| File name: | FanControl.zip |
| Full analysis: | https://app.any.run/tasks/c8c9e2a1-fa1f-4c0e-9ab5-781c09abc637 |
| Verdict: | Malicious activity |
| Analysis date: | April 19, 2024, 19:39:51 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract, compression method=deflate |
| MD5: | 77FBA7268491535DDBA8E253792E407D |
| SHA1: | AE627CC69447A5A5752E605B6DB95AAC54E47A7C |
| SHA256: | A933D20C70CBF1BFD1A0A4ADCB405A9DE14E62EDCA6000C9437E37F3A7348FD7 |
| SSDEEP: | 98304:Qh2F0h8yy/CpxwDjpDOByYaIEzWJx1fYK9uze7LqfIMYyDKB22Hs3K+HWAcVvLdT:60bGlrno+Nl |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 20 |
|---|---|
| ZipBitFlag: | - |
| ZipCompression: | Deflated |
| ZipModifyDate: | 2022:02:10 18:07:10 |
| ZipCRC: | 0xdb6673c5 |
| ZipCompressedSize: | 4058 |
| ZipUncompressedSize: | 9728 |
| ZipFileName: | de\Microsoft.Win32.TaskScheduler.resources.dll |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1196 | "C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\Desktop\FanControl.zip | C:\Program Files\WinRAR\WinRAR.exe | — | explorer.exe | |||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| 2028 | "C:\Users\admin\Desktop\FanControl\FanControl.exe" | C:\Users\admin\Desktop\FanControl\FanControl.exe | explorer.exe | ||||||||||||
User: admin Company: Rémi Mercier Integrity Level: HIGH Description: FanControl Version: 187.0.0.0 Modules
| |||||||||||||||
| 2524 | "C:\Program Files\WinRAR\WinRAR.exe" x -iext -ow -ver -- "C:\Users\admin\Desktop\FanControl.zip" C:\Users\admin\Desktop\FanControl\ | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| 3332 | "C:\Users\admin\Desktop\FanControl\FanControl.exe" | C:\Users\admin\Desktop\FanControl\FanControl.exe | — | explorer.exe | |||||||||||
User: admin Company: Rémi Mercier Integrity Level: MEDIUM Description: FanControl Exit code: 3221226540 Version: 187.0.0.0 Modules
| |||||||||||||||
| (PID) Process: | (1196) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (1196) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (1196) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (1196) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\phacker.zip | |||
| (PID) Process: | (1196) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (1196) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip | |||
| (PID) Process: | (1196) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop\FanControl.zip | |||
| (PID) Process: | (1196) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (1196) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (1196) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2524 | WinRAR.exe | C:\Users\admin\Desktop\FanControl\FanControl.Plugins.xml | xml | |
MD5:2F773BFF374F0EA0AFAE2E258D20D85C | SHA256:39CAFAF34D0FA0652E7EF4CF2FCD119D1898D98B0574FFB78C4C643FBB1B542C | |||
| 2524 | WinRAR.exe | C:\Users\admin\Desktop\FanControl\fr\Microsoft.Win32.TaskScheduler.resources.dll | executable | |
MD5:3B4621370ADDCF4306669C9E7E45C865 | SHA256:E3EE50E08124A7603BE7D996DCF596EB0D3F9C603768E86E003F7B942D7097F3 | |||
| 2524 | WinRAR.exe | C:\Users\admin\Desktop\FanControl\es\Microsoft.Win32.TaskScheduler.resources.dll | executable | |
MD5:15DB634B70D6D9D6CD41BAAE3F02EB14 | SHA256:E893C6907DA8D68C03B1A10E68B554AD5A8C0533F15912106F32E925F2BEABF0 | |||
| 2524 | WinRAR.exe | C:\Users\admin\Desktop\FanControl\pl\Microsoft.Win32.TaskScheduler.resources.dll | executable | |
MD5:B60817A69E314B22F746917C826DA53E | SHA256:6E58D86C42B61226DD7AF35D7C9432CE6F0982D1D0D5A2F4120E8ABC5C787A02 | |||
| 2524 | WinRAR.exe | C:\Users\admin\Desktop\FanControl\it\Microsoft.Win32.TaskScheduler.resources.dll | executable | |
MD5:1C331DA4BCE2809E16913C02E385576E | SHA256:1D0493E38D8B3FCC7EFA4916FEA1EEA69EE6449BF435E1869C1BC3F54D4090C5 | |||
| 2524 | WinRAR.exe | C:\Users\admin\Desktop\FanControl\zh-CN\Microsoft.Win32.TaskScheduler.resources.dll | executable | |
MD5:3CEFEC17BAAC089C54C8102A4CFD160C | SHA256:AAFBE48966DBC5372A308AB9501245CE261D2715F336AD1908C799D354C981A2 | |||
| 2524 | WinRAR.exe | C:\Users\admin\Desktop\FanControl\zh-Hant\Microsoft.Win32.TaskScheduler.resources.dll | executable | |
MD5:833F269BA6F0C34F49273DA7FBD7DCE7 | SHA256:F8C769A357E6CD27452835E5288FE515FB50BFEEC83EF3969975171174B467E5 | |||
| 2524 | WinRAR.exe | C:\Users\admin\Desktop\FanControl\FanControl.exe.config | xml | |
MD5:24ADD3F9146A78C73A123AB5D9ABD33C | SHA256:05A46B19F73FE30022C77FC45B37A521F18E70BCE9F75E87219B3692D1A7BE7B | |||
| 2524 | WinRAR.exe | C:\Users\admin\Desktop\FanControl\FanControl.exe | executable | |
MD5:07D98BDD62C93C3C4FB7B7432B21F436 | SHA256:C2048B6A0948D53B85D181F270D57EAD7622CC135252B6B5D4AA47E3101B91DD | |||
| 2524 | WinRAR.exe | C:\Users\admin\Desktop\FanControl\Autofac.dll | executable | |
MD5:EFDF8C3BC767A12924C0BA8BB5040077 | SHA256:7C01DB10615C750AFC9E711F2E2F9E9BF03B9B96586A904B54124C601FC1CBAE | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
— | — | 224.0.0.252:5355 | — | — | — | unknown |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |