| File name: | Partition_Bad_Disk_3.4.1___Crack.rar |
| Full analysis: | https://app.any.run/tasks/402299ac-1000-4b8d-89c4-cfda15b0aef3 |
| Verdict: | Malicious activity |
| Analysis date: | June 08, 2018, 08:39:00 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-rar |
| File info: | RAR archive data, v4, os: Win32 |
| MD5: | 1094C856D615013E410E41D3FCB0B80B |
| SHA1: | 7D52EE4B07E12F0E1F1231CB5E72AF5ECDD69AE0 |
| SHA256: | 9065327AB4BA3165878BF060547B9A6A6AA1F7A6282944E08BEACB751A671B8C |
| SSDEEP: | 196608:192/EkpyKVJ6MEmJcDvD0/+XdZdt8O7liQlTMXvzSMk2VAwINxDLPP:1U/EgH/J2Q/+tyYiQavzHZ6xP |
| .rar | | | RAR compressed archive (v-4.x) (58.3) |
|---|---|---|
| .rar | | | RAR compressed archive (gen) (41.6) |
| CompressedSize: | 187 |
|---|---|
| UncompressedSize: | 109 |
| OperatingSystem: | Win32 |
| ModifyDate: | 2016:09:29 17:53:18 |
| PackingMethod: | Best Compression |
| ArchivedFileName: | Partition Bad Disk 3.4.1 + Crack\Crack\CracksUP.com.url |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 332 | "C:\Users\admin\AppData\Local\Temp\7zOC3CF8D74\pbd-setup.exe" /SPAWNWND=$601FA /NOTIFYWND=$601F4 | C:\Users\admin\AppData\Local\Temp\7zOC3CF8D74\pbd-setup.exe | pbd-setup.tmp | ||||||||||||
User: admin Company: Goodlucksoft Integrity Level: HIGH Description: Partition Bad Disk Setup Exit code: 0 Version: Modules
| |||||||||||||||
| 1732 | "C:\Users\admin\AppData\Local\Temp\7zOC3CF8D74\pbd-setup.exe" | C:\Users\admin\AppData\Local\Temp\7zOC3CF8D74\pbd-setup.exe | 7zFM.exe | ||||||||||||
User: admin Company: Goodlucksoft Integrity Level: MEDIUM Description: Partition Bad Disk Setup Exit code: 0 Version: Modules
| |||||||||||||||
| 2260 | "C:\Program Files\Partition Bad Disk\pbd.exe" | C:\Program Files\Partition Bad Disk\pbd.exe | — | pbd-setup.tmp | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 2816 | "C:\Users\admin\AppData\Local\Temp\is-ENTLM.tmp\pbd-setup.tmp" /SL5="$701FC,9777337,54272,C:\Users\admin\AppData\Local\Temp\7zOC3CF8D74\pbd-setup.exe" /SPAWNWND=$601FA /NOTIFYWND=$601F4 | C:\Users\admin\AppData\Local\Temp\is-ENTLM.tmp\pbd-setup.tmp | pbd-setup.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: Setup/Uninstall Exit code: 0 Version: 51.52.0.0 Modules
| |||||||||||||||
| 2968 | "C:\Users\admin\Desktop\pbd.exe" | C:\Users\admin\Desktop\pbd.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 3221225781 Modules
| |||||||||||||||
| 3132 | "C:\Program Files\7-Zip\7zFM.exe" "C:\Users\admin\AppData\Local\Temp\Partition_Bad_Disk_3.4.1___Crack.rar" | C:\Program Files\7-Zip\7zFM.exe | explorer.exe | ||||||||||||
User: admin Company: Igor Pavlov Integrity Level: MEDIUM Description: 7-Zip File Manager Exit code: 0 Version: 16.04 Modules
| |||||||||||||||
| 3588 | "C:\Users\admin\AppData\Local\Temp\is-Q8SGE.tmp\pbd-setup.tmp" /SL5="$601F4,9777337,54272,C:\Users\admin\AppData\Local\Temp\7zOC3CF8D74\pbd-setup.exe" | C:\Users\admin\AppData\Local\Temp\is-Q8SGE.tmp\pbd-setup.tmp | — | pbd-setup.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: Setup/Uninstall Exit code: 0 Version: 51.52.0.0 Modules
| |||||||||||||||
| 3732 | "C:\Users\admin\AppData\Local\Temp\7zOC3C771D4\pbd.exe" | C:\Users\admin\AppData\Local\Temp\7zOC3C771D4\pbd.exe | — | 7zFM.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 3221225781 Modules
| |||||||||||||||
| (PID) Process: | (3132) 7zFM.exe | Key: | HKEY_CURRENT_USER\Software\7-Zip\FM\Columns |
| Operation: | write | Name: | 7-Zip.Rar |
Value: 0100000004000000010000000400000001000000A00000000700000001000000640000000800000001000000640000000C00000001000000640000000A00000001000000640000000B00000001000000640000000900000001000000640000000F00000001000000640000000D00000001000000640000000E00000001000000640000001000000001000000640000001100000001000000640000001300000001000000640000001700000001000000640000001600000001000000640000002100000001000000640000001F0000000100000064000000200000000100000064000000 | |||
| (PID) Process: | (3132) 7zFM.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
| (PID) Process: | (3132) 7zFM.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 1 | |||
| (PID) Process: | (2816) pbd-setup.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | Owner |
Value: 000B0000E404223F04FFD301 | |||
| (PID) Process: | (2816) pbd-setup.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | SessionHash |
Value: 07E0E7CF4849763E5454E195A108EF0946E21B325B62E4155F94B26A15E15DAE | |||
| (PID) Process: | (2816) pbd-setup.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | Sequence |
Value: 1 | |||
| (PID) Process: | (2816) pbd-setup.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | RegFiles0000 |
Value: C:\Program Files\Partition Bad Disk\pbd.exe | |||
| (PID) Process: | (2816) pbd-setup.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | RegFilesHash |
Value: 401A08BF1088F420C44516AB2D9976E3B5A057930C2F91A080D9F3AA14DAE5CD | |||
| (PID) Process: | (2816) pbd-setup.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2B12BB43-0437-42B0-9409-01CC516016E7}_is1 |
| Operation: | write | Name: | Inno Setup: Setup Version |
Value: 5.5.1 (a) | |||
| (PID) Process: | (2816) pbd-setup.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2B12BB43-0437-42B0-9409-01CC516016E7}_is1 |
| Operation: | write | Name: | Inno Setup: App Path |
Value: C:\Program Files\Partition Bad Disk | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2816 | pbd-setup.tmp | C:\Program Files\Partition Bad Disk\is-SL95C.tmp | — | |
MD5:— | SHA256:— | |||
| 2816 | pbd-setup.tmp | C:\Program Files\Partition Bad Disk\is-9DMG8.tmp | — | |
MD5:— | SHA256:— | |||
| 2816 | pbd-setup.tmp | C:\Program Files\Partition Bad Disk\is-8QG50.tmp | — | |
MD5:— | SHA256:— | |||
| 2816 | pbd-setup.tmp | C:\Program Files\Partition Bad Disk\is-SUB3T.tmp | — | |
MD5:— | SHA256:— | |||
| 2816 | pbd-setup.tmp | C:\Program Files\Partition Bad Disk\is-R3VIO.tmp | — | |
MD5:— | SHA256:— | |||
| 2816 | pbd-setup.tmp | C:\Program Files\Partition Bad Disk\is-NOI27.tmp | — | |
MD5:— | SHA256:— | |||
| 2816 | pbd-setup.tmp | C:\Program Files\Partition Bad Disk\is-96J9O.tmp | — | |
MD5:— | SHA256:— | |||
| 2816 | pbd-setup.tmp | C:\Program Files\Partition Bad Disk\is-EIPIK.tmp | — | |
MD5:— | SHA256:— | |||
| 2816 | pbd-setup.tmp | C:\Program Files\Partition Bad Disk\is-7P1F9.tmp | — | |
MD5:— | SHA256:— | |||
| 2816 | pbd-setup.tmp | C:\Program Files\Partition Bad Disk\is-PURFS.tmp | — | |
MD5:— | SHA256:— | |||