File name: | Windows 7 Loader eXtreme Edition 3.503.rar |
Full analysis: | https://app.any.run/tasks/243422d7-d6af-49bc-a1cc-8f8d8127fbbc |
Verdict: | Malicious activity |
Analysis date: | June 30, 2019, 11:16:01 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | application/x-rar |
File info: | RAR archive data, v4, os: Win32 |
MD5: | 1DB7B1E08E6330F3315423D1BA1053E3 |
SHA1: | B4D38CDE891D7102E9524348EC90D9EA8DEFBD6F |
SHA256: | 9A409819D774CEDD115653F30B0E03AD1A0C6B21B735B87444DAEC60467B2267 |
SSDEEP: | 196608:8CoWay7gLVsP/TR/EbjtggkygIuc021vPcaupQGJ+5ENTo:J7SkTR/kttkyZX1vPcaalQ+to |
.rar | | | RAR compressed archive (v-4.x) (58.3) |
---|---|---|
.rar | | | RAR compressed archive (gen) (41.6) |
CompressedSize: | 4327 |
---|---|
UncompressedSize: | 22004 |
OperatingSystem: | Win32 |
ModifyDate: | 2010:05:21 02:00:23 |
PackingMethod: | Normal |
ArchivedFileName: | Windows 7 Loader eXtreme Edition 3.503\FAQ\FAQ(Afrikaans).txt |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
2748 | "C:\Users\admin\Desktop\Windows 7 Loader eXtreme Edition 3.503\w7lxe.exe" | C:\Users\admin\Desktop\Windows 7 Loader eXtreme Edition 3.503\w7lxe.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: Universal Windows Activation Tool Exit code: 3221226540 Version: 3.5.0.3 Modules
| |||||||||||||||
3320 | "C:\Users\admin\Desktop\Windows 7 Loader eXtreme Edition 3.503\w7lxe.exe" | C:\Users\admin\Desktop\Windows 7 Loader eXtreme Edition 3.503\w7lxe.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: Universal Windows Activation Tool Exit code: 0 Version: 3.5.0.3 Modules
| |||||||||||||||
3792 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Windows 7 Loader eXtreme Edition 3.503.rar" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.60.0 Modules
|
(PID) Process: | (3792) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
Operation: | write | Name: | ShellExtBMP |
Value: | |||
(PID) Process: | (3792) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
Operation: | write | Name: | ShellExtIcon |
Value: | |||
(PID) Process: | (3792) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\62\52C64B7E |
Operation: | write | Name: | LanguageList |
Value: en-US | |||
(PID) Process: | (3792) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\Windows 7 Loader eXtreme Edition 3.503.rar | |||
(PID) Process: | (3792) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | name |
Value: 120 | |||
(PID) Process: | (3792) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | size |
Value: 80 | |||
(PID) Process: | (3792) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | type |
Value: 120 | |||
(PID) Process: | (3792) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | mtime |
Value: 100 | |||
(PID) Process: | (3792) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin |
Operation: | write | Name: | Placement |
Value: 2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000 | |||
(PID) Process: | (3792) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\General |
Operation: | write | Name: | LastFolder |
Value: C:\Users\admin\AppData\Local\Temp |
PID | Process | Filename | Type | |
---|---|---|---|---|
3792 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3792.40288\Windows 7 Loader eXtreme Edition 3.503\FAQ\FAQ(Filipino).txt | binary | |
MD5:30616F1EB6E0EC4498A8843A1A07BD5A | SHA256:E6184371A84FFAF6817158A9D81721503952AC0F9C3AC185E86810269D171936 | |||
3792 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3792.40288\Windows 7 Loader eXtreme Edition 3.503\FAQ\FAQ(Arabic).txt | binary | |
MD5:6FB0CAFB2697EA0C12C4087B302587FC | SHA256:0296A6631F9822B163B0EF1B0180FF970D34D15D9A1E5B8039DCB58D9CB45640 | |||
3792 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3792.40288\Windows 7 Loader eXtreme Edition 3.503\FAQ\FAQ(Chinese (Simplified)).txt | binary | |
MD5:2EC9A2D00D7C81565F83FA294DD69717 | SHA256:8FD7172CB87910D91E40AF088B5782B8A85D13AB63CB3B41731EC11AA594A157 | |||
3792 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3792.40288\Windows 7 Loader eXtreme Edition 3.503\FAQ\FAQ(Catalan).txt | binary | |
MD5:43F9A7A8DD1DA5543D8B2E66CADBEC19 | SHA256:6D17A7E1E48F63716AE82E2380702BA16942C158E3EF0B38D7E7E14A41AAE2A7 | |||
3792 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3792.40288\Windows 7 Loader eXtreme Edition 3.503\FAQ\FAQ(Albanian).txt | binary | |
MD5:8290251B08DD45FE6869D638549C86B4 | SHA256:5A7106D77660FAA536FB0C4E7173C59FC53BF916992973044875431002859B58 | |||
3792 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3792.40288\Windows 7 Loader eXtreme Edition 3.503\FAQ\FAQ(Bulgarian).txt | text | |
MD5:22D3BBB32B8C4D91256932F9B4184D35 | SHA256:3418CE316CB4B21FEB495E6F2DD612D6AEEB1EC8F1A77BEA068914E23817FFD2 | |||
3792 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3792.40288\Windows 7 Loader eXtreme Edition 3.503\FAQ\FAQ(Dutch).txt | binary | |
MD5:4674A9C8D7CFADE0DA8E0F41735CC267 | SHA256:FE58E4A8033CEF600DCC6ED88BFBFE27D8FD7646D926EA9A7D191CB5BED627AA | |||
3792 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3792.40288\Windows 7 Loader eXtreme Edition 3.503\FAQ\FAQ(Czech).txt | binary | |
MD5:22D4742A6298FC3EA2D7C60FE7443826 | SHA256:3120C74CC07C1F13BC6E172E39D56471A1B4D62809D020487845ECA423883134 | |||
3792 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3792.40288\Windows 7 Loader eXtreme Edition 3.503\FAQ\FAQ(Croatian).txt | binary | |
MD5:354E9281DA201B493150890682934C74 | SHA256:1C629ED0B868D686EF45AC126A3FE9764A33117150BA7917485ADE1CE5475C1B | |||
3792 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3792.40288\Windows 7 Loader eXtreme Edition 3.503\FAQ\FAQ(Chinese (Traditional)).txt | binary | |
MD5:DF93B5E4B384B500A3A6FCFD729E6644 | SHA256:AEF10393DA1C51ECF792AE1A50C4C47EAD81057D5E3B11E1FA40F1B867D2C567 |