| File name: | Ultimate Windows Tweaker Pack.rar |
| Full analysis: | https://app.any.run/tasks/895b3a62-3fe3-4feb-b876-3274f384cb7d |
| Verdict: | Malicious activity |
| Analysis date: | June 01, 2024, 14:11:56 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-rar |
| File info: | RAR archive data, v5 |
| MD5: | CE43620F81C1AC6644A6694B8CF3F00F |
| SHA1: | CD60E000D8F41D05D5D6404F556F52CB3B4AFF45 |
| SHA256: | E1C803F0488A0B4E9E1B47FDCA446732790AA2FA24057158D189C6D4502D261B |
| SSDEEP: | 24576:7SWSpXbv6+qEgx7JCqAoDGHg+bndWq75nfPYQv1:7tSpXbv6+qEgx7JZAoDGHjdWq75nfPYI |
| .rar | | | RAR compressed archive (v5.0) (61.5) |
|---|---|---|
| .rar | | | RAR compressed archive (gen) (38.4) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 368 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --first-renderer-process --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --mojo-platform-channel-handle=2216 --field-trial-handle=1320,i,10556659830748864886,15191428959325626163,131072 /prefetch:1 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Version: 109.0.1518.115 Modules
| |||||||||||||||
| 692 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=35 --mojo-platform-channel-handle=1164 --field-trial-handle=1320,i,10556659830748864886,15191428959325626163,131072 /prefetch:1 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1020 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3956 --field-trial-handle=1320,i,10556659830748864886,15191428959325626163,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1024 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3984 --field-trial-handle=1320,i,10556659830748864886,15191428959325626163,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1028 | "C:\Users\admin\Desktop\Ultimate Windows Tweaker 4.8\Ultimate Windows Tweaker 4.8.exe" | C:\Users\admin\Desktop\Ultimate Windows Tweaker 4.8\Ultimate Windows Tweaker 4.8.exe | explorer.exe | ||||||||||||
User: admin Company: The Windows Club Integrity Level: HIGH Description: Ultimate Windows Tweaker 4.8 Exit code: 0 Version: 4.8.0.0 Modules
| |||||||||||||||
| 1080 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=15 --mojo-platform-channel-handle=3980 --field-trial-handle=1320,i,10556659830748864886,15191428959325626163,131072 /prefetch:1 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1184 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=37 --mojo-platform-channel-handle=2132 --field-trial-handle=1320,i,10556659830748864886,15191428959325626163,131072 /prefetch:1 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1240 | "C:\Users\admin\Desktop\Ultimate Windows Tweaker 4.8\Ultimate Windows Tweaker 4.8.exe" | C:\Users\admin\Desktop\Ultimate Windows Tweaker 4.8\Ultimate Windows Tweaker 4.8.exe | — | explorer.exe | |||||||||||
User: admin Company: The Windows Club Integrity Level: MEDIUM Description: Ultimate Windows Tweaker 4.8 Exit code: 3221226540 Version: 4.8.0.0 Modules
| |||||||||||||||
| 1284 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=17 --mojo-platform-channel-handle=4152 --field-trial-handle=1320,i,10556659830748864886,15191428959325626163,131072 /prefetch:1 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1368 | "C:\Users\admin\Desktop\UWT v2.2\Ultimate Windows Tweaker.exe" | C:\Users\admin\Desktop\UWT v2.2\Ultimate Windows Tweaker.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: Ultimate Windows Tweaker Version: 2.2.0.0 Modules
| |||||||||||||||
| (PID) Process: | (3976) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (3976) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (3976) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3976) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\phacker.zip | |||
| (PID) Process: | (3976) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (3976) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip | |||
| (PID) Process: | (3976) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\Ultimate Windows Tweaker Pack.rar | |||
| (PID) Process: | (3976) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (3976) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (3976) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3976 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3976.43908\Ultimate Windows Tweaker Pack\RAM Optimization\24GB Ram.reg | text | |
MD5:B61F3A91476B5471AC43CB3CCB7855A8 | SHA256:C2BBE087C8FD2F56B58700C7F8EE19525855EF5BFA4DD9A7DD315E99C38EDFEF | |||
| 3976 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3976.43908\Ultimate Windows Tweaker Pack\Cleaner\ATF-Cleaner.exe | executable | |
MD5:D9DE89F0FAF18019BC9595F0F47BCA61 | SHA256:E900D883001EC60353C2E8E1A54E1C5948A11513FFFAFBD5A28B44C1E319677A | |||
| 3976 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3976.43908\Ultimate Windows Tweaker Pack\For Windows 11\UWT5.zip | compressed | |
MD5:ACB41F9EE190D235A279A2EC51FB566E | SHA256:585F5A26710F303595B5210E905D93279CAB50F827F9B2F77B2E6F6A533EC1F7 | |||
| 3976 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3976.43908\Ultimate Windows Tweaker Pack\RAM Optimization\16GB Ram.reg | text | |
MD5:0B237013DEED49B23D7BC554428C61BD | SHA256:CF8B50BF2584488ADF9A629A3980BA6149A16131B73F1EDF0571B06C7CD35B9B | |||
| 3976 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3976.43908\Ultimate Windows Tweaker Pack\RAM Optimization\6GB Ram.reg | text | |
MD5:5812550FF961E33A8727CEFC9C106506 | SHA256:5A5711488873DB522C1092F55D47756B0632CDF2DFC4A2C747310A11B1E532DA | |||
| 3976 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3976.43908\Ultimate Windows Tweaker Pack\RAM Optimization\48GB Ram.reg | text | |
MD5:5F74951E5CEAE31DEC1BFA65EB737F67 | SHA256:7379D6819A0CCD37E0688FE0B38B237E70F435E6519736B14C77CACEDCE105CA | |||
| 3976 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3976.43908\Ultimate Windows Tweaker Pack\RAM Optimization\64GB Ram.reg | text | |
MD5:2C745BCE4B294BC98D2DF8C9428BA733 | SHA256:5A56903C364A5F4AFC1036E5F1EFF25826340D7C08A54C07CB91AC7906F188F2 | |||
| 3976 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3976.43908\Ultimate Windows Tweaker Pack\RAM Optimization\3GB Ram.reg | text | |
MD5:7C27A485A55FEE8A815C5FCEB4B27B87 | SHA256:4B7E7AFA1A12FEECD575F5FDF2B405324C7D6444049938955891DE78FB3AA3A1 | |||
| 3976 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3976.43908\Ultimate Windows Tweaker Pack\RAM Optimization\20GB Ram.reg | text | |
MD5:558013B46D325679BAB85CCA901CEAF5 | SHA256:C3537FAC4C63E20BEC51E6E4E4D86B68CFA8B13F258A256C0E536D81D870C398 | |||
| 3976 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3976.43908\Ultimate Windows Tweaker Pack\RAM Optimization\2GB Ram.reg | text | |
MD5:5AE14EB3FEBA46B8E96B41278D7D73B4 | SHA256:65C5F3E60952B0C38CF7F435DD81BECA9F49DF708AC62F8644E955626E13E466 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3080 | msedge.exe | GET | 200 | 192.229.221.95:80 | http://cacerts.rapidssl.com/RapidSSLTLSRSACAG1.crt | unknown | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1088 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
3080 | msedge.exe | 13.107.42.16:443 | config.edge.skype.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
3080 | msedge.exe | 172.67.73.191:443 | www.thewindowsclub.com | CLOUDFLARENET | US | unknown |
3080 | msedge.exe | 204.79.197.239:443 | edge.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | unknown |
2796 | msedge.exe | 239.255.255.250:1900 | — | — | — | unknown |
3080 | msedge.exe | 172.67.199.186:443 | privacy.gatekeeperconsent.com | CLOUDFLARENET | US | unknown |
3080 | msedge.exe | 142.250.185.136:443 | www.googletagmanager.com | GOOGLE | US | unknown |
3080 | msedge.exe | 216.58.206.78:443 | www.youtube.com | GOOGLE | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
www.thewindowsclub.com |
| unknown |
config.edge.skype.com |
| whitelisted |
edge.microsoft.com |
| whitelisted |
privacy.gatekeeperconsent.com |
| unknown |
www.googletagmanager.com |
| whitelisted |
player.anyclip.com |
| unknown |
www.youtube.com |
| whitelisted |
go.ezoic.net |
| shared |
go.ezodn.com |
| unknown |
reviews.thewindowsclub.com |
| unknown |