| File name: | CrystalDiskInfo8_1_0.zip |
| Full analysis: | https://app.any.run/tasks/32303ff8-902e-4d9e-903b-4ffb383fad2a |
| Verdict: | Malicious activity |
| Analysis date: | May 21, 2019, 02:10:31 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v1.0 to extract |
| MD5: | 563D0AE995DC41973260681DAB96AD7A |
| SHA1: | BA60A6C8C9533EFE65B3C33901E0516CE09504A8 |
| SHA256: | 840F394F6AAD421BC24FDA4F1625A318C4F1C136D1067BE0C8AB621AF81743EC |
| SSDEEP: | 98304:A74DdJdi5O4M/vvgKQCaPJw6fsYByuRUYSpsU7bzS4/wPbyKZxy9MmQ:FdJdi5OhIKQ4EkASpsU7ZsyQxClQ |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 10 |
|---|---|
| ZipBitFlag: | - |
| ZipCompression: | None |
| ZipModifyDate: | 2019:04:22 21:45:11 |
| ZipCRC: | 0x00000000 |
| ZipCompressedSize: | - |
| ZipUncompressedSize: | - |
| ZipFileName: | CdiResource/ |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 592 | "C:\Program Files\CCleaner\CCleaner.exe" /uac | C:\Program Files\CCleaner\CCleaner.exe | taskeng.exe | ||||||||||||
User: admin Company: Piriform Ltd Integrity Level: HIGH Description: CCleaner Exit code: 0 Version: 5, 35, 0, 6210 Modules
| |||||||||||||||
| 916 | "C:\Users\admin\Desktop\DiskInfo32.exe" | C:\Users\admin\Desktop\DiskInfo32.exe | explorer.exe | ||||||||||||
User: admin Company: Crystal Dew World Integrity Level: HIGH Description: CrystalDiskInfo Exit code: 0 Version: 8.1.0.2019 Modules
| |||||||||||||||
| 1048 | "C:\Windows\system32\calc.exe" | C:\Windows\system32\calc.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Calculator Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1692 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3676.0.1275171948\1042578857" -parentBuildID 20190225143501 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" - "C:\Users\admin\AppData\LocalLow\Mozilla\Temp-{ce348e4c-7d33-445e-89f9-60108c51bcaf}" 3676 "\\.\pipe\gecko-crash-server-pipe.3676" 1124 gpu | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 65.0.2 Modules
| |||||||||||||||
| 1804 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3676.13.1323372169\1840361668" -childID 2 -isForBrowser -prefsHandle 2092 -prefMapHandle 2124 -prefsLen 122 -prefMapSize 180950 -schedulerPrefs 0001,2 -parentBuildID 20190225143501 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" - 3676 "\\.\pipe\gecko-crash-server-pipe.3676" 2328 tab | C:\Program Files\Mozilla Firefox\firefox.exe | firefox.exe | ||||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 65.0.2 Modules
| |||||||||||||||
| 1976 | "C:\Program Files\CCleaner\CCleaner.exe" /monitor | C:\Program Files\CCleaner\CCleaner.exe | CCleaner.exe | ||||||||||||
User: admin Company: Piriform Ltd Integrity Level: HIGH Description: CCleaner Exit code: 0 Version: 5, 35, 0, 6210 Modules
| |||||||||||||||
| 2172 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3676.41.1864946234\746516660" -childID 6 -isForBrowser -prefsHandle 4256 -prefMapHandle 3696 -prefsLen 6996 -prefMapSize 180950 -schedulerPrefs 0001,2 -parentBuildID 20190225143501 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" - 3676 "\\.\pipe\gecko-crash-server-pipe.3676" 4340 tab | C:\Program Files\Mozilla Firefox\firefox.exe | firefox.exe | ||||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 65.0.2 Modules
| |||||||||||||||
| 2232 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\CrystalDiskInfo8_1_0.zip" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.60.0 Modules
| |||||||||||||||
| 2636 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3676.6.1410477704\1023043606" -childID 1 -isForBrowser -prefsHandle 1636 -prefMapHandle 1656 -prefsLen 1 -prefMapSize 180950 -schedulerPrefs 0001,2 -parentBuildID 20190225143501 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" - 3676 "\\.\pipe\gecko-crash-server-pipe.3676" 1644 tab | C:\Program Files\Mozilla Firefox\firefox.exe | firefox.exe | ||||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 65.0.2 Modules
| |||||||||||||||
| 2760 | "C:\Program Files\CCleaner\CCleaner.exe" | C:\Program Files\CCleaner\CCleaner.exe | — | explorer.exe | |||||||||||
User: admin Company: Piriform Ltd Integrity Level: MEDIUM Description: CCleaner Exit code: 0 Version: 5, 35, 0, 6210 Modules
| |||||||||||||||
| (PID) Process: | (2232) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (2232) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (2232) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\62\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2232) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\CrystalDiskInfo8_1_0.zip | |||
| (PID) Process: | (2232) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (2232) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (2232) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (2232) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (2232) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin |
| Operation: | write | Name: | Placement |
Value: 2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000 | |||
| (PID) Process: | (2232) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\General |
| Operation: | write | Name: | LastFolder |
Value: C:\Users\admin\AppData\Local\Temp | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2232 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2232.15807\CdiResource\dialog\image\blank.png | image | |
MD5:0CE7026FC86A80DCBBAAF22382B66D91 | SHA256:20E711326CBBA640E40CA63D8A9151B485929814309BD6CAC9189D9CE26492C1 | |||
| 2232 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2232.15807\CdiResource\dialog\image\file.png | image | |
MD5:4D329376128328C069C43D21AEF2C792 | SHA256:6C0363C3B862A56B8DFD7BBDCD7759E6A4B4843FC1627873B97309939EDDF7C4 | |||
| 2232 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2232.15807\CdiResource\dialog\image\labelEnable.png | image | |
MD5:5BF6DFA9A281A52B31CE5190B3CE1D9C | SHA256:985F656FB6EB0ECFBBED6242F6FDC693C15630A7259BD0787326C2B9F28575A1 | |||
| 2232 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2232.15807\CdiResource\dialog\image\buttonHover.png | image | |
MD5:05CBBDA99D889FB8A6C6595F8B954FC2 | SHA256:FD7B2E419D2954AD2345122BFFCF11F5D4DD3DFDBEE4955E015D60628B0B4896 | |||
| 2232 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2232.15807\CdiResource\dialog\image\labelDisable.png | image | |
MD5:142D80B0425A1CED30898DCD4C376645 | SHA256:5471871A0542D270CFF2AD7992C39CE3EF8839C65BC1A0B13F22856D9DE49D03 | |||
| 2232 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2232.15807\CdiResource\dialog\flot\excanvas.min.js | text | |
MD5:08182065D2093C978A9BFA16B0829173 | SHA256:5F94B032A110504B7B261EAF71392FA3E8D82CDC6455C0CBA5C9F03CD34ED122 | |||
| 2232 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2232.15807\CdiResource\dialog\image\GraphReset.png | image | |
MD5:6A14DF27BA1CCE174D896B3F0196C653 | SHA256:BCCB279A905906F1B4DF54541E410A11E31CACCE3158342FF8219395418F209B | |||
| 2232 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2232.15807\CdiResource\dialog\image\background.png | image | |
MD5:1CFDA5CA069D29FEF4EE61F8A119249A | SHA256:0201EE1A84E8CE5D1CDEA826C3B793FD26106517DE12D07765E66C97A884B3E3 | |||
| 2232 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2232.15807\CdiResource\dialog\Graph.css | text | |
MD5:92D30E5381370231C4888B57D29D27C6 | SHA256:5D6EDF2D14B16C1C47E85609346874593B4E989214AFDBFEF4D849A30F9F719F | |||
| 2232 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2232.15807\CdiResource\AlertMail.exe | executable | |
MD5:46A29DAB77E0C3FF5B7E0EA2F1E5B7C8 | SHA256:A9B8A51A99B4C63038C948C5BDA54750EA85E0D9B4DB7D78FB4DAC9D8854FEEA | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2972 | iexplore.exe | GET | 301 | 151.101.0.64:80 | http://www.piriform.com/ccleaner/update?a=0&v=5.35.6210&l=1033&o=6.1W3&t=4&au=1 | US | — | — | whitelisted |
592 | CCleaner.exe | GET | 301 | 151.101.0.64:80 | http://www.piriform.com/auto?a=0&p=cc&v=5.35.6210&l=1033&lk=&mk=IJR6-W5SV-5KYR-QBZD-6BY4-RN5Z-WAV9-RVK2-VJCA&o=6.1W3&au=1&mx=97B7721C4994E2556FF6A439510F665DB45337A341A47E15F4997584423BF714&gu=00000000-0000-4000-8000-d6f7f2be5127 | US | — | — | whitelisted |
2972 | iexplore.exe | GET | 200 | 13.107.4.50:80 | http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab | US | compressed | 56.1 Kb | whitelisted |
3676 | firefox.exe | POST | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/ | US | der | 471 b | whitelisted |
3676 | firefox.exe | POST | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/ | US | der | 471 b | whitelisted |
3676 | firefox.exe | POST | 200 | 172.217.16.131:80 | http://ocsp.pki.goog/GTSGIAG3 | US | der | 471 b | whitelisted |
3676 | firefox.exe | GET | 302 | 18.208.31.59:80 | http://download.mozilla.org/?product=firefox-66.0.5-complete&os=win&lang=en-US | US | html | 129 b | whitelisted |
3676 | firefox.exe | POST | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/ | US | der | 471 b | whitelisted |
3676 | firefox.exe | POST | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/ | US | der | 471 b | whitelisted |
3204 | iexplore.exe | GET | 200 | 204.79.197.200:80 | http://www.bing.com/favicon.ico | US | image | 237 b | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
592 | CCleaner.exe | 151.101.0.64:443 | www.piriform.com | Fastly | US | whitelisted |
592 | CCleaner.exe | 151.101.0.64:80 | www.piriform.com | Fastly | US | whitelisted |
592 | CCleaner.exe | 151.101.2.202:443 | www.ccleaner.com | Fastly | US | suspicious |
— | — | 151.101.0.64:443 | www.piriform.com | Fastly | US | whitelisted |
2972 | iexplore.exe | 151.101.0.64:80 | www.piriform.com | Fastly | US | whitelisted |
3204 | iexplore.exe | 204.79.197.200:80 | www.bing.com | Microsoft Corporation | US | whitelisted |
2972 | iexplore.exe | 151.101.2.202:443 | www.ccleaner.com | Fastly | US | suspicious |
2972 | iexplore.exe | 151.139.237.73:443 | s1.pir.fm | netDNA | US | unknown |
2972 | iexplore.exe | 159.122.87.153:443 | dev.visualwebsiteoptimizer.com | SoftLayer Technologies Inc. | DE | unknown |
2972 | iexplore.exe | 151.139.237.73:80 | s1.pir.fm | netDNA | US | unknown |
Domain | IP | Reputation |
|---|---|---|
www.piriform.com |
| whitelisted |
www.ccleaner.com |
| whitelisted |
www.bing.com |
| whitelisted |
www.google.com |
| malicious |
s7.addthis.com |
| whitelisted |
fonts.googleapis.com |
| whitelisted |
fonts.gstatic.com |
| whitelisted |
www.googletagmanager.com |
| whitelisted |
dev.visualwebsiteoptimizer.com |
| whitelisted |
s1.pir.fm |
| suspicious |