| File name: | Italiano.reg |
| Full analysis: | https://app.any.run/tasks/b7d4cfe2-42f7-4174-aedd-bd19db388133 |
| Verdict: | Suspicious activity |
| Analysis date: | April 17, 2019, 11:32:09 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | text/plain |
| File info: | UTF-8 Unicode text, with CRLF, LF line terminators |
| MD5: | 12A90099EEA0FECCD2837083DD30F546 |
| SHA1: | 057B0FD025DFE1957DAF8322E9299318F8837697 |
| SHA256: | 97764898F88F10917CE1FF3B0A7090C21674F9CBDA73C1C39B3A220F652B50C8 |
| SSDEEP: | 48:9JY0qHQoRER7W7cI4tkP7e0k9yEb7+G6QlQcqeEVe9hchoUo:PNqwoRER7W714tI7e0k9Tb7+QQcqemep |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 332 | "C:\Windows\System32\control.exe" "C:\Windows\system32\timedate.cpl", | C:\Windows\System32\control.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Control Panel Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 488 | "C:\Windows\regedit.exe" "C:\Users\admin\Desktop\Italiano.reg" | C:\Windows\regedit.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Registry Editor Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 856 | "C:\Windows\regedit.exe" | C:\Windows\regedit.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Registry Editor Exit code: 3221226540 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1412 | "C:\Windows\System32\control.exe" "C:\Windows\system32\timedate.cpl", | C:\Windows\System32\control.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Control Panel Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2076 | "C:\Windows\regedit.exe" "C:\Users\admin\Desktop\Italiano.reg" | C:\Windows\regedit.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Registry Editor Exit code: 3221226540 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2584 | "C:\Windows\system32\rundll32.exe" Shell32.dll,Control_RunDLL "C:\Windows\system32\timedate.cpl", | C:\Windows\system32\rundll32.exe | — | control.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows host process (Rundll32) Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3152 | "C:\Windows\system32\rundll32.exe" Shell32.dll,Control_RunDLL "C:\Windows\system32\timedate.cpl", | C:\Windows\system32\rundll32.exe | — | control.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows host process (Rundll32) Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3376 | "regedit.exe" "C:\Users\admin\Desktop\Italiano.reg" | C:\Windows\regedit.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Registry Editor Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3904 | "regedit.exe" "C:\Users\admin\Desktop\Italiano.reg" | C:\Windows\regedit.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Registry Editor Exit code: 3221226540 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3916 | "C:\Windows\regedit.exe" | C:\Windows\regedit.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Registry Editor Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (488) regedit.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\TimeZoneInformation |
| Operation: | write | Name: | Bias |
Value: 4294967236 | |||
| (PID) Process: | (488) regedit.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\TimeZoneInformation |
| Operation: | write | Name: | DaylightBias |
Value: 4294967236 | |||
| (PID) Process: | (488) regedit.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\TimeZoneInformation |
| Operation: | write | Name: | DaylightName |
Value: @tzres.dll,-321 | |||
| (PID) Process: | (488) regedit.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\TimeZoneInformation |
| Operation: | write | Name: | DaylightStart |
Value: 00000300050002000000000000000000 | |||
| (PID) Process: | (488) regedit.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\TimeZoneInformation |
| Operation: | write | Name: | StandardBias |
Value: 0 | |||
| (PID) Process: | (488) regedit.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\TimeZoneInformation |
| Operation: | write | Name: | StandardName |
Value: @tzres.dll,-322 | |||
| (PID) Process: | (488) regedit.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\TimeZoneInformation |
| Operation: | write | Name: | StandardStart |
Value: 00000A00050003000000000000000000 | |||
| (PID) Process: | (488) regedit.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\TimeZoneInformation |
| Operation: | write | Name: | TimeZoneKeyName |
Value: W. Europe Standard Time | |||
| (PID) Process: | (488) regedit.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\TimeZoneInformation |
| Operation: | write | Name: | DynamicDaylightTimeDisabled |
Value: 0 | |||
| (PID) Process: | (488) regedit.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\TimeZoneInformation |
| Operation: | write | Name: | ActiveTimeBias |
Value: 4294967176 | |||