File name:

EaseUS Partition Master 16.5 Multilingual.Activator.rar

Full analysis: https://app.any.run/tasks/b9400c8a-55ed-4867-a053-1ef9a36438a1
Verdict: Malicious activity
Analysis date: December 12, 2021, 03:10:40
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

D72B1D23039D3DDAC6DA5995F34E2C2B

SHA1:

9079494CF2A536F9116734D8B1793EB61AA6B507

SHA256:

D289801E11841179BB987B8BC0632B954AB3603A3D514D684C5F21D0E1E80146

SSDEEP:

24576:xDPga66NiuzQU2xCbgnypjt3En0KMYFFqWPCq8jwyteUa7:+alN+U248nyozFECYw+eUa7

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops executable file immediately after starts

      • WinRAR.exe (PID: 2696)
    • Application was dropped or rewritten from another process

      • EaseUS PM v14.x Activator v1.1.exe (PID: 3156)
      • EaseUS PM v14.x Activator v1.1.exe (PID: 3636)
  • SUSPICIOUS

    • Reads the computer name

      • WinRAR.exe (PID: 2696)
      • WinRAR.exe (PID: 1256)
      • EaseUS PM v14.x Activator v1.1.exe (PID: 3636)
      • javaw.exe (PID: 3200)
      • jucheck.exe (PID: 1124)
      • jucheck.exe (PID: 2220)
      • jucheck.exe (PID: 752)
      • ssvagent.exe (PID: 2464)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2696)
    • Checks supported languages

      • WinRAR.exe (PID: 2696)
      • WinRAR.exe (PID: 1256)
      • EaseUS PM v14.x Activator v1.1.exe (PID: 3636)
      • javacpl.exe (PID: 2960)
      • javaw.exe (PID: 3200)
      • jucheck.exe (PID: 1124)
      • jucheck.exe (PID: 752)
      • jucheck.exe (PID: 2220)
      • ssvagent.exe (PID: 2464)
    • Executed via COM

      • DllHost.exe (PID: 3880)
      • rundll32.exe (PID: 2908)
    • Executes JAVA applets

      • javacpl.exe (PID: 2960)
    • Check for Java to be installed

      • javaw.exe (PID: 3200)
      • jucheck.exe (PID: 1124)
      • jucheck.exe (PID: 2220)
      • jucheck.exe (PID: 752)
    • Searches for installed software

      • EaseUS PM v14.x Activator v1.1.exe (PID: 3636)
  • INFO

    • Manual execution by user

      • WinRAR.exe (PID: 2696)
      • EaseUS PM v14.x Activator v1.1.exe (PID: 3156)
      • EaseUS PM v14.x Activator v1.1.exe (PID: 3636)
      • javacpl.exe (PID: 2960)
    • Checks supported languages

      • rundll32.exe (PID: 2908)
      • DllHost.exe (PID: 3880)
    • Reads Microsoft Office registry keys

      • EaseUS PM v14.x Activator v1.1.exe (PID: 3636)
    • Reads the computer name

      • DllHost.exe (PID: 3880)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
62
Monitored processes
12
Malicious processes
5
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe no specs winrar.exe easeus pm v14.x activator v1.1.exe no specs easeus pm v14.x activator v1.1.exe Connection Manager LUA Host Object no specs rundll32.exe no specs javacpl.exe no specs javaw.exe no specs jucheck.exe no specs jucheck.exe no specs jucheck.exe no specs ssvagent.exe

Process information

PID
CMD
Path
Indicators
Parent process
752"C:\Program Files\Common Files\Java\Java Update\jucheck.exe" -setconfig=enabledUser:0;frequency:weekly;day:7;hour:22;notifyType:beforeDownloadC:\Program Files\Common Files\Java\Java Update\jucheck.exejavaw.exe
User:
admin
Company:
Oracle Corporation
Integrity Level:
MEDIUM
Description:
Java Update Checker
Exit code:
0
Version:
2.8.271.9
Modules
Images
c:\program files\common files\java\java update\jucheck.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1124"C:\Program Files\Common Files\Java\Java Update\jucheck.exe" -getconfig=1C:\Program Files\Common Files\Java\Java Update\jucheck.exejavaw.exe
User:
admin
Company:
Oracle Corporation
Integrity Level:
MEDIUM
Description:
Java Update Checker
Exit code:
0
Version:
2.8.271.9
Modules
Images
c:\program files\common files\java\java update\jucheck.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1256"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\EaseUS Partition Master 16.5 Multilingual.Activator.rar"C:\Program Files\WinRAR\WinRAR.exeExplorer.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\windows\system32\ntdll.dll
c:\program files\winrar\winrar.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2220"C:\Program Files\Common Files\Java\Java Update\jucheck.exe" -setconfig=enabledUser:0;frequency:weekly;day:7;hour:22;notifyType:beforeDownloadC:\Program Files\Common Files\Java\Java Update\jucheck.exejavaw.exe
User:
admin
Company:
Oracle Corporation
Integrity Level:
MEDIUM
Description:
Java Update Checker
Exit code:
0
Version:
2.8.271.9
Modules
Images
c:\program files\common files\java\java update\jucheck.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\shlwapi.dll
2464"C:\PROGRA~1\Java\JRE18~1.0_2\bin\ssvagent.exe" -disablewebjavaC:\PROGRA~1\Java\JRE18~1.0_2\bin\ssvagent.exe
javaw.exe
User:
admin
Company:
Oracle Corporation
Integrity Level:
HIGH
Description:
Java(TM) Platform SE binary
Exit code:
0
Version:
11.271.2.09
Modules
Images
c:\program files\java\jre1.8.0_271\bin\ssvagent.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
2696"C:\Program Files\WinRAR\WinRAR.exe" x -iext -ow -ver -- "C:\Users\admin\Desktop\EaseUS Partition Master 16.5 Multilingual.Activator\DE!\EaseUS PM v14.x Activator v1.1.rar" "C:\Users\admin\Desktop\EaseUS Partition Master 16.5 Multilingual.Activator\DE!\EaseUS PM v14.x Activator v1.1\"C:\Program Files\WinRAR\WinRAR.exe
Explorer.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\shlwapi.dll
2908C:\Windows\System32\rundll32.exe shell32.dll,SHCreateLocalServerRunDll {995C996E-D918-4a8c-A302-45719A6F4EA7} -EmbeddingC:\Windows\System32\rundll32.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
2960"C:\Program Files\Java\jre1.8.0_271\bin\javacpl.exe" C:\Program Files\Java\jre1.8.0_271\bin\javacpl.exeExplorer.EXE
User:
admin
Company:
Oracle Corporation
Integrity Level:
MEDIUM
Description:
Java Control Panel
Exit code:
0
Version:
11.271.2.09
Modules
Images
c:\program files\java\jre1.8.0_271\bin\javacpl.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
3156"C:\Users\admin\Desktop\EaseUS Partition Master 16.5 Multilingual.Activator\DE!\EaseUS PM v14.x Activator v1.1\EaseUS PM v14.x Activator v1.1.exe" C:\Users\admin\Desktop\EaseUS Partition Master 16.5 Multilingual.Activator\DE!\EaseUS PM v14.x Activator v1.1\EaseUS PM v14.x Activator v1.1.exeExplorer.EXE
User:
admin
Integrity Level:
MEDIUM
Description:
EaseUS_EPM
Exit code:
3221226540
Version:
2.0.0.0
Modules
Images
c:\windows\system32\ntdll.dll
c:\users\admin\desktop\easeus partition master 16.5 multilingual.activator\de!\easeus pm v14.x activator v1.1\easeus pm v14.x activator v1.1.exe
3200"C:\Program Files\Java\jre1.8.0_271\bin\javaw.exe" -Xbootclasspath/a:"C:\Program Files\Java\jre1.8.0_271\bin\..\lib\deploy.jar" -Djava.locale.providers=HOST,JRE,SPI -Djdk.disableLastUsageTracking -Dsun.java2d.dpiaware=true -Duser.home="C:\Users\admin" com.sun.deploy.panel.ControlPanel C:\Program Files\Java\jre1.8.0_271\bin\javaw.exejavacpl.exe
User:
admin
Company:
Oracle Corporation
Integrity Level:
MEDIUM
Description:
Java(TM) Platform SE binary
Exit code:
0
Version:
8.0.2710.9
Modules
Images
c:\program files\java\jre1.8.0_271\bin\javaw.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
Total events
22 636
Read events
9 854
Write events
400
Delete events
12 382

Modification events

(PID) Process:(1256) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(1256) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(1256) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1256) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(1256) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(1256) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\EaseUS Partition Master 16.5 Multilingual.Activator.rar
(PID) Process:(1256) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(1256) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(1256) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(1256) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
Executable files
1
Suspicious files
2
Text files
5
Unknown types
1

Dropped files

PID
Process
Filename
Type
1256WinRAR.exeC:\Users\admin\Desktop\EaseUS Partition Master 16.5 Multilingual.Activator\DE!\ReadMe.txttext
MD5:2E714C0F5160FB97F13BA31801571CB4
SHA256:AB72D144E09A59600DFE379339CE35525D41B3A77DC78CEFE2647720525DAA79
1256WinRAR.exeC:\Users\admin\Desktop\EaseUS Partition Master 16.5 Multilingual.Activator\EuCfg.binbinary
MD5:2EDF935A31DC5E6E2B06CE06ED45C101
SHA256:8761FB2D423E82AB5318216231ABD508AA100C15F6A7F73C3509CDAAEC3A115C
1124jucheck.exeC:\Users\admin\AppData\Local\Temp\jusched.logtext
MD5:31307E652612D951BA4EA48274FA0202
SHA256:B803BE92ECAC7F5BDC547EA46040CA16BAD1977604EACE53DB7DFD4B9D4BCFCF
1256WinRAR.exeC:\Users\admin\Desktop\EaseUS Partition Master 16.5 Multilingual.Activator\DE!\EaseUS PM v14.x Activator v1.1.rarcompressed
MD5:1C65844380D51E5B145261AF112CE871
SHA256:62CBA573024D2112168791DFD582C65EA5EA83D50BC5292B4693C03DA1F9F3A9
1256WinRAR.exeC:\Users\admin\Desktop\EaseUS Partition Master 16.5 Multilingual.Activator\New Internet Shortcut.urlurl
MD5:4100813D43FC87E8808741C6A8CB9C81
SHA256:27441507C0E5BCC5C387E566D552445D3D734B49FEDAF0DAA5452ABD3E592123
3200javaw.exeC:\Users\admin\AppData\LocalLow\Sun\Java\Deployment\tmp\si\JavaControlPanel-x86_64872text
MD5:6D81EE2C1EC20093BD6FAEF28DA3EA86
SHA256:46C163562A198BC53FA5C560A615D7B8F9BA2726B3C9B074178BB17605612EDF
3200javaw.exeC:\Users\admin\AppData\LocalLow\Sun\Java\Deployment\deployment.propertiestext
MD5:8E3B641EDD3FE164218CF6CAA1766A1B
SHA256:86152F6846E165CF1DBFE55F7F0BFB2FAB695E7E427D9A02A4A5E37F4C1BCD31
3200javaw.exeC:\Users\admin\AppData\Local\Temp\JavaDeployReg.logtext
MD5:D584081F3168C11A63D44F339DC1BCE7
SHA256:B119FFA6D184FBE57A0EF1FA912380242B3FC011AEB344F844EB11F4AAEE9EC7
2696WinRAR.exeC:\Users\admin\Desktop\EaseUS Partition Master 16.5 Multilingual.Activator\DE!\EaseUS PM v14.x Activator v1.1\EaseUS PM v14.x Activator v1.1.exeexecutable
MD5:9BDFF46961AEF386D4DE5E2B1405DC40
SHA256:D8E43DFB7662E0EEB26821F5A6A8D9F8A5B351D1D1E769A516ED65B86144E605
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info