File name: | FanControl.zip |
Full analysis: | https://app.any.run/tasks/c8c9e2a1-fa1f-4c0e-9ab5-781c09abc637 |
Verdict: | Malicious activity |
Analysis date: | April 19, 2024, 19:39:51 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | application/zip |
File info: | Zip archive data, at least v2.0 to extract, compression method=deflate |
MD5: | 77FBA7268491535DDBA8E253792E407D |
SHA1: | AE627CC69447A5A5752E605B6DB95AAC54E47A7C |
SHA256: | A933D20C70CBF1BFD1A0A4ADCB405A9DE14E62EDCA6000C9437E37F3A7348FD7 |
SSDEEP: | 98304:Qh2F0h8yy/CpxwDjpDOByYaIEzWJx1fYK9uze7LqfIMYyDKB22Hs3K+HWAcVvLdT:60bGlrno+Nl |
.zip | | | ZIP compressed archive (100) |
---|
ZipRequiredVersion: | 20 |
---|---|
ZipBitFlag: | - |
ZipCompression: | Deflated |
ZipModifyDate: | 2022:02:10 18:07:10 |
ZipCRC: | 0xdb6673c5 |
ZipCompressedSize: | 4058 |
ZipUncompressedSize: | 9728 |
ZipFileName: | de\Microsoft.Win32.TaskScheduler.resources.dll |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
1196 | "C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\Desktop\FanControl.zip | C:\Program Files\WinRAR\WinRAR.exe | — | explorer.exe | |||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
2028 | "C:\Users\admin\Desktop\FanControl\FanControl.exe" | C:\Users\admin\Desktop\FanControl\FanControl.exe | explorer.exe | ||||||||||||
User: admin Company: Rémi Mercier Integrity Level: HIGH Description: FanControl Version: 187.0.0.0 Modules
| |||||||||||||||
2524 | "C:\Program Files\WinRAR\WinRAR.exe" x -iext -ow -ver -- "C:\Users\admin\Desktop\FanControl.zip" C:\Users\admin\Desktop\FanControl\ | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
3332 | "C:\Users\admin\Desktop\FanControl\FanControl.exe" | C:\Users\admin\Desktop\FanControl\FanControl.exe | — | explorer.exe | |||||||||||
User: admin Company: Rémi Mercier Integrity Level: MEDIUM Description: FanControl Exit code: 3221226540 Version: 187.0.0.0 Modules
|
(PID) Process: | (1196) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
Operation: | write | Name: | ShellExtBMP |
Value: | |||
(PID) Process: | (1196) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
Operation: | write | Name: | ShellExtIcon |
Value: | |||
(PID) Process: | (1196) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
Operation: | write | Name: | LanguageList |
Value: en-US | |||
(PID) Process: | (1196) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\phacker.zip | |||
(PID) Process: | (1196) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
(PID) Process: | (1196) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip | |||
(PID) Process: | (1196) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop\FanControl.zip | |||
(PID) Process: | (1196) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | name |
Value: 120 | |||
(PID) Process: | (1196) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | size |
Value: 80 | |||
(PID) Process: | (1196) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | type |
Value: 120 |
PID | Process | Filename | Type | |
---|---|---|---|---|
2524 | WinRAR.exe | C:\Users\admin\Desktop\FanControl\es\Microsoft.Win32.TaskScheduler.resources.dll | executable | |
MD5:15DB634B70D6D9D6CD41BAAE3F02EB14 | SHA256:E893C6907DA8D68C03B1A10E68B554AD5A8C0533F15912106F32E925F2BEABF0 | |||
2524 | WinRAR.exe | C:\Users\admin\Desktop\FanControl\de\Microsoft.Win32.TaskScheduler.resources.dll | executable | |
MD5:F83D720B236576C7D1F9F55D3BB988F9 | SHA256:6909A1C134D0285FBA2422A40EA0E65C1F0CA3C3EF2B94A1166015AF2A87780F | |||
2524 | WinRAR.exe | C:\Users\admin\Desktop\FanControl\fr\Microsoft.Win32.TaskScheduler.resources.dll | executable | |
MD5:3B4621370ADDCF4306669C9E7E45C865 | SHA256:E3EE50E08124A7603BE7D996DCF596EB0D3F9C603768E86E003F7B942D7097F3 | |||
2524 | WinRAR.exe | C:\Users\admin\Desktop\FanControl\zh-CN\Microsoft.Win32.TaskScheduler.resources.dll | executable | |
MD5:3CEFEC17BAAC089C54C8102A4CFD160C | SHA256:AAFBE48966DBC5372A308AB9501245CE261D2715F336AD1908C799D354C981A2 | |||
2524 | WinRAR.exe | C:\Users\admin\Desktop\FanControl\pl\Microsoft.Win32.TaskScheduler.resources.dll | executable | |
MD5:B60817A69E314B22F746917C826DA53E | SHA256:6E58D86C42B61226DD7AF35D7C9432CE6F0982D1D0D5A2F4120E8ABC5C787A02 | |||
2524 | WinRAR.exe | C:\Users\admin\Desktop\FanControl\Resources\EULA.txt | text | |
MD5:CA2BEC7E34A6021E0CD3F3CE02B9B261 | SHA256:501AA9552D83B094D4C42E2CD268ADEA0DD59C8E3A085A72F54F898EF286E9C7 | |||
2524 | WinRAR.exe | C:\Users\admin\Desktop\FanControl\zh-Hant\Microsoft.Win32.TaskScheduler.resources.dll | executable | |
MD5:833F269BA6F0C34F49273DA7FBD7DCE7 | SHA256:F8C769A357E6CD27452835E5288FE515FB50BFEEC83EF3969975171174B467E5 | |||
2524 | WinRAR.exe | C:\Users\admin\Desktop\FanControl\Emoji.Wpf.dll | executable | |
MD5:689E1A832309C484F95B07BD07FE6A2A | SHA256:21FB67EFACE68ADE290EE88F8A6CCC3869E648A49B5F5FFBAD686C3323D1CF03 | |||
2524 | WinRAR.exe | C:\Users\admin\Desktop\FanControl\ru\Microsoft.Win32.TaskScheduler.resources.dll | executable | |
MD5:DADE13E423762BDAE745D57CA3DC86EF | SHA256:1A1D5FDAC027144BCAA0E8110F4DE717E80944420C59708B3DD8E2BD31BC7ED4 | |||
2524 | WinRAR.exe | C:\Users\admin\Desktop\FanControl\Autofac.dll | executable | |
MD5:EFDF8C3BC767A12924C0BA8BB5040077 | SHA256:7C01DB10615C750AFC9E711F2E2F9E9BF03B9B96586A904B54124C601FC1CBAE |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | unknown |
4 | System | 192.168.100.255:138 | — | — | — | unknown |
— | — | 224.0.0.252:5355 | — | — | — | unknown |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |