File name: | MicTray.cab |
Full analysis: | https://app.any.run/tasks/4cf2138d-a8c0-4485-9391-44c5244636f2 |
Verdict: | Malicious activity |
Analysis date: | November 19, 2019, 19:41:48 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | application/vnd.ms-cab-compressed |
File info: | Microsoft Cabinet archive data, 9224939 bytes, 7 files |
MD5: | 20D782CCAFC0492A0D1E41E5D6FEB694 |
SHA1: | F9EC70B866257C6A3DA8E0264E7DEE66A778E3AA |
SHA256: | F00969B10037F3C19A4BCE435743615894DAB301AB6E3432AED96E663354C1D4 |
SSDEEP: | 196608:d9DpZEbwamxjiOQ6ZkRiFlw5KhVvtuaqwmJzLhibazurfsbeD1l:zD3EcBQykelYaqHJPhyrfsCX |
.cab | | | Microsoft Cabinet Archive (100) |
---|
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
1096 | "C:\Users\admin\Desktop\MicTray\Setup.exe" | C:\Users\admin\Desktop\MicTray\Setup.exe | — | explorer.exe | |||||||||||
User: admin Company: Conexant Systems, Inc. Integrity Level: MEDIUM Description: Conexant Universal Device Install/Uninstall x86 Application Exit code: 3221226540 Version: 7.152.0.2 Modules
| |||||||||||||||
2084 | "C:\Users\admin\Desktop\MicTray\Setup.exe" | C:\Users\admin\Desktop\MicTray\Setup.exe | explorer.exe | ||||||||||||
User: admin Company: Conexant Systems, Inc. Integrity Level: HIGH Description: Conexant Universal Device Install/Uninstall x86 Application Exit code: 0 Version: 7.152.0.2 Modules
| |||||||||||||||
2840 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\MicTray.cab" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.60.0 Modules
|
(PID) Process: | (2840) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
Operation: | write | Name: | ShellExtBMP |
Value: | |||
(PID) Process: | (2840) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
Operation: | write | Name: | ShellExtIcon |
Value: | |||
(PID) Process: | (2840) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E |
Operation: | write | Name: | LanguageList |
Value: en-US | |||
(PID) Process: | (2840) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\MicTray.cab | |||
(PID) Process: | (2840) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | name |
Value: 120 | |||
(PID) Process: | (2840) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | size |
Value: 80 | |||
(PID) Process: | (2840) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | type |
Value: 120 | |||
(PID) Process: | (2840) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | mtime |
Value: 100 | |||
(PID) Process: | (2840) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\DialogEditHistory\ExtrPath |
Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop | |||
(PID) Process: | (2840) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin |
Operation: | write | Name: | Placement |
Value: 2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000 |
PID | Process | Filename | Type | |
---|---|---|---|---|
2840 | WinRAR.exe | C:\Users\admin\Desktop\MicTray\MicTray.ini | ini | |
MD5:— | SHA256:— | |||
2840 | WinRAR.exe | C:\Users\admin\Desktop\MicTray\Setup.exe | executable | |
MD5:EC187C15FF1B0C0DFA01162436C4D4F4 | SHA256:16A0671B07DEB72951D662404F59A3FA94901673B51063DEE9D21CAACB258CEF | |||
2084 | Setup.exe | C:\ProgramData\UIU\InstallerLogs\UIU_INSTALL.LOG | text | |
MD5:— | SHA256:— | |||
2084 | Setup.exe | C:\Windows\TEMP\MicTray.ini | ini | |
MD5:— | SHA256:— | |||
2084 | Setup.exe | C:\Windows\SYSTEM32\LOGL2DI_COINST.DAT | text | |
MD5:F4892F13662D3690A1AA34EFF5F2F1FE | SHA256:9BF2DE0F6F6507392E985F13BE9B501AAE1878C97A5738DAA3706009E21481AB | |||
2084 | Setup.exe | C:\Windows\INF\setupapi.app.log | text | |
MD5:— | SHA256:— | |||
2840 | WinRAR.exe | C:\Users\admin\Desktop\MicTray\MicTray\MicTray.exe | executable | |
MD5:89F7A319607FB7D87B2512E7EF5CF7E1 | SHA256:E882149C43976DFADB2746EB2D75A73F0BE5AA193623B18B50827F43CCE3ED84 | |||
2840 | WinRAR.exe | C:\Users\admin\Desktop\MicTray\x64\Setup64.exe | executable | |
MD5:BC9D62B926AA285243FE30D8FD06F5AB | SHA256:E446898E598680C0A31F69E81F81A41010703A3F48F5E9AE43F5F6B8C5E2D46E | |||
2840 | WinRAR.exe | C:\Users\admin\Desktop\MicTray\MicTray\MicTray.xml | xml | |
MD5:F42460C53E58B35A84BA52E9ADC5B35C | SHA256:DDABBD086B22E1057753133245D25206445CC438B6DDE86E4F0EEF87211C48F2 | |||
2840 | WinRAR.exe | C:\Users\admin\Desktop\MicTray\MicTray\MicTray64.xml | xml | |
MD5:1D7C0B6A252665DC1607FBB6F8D6A6A9 | SHA256:BA1BC46AE6A4A6ECCA08028022163E6BBA291C330B057C6235C33A7519E617B7 |