| File name: | Easy Tune 4 Utility vB04.101901.7z |
| Full analysis: | https://app.any.run/tasks/7011f551-e905-424a-b418-055a42e78e52 |
| Verdict: | Malicious activity |
| Analysis date: | October 02, 2024, 16:01:08 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-7z-compressed |
| File info: | 7-zip archive data, version 0.4 |
| MD5: | 05370ACCEA6CD5D574BC4D3A45057506 |
| SHA1: | 21835D1FC7F7B647E007797FBE51FCAAE367A9BF |
| SHA256: | D85046886B200A39825511163A90A82DCB6EFC66C4C700B268722F1D0068381C |
| SSDEEP: | 98304:Gv/9/aO6Fom5+eqI3G3sA93SJnvV5yHJPh68qwQnUCfcjknMRvYrLj4XoA7Sa8QI:XmdtzeLwIUJBQNL4NQ0zRoQu |
| .7z | | | 7-Zip compressed archive (v0.4) (57.1) |
|---|---|---|
| .7z | | | 7-Zip compressed archive (gen) (42.8) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 288 | C:\Windows\system32\sipnotify.exe -LogonOrUnlock | C:\Windows\System32\sipnotify.exe | — | taskeng.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: sipnotify Exit code: 0 Version: 6.1.7602.20480 (win7sp1_ldr_escrow.191010-1716) Modules
| |||||||||||||||
| 1684 | C:\Windows\System32\ctfmon.exe | C:\Windows\System32\ctfmon.exe | — | taskeng.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: CTF Loader Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2108 | "C:\Program Files\Common Files\microsoft shared\IME14\SHARED\IMEKLMG.EXE" /SetPreload /JPN /Log | C:\Program Files\Common Files\microsoft shared\IME14\SHARED\IMEKLMG.EXE | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Office IME 2010 Exit code: 1 Version: 14.0.4734.1000 Modules
| |||||||||||||||
| 2116 | "C:\Program Files\Common Files\microsoft shared\IME14\SHARED\IMEKLMG.EXE" /SetPreload /KOR /Log | C:\Program Files\Common Files\microsoft shared\IME14\SHARED\IMEKLMG.EXE | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Office IME 2010 Exit code: 1 Version: 14.0.4734.1000 Modules
| |||||||||||||||
| 2136 | "C:\Program Files\Gigabyte\EasyTune4\ET4.exe" | C:\Program Files\Gigabyte\EasyTune4\ET4.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Description: ET4 MFC Application Exit code: 3221225477 Version: 1, 0, 0, 1 Modules
| |||||||||||||||
| 2436 | "C:\Program Files\Windows Media Player\wmpnscfg.exe" | C:\Program Files\Windows Media Player\wmpnscfg.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Network Sharing Service Configuration Application Exit code: 0 Version: 12.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2464 | "C:\Program Files\Windows Media Player\wmpnscfg.exe" | C:\Program Files\Windows Media Player\wmpnscfg.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Network Sharing Service Configuration Application Exit code: 0 Version: 12.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2636 | "C:\Windows\explorer.exe" | C:\Windows\explorer.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Explorer Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2644 | C:\Users\admin\AppData\Local\Temp\_ISTMP1.DIR\_INS5576._MP | C:\Users\admin\AppData\Local\Temp\_ISTMP1.DIR\_INS5576._MP | Setup.exe | ||||||||||||
User: admin Company: InstallShield Software Corporation Integrity Level: HIGH Description: InstallShield Engine Exit code: 0 Version: 5, 50, 137, 0 Modules
| |||||||||||||||
| 2696 | "C:\Program Files\Windows Media Player\wmpnscfg.exe" | C:\Program Files\Windows Media Player\wmpnscfg.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Network Sharing Service Configuration Application Exit code: 0 Version: 12.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (3660) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (3660) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (3660) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3660) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\phacker.zip | |||
| (PID) Process: | (3660) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (3660) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip | |||
| (PID) Process: | (3660) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop\Easy Tune 4 Utility vB04.101901.7z | |||
| (PID) Process: | (3660) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (3660) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (3660) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3660 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3660.20122\Easy Tune 4 Utility vB04.101901\data1.cab | — | |
MD5:— | SHA256:— | |||
| 3660 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3660.20122\Easy Tune 4 Utility vB04.101901\setup.bmp | binary | |
MD5:C22F0FD57DCF841721C63C811BB48BCE | SHA256:2CBAC572C95F1FE05B8B0E7C9C4FA32F004BEA86922C070C2F256CF6B7F718AA | |||
| 3660 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3660.20122\Easy Tune 4 Utility vB04.101901\DATA.TAG | text | |
MD5:5066BC161F077CDD1EDAFA77C48E7FCA | SHA256:167EC4C6A66C121BC61E5D73919408542FE925F1EDADDEA922A97D91FA541717 | |||
| 3660 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3660.20122\Easy Tune 4 Utility vB04.101901\setup.lid | text | |
MD5:1B79748E93A541CC1590505B6C72828A | SHA256:708D29C649525882937031B3D73CC851B7B1BC30772EB4E0E2A71523908F2EB5 | |||
| 3660 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3660.20122\Easy Tune 4 Utility vB04.101901\os.dat | ini | |
MD5:478F65A0B922B6BA0A6CE99E1D15C336 | SHA256:BE2292517342DE82D50CEFBACB185E36558FCDFBF686692E7DF08A80331F9BEE | |||
| 3660 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3660.20122\Easy Tune 4 Utility vB04.101901\layout.bin | binary | |
MD5:573A549DEC79617AA8A14F9566BC0D6A | SHA256:7698DFA2A1FC0F4529EF9FF44958983C605C58CD8EC272614E70B73B46196CE6 | |||
| 3660 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3660.20122\Easy Tune 4 Utility vB04.101901\SETUP.INI | ini | |
MD5:D64D366D784B5334BD16657F32B4D82A | SHA256:621258D77660E0D2E918768C70217598F8EC6E2E9992C2209D9546BA59612B75 | |||
| 3660 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3660.20122\Easy Tune 4 Utility vB04.101901\data1.hdr | compressed | |
MD5:2322AC16A60BCF0FE53CE927D7AE8551 | SHA256:D20265B3ECED5356B0BE6D1520F3554E0E378C73B7A76A96F852749D93F5CF0E | |||
| 3660 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3660.20122\Easy Tune 4 Utility vB04.101901\lang.dat | ini | |
MD5:CCCAAE5C8A23EAE65DF80531A235F6E8 | SHA256:04F46E56C0D16ED246779698631DD28E81EA0A9D30F8BD9025A7B9996A9E562D | |||
| 3660 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3660.20122\Easy Tune 4 Utility vB04.101901\Setup.exe | executable | |
MD5:1E013F8D89F59CE39C7FA9BC8BD3A166 | SHA256:A6D2F8B9173FD43F03AABFF0B8CC3FADBD0B15224BCBE5F562A32158A297B502 | |||