File name:

InnoExtractor Plus 6.2.1.418 Multilingual[pesktop.com].rar

Full analysis: https://app.any.run/tasks/e3f6d932-49dd-45d1-9285-e146d19b57bb
Verdict: Malicious activity
Analysis date: June 26, 2023, 18:09:07
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
opendir
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

0C701F40AA59338A6DB030F51E846A64

SHA1:

825704328EF5407B63509ACE7E817852D6277FEB

SHA256:

90AFA21E971137FD4E0B532654B6DE4A75712CF9DC75EEEBFC0C995D22E848C4

SSDEEP:

49152:ASzDoSKaUW34G9gm7Pwp3/XWwaOnwuFaAmNq1XJwbp2y7M3VeMey0jvIiFOqsXj:vzcSvzLkpvoEJa7A4p2yg3Vz09cqsXj

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Keygen.exe (PID: 3844)
      • InnoExtractorPlus-generic-patch.exe (PID: 3928)
      • InnoExtractorPlus-generic-patch.exe (PID: 3456)
      • Keygen.exe (PID: 3720)
  • SUSPICIOUS

    • Reads the Internet Settings

      • Keygen.exe (PID: 3844)
    • Executable content was dropped or overwritten

      • InnoExtractorPlus-generic-patch.exe (PID: 3456)
  • INFO

    • Manual execution by a user

      • Keygen.exe (PID: 3844)
      • notepad.exe (PID: 1048)
      • InnoExtractorPlus-generic-patch.exe (PID: 3928)
      • InnoExtractorPlus-generic-patch.exe (PID: 3456)
      • WinRAR.exe (PID: 2496)
      • Keygen.exe (PID: 3720)
      • WinRAR.exe (PID: 2284)
      • WinRAR.exe (PID: 2512)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2284)
      • WinRAR.exe (PID: 2512)
    • Reads the computer name

      • Keygen.exe (PID: 3844)
    • Application launched itself

      • iexplore.exe (PID: 1756)
    • Checks supported languages

      • Keygen.exe (PID: 3844)
      • InnoExtractorPlus-generic-patch.exe (PID: 3456)
      • Keygen.exe (PID: 3720)
    • Create files in a temporary directory

      • InnoExtractorPlus-generic-patch.exe (PID: 3456)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
56
Monitored processes
11
Malicious processes
3
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe no specs winrar.exe winrar.exe keygen.exe no specs notepad.exe no specs iexplore.exe iexplore.exe innoextractorplus-generic-patch.exe no specs innoextractorplus-generic-patch.exe winrar.exe no specs keygen.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1048"C:\Windows\system32\NOTEPAD.EXE" C:\Users\admin\Desktop\isgxrlHKoqaWqxCv-5666FD04.txtC:\Windows\System32\notepad.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\notepad.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1756"C:\Program Files\Internet Explorer\iexplore.exe" http://www.havysoft.cl/C:\Program Files\Internet Explorer\iexplore.exe
Keygen.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\version.dll
c:\windows\system32\rpcrt4.dll
2284"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\InnoExtractor Plus 6.2.1.418 Multilingual\Keygen.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
c:\windows\system32\user32.dll
c:\windows\system32\comdlg32.dll
2456"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:1756 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2496"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\InnoExtractor Plus 6.2.1.418 Multilingual\IE_Install.zip"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\user32.dll
c:\program files\winrar\winrar.exe
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
2512"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\InnoExtractor Plus 6.2.1.418 Multilingual\Patch.rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
3456"C:\Users\admin\Desktop\InnoExtractorPlus-generic-patch.exe" C:\Users\admin\Desktop\InnoExtractorPlus-generic-patch.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\desktop\innoextractorplus-generic-patch.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\users\admin\appdata\local\temp\dup2patcher.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\comdlg32.dll
3524"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\InnoExtractor Plus 6.2.1.418 Multilingual[pesktop.com].rar"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
3720"C:\Users\admin\Desktop\Keygen.exe" C:\Users\admin\Desktop\Keygen.exeexplorer.exe
User:
admin
Company:
RadiXX11
Integrity Level:
MEDIUM
Description:
Havysoft Products Keygen
Exit code:
0
Version:
1.2.0.0
Modules
Images
c:\windows\system32\ntdll.dll
c:\users\admin\desktop\keygen.exe
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\gdi32.dll
3844"C:\Users\admin\Desktop\Keygen.exe" C:\Users\admin\Desktop\Keygen.exeexplorer.exe
User:
admin
Company:
RadiXX11
Integrity Level:
MEDIUM
Description:
Havysoft Products Keygen
Exit code:
0
Version:
1.2.0.0
Modules
Images
c:\users\admin\desktop\keygen.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\sechost.dll
Total events
8 130
Read events
7 984
Write events
146
Delete events
0

Modification events

(PID) Process:(3524) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16D\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3524) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(3524) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(3524) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(3524) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3524) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3524) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3524) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3524) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface
Operation:writeName:ShowPassword
Value:
0
(PID) Process:(3524) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000
Executable files
3
Suspicious files
9
Text files
3
Unknown types
0

Dropped files

PID
Process
Filename
Type
2284WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2284.47472\Keygen.exeexecutable
MD5:700724CE9B29832DB92E227FD6F15D9B
SHA256:324EB90E7F9A5676DCBE5F1D8005825025F75FA4FDEE82AFB5D28B0B237D8C26
2512WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2512.48088\InnoExtractorPlus-generic-patch.exeexecutable
MD5:03B913112ABD33C8856663F6A8A21126
SHA256:2623F1C539CF2B8D9C13F63DD43A87833D5D705D1D6EB996E62890ED6DC9549E
3524WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb3524.44788\InnoExtractor Plus 6.2.1.418 Multilingual\Visit www.pesktop.com.urlbinary
MD5:EC78904D048134A63C41A2DD63A5B201
SHA256:42E647086D0D6D89C283279AB7974260ED242B0B925D683C8856AF8C004EA430
3524WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb3524.44788\InnoExtractor Plus 6.2.1.418 Multilingual\IE_Install.zipcompressed
MD5:C81515D0A6FBBA68B452C931D10CF9F8
SHA256:E1277ADE19BEA5145167E0168BE86C5166B3763FE696FCA43D6327E03D7F553E
1756iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\urlblockindex[1].binbinary
MD5:FA518E3DFAE8CA3A0E495460FD60C791
SHA256:775853600060162C4B4E5F883F9FD5A278E61C471B3EE1826396B6D129499AA7
2456iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\innoextractor[1].pngimage
MD5:10E2D4368BC72C5D0CBB5EF344BA6BDC
SHA256:01E873D0ED5D6EE8942903A491ECDDE568B66F9293F8CD515E534BE3D5026D35
2456iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\CNA59KCT.htmhtml
MD5:CEB23D191370F15FFCB277A470633B12
SHA256:3998E4AFDC6C4979592B3035C763D045578DA034E4752D61AB0F88D77C2A3C71
3524WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb3524.44788\InnoExtractor Plus 6.2.1.418 Multilingual\Patch.rarcompressed
MD5:4FA9784205D09CAE06C517B9A0946B50
SHA256:4D5B14A1A2AC16BB06FEB1EFED30B65B9EFCBC08D8169BBA921C53D36C3E9CAF
1756iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\6DB145CFEEC544B1582FED1ADA3370DDbinary
MD5:B13DB2DC56460B7CF0BE2F7557A22C49
SHA256:B5D1ADDB57F42327407FE8BB6C43C443AECB85EB94F74DEEBE284AEE34CA5DA7
3524WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb3524.44788\InnoExtractor Plus 6.2.1.418 Multilingual\Keygen.zipcompressed
MD5:6BAFC2EDB42B1C29E6B4F96D840BBD09
SHA256:0B73AC010428DCB2842F72BE091C0192B1DE12C5A85ED09E8413CAC4CF7C333C
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
64
DNS requests
14
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1756
iexplore.exe
GET
200
192.229.221.95:80
http://crl3.digicert.com/DigiCertGlobalRootCA.crl
US
der
779 b
whitelisted
2456
iexplore.exe
GET
200
198.23.57.183:80
http://www.havysoft.cl/css/estilo.css
US
text
1.38 Kb
suspicious
2456
iexplore.exe
GET
200
198.23.57.183:80
http://www.havysoft.cl/
US
html
1.73 Kb
suspicious
2456
iexplore.exe
GET
200
198.23.57.183:80
http://www.havysoft.cl/logos/innoextractor.png
US
image
21.2 Kb
suspicious
1756
iexplore.exe
GET
200
192.229.221.95:80
http://crl4.digicert.com/DigiCertGlobalRootCA.crl
US
der
779 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
2748
svchost.exe
239.255.255.250:1900
whitelisted
1076
svchost.exe
224.0.0.252:5355
unknown
2456
iexplore.exe
198.23.57.183:80
www.havysoft.cl
STEADFAST
US
malicious
1756
iexplore.exe
104.126.37.130:443
www.bing.com
Akamai International B.V.
DE
suspicious
2456
iexplore.exe
157.240.253.1:443
connect.facebook.net
FACEBOOK
DE
whitelisted
2456
iexplore.exe
151.101.2.133:443
www.paypalobjects.com
FASTLY
US
malicious
1756
iexplore.exe
152.199.19.161:443
r20swj13mr.microsoft.com
EDGECAST
US
whitelisted
2456
iexplore.exe
151.101.66.133:443
www.paypalobjects.com
FASTLY
US
suspicious

DNS requests

Domain
IP
Reputation
www.havysoft.cl
  • 198.23.57.183
suspicious
api.bing.com
  • 13.107.5.80
whitelisted
www.bing.com
  • 104.126.37.130
  • 104.126.37.131
  • 104.126.37.162
  • 104.126.37.161
  • 104.126.37.153
  • 104.126.37.160
  • 104.126.37.170
  • 104.126.37.123
  • 104.126.37.137
whitelisted
connect.facebook.net
  • 157.240.253.1
whitelisted
www.paypalobjects.com
  • 151.101.2.133
  • 151.101.66.133
  • 151.101.130.133
  • 151.101.194.133
whitelisted
r20swj13mr.microsoft.com
  • 152.199.19.161
whitelisted
iecvlist.microsoft.com
  • 152.199.19.161
whitelisted
ctldl.windowsupdate.com
  • 95.140.236.128
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
crl3.digicert.com
  • 192.229.221.95
whitelisted

Threats

No threats detected
No debug info