| File name: | Epson L5190 + Keygen-nosware.com.zip |
| Full analysis: | https://app.any.run/tasks/a1197793-4116-43aa-923f-eb801a184a53 |
| Verdict: | Malicious activity |
| Analysis date: | July 13, 2022, 14:01:07 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v1.0 to extract |
| MD5: | 652717F147E7DABA98EA8EF71B8CB722 |
| SHA1: | 18EEC6D21EF7E9E1AEAD67DA1751A50465ECB518 |
| SHA256: | 7C4CC2DF02F0F8456B8A7854818A47E2F1A773164A815C5278F4CDBFBCA4FEB1 |
| SSDEEP: | 98304:1nVUkG9kLvKxTShS4nt/IG3pVWTUcH2iy0eHyf2j1JhITRpTguJSuoDoPM73iTmK:xVeC2xTW53EUcH7yfy+jGLSoNwSdt5kM |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipFileName: | Epson L5190 + Keygen-nosware.com/ |
|---|---|
| ZipUncompressedSize: | - |
| ZipCompressedSize: | - |
| ZipCRC: | 0x00000000 |
| ZipModifyDate: | 2020:06:21 08:23:15 |
| ZipCompression: | None |
| ZipBitFlag: | - |
| ZipRequiredVersion: | 10 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1536 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa3244.3788\Epson L5190 + Keygen-nosware.com\L5190 onePC\Adjprog.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa3244.3788\Epson L5190 + Keygen-nosware.com\L5190 onePC\Adjprog.exe | WinRAR.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Description: Adjustment program for EPSON Inkjet Printer / Scanner Exit code: 2 Version: 1, 0, 0, 0 Modules
| |||||||||||||||
| 3060 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa3244.5041\Epson L5190 + Keygen-nosware.com\Specific Generators\EXE\WLGen_Epson L5190.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa3244.5041\Epson L5190 + Keygen-nosware.com\Specific Generators\EXE\WLGen_Epson L5190.exe | — | WinRAR.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 3244 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Epson L5190 + Keygen-nosware.com.zip" | C:\Program Files\WinRAR\WinRAR.exe | Explorer.EXE | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| (PID) Process: | (3244) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (3244) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (3244) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3244) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip | |||
| (PID) Process: | (3244) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (3244) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\Epson L5190 + Keygen-nosware.com.zip | |||
| (PID) Process: | (3244) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (3244) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (3244) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (3244) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3244 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3244.3788\Epson L5190 + Keygen-nosware.com\L5190 onePC\Adjprog.exe | executable | |
MD5:— | SHA256:— | |||
| 3244 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3244.3788\Epson L5190 + Keygen-nosware.com\L5190 onePC\headid.bmp | image | |
MD5:BD2D076F0D4C5CB4E4DD622EDEFF72B3 | SHA256:268119E12AE85210E6DA2D1E98C8D66B267C8696CC3A9E590B79B9546D9363AF | |||
| 3244 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3244.3788\Epson L5190 + Keygen-nosware.com\L5190 onePC\apdadrv.dll | executable | |
MD5:7BC6071301F011EDFE115026A5E3A20D | SHA256:F2277C9F1F477A6BD06B4645BD818E241CE8352395B4D67BAB87583AAEBD36FD | |||
| 3244 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3244.3788\Epson L5190 + Keygen-nosware.com\L5190 onePC\LimitSample.exe.config | xml | |
MD5:6FF09217336C85CE71456B1C79B56B66 | SHA256:B9F388E388FB855999926F8BA0E6997F3917285A3AF83A96C249FC529F341975 | |||
| 3244 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3244.3788\Epson L5190 + Keygen-nosware.com\L5190 onePC\caution.bmp | image | |
MD5:29158633EF078D5D4AE7D1C76165A0A9 | SHA256:D9461C3292A2283EADC730E2EAEFB42A4EAC2C48B98397BAD0F7B918C86F3893 | |||
| 3244 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3244.3788\Epson L5190 + Keygen-nosware.com\L5190 onePC\nw_resetdata.dat | text | |
MD5:4B8033954B4440361C2479863C051C4A | SHA256:1587151474592C2CF4BCDAE0A1CAA10185B1AAB07F02390ADC9ABAF7C2F14CE6 | |||
| 3244 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3244.3788\Epson L5190 + Keygen-nosware.com\Specific Generators\DLL\COFF\CustomWinLicenseSDK.lib | obj | |
MD5:DB92795AA5E48EE56B3CF9CDAC664CEA | SHA256:882107707F13EA3D40C9C5EE4BFCEFDC2133F542628ED55D918B06BEC812068F | |||
| 3244 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3244.3788\Epson L5190 + Keygen-nosware.com\L5190 onePC\EditText.dat | ini | |
MD5:5B1E183F5CAD1ADF0799B514F5D31295 | SHA256:85D5F3B287A4C34CA1FA3C6B221C1635689B53668571D05B6EDCCE55992B2BBB | |||
| 3244 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3244.3788\Epson L5190 + Keygen-nosware.com\L5190 onePC\ErrorDetail.dat | ini | |
MD5:62776BE9A152B466B3D86D2D266F9D42 | SHA256:4C38555FB1AE9A16F7BE0132261F666B4570FDFF457C3CEFC5ED36D8F2AE6974 | |||
| 3244 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3244.3788\Epson L5190 + Keygen-nosware.com\L5190 onePC\LimitSample.exe | executable | |
MD5:A8D3728F36A5CEEDA695F62CC7382D9E | SHA256:412DF15CF48EAF8C274D349CE980C9B728CD4F997254983ECA7DD552843CAF8F | |||
Process | Message |
|---|---|
Adjprog.exe |
%s------------------------------------------------
--- WinLicense Professional ---
--- (c)2012 Oreans Technologies ---
------------------------------------------------
|