| File name: | DLL错误专修工具_T3T5976.exe.zip |
| Full analysis: | https://app.any.run/tasks/883ac76e-7378-47b8-8d02-36ccb3918475 |
| Verdict: | Malicious activity |
| Analysis date: | March 02, 2024, 18:56:36 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract, compression method=deflate |
| MD5: | 163BD2A015B550B34514EA668DC87FF5 |
| SHA1: | 6162313379EC0CF4C5543DE245054688523D5287 |
| SHA256: | BEA354C8121B4D3CB7A1E50F908C7D636E2E7EA37A61F025129AB3605B9913A4 |
| SSDEEP: | 49152:Xproj+d5bvKNz1mrnHH0isVrhUVoEeRBVKjNX1D6bxqr6VmWDFKybivJDZuJvuWV:55qm7n0isVrhUVolKlp6FqmM8cQQZZST |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 20 |
|---|---|
| ZipBitFlag: | 0x0800 |
| ZipCompression: | Deflated |
| ZipModifyDate: | 2024:02:02 03:17:24 |
| ZipCRC: | 0x3639d0e9 |
| ZipCompressedSize: | 1419627 |
| ZipUncompressedSize: | 3192248 |
| ZipFileName: | DLL错误专修工具_T3T5976.exe |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1496 | "C:\Users\admin\AppData\Local\DLL综合解决工具\dllrepair_win.exe" -runas | C:\Users\admin\AppData\Local\DLL综合解决工具\dllrepair_win.exe | dllrepair_win.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 2572 | "C:\Users\admin\Desktop\DLL错误专修工具_T3T5976.exe" | C:\Users\admin\Desktop\DLL错误专修工具_T3T5976.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: 一键修复DLL Exit code: 0 Version: 2.0.1.7 Modules
| |||||||||||||||
| 2756 | "C:\Users\admin\AppData\Local\DLL综合解决工具\dllrepair_win.exe" "" | C:\Users\admin\AppData\Local\DLL综合解决工具\dllrepair_win.exe | — | DLL错误专修工具_T3T5976.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 3668 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\DLL错误专修工具_T3T5976.exe.zip" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| 3732 | "C:\Users\admin\Desktop\DLL错误专修工具_T3T5976.exe" | C:\Users\admin\Desktop\DLL错误专修工具_T3T5976.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: 一键修复DLL Exit code: 3221226540 Version: 2.0.1.7 Modules
| |||||||||||||||
| (PID) Process: | (3668) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (3668) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (3668) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3668) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\phacker.zip | |||
| (PID) Process: | (3668) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (3668) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip | |||
| (PID) Process: | (3668) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\DLL错误专修工具_T3T5976.exe.zip | |||
| (PID) Process: | (3668) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (3668) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (3668) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3668 | WinRAR.exe | C:\Users\admin\Desktop\checksums.txt | text | |
MD5:5437403D21E0F257E6FF914080553397 | SHA256:358606342D392D043705069852934FCE2C35AE1A042BCDED6D15528CA28593B5 | |||
| 2572 | DLL错误专修工具_T3T5976.exe | C:\Users\admin\AppData\Local\DLL综合解决工具\bin\Qt5Core.dll | executable | |
MD5:A3E3CA2DC518EC0014E6493336E0D343 | SHA256:B67674280801E2823BA87D15EC6341A2ABA241ACF78D609407CB4ECE73B08F99 | |||
| 2572 | DLL错误专修工具_T3T5976.exe | C:\Users\admin\AppData\Local\DLL综合解决工具\bin\QCommonUI.dll | executable | |
MD5:1752ADE1202FB41EFD89B356147F5777 | SHA256:62067760F7BFA2FBC200D13B3C97C4158B00132A95E9FB80BD8F82B5A60D72B6 | |||
| 2572 | DLL错误专修工具_T3T5976.exe | C:\Users\admin\AppData\Local\DLL综合解决工具\bin\7z.dll | executable | |
MD5:21F6DBF0E4A4AC9CDE24DED06A8FC509 | SHA256:366FAEB98DC10E0453337D60940F8C4EF3FEDB7B6B7B3EB047490F35B3EF5A54 | |||
| 2572 | DLL错误专修工具_T3T5976.exe | C:\Users\admin\AppData\Local\Temp\dllrepair_win.zip | compressed | |
MD5:533EBF42ADDC179AF37FFADFE01863B5 | SHA256:BF0CD0FA8E309625893E36F5A9FF5B26A0AA92D39B3F973D417DDDCDB1114C5B | |||
| 3668 | WinRAR.exe | C:\Users\admin\Desktop\DLL错误专修工具_T3T5976.exe | executable | |
MD5:F6989E53C2CBA29C31FA545C931599E0 | SHA256:B5E5ED6732D149485FDA09A04C5D934A76E7D4A274539DCC0A2A6F87A81FC7B6 | |||
| 2572 | DLL错误专修工具_T3T5976.exe | C:\Users\admin\AppData\Local\DLL综合解决工具\bin\7z.exe | executable | |
MD5:ED2CEE859B802452B5BA2A7987A0954E | SHA256:B1C7BB12DDA1C6D5ED678A73697983CA8833D7E747540184FD35AE9B690B4F68 | |||
| 2572 | DLL错误专修工具_T3T5976.exe | C:\Users\admin\AppData\Local\DLL综合解决工具\bin\Qt5Network.dll | executable | |
MD5:89CC35D5F340F0749DC6EC35E1AF9BE4 | SHA256:74C4E14E06FBACBA2CD27C9CC1CE19617AADC785752FF476D8CB08B7EF52943E | |||
| 2572 | DLL错误专修工具_T3T5976.exe | C:\Users\admin\AppData\Local\DLL综合解决工具\bin\Qt5Gui.dll | executable | |
MD5:F11735393001E109AC21D075E9A187CC | SHA256:CC3F090AB06B8F14626891791768AE16170DF8A0DEAAE12C6EF5CCC8BD08454F | |||
| 2572 | DLL错误专修工具_T3T5976.exe | C:\Users\admin\AppData\Local\DLL综合解决工具\bin\api-ms-win-core-file-l2-1-0.dll | executable | |
MD5:F2CD3227975BD33AE08E34221D223CA6 | SHA256:F88209BB4993BFBCFC9727D101A4F1ECF84649CA5FD15B264FAAC11DAF19AC7F | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2572 | DLL错误专修工具_T3T5976.exe | GET | 200 | 111.170.26.41:80 | http://api.kuaixunda.cn/api/report/preinstall?soft_id=dllrepair_win&curr_ver=2.0.1.7&source=T3T5976&device_code=E3C6F2B3C4D546698DE6CCA08D365126da&kid= | unknown | binary | 41 b | unknown |
2572 | DLL错误专修工具_T3T5976.exe | GET | 200 | 171.107.86.41:80 | http://api.kuaixunda.cn/api/report/install?soft_id=dllrepair_win&curr_ver=2.0.1.7&source=T3T5976&device_code=E3C6F2B3C4D546698DE6CCA08D365126da&kid= | unknown | binary | 41 b | unknown |
2572 | DLL错误专修工具_T3T5976.exe | GET | 200 | 163.181.56.213:80 | http://cdn-inst.hoposoft.com/dllrepair/dllrepair2.0.1.7.zip | unknown | compressed | 29.0 Mb | unknown |
2572 | DLL错误专修工具_T3T5976.exe | GET | 200 | 111.170.22.41:80 | http://api.kuaixunda.cn/api/config/soft_down?soft_id=dllrepair_win&source=T3T5976 | unknown | binary | 249 b | unknown |
2572 | DLL错误专修工具_T3T5976.exe | GET | 200 | 171.107.86.41:80 | http://api.kuaixunda.cn/api/report/event?soft_id=dllrepair_win&curr_ver=2.0.1.7&source=T3T5976&device_code=E3C6F2B3C4D546698DE6CCA08D365126da&event_id=install_end&kid= | unknown | binary | 41 b | unknown |
1496 | dllrepair_win.exe | POST | 200 | 180.97.198.41:80 | http://api.kuaixunda.cn/api/report/online?curr_ver=2.0.0.1&soft_id=dllrepair_win&mac_code=W08994C5DB24&os=1&source=T3T5976&device_code=E3C6F2B3C4D546698DE6CCA08D365126da&source_soft_id=dllrepair_win&token=&api_version=2&ekey=9286hko6oc3n1768 | unknown | binary | 41 b | unknown |
1496 | dllrepair_win.exe | GET | 200 | 180.97.198.41:80 | http://api.kuaixunda.cn/api/product/info/dllrepair_win/?site=1&soft_id=dllrepair_win&mac_code=W08994C5DB24&os=1&source=T3T5976&device_code=E3C6F2B3C4D546698DE6CCA08D365126da&source_soft_id=dllrepair_win&token=&api_version=2&ekey=9286hko6oc3n1768 | unknown | binary | 747 b | unknown |
1496 | dllrepair_win.exe | GET | 200 | 180.97.198.41:80 | http://api.kuaixunda.cn/api/config/update?curr_ver=2.0.0.1&soft_id=dllrepair_win&mac_code=W08994C5DB24&os=1&source=T3T5976&device_code=E3C6F2B3C4D546698DE6CCA08D365126da&source_soft_id=dllrepair_win&token=&api_version=2&ekey=9286hko6oc3n1768 | unknown | binary | 57 b | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
2572 | DLL错误专修工具_T3T5976.exe | 111.170.22.41:80 | api.kuaixunda.cn | Chinanet | CN | unknown |
2572 | DLL错误专修工具_T3T5976.exe | 111.170.26.41:80 | api.kuaixunda.cn | Chinanet | CN | unknown |
2572 | DLL错误专修工具_T3T5976.exe | 171.107.86.41:80 | api.kuaixunda.cn | CHINATELECOM Guangxi Nanning IDC networkdescr: NanningGuangxi Province, P.R.China. | CN | unknown |
2572 | DLL错误专修工具_T3T5976.exe | 163.181.56.213:80 | cdn-inst.hoposoft.com | Zhejiang Taobao Network Co.,Ltd | DE | unknown |
1496 | dllrepair_win.exe | 180.97.198.41:80 | api.kuaixunda.cn | CHINATELECOM Jiangsu province Suzhou 5G network | CN | unknown |
Domain | IP | Reputation |
|---|---|---|
api.kuaixunda.cn |
| unknown |
cdn-inst.hoposoft.com |
| unknown |
Process | Message |
|---|---|
dllrepair_win.exe | QObject::connect: Cannot connect HRequest::jsonFinished(bool, const QValue&, const QString&) to (null)::(null)
|
dllrepair_win.exe | QString::arg: Argument missing: "QLabel{border:none;font-size: 15px;font-family: Microsoft YaHei;color:#313131;}" , 14
|