File name:

IDM_6.4x_Crack_v19.7.zip

Full analysis: https://app.any.run/tasks/60eec92a-759c-4edb-87c8-c79be830bf6b
Verdict: Malicious activity
Analysis date: April 19, 2024, 19:31:11
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=AES Encrypted
MD5:

56368E8804E290A002F1EFCA0586F7D5

SHA1:

1A6163F79A45CABE2DA7757B2151C93716890FD2

SHA256:

C684DF9AB4958FD7FFC618076D6351ED825AA7573C7ECBAD1FED739DB2D91714

SSDEEP:

1536:Nhqww/puA8voPBEvQmXBPhfmR7QdtiKBhfm6Or8SFiaMGU:37w/puA8mBE4mxeQywhenrHOGU

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Reads the value of a key from the registry (SCRIPT)

      • wscript.exe (PID: 3488)
    • Accesses environment variables (SCRIPT)

      • wscript.exe (PID: 3488)
    • Deletes a file (SCRIPT)

      • wscript.exe (PID: 3488)
  • SUSPICIOUS

    • Reads the Internet Settings

      • IDM_6.4x_Crack_v19.7.exe (PID: 3244)
    • The process executes VB scripts

      • IDM_6.4x_Crack_v19.7.exe (PID: 3244)
    • Creates FileSystem object to access computer's file system (SCRIPT)

      • wscript.exe (PID: 3488)
    • Uses REG/REGEDIT.EXE to modify registry

      • IDM_6.4x_Crack_v19.7.exe (PID: 3244)
      • cmd.exe (PID: 2960)
      • cmd.exe (PID: 3036)
    • Gets full path of the running script (SCRIPT)

      • wscript.exe (PID: 3488)
    • Starts CMD.EXE for commands execution

      • IDM_6.4x_Crack_v19.7.exe (PID: 3244)
      • cmd.exe (PID: 2960)
    • Executing commands from a ".bat" file

      • IDM_6.4x_Crack_v19.7.exe (PID: 3244)
      • cmd.exe (PID: 2960)
    • Possibly malicious use of IEX has been detected

      • cmd.exe (PID: 2960)
    • Application launched itself

      • cmd.exe (PID: 2960)
    • Probably obfuscated PowerShell command line is found

      • cmd.exe (PID: 2960)
    • Starts POWERSHELL.EXE for commands execution

      • cmd.exe (PID: 2960)
      • cmd.exe (PID: 3588)
      • cmd.exe (PID: 1604)
    • Hides command output

      • cmd.exe (PID: 3588)
      • cmd.exe (PID: 3036)
    • Reads security settings of Internet Explorer

      • IDM_6.4x_Crack_v19.7.exe (PID: 3244)
    • Starts application with an unusual extension

      • cmd.exe (PID: 2960)
  • INFO

    • Application launched itself

      • msedge.exe (PID: 884)
      • msedge.exe (PID: 3404)
      • chrome.exe (PID: 3236)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3416)
    • Checks supported languages

      • IDM_6.4x_Crack_v19.7.exe (PID: 3244)
      • chcp.com (PID: 4048)
    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 3416)
    • Manual execution by a user

      • IDM_6.4x_Crack_v19.7.exe (PID: 3244)
      • IDM_6.4x_Crack_v19.7.exe (PID: 2132)
      • msedge.exe (PID: 3404)
      • explorer.exe (PID: 2512)
    • Reads the computer name

      • IDM_6.4x_Crack_v19.7.exe (PID: 3244)
    • Create files in a temporary directory

      • IDM_6.4x_Crack_v19.7.exe (PID: 3244)
      • reg.exe (PID: 864)
    • Checks whether the specified file exists (POWERSHELL)

      • powershell.exe (PID: 2324)
      • powershell.exe (PID: 3612)
    • Checks operating system version

      • cmd.exe (PID: 2960)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: 0x0009
ZipCompression: Unknown (99)
ZipModifyDate: 2024:04:10 22:42:52
ZipCRC: 0xf4afa791
ZipCompressedSize: 57015
ZipUncompressedSize: 60928
ZipFileName: IDM_6.4x_Crack_v19.7.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
123
Monitored processes
82
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe idm_6.4x_crack_v19.7.exe no specs idm_6.4x_crack_v19.7.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs wscript.exe no specs reg.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs find.exe no specs powershell.exe no specs find.exe no specs reg.exe no specs find.exe no specs powershell.exe no specs find.exe no specs cmd.exe no specs powershell.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs cmd.exe no specs cmd.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs cmd.exe no specs powershell.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs powershell.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chcp.com no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs powershell.exe no specs chrome.exe no specs explorer.exe no specs msedge.exe no specs msedge.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
584reg query "HKCU\Software\DownloadManager" "/v" "tvfrdt" C:\Windows\System32\reg.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Registry Console Tool
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\reg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
696reg query "HKCU\Software\DownloadManager" "/v" "LastCheckQU" C:\Windows\System32\reg.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Registry Console Tool
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\reg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
848"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3708 --field-trial-handle=1284,i,15988788336360100141,11488572945701977642,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
848"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=2104 --field-trial-handle=1088,i,10267570579651528970,16610611199423665164,131072 /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
864reg export HKCU\Software\Classes\CLSID "C:\Windows\Temp\_Backup_HKCU_CLSID_20240419-203153448.reg"C:\Windows\System32\reg.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Registry Console Tool
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\reg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
884"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --single-argument https://www.internetdownloadmanager.com/register/new_faq/functions7.htmlC:\Program Files\Microsoft\Edge\Application\msedge.exeIDM_6.4x_Crack_v19.7.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
956reg.exe import C:\Users\admin\AppData\Local\Temp\IDMRegClean.regC:\Windows\System32\reg.exeIDM_6.4x_Crack_v19.7.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Registry Console Tool
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\reg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1020"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --first-renderer-process --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --mojo-platform-channel-handle=2148 --field-trial-handle=1284,i,15988788336360100141,11488572945701977642,131072 /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1124find /i "computersystem" C:\Windows\System32\find.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Find String (grep) Utility
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\find.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ulib.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1192powershell.exe write-host -back '"DarkGreen"' -fore '"white"' '"The IDM reset process has been completed."'C:\Windows\System32\WindowsPowerShell\v1.0\powershell.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows PowerShell
Exit code:
0
Version:
10.0.14409.1005 (rs1_srvoob.161208-1155)
Modules
Images
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\atl.dll
c:\windows\system32\user32.dll
Total events
27 554
Read events
27 423
Write events
107
Delete events
24

Modification events

(PID) Process:(3416) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3416) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3416) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3416) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(3416) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(3416) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(3416) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\IDM_6.4x_Crack_v19.7.zip
(PID) Process:(3416) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3416) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3416) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
Executable files
2
Suspicious files
42
Text files
27
Unknown types
15

Dropped files

PID
Process
Filename
Type
884msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\26f1178a-7b13-4784-9b72-34c2572127b6.tmp
MD5:
SHA256:
884msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Local State~RF1c27e2.TMP
MD5:
SHA256:
3576msedge.exe
MD5:
SHA256:
884msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Local State~RF1c2802.TMP
MD5:
SHA256:
3404msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old~RF1c28ec.TMP
MD5:
SHA256:
3404msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old
MD5:
SHA256:
3404msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old~RF1c28fc.TMP
MD5:
SHA256:
3404msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old
MD5:
SHA256:
3404msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old~RF1c291b.TMP
MD5:
SHA256:
3404msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\LOG.old~RF1c294a.TMP
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
33
DNS requests
38
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
unknown
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
unknown
1080
svchost.exe
224.0.0.252:5355
unknown
3404
msedge.exe
239.255.255.250:1900
unknown
3668
msedge.exe
13.107.42.16:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
3668
msedge.exe
13.107.21.239:443
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
3668
msedge.exe
169.61.27.133:443
www.internetdownloadmanager.com
SOFTLAYER
US
unknown
3668
msedge.exe
23.212.110.136:443
www.bing.com
Akamai International B.V.
CZ
unknown
3404
msedge.exe
224.0.0.251:5353
unknown

DNS requests

Domain
IP
Reputation
config.edge.skype.com
  • 13.107.42.16
unknown
www.internetdownloadmanager.com
  • 169.61.27.133
unknown
edge.microsoft.com
  • 13.107.21.239
  • 204.79.197.239
unknown
www.bing.com
  • 23.212.110.136
  • 23.212.110.139
  • 23.212.110.208
  • 23.212.110.147
  • 23.212.110.155
  • 23.212.110.154
  • 23.212.110.144
  • 23.212.110.209
  • 23.212.110.217
unknown
msedgeextensions.sf.tlu.dl.delivery.mp.microsoft.com
  • 152.199.21.175
unknown
www.softpedia.com
  • 104.22.13.228
  • 104.22.12.228
  • 172.67.5.104
unknown
accounts.google.com
  • 142.251.168.84
unknown
clientservices.googleapis.com
  • 216.58.206.67
unknown
cdnssl.softpedia.com
  • 104.22.13.228
  • 172.67.5.104
  • 104.22.12.228
unknown
www.googletagmanager.com
  • 142.250.186.168
unknown

Threats

No threats detected
No debug info