File name:

HD_Tune_Pro_5.70_Free.rar

Full analysis: https://app.any.run/tasks/085bebaf-952d-4c38-97d2-6eb474330022
Verdict: Malicious activity
Analysis date: June 20, 2020, 22:43:52
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v4, os: Win32
MD5:

4CC3516365EFE9B8C686FD68F14F6112

SHA1:

834F79DC60FB706A4E70F43B8F7D087A4406B9CA

SHA256:

92A82B10DB3952048D4ED4567D681CE490D23D566E8C2A98B3C10539D0734F72

SSDEEP:

49152:wljSHV9nKo3O7otgaapXM6Tcskj3OZszX9q6QALk9lfxot4Suf0T/:wlmH7Ko3O7Day8l+ZYq6QAGli+B8T/

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • HD Tune Pro 5.70.exe (PID: 2776)
      • HD Tune Pro 5.70.exe (PID: 2688)
      • HDTunePro.exe (PID: 3060)
      • HDTunePro.exe (PID: 3928)
      • HDTunePro.exe (PID: 2696)
    • Actions looks like stealing of personal data

      • WinRAR.exe (PID: 3004)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • HD Tune Pro 5.70.exe (PID: 2776)
      • WinRAR.exe (PID: 3004)
      • HD Tune Pro 5.70.tmp (PID: 3068)
      • HD Tune Pro 5.70.exe (PID: 2688)
    • Low-level read access rights to disk partition

      • HDTunePro.exe (PID: 3060)
      • HDTunePro.exe (PID: 2696)
  • INFO

    • Application was dropped or rewritten from another process

      • HD Tune Pro 5.70.tmp (PID: 3208)
      • HD Tune Pro 5.70.tmp (PID: 3068)
    • Loads dropped or rewritten executable

      • HD Tune Pro 5.70.tmp (PID: 3068)
    • Creates files in the program directory

      • HD Tune Pro 5.70.tmp (PID: 3068)
    • Creates a software uninstall entry

      • HD Tune Pro 5.70.tmp (PID: 3068)
    • Manual execution by user

      • HDTunePro.exe (PID: 3928)
      • HDTunePro.exe (PID: 2696)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v-4.x) (58.3)
.rar | RAR compressed archive (gen) (41.6)

EXIF

ZIP

CompressedSize: 2226908
UncompressedSize: 2248569
OperatingSystem: Win32
ModifyDate: 2017:08:04 15:04:15
PackingMethod: Best Compression
ArchivedFileName: HD Tune Pro 5.70.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
47
Monitored processes
8
Malicious processes
1
Suspicious processes
2

Behavior graph

Click at the process to see the details
drop and start start drop and start drop and start drop and start winrar.exe hd tune pro 5.70.exe hd tune pro 5.70.tmp no specs hd tune pro 5.70.exe hd tune pro 5.70.tmp hdtunepro.exe no specs hdtunepro.exe no specs hdtunepro.exe

Process information

PID
CMD
Path
Indicators
Parent process
2688"C:\Users\admin\AppData\Local\Temp\Rar$EXa3004.39246\HD Tune Pro 5.70.exe" /SPAWNWND=$20180 /NOTIFYWND=$20160 C:\Users\admin\AppData\Local\Temp\Rar$EXa3004.39246\HD Tune Pro 5.70.exe
HD Tune Pro 5.70.tmp
User:
admin
Company:
EFD Software
Integrity Level:
HIGH
Description:
HD Tune Pro Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3004.39246\hd tune pro 5.70.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
2696"C:\Program Files\HD Tune Pro\HDTunePro.exe" C:\Program Files\HD Tune Pro\HDTunePro.exe
explorer.exe
User:
admin
Company:
EFD Software
Integrity Level:
HIGH
Description:
HD Tune Pro
Exit code:
0
Version:
5, 6, 0, 0
Modules
Images
c:\program files\hd tune pro\hdtunepro.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\advapi32.dll
2776"C:\Users\admin\AppData\Local\Temp\Rar$EXa3004.39246\HD Tune Pro 5.70.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3004.39246\HD Tune Pro 5.70.exe
WinRAR.exe
User:
admin
Company:
EFD Software
Integrity Level:
MEDIUM
Description:
HD Tune Pro Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3004.39246\hd tune pro 5.70.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
3004"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\HD_Tune_Pro_5.70_Free.rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3060"C:\Program Files\HD Tune Pro\HDTunePro.exe"C:\Program Files\HD Tune Pro\HDTunePro.exeHD Tune Pro 5.70.tmp
User:
admin
Company:
EFD Software
Integrity Level:
HIGH
Description:
HD Tune Pro
Exit code:
2
Version:
5, 6, 0, 0
Modules
Images
c:\program files\hd tune pro\hdtunepro.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\advapi32.dll
3068"C:\Users\admin\AppData\Local\Temp\is-T770G.tmp\HD Tune Pro 5.70.tmp" /SL5="$3017E,2004805,54272,C:\Users\admin\AppData\Local\Temp\Rar$EXa3004.39246\HD Tune Pro 5.70.exe" /SPAWNWND=$20180 /NOTIFYWND=$20160 C:\Users\admin\AppData\Local\Temp\is-T770G.tmp\HD Tune Pro 5.70.tmp
HD Tune Pro 5.70.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.52.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-t770g.tmp\hd tune pro 5.70.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
3208"C:\Users\admin\AppData\Local\Temp\is-CL843.tmp\HD Tune Pro 5.70.tmp" /SL5="$20160,2004805,54272,C:\Users\admin\AppData\Local\Temp\Rar$EXa3004.39246\HD Tune Pro 5.70.exe" C:\Users\admin\AppData\Local\Temp\is-CL843.tmp\HD Tune Pro 5.70.tmpHD Tune Pro 5.70.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.52.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-cl843.tmp\hd tune pro 5.70.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
3928"C:\Program Files\HD Tune Pro\HDTunePro.exe" C:\Program Files\HD Tune Pro\HDTunePro.exeexplorer.exe
User:
admin
Company:
EFD Software
Integrity Level:
MEDIUM
Description:
HD Tune Pro
Exit code:
3221226540
Version:
5, 6, 0, 0
Modules
Images
c:\program files\hd tune pro\hdtunepro.exe
c:\systemroot\system32\ntdll.dll
Total events
1 140
Read events
1 015
Write events
125
Delete events
0

Modification events

(PID) Process:(3004) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3004) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3004) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3004) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12F\52C64B7E
Operation:writeName:@C:\Windows\system32\NetworkExplorer.dll,-1
Value:
Network
(PID) Process:(3004) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\HD_Tune_Pro_5.70_Free.rar
(PID) Process:(3004) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3004) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3004) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3004) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3004) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
Executable files
8
Suspicious files
2
Text files
2
Unknown types
8

Dropped files

PID
Process
Filename
Type
3068HD Tune Pro 5.70.tmpC:\Program Files\HD Tune Pro\is-B8E0G.tmp
MD5:
SHA256:
3068HD Tune Pro 5.70.tmpC:\Program Files\HD Tune Pro\is-3P77O.tmp
MD5:
SHA256:
3068HD Tune Pro 5.70.tmpC:\Program Files\HD Tune Pro\is-7MM96.tmp
MD5:
SHA256:
3068HD Tune Pro 5.70.tmpC:\Program Files\HD Tune Pro\is-BUU2M.tmp
MD5:
SHA256:
3068HD Tune Pro 5.70.tmpC:\Program Files\HD Tune Pro\is-7ARTC.tmp
MD5:
SHA256:
3068HD Tune Pro 5.70.tmpC:\Program Files\HD Tune Pro\is-KNBB2.tmp
MD5:
SHA256:
3004WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3004.39246\HD Tune Pro 5.70.exeexecutable
MD5:
SHA256:
2776HD Tune Pro 5.70.exeC:\Users\admin\AppData\Local\Temp\is-CL843.tmp\HD Tune Pro 5.70.tmpexecutable
MD5:C080F73B1BDDE0853CB0258D9A02B0EC
SHA256:A0CFBC8DA39AD4A4D21C61D73873D225FFA5D7650FAE5938AB643F719D5F7363
3068HD Tune Pro 5.70.tmpC:\Program Files\HD Tune Pro\unins000.exeexecutable
MD5:63ABC2E67A080888AEA74E47C07FA345
SHA256:3532B10C54CDFA5499CAD3EF427FD74C7967444924396F9F521B827A0769A328
3068HD Tune Pro 5.70.tmpC:\ProgramData\Microsoft\Windows\Start Menu\Programs\HD Tune Pro\HD Tune Pro Drive Status.lnklnk
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info