File name:

DLL错误专修工具_T3T5976.exe.zip

Full analysis: https://app.any.run/tasks/883ac76e-7378-47b8-8d02-36ccb3918475
Verdict: Malicious activity
Analysis date: March 02, 2024, 18:56:36
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=deflate
MD5:

163BD2A015B550B34514EA668DC87FF5

SHA1:

6162313379EC0CF4C5543DE245054688523D5287

SHA256:

BEA354C8121B4D3CB7A1E50F908C7D636E2E7EA37A61F025129AB3605B9913A4

SSDEEP:

49152:Xproj+d5bvKNz1mrnHH0isVrhUVoEeRBVKjNX1D6bxqr6VmWDFKybivJDZuJvuWV:55qm7n0isVrhUVolKlp6FqmM8cQQZZST

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 3668)
      • DLL错误专修工具_T3T5976.exe (PID: 2572)
  • SUSPICIOUS

    • Searches for installed software

      • DLL错误专修工具_T3T5976.exe (PID: 2572)
    • Executable content was dropped or overwritten

      • DLL错误专修工具_T3T5976.exe (PID: 2572)
    • The process drops C-runtime libraries

      • DLL错误专修工具_T3T5976.exe (PID: 2572)
    • Drops 7-zip archiver for unpacking

      • DLL错误专修工具_T3T5976.exe (PID: 2572)
    • Process drops legitimate windows executable

      • DLL错误专修工具_T3T5976.exe (PID: 2572)
    • Creates a software uninstall entry

      • DLL错误专修工具_T3T5976.exe (PID: 2572)
    • Reads the Internet Settings

      • dllrepair_win.exe (PID: 2756)
    • Reads security settings of Internet Explorer

      • dllrepair_win.exe (PID: 2756)
    • Application launched itself

      • dllrepair_win.exe (PID: 2756)
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3668)
    • Checks supported languages

      • DLL错误专修工具_T3T5976.exe (PID: 2572)
      • dllrepair_win.exe (PID: 2756)
      • dllrepair_win.exe (PID: 1496)
    • Reads the computer name

      • DLL错误专修工具_T3T5976.exe (PID: 2572)
      • dllrepair_win.exe (PID: 2756)
      • dllrepair_win.exe (PID: 1496)
    • Manual execution by a user

      • DLL错误专修工具_T3T5976.exe (PID: 3732)
      • DLL错误专修工具_T3T5976.exe (PID: 2572)
    • Create files in a temporary directory

      • DLL错误专修工具_T3T5976.exe (PID: 2572)
    • Creates files or folders in the user directory

      • DLL错误专修工具_T3T5976.exe (PID: 2572)
      • dllrepair_win.exe (PID: 1496)
    • Reads the machine GUID from the registry

      • dllrepair_win.exe (PID: 1496)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: 0x0800
ZipCompression: Deflated
ZipModifyDate: 2024:02:02 03:17:24
ZipCRC: 0x3639d0e9
ZipCompressedSize: 1419627
ZipUncompressedSize: 3192248
ZipFileName: DLL错误专修工具_T3T5976.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
46
Monitored processes
5
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe dll错误专修工具_t3t5976.exe no specs dll错误专修工具_t3t5976.exe dllrepair_win.exe no specs dllrepair_win.exe

Process information

PID
CMD
Path
Indicators
Parent process
1496"C:\Users\admin\AppData\Local\DLL综合解决工具\dllrepair_win.exe" -runasC:\Users\admin\AppData\Local\DLL综合解决工具\dllrepair_win.exe
dllrepair_win.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\dll综合解决工具\dllrepair_win.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\wkscli.dll
2572"C:\Users\admin\Desktop\DLL错误专修工具_T3T5976.exe" C:\Users\admin\Desktop\DLL错误专修工具_T3T5976.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Description:
一键修复DLL
Exit code:
0
Version:
2.0.1.7
Modules
Images
c:\users\admin\desktop\dll错误专修工具_t3t5976.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2756"C:\Users\admin\AppData\Local\DLL综合解决工具\dllrepair_win.exe" "" C:\Users\admin\AppData\Local\DLL综合解决工具\dllrepair_win.exeDLL错误专修工具_T3T5976.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\dll综合解决工具\dllrepair_win.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\wkscli.dll
3668"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\DLL错误专修工具_T3T5976.exe.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3732"C:\Users\admin\Desktop\DLL错误专修工具_T3T5976.exe" C:\Users\admin\Desktop\DLL错误专修工具_T3T5976.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
一键修复DLL
Exit code:
3221226540
Version:
2.0.1.7
Modules
Images
c:\users\admin\desktop\dll错误专修工具_t3t5976.exe
c:\windows\system32\ntdll.dll
Total events
10 072
Read events
10 041
Write events
31
Delete events
0

Modification events

(PID) Process:(3668) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3668) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3668) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3668) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(3668) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(3668) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(3668) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\DLL错误专修工具_T3T5976.exe.zip
(PID) Process:(3668) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3668) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3668) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
Executable files
56
Suspicious files
4
Text files
13
Unknown types
2

Dropped files

PID
Process
Filename
Type
3668WinRAR.exeC:\Users\admin\Desktop\checksums.txttext
MD5:5437403D21E0F257E6FF914080553397
SHA256:358606342D392D043705069852934FCE2C35AE1A042BCDED6D15528CA28593B5
2572DLL错误专修工具_T3T5976.exeC:\Users\admin\AppData\Local\DLL综合解决工具\bin\Qt5Core.dllexecutable
MD5:A3E3CA2DC518EC0014E6493336E0D343
SHA256:B67674280801E2823BA87D15EC6341A2ABA241ACF78D609407CB4ECE73B08F99
2572DLL错误专修工具_T3T5976.exeC:\Users\admin\AppData\Local\DLL综合解决工具\bin\QCommonUI.dllexecutable
MD5:1752ADE1202FB41EFD89B356147F5777
SHA256:62067760F7BFA2FBC200D13B3C97C4158B00132A95E9FB80BD8F82B5A60D72B6
2572DLL错误专修工具_T3T5976.exeC:\Users\admin\AppData\Local\DLL综合解决工具\bin\7z.dllexecutable
MD5:21F6DBF0E4A4AC9CDE24DED06A8FC509
SHA256:366FAEB98DC10E0453337D60940F8C4EF3FEDB7B6B7B3EB047490F35B3EF5A54
2572DLL错误专修工具_T3T5976.exeC:\Users\admin\AppData\Local\Temp\dllrepair_win.zipcompressed
MD5:533EBF42ADDC179AF37FFADFE01863B5
SHA256:BF0CD0FA8E309625893E36F5A9FF5B26A0AA92D39B3F973D417DDDCDB1114C5B
3668WinRAR.exeC:\Users\admin\Desktop\DLL错误专修工具_T3T5976.exeexecutable
MD5:F6989E53C2CBA29C31FA545C931599E0
SHA256:B5E5ED6732D149485FDA09A04C5D934A76E7D4A274539DCC0A2A6F87A81FC7B6
2572DLL错误专修工具_T3T5976.exeC:\Users\admin\AppData\Local\DLL综合解决工具\bin\7z.exeexecutable
MD5:ED2CEE859B802452B5BA2A7987A0954E
SHA256:B1C7BB12DDA1C6D5ED678A73697983CA8833D7E747540184FD35AE9B690B4F68
2572DLL错误专修工具_T3T5976.exeC:\Users\admin\AppData\Local\DLL综合解决工具\bin\Qt5Network.dllexecutable
MD5:89CC35D5F340F0749DC6EC35E1AF9BE4
SHA256:74C4E14E06FBACBA2CD27C9CC1CE19617AADC785752FF476D8CB08B7EF52943E
2572DLL错误专修工具_T3T5976.exeC:\Users\admin\AppData\Local\DLL综合解决工具\bin\Qt5Gui.dllexecutable
MD5:F11735393001E109AC21D075E9A187CC
SHA256:CC3F090AB06B8F14626891791768AE16170DF8A0DEAAE12C6EF5CCC8BD08454F
2572DLL错误专修工具_T3T5976.exeC:\Users\admin\AppData\Local\DLL综合解决工具\bin\api-ms-win-core-file-l2-1-0.dllexecutable
MD5:F2CD3227975BD33AE08E34221D223CA6
SHA256:F88209BB4993BFBCFC9727D101A4F1ECF84649CA5FD15B264FAAC11DAF19AC7F
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
8
TCP/UDP connections
12
DNS requests
6
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2572
DLL错误专修工具_T3T5976.exe
GET
200
111.170.26.41:80
http://api.kuaixunda.cn/api/report/preinstall?soft_id=dllrepair_win&curr_ver=2.0.1.7&source=T3T5976&device_code=E3C6F2B3C4D546698DE6CCA08D365126da&kid=
unknown
binary
41 b
unknown
2572
DLL错误专修工具_T3T5976.exe
GET
200
171.107.86.41:80
http://api.kuaixunda.cn/api/report/install?soft_id=dllrepair_win&curr_ver=2.0.1.7&source=T3T5976&device_code=E3C6F2B3C4D546698DE6CCA08D365126da&kid=
unknown
binary
41 b
unknown
2572
DLL错误专修工具_T3T5976.exe
GET
200
163.181.56.213:80
http://cdn-inst.hoposoft.com/dllrepair/dllrepair2.0.1.7.zip
unknown
compressed
29.0 Mb
unknown
2572
DLL错误专修工具_T3T5976.exe
GET
200
111.170.22.41:80
http://api.kuaixunda.cn/api/config/soft_down?soft_id=dllrepair_win&source=T3T5976
unknown
binary
249 b
unknown
2572
DLL错误专修工具_T3T5976.exe
GET
200
171.107.86.41:80
http://api.kuaixunda.cn/api/report/event?soft_id=dllrepair_win&curr_ver=2.0.1.7&source=T3T5976&device_code=E3C6F2B3C4D546698DE6CCA08D365126da&event_id=install_end&kid=
unknown
binary
41 b
unknown
1496
dllrepair_win.exe
POST
200
180.97.198.41:80
http://api.kuaixunda.cn/api/report/online?curr_ver=2.0.0.1&soft_id=dllrepair_win&mac_code=W08994C5DB24&os=1&source=T3T5976&device_code=E3C6F2B3C4D546698DE6CCA08D365126da&source_soft_id=dllrepair_win&token=&api_version=2&ekey=9286hko6oc3n1768
unknown
binary
41 b
unknown
1496
dllrepair_win.exe
GET
200
180.97.198.41:80
http://api.kuaixunda.cn/api/product/info/dllrepair_win/?site=1&soft_id=dllrepair_win&mac_code=W08994C5DB24&os=1&source=T3T5976&device_code=E3C6F2B3C4D546698DE6CCA08D365126da&source_soft_id=dllrepair_win&token=&api_version=2&ekey=9286hko6oc3n1768
unknown
binary
747 b
unknown
1496
dllrepair_win.exe
GET
200
180.97.198.41:80
http://api.kuaixunda.cn/api/config/update?curr_ver=2.0.0.1&soft_id=dllrepair_win&mac_code=W08994C5DB24&os=1&source=T3T5976&device_code=E3C6F2B3C4D546698DE6CCA08D365126da&source_soft_id=dllrepair_win&token=&api_version=2&ekey=9286hko6oc3n1768
unknown
binary
57 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
2572
DLL错误专修工具_T3T5976.exe
111.170.22.41:80
api.kuaixunda.cn
Chinanet
CN
unknown
2572
DLL错误专修工具_T3T5976.exe
111.170.26.41:80
api.kuaixunda.cn
Chinanet
CN
unknown
2572
DLL错误专修工具_T3T5976.exe
171.107.86.41:80
api.kuaixunda.cn
CHINATELECOM Guangxi Nanning IDC networkdescr: NanningGuangxi Province, P.R.China.
CN
unknown
2572
DLL错误专修工具_T3T5976.exe
163.181.56.213:80
cdn-inst.hoposoft.com
Zhejiang Taobao Network Co.,Ltd
DE
unknown
1496
dllrepair_win.exe
180.97.198.41:80
api.kuaixunda.cn
CHINATELECOM Jiangsu province Suzhou 5G network
CN
unknown

DNS requests

Domain
IP
Reputation
api.kuaixunda.cn
  • 111.170.26.41
  • 113.105.172.41
  • 171.107.86.41
  • 140.249.244.41
  • 124.238.241.41
  • 111.170.22.41
  • 106.225.194.41
  • 180.97.198.41
  • 123.184.58.41
  • 124.225.184.41
unknown
cdn-inst.hoposoft.com
  • 163.181.56.213
  • 163.181.56.210
  • 163.181.56.209
  • 163.181.56.215
  • 163.181.56.211
  • 163.181.56.216
  • 163.181.56.212
  • 163.181.56.214
unknown

Threats

No threats detected
Process
Message
dllrepair_win.exe
QObject::connect: Cannot connect HRequest::jsonFinished(bool, const QValue&, const QString&) to (null)::(null)
dllrepair_win.exe
QString::arg: Argument missing: "QLabel{border:none;font-size: 15px;font-family: Microsoft YaHei;color:#313131;}" , 14