File name: | original IDM trial reset.rar |
Full analysis: | https://app.any.run/tasks/f30d007d-e461-4b88-ab8c-bd8fb489b02c |
Verdict: | Malicious activity |
Analysis date: | December 06, 2019, 19:41:32 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | application/x-rar |
File info: | RAR archive data, v4, os: Win32 |
MD5: | 8399A47BAE7C384A00207D67198ED574 |
SHA1: | C21C8F0ACF56C86D22CF9945B29F77B79BD64CC8 |
SHA256: | 9880EDA1C30A68C5226E0002332877B2CC5B2ADEECF2EECA73E6D240C6C1610F |
SSDEEP: | 24576:5YSN3kdGOgebtVwwVOez3Fw3KgViYLLoHLTzJ9BJdj8w4avHrnz+zu:fFg2Ct1c+FsiYLLsL541EHrz+K |
.rar | | | RAR compressed archive (v-4.x) (58.3) |
---|---|---|
.rar | | | RAR compressed archive (gen) (41.6) |
ArchivedFileName: | idm_trial_reset.exe |
---|---|
PackingMethod: | Normal |
ModifyDate: | 2015:04:11 22:52:01 |
OperatingSystem: | Win32 |
UncompressedSize: | 1179136 |
CompressedSize: | 1030246 |
PID | CMD | Path | Indicators | Parent process |
---|---|---|---|---|
2168 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\original IDM trial reset.rar" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | |
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Version: 5.60.0 | ||||
2116 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa2168.31472\idm_trial_reset.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa2168.31472\idm_trial_reset.exe | — | WinRAR.exe |
User: admin Integrity Level: MEDIUM Exit code: 3221226540 | ||||
952 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa2168.31472\idm_trial_reset.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa2168.31472\idm_trial_reset.exe | WinRAR.exe | |
User: admin Integrity Level: HIGH | ||||
2188 | C:\Windows\system32\cmd.exe /c reg query hkcr\clsid /s > C:\Users\admin\AppData\Local\Temp\reg_query.tmp | C:\Windows\system32\cmd.exe | — | idm_trial_reset.exe |
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) | ||||
2748 | reg query hkcr\clsid /s | C:\Windows\system32\reg.exe | — | cmd.exe |
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Registry Console Tool Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
1784 | "C:\Windows\system32\cmd.exe" /c findstr /N /I cDTvBFquXk0 C:\Users\admin\AppData\Local\Temp\reg_query.tmp | C:\Windows\system32\cmd.exe | — | idm_trial_reset.exe |
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 1 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) | ||||
1948 | findstr /N /I cDTvBFquXk0 C:\Users\admin\AppData\Local\Temp\reg_query.tmp | C:\Windows\system32\findstr.exe | — | cmd.exe |
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Find String (QGREP) Utility Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
3860 | "C:\Windows\system32\cmd.exe" /c findstr /N . C:\Users\admin\AppData\Local\Temp\reg_query.tmp | findstr /b -1: | C:\Windows\system32\cmd.exe | — | idm_trial_reset.exe |
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 2 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) | ||||
2928 | findstr /N . C:\Users\admin\AppData\Local\Temp\reg_query.tmp | C:\Windows\system32\findstr.exe | — | cmd.exe |
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Find String (QGREP) Utility Exit code: 2 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
1608 | findstr /b -1: | C:\Windows\system32\findstr.exe | — | cmd.exe |
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Find String (QGREP) Utility Exit code: 2 Version: 6.1.7600.16385 (win7_rtm.090713-1255) |
(PID) Process: | (2168) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
Operation: | write | Name: | ShellExtBMP |
Value: | |||
(PID) Process: | (2168) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
Operation: | write | Name: | ShellExtIcon |
Value: | |||
(PID) Process: | (2168) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E |
Operation: | write | Name: | LanguageList |
Value: en-US | |||
(PID) Process: | (2168) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\original IDM trial reset.rar | |||
(PID) Process: | (2168) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | name |
Value: 120 | |||
(PID) Process: | (2168) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | size |
Value: 80 | |||
(PID) Process: | (2168) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | type |
Value: 120 | |||
(PID) Process: | (2168) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | mtime |
Value: 100 | |||
(PID) Process: | (2168) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
(PID) Process: | (2168) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | AutoDetect |
Value: 1 |
PID | Process | Filename | Type | |
---|---|---|---|---|
952 | idm_trial_reset.exe | C:\Users\admin\AppData\Local\Temp\autC212.tmp | — | |
MD5:— | SHA256:— | |||
952 | idm_trial_reset.exe | C:\Users\admin\AppData\Local\Temp\autC213.tmp | — | |
MD5:— | SHA256:— | |||
952 | idm_trial_reset.exe | C:\Users\admin\AppData\Local\Temp\autC214.tmp | — | |
MD5:— | SHA256:— | |||
952 | idm_trial_reset.exe | C:\Users\admin\AppData\Local\Temp\autC215.tmp | — | |
MD5:— | SHA256:— | |||
952 | idm_trial_reset.exe | C:\Users\admin\AppData\Local\Temp\autC235.tmp | — | |
MD5:— | SHA256:— | |||
2168 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2168.31472\source\core.au3 | text | |
MD5:04C13FC88BEBBAC1B5C9CE6E69A9183C | SHA256:C99E715763DAD1342EA5400E7C9D1D4F884400BCD46AF8CE92AEBBEE10889EE3 | |||
2168 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2168.31472\source\idm_trial_reset.au3 | text | |
MD5:276DA5472764D9BC8D8264BF523A571A | SHA256:C164E02D1D5408D89017B643DD0A504AA5C99ABBE774DFB4EE550DDF7F179165 | |||
2168 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2168.31472\source\idm_trial_reset.ico | image | |
MD5:C0CA78AE849DE5C3CA09F297DFCC9C81 | SHA256:8B166B17B3DE50EA0853727E5DFE5CDB9BEDC0E3C2EF440C165327F0FE2E3575 | |||
2168 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2168.31472\source\idm_trial.reg | text | |
MD5:237962E36948F3D0C9EC42EFA289AC52 | SHA256:40AD93CF424EEE41A0877B11ACB92F7F12D58AB3AA6FA6D64D92CFBBE11695A2 | |||
2168 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2168.31472\source\SetACLx64.exe | executable | |
MD5:3E350EB5DF15C06DEC400A39DD1C6F29 | SHA256:427FF43693CB3CA2812C4754F607F107A6B2D3F5A8B313ADDEE57D89982DF419 |