED4A89E99B | SHA256:4647E65063EF6A3CF205749CF4AB13E7CE20CB3735214B7BA9DD709086F41617 | |||
| 6388 | nst68A1.tmp | C:\Users\admin\AppData\Local\Temp\nst6AB4.tmp\Language\AnyDVDen.lng | binary | |
MD5:6E06D12E1A3CCE869D13DF2328934670 | SHA256:C3AB460DB9A8669774104AA6C7A7D879981564CF55177347D29E584331B3A608 | |||
| 6388 | nst68A1.tmp | C:\Users\admin\AppData\Local\Temp\nst6AB4.tmp\Language\AnyDVDes.lng | binary | |
MD5:BCE68201976CAC0A6B90ECA44E0C591C | SHA256:4D96331D16DF4A3A9ED3DDD344887EC64006665C30EAA96F8F8A7F63218C2DDC | |||
| 6388 | nst68A1.tmp | C:\Users\admin\AppData\Local\Temp\nst6AB4.tmp\Language\AnyDVDde.lng | binary | |
MD5:DA372A007E291ADD2A1DB9EC4C686F8B | SHA256:346E53CA0DC5108E5F67A2F7781AAD315C194A501A16AFF084740211081204B3 | |||
| 6388 | nst68A1.tmp | C:\Users\admin\AppData\Local\Temp\nst6AB4.tmp\Language\AnyDVDda.lng | binary | |
MD5:B0862E79D6A2F22E8191DE575ED090A5 | SHA256:BF754C0B86FCB51A8EA76C3ED2BF0B1DECEE617A41B5B807326094958E37525D | |||
| 6388 | nst68A1.tmp | C:\Users\admin\AppData\Local\Temp\nst6AB4.tmp\Language\AnyDVDbr.lng | binary | |
MD5:BB64F654EF32C93F3BE2A7FC6229F591 | SHA256:0866626AD5C985B454261C1BF8BA4E7CFB47EA23C93588EB9006473B4311A3E2 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | GET | 200 | 2.16.164.59:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
— | — | GET | 200 | 2.16.164.59:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
— | — | GET | 200 | 88.221.169.152:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
— | — | GET | 200 | 88.221.169.152:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
— | — | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D | unknown | — | — | whitelisted |
— | — | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
6612 | backgroundTaskHost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D | unknown | — | — | whitelisted |
— | — | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
— | — | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
— | — | 2.16.164.59:80 | crl.microsoft.com | Akamai International B.V. | NL | whitelisted |
— | — | 88.221.169.152:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
5064 | SearchApp.exe | 2.23.209.149:443 | www.bing.com | Akamai International B.V. | GB | whitelisted |
— | — | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1176 | svchost.exe | 20.190.160.17:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
1076 | svchost.exe | 184.28.89.167:443 | go.microsoft.com | AKAMAI-AS | US | whitelisted |
1488 | svchost.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
www.bing.com |
| whitelisted |
google.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
login.live.com |
| whitelisted |
go.microsoft.com |
| whitelisted |
arc.msn.com |
| whitelisted |
fd.api.iris.microsoft.com |
| whitelisted |