| File name: | free4pc.org_IDM _ 6.38 Build 2____ _.rar |
| Full analysis: | https://app.any.run/tasks/51ecfedd-7c61-49fc-8da0-85598e7c88cd |
| Verdict: | Malicious activity |
| Threats: | Remote access trojans (RATs) are a type of malware that enables attackers to establish complete to partial control over infected computers. Such malicious programs often have a modular design, offering a wide range of functionalities for conducting illicit activities on compromised systems. Some of the most common features of RATs include access to the users’ data, webcam, and keystrokes. This malware is often distributed through phishing emails and links. |
| Analysis date: | August 26, 2020, 04:56:43 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-rar |
| File info: | RAR archive data, v5 |
| MD5: | E43F1BB7120FE6C4F57005A2F4474D6F |
| SHA1: | 4FF8421BBDFFF2DD61FA290BB0185B6A59FC408C |
| SHA256: | 9A67AE0F49040DF71A38C03846A7247E4D7EDB945754D55A7240874189C89F05 |
| SSDEEP: | 196608:ePBnC9zfqmfNxoqdAPsulI3wxSJDLMVPHr84PEJjd41f3BF2gNtWavC3Oqcll4aQ:jfqCom+FIgSMVvo4PEJUvBlNZYlcll2 |
| .rar | | | RAR compressed archive (v5.0) (61.5) |
|---|---|---|
| .rar | | | RAR compressed archive (gen) (38.4) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 700 | taskkill.exe /IM IDMan.exe /F | C:\Windows\system32\taskkill.exe | — | IDM_6.3x_Crack_v17.8.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Terminates Processes Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1432 | "C:\Program Files\Internet Download Manager\Uninstall.exe" -instdriv | C:\Program Files\Internet Download Manager\Uninstall.exe | — | IDMan.exe | |||||||||||
User: admin Company: Tonec Inc. Integrity Level: HIGH Description: Internet Download Manager installer Exit code: 1 Version: 6, 37, 15, 1 Modules
| |||||||||||||||
| 1520 | "C:\Windows\system32\runonce.exe" -r | C:\Windows\system32\runonce.exe | — | rundll32.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Run Once Wrapper Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1704 | "C:\Users\admin\AppData\Local\Temp\UnSigner.exe" -f -b "C:\Program Files\Internet Download Manager\IDMan.exe~~" | C:\Users\admin\AppData\Local\Temp\UnSigner.exe | — | IDM_6.3x_Crack_v17.8.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 1 Modules
| |||||||||||||||
| 1760 | C:\Windows\system32\net1 start IDMWFP | C:\Windows\system32\net1.exe | — | net.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Net Command Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 2068 | wscript.exe "C:\Users\admin\AppData\Local\Temp\IDM_BAK.vbs" /idmdir:"C:\Program Files\Internet Download Manager\" | C:\Windows\system32\wscript.exe | IDM_6.3x_Crack_v17.8.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft ® Windows Based Script Host Exit code: 0 Version: 5.8.7600.16385 Modules
| |||||||||||||||
| 2068 | "C:\Windows\System32\net.exe" start IDMWFP | C:\Windows\System32\net.exe | — | Uninstall.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Net Command Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2220 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3316.3.322127494\694654513" -childID 1 -isForBrowser -prefsHandle 1684 -prefMapHandle 836 -prefsLen 1 -prefMapSize 191824 -parentBuildID 20190717172542 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" - 3316 "\\.\pipe\gecko-crash-server-pipe.3316" 1772 tab | C:\Program Files\Mozilla Firefox\firefox.exe | firefox.exe | ||||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 68.0.1 Modules
| |||||||||||||||
| 2264 | reg.exe import C:\Users\admin\AppData\Local\Temp\IDMRegClean.reg | C:\Windows\system32\reg.exe | — | IDM_6.3x_Crack_v17.8.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Registry Console Tool Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2304 | "C:\Program Files\Internet Download Manager\IEMonitor.exe" | C:\Program Files\Internet Download Manager\IEMonitor.exe | — | IDMan.exe | |||||||||||
User: admin Company: Tonec Inc. Integrity Level: MEDIUM Description: Internet Download Manager agent for click monitoring in IE-based browsers Exit code: 0 Version: 6, 37, 8, 1 Modules
| |||||||||||||||
| (PID) Process: | (2964) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (2964) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (2964) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\139\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2964) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\139\52C64B7E |
| Operation: | write | Name: | @C:\Windows\system32\NetworkExplorer.dll,-1 |
Value: Network | |||
| (PID) Process: | (2964) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\free4pc.org_IDM _ 6.38 Build 2____ _.rar | |||
| (PID) Process: | (2964) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (2964) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (2964) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (2964) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (2964) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface |
| Operation: | write | Name: | ShowPassword |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3500 | IDM1.tmp | C:\Users\admin\AppData\Local\Temp\~DFD8BEF3526B4360C1.TMP | — | |
MD5:— | SHA256:— | |||
| 2964 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb2964.16297\free4pc.org_IDM Crack 6.38 Build 2_Patch_Serial Key\Cracked PC Software's,Serial Keys Direct Links.url | text | |
MD5:— | SHA256:— | |||
| 2964 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb2964.16297\free4pc.org_IDM Crack 6.38 Build 2_Patch_Serial Key\idman638build2f.exe | executable | |
MD5:— | SHA256:— | |||
| 3968 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3968.21431\IDM_6.3x_Crack_v17.8.exe | — | |
MD5:— | SHA256:— | |||
| 2964 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb2964.16297\free4pc.org_IDM Crack 6.38 Build 2_Patch_Serial Key\IDM_6.3x_Crack_v17.8_Ali.Dbg.rar | compressed | |
MD5:— | SHA256:— | |||
| 2824 | IDM_6.3x_Crack_v17.8.exe | C:\Users\admin\AppData\Local\Temp\IDM_BAK.vbs | — | |
MD5:— | SHA256:— | |||
| 3500 | IDM1.tmp | C:\Users\admin\AppData\Local\Temp\IDM_Setup_Temp\IDMSetup2.log | binary | |
MD5:— | SHA256:— | |||
| 3500 | IDM1.tmp | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Internet Download Manager\IDM Help.lnk | lnk | |
MD5:— | SHA256:— | |||
| 3500 | IDM1.tmp | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Internet Download Manager\Grabber Help.lnk | lnk | |
MD5:— | SHA256:— | |||
| 3500 | IDM1.tmp | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Internet Download Manager\TUTORIALS.lnk | lnk | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3828 | IDMan.exe | GET | 304 | 93.184.221.240:80 | http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab | US | — | — | whitelisted |
2480 | IDMan.exe | GET | 304 | 93.184.221.240:80 | http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab | US | — | — | whitelisted |
4064 | IDMan.exe | GET | 304 | 93.184.221.240:80 | http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab | US | compressed | 57.0 Kb | whitelisted |
3316 | firefox.exe | POST | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/ | US | der | 471 b | whitelisted |
3316 | firefox.exe | POST | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/ | US | der | 471 b | whitelisted |
4064 | IDMan.exe | GET | 200 | 93.184.221.240:80 | http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab | US | compressed | 57.0 Kb | whitelisted |
3732 | pingsender.exe | GET | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAH9o%2BtuynXIiEOLckvPvJE%3D | US | der | 471 b | whitelisted |
3732 | pingsender.exe | GET | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQQX6Z6gAidtSefNc6DC0OInqPHDQQUD4BhHIIxYdUvKOeNRji0LOHG2eICEAzmtf2PsbB81NVMrv5Nv1c%3D | US | der | 471 b | whitelisted |
3316 | firefox.exe | POST | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/ | US | der | 471 b | whitelisted |
2480 | IDMan.exe | POST | 200 | 169.55.0.224:80 | http://www.internetdownloadmanager.com/data/update623.txt?v=638b02 | US | text | 15.2 Kb | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4064 | IDMan.exe | 93.184.221.240:80 | www.download.windowsupdate.com | MCI Communications Services, Inc. d/b/a Verizon Business | US | whitelisted |
3316 | firefox.exe | 169.55.0.224:443 | www.internetdownloadmanager.com | SoftLayer Technologies Inc. | US | suspicious |
3316 | firefox.exe | 52.13.211.193:443 | search.services.mozilla.com | Amazon.com, Inc. | US | unknown |
3316 | firefox.exe | 93.184.220.29:80 | ocsp.digicert.com | MCI Communications Services, Inc. d/b/a Verizon Business | US | whitelisted |
3316 | firefox.exe | 52.89.233.136:443 | addons.mozilla.org | Amazon.com, Inc. | US | unknown |
3732 | pingsender.exe | 93.184.220.29:80 | ocsp.digicert.com | MCI Communications Services, Inc. d/b/a Verizon Business | US | whitelisted |
2480 | IDMan.exe | 93.184.221.240:80 | www.download.windowsupdate.com | MCI Communications Services, Inc. d/b/a Verizon Business | US | whitelisted |
2480 | IDMan.exe | 169.55.0.224:80 | www.internetdownloadmanager.com | SoftLayer Technologies Inc. | US | suspicious |
— | — | 169.55.0.224:80 | www.internetdownloadmanager.com | SoftLayer Technologies Inc. | US | suspicious |
3316 | firefox.exe | 2.16.177.88:80 | detectportal.firefox.com | Akamai International B.V. | — | suspicious |
Domain | IP | Reputation |
|---|---|---|
www.download.windowsupdate.com |
| whitelisted |
detectportal.firefox.com |
| whitelisted |
a1089.dscd.akamai.net |
| whitelisted |
www.internetdownloadmanager.com |
| whitelisted |
test.internetdownloadmanager.com |
| whitelisted |
secure.internetdownloadmanager.com |
| whitelisted |
mirror3.internetdownloadmanager.com |
| whitelisted |
mirror5.internetdownloadmanager.com |
| whitelisted |
registeridm.com |
| suspicious |
search.services.mozilla.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
2480 | IDMan.exe | Potential Corporate Privacy Violation | ET POLICY Outgoing Basic Auth Base64 HTTP Password detected unencrypted |