| File name: | processhacker-2.39-bin.zip |
| Full analysis: | https://app.any.run/tasks/c0c966d5-3232-4ed3-8b6d-4db2302e16ea |
| Verdict: | Malicious activity |
| Analysis date: | February 27, 2019, 09:50:50 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v1.0 to extract |
| MD5: | 41CE544132439494CEA046F7CFBB6422 |
| SHA1: | AE42490C5412EA13455498CCB1DF329388F001BD |
| SHA256: | C7921C71A40EC56CDE34CAC854C7164AF456BBB7393BCBF8C306702BFF15719F |
| SSDEEP: | 49152:l85pB0X687BimNifJTbWhzV71f/6HzsQ+rMuhu5vEQ1tYFZzgs993VdbrD1O:S5pan1OWhzV9CHzR+rWeHz9zQ |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 10 |
|---|---|
| ZipBitFlag: | - |
| ZipCompression: | None |
| ZipModifyDate: | 2017:10:02 17:04:24 |
| ZipCRC: | 0x00000000 |
| ZipCompressedSize: | - |
| ZipUncompressedSize: | - |
| ZipFileName: | processhacker-2.39-bin/ |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2564 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa3544.9224\processhacker-2.39-bin\x86\ProcessHacker.exe" -v -selecttab Disk | C:\Users\admin\AppData\Local\Temp\Rar$EXa3544.9224\processhacker-2.39-bin\x86\ProcessHacker.exe | ProcessHacker.exe | ||||||||||||
User: admin Company: wj32 Integrity Level: HIGH Description: Process Hacker Exit code: 0 Version: 2.39.0.124 Modules
| |||||||||||||||
| 3544 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Downloads\processhacker-2.39-bin.zip" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.60.0 Modules
| |||||||||||||||
| 3744 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa3544.9224\processhacker-2.39-bin\x86\ProcessHacker.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa3544.9224\processhacker-2.39-bin\x86\ProcessHacker.exe | WinRAR.exe | ||||||||||||
User: admin Company: wj32 Integrity Level: MEDIUM Description: Process Hacker Exit code: 0 Version: 2.39.0.124 Modules
| |||||||||||||||
| (PID) Process: | (3544) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (3544) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (3544) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3544) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Downloads\processhacker-2.39-bin.zip | |||
| (PID) Process: | (3544) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (3544) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (3544) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (3544) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (3544) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
| (PID) Process: | (3544) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3544 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3544.7783\processhacker-2.39-bin\COPYRIGHT.txt | text | |
MD5:39B07060A5C6199730219E29C747C061 | SHA256:319CD301CF40BE03C00CD086560D4E810E0F6D0DBFDC2D28D6AF3522C027CF49 | |||
| 3544 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3544.7783\processhacker-2.39-bin\x64\plugins\ExtendedNotifications.dll | executable | |
MD5:BE4DC4D2D1D05001AB0BB2BB8659BFAD | SHA256:61E8CD8DE80A5C0D7CED280FE04AD8387A846A7BF2EE51BCBBA96B971C7C1795 | |||
| 3544 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3544.7783\processhacker-2.39-bin\x64\plugins\ExtendedServices.dll | executable | |
MD5:4858BDB7731BF0B46B247A1F01F4A282 | SHA256:5AE7C0972FD4E4C4AE14C0103602CA854377FEFCBCCD86FA68CFC5A6D1F99F60 | |||
| 3544 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3544.7783\processhacker-2.39-bin\x64\plugins\ExtendedTools.dll | executable | |
MD5:BC61E6FB02FBBFE16FB43CC9F4E949F1 | SHA256:F2805E0F81513641A440F1A21057A664961C22192CB33FCA3870362C8F872D87 | |||
| 3544 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3544.7783\processhacker-2.39-bin\LICENSE.txt | text | |
MD5:EB59E0A5D01D0A5B02DA0C9E7786969F | SHA256:C38E811F6F83428921D0CECD998A44B717149B577B4C1A63B66064F03C34E4E7 | |||
| 3544 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3544.7783\processhacker-2.39-bin\CHANGELOG.txt | text | |
MD5:B13DE4E8531AF294F87FFDDCCB08D7CE | SHA256:69E38F590A9A25F656E7507AF76229A3A6678A8C57B4E879FF8CE7E52FD704FF | |||
| 3544 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3544.7783\processhacker-2.39-bin\x64\peview.exe | executable | |
MD5:DDE1F44789CD50C1F034042D337DEAE3 | SHA256:4259E53D48A3FED947F561FF04C7F94446BEDD64C87F52400B2CB47A77666AAA | |||
| 3544 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3544.7783\processhacker-2.39-bin\README.txt | text | |
MD5:72AC5A8DD6491E525B9783C9BC439FE6 | SHA256:0C4F051675A690EA4DB6AB2EB81FDCED6990E2538AD21DC4610AA5925253A090 | |||
| 3544 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3544.7783\processhacker-2.39-bin\x64\plugins\WindowExplorer.dll | executable | |
MD5:0E8D04159C075F0048B89270D22D2DBB | SHA256:282696487EA5DC781788D5D8477B977F72B7C70F201C2AF0CFE7E1A9FD8D749A | |||
| 3544 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3544.7783\processhacker-2.39-bin\x64\plugins\ToolStatus.dll | executable | |
MD5:3788EFFF135F8B17A179D02334D505E6 | SHA256:5713D40DEC146DBC819230DAEFE1B886FA6D6F6DBD619301BB8899562195CBAB | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
3744 | ProcessHacker.exe | 162.243.25.33:443 | wj32.org | Digital Ocean, Inc. | US | suspicious |
Domain | IP | Reputation |
|---|---|---|
wj32.org |
| whitelisted |