| File name: | SMADAV PRO LIFETIME (1).rar |
| Full analysis: | https://app.any.run/tasks/c7f7b414-ad2e-47a0-8371-93a8d973654b |
| Verdict: | Malicious activity |
| Threats: | A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection. |
| Analysis date: | March 30, 2018, 18:46:15 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-rar |
| File info: | RAR archive data, v4, os: Win32 |
| MD5: | E97D6E3941C84FB81629FFEADB55DE51 |
| SHA1: | 0E53B6D58B1DA54862B7CF3239A7BCE3172660A5 |
| SHA256: | C5A3358D4CFFA7D3D2019EBA3E6E4989E733BA3ECE00321099ED05C332F2CCAB |
| SSDEEP: | 49152:E9U9TukG5CGTpBdU1YHjt09lyVpcwxqPj:E9UJukG41sK9wVeUqr |
| .rar | | | RAR compressed archive (v-4.x) (58.3) |
|---|---|---|
| .rar | | | RAR compressed archive (gen) (41.6) |
| CompressedSize: | 247 |
|---|---|
| UncompressedSize: | 262 |
| OperatingSystem: | Win32 |
| ModifyDate: | 2017:08:02 07:40:06 |
| PackingMethod: | Normal |
| ArchivedFileName: | SMADAV PRO\App\Settings.reg |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 760 | "C:\Program Files\7-Zip\7zFM.exe" "C:\Users\admin\Desktop\SMADAV PRO LIFETIME (1).rar" | C:\Program Files\7-Zip\7zFM.exe | explorer.exe | ||||||||||||
User: admin Company: Igor Pavlov Integrity Level: MEDIUM Description: 7-Zip File Manager Exit code: 0 Version: 16.04 Modules
| |||||||||||||||
| 1364 | "C:\Users\admin\Desktop\SMADAV PRO\SMADAV PRO.exe" | C:\Users\admin\Desktop\SMADAV PRO\SMADAV PRO.exe | explorer.exe | ||||||||||||
User: admin Company: SaNet Integrity Level: HIGH Description: Smadav Pro Portable Exit code: 0 Version: 11.3.2.0 Modules
| |||||||||||||||
| 1476 | "taskhost.exe" | C:\Windows\System32\taskhost.exe | — | services.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Host Process for Windows Tasks Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1572 | "C:\Windows\system32\Dwm.exe" | C:\Windows\System32\dwm.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Desktop Window Manager Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1632 | C:\Windows\Explorer.EXE | C:\Windows\explorer.exe | — | — | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Explorer Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2224 | "C:\Users\admin\Desktop\SMADAV PRO\SMADAV PRO.exe" | C:\Users\admin\Desktop\SMADAV PRO\SMADAV PRO.exe | — | explorer.exe | |||||||||||
User: admin Company: SaNet Integrity Level: MEDIUM Description: Smadav Pro Portable Exit code: 3221226540 Version: 11.3.2.0 Modules
| |||||||||||||||
| 2388 | "C:\Users\admin\AppData\Roaming\Smadav\Update-Smadav.exe" /NOCLOSEAPPLICATIONS /VERYSILENT /SMADAVUPDATE | C:\Users\admin\AppData\Roaming\Smadav\Update-Smadav.exe | Smadav-Updater.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 2628 | "C:\Program Files\Smadav\SmadavProtect32.exe" | C:\Program Files\Smadav\SmadavProtect32.exe | — | SMΔRTP.exe | |||||||||||
User: admin Company: Smadav Software Integrity Level: HIGH Description: Smadav Whitelisting Protection Exit code: 0 Version: 1, 0, 0, 1 Modules
| |||||||||||||||
| 2708 | "C:\Program Files\Smadav\Smadav-Updater.exe" | C:\Program Files\Smadav\Smadav-Updater.exe | SMΔRTP.exe | ||||||||||||
User: admin Company: Smadsoft Integrity Level: HIGH Description: Smadav Updater Exit code: 0 Version: 1.05 Modules
| |||||||||||||||
| 2812 | "C:\Users\admin\AppData\Roaming\Smadav\Update1183\Smadav1183-Update.exe" slt | C:\Users\admin\AppData\Roaming\Smadav\Update1183\Smadav1183-Update.exe | Update-Smadav.exe | ||||||||||||
User: admin Company: Smadsoft Integrity Level: HIGH Description: Smadav USB Antivirus & Additional Protection Exit code: 0 Version: 4.118.0003 Modules
| |||||||||||||||
| (PID) Process: | (1632) explorer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Action Center\Checks\{C8E6F269-B90A-4053-A3BE-499AFCEC98C4}.check.0 |
| Operation: | write | Name: | CheckSetting |
Value: 23004100430042006C006F00620000000000000000000000010000000000000000000000 | |||
| (PID) Process: | (760) 7zFM.exe | Key: | HKEY_CURRENT_USER\Software\7-Zip\FM |
| Operation: | write | Name: | CopyHistory |
Value: 43003A005C00550073006500720073005C00610064006D0069006E005C004400650073006B0074006F0070005C000000 | |||
| (PID) Process: | (760) 7zFM.exe | Key: | HKEY_CURRENT_USER\Software\7-Zip\FM\Columns |
| Operation: | write | Name: | 7-Zip.Rar |
Value: 0100000004000000010000000400000001000000A00000000700000001000000640000000800000001000000640000000C00000001000000640000000A00000001000000640000000B00000001000000640000000900000001000000640000000F00000001000000640000000D00000001000000640000000E00000001000000640000001000000001000000640000001100000001000000640000001300000001000000640000001700000001000000640000001600000001000000640000002100000001000000640000001F0000000100000064000000200000000100000064000000 | |||
| (PID) Process: | (1632) explorer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count |
| Operation: | write | Name: | {7P5N40RS-N0SO-4OSP-874N-P0S2R0O9SN8R}\7-Mvc\7mSZ.rkr |
Value: 00000000000000000000000000000000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF000000000000000000000000 | |||
| (PID) Process: | (1632) explorer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count |
| Operation: | write | Name: | HRZR_PGYFRFFVBA |
Value: 000000000A0000001B000000247C0700020000000E000000633103007B00460033003800420046003400300034002D0031004400340033002D0034003200460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E00650078006500000000000000F0E43102FFFFFFFF888B0E00FFFFFFFF9049717500000000000000008CE43102D5746D750004000000000000F0E43102FFFFFFFF888B0E00FFFFFFFF38840E007C840E00808B0E00BCE431022FB1687680B09B76FCF13102381E69761463697610180D00F0E431020000000070000000DEA5C579D0E43102BE6A697610180D00F0E4310200000000FCE631026F62697610180D00F0E4310200000400000000807C62697610180D0063003A005C00750073006500720073005C00610064006D0069006E005C0061007000700064006100740061005C0072006F0061006D0069006E0067005C006D006900630072006F0073006F00660074005C0069006E007400650072006E006500740020006500780070006C006F007200650072005C0071007500690063006B0020006C00610075006E0063001100000010470D0008470D002000700069006E006E00650064005C0008E60000C2A4C579B8E531028291697608E63102BCE5310227956976000000005CC51500E4E53102CD9469765CC5150090E63102D0C01500E194697600000000D0C0150090E63102ECE53102020000000E000000633103007B00460033003800420046003400300034002D0031004400340033002D0034003200460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E00650078006500000000000000F0E43102FFFFFFFF888B0E00FFFFFFFF9049717500000000000000008CE43102D5746D750004000000000000F0E43102FFFFFFFF888B0E00FFFFFFFF38840E007C840E00808B0E00BCE431022FB1687680B09B76FCF13102381E69761463697610180D00F0E431020000000070000000DEA5C579D0E43102BE6A697610180D00F0E4310200000000FCE631026F62697610180D00F0E4310200000400000000807C62697610180D0063003A005C00750073006500720073005C00610064006D0069006E005C0061007000700064006100740061005C0072006F0061006D0069006E0067005C006D006900630072006F0073006F00660074005C0069006E007400650072006E006500740020006500780070006C006F007200650072005C0071007500690063006B0020006C00610075006E0063001100000010470D0008470D002000700069006E006E00650064005C0008E60000C2A4C579B8E531028291697608E63102BCE5310227956976000000005CC51500E4E53102CD9469765CC5150090E63102D0C01500E194697600000000D0C0150090E63102ECE53102020000000E000000633103007B00460033003800420046003400300034002D0031004400340033002D0034003200460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E00650078006500000000000000F0E43102FFFFFFFF888B0E00FFFFFFFF9049717500000000000000008CE43102D5746D750004000000000000F0E43102FFFFFFFF888B0E00FFFFFFFF38840E007C840E00808B0E00BCE431022FB1687680B09B76FCF13102381E69761463697610180D00F0E431020000000070000000DEA5C579D0E43102BE6A697610180D00F0E4310200000000FCE631026F62697610180D00F0E4310200000400000000807C62697610180D0063003A005C00750073006500720073005C00610064006D0069006E005C0061007000700064006100740061005C0072006F0061006D0069006E0067005C006D006900630072006F0073006F00660074005C0069006E007400650072006E006500740020006500780070006C006F007200650072005C0071007500690063006B0020006C00610075006E0063001100000010470D0008470D002000700069006E006E00650064005C0008E60000C2A4C579B8E531028291697608E63102BCE5310227956976000000005CC51500E4E53102CD9469765CC5150090E63102D0C01500E194697600000000D0C0150090E63102ECE53102 | |||
| (PID) Process: | (1632) explorer.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU |
| Operation: | write | Name: | NodeSlots |
Value: 02020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202 | |||
| (PID) Process: | (1632) explorer.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU |
| Operation: | write | Name: | MRUListEx |
Value: 01000000020000000000000009000000080000000300000006000000070000000500000004000000FFFFFFFF | |||
| (PID) Process: | (3972) SearchProtocolHost.exe | Key: | HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\8F\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3972) SearchProtocolHost.exe | Key: | HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\8F\52C64B7E |
| Operation: | write | Name: | @C:\Windows\system32\notepad.exe,-469 |
Value: Text Document | |||
| (PID) Process: | (3972) SearchProtocolHost.exe | Key: | HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\8F\52C64B7E |
| Operation: | write | Name: | @C:\Windows\regedit.exe,-309 |
Value: Registration Entries | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 760 | 7zFM.exe | C:\Users\admin\Desktop\SMADAV PRO\App\Smadav-Updater.exe | executable | |
MD5:— | SHA256:— | |||
| 760 | 7zFM.exe | C:\Users\admin\Desktop\SMADAV PRO\App\Smadav.loov | binary | |
MD5:— | SHA256:— | |||
| 760 | 7zFM.exe | C:\Users\admin\Desktop\SMADAV PRO\App\SmadavProtect64.exe | executable | |
MD5:— | SHA256:— | |||
| 760 | 7zFM.exe | C:\Users\admin\Desktop\SMADAV PRO\App\Settings.reg | text | |
MD5:— | SHA256:— | |||
| 3856 | SM_RTP.exe | C:\Users\admin\AppData\Local\Temp\Smadav.lnk | — | |
MD5:— | SHA256:— | |||
| 760 | 7zFM.exe | C:\Users\admin\Desktop\SMADAV PRO\SMADAV PRO.exe | executable | |
MD5:— | SHA256:— | |||
| 760 | 7zFM.exe | C:\Users\admin\Desktop\SMADAV PRO\App\SmadavProtect32.exe | executable | |
MD5:B830CD1B49BD31BCDB6192C20CF0B141 | SHA256:21D34A02EC28E9BD6F7B2F96AC7921F5EF08D291416B38A3FC8CF651F11FC820 | |||
| 3012 | SMΔRTP.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GZH9GIXH\smadstat[1].htm | — | |
MD5:— | SHA256:— | |||
| 3012 | SMΔRTP.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GZH9GIXH\secure-smadav[1].txt | — | |
MD5:— | SHA256:— | |||
| 2708 | Smadav-Updater.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GZH9GIXH\extrasecure-smadav[1].htm | — | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | GET | 200 | 50.63.161.112:80 | http://www.lempar.com/update/secure-smadav.txt | US | text | 392 b | malicious |
— | — | GET | 200 | 50.63.161.112:80 | http://www.lempar.com/update/extrasecure-smadav.txt/ | US | text | 394 b | malicious |
— | — | GET | — | 208.113.220.122:80 | http://sistemcerdas.com/smadav1183.update | US | — | — | unknown |
— | — | GET | 200 | 50.63.161.112:80 | http://lempar.com/smadstat.php?mac=1994429369&key=691233764412&name=KillDozer+%28SaNet%2Ecd%29&os=2%2E6%2E1%2E7601&build=871&old=-1&mode=1&stat1=777&stat2=1&stat3=0&stat4=3&stat5=8002&stat6=6 | US | binary | 1 b | malicious |
— | — | GET | 200 | 132.148.148.111:80 | http://prblm.com/smadav1183.update | US | executable | 1.39 Mb | unknown |
— | — | GET | 301 | 50.63.161.112:80 | http://www.lempar.com/update/extrasecure-smadav.txt | US | html | 260 b | malicious |
— | — | GET | 200 | 50.63.161.112:80 | http://www.lempar.com/update/secure-smadav.txt | US | text | 392 b | malicious |
— | — | GET | 200 | 50.63.161.112:80 | http://www.lempar.com/update/secure-smadav.txt | US | text | 392 b | malicious |
— | — | GET | 200 | 50.63.161.112:80 | http://lempar.com/smadstat.php?mac=1994429369A561640&key=691233764412&name=KillDozer+%28SaNet%2Ecd%29&os=2%2E6%2E1%2E7601&build=903&old=871&mode=1&stat1=777&stat2=1&stat3=0&stat4=3&stat5=8002&stat6=6 | US | binary | 1 b | malicious |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 50.63.161.112:80 | lempar.com | GoDaddy.com, LLC | US | malicious |
— | — | 208.113.220.122:80 | sistemcerdas.com | New Dream Network, LLC | US | unknown |
— | — | 132.148.148.111:80 | prblm.com | GoDaddy.com, LLC | US | unknown |
Domain | IP | Reputation |
|---|---|---|
lempar.com |
| malicious |
www.lempar.com |
| malicious |
sistemcerdas.com |
| unknown |
prblm.com |
| unknown |
PID | Process | Class | Message |
|---|---|---|---|
— | — | Potential Corporate Privacy Violation | ET POLICY PE EXE or DLL Windows file download HTTP |
— | — | A Network Trojan was detected | ET CURRENT_EVENTS Likely Evil EXE download from MSXMLHTTP non-exe extension M2 |