| File name: | alien.skin.plugins.x86-x64-patch.rar |
| Full analysis: | https://app.any.run/tasks/d1aa453d-e785-4f55-941a-d992b7d083ff |
| Verdict: | Malicious activity |
| Analysis date: | December 29, 2022, 20:55:21 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-rar |
| File info: | RAR archive data, v4, os: Win32 |
| MD5: | 2FB83C549354DF91A9B78797F127F3B0 |
| SHA1: | D339C6D1C78B41500A5F9C43F9CD060017F8599F |
| SHA256: | C3FD16E0B07C0D1B31F2034FA62BC3E22D113ACE0EBBEFB052FEFB377F0DE8C2 |
| SSDEEP: | 6144:vXp4j3RtICVOQgc54hX0wm1R/m7AR1+iGy01IpdmPh3D6vJeOthvU/K:vXp4jhtIC/gc00n/mC1qz1BPZIIyhvUS |
| .rar | | | RAR compressed archive (v-4.x) (58.3) |
|---|---|---|
| .rar | | | RAR compressed archive (gen) (41.6) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 856 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\alien.skin.plugins.x86-x64-patch.rar" | C:\Program Files\WinRAR\WinRAR.exe | Explorer.EXE | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| 3352 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa856.32215\alien.skin.plugins.x86-x64-patch.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa856.32215\alien.skin.plugins.x86-x64-patch.exe | — | WinRAR.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 3221226540 Modules
| |||||||||||||||
| 3580 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa856.32215\alien.skin.plugins.x86-x64-patch.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa856.32215\alien.skin.plugins.x86-x64-patch.exe | WinRAR.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| (PID) Process: | (856) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (856) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (856) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\16D\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (856) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip | |||
| (PID) Process: | (856) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (856) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\alien.skin.plugins.x86-x64-patch.rar | |||
| (PID) Process: | (856) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (856) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (856) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (856) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3580 | alien.skin.plugins.x86-x64-patch.exe | C:\Users\admin\AppData\Local\Temp\bassmod.dll | executable | |
MD5:780D14604D49E3C634200C523DEF8351 | SHA256:844EB66A10B848D3A71A8C63C35F0A01550A46D2FF8503E2CA8947978B03B4D2 | |||
| 856 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa856.32215\alien.skin.plugins.x86-x64-patch.exe | executable | |
MD5:58A92B4897294E492CA4B1DA15717B5A | SHA256:55A1D2F415D00BEBC76B6D4A7D0088DAA58BFE3703BFE047A66E9FA4A5F9FDD4 | |||
| 3580 | alien.skin.plugins.x86-x64-patch.exe | C:\Users\admin\AppData\Local\Temp\dup2patcher.dll | executable | |
MD5:C2BC47FDC2AD7F45CDD3065B59CBD111 | SHA256:EEDEE2CF4F79DE919AA51A87B72A10C4C04E3B49BA1400119496E0602BA9D522 | |||