| File name: | google sketchup pro 2019 crack plus key_4289d353e.iso |
| Full analysis: | https://app.any.run/tasks/816bd20b-9771-4efe-978f-b6e6bc73dc5e |
| Verdict: | Malicious activity |
| Threats: | Adware is a form of malware that targets users with unwanted advertisements, often disrupting their browsing experience. It typically infiltrates systems through software bundling, malicious websites, or deceptive downloads. Once installed, it may track user activity, collect sensitive data, and display intrusive ads, including pop-ups or banners. Some advanced adware variants can bypass security measures and establish persistence on devices, making removal challenging. Additionally, adware can create vulnerabilities that other malware can exploit, posing a significant risk to user privacy and system security. |
| Analysis date: | September 06, 2019, 07:09:31 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-iso9660-image |
| File info: | ISO 9660 CD-ROM filesystem data '20876a0448' |
| MD5: | 36463B76412CB52D2D4366FEC2806E33 |
| SHA1: | 2AAE1E190970C2EF71BC0070DDF728F8ECFE82FA |
| SHA256: | D95C036CEB110E05F16039A5539281AD290DDA19891C7E6A8C3FC321DE05FC86 |
| SSDEEP: | 98304:4+wgVTH0glEg4uJ3kS2DU6aOzK2tmXK/aq:agVYgqg/3kvCK/a |
| .atn | | | Photoshop Action (37.5) |
|---|---|---|
| .gmc | | | Game Music Creator Music (8.4) |
| .abr | | | Adobe PhotoShop Brush (7.5) |
| VolumeName: | 20876a0448 |
|---|---|
| VolumeBlockCount: | 1880 |
| VolumeBlockSize: | 2048 |
| RootDirectoryCreateDate: | 2019:09:06 07:07:04+00:00 |
| DataPreparer: | XORRISO-1.4.8 2017.09.12.143001, LIBISOBURN-1.4.8, LIBISOFS-1.4.8, LIBBURN-1.4.8 |
| VolumeCreateDate: | 2019:09:06 07:07:04.00+00:00 |
| VolumeModifyDate: | 2019:09:06 07:07:04.00+00:00 |
| VolumeSize: | 3.7 MB |
|---|
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 3560 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\google sketchup pro 2019 crack plus key_4289d353e.iso" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.60.0 Modules
| |||||||||||||||
| 3612 | "C:\Users\admin\Desktop\google sketchup pro 2019 crack plus key-20876a0448.exe" | C:\Users\admin\Desktop\google sketchup pro 2019 crack plus key-20876a0448.exe | — | explorer.exe | |||||||||||
User: admin Company: Mpe fcqhdbc Integrity Level: MEDIUM Description: Mpe vmfsit Exit code: 3221226540 Version: 7.6.2609.1265 (aaat.180449-2328) Modules
| |||||||||||||||
| 3916 | "C:\Users\admin\Desktop\google sketchup pro 2019 crack plus key-20876a0448.exe" | C:\Users\admin\Desktop\google sketchup pro 2019 crack plus key-20876a0448.exe | explorer.exe | ||||||||||||
User: admin Company: Mpe fcqhdbc Integrity Level: HIGH Description: Mpe vmfsit Exit code: 0 Version: 7.6.2609.1265 (aaat.180449-2328) Modules
| |||||||||||||||
| (PID) Process: | (3560) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (3560) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (3560) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\72\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3560) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\google sketchup pro 2019 crack plus key_4289d353e.iso | |||
| (PID) Process: | (3560) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (3560) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (3560) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (3560) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (3560) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin |
| Operation: | write | Name: | Placement |
Value: 2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF420000004A0000000204000037020000 | |||
| (PID) Process: | (3560) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\General |
| Operation: | write | Name: | LastFolder |
Value: C:\Users\admin\AppData\Local\Temp | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3560 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3560.29975\google sketchup pro 2019 crack plus key-20876a0448.exe | executable | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3916 | google sketchup pro 2019 crack plus key-20876a0448.exe | POST | 200 | 104.27.143.212:80 | http://kinohome.live/v2/events | US | html | 6.53 Kb | malicious |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
3916 | google sketchup pro 2019 crack plus key-20876a0448.exe | 104.27.143.212:80 | kinohome.live | Cloudflare Inc | US | shared |
Domain | IP | Reputation |
|---|---|---|
kinohome.live |
| malicious |
PID | Process | Class | Message |
|---|---|---|---|
3916 | google sketchup pro 2019 crack plus key-20876a0448.exe | Misc activity | ADWARE [PTsecurity] Win32/DownloadAssistant.F |