File name:

InnoExtractor Plus 6.2.1.418 Multilingual[pesktop.com].rar

Full analysis: https://app.any.run/tasks/e3f6d932-49dd-45d1-9285-e146d19b57bb
Verdict: Malicious activity
Analysis date: June 26, 2023, 18:09:07
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
opendir
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

0C701F40AA59338A6DB030F51E846A64

SHA1:

825704328EF5407B63509ACE7E817852D6277FEB

SHA256:

90AFA21E971137FD4E0B532654B6DE4A75712CF9DC75EEEBFC0C995D22E848C4

SSDEEP:

49152:ASzDoSKaUW34G9gm7Pwp3/XWwaOnwuFaAmNq1XJwbp2y7M3VeMey0jvIiFOqsXj:vzcSvzLkpvoEJa7A4p2yg3Vz09cqsXj

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Keygen.exe (PID: 3844)
      • InnoExtractorPlus-generic-patch.exe (PID: 3456)
      • InnoExtractorPlus-generic-patch.exe (PID: 3928)
      • Keygen.exe (PID: 3720)
  • SUSPICIOUS

    • Reads the Internet Settings

      • Keygen.exe (PID: 3844)
    • Executable content was dropped or overwritten

      • InnoExtractorPlus-generic-patch.exe (PID: 3456)
  • INFO

    • Manual execution by a user

      • WinRAR.exe (PID: 2512)
      • WinRAR.exe (PID: 2284)
      • Keygen.exe (PID: 3844)
      • InnoExtractorPlus-generic-patch.exe (PID: 3928)
      • notepad.exe (PID: 1048)
      • InnoExtractorPlus-generic-patch.exe (PID: 3456)
      • WinRAR.exe (PID: 2496)
      • Keygen.exe (PID: 3720)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2284)
      • WinRAR.exe (PID: 2512)
    • Checks supported languages

      • Keygen.exe (PID: 3844)
      • InnoExtractorPlus-generic-patch.exe (PID: 3456)
      • Keygen.exe (PID: 3720)
    • Reads the computer name

      • Keygen.exe (PID: 3844)
    • Create files in a temporary directory

      • InnoExtractorPlus-generic-patch.exe (PID: 3456)
    • Application launched itself

      • iexplore.exe (PID: 1756)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
56
Monitored processes
11
Malicious processes
3
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe no specs winrar.exe winrar.exe keygen.exe no specs notepad.exe no specs iexplore.exe iexplore.exe innoextractorplus-generic-patch.exe no specs innoextractorplus-generic-patch.exe winrar.exe no specs keygen.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1048"C:\Windows\system32\NOTEPAD.EXE" C:\Users\admin\Desktop\isgxrlHKoqaWqxCv-5666FD04.txtC:\Windows\System32\notepad.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\notepad.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1756"C:\Program Files\Internet Explorer\iexplore.exe" http://www.havysoft.cl/C:\Program Files\Internet Explorer\iexplore.exe
Keygen.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\version.dll
c:\windows\system32\rpcrt4.dll
2284"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\InnoExtractor Plus 6.2.1.418 Multilingual\Keygen.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
c:\windows\system32\user32.dll
c:\windows\system32\comdlg32.dll
2456"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:1756 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2496"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\InnoExtractor Plus 6.2.1.418 Multilingual\IE_Install.zip"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\user32.dll
c:\program files\winrar\winrar.exe
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
2512"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\InnoExtractor Plus 6.2.1.418 Multilingual\Patch.rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
3456"C:\Users\admin\Desktop\InnoExtractorPlus-generic-patch.exe" C:\Users\admin\Desktop\InnoExtractorPlus-generic-patch.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\desktop\innoextractorplus-generic-patch.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\users\admin\appdata\local\temp\dup2patcher.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\comdlg32.dll
3524"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\InnoExtractor Plus 6.2.1.418 Multilingual[pesktop.com].rar"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
3720"C:\Users\admin\Desktop\Keygen.exe" C:\Users\admin\Desktop\Keygen.exeexplorer.exe
User:
admin
Company:
RadiXX11
Integrity Level:
MEDIUM
Description:
Havysoft Products Keygen
Exit code:
0
Version:
1.2.0.0
Modules
Images
c:\windows\system32\ntdll.dll
c:\users\admin\desktop\keygen.exe
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\gdi32.dll
3844"C:\Users\admin\Desktop\Keygen.exe" C:\Users\admin\Desktop\Keygen.exeexplorer.exe
User:
admin
Company:
RadiXX11
Integrity Level:
MEDIUM
Description:
Havysoft Products Keygen
Exit code:
0
Version:
1.2.0.0
Modules
Images
c:\users\admin\desktop\keygen.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\sechost.dll
Total events
8 130
Read events
7 984
Write events
146
Delete events
0

Modification events

(PID) Process:(3524) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16D\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3524) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(3524) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(3524) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(3524) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3524) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3524) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3524) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3524) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface
Operation:writeName:ShowPassword
Value:
0
(PID) Process:(3524) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000
Executable files
3
Suspicious files
9
Text files
3
Unknown types
0

Dropped files

PID
Process
Filename
Type
3524WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb3524.44788\InnoExtractor Plus 6.2.1.418 Multilingual\Patch.rarcompressed
MD5:4FA9784205D09CAE06C517B9A0946B50
SHA256:4D5B14A1A2AC16BB06FEB1EFED30B65B9EFCBC08D8169BBA921C53D36C3E9CAF
3524WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb3524.44788\InnoExtractor Plus 6.2.1.418 Multilingual\Visit www.pesktop.com.urlbinary
MD5:EC78904D048134A63C41A2DD63A5B201
SHA256:42E647086D0D6D89C283279AB7974260ED242B0B925D683C8856AF8C004EA430
2284WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2284.47472\Keygen.exeexecutable
MD5:700724CE9B29832DB92E227FD6F15D9B
SHA256:324EB90E7F9A5676DCBE5F1D8005825025F75FA4FDEE82AFB5D28B0B237D8C26
3524WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb3524.44788\InnoExtractor Plus 6.2.1.418 Multilingual\Keygen.zipcompressed
MD5:6BAFC2EDB42B1C29E6B4F96D840BBD09
SHA256:0B73AC010428DCB2842F72BE091C0192B1DE12C5A85ED09E8413CAC4CF7C333C
3524WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb3524.44788\InnoExtractor Plus 6.2.1.418 Multilingual\IE_Install.zipcompressed
MD5:C81515D0A6FBBA68B452C931D10CF9F8
SHA256:E1277ADE19BEA5145167E0168BE86C5166B3763FE696FCA43D6327E03D7F553E
1756iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\urlblockindex[1].binbinary
MD5:FA518E3DFAE8CA3A0E495460FD60C791
SHA256:775853600060162C4B4E5F883F9FD5A278E61C471B3EE1826396B6D129499AA7
2512WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2512.48088\InnoExtractorPlus-generic-patch.exeexecutable
MD5:03B913112ABD33C8856663F6A8A21126
SHA256:2623F1C539CF2B8D9C13F63DD43A87833D5D705D1D6EB996E62890ED6DC9549E
3456InnoExtractorPlus-generic-patch.exeC:\Users\admin\AppData\Local\Temp\dup2patcher.dllexecutable
MD5:8B3604936FB0F49C19033DB50C3AE15B
SHA256:DBDE07CF5AF2DFB0ED9D6C0144FF329B23BB5731AE5C856F242BD989FE1D690F
2456iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\CNA59KCT.htmhtml
MD5:CEB23D191370F15FFCB277A470633B12
SHA256:3998E4AFDC6C4979592B3035C763D045578DA034E4752D61AB0F88D77C2A3C71
2456iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5IWPIAR9\estilo[1].csstext
MD5:C234094962C39C51DA8F27208C56102B
SHA256:D43B098FE786B3B3CF41FA548E313316E6CCB1B5CA425441777533811DE0A4B7
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
64
DNS requests
14
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2456
iexplore.exe
GET
200
198.23.57.183:80
http://www.havysoft.cl/
US
html
1.73 Kb
suspicious
1756
iexplore.exe
GET
200
192.229.221.95:80
http://crl4.digicert.com/DigiCertGlobalRootCA.crl
US
der
779 b
whitelisted
2456
iexplore.exe
GET
200
198.23.57.183:80
http://www.havysoft.cl/logos/innoextractor.png
US
image
21.2 Kb
suspicious
1756
iexplore.exe
GET
200
192.229.221.95:80
http://crl3.digicert.com/DigiCertGlobalRootCA.crl
US
der
779 b
whitelisted
2456
iexplore.exe
GET
200
198.23.57.183:80
http://www.havysoft.cl/css/estilo.css
US
text
1.38 Kb
suspicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1756
iexplore.exe
95.140.236.128:80
ctldl.windowsupdate.com
LLNW
US
malicious
2456
iexplore.exe
151.101.66.133:443
www.paypalobjects.com
FASTLY
US
suspicious
1756
iexplore.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1076
svchost.exe
224.0.0.252:5355
unknown
2748
svchost.exe
239.255.255.250:1900
whitelisted
2456
iexplore.exe
198.23.57.183:80
www.havysoft.cl
STEADFAST
US
malicious
1756
iexplore.exe
104.126.37.130:443
www.bing.com
Akamai International B.V.
DE
suspicious
2456
iexplore.exe
151.101.2.133:443
www.paypalobjects.com
FASTLY
US
malicious

DNS requests

Domain
IP
Reputation
www.havysoft.cl
  • 198.23.57.183
suspicious
api.bing.com
  • 13.107.5.80
whitelisted
www.bing.com
  • 104.126.37.130
  • 104.126.37.131
  • 104.126.37.162
  • 104.126.37.161
  • 104.126.37.153
  • 104.126.37.160
  • 104.126.37.170
  • 104.126.37.123
  • 104.126.37.137
whitelisted
connect.facebook.net
  • 157.240.253.1
whitelisted
www.paypalobjects.com
  • 151.101.2.133
  • 151.101.66.133
  • 151.101.130.133
  • 151.101.194.133
whitelisted
r20swj13mr.microsoft.com
  • 152.199.19.161
whitelisted
iecvlist.microsoft.com
  • 152.199.19.161
whitelisted
ctldl.windowsupdate.com
  • 95.140.236.128
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
crl3.digicert.com
  • 192.229.221.95
whitelisted

Threats

No threats detected
No debug info