| File name: | bat-to-exe-converter-2-3-1-multi-win.zip |
| Full analysis: | https://app.any.run/tasks/5934051d-c89b-46ed-af1a-22aab793d0e0 |
| Verdict: | Malicious activity |
| Analysis date: | July 19, 2020, 07:47:15 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract |
| MD5: | ABA051F31F773F476A5946309B5438E2 |
| SHA1: | C7CF870D3BE6E15C30DF719D1614E92CB84E17FB |
| SHA256: | A516506B2B63D8295BFFC8FA99523C1334ED676F6D93958B8EB7ABD8F7D71BA5 |
| SSDEEP: | 98304:yNwwIXJeRONAPnbgoOvzIJaz9PlvLDtm3DiU0DQK3z6s:ow1eaI0oOc8zHg+Vb3/ |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 20 |
|---|---|
| ZipBitFlag: | - |
| ZipCompression: | Deflated |
| ZipModifyDate: | 2015:06:16 14:09:01 |
| ZipCRC: | 0xf9b4be23 |
| ZipCompressedSize: | 2720312 |
| ZipUncompressedSize: | 2792684 |
| ZipFileName: | Bat_To_Exe_Converter_(Setup).exe |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2164 | "C:\Users\admin\Desktop\Bat_To_Exe_Converter_(Setup).exe" | C:\Users\admin\Desktop\Bat_To_Exe_Converter_(Setup).exe | explorer.exe | ||||||||||||
User: admin Company: Fatih Kodak Integrity Level: MEDIUM Description: Bat To Exe Converter Setup Exit code: 0 Version: 2.3.1.0 Modules
| |||||||||||||||
| 2252 | RunDll32.exe "C:\Users\admin\AppData\Local\Temp\is-F192R.tmp\OCSetupHlp.dll",_OCPID1057OpenCandy2@16 2676,02C4683D18F94FF48CCD5E393B345B8A,33B587B7667347A4A64FB663B9A785B4,399A92A095874C46AF61C9F053C4D872 | C:\Windows\system32\RunDll32.exe | — | Bat_To_Exe_Converter_(Setup).tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows host process (Rundll32) Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2264 | "C:\Users\admin\Desktop\Bat_To_Exe_Converter_(Setup).exe" /SPAWNWND=$20176 /NOTIFYWND=$30180 | C:\Users\admin\Desktop\Bat_To_Exe_Converter_(Setup).exe | Bat_To_Exe_Converter_(Setup).tmp | ||||||||||||
User: admin Company: Fatih Kodak Integrity Level: HIGH Description: Bat To Exe Converter Setup Exit code: 0 Version: 2.3.1.0 Modules
| |||||||||||||||
| 2676 | "C:\Users\admin\AppData\Local\Temp\is-E14QJ.tmp\Bat_To_Exe_Converter_(Setup).tmp" /SL5="$50160,2396495,119296,C:\Users\admin\Desktop\Bat_To_Exe_Converter_(Setup).exe" /SPAWNWND=$20176 /NOTIFYWND=$30180 | C:\Users\admin\AppData\Local\Temp\is-E14QJ.tmp\Bat_To_Exe_Converter_(Setup).tmp | Bat_To_Exe_Converter_(Setup).exe | ||||||||||||
User: admin Integrity Level: HIGH Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 Modules
| |||||||||||||||
| 2904 | "C:\Users\admin\AppData\Local\Temp\is-0VDFB.tmp\Bat_To_Exe_Converter_(Setup).tmp" /SL5="$30180,2396495,119296,C:\Users\admin\Desktop\Bat_To_Exe_Converter_(Setup).exe" | C:\Users\admin\AppData\Local\Temp\is-0VDFB.tmp\Bat_To_Exe_Converter_(Setup).tmp | — | Bat_To_Exe_Converter_(Setup).exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 Modules
| |||||||||||||||
| 3004 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\bat-to-exe-converter-2-3-1-multi-win.zip" | C:\Program Files\WinRAR\WinRAR.exe | — | explorer.exe | |||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.60.0 Modules
| |||||||||||||||
| 3588 | "C:\Program Files\Bat To Exe Converter\Bat_To_Exe_Converter.exe" | C:\Program Files\Bat To Exe Converter\Bat_To_Exe_Converter.exe | Bat_To_Exe_Converter_(Setup).tmp | ||||||||||||
User: admin Company: Fatih Kodak Integrity Level: MEDIUM Description: Bat To Exe Converter Exit code: 0 Version: 2.3.1 Modules
| |||||||||||||||
| (PID) Process: | (3004) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (3004) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (3004) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\132\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3004) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\bat-to-exe-converter-2-3-1-multi-win.zip | |||
| (PID) Process: | (3004) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (3004) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (3004) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (3004) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (2676) Bat_To_Exe_Converter_(Setup).tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | Owner |
Value: 740A0000E23915E9A05DD601 | |||
| (PID) Process: | (2676) Bat_To_Exe_Converter_(Setup).tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | SessionHash |
Value: 0622E6DE8444AF1AFC38C2728D10E33A9AC2983701581B15ACD42EEBECBB4826 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3004 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3004.19568\Bat_To_Exe_Converter_(Setup).exe | — | |
MD5:— | SHA256:— | |||
| 3004 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3004.19568\Examples\AesDecode.bat | — | |
MD5:— | SHA256:— | |||
| 3004 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3004.19568\Examples\AesEncode.bat | — | |
MD5:— | SHA256:— | |||
| 3004 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3004.19568\Examples\Base64Decode.bat | — | |
MD5:— | SHA256:— | |||
| 3004 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3004.19568\Examples\Base64Encode.bat | — | |
MD5:— | SHA256:— | |||
| 3004 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3004.19568\Examples\BrowseForFile.bat | — | |
MD5:— | SHA256:— | |||
| 3004 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3004.19568\Examples\BrowseForFile2.bat | — | |
MD5:— | SHA256:— | |||
| 3004 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3004.19568\Examples\BrowseForFolder.bat | — | |
MD5:— | SHA256:— | |||
| 3004 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3004.19568\Examples\CloseWindow.bat | — | |
MD5:— | SHA256:— | |||
| 3004 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3004.19568\Examples\CRC32.bat | — | |
MD5:— | SHA256:— | |||
Domain | IP | Reputation |
|---|---|---|
api.opencandy.com |
| whitelisted |