| File name: | Windows 7 Loader eXtreme Edition 3.503.rar |
| Full analysis: | https://app.any.run/tasks/243422d7-d6af-49bc-a1cc-8f8d8127fbbc |
| Verdict: | Malicious activity |
| Analysis date: | June 30, 2019, 11:16:01 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-rar |
| File info: | RAR archive data, v4, os: Win32 |
| MD5: | 1DB7B1E08E6330F3315423D1BA1053E3 |
| SHA1: | B4D38CDE891D7102E9524348EC90D9EA8DEFBD6F |
| SHA256: | 9A409819D774CEDD115653F30B0E03AD1A0C6B21B735B87444DAEC60467B2267 |
| SSDEEP: | 196608:8CoWay7gLVsP/TR/EbjtggkygIuc021vPcaupQGJ+5ENTo:J7SkTR/kttkyZX1vPcaalQ+to |
| .rar | | | RAR compressed archive (v-4.x) (58.3) |
|---|---|---|
| .rar | | | RAR compressed archive (gen) (41.6) |
| CompressedSize: | 4327 |
|---|---|
| UncompressedSize: | 22004 |
| OperatingSystem: | Win32 |
| ModifyDate: | 2010:05:21 02:00:23 |
| PackingMethod: | Normal |
| ArchivedFileName: | Windows 7 Loader eXtreme Edition 3.503\FAQ\FAQ(Afrikaans).txt |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2748 | "C:\Users\admin\Desktop\Windows 7 Loader eXtreme Edition 3.503\w7lxe.exe" | C:\Users\admin\Desktop\Windows 7 Loader eXtreme Edition 3.503\w7lxe.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: Universal Windows Activation Tool Exit code: 3221226540 Version: 3.5.0.3 Modules
| |||||||||||||||
| 3320 | "C:\Users\admin\Desktop\Windows 7 Loader eXtreme Edition 3.503\w7lxe.exe" | C:\Users\admin\Desktop\Windows 7 Loader eXtreme Edition 3.503\w7lxe.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: Universal Windows Activation Tool Exit code: 0 Version: 3.5.0.3 Modules
| |||||||||||||||
| 3792 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Windows 7 Loader eXtreme Edition 3.503.rar" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.60.0 Modules
| |||||||||||||||
| (PID) Process: | (3792) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (3792) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (3792) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\62\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3792) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\Windows 7 Loader eXtreme Edition 3.503.rar | |||
| (PID) Process: | (3792) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (3792) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (3792) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (3792) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (3792) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin |
| Operation: | write | Name: | Placement |
Value: 2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000 | |||
| (PID) Process: | (3792) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\General |
| Operation: | write | Name: | LastFolder |
Value: C:\Users\admin\AppData\Local\Temp | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3792 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3792.40288\Windows 7 Loader eXtreme Edition 3.503\FAQ\FAQ(Chinese (Simplified)).txt | binary | |
MD5:2EC9A2D00D7C81565F83FA294DD69717 | SHA256:8FD7172CB87910D91E40AF088B5782B8A85D13AB63CB3B41731EC11AA594A157 | |||
| 3792 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3792.40288\Windows 7 Loader eXtreme Edition 3.503\FAQ\FAQ(Bulgarian).txt | text | |
MD5:22D3BBB32B8C4D91256932F9B4184D35 | SHA256:3418CE316CB4B21FEB495E6F2DD612D6AEEB1EC8F1A77BEA068914E23817FFD2 | |||
| 3792 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3792.40288\Windows 7 Loader eXtreme Edition 3.503\FAQ\FAQ(Arabic).txt | binary | |
MD5:6FB0CAFB2697EA0C12C4087B302587FC | SHA256:0296A6631F9822B163B0EF1B0180FF970D34D15D9A1E5B8039DCB58D9CB45640 | |||
| 3792 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3792.40288\Windows 7 Loader eXtreme Edition 3.503\FAQ\FAQ(Czech).txt | binary | |
MD5:22D4742A6298FC3EA2D7C60FE7443826 | SHA256:3120C74CC07C1F13BC6E172E39D56471A1B4D62809D020487845ECA423883134 | |||
| 3792 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3792.40288\Windows 7 Loader eXtreme Edition 3.503\FAQ\FAQ(Catalan).txt | binary | |
MD5:43F9A7A8DD1DA5543D8B2E66CADBEC19 | SHA256:6D17A7E1E48F63716AE82E2380702BA16942C158E3EF0B38D7E7E14A41AAE2A7 | |||
| 3792 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3792.40288\Windows 7 Loader eXtreme Edition 3.503\FAQ\FAQ(Afrikaans).txt | binary | |
MD5:46BE00B8239196105C09F0219F5CDCAF | SHA256:34384F1BE3267A46B6247405F80EE6CBECDC0D90C7FDBB723A8FB1ABBA12D223 | |||
| 3792 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3792.40288\Windows 7 Loader eXtreme Edition 3.503\FAQ\FAQ(Chinese (Traditional)).txt | binary | |
MD5:DF93B5E4B384B500A3A6FCFD729E6644 | SHA256:AEF10393DA1C51ECF792AE1A50C4C47EAD81057D5E3B11E1FA40F1B867D2C567 | |||
| 3792 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3792.40288\Windows 7 Loader eXtreme Edition 3.503\FAQ\FAQ(Belarusian).txt | binary | |
MD5:23931109ABCFFBCAF1F9EDB9A6B0A771 | SHA256:D3D494D19C96030044AAFF5BCAE383C3D304C5ACB643E0B6810849CD05D75F01 | |||
| 3792 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3792.40288\Windows 7 Loader eXtreme Edition 3.503\FAQ\FAQ(Finnish).txt | binary | |
MD5:AB46BC7BA8FC98FF3FA9FF4C96BB0A34 | SHA256:2F373BAFC1B70F9F069DC5D545FDC92C3E2FDE3E533E74BB43B757570E09CEE6 | |||
| 3792 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3792.40288\Windows 7 Loader eXtreme Edition 3.503\FAQ\FAQ(Filipino).txt | binary | |
MD5:30616F1EB6E0EC4498A8843A1A07BD5A | SHA256:E6184371A84FFAF6817158A9D81721503952AC0F9C3AC185E86810269D171936 | |||