| File name: | Calculadoras Casio FX-ES PLUS [Software PRO].rar |
| Full analysis: | https://app.any.run/tasks/e4d1162e-3fa1-4b1b-80ac-d284564165b6 |
| Verdict: | Malicious activity |
| Analysis date: | December 29, 2020, 09:27:06 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-rar |
| File info: | RAR archive data, v5 |
| MD5: | 09554D2F5EBFBBC66B9B281F55317B30 |
| SHA1: | C43D425FCD91FA2ABE49C4817D381B38139FBABC |
| SHA256: | A8879AD89BA76E6491743E5C032835FC8A0E98DF23AEBFF29AD6BAAFD1AEB6F9 |
| SSDEEP: | 196608:b2oXuw0OTCURBtLZVf4TCOQDTxAuY9ONkchM+ncIyneMwneWEA/cIHvp9hVt6D3M:qcZei3Z+TCZTXyqv++ncIynel7EApHRt |
| .rar | | | RAR compressed archive (v5.0) (61.5) |
|---|---|---|
| .rar | | | RAR compressed archive (gen) (38.4) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 292 | "C:\Users\admin\Desktop\Casio FX 85ES PLUS.exe" | C:\Users\admin\Desktop\Casio FX 85ES PLUS.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 2812 | "C:\Users\admin\AppData\Local\Temp\RarSFX2\fx-991ES PLUS C Emulator.exe" | C:\Users\admin\AppData\Local\Temp\RarSFX2\fx-991ES PLUS C Emulator.exe | — | Casio FX 991ES PLUS C.exe | |||||||||||
User: admin Company: CASIO COMPUTER CO., LTD. Integrity Level: MEDIUM Description: fx-ES PLUS Emulator Exit code: 0 Version: 4.0.0.0 Modules
| |||||||||||||||
| 2872 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Calculadoras Casio FX-ES PLUS [Software PRO].rar" | C:\Program Files\WinRAR\WinRAR.exe | — | explorer.exe | |||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.60.0 Modules
| |||||||||||||||
| 3128 | "C:\Users\admin\Desktop\Casio FX 991ES PLUS C.exe" | C:\Users\admin\Desktop\Casio FX 991ES PLUS C.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 3276 | "C:\Users\admin\AppData\Local\Temp\RarSFX0\fx-570LA X_991LA X Emulator.exe" | C:\Users\admin\AppData\Local\Temp\RarSFX0\fx-570LA X_991LA X Emulator.exe | Casio Classwiz FX 991 LAX.exe | ||||||||||||
User: admin Company: CASIO COMPUTER CO., LTD. Integrity Level: MEDIUM Description: ClassWiz Emulator Exit code: 0 Version: 2.0.1.0 Modules
| |||||||||||||||
| 3588 | "C:\Users\admin\AppData\Local\Temp\RarSFX1\fx-85ES PLUS Emulator.exe" | C:\Users\admin\AppData\Local\Temp\RarSFX1\fx-85ES PLUS Emulator.exe | — | Casio FX 85ES PLUS.exe | |||||||||||
User: admin Company: CASIO COMPUTER CO., LTD. Integrity Level: MEDIUM Description: fx-ES PLUS Emulator Exit code: 0 Version: 4.0.0.0 Modules
| |||||||||||||||
| 3988 | "C:\Users\admin\Desktop\Casio Classwiz FX 991 LAX.exe" | C:\Users\admin\Desktop\Casio Classwiz FX 991 LAX.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| (PID) Process: | (2872) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (2872) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (2872) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\13B\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2872) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\Calculadoras Casio FX-ES PLUS [Software PRO].rar | |||
| (PID) Process: | (2872) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (2872) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (2872) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (2872) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (2872) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin |
| Operation: | write | Name: | Placement |
Value: 2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000 | |||
| (PID) Process: | (2872) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\General |
| Operation: | write | Name: | LastFolder |
Value: C:\Users\admin\AppData\Local\Temp | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2872 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2872.40412\Casio Classwiz FX 991 LAX.exe | — | |
MD5:— | SHA256:— | |||
| 2872 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2872.40412\Casio FX 85ES PLUS.exe | — | |
MD5:— | SHA256:— | |||
| 2872 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2872.40731\Casio FX 991ES PLUS C.exe | — | |
MD5:— | SHA256:— | |||
| 292 | Casio FX 85ES PLUS.exe | C:\Users\admin\AppData\Local\Temp\RarSFX1\fxESPLUS_P1.dll | executable | |
MD5:— | SHA256:— | |||
| 3988 | Casio Classwiz FX 991 LAX.exe | C:\Users\admin\AppData\Local\Temp\RarSFX0\SimU8engine.dll | executable | |
MD5:9A20D708A346868A162F750FC4B19FD6 | SHA256:B2D9BA345A0DBBED569C1E4A67CDFBF066FCA7E1BBCC1B6AEB53AD22371D5105 | |||
| 3988 | Casio Classwiz FX 991 LAX.exe | C:\Users\admin\AppData\Local\Temp\RarSFX0\SimU8.dll | executable | |
MD5:228C76037C2268F4954FF042D1C92AEA | SHA256:634051B2DD8F93663D618AC1A4370F5BDAEC8DE5F23D938C9915ABB429FF4CBF | |||
| 3988 | Casio Classwiz FX 991 LAX.exe | C:\Users\admin\AppData\Local\Temp\RarSFX0\libcurl.dll | executable | |
MD5:70E2A0F0E403F097E9804D8ACFF5658E | SHA256:7E346863F3F157CA1CC60BF73109068BA5841BF719007F193C41D9DC7C0011DD | |||
| 3988 | Casio Classwiz FX 991 LAX.exe | C:\Users\admin\AppData\Local\Temp\RarSFX0\fx-570LA X_991LA X Emulator.lic | text | |
MD5:B5079698754ED5228FFDD030D10D2349 | SHA256:7AD701A07921C77A4C203800BADE620ECB6A1ED76089ED2D0AB7DD637A24A0F4 | |||
| 3988 | Casio Classwiz FX 991 LAX.exe | C:\Users\admin\AppData\Local\Temp\RarSFX0\CLASSWIZ_P16.dll | executable | |
MD5:B4FB3B8F14426435E415F3B610C95762 | SHA256:92E3C7369B95A97C708E84A06B291496235A62E7D062E2939A5F9AF6C9FBDCB3 | |||
| 3988 | Casio Classwiz FX 991 LAX.exe | C:\Users\admin\AppData\Local\Temp\RarSFX0\License.rtf | text | |
MD5:B73E36C19CAC214A3CF7BEA059454464 | SHA256:607421EBEF87CA0DAB08B7707F4DA3F49C4FEC12AB4C2017319A92825A72932E | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
3276 | fx-570LA X_991LA X Emulator.exe | 52.193.252.34:443 | edu.casio.com | Amazon.com, Inc. | JP | unknown |
Domain | IP | Reputation |
|---|---|---|
edu.casio.com |
| unknown |