| File name: | izarc4.1.exe |
| Full analysis: | https://app.any.run/tasks/d5460782-2015-4354-a336-77a81d7889fa |
| Verdict: | Malicious activity |
| Analysis date: | August 08, 2024, 14:40:15 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | F0E553A8109F751EFA8FB3F1ED1115AE |
| SHA1: | 6DBE312ADC97CC0F5DCFB527449893EA5169B0B6 |
| SHA256: | 814FCB32AF414DC6C997F65B1DEC3021F4F6D71FCBECE124AA156FEFA1746FD8 |
| SSDEEP: | 98304:e6CfM85zChxYWpCBOR2lFj7ywEXrsC8XG6H6KwEYlj/u+yLqNmsWZLgsTYoMuBme:BJxyJP |
| .exe | | | Inno Setup installer (77.7) |
|---|---|---|
| .exe | | | Win32 Executable Delphi generic (10) |
| .dll | | | Win32 Dynamic Link Library (generic) (4.6) |
| .exe | | | Win32 Executable (generic) (3.1) |
| .exe | | | Win16/32 Executable Delphi generic (1.4) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 1992:06:19 22:22:17+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi |
| PEType: | PE32 |
| LinkerVersion: | 2.25 |
| CodeSize: | 37888 |
| InitializedDataSize: | 35840 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x9b24 |
| OSVersion: | 1 |
| ImageVersion: | 6 |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 4.1.0.0 |
| ProductVersionNumber: | 4.1.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| Comments: | This installation was built with Inno Setup. |
| CompanyName: | Ivan Zahariev |
| FileDescription: | IZArc 4.1 Setup |
| FileVersion: | 4.1 |
| LegalCopyright: | 2009 Ivan Zahariev |
| ProductName: | IZArc 4.1 |
| ProductVersion: | 4.1 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 644 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=3704 --field-trial-handle=2272,i,5460842830106495654,6691582795631936404,262144 --variations-seed-version /prefetch:1 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| 872 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=3868 --field-trial-handle=2272,i,5460842830106495654,6691582795631936404,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| 1224 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=15 --mojo-platform-channel-handle=6160 --field-trial-handle=2272,i,5460842830106495654,6691582795631936404,262144 --variations-seed-version /prefetch:1 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| 1488 | /s "C:\Program Files (x86)\IZArc\IZArcCM64.dll" | C:\Windows\System32\regsvr32.exe | — | regsvr32.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft(C) Register Server Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1488 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-appcompat-clear --mojo-platform-channel-handle=2408 --field-trial-handle=2272,i,5460842830106495654,6691582795631936404,262144 --variations-seed-version /prefetch:3 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | msedge.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| 2180 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --no-appcompat-clear --gpu-preferences=WAAAAAAAAADgAAAMAAAAAAAAAAAAAAAAAABgAAAAAAA4AAAAAAAAAAAAAAAEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGAAAAAAAAAAYAAAAAAAAAAgAAAAAAAAACAAAAAAAAAAIAAAAAAAAAA== --mojo-platform-channel-handle=2264 --field-trial-handle=2272,i,5460842830106495654,6691582795631936404,262144 --variations-seed-version /prefetch:2 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| 2680 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=3316 --field-trial-handle=2348,i,16233683546974639861,10072666436192329245,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| 3208 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=24 --mojo-platform-channel-handle=6756 --field-trial-handle=2272,i,5460842830106495654,6691582795631936404,262144 --variations-seed-version /prefetch:1 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| 3268 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=21 --mojo-platform-channel-handle=6060 --field-trial-handle=2272,i,5460842830106495654,6691582795631936404,262144 --variations-seed-version /prefetch:1 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| 3272 | "C:\Program Files (x86)\IZArc\IZArc.exe" -sa | C:\Program Files (x86)\IZArc\IZArc.exe | — | izarc4.1.tmp | |||||||||||
User: admin Integrity Level: HIGH Description: IZArc Archiver Exit code: 0 Version: 4.1.0.1820 Modules
| |||||||||||||||
| (PID) Process: | (1488) regsvr32.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3BBAC0AD-8227-3462-C8EF-A36794DD8CD2}\InprocServer32 |
| Operation: | write | Name: | ThreadingModel |
Value: Apartment | |||
| (PID) Process: | (1488) regsvr32.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{3BBAC0AD-8227-3462-C8EF-A36794DD8CD2}\InprocServer32 |
| Operation: | write | Name: | ThreadingModel |
Value: Apartment | |||
| (PID) Process: | (1488) regsvr32.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\IZArcCM |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (1488) regsvr32.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\IZArcCM |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (1488) regsvr32.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved |
| Operation: | write | Name: | {3BBAC0AD-8227-3462-C8EF-A36794DD8CD2} |
Value: IZArc Shell Extension | |||
| (PID) Process: | (1488) regsvr32.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved |
| Operation: | write | Name: | {3BBAC0AD-8227-3462-C8EF-A36794DD8CD2} |
Value: IZArc Shell Extension | |||
| (PID) Process: | (6620) izarc4.1.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{97C82B44-D408-4F14-9252-47FC1636D23E}_is1 |
| Operation: | write | Name: | Inno Setup: Setup Version |
Value: 5.3.6 (a) | |||
| (PID) Process: | (6620) izarc4.1.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{97C82B44-D408-4F14-9252-47FC1636D23E}_is1 |
| Operation: | write | Name: | Inno Setup: App Path |
Value: C:\Program Files (x86)\IZArc | |||
| (PID) Process: | (6620) izarc4.1.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{97C82B44-D408-4F14-9252-47FC1636D23E}_is1 |
| Operation: | write | Name: | InstallLocation |
Value: C:\Program Files (x86)\IZArc\ | |||
| (PID) Process: | (6620) izarc4.1.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{97C82B44-D408-4F14-9252-47FC1636D23E}_is1 |
| Operation: | write | Name: | Inno Setup: Icon Group |
Value: IZArc | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6620 | izarc4.1.tmp | C:\Program Files (x86)\IZArc\is-MQN05.tmp | executable | |
MD5:56D1932B7EDB3AB165D456944EF484DD | SHA256:1514CEE215B7EE3D67FB6E8968C0AF73E4E4C970A3378EF331B2A77ED76E1A4E | |||
| 6620 | izarc4.1.tmp | C:\Program Files (x86)\IZArc\IZArc.exe | executable | |
MD5:DA45613058B8E0302D53AC071EC6B8E9 | SHA256:E43B0E58023F3B1F8560DE796E56E772DAA4F2B82B53E0D6962119329422FD8E | |||
| 6620 | izarc4.1.tmp | C:\Users\admin\AppData\Local\Temp\is-2EFCJ.tmp\OCSetupHlp.dll | executable | |
MD5:BF1DEC904D384A8C9053119BCA691C70 | SHA256:5F3BE1F3898AE1BF9B20543D8B2B2A08FD717D0BBCD8EC11F2B212C57127E410 | |||
| 6620 | izarc4.1.tmp | C:\Program Files (x86)\IZArc\is-2BELJ.tmp | executable | |
MD5:D13A7CC98FC3CBDCAC897747EB30D9E5 | SHA256:EACD666AD079917AEE7392F55E5F3653843AF92C2DFBBCB2EBBBE55B2B8DA1B1 | |||
| 6620 | izarc4.1.tmp | C:\Program Files (x86)\IZArc\WHATSNEW.TXT | text | |
MD5:BD46E9D3477ACCEF157C9204E0558747 | SHA256:87C99049CE1958680D15C3EC4DF13B15774BEF14DA38A9149E562D8831B786C0 | |||
| 6620 | izarc4.1.tmp | C:\Program Files (x86)\IZArc\is-PK348.tmp | text | |
MD5:BD46E9D3477ACCEF157C9204E0558747 | SHA256:87C99049CE1958680D15C3EC4DF13B15774BEF14DA38A9149E562D8831B786C0 | |||
| 6620 | izarc4.1.tmp | C:\Program Files (x86)\IZArc\is-EMEM0.tmp | executable | |
MD5:DA45613058B8E0302D53AC071EC6B8E9 | SHA256:E43B0E58023F3B1F8560DE796E56E772DAA4F2B82B53E0D6962119329422FD8E | |||
| 6620 | izarc4.1.tmp | C:\Program Files (x86)\IZArc\is-I0KES.tmp | chm | |
MD5:27C61867920834F1BB1FE882E73750F3 | SHA256:EF8294A69ABC9442216E66038B4F5DE5C966676738FFFEE270786D4687CA42E5 | |||
| 6588 | izarc4.1.exe | C:\Users\admin\AppData\Local\Temp\is-KRN15.tmp\izarc4.1.tmp | executable | |
MD5:3F8176B7BE40386C043DE30C85D41E6B | SHA256:72AE59418A77F40B98D3C8AA7F4CCF8A77673803A22C91592D0286F44B983F13 | |||
| 6620 | izarc4.1.tmp | C:\Program Files (x86)\IZArc\unins000.exe | executable | |
MD5:CD682652316B24BDF5B7777E9B687FA3 | SHA256:C9D2567CA6AB9310559D0201DFA09A3C1EF067E6E86E303637551630532804FB | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
5336 | SearchApp.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D | unknown | — | — | whitelisted |
7008 | backgroundTaskHost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D | unknown | — | — | whitelisted |
1488 | msedge.exe | GET | 301 | 162.213.251.221:80 | http://izarc.org/donate.html | unknown | — | — | unknown |
7060 | backgroundTaskHost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D | unknown | — | — | whitelisted |
7312 | IZArc.exe | GET | 200 | 172.64.149.23:80 | http://ocsp.comodoca.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRTtU9uFqgVGHhJwXZyWCNXmVR5ngQUoBEKIz6W8Qfs4q8p74Klf9AwpLQCEDlyRDr5IrdR19NsEN0xNZU%3D | unknown | — | — | whitelisted |
7312 | IZArc.exe | GET | 301 | 162.213.251.221:80 | http://www.izarc.org/download/update.ini | unknown | — | — | malicious |
5140 | svchost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
5140 | svchost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
7312 | IZArc.exe | GET | 200 | 104.18.38.233:80 | http://ocsp.usertrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTNMNJMNDqCqx8FcBWK16EHdimS6QQUU3m%2FWqorSs9UgOHYm8Cd8rIDZssCEH1bUSa0droR23QWC7xTDac%3D | unknown | — | — | whitelisted |
7312 | IZArc.exe | GET | 200 | 172.64.149.23:80 | http://ocsp.sectigo.com/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBRDC9IOTxN6GmyRjyTl2n4yTUczyAQUjYxexFStiuF36Zv5mwXhuAGNYeECEQDBfLvWGPP%2FcCqn2quqkRDV | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4160 | svchost.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
2120 | MoUsoCoreWorker.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
532 | RUXIMICS.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
3888 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
5336 | SearchApp.exe | 184.86.251.21:443 | www.bing.com | Akamai International B.V. | DE | unknown |
5336 | SearchApp.exe | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
5140 | svchost.exe | 40.126.31.67:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
7008 | backgroundTaskHost.exe | 20.223.35.26:443 | fd.api.iris.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
api.opencandy.com |
| whitelisted |
www.bing.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
login.live.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
th.bing.com |
| whitelisted |
fd.api.iris.microsoft.com |
| whitelisted |
arc.msn.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
1488 | msedge.exe | Not Suspicious Traffic | INFO [ANY.RUN] Cloudflare content delivery network (cdnjs .cloudflare .com) |
1488 | msedge.exe | Not Suspicious Traffic | INFO [ANY.RUN] Cloudflare content delivery network (cdnjs .cloudflare .com) |
1488 | msedge.exe | Not Suspicious Traffic | INFO [ANY.RUN] Cloudflare content delivery network (cdnjs .cloudflare .com) |
1488 | msedge.exe | Not Suspicious Traffic | INFO [ANY.RUN] Cloudflare content delivery network (cdnjs .cloudflare .com) |