File name:

Easy Tune 4 Utility vB04.101901.7z

Full analysis: https://app.any.run/tasks/7011f551-e905-424a-b418-055a42e78e52
Verdict: Malicious activity
Analysis date: October 02, 2024, 16:01:08
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-7z-compressed
File info: 7-zip archive data, version 0.4
MD5:

05370ACCEA6CD5D574BC4D3A45057506

SHA1:

21835D1FC7F7B647E007797FBE51FCAAE367A9BF

SHA256:

D85046886B200A39825511163A90A82DCB6EFC66C4C700B268722F1D0068381C

SSDEEP:

98304:Gv/9/aO6Fom5+eqI3G3sA93SJnvV5yHJPh68qwQnUCfcjknMRvYrLj4XoA7Sa8QI:XmdtzeLwIUJBQNL4NQ0zRoQu

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • _INS5576._MP (PID: 3496)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • Setup.exe (PID: 2768)
      • _INS5576._MP (PID: 2644)
      • Setup.exe (PID: 3504)
      • _INS5576._MP (PID: 3496)
    • Starts application with an unusual extension

      • Setup.exe (PID: 2768)
      • Setup.exe (PID: 3504)
    • Process drops legitimate windows executable

      • _INS5576._MP (PID: 2644)
      • _INS5576._MP (PID: 3496)
    • Creates file in the systems drive root

      • _ISDel.exe (PID: 3532)
      • _ISDel.exe (PID: 3512)
    • The process executes via Task Scheduler

      • sipnotify.exe (PID: 288)
      • ctfmon.exe (PID: 1684)
    • Creates a software uninstall entry

      • _INS5576._MP (PID: 3496)
  • INFO

    • The process uses the downloaded file

      • WinRAR.exe (PID: 3660)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3660)
    • Checks supported languages

      • Setup.exe (PID: 2768)
      • _ISDel.exe (PID: 3532)
      • _INS5576._MP (PID: 2644)
      • Setup.exe (PID: 3504)
      • _INS5576._MP (PID: 3496)
      • _ISDel.exe (PID: 3512)
    • Manual execution by a user

      • Setup.exe (PID: 2720)
      • Setup.exe (PID: 2768)
      • Setup.exe (PID: 3504)
      • wmpnscfg.exe (PID: 2464)
      • wmpnscfg.exe (PID: 2696)
      • ET4.exe (PID: 3640)
      • ET4.exe (PID: 3044)
      • ET4.exe (PID: 3352)
      • ET4.exe (PID: 3540)
      • ET4.exe (PID: 2136)
      • IMEKLMG.EXE (PID: 2108)
      • IMEKLMG.EXE (PID: 2116)
      • wmpnscfg.exe (PID: 2436)
      • explorer.exe (PID: 2636)
      • ET4.exe (PID: 3232)
    • Reads the computer name

      • Setup.exe (PID: 2768)
      • _INS5576._MP (PID: 2644)
      • _ISDel.exe (PID: 3532)
      • Setup.exe (PID: 3504)
      • _ISDel.exe (PID: 3512)
      • _INS5576._MP (PID: 3496)
    • Create files in a temporary directory

      • Setup.exe (PID: 2768)
      • _INS5576._MP (PID: 2644)
      • Setup.exe (PID: 3504)
      • _INS5576._MP (PID: 3496)
    • Creates files in the program directory

      • _INS5576._MP (PID: 3496)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.7z | 7-Zip compressed archive (v0.4) (57.1)
.7z | 7-Zip compressed archive (gen) (42.8)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
118
Monitored processes
22
Malicious processes
2
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe setup.exe no specs setup.exe _ins5576._mp _isdel.exe no specs setup.exe _ins5576._mp _isdel.exe no specs ctfmon.exe no specs sipnotify.exe no specs imeklmg.exe no specs imeklmg.exe no specs et4.exe wmpnscfg.exe no specs wmpnscfg.exe no specs explorer.exe no specs wmpnscfg.exe no specs et4.exe et4.exe no specs et4.exe et4.exe no specs et4.exe

Process information

PID
CMD
Path
Indicators
Parent process
288C:\Windows\system32\sipnotify.exe -LogonOrUnlockC:\Windows\System32\sipnotify.exetaskeng.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
sipnotify
Exit code:
0
Version:
6.1.7602.20480 (win7sp1_ldr_escrow.191010-1716)
Modules
Images
c:\windows\system32\sipnotify.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1684C:\Windows\System32\ctfmon.exe C:\Windows\System32\ctfmon.exetaskeng.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
CTF Loader
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ctfmon.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msctfmonitor.dll
c:\windows\system32\msctf.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
2108"C:\Program Files\Common Files\microsoft shared\IME14\SHARED\IMEKLMG.EXE" /SetPreload /JPN /LogC:\Program Files\Common Files\microsoft shared\IME14\SHARED\IMEKLMG.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Office IME 2010
Exit code:
1
Version:
14.0.4734.1000
Modules
Images
c:\program files\common files\microsoft shared\ime14\shared\imeklmg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\userenv.dll
2116"C:\Program Files\Common Files\microsoft shared\IME14\SHARED\IMEKLMG.EXE" /SetPreload /KOR /LogC:\Program Files\Common Files\microsoft shared\IME14\SHARED\IMEKLMG.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Office IME 2010
Exit code:
1
Version:
14.0.4734.1000
Modules
Images
c:\program files\common files\microsoft shared\ime14\shared\imeklmg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\userenv.dll
2136"C:\Program Files\Gigabyte\EasyTune4\ET4.exe" C:\Program Files\Gigabyte\EasyTune4\ET4.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
ET4 MFC Application
Exit code:
3221225477
Version:
1, 0, 0, 1
Modules
Images
c:\program files\gigabyte\easytune4\et4.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\gigabyte\easytune4\etiv.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
2436"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2464"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2636"C:\Windows\explorer.exe" C:\Windows\explorer.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2644C:\Users\admin\AppData\Local\Temp\_ISTMP1.DIR\_INS5576._MPC:\Users\admin\AppData\Local\Temp\_ISTMP1.DIR\_INS5576._MP
Setup.exe
User:
admin
Company:
InstallShield Software Corporation
Integrity Level:
HIGH
Description:
InstallShield Engine
Exit code:
0
Version:
5, 50, 137, 0
Modules
Images
c:\users\admin\appdata\local\temp\_istmp1.dir\_ins5576._mp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winspool.drv
2696"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
Total events
2 538
Read events
2 502
Write events
35
Delete events
1

Modification events

(PID) Process:(3660) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3660) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3660) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3660) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(3660) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(3660) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(3660) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\Easy Tune 4 Utility vB04.101901.7z
(PID) Process:(3660) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3660) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3660) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
Executable files
39
Suspicious files
20
Text files
19
Unknown types
2

Dropped files

PID
Process
Filename
Type
3660WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3660.20122\Easy Tune 4 Utility vB04.101901\data1.cab
MD5:
SHA256:
3660WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3660.20122\Easy Tune 4 Utility vB04.101901\setup.bmpbinary
MD5:C22F0FD57DCF841721C63C811BB48BCE
SHA256:2CBAC572C95F1FE05B8B0E7C9C4FA32F004BEA86922C070C2F256CF6B7F718AA
3660WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3660.20122\Easy Tune 4 Utility vB04.101901\DATA.TAGtext
MD5:5066BC161F077CDD1EDAFA77C48E7FCA
SHA256:167EC4C6A66C121BC61E5D73919408542FE925F1EDADDEA922A97D91FA541717
3660WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3660.20122\Easy Tune 4 Utility vB04.101901\setup.lidtext
MD5:1B79748E93A541CC1590505B6C72828A
SHA256:708D29C649525882937031B3D73CC851B7B1BC30772EB4E0E2A71523908F2EB5
3660WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3660.20122\Easy Tune 4 Utility vB04.101901\os.datini
MD5:478F65A0B922B6BA0A6CE99E1D15C336
SHA256:BE2292517342DE82D50CEFBACB185E36558FCDFBF686692E7DF08A80331F9BEE
3660WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3660.20122\Easy Tune 4 Utility vB04.101901\layout.binbinary
MD5:573A549DEC79617AA8A14F9566BC0D6A
SHA256:7698DFA2A1FC0F4529EF9FF44958983C605C58CD8EC272614E70B73B46196CE6
3660WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3660.20122\Easy Tune 4 Utility vB04.101901\SETUP.INIini
MD5:D64D366D784B5334BD16657F32B4D82A
SHA256:621258D77660E0D2E918768C70217598F8EC6E2E9992C2209D9546BA59612B75
3660WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3660.20122\Easy Tune 4 Utility vB04.101901\data1.hdrcompressed
MD5:2322AC16A60BCF0FE53CE927D7AE8551
SHA256:D20265B3ECED5356B0BE6D1520F3554E0E378C73B7A76A96F852749D93F5CF0E
3660WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3660.20122\Easy Tune 4 Utility vB04.101901\lang.datini
MD5:CCCAAE5C8A23EAE65DF80531A235F6E8
SHA256:04F46E56C0D16ED246779698631DD28E81EA0A9D30F8BD9025A7B9996A9E562D
3660WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3660.20122\Easy Tune 4 Utility vB04.101901\Setup.exeexecutable
MD5:1E013F8D89F59CE39C7FA9BC8BD3A166
SHA256:A6D2F8B9173FD43F03AABFF0B8CC3FADBD0B15224BCBE5F562A32158A297B502
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info