| File name: | BleachBit-4.6.0-portable.zip |
| Full analysis: | https://app.any.run/tasks/a2d9cce1-75ad-40a0-b8a2-275574233553 |
| Verdict: | Malicious activity |
| Analysis date: | February 12, 2024, 18:52:28 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract, compression method=store |
| MD5: | 86B543EBFD356501F8246D5FAF1CA608 |
| SHA1: | DD0D5521757EFC94718424AA1173F24E4F74B03E |
| SHA256: | EE9C06251E56695119B8184979F9BB17FB8BE44C2A0A46B34A8FDFA97CBCA502 |
| SSDEEP: | 98304:dYLEELqBrvNgfAi2gNHJEJfCoiKFzks/gnn7bGpd2JV/4Fjrlzo9RznhlIFDigov:J5HN5UwrXAHXWcWQ62FCGD |
| .zip | | | ZIP compressed archive (36.3) |
|---|
| ZipRequiredVersion: | 20 |
|---|---|
| ZipBitFlag: | - |
| ZipCompression: | None |
| ZipModifyDate: | 2023:11:05 15:37:28 |
| ZipCRC: | 0x00000000 |
| ZipCompressedSize: | - |
| ZipUncompressedSize: | - |
| ZipFileName: | BleachBit-Portable/ |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1576 | "C:\Windows\explorer.exe" | C:\Windows\explorer.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Explorer Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1880 | "C:\Windows\system32\rundll32.exe" C:\Users\admin\Desktop\BLEACH~1\LIBGIO~1.DLL,g_win32_run_session_bus@16 | C:\Windows\System32\rundll32.exe | — | bleachbit_console.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows host process (Rundll32) Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2648 | "C:\Users\admin\Desktop\BleachBit-Portable\bleachbit.exe" --gui --no-uac | C:\Users\admin\Desktop\BleachBit-Portable\bleachbit.exe | bleachbit.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: BleachBit frees space and maintains privacy by quickly wiping files you don't need and didn't know you had. Supported applications include Edge, Firefox, Google Chrome, VLC, and many others. Exit code: 0 Version: 4.6.0 Modules
| |||||||||||||||
| 2852 | "C:\Users\admin\Desktop\BleachBit-Portable\bleachbit.exe" | C:\Users\admin\Desktop\BleachBit-Portable\bleachbit.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: BleachBit frees space and maintains privacy by quickly wiping files you don't need and didn't know you had. Supported applications include Edge, Firefox, Google Chrome, VLC, and many others. Exit code: 0 Version: 4.6.0 Modules
| |||||||||||||||
| 2916 | "C:\Users\admin\Desktop\BleachBit-Portable\bleachbit_console.exe" | C:\Users\admin\Desktop\BleachBit-Portable\bleachbit_console.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: BleachBit frees space and maintains privacy by quickly wiping files you don't need and didn't know you had. Supported applications include Edge, Firefox, Google Chrome, VLC, and many others. Exit code: 0 Version: 4.6.0 Modules
| |||||||||||||||
| 2980 | "C:\Users\admin\Desktop\BleachBit-Portable\bleachbit_console.exe" --gui --no-uac | C:\Users\admin\Desktop\BleachBit-Portable\bleachbit_console.exe | bleachbit_console.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: BleachBit frees space and maintains privacy by quickly wiping files you don't need and didn't know you had. Supported applications include Edge, Firefox, Google Chrome, VLC, and many others. Exit code: 0 Version: 4.6.0 Modules
| |||||||||||||||
| 3668 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\BleachBit-4.6.0-portable.zip" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| 3964 | "C:\Windows\system32\rundll32.exe" C:\Users\admin\Desktop\BLEACH~1\LIBGIO~1.DLL,g_win32_run_session_bus@16 | C:\Windows\System32\rundll32.exe | — | bleachbit.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows host process (Rundll32) Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (3668) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (3668) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (3668) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3668) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\phacker.zip | |||
| (PID) Process: | (3668) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (3668) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip | |||
| (PID) Process: | (3668) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\BleachBit-4.6.0-portable.zip | |||
| (PID) Process: | (3668) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (3668) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (3668) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3668 | WinRAR.exe | C:\Users\admin\Desktop\BleachBit-Portable\cacert.pem | text | |
MD5:EA4EE2AF66C4C57B8A275867E9DC07CD | SHA256:FA883829EBB8CD2A602F9B21C1F85DE24CF47949D520BCEB1828B4CD1CB6906C | |||
| 3668 | WinRAR.exe | C:\Users\admin\Desktop\BleachBit-Portable\etc\dbus-1\system.conf | text | |
MD5:B03D0315F1346F423075CA3A33EA0739 | SHA256:C9992C5D59FE38703B613383963E4417D23D96115D5EE8D08A214B81DF6A1B57 | |||
| 3668 | WinRAR.exe | C:\Users\admin\Desktop\BleachBit-Portable\COPYING | text | |
MD5:C678957B0C8E964AA6C70FD77641A71E | SHA256:E79E9C8A0C85D735FF98185918EC94ED7D175EFC377012787AEBCF3B80F0D90B | |||
| 3668 | WinRAR.exe | C:\Users\admin\Desktop\BleachBit-Portable\etc\fonts\conf.d\20-unhint-small-dejavu-sans-mono.conf | xml | |
MD5:0CBF30E4580C5A8570DA071AB12C5E4D | SHA256:3E90C9C36BEEF46F10D1529251F8683B9C4AC900695ADBB4A23A4B6036F938A5 | |||
| 3668 | WinRAR.exe | C:\Users\admin\Desktop\BleachBit-Portable\etc\fonts\conf.d\20-unhint-small-dejavu-serif.conf | xml | |
MD5:E90C678D46F49BB9D6BA469B64E80C0C | SHA256:68777B1705EC7A05A86430DEF4BE093668E84E305CC7E11291DF52403A7318CC | |||
| 3668 | WinRAR.exe | C:\Users\admin\Desktop\BleachBit-Portable\etc\fonts\conf.d\10-scale-bitmap-fonts.conf | xml | |
MD5:C79833EF7E11FC58472AAE2D55E233B2 | SHA256:9E8E338453028B8B6AD97A9103E799A1E338B51E8231C73D28B82A4C530927A0 | |||
| 3668 | WinRAR.exe | C:\Users\admin\Desktop\BleachBit-Portable\etc\fonts\conf.d\20-unhint-small-dejavu-sans.conf | xml | |
MD5:F7DF7BBA810DD953DD78212900F4DCAD | SHA256:0D9C177B6A85DAA9957ED6750D4EB26122604DA18D340E7BA31E6F4D24F963ED | |||
| 3668 | WinRAR.exe | C:\Users\admin\Desktop\BleachBit-Portable\etc\fonts\conf.d\20-unhint-small-vera.conf | xml | |
MD5:6FB496D0BB963A54D5DB870955DDD771 | SHA256:855E1F86A70170982CDA0E796E407173C81E4033537CCB6FA899F638A324EF60 | |||
| 3668 | WinRAR.exe | C:\Users\admin\Desktop\BleachBit-Portable\etc\fonts\conf.d\28-user.conf | xml | |
MD5:A266C2A0043823CBF1D24299A8192DCA | SHA256:E7452C8AD25DD83C07C405B20DACFDD60D329933E666496E6D6D325B7962197B | |||
| 3668 | WinRAR.exe | C:\Users\admin\Desktop\BleachBit-Portable\BleachBit.ini | text | |
MD5:0FA0571B5329B8A2B4019589E97FE1F6 | SHA256:CF864D8C3E89A789B57218413EB047F3F66537303BC0729013F4CFC887F956DB | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
2648 | bleachbit.exe | 104.21.36.254:443 | update.bleachbit.org | CLOUDFLARENET | — | unknown |
2980 | bleachbit_console.exe | 104.21.36.254:443 | update.bleachbit.org | CLOUDFLARENET | — | unknown |
Domain | IP | Reputation |
|---|---|---|
update.bleachbit.org |
| unknown |