| File name: | WinRAR 6.10 Final [32bit 64bit] Crack [Coder].zip |
| Full analysis: | https://app.any.run/tasks/50c21458-0a2c-48ed-bc1b-a5601398ea03 |
| Verdict: | Malicious activity |
| Analysis date: | January 26, 2022, 10:02:11 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v1.0 to extract |
| MD5: | 8FB2EC5B7C7D25A0E74FD02582402702 |
| SHA1: | 8571D709C02E0404E624466ED0BE2C93BF3CAD85 |
| SHA256: | E3432CE45E84491676EB2ADDEA9D64A3BF22AB72EAF9B454D4BC0A554D0FBF54 |
| SSDEEP: | 196608:hwDF5+kmfOJbSXOMVON7xvlogeSOatlUhD:ez+kmfqbSXSl7rtlU9 |
| .xpi | | | Mozilla Firefox browser extension (66.6) |
|---|---|---|
| .zip | | | ZIP compressed archive (33.3) |
| ZipFileName: | WinRAR 6.10 Final [32bit 64bit] Crack [Coder]/Coder.txt |
|---|---|
| ZipUncompressedSize: | 191 |
| ZipCompressedSize: | 191 |
| ZipCRC: | 0xaf45f319 |
| ZipModifyDate: | 2022:01:26 09:37:13 |
| ZipCompression: | None |
| ZipBitFlag: | 0x0800 |
| ZipRequiredVersion: | 10 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2332 | "C:\Users\admin\Desktop\WinRAR 6.10 Final [32bit 64bit] Crack [Coder]\Setup file for 32bit\winrar-x32-610.exe" | C:\Users\admin\Desktop\WinRAR 6.10 Final [32bit 64bit] Crack [Coder]\Setup file for 32bit\winrar-x32-610.exe | Explorer.EXE | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: HIGH Description: WinRAR archiver Exit code: 9 Version: 6.10.0 Modules
| |||||||||||||||
| 3508 | "C:\Windows\system32\rundll32.exe" C:\Windows\system32\shell32.dll,OpenAs_RunDLL "C:\Users\admin\AppData\Local\Temp\WinRAR 6.10 Final [32bit 64bit] Crack [Coder].zip.xpi" | C:\Windows\system32\rundll32.exe | — | Explorer.EXE | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows host process (Rundll32) Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3880 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\WinRAR 6.10 Final [32bit 64bit] Crack [Coder].zip.xpi" | C:\Program Files\WinRAR\WinRAR.exe | rundll32.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| (PID) Process: | (3508) rundll32.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache |
| Operation: | write | Name: | C:\Windows\eHome\ehshell.exe |
Value: Windows Media Center | |||
| (PID) Process: | (3508) rundll32.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe |
Value: Firefox | |||
| (PID) Process: | (3508) rundll32.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache |
| Operation: | write | Name: | C:\Windows\system32\mspaint.exe |
Value: Paint | |||
| (PID) Process: | (3508) rundll32.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache |
| Operation: | write | Name: | C:\Windows\system32\NOTEPAD.EXE |
Value: Notepad | |||
| (PID) Process: | (3508) rundll32.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache |
| Operation: | write | Name: | C:\PROGRA~1\MICROS~1\Office14\OIS.EXE |
Value: Microsoft Office 2010 | |||
| (PID) Process: | (3508) rundll32.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache |
| Operation: | write | Name: | C:\Program Files\Opera\Opera.exe |
Value: Opera Internet Browser | |||
| (PID) Process: | (3508) rundll32.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache |
| Operation: | write | Name: | C:\Program Files\Windows Photo Viewer\PhotoViewer.dll |
Value: Windows Photo Viewer | |||
| (PID) Process: | (3508) rundll32.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache |
| Operation: | write | Name: | C:\Program Files\VideoLAN\VLC\vlc.exe |
Value: VLC media player | |||
| (PID) Process: | (3508) rundll32.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache |
| Operation: | write | Name: | C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Value: Microsoft Word | |||
| (PID) Process: | (3508) rundll32.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3880 | WinRAR.exe | C:\Users\admin\Desktop\WinRAR 6.10 Final [32bit 64bit] Crack [Coder]\Coder.txt | text | |
MD5:— | SHA256:— | |||
| 3880 | WinRAR.exe | C:\Users\admin\Desktop\WinRAR 6.10 Final [32bit 64bit] Crack [Coder]\Setup file for 32bit\winrar-x32-610.exe | executable | |
MD5:— | SHA256:— | |||
| 3880 | WinRAR.exe | C:\Users\admin\Desktop\WinRAR 6.10 Final [32bit 64bit] Crack [Coder]\Crack file\rarreg.key | text | |
MD5:— | SHA256:— | |||
| 3880 | WinRAR.exe | C:\Users\admin\Desktop\WinRAR 6.10 Final [32bit 64bit] Crack [Coder]\Setup file for 64bit\winrar-x64-610.exe | executable | |
MD5:— | SHA256:— | |||
| 2332 | winrar-x32-610.exe | C:\Program Files\WinRAR\License.txt | text | |
MD5:672064CF19DB0B083B981CF0BE7662B0 | SHA256:9FC8AA33CCAFA04C1CE4C0A61047B341297D720ADAB1B77F67B5FE59F43BB59F | |||
| 2332 | winrar-x32-610.exe | C:\Program Files\WinRAR\Rar.txt | text | |
MD5:AA94798C46F4B375AB50752552B93CA4 | SHA256:AA982C2813A0CA7B8B2461B8500FE72A5B275B4376162D904ED4EC1F86A88423 | |||
| 2332 | winrar-x32-610.exe | C:\Program Files\WinRAR\7zxa.dll | executable | |
MD5:CB6C821F3849C2146C7DBBE5C676C01F | SHA256:1679A59A3D5428CC6A3EA2DAD6670057E263BC3F7F723C0F83F08A859E5A3A09 | |||
| 2332 | winrar-x32-610.exe | C:\Program Files\WinRAR\Default.SFX | executable | |
MD5:EEE3A229DA26073CB80240F32EBE70D3 | SHA256:E1F5ADC2FBE9C783DCB68D3DF79DA423FBE450AB21A18E9985E64EC1CEFF1AD3 | |||
| 2332 | winrar-x32-610.exe | C:\Program Files\WinRAR\ReadMe.txt | text | |
MD5:00D0A57A6D64EE3DE8F4D5529D6C6447 | SHA256:FCD13E1B97AF47B8B923BA97AE15E9731C66093609667C3171D5DD24A6F7F2E6 | |||
| 2332 | winrar-x32-610.exe | C:\Program Files\WinRAR\Descript.ion | text | |
MD5:3FB658E292A09D2303B6D84FAF079E0C | SHA256:FA7BFC756E502CA814F927130574CBB472FC8B9C608F98B470409E7D8D1AD30D | |||