File name:

EaseUS Partition Master 16.5 Multilingual.Activator.rar

Full analysis: https://app.any.run/tasks/b9400c8a-55ed-4867-a053-1ef9a36438a1
Verdict: Malicious activity
Analysis date: December 12, 2021, 03:10:40
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

D72B1D23039D3DDAC6DA5995F34E2C2B

SHA1:

9079494CF2A536F9116734D8B1793EB61AA6B507

SHA256:

D289801E11841179BB987B8BC0632B954AB3603A3D514D684C5F21D0E1E80146

SSDEEP:

24576:xDPga66NiuzQU2xCbgnypjt3En0KMYFFqWPCq8jwyteUa7:+alN+U248nyozFECYw+eUa7

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • EaseUS PM v14.x Activator v1.1.exe (PID: 3156)
      • EaseUS PM v14.x Activator v1.1.exe (PID: 3636)
    • Drops executable file immediately after starts

      • WinRAR.exe (PID: 2696)
  • SUSPICIOUS

    • Reads the computer name

      • WinRAR.exe (PID: 2696)
      • WinRAR.exe (PID: 1256)
      • jucheck.exe (PID: 1124)
      • jucheck.exe (PID: 2220)
      • EaseUS PM v14.x Activator v1.1.exe (PID: 3636)
      • javaw.exe (PID: 3200)
      • jucheck.exe (PID: 752)
      • ssvagent.exe (PID: 2464)
    • Checks supported languages

      • WinRAR.exe (PID: 1256)
      • WinRAR.exe (PID: 2696)
      • EaseUS PM v14.x Activator v1.1.exe (PID: 3636)
      • javacpl.exe (PID: 2960)
      • javaw.exe (PID: 3200)
      • jucheck.exe (PID: 1124)
      • jucheck.exe (PID: 2220)
      • ssvagent.exe (PID: 2464)
      • jucheck.exe (PID: 752)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2696)
    • Executed via COM

      • DllHost.exe (PID: 3880)
      • rundll32.exe (PID: 2908)
    • Check for Java to be installed

      • jucheck.exe (PID: 1124)
      • javaw.exe (PID: 3200)
      • jucheck.exe (PID: 2220)
      • jucheck.exe (PID: 752)
    • Executes JAVA applets

      • javacpl.exe (PID: 2960)
    • Searches for installed software

      • EaseUS PM v14.x Activator v1.1.exe (PID: 3636)
  • INFO

    • Manual execution by user

      • WinRAR.exe (PID: 2696)
      • EaseUS PM v14.x Activator v1.1.exe (PID: 3636)
      • EaseUS PM v14.x Activator v1.1.exe (PID: 3156)
      • javacpl.exe (PID: 2960)
    • Checks supported languages

      • rundll32.exe (PID: 2908)
      • DllHost.exe (PID: 3880)
    • Reads Microsoft Office registry keys

      • EaseUS PM v14.x Activator v1.1.exe (PID: 3636)
    • Reads the computer name

      • DllHost.exe (PID: 3880)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
62
Monitored processes
12
Malicious processes
5
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe no specs winrar.exe easeus pm v14.x activator v1.1.exe no specs easeus pm v14.x activator v1.1.exe Connection Manager LUA Host Object no specs rundll32.exe no specs javacpl.exe no specs javaw.exe no specs jucheck.exe no specs jucheck.exe no specs jucheck.exe no specs ssvagent.exe

Process information

PID
CMD
Path
Indicators
Parent process
752"C:\Program Files\Common Files\Java\Java Update\jucheck.exe" -setconfig=enabledUser:0;frequency:weekly;day:7;hour:22;notifyType:beforeDownloadC:\Program Files\Common Files\Java\Java Update\jucheck.exejavaw.exe
User:
admin
Company:
Oracle Corporation
Integrity Level:
MEDIUM
Description:
Java Update Checker
Exit code:
0
Version:
2.8.271.9
Modules
Images
c:\program files\common files\java\java update\jucheck.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1124"C:\Program Files\Common Files\Java\Java Update\jucheck.exe" -getconfig=1C:\Program Files\Common Files\Java\Java Update\jucheck.exejavaw.exe
User:
admin
Company:
Oracle Corporation
Integrity Level:
MEDIUM
Description:
Java Update Checker
Exit code:
0
Version:
2.8.271.9
Modules
Images
c:\program files\common files\java\java update\jucheck.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1256"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\EaseUS Partition Master 16.5 Multilingual.Activator.rar"C:\Program Files\WinRAR\WinRAR.exeExplorer.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\windows\system32\ntdll.dll
c:\program files\winrar\winrar.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2220"C:\Program Files\Common Files\Java\Java Update\jucheck.exe" -setconfig=enabledUser:0;frequency:weekly;day:7;hour:22;notifyType:beforeDownloadC:\Program Files\Common Files\Java\Java Update\jucheck.exejavaw.exe
User:
admin
Company:
Oracle Corporation
Integrity Level:
MEDIUM
Description:
Java Update Checker
Exit code:
0
Version:
2.8.271.9
Modules
Images
c:\program files\common files\java\java update\jucheck.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\shlwapi.dll
2464"C:\PROGRA~1\Java\JRE18~1.0_2\bin\ssvagent.exe" -disablewebjavaC:\PROGRA~1\Java\JRE18~1.0_2\bin\ssvagent.exe
javaw.exe
User:
admin
Company:
Oracle Corporation
Integrity Level:
HIGH
Description:
Java(TM) Platform SE binary
Exit code:
0
Version:
11.271.2.09
Modules
Images
c:\program files\java\jre1.8.0_271\bin\ssvagent.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
2696"C:\Program Files\WinRAR\WinRAR.exe" x -iext -ow -ver -- "C:\Users\admin\Desktop\EaseUS Partition Master 16.5 Multilingual.Activator\DE!\EaseUS PM v14.x Activator v1.1.rar" "C:\Users\admin\Desktop\EaseUS Partition Master 16.5 Multilingual.Activator\DE!\EaseUS PM v14.x Activator v1.1\"C:\Program Files\WinRAR\WinRAR.exe
Explorer.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\shlwapi.dll
2908C:\Windows\System32\rundll32.exe shell32.dll,SHCreateLocalServerRunDll {995C996E-D918-4a8c-A302-45719A6F4EA7} -EmbeddingC:\Windows\System32\rundll32.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
2960"C:\Program Files\Java\jre1.8.0_271\bin\javacpl.exe" C:\Program Files\Java\jre1.8.0_271\bin\javacpl.exeExplorer.EXE
User:
admin
Company:
Oracle Corporation
Integrity Level:
MEDIUM
Description:
Java Control Panel
Exit code:
0
Version:
11.271.2.09
Modules
Images
c:\program files\java\jre1.8.0_271\bin\javacpl.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
3156"C:\Users\admin\Desktop\EaseUS Partition Master 16.5 Multilingual.Activator\DE!\EaseUS PM v14.x Activator v1.1\EaseUS PM v14.x Activator v1.1.exe" C:\Users\admin\Desktop\EaseUS Partition Master 16.5 Multilingual.Activator\DE!\EaseUS PM v14.x Activator v1.1\EaseUS PM v14.x Activator v1.1.exeExplorer.EXE
User:
admin
Integrity Level:
MEDIUM
Description:
EaseUS_EPM
Exit code:
3221226540
Version:
2.0.0.0
Modules
Images
c:\windows\system32\ntdll.dll
c:\users\admin\desktop\easeus partition master 16.5 multilingual.activator\de!\easeus pm v14.x activator v1.1\easeus pm v14.x activator v1.1.exe
3200"C:\Program Files\Java\jre1.8.0_271\bin\javaw.exe" -Xbootclasspath/a:"C:\Program Files\Java\jre1.8.0_271\bin\..\lib\deploy.jar" -Djava.locale.providers=HOST,JRE,SPI -Djdk.disableLastUsageTracking -Dsun.java2d.dpiaware=true -Duser.home="C:\Users\admin" com.sun.deploy.panel.ControlPanel C:\Program Files\Java\jre1.8.0_271\bin\javaw.exejavacpl.exe
User:
admin
Company:
Oracle Corporation
Integrity Level:
MEDIUM
Description:
Java(TM) Platform SE binary
Exit code:
0
Version:
8.0.2710.9
Modules
Images
c:\program files\java\jre1.8.0_271\bin\javaw.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
Total events
22 636
Read events
9 854
Write events
400
Delete events
12 382

Modification events

(PID) Process:(1256) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(1256) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(1256) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1256) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(1256) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(1256) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\EaseUS Partition Master 16.5 Multilingual.Activator.rar
(PID) Process:(1256) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(1256) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(1256) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(1256) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
Executable files
1
Suspicious files
2
Text files
5
Unknown types
1

Dropped files

PID
Process
Filename
Type
1256WinRAR.exeC:\Users\admin\Desktop\EaseUS Partition Master 16.5 Multilingual.Activator\DE!\EaseUS PM v14.x Activator v1.1.rarcompressed
MD5:
SHA256:
1256WinRAR.exeC:\Users\admin\Desktop\EaseUS Partition Master 16.5 Multilingual.Activator\EuCfg.binbinary
MD5:
SHA256:
1256WinRAR.exeC:\Users\admin\Desktop\EaseUS Partition Master 16.5 Multilingual.Activator\New Internet Shortcut.urlurl
MD5:
SHA256:
1256WinRAR.exeC:\Users\admin\Desktop\EaseUS Partition Master 16.5 Multilingual.Activator\DE!\ReadMe.txttext
MD5:
SHA256:
3200javaw.exeC:\Users\admin\AppData\LocalLow\Sun\Java\Deployment\tmp\si\JavaControlPanel-x86_64872text
MD5:
SHA256:
3200javaw.exeC:\Users\admin\AppData\Local\Temp\JavaDeployReg.logtext
MD5:
SHA256:
1124jucheck.exeC:\Users\admin\AppData\Local\Temp\jusched.logtext
MD5:
SHA256:
3200javaw.exeC:\Users\admin\AppData\LocalLow\Sun\Java\Deployment\deployment.propertiestext
MD5:
SHA256:
2696WinRAR.exeC:\Users\admin\Desktop\EaseUS Partition Master 16.5 Multilingual.Activator\DE!\EaseUS PM v14.x Activator v1.1\EaseUS PM v14.x Activator v1.1.exeexecutable
MD5:9BDFF46961AEF386D4DE5E2B1405DC40
SHA256:D8E43DFB7662E0EEB26821F5A6A8D9F8A5B351D1D1E769A516ED65B86144E605
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info