| File name: | adobe.snr.patch.v2.0-painter.zip |
| Full analysis: | https://app.any.run/tasks/d53c12f8-ad20-49eb-abc6-417ee36e5758 |
| Verdict: | Malicious activity |
| Analysis date: | April 14, 2020, 03:07:05 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract |
| MD5: | 4ED23E6F5520F290CE5C91C515313902 |
| SHA1: | D8CD9355EA54BF27C3665EAAF2C5BD32C664B27D |
| SHA256: | 81804246C3D365A9D8BCBBA34D4D5C401D17CCA988B93A53B6E90B86C2CD6D3F |
| SSDEEP: | 12288:cmr99NVzVbgZRK1Lq+RCIYPxfqsgo/4H1WYcmMC+BsEjf8Xda02xmKp:cmDdEH+bYPljgo/8kvso8XdkkKp |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 20 |
|---|---|
| ZipBitFlag: | - |
| ZipCompression: | Deflated |
| ZipModifyDate: | 2016:12:12 22:22:11 |
| ZipCRC: | 0xbcf93708 |
| ZipCompressedSize: | 807 |
| ZipUncompressedSize: | 1880 |
| ZipFileName: | changelog.txt |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1916 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa3884.48409\adobe.snr.patch.v2.0-painter.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa3884.48409\adobe.snr.patch.v2.0-painter.exe | — | WinRAR.exe | |||||||||||
User: admin Company: PainteR Integrity Level: MEDIUM Description: Universal Adobe Patcher Exit code: 3221226540 Version: 2.0.0.0 Modules
| |||||||||||||||
| 2436 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa3884.48409\adobe.snr.patch.v2.0-painter.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa3884.48409\adobe.snr.patch.v2.0-painter.exe | WinRAR.exe | ||||||||||||
User: admin Company: PainteR Integrity Level: HIGH Description: Universal Adobe Patcher Exit code: 0 Version: 2.0.0.0 Modules
| |||||||||||||||
| 2752 | "C:\Windows\system32\NOTEPAD.EXE" C:\Users\admin\AppData\Local\Temp\Rar$DIa3884.689\Readme.txt | C:\Windows\system32\NOTEPAD.EXE | — | WinRAR.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Notepad Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3884 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\adobe.snr.patch.v2.0-painter.zip" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.60.0 Modules
| |||||||||||||||
| (PID) Process: | (3884) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (3884) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (3884) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3884) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\adobe.snr.patch.v2.0-painter.zip | |||
| (PID) Process: | (3884) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (3884) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (3884) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (3884) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (3884) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E |
| Operation: | write | Name: | @C:\Windows\system32\msinfo32.exe,-10001 |
Value: System Information File | |||
| (PID) Process: | (3884) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3884 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3884.48409\Readme.txt | text | |
MD5:— | SHA256:— | |||
| 3884 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3884.48409\file_id.diz | text | |
MD5:5DCCE195DB29635777AE84D6C18DBA9C | SHA256:93596DE1286A819BF599D48A774B59F82F4FF0428A53813B12D847B36D41B236 | |||
| 3884 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3884.48409\adobe.snr.patch.v2.0-painter.exe | executable | |
MD5:B31679DB7DB878992B4553290A9E6C7C | SHA256:256C2A409C97448D168F3EB1BFB89AF3D259DFC05A510A3F464D8E4B348116D4 | |||
| 3884 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3884.48409\changelog.txt | text | |
MD5:4B2D5F72CBCF32FB287A4500C746A06D | SHA256:9A42940065A010FA5BA4286B4C68769732C1697E54B81945349EB909CE352D73 | |||
| 3884 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DIa3884.689\Readme.txt | text | |
MD5:— | SHA256:— | |||
| 2436 | adobe.snr.patch.v2.0-painter.exe | C:\Users\admin\AppData\Local\Temp\vgm_player.dll | executable | |
MD5:47361F2E1CE562953C36C1E3E4509C06 | SHA256:C5F76741A5B02C7373A05C13F44B47AF60D130F2B2D1A510E7DF270BD2E4D62A | |||
| 3884 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3884.48409\painter.nfo | text | |
MD5:F52DB05E737789CB5DDE8E9707864F84 | SHA256:C67578B40AB730E7F6950CE8BE64755251B948E7A3D4DE5E6DEDDE77D5ED5984 | |||