| File name: | WinRAR 6.10 Final [32bit 64bit] Crack [Coder].zip |
| Full analysis: | https://app.any.run/tasks/50c21458-0a2c-48ed-bc1b-a5601398ea03 |
| Verdict: | Malicious activity |
| Analysis date: | January 26, 2022, 10:02:11 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v1.0 to extract |
| MD5: | 8FB2EC5B7C7D25A0E74FD02582402702 |
| SHA1: | 8571D709C02E0404E624466ED0BE2C93BF3CAD85 |
| SHA256: | E3432CE45E84491676EB2ADDEA9D64A3BF22AB72EAF9B454D4BC0A554D0FBF54 |
| SSDEEP: | 196608:hwDF5+kmfOJbSXOMVON7xvlogeSOatlUhD:ez+kmfqbSXSl7rtlU9 |
| .xpi | | | Mozilla Firefox browser extension (66.6) |
|---|---|---|
| .zip | | | ZIP compressed archive (33.3) |
| ZipFileName: | WinRAR 6.10 Final [32bit 64bit] Crack [Coder]/Coder.txt |
|---|---|
| ZipUncompressedSize: | 191 |
| ZipCompressedSize: | 191 |
| ZipCRC: | 0xaf45f319 |
| ZipModifyDate: | 2022:01:26 09:37:13 |
| ZipCompression: | None |
| ZipBitFlag: | 0x0800 |
| ZipRequiredVersion: | 10 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2332 | "C:\Users\admin\Desktop\WinRAR 6.10 Final [32bit 64bit] Crack [Coder]\Setup file for 32bit\winrar-x32-610.exe" | C:\Users\admin\Desktop\WinRAR 6.10 Final [32bit 64bit] Crack [Coder]\Setup file for 32bit\winrar-x32-610.exe | Explorer.EXE | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: HIGH Description: WinRAR archiver Exit code: 9 Version: 6.10.0 Modules
| |||||||||||||||
| 3508 | "C:\Windows\system32\rundll32.exe" C:\Windows\system32\shell32.dll,OpenAs_RunDLL "C:\Users\admin\AppData\Local\Temp\WinRAR 6.10 Final [32bit 64bit] Crack [Coder].zip.xpi" | C:\Windows\system32\rundll32.exe | — | Explorer.EXE | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows host process (Rundll32) Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3880 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\WinRAR 6.10 Final [32bit 64bit] Crack [Coder].zip.xpi" | C:\Program Files\WinRAR\WinRAR.exe | rundll32.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| (PID) Process: | (3508) rundll32.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache |
| Operation: | write | Name: | C:\Windows\eHome\ehshell.exe |
Value: Windows Media Center | |||
| (PID) Process: | (3508) rundll32.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe |
Value: Firefox | |||
| (PID) Process: | (3508) rundll32.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache |
| Operation: | write | Name: | C:\Windows\system32\mspaint.exe |
Value: Paint | |||
| (PID) Process: | (3508) rundll32.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache |
| Operation: | write | Name: | C:\Windows\system32\NOTEPAD.EXE |
Value: Notepad | |||
| (PID) Process: | (3508) rundll32.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache |
| Operation: | write | Name: | C:\PROGRA~1\MICROS~1\Office14\OIS.EXE |
Value: Microsoft Office 2010 | |||
| (PID) Process: | (3508) rundll32.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache |
| Operation: | write | Name: | C:\Program Files\Opera\Opera.exe |
Value: Opera Internet Browser | |||
| (PID) Process: | (3508) rundll32.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache |
| Operation: | write | Name: | C:\Program Files\Windows Photo Viewer\PhotoViewer.dll |
Value: Windows Photo Viewer | |||
| (PID) Process: | (3508) rundll32.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache |
| Operation: | write | Name: | C:\Program Files\VideoLAN\VLC\vlc.exe |
Value: VLC media player | |||
| (PID) Process: | (3508) rundll32.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache |
| Operation: | write | Name: | C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Value: Microsoft Word | |||
| (PID) Process: | (3508) rundll32.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3880 | WinRAR.exe | C:\Users\admin\Desktop\WinRAR 6.10 Final [32bit 64bit] Crack [Coder]\Coder.txt | text | |
MD5:— | SHA256:— | |||
| 2332 | winrar-x32-610.exe | C:\Program Files\WinRAR\License.txt | text | |
MD5:672064CF19DB0B083B981CF0BE7662B0 | SHA256:9FC8AA33CCAFA04C1CE4C0A61047B341297D720ADAB1B77F67B5FE59F43BB59F | |||
| 2332 | winrar-x32-610.exe | C:\Program Files\WinRAR\Order.htm | html | |
MD5:5C336DE3B3D794322AD9E5915E3A509F | SHA256:BCE29EF3B95306CB7B304FB8C3039BE7157356D9F9D4E7E1C6BFBF02A117F48F | |||
| 2332 | winrar-x32-610.exe | C:\Program Files\WinRAR\Uninstall.exe | executable | |
MD5:1E4ECDB0CA5F73B79DA4DDDD0FD1AE66 | SHA256:431B365B4E95E0C7A864F9B6F97D5A30911CC1FCC14CDB97887D262A51E52C67 | |||
| 2332 | winrar-x32-610.exe | C:\Program Files\WinRAR\Descript.ion | text | |
MD5:3FB658E292A09D2303B6D84FAF079E0C | SHA256:FA7BFC756E502CA814F927130574CBB472FC8B9C608F98B470409E7D8D1AD30D | |||
| 2332 | winrar-x32-610.exe | C:\Program Files\WinRAR\RarExt64.dll | executable | |
MD5:02FFB00705D8269227B0318E6082035D | SHA256:8A310437F8BD6DEA569783353DAD2E1AA9400A93FBD2C8D708DA67E16FE0925F | |||
| 3880 | WinRAR.exe | C:\Users\admin\Desktop\WinRAR 6.10 Final [32bit 64bit] Crack [Coder]\Setup file for 64bit\winrar-x64-610.exe | executable | |
MD5:— | SHA256:— | |||
| 2332 | winrar-x32-610.exe | C:\Program Files\WinRAR\Rar.exe | executable | |
MD5:53E8EF208EC4F687A4E728013872D49B | SHA256:E7ADF9D8F3A83A8130E21E122F29FBFE096A4F80F71CB1E3A57B45562B548880 | |||
| 2332 | winrar-x32-610.exe | C:\Program Files\WinRAR\WhatsNew.txt | text | |
MD5:8E1B3621B868F50FC8FE45991056E970 | SHA256:0AFA8DBC79BB7CEDAD30E5EF62888028949F63A9603D66664B6D7922FB0BFF09 | |||
| 2332 | winrar-x32-610.exe | C:\Program Files\WinRAR\Default.SFX | executable | |
MD5:EEE3A229DA26073CB80240F32EBE70D3 | SHA256:E1F5ADC2FBE9C783DCB68D3DF79DA423FBE450AB21A18E9985E64EC1CEFF1AD3 | |||