| File name: | LibreHardwareMonitor-net472.zip |
| Full analysis: | https://app.any.run/tasks/47be50ee-278b-4ec4-bd40-81a8bf1df108 |
| Verdict: | Malicious activity |
| Analysis date: | July 30, 2024, 14:18:52 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract, compression method=deflate |
| MD5: | EEC14A641D5F10F55F06478F5DA22C05 |
| SHA1: | 12248C40F613EC3AA91CCE913F699D223EF68C57 |
| SHA256: | EF33F7F3F4FCF00CB9B4DF0066CE6D8C5D13C7AC6D99DEFFCB6098EED9573973 |
| SSDEEP: | 98304:YZbqrOS6c+HhfpGnk808vHLKZBq2PTxsHFsSJaOpS6/G+2LGIIYZgaCJNGflB2bE:k2I |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 20 |
|---|---|
| ZipBitFlag: | 0x0008 |
| ZipCompression: | Deflated |
| ZipModifyDate: | 2023:12:31 12:52:58 |
| ZipCRC: | 0xadc4f5c0 |
| ZipCompressedSize: | 61207 |
| ZipUncompressedSize: | 146944 |
| ZipFileName: | Aga.Controls.dll |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1136 | "C:\Users\admin\Desktop\LibreHardwareMonitor-net472\LibreHardwareMonitor.exe" | C:\Users\admin\Desktop\LibreHardwareMonitor-net472\LibreHardwareMonitor.exe | explorer.exe | ||||||||||||
User: admin Company: LibreHardwareMonitor Integrity Level: HIGH Description: Libre Hardware Monitor Version: 0.9.3.0 Modules
| |||||||||||||||
| 1568 | "C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\Desktop\LibreHardwareMonitor-net472.zip | C:\Program Files\WinRAR\WinRAR.exe | — | explorer.exe | |||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| 2412 | "C:\Program Files\WinRAR\WinRAR.exe" x -iext -ow -ver -- "C:\Users\admin\Desktop\LibreHardwareMonitor-net472.zip" C:\Users\admin\Desktop\LibreHardwareMonitor-net472\ | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| 2548 | "C:\Windows\system32\WBEM\mofcomp.exe" C:\Windows\system32\WBEM\Framework\root\LibreHardwareMonitor\LibreHardwareMonitor_SN__Version_0.9.3.0.mof | C:\Windows\System32\wbem\mofcomp.exe | — | LibreHardwareMonitor.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: The Managed Object Format (MOF) Compiler Exit code: 0 Version: 10.0.14409.1005 (rs1_srvoob.161208-1155) Modules
| |||||||||||||||
| 2736 | "C:\Program Files\Windows Media Player\wmpnscfg.exe" | C:\Program Files\Windows Media Player\wmpnscfg.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Network Sharing Service Configuration Application Exit code: 0 Version: 12.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3504 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 "/OUT:C:\Users\admin\AppData\Local\Temp\RESEF89.tmp" "c:\Users\admin\AppData\Local\Temp\4rkamdfx\CSC3E3F3DDE948648E4A013964033E64C.TMP" | C:\Windows\Microsoft.NET\Framework\v4.0.30319\cvtres.exe | — | csc.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft® Resource File To COFF Object Conversion Utility Exit code: 0 Version: 14.10.25028.0 built by: VCTOOLSD15RTM Modules
| |||||||||||||||
| 3544 | "C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe" /noconfig /fullpaths @"C:\Users\admin\AppData\Local\Temp\4rkamdfx\4rkamdfx.cmdline" | C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe | LibreHardwareMonitor.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Visual C# Command Line Compiler Exit code: 0 Version: 4.8.3761.0 built by: NET48REL1 Modules
| |||||||||||||||
| 3892 | "C:\Users\admin\Desktop\LibreHardwareMonitor-net472\LibreHardwareMonitor.exe" | C:\Users\admin\Desktop\LibreHardwareMonitor-net472\LibreHardwareMonitor.exe | — | explorer.exe | |||||||||||
User: admin Company: LibreHardwareMonitor Integrity Level: MEDIUM Description: Libre Hardware Monitor Exit code: 3221226540 Version: 0.9.3.0 Modules
| |||||||||||||||
| (PID) Process: | (1568) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (1568) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (1568) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (1568) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\phacker.zip | |||
| (PID) Process: | (1568) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (1568) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip | |||
| (PID) Process: | (1568) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop\LibreHardwareMonitor-net472.zip | |||
| (PID) Process: | (1568) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (1568) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (1568) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2412 | WinRAR.exe | C:\Users\admin\Desktop\LibreHardwareMonitor-net472\LibreHardwareMonitorLib.xml | xml | |
MD5:105CC7617B843C786A9BCD8EF6A76CD5 | SHA256:63045964EE6138F26FD8CE7083D9873033D7CB5AA95F14C7CCD6397768402811 | |||
| 2412 | WinRAR.exe | C:\Users\admin\Desktop\LibreHardwareMonitor-net472\Newtonsoft.Json.dll | executable | |
MD5:195FFB7167DB3219B217C4FD439EEDD6 | SHA256:E1E27AF7B07EEEDF5CE71A9255F0422816A6FC5849A483C6714E1B472044FA9D | |||
| 2412 | WinRAR.exe | C:\Users\admin\Desktop\LibreHardwareMonitor-net472\OxyPlot.WindowsForms.dll | executable | |
MD5:42DB63F47FF2B3EB71CA4E1B24C9C7E4 | SHA256:57BB97DD3053D9849490721B2E1F671E28062C5B416D45E8D447F8180DCA19ED | |||
| 2412 | WinRAR.exe | C:\Users\admin\Desktop\LibreHardwareMonitor-net472\Aga.Controls.dll | executable | |
MD5:A492C040DC7F2749DB754274D0B7AA1B | SHA256:C5FDF080CCE883D702EBB6660B9A4FEF6B2D17CE3E4D2C785DD66A969CF67CAC | |||
| 2412 | WinRAR.exe | C:\Users\admin\Desktop\LibreHardwareMonitor-net472\HidSharp.dll | executable | |
MD5:8D3EB299F8447B633334D1C426A2F0F7 | SHA256:8C58E5FBA22ACC751032DFE97CE633E4F8A4C96089749BF316D55283B36649C2 | |||
| 2412 | WinRAR.exe | C:\Users\admin\Desktop\LibreHardwareMonitor-net472\LibreHardwareMonitorLib.pdb | binary | |
MD5:68BE4ED297BE38F65CC150A3C4611C50 | SHA256:139824062A36EAE0AA689F01191F093693841B1FB904B8EDA0B80DDC1EB5CDB4 | |||
| 2412 | WinRAR.exe | C:\Users\admin\Desktop\LibreHardwareMonitor-net472\LibreHardwareMonitor.exe | executable | |
MD5:40D8A89DE4E6B12F4F5D146EDDBF14B6 | SHA256:2811FA3CF6DA248AFD46032D8407F5466C011F6B814BA3D24A178A161E4259D3 | |||
| 2412 | WinRAR.exe | C:\Users\admin\Desktop\LibreHardwareMonitor-net472\LibreHardwareMonitorLib.dll | executable | |
MD5:5B4FF376C0A64564DBDC149E686035E0 | SHA256:A24C7CBB3D6CA12950E570FBAD82778A87C87311CDE6218914A283A2C0A04E19 | |||
| 2412 | WinRAR.exe | C:\Users\admin\Desktop\LibreHardwareMonitor-net472\LibreHardwareMonitor.exe.config | xml | |
MD5:21FA0B1D75C0CC7369F1E735FE90C7A9 | SHA256:AD8267122C40D37DCD9D99E1412D763187A1825732F378DB8867F3ECF675CF70 | |||
| 2412 | WinRAR.exe | C:\Users\admin\Desktop\LibreHardwareMonitor-net472\Aga.Controls.pdb | pdb | |
MD5:66EFF911A602F41206C7E4CF7F7D11AC | SHA256:7C0574A4270AB68B315E92AC7F182237B8DE0A9CEB0189ABBF25A1748E86350D | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
1372 | svchost.exe | GET | 304 | 23.50.131.216:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?33775f6043c93e33 | unknown | — | — | whitelisted |
1060 | svchost.exe | GET | 304 | 93.184.221.240:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?fbe613066ac7852b | unknown | — | — | whitelisted |
1372 | svchost.exe | GET | 200 | 23.52.120.96:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
1372 | svchost.exe | GET | 200 | 23.48.23.143:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 224.0.0.252:5355 | — | — | — | whitelisted |
1372 | svchost.exe | 40.127.240.158:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
1060 | svchost.exe | 224.0.0.252:5355 | — | — | — | whitelisted |
1372 | svchost.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
1372 | svchost.exe | 23.50.131.216:80 | ctldl.windowsupdate.com | Akamai International B.V. | DE | unknown |
1372 | svchost.exe | 23.48.23.143:80 | crl.microsoft.com | Akamai International B.V. | DE | unknown |
1372 | svchost.exe | 23.52.120.96:80 | www.microsoft.com | AKAMAI-AS | DE | unknown |
1060 | svchost.exe | 93.184.221.240:80 | ctldl.windowsupdate.com | EDGECAST | GB | whitelisted |
Domain | IP | Reputation |
|---|---|---|
google.com |
| whitelisted |
dns.msftncsi.com |
| whitelisted |
settings-win.data.microsoft.com |
| whitelisted |
ctldl.windowsupdate.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |