| File name: | Calculadoras Casio FX-ES PLUS [Software PRO].rar |
| Full analysis: | https://app.any.run/tasks/e4d1162e-3fa1-4b1b-80ac-d284564165b6 |
| Verdict: | Malicious activity |
| Analysis date: | December 29, 2020, 09:27:06 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-rar |
| File info: | RAR archive data, v5 |
| MD5: | 09554D2F5EBFBBC66B9B281F55317B30 |
| SHA1: | C43D425FCD91FA2ABE49C4817D381B38139FBABC |
| SHA256: | A8879AD89BA76E6491743E5C032835FC8A0E98DF23AEBFF29AD6BAAFD1AEB6F9 |
| SSDEEP: | 196608:b2oXuw0OTCURBtLZVf4TCOQDTxAuY9ONkchM+ncIyneMwneWEA/cIHvp9hVt6D3M:qcZei3Z+TCZTXyqv++ncIynel7EApHRt |
| .rar | | | RAR compressed archive (v5.0) (61.5) |
|---|---|---|
| .rar | | | RAR compressed archive (gen) (38.4) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 292 | "C:\Users\admin\Desktop\Casio FX 85ES PLUS.exe" | C:\Users\admin\Desktop\Casio FX 85ES PLUS.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 2812 | "C:\Users\admin\AppData\Local\Temp\RarSFX2\fx-991ES PLUS C Emulator.exe" | C:\Users\admin\AppData\Local\Temp\RarSFX2\fx-991ES PLUS C Emulator.exe | — | Casio FX 991ES PLUS C.exe | |||||||||||
User: admin Company: CASIO COMPUTER CO., LTD. Integrity Level: MEDIUM Description: fx-ES PLUS Emulator Exit code: 0 Version: 4.0.0.0 Modules
| |||||||||||||||
| 2872 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Calculadoras Casio FX-ES PLUS [Software PRO].rar" | C:\Program Files\WinRAR\WinRAR.exe | — | explorer.exe | |||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.60.0 Modules
| |||||||||||||||
| 3128 | "C:\Users\admin\Desktop\Casio FX 991ES PLUS C.exe" | C:\Users\admin\Desktop\Casio FX 991ES PLUS C.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 3276 | "C:\Users\admin\AppData\Local\Temp\RarSFX0\fx-570LA X_991LA X Emulator.exe" | C:\Users\admin\AppData\Local\Temp\RarSFX0\fx-570LA X_991LA X Emulator.exe | Casio Classwiz FX 991 LAX.exe | ||||||||||||
User: admin Company: CASIO COMPUTER CO., LTD. Integrity Level: MEDIUM Description: ClassWiz Emulator Exit code: 0 Version: 2.0.1.0 Modules
| |||||||||||||||
| 3588 | "C:\Users\admin\AppData\Local\Temp\RarSFX1\fx-85ES PLUS Emulator.exe" | C:\Users\admin\AppData\Local\Temp\RarSFX1\fx-85ES PLUS Emulator.exe | — | Casio FX 85ES PLUS.exe | |||||||||||
User: admin Company: CASIO COMPUTER CO., LTD. Integrity Level: MEDIUM Description: fx-ES PLUS Emulator Exit code: 0 Version: 4.0.0.0 Modules
| |||||||||||||||
| 3988 | "C:\Users\admin\Desktop\Casio Classwiz FX 991 LAX.exe" | C:\Users\admin\Desktop\Casio Classwiz FX 991 LAX.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| (PID) Process: | (2872) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (2872) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (2872) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\13B\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2872) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\Calculadoras Casio FX-ES PLUS [Software PRO].rar | |||
| (PID) Process: | (2872) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (2872) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (2872) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (2872) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (2872) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin |
| Operation: | write | Name: | Placement |
Value: 2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000 | |||
| (PID) Process: | (2872) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\General |
| Operation: | write | Name: | LastFolder |
Value: C:\Users\admin\AppData\Local\Temp | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2872 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2872.40412\Casio Classwiz FX 991 LAX.exe | — | |
MD5:— | SHA256:— | |||
| 2872 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2872.40412\Casio FX 85ES PLUS.exe | — | |
MD5:— | SHA256:— | |||
| 2872 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2872.40731\Casio FX 991ES PLUS C.exe | — | |
MD5:— | SHA256:— | |||
| 292 | Casio FX 85ES PLUS.exe | C:\Users\admin\AppData\Local\Temp\RarSFX1\fxESPLUS_P1.dll | executable | |
MD5:— | SHA256:— | |||
| 3988 | Casio Classwiz FX 991 LAX.exe | C:\Users\admin\AppData\Local\Temp\RarSFX0\opencv_highgui2410.dll | executable | |
MD5:67CD5063A8E1A6843906FED6B2F4CD78 | SHA256:33E1867AA2502409E19531940F47D464FBC82C9D512F417ECC5D46432D91DDFD | |||
| 3988 | Casio Classwiz FX 991 LAX.exe | C:\Users\admin\AppData\Local\Temp\RarSFX0\opencv_imgproc2410.dll | executable | |
MD5:4EACF36B9DA3053A9AC2BDA5E5147745 | SHA256:7A48136BD2B09A6C5530390E4F5123A2CEBE92EC30779B482CC4B8AAC603E8F5 | |||
| 3988 | Casio Classwiz FX 991 LAX.exe | C:\Users\admin\AppData\Local\Temp\RarSFX0\SimU8engine.dll | executable | |
MD5:9A20D708A346868A162F750FC4B19FD6 | SHA256:B2D9BA345A0DBBED569C1E4A67CDFBF066FCA7E1BBCC1B6AEB53AD22371D5105 | |||
| 3988 | Casio Classwiz FX 991 LAX.exe | C:\Users\admin\AppData\Local\Temp\RarSFX0\fx-570LA X_991LA X Emulator.exe | executable | |
MD5:0DF801B5BA7ED603761ECA879D7429B2 | SHA256:1DF70EA44E6603A46ED4A40BE51350B9A65D000E8BA28E94A7C847902CF0F8EB | |||
| 3988 | Casio Classwiz FX 991 LAX.exe | C:\Users\admin\AppData\Local\Temp\RarSFX0\fx-570LA X_991LA X Emulator.lic | text | |
MD5:B5079698754ED5228FFDD030D10D2349 | SHA256:7AD701A07921C77A4C203800BADE620ECB6A1ED76089ED2D0AB7DD637A24A0F4 | |||
| 292 | Casio FX 85ES PLUS.exe | C:\Users\admin\AppData\Local\Temp\RarSFX1\License.rtf | text | |
MD5:2DB15A6A31EFED9423199C91C648D4F2 | SHA256:959CD047936E26A0C04E0A8AAA5895C98DBD2CD1C987FB5034924D7ADEE00B6B | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
3276 | fx-570LA X_991LA X Emulator.exe | 52.193.252.34:443 | edu.casio.com | Amazon.com, Inc. | JP | unknown |
Domain | IP | Reputation |
|---|---|---|
edu.casio.com |
| unknown |