| File name: | FanControl.zip |
| Full analysis: | https://app.any.run/tasks/c8c9e2a1-fa1f-4c0e-9ab5-781c09abc637 |
| Verdict: | Malicious activity |
| Analysis date: | April 19, 2024, 19:39:51 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract, compression method=deflate |
| MD5: | 77FBA7268491535DDBA8E253792E407D |
| SHA1: | AE627CC69447A5A5752E605B6DB95AAC54E47A7C |
| SHA256: | A933D20C70CBF1BFD1A0A4ADCB405A9DE14E62EDCA6000C9437E37F3A7348FD7 |
| SSDEEP: | 98304:Qh2F0h8yy/CpxwDjpDOByYaIEzWJx1fYK9uze7LqfIMYyDKB22Hs3K+HWAcVvLdT:60bGlrno+Nl |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 20 |
|---|---|
| ZipBitFlag: | - |
| ZipCompression: | Deflated |
| ZipModifyDate: | 2022:02:10 18:07:10 |
| ZipCRC: | 0xdb6673c5 |
| ZipCompressedSize: | 4058 |
| ZipUncompressedSize: | 9728 |
| ZipFileName: | de\Microsoft.Win32.TaskScheduler.resources.dll |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1196 | "C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\Desktop\FanControl.zip | C:\Program Files\WinRAR\WinRAR.exe | — | explorer.exe | |||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| 2028 | "C:\Users\admin\Desktop\FanControl\FanControl.exe" | C:\Users\admin\Desktop\FanControl\FanControl.exe | explorer.exe | ||||||||||||
User: admin Company: Rémi Mercier Integrity Level: HIGH Description: FanControl Version: 187.0.0.0 Modules
| |||||||||||||||
| 2524 | "C:\Program Files\WinRAR\WinRAR.exe" x -iext -ow -ver -- "C:\Users\admin\Desktop\FanControl.zip" C:\Users\admin\Desktop\FanControl\ | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| 3332 | "C:\Users\admin\Desktop\FanControl\FanControl.exe" | C:\Users\admin\Desktop\FanControl\FanControl.exe | — | explorer.exe | |||||||||||
User: admin Company: Rémi Mercier Integrity Level: MEDIUM Description: FanControl Exit code: 3221226540 Version: 187.0.0.0 Modules
| |||||||||||||||
| (PID) Process: | (1196) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (1196) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (1196) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (1196) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\phacker.zip | |||
| (PID) Process: | (1196) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (1196) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip | |||
| (PID) Process: | (1196) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop\FanControl.zip | |||
| (PID) Process: | (1196) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (1196) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (1196) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2524 | WinRAR.exe | C:\Users\admin\Desktop\FanControl\it\Microsoft.Win32.TaskScheduler.resources.dll | executable | |
MD5:1C331DA4BCE2809E16913C02E385576E | SHA256:1D0493E38D8B3FCC7EFA4916FEA1EEA69EE6449BF435E1869C1BC3F54D4090C5 | |||
| 2524 | WinRAR.exe | C:\Users\admin\Desktop\FanControl\es\Microsoft.Win32.TaskScheduler.resources.dll | executable | |
MD5:15DB634B70D6D9D6CD41BAAE3F02EB14 | SHA256:E893C6907DA8D68C03B1A10E68B554AD5A8C0533F15912106F32E925F2BEABF0 | |||
| 2524 | WinRAR.exe | C:\Users\admin\Desktop\FanControl\Resources\EULA.txt | text | |
MD5:CA2BEC7E34A6021E0CD3F3CE02B9B261 | SHA256:501AA9552D83B094D4C42E2CD268ADEA0DD59C8E3A085A72F54F898EF286E9C7 | |||
| 2524 | WinRAR.exe | C:\Users\admin\Desktop\FanControl\pl\Microsoft.Win32.TaskScheduler.resources.dll | executable | |
MD5:B60817A69E314B22F746917C826DA53E | SHA256:6E58D86C42B61226DD7AF35D7C9432CE6F0982D1D0D5A2F4120E8ABC5C787A02 | |||
| 2524 | WinRAR.exe | C:\Users\admin\Desktop\FanControl\ru\Microsoft.Win32.TaskScheduler.resources.dll | executable | |
MD5:DADE13E423762BDAE745D57CA3DC86EF | SHA256:1A1D5FDAC027144BCAA0E8110F4DE717E80944420C59708B3DD8E2BD31BC7ED4 | |||
| 2524 | WinRAR.exe | C:\Users\admin\Desktop\FanControl\zh-Hant\Microsoft.Win32.TaskScheduler.resources.dll | executable | |
MD5:833F269BA6F0C34F49273DA7FBD7DCE7 | SHA256:F8C769A357E6CD27452835E5288FE515FB50BFEEC83EF3969975171174B467E5 | |||
| 2524 | WinRAR.exe | C:\Users\admin\Desktop\FanControl\Autofac.dll | executable | |
MD5:EFDF8C3BC767A12924C0BA8BB5040077 | SHA256:7C01DB10615C750AFC9E711F2E2F9E9BF03B9B96586A904B54124C601FC1CBAE | |||
| 2524 | WinRAR.exe | C:\Users\admin\Desktop\FanControl\zh-CN\Microsoft.Win32.TaskScheduler.resources.dll | executable | |
MD5:3CEFEC17BAAC089C54C8102A4CFD160C | SHA256:AAFBE48966DBC5372A308AB9501245CE261D2715F336AD1908C799D354C981A2 | |||
| 2524 | WinRAR.exe | C:\Users\admin\Desktop\FanControl\de\Microsoft.Win32.TaskScheduler.resources.dll | executable | |
MD5:F83D720B236576C7D1F9F55D3BB988F9 | SHA256:6909A1C134D0285FBA2422A40EA0E65C1F0CA3C3EF2B94A1166015AF2A87780F | |||
| 2524 | WinRAR.exe | C:\Users\admin\Desktop\FanControl\FanControl.Plugins.xml | xml | |
MD5:2F773BFF374F0EA0AFAE2E258D20D85C | SHA256:39CAFAF34D0FA0652E7EF4CF2FCD119D1898D98B0574FFB78C4C643FBB1B542C | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
— | — | 224.0.0.252:5355 | — | — | — | unknown |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |