| File name: | ColdTurkey.both.editions.rar |
| Full analysis: | https://app.any.run/tasks/1d4d04b5-9e15-4338-9c15-b1f3fd9fee66 |
| Verdict: | Malicious activity |
| Analysis date: | January 14, 2025, 20:11:32 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Indicators: | |
| MIME: | application/x-rar |
| File info: | RAR archive data, v5 |
| MD5: | 32919F13EBE0E6A974EE624A63DC3EF1 |
| SHA1: | AD1B7088BBEA5375F1B1134AADFF1C823C4CA169 |
| SHA256: | A90682716D1DB62E81CED02EEED732175A101DB4D08857CB4826DD00D73BF357 |
| SSDEEP: | 196608:Jzp3zuYuxGVbvF+WeGFt0cKqfrSuz0dqkvOfQ0:R9aSV3t06+ub |
| .rar | | | RAR compressed archive (v5.0) (61.5) |
|---|---|---|
| .rar | | | RAR compressed archive (gen) (38.4) |
| FileVersion: | RAR v5 |
|---|
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 644 | "C:\Users\admin\Desktop\Cold_Turkey_Installer.exe" | C:\Users\admin\Desktop\Cold_Turkey_Installer.exe | explorer.exe | ||||||||||||
User: admin Company: Cold Turkey Software, Inc. Integrity Level: MEDIUM Description: Cold Turkey Blocker Setup Exit code: 0 Version: Modules
| |||||||||||||||
| 1356 | "C:\Users\admin\AppData\Local\Temp\is-0KH9L.tmp\Cold_Turkey_Installer.tmp" /SL5="$80294,6950134,837632,C:\Users\admin\Desktop\Cold_Turkey_Installer.exe" | C:\Users\admin\AppData\Local\Temp\is-0KH9L.tmp\Cold_Turkey_Installer.tmp | — | Cold_Turkey_Installer.exe | |||||||||||
User: admin Company: Cold Turkey Software, Inc. Integrity Level: MEDIUM Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 Modules
| |||||||||||||||
| 1536 | "C:\Users\admin\Desktop\Cold_Turkey_Micromanager_Free_Installer.exe" /SPAWNWND=$20238 /NOTIFYWND=$20248 | C:\Users\admin\Desktop\Cold_Turkey_Micromanager_Free_Installer.exe | Cold_Turkey_Micromanager_Free_Installer.tmp | ||||||||||||
User: admin Company: Cold Turkey Software, Inc. Integrity Level: HIGH Description: Cold Turkey Micromanager Setup Exit code: 0 Version: Modules
| |||||||||||||||
| 1536 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Google\Chrome\User Data" /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Google\Chrome\User Data\Crashpad" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win64 --annotation=prod=Chrome --annotation=ver=122.0.6261.70 --initial-client-data=0x21c,0x220,0x224,0x1f8,0x228,0x7ff815ebdc40,0x7ff815ebdc4c,0x7ff815ebdc58 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Version: 122.0.6261.70 Modules
| |||||||||||||||
| 1620 | "C:\Program Files\Cold Turkey\CTHostInstaller.exe" chrome false | C:\Program Files\Cold Turkey\CTHostInstaller.exe | — | Cold Turkey Blocker.exe | |||||||||||
User: admin Company: Cold Turkey Software Inc. Integrity Level: MEDIUM Description: CTHostInstaller Exit code: 3221226540 Version: 1.0.0.0 Modules
| |||||||||||||||
| 2548 | "C:\Program Files\Cold Turkey\Cold Turkey Blocker.exe" -first-run | C:\Program Files\Cold Turkey\Cold Turkey Blocker.exe | ServiceHub.Helper.exe | ||||||||||||
User: admin Company: Cold Turkey Software Inc. Integrity Level: MEDIUM Description: Cold Turkey Blocker Version: 4.5.0.0 Modules
| |||||||||||||||
| 2728 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | netsh.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2796 | "C:\Program Files\Cold Turkey Micromanager\Cold Turkey Micromanager.exe" | C:\Program Files\Cold Turkey Micromanager\Cold Turkey Micromanager.exe | Cold_Turkey_Micromanager_Free_Installer.tmp | ||||||||||||
User: admin Company: Cold Turkey Software Integrity Level: HIGH Description: Cold Turkey Micromanager Version: 1.2.0.0 Modules
| |||||||||||||||
| 4136 | "C:\Program Files\Cold Turkey\ServiceHub.Helper.exe" -first-run | C:\Program Files\Cold Turkey\ServiceHub.Helper.exe | ServiceHub.Power.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Description: ServiceHub.Helper Version: 1.0.0.0 Modules
| |||||||||||||||
| 4764 | "C:\Program Files\Cold Turkey\CTHostInstaller.exe" chrome false | C:\Program Files\Cold Turkey\CTHostInstaller.exe | Cold Turkey Blocker.exe | ||||||||||||
User: admin Company: Cold Turkey Software Inc. Integrity Level: HIGH Description: CTHostInstaller Exit code: 0 Version: 1.0.0.0 Modules
| |||||||||||||||
| (PID) Process: | (6948) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface |
| Operation: | write | Name: | ShowPassword |
Value: 0 | |||
| (PID) Process: | (6948) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\preferences.zip | |||
| (PID) Process: | (6948) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\chromium_ext.zip | |||
| (PID) Process: | (6948) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\omni_23_10_2024_.zip | |||
| (PID) Process: | (6948) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\ColdTurkey.both.editions.rar | |||
| (PID) Process: | (6948) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (6948) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (6948) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (6948) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (6408) Cold_Turkey_Micromanager_Free_Installer.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{6498E673-B9C2-4544-A722-2E854B5B573F}_is1 |
| Operation: | write | Name: | Inno Setup: Setup Version |
Value: 6.1.0-beta | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 644 | Cold_Turkey_Installer.exe | C:\Users\admin\AppData\Local\Temp\is-0KH9L.tmp\Cold_Turkey_Installer.tmp | executable | |
MD5:03840135BB43E6C3DE3BEE0724C3C187 | SHA256:70B5FAC312A869659BD0EF69A7DF1AB46AD7F19F340EB659E57CA71A579DA02A | |||
| 6948 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb6948.31721\Cold_Turkey_Installer.exe | executable | |
MD5:EAA0F3DDD71DB24C3A64ECF58E40DA52 | SHA256:23A32B9DB00C74B0440132FD6DFD0A2B5F9F522B13F59B491C4BBF98070CDDF2 | |||
| 6408 | Cold_Turkey_Micromanager_Free_Installer.tmp | C:\Users\admin\AppData\Local\Temp\is-QCEQE.tmp\_isetup\_setup64.tmp | executable | |
MD5:E4211D6D009757C078A9FAC7FF4F03D4 | SHA256:388A796580234EFC95F3B1C70AD4CB44BFDDC7BA0F9203BF4902B9929B136F95 | |||
| 5992 | Cold_Turkey_Installer.exe | C:\Users\admin\AppData\Local\Temp\is-NHMUH.tmp\Cold_Turkey_Installer.tmp | executable | |
MD5:03840135BB43E6C3DE3BEE0724C3C187 | SHA256:70B5FAC312A869659BD0EF69A7DF1AB46AD7F19F340EB659E57CA71A579DA02A | |||
| 6292 | Cold_Turkey_Installer.tmp | C:\Users\admin\AppData\Local\Temp\is-3GCEP.tmp\_isetup\_setup64.tmp | executable | |
MD5:E4211D6D009757C078A9FAC7FF4F03D4 | SHA256:388A796580234EFC95F3B1C70AD4CB44BFDDC7BA0F9203BF4902B9929B136F95 | |||
| 1536 | Cold_Turkey_Micromanager_Free_Installer.exe | C:\Users\admin\AppData\Local\Temp\is-R03OE.tmp\Cold_Turkey_Micromanager_Free_Installer.tmp | executable | |
MD5:D7AFC237AAAF88D587F5BF71086171C1 | SHA256:431FE13352F26B23665C8DBC722EBE5E5FCE55FEB22D358FB5B7607E8F770BFF | |||
| 6948 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb6948.31721\Cold_Turkey_Micromanager_Free_Installer.exe | executable | |
MD5:677D68AC530DEDC3DDA7B8E0E56FCB6A | SHA256:550691F5EE2D1EE8F30299C0E0602FBC4BEF42DA2F2B7AD1F7A2C77E5AB9B538 | |||
| 6408 | Cold_Turkey_Micromanager_Free_Installer.tmp | C:\Program Files\Cold Turkey Micromanager\is-B4GLJ.tmp | executable | |
MD5:805135DA62C5B65618B9782A5DC48F06 | SHA256:A0B5BE9580BF6548F685D79E5439F6D946EF57E013D201F946B2A894E7441804 | |||
| 6408 | Cold_Turkey_Micromanager_Free_Installer.tmp | C:\Program Files\Cold Turkey Micromanager\is-180ED.tmp | executable | |
MD5:3E45F5377EB3381C1A81704296274C56 | SHA256:A8B6409DC0E94EC804F418B74A26CE0D2A56A8FA9AA034E6025761675AD22D6C | |||
| 6408 | Cold_Turkey_Micromanager_Free_Installer.tmp | C:\Program Files\Cold Turkey Micromanager\Microsoft.Toolkit.Uwp.Notifications.dll | executable | |
MD5:805135DA62C5B65618B9782A5DC48F06 | SHA256:A0B5BE9580BF6548F685D79E5439F6D946EF57E013D201F946B2A894E7441804 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | GET | 200 | 2.16.241.19:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
4712 | MoUsoCoreWorker.exe | GET | 200 | 2.23.246.101:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
— | — | GET | 200 | 2.23.246.101:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
4712 | MoUsoCoreWorker.exe | GET | 200 | 2.16.241.19:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
— | — | GET | 200 | 2.17.190.73:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D | unknown | — | — | whitelisted |
— | — | GET | 200 | 2.17.190.73:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
6560 | backgroundTaskHost.exe | GET | 200 | 2.23.77.188:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D | unknown | — | — | whitelisted |
2452 | SIHClient.exe | GET | 200 | 23.35.229.160:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
2452 | SIHClient.exe | GET | 200 | 23.35.229.160:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4712 | MoUsoCoreWorker.exe | 2.16.241.19:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
— | — | 2.16.241.19:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
4712 | MoUsoCoreWorker.exe | 2.23.246.101:80 | www.microsoft.com | Ooredoo Q.S.C. | QA | whitelisted |
— | — | 2.23.246.101:80 | www.microsoft.com | Ooredoo Q.S.C. | QA | whitelisted |
— | — | 2.23.227.208:443 | www.bing.com | Ooredoo Q.S.C. | QA | whitelisted |
— | — | 2.17.190.73:80 | ocsp.digicert.com | AKAMAI-AS | DE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1176 | svchost.exe | 40.126.32.76:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
www.bing.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
login.live.com |
| whitelisted |
go.microsoft.com |
| whitelisted |
arc.msn.com |
| whitelisted |
fd.api.iris.microsoft.com |
| whitelisted |
Process | Message |
|---|---|
ServiceHub.Power.exe | Native library pre-loader is trying to load native SQLite library "C:\Program Files\Cold Turkey\x64\SQLite.Interop.dll"...
|
ServiceHub.Helper.exe | Native library pre-loader is trying to load native SQLite library "C:\Program Files\Cold Turkey\x64\SQLite.Interop.dll"...
|
Cold Turkey Blocker.exe | Native library pre-loader is trying to load native SQLite library "C:\Program Files\Cold Turkey\x64\SQLite.Interop.dll"...
|