File name:

AnyDVD-HD.6.6.8.0.Final.Patch.R2-JW.zip

Full analysis: https://app.any.run/tasks/9f01dacc-fa7c-4bdc-814f-d7462b9314c8
Verdict: Malicious activity
Analysis date: January 29, 2024, 20:44:57
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

D9D3A328307A3286946485F278FDF5FB

SHA1:

3F98EC9B68D9A9C5C82E0F170522CAFBFBBBDCE4

SHA256:

9C5841AA0D001D8DCE2074881CE262A946F9D2CEDA047AB67570DFF1B8CA0E15

SSDEEP:

98304:9G7X7EnsXjBZYgTyomhq78WDruAqGp/k3w+so1kpX4ApMiJrJiFYD+Jy52ILoOXd:ovRRCJrG9a2kWXN

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 1392)
      • AnyDVD-HD.6.6.8.0.Final.Patch.R2-JW.exe (PID: 3360)
      • SetupAnyDVD6680.exe (PID: 3248)
    • Creates a writable file in the system directory

      • SetupAnyDVD6680.exe (PID: 3248)
  • SUSPICIOUS

    • Creates files in the driver directory

      • SetupAnyDVD6680.exe (PID: 3248)
    • Executable content was dropped or overwritten

      • SetupAnyDVD6680.exe (PID: 3248)
      • AnyDVD-HD.6.6.8.0.Final.Patch.R2-JW.exe (PID: 3360)
    • Drops a system driver (possible attempt to evade defenses)

      • SetupAnyDVD6680.exe (PID: 3248)
  • INFO

    • Reads the computer name

      • SetupAnyDVD6680.exe (PID: 3248)
      • AnyDVDtray.exe (PID: 3436)
    • Create files in a temporary directory

      • SetupAnyDVD6680.exe (PID: 3248)
    • Creates files in the program directory

      • SetupAnyDVD6680.exe (PID: 3248)
      • AnyDVD-HD.6.6.8.0.Final.Patch.R2-JW.exe (PID: 3360)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 1392)
    • Checks supported languages

      • SetupAnyDVD6680.exe (PID: 3248)
      • AnyDVDTray.exe (PID: 2784)
      • SetRegACL.exe (PID: 2544)
      • AnyDVD.exe (PID: 3376)
      • AnyDVD-HD.6.6.8.0.Final.Patch.R2-JW.exe (PID: 3360)
      • AnyDVDtray.exe (PID: 3436)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2010:07:28 22:48:10
ZipCRC: 0xcda721b9
ZipCompressedSize: 60793
ZipUncompressedSize: 63136
ZipFileName: AnyDVD-HD.6.6.8.0.Final.Patch.R2-JW.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
52
Monitored processes
9
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe setupanydvd6680.exe no specs setupanydvd6680.exe anydvdtray.exe no specs setregacl.exe no specs anydvd.exe no specs anydvdtray.exe no specs anydvd-hd.6.6.8.0.final.patch.r2-jw.exe no specs anydvd-hd.6.6.8.0.final.patch.r2-jw.exe

Process information

PID
CMD
Path
Indicators
Parent process
1392"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\AnyDVD-HD.6.6.8.0.Final.Patch.R2-JW.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2544"C:\Program Files\SlySoft\AnyDVD\SetRegACL.exe" Software\Microsoft\Windows\CurrentVersion\Explorer\DriveIcons 64C:\Program Files\SlySoft\AnyDVD\SetRegACL.exeSetupAnyDVD6680.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\program files\slysoft\anydvd\setregacl.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
2784"C:\Users\admin\AppData\Local\Temp\nst455A.tmp\AnyDVDTray.exe" -cC:\Users\admin\AppData\Local\Temp\nst455A.tmp\AnyDVDTray.exeSetupAnyDVD6680.exe
User:
admin
Company:
SlySoft, Inc.
Integrity Level:
HIGH
Description:
AnyDVD Application
Exit code:
10
Version:
6.6.8.0
Modules
Images
c:\users\admin\appdata\local\temp\nst455a.tmp\anydvdtray.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\imagehlp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
3248"C:\Users\admin\AppData\Local\Temp\Rar$EXa1392.10025\SetupAnyDVD6680.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa1392.10025\SetupAnyDVD6680.exe
WinRAR.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa1392.10025\setupanydvd6680.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\gdi32.dll
3360"C:\Users\admin\AppData\Local\Temp\Rar$EXa1392.11827\AnyDVD-HD.6.6.8.0.Final.Patch.R2-JW.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa1392.11827\AnyDVD-HD.6.6.8.0.Final.Patch.R2-JW.exe
WinRAR.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa1392.11827\anydvd-hd.6.6.8.0.final.patch.r2-jw.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sspicli.dll
3376"C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe" -cC:\Program Files\SlySoft\AnyDVD\AnyDVD.exeSetupAnyDVD6680.exe
User:
admin
Company:
SlySoft, Inc.
Integrity Level:
HIGH
Description:
AnyDVD Application
Exit code:
10
Version:
6.6.8.0
Modules
Images
c:\program files\slysoft\anydvd\anydvd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imm32.dll
3436"C:\Program Files\SlySoft\AnyDVD\AnyDVDtray.exe" -cC:\Program Files\SlySoft\AnyDVD\AnyDVDtray.exeAnyDVD.exe
User:
admin
Company:
SlySoft, Inc.
Integrity Level:
HIGH
Description:
AnyDVD Application
Exit code:
10
Version:
6.6.8.0
Modules
Images
c:\program files\slysoft\anydvd\anydvdtray.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\imagehlp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
3468"C:\Users\admin\AppData\Local\Temp\Rar$EXa1392.10025\SetupAnyDVD6680.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa1392.10025\SetupAnyDVD6680.exeWinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa1392.10025\setupanydvd6680.exe
c:\windows\system32\ntdll.dll
3584"C:\Users\admin\AppData\Local\Temp\Rar$EXa1392.11827\AnyDVD-HD.6.6.8.0.Final.Patch.R2-JW.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa1392.11827\AnyDVD-HD.6.6.8.0.Final.Patch.R2-JW.exeWinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa1392.11827\anydvd-hd.6.6.8.0.final.patch.r2-jw.exe
c:\windows\system32\ntdll.dll
Total events
1 416
Read events
1 385
Write events
31
Delete events
0

Modification events

(PID) Process:(1392) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1392) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(1392) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(1392) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(1392) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(1392) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(1392) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(1392) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(1392) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(1392) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
Executable files
24
Suspicious files
54
Text files
24
Unknown types
0

Dropped files

PID
Process
Filename
Type
1392WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa1392.10025\AnyDVD-HD.6.6.8.0.Final.Patch.R2-JW.exeexecutable
MD5:42EC017AA041EED9F79BDA05CF55B946
SHA256:62E796C7BFB2CF69BD2A9E74C551BED0F7944E8CD8E1E613016DDD6D422EC0A6
3248SetupAnyDVD6680.exeC:\Users\admin\AppData\Local\Temp\nst455A.tmp\AnyDVDtray.exeexecutable
MD5:0A45B257DDA4AD78E6148F8868432424
SHA256:399497312A7D1FD656BBCF5CF1C9B48F00A93B00E48E0E81F4AA996D16C5E677
1392WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa1392.10025\JohnWho.nfotext
MD5:5D6396037FF4AD9A5388D8B0017BF290
SHA256:4D8111E303FFF37638577E56E2A5E41C38AB6C8BA4497979433CD95855850E09
1392WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa1392.10025\SetupAnyDVD6680.exeexecutable
MD5:6C8967DE078A66EF2F3BD13FCCB6599B
SHA256:BC20C925465CEDBCFEA1755884A3089E1A12C26CDC35705A19033EB0FD09AE9F
3248SetupAnyDVD6680.exeC:\Users\admin\AppData\Local\Temp\nst455A.tmp\InstallHelp.dllexecutable
MD5:A06B01DD3CAA19DF00A8968F2FB18224
SHA256:9C4044C0A4CD384C186DFB2C00E1D1FC26250B686A25338806FBE78DAEF98F69
3248SetupAnyDVD6680.exeC:\Program Files\SlySoft\AnyDVD\AnyDVDtray.exeexecutable
MD5:0A45B257DDA4AD78E6148F8868432424
SHA256:399497312A7D1FD656BBCF5CF1C9B48F00A93B00E48E0E81F4AA996D16C5E677
3248SetupAnyDVD6680.exeC:\Program Files\SlySoft\AnyDVD\InstallHelp.dllexecutable
MD5:A06B01DD3CAA19DF00A8968F2FB18224
SHA256:9C4044C0A4CD384C186DFB2C00E1D1FC26250B686A25338806FBE78DAEF98F69
3248SetupAnyDVD6680.exeC:\Program Files\SlySoft\AnyDVD\ExecuteWithUAC.exeexecutable
MD5:57CFD2E9CC23E1C6B0584B7AFCAB2EBA
SHA256:DA4BF249FE578186E0CC1DE7947C7FDB85D471134546B120F7B98674CBDD9BE9
3248SetupAnyDVD6680.exeC:\Program Files\SlySoft\AnyDVD\AnyDVD-uninst.initext
MD5:8BA5E1CA33E866DDD7B7B2949D514B1E
SHA256:F5925F586FA4E331187983410FBF9BA93186241C1B5A6E284A413E50CF7FD01C
3248SetupAnyDVD6680.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\SlySoft\AnyDVD\Uninstall.lnkbinary
MD5:25595D7B574A3C86986B04D37F1A718D
SHA256:D14A4C1AF39B8927CA0A43020D1E14785F76495205061D0928F122975BF97F77
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
unknown
4
System
192.168.100.255:138
unknown
1080
svchost.exe
224.0.0.252:5355
unknown

DNS requests

No data

Threats

No threats detected
No debug info