| File name: | original IDM trial reset.rar |
| Full analysis: | https://app.any.run/tasks/f30d007d-e461-4b88-ab8c-bd8fb489b02c |
| Verdict: | Malicious activity |
| Analysis date: | December 06, 2019, 19:41:32 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-rar |
| File info: | RAR archive data, v4, os: Win32 |
| MD5: | 8399A47BAE7C384A00207D67198ED574 |
| SHA1: | C21C8F0ACF56C86D22CF9945B29F77B79BD64CC8 |
| SHA256: | 9880EDA1C30A68C5226E0002332877B2CC5B2ADEECF2EECA73E6D240C6C1610F |
| SSDEEP: | 24576:5YSN3kdGOgebtVwwVOez3Fw3KgViYLLoHLTzJ9BJdj8w4avHrnz+zu:fFg2Ct1c+FsiYLLsL541EHrz+K |
| .rar | | | RAR compressed archive (v-4.x) (58.3) |
|---|---|---|
| .rar | | | RAR compressed archive (gen) (41.6) |
| CompressedSize: | 1030246 |
|---|---|
| UncompressedSize: | 1179136 |
| OperatingSystem: | Win32 |
| ModifyDate: | 2015:04:11 22:52:01 |
| PackingMethod: | Normal |
| ArchivedFileName: | idm_trial_reset.exe |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 272 | "C:\Users\admin\AppData\Local\Temp\SetACLx32.exe" -on HKCU\Software\Classes\Wow6432Node\CLSID\{6DDF00DB-1234-46EC-8356-27E7B2051192} -ot reg -actn setowner -ownr "n:S-1-1-0" -silent | C:\Users\admin\AppData\Local\Temp\SetACLx32.exe | — | idm_trial_reset.exe | |||||||||||
User: admin Company: Helge Klein Integrity Level: HIGH Description: SetACL 3 Exit code: 5 Version: 3.0.6.0 Modules
| |||||||||||||||
| 284 | "C:\Users\admin\AppData\Local\Temp\SetACLx32.exe" -on HKCU\Software\Classes\Wow6432Node\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC} -ot reg -actn ace -ace "n:everyone;p:full" -actn setprot -op "dacl:p_nc;sacl:p_nc" -silent | C:\Users\admin\AppData\Local\Temp\SetACLx32.exe | — | idm_trial_reset.exe | |||||||||||
User: admin Company: Helge Klein Integrity Level: HIGH Description: SetACL 3 Exit code: 5 Version: 3.0.6.0 Modules
| |||||||||||||||
| 460 | "C:\Users\admin\AppData\Local\Temp\SetACLx32.exe" -on HKCU\Software\Classes\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C} -ot reg -actn ace -ace "n:everyone;p:full" -actn setprot -op "dacl:p_nc;sacl:p_nc" -silent | C:\Users\admin\AppData\Local\Temp\SetACLx32.exe | — | idm_trial_reset.exe | |||||||||||
User: admin Company: Helge Klein Integrity Level: HIGH Description: SetACL 3 Exit code: 5 Version: 3.0.6.0 Modules
| |||||||||||||||
| 532 | "C:\Users\admin\AppData\Local\Temp\SetACLx32.exe" -on HKCU\Software\Classes\Wow6432Node\CLSID\{07999AC3-058B-40BF-984F-69EB1E554CA7} -ot reg -actn ace -ace "n:everyone;p:full" -actn setprot -op "dacl:p_nc;sacl:p_nc" -silent | C:\Users\admin\AppData\Local\Temp\SetACLx32.exe | — | idm_trial_reset.exe | |||||||||||
User: admin Company: Helge Klein Integrity Level: HIGH Description: SetACL 3 Exit code: 5 Version: 3.0.6.0 Modules
| |||||||||||||||
| 640 | "C:\Users\admin\AppData\Local\Temp\SetACLx32.exe" -on HKLM\Software\Classes\Wow6432Node\CLSID\{6DDF00DB-1234-46EC-8356-27E7B2051192} -ot reg -actn setowner -ownr "n:S-1-1-0" -silent | C:\Users\admin\AppData\Local\Temp\SetACLx32.exe | — | idm_trial_reset.exe | |||||||||||
User: admin Company: Helge Klein Integrity Level: HIGH Description: SetACL 3 Exit code: 5 Version: 3.0.6.0 Modules
| |||||||||||||||
| 656 | "C:\Users\admin\AppData\Local\Temp\SetACLx32.exe" -on HKLM\Software\Classes\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C} -ot reg -actn ace -ace "n:everyone;p:full" -actn setprot -op "dacl:p_nc;sacl:p_nc" -silent | C:\Users\admin\AppData\Local\Temp\SetACLx32.exe | — | idm_trial_reset.exe | |||||||||||
User: admin Company: Helge Klein Integrity Level: HIGH Description: SetACL 3 Exit code: 5 Version: 3.0.6.0 Modules
| |||||||||||||||
| 656 | "C:\Users\admin\AppData\Local\Temp\SetACLx32.exe" -on HKCU\Software\Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC} -ot reg -actn ace -ace "n:everyone;p:read" -actn setprot -op "dacl:p_nc;sacl:p_nc" -silent | C:\Users\admin\AppData\Local\Temp\SetACLx32.exe | — | idm_trial_reset.exe | |||||||||||
User: admin Company: Helge Klein Integrity Level: HIGH Description: SetACL 3 Exit code: 5 Version: 3.0.6.0 | |||||||||||||||
| 788 | "C:\Users\admin\AppData\Local\Temp\SetACLx32.exe" -on HKCU\Software\Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC} -ot reg -actn setowner -ownr "n:S-1-1-0" -silent | C:\Users\admin\AppData\Local\Temp\SetACLx32.exe | — | idm_trial_reset.exe | |||||||||||
User: admin Company: Helge Klein Integrity Level: HIGH Description: SetACL 3 Exit code: 5 Version: 3.0.6.0 Modules
| |||||||||||||||
| 884 | "C:\Users\admin\AppData\Local\Temp\SetACLx32.exe" -on HKLM\Software\Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC} -ot reg -actn ace -ace "n:everyone;p:read" -actn setprot -op "dacl:p_nc;sacl:p_nc" -silent | C:\Users\admin\AppData\Local\Temp\SetACLx32.exe | — | idm_trial_reset.exe | |||||||||||
User: admin Company: Helge Klein Integrity Level: HIGH Description: SetACL 3 Exit code: 5 Version: 3.0.6.0 | |||||||||||||||
| 952 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa2168.31472\idm_trial_reset.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa2168.31472\idm_trial_reset.exe | WinRAR.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| (PID) Process: | (2168) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (2168) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (2168) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2168) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\original IDM trial reset.rar | |||
| (PID) Process: | (2168) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (2168) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (2168) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (2168) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (2168) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
| (PID) Process: | (2168) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 952 | idm_trial_reset.exe | C:\Users\admin\AppData\Local\Temp\autC212.tmp | — | |
MD5:— | SHA256:— | |||
| 952 | idm_trial_reset.exe | C:\Users\admin\AppData\Local\Temp\autC213.tmp | — | |
MD5:— | SHA256:— | |||
| 952 | idm_trial_reset.exe | C:\Users\admin\AppData\Local\Temp\autC214.tmp | — | |
MD5:— | SHA256:— | |||
| 952 | idm_trial_reset.exe | C:\Users\admin\AppData\Local\Temp\autC215.tmp | — | |
MD5:— | SHA256:— | |||
| 952 | idm_trial_reset.exe | C:\Users\admin\AppData\Local\Temp\autC235.tmp | — | |
MD5:— | SHA256:— | |||
| 2168 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2168.31472\source\idm_trial_reset.au3 | text | |
MD5:— | SHA256:— | |||
| 2168 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2168.31472\source\idm_trial_reset.ico | image | |
MD5:— | SHA256:— | |||
| 2168 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2168.31472\source\core.au3 | text | |
MD5:— | SHA256:— | |||
| 2168 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2168.31472\source\SetACLx64.exe | executable | |
MD5:3E350EB5DF15C06DEC400A39DD1C6F29 | SHA256:427FF43693CB3CA2812C4754F607F107A6B2D3F5A8B313ADDEE57D89982DF419 | |||
| 2168 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2168.31472\idm_trial_reset.exe | executable | |
MD5:072760D80286205652AF3041D68D7033 | SHA256:56FF6937AC04352EEB83B3AE75B9A1D2EFB3177F7B460C148864A3236B22EFB2 | |||