| File name: | JDownloader.jar |
| Full analysis: | https://app.any.run/tasks/bc200177-d4cf-4060-8658-35f7edbefc95 |
| Verdict: | Malicious activity |
| Analysis date: | May 19, 2019, 14:32:43 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/java-archive |
| File info: | Java archive data (JAR) |
| MD5: | 995E43D989E30CFD5289DA17F41275FA |
| SHA1: | 6006E0915D2A485EF6DE684BDC78357EC80EB07B |
| SHA256: | F52342201874896EDA372063F7B704B7A3758D0FE1CA9F5F9B485CCBCFE3AC97 |
| SSDEEP: | 49152:1bra1QxXQN2LMZQ94EUUO8CcAzvPYFlu+KJLDM9CHz+hE2yMwe3HUy367YVKMdpN:wi6eMu40AzUlu/JLDM4HCLKmpzAOyi |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 20 |
|---|---|
| ZipBitFlag: | 0x0808 |
| ZipCompression: | Deflated |
| ZipModifyDate: | 2018:11:30 11:42:05 |
| ZipCRC: | 0x390f57d5 |
| ZipCompressedSize: | 119 |
| ZipUncompressedSize: | 138 |
| ZipFileName: | META-INF/MANIFEST.MF |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 556 | "C:\Program Files\Java\jre1.8.0_92\bin\javaw.exe" -jar JDownloader.jar | C:\Program Files\Java\jre1.8.0_92\bin\javaw.exe | javaw.exe | ||||||||||||
User: admin Company: Oracle Corporation Integrity Level: MEDIUM Description: Java(TM) Platform SE binary Exit code: 0 Version: 8.0.920.14 Modules
| |||||||||||||||
| 2172 | reg query "HKEY_CURRENT_USER\Control Panel\Desktop" /v "ForegroundLockTimeout" | C:\Windows\system32\reg.exe | — | javaw.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Registry Console Tool Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2548 | "C:\Program Files\Java\jre1.8.0_92\bin\javaw.exe" -jar C:\Users\admin\AppData\Local\Temp\tmp\update\self\JDU\JDownloader.jar -selftest tmp/selftest_1558276412909 C:\Users\admin\AppData\Local\Temp | C:\Program Files\Java\jre1.8.0_92\bin\javaw.exe | javaw.exe | ||||||||||||
User: admin Company: Oracle Corporation Integrity Level: MEDIUM Description: Java(TM) Platform SE binary Exit code: 0 Version: 8.0.920.14 Modules
| |||||||||||||||
| 2560 | "C:\Program Files\Java\jre1.8.0_92\bin\javaw.exe" -jar JDownloader.jar -afterupdate | C:\Program Files\Java\jre1.8.0_92\bin\javaw.exe | javaw.exe | ||||||||||||
User: admin Company: Oracle Corporation Integrity Level: MEDIUM Description: Java(TM) Platform SE binary Exit code: 0 Version: 8.0.920.14 Modules
| |||||||||||||||
| 2660 | reg query "HKEY_CURRENT_USER\Control Panel\Desktop" /v "ForegroundLockTimeout" | C:\Windows\system32\reg.exe | — | javaw.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Registry Console Tool Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2904 | reg query "HKEY_CURRENT_USER\Control Panel\Desktop" /v "ForegroundLockTimeout" | C:\Windows\system32\reg.exe | — | javaw.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Registry Console Tool Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3324 | reg query "HKEY_CURRENT_USER\Control Panel\Desktop" /v "ForegroundLockTimeout" | C:\Windows\system32\reg.exe | — | javaw.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Registry Console Tool Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3540 | "C:\Program Files\Java\jre1.8.0_92\bin\javaw.exe" -jar "C:\Users\admin\AppData\Local\Temp\JDownloader.jar" | C:\Program Files\Java\jre1.8.0_92\bin\javaw.exe | explorer.exe | ||||||||||||
User: admin Company: Oracle Corporation Integrity Level: MEDIUM Description: Java(TM) Platform SE binary Exit code: 0 Version: 8.0.920.14 Modules
| |||||||||||||||
| 3944 | reg query "HKEY_CURRENT_USER\Control Panel\Desktop" /v "ForegroundLockTimeout" | C:\Windows\system32\reg.exe | — | javaw.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Registry Console Tool Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3540 | javaw.exe | C:\Users\admin\AppData\Local\Temp\cfg\ProxySelector.proxies.json.tmp | — | |
MD5:— | SHA256:— | |||
| 3540 | javaw.exe | C:\Users\admin\AppData\Local\Temp\cfg\org.jdownloader.settings.InternetConnectionSettings.customproxylist.json.tmp | — | |
MD5:— | SHA256:— | |||
| 3540 | javaw.exe | C:\Users\admin\AppData\Local\Temp\update\versioninfo\JD\org.appwork.updatesys.client.tracker.TrackConfig.tracklog.json.tmp | — | |
MD5:— | SHA256:— | |||
| 3540 | javaw.exe | C:\Users\admin\AppData\Local\Temp\update\versioninfo\JDU\org.appwork.updatesys.client.tracker.TrackConfig.tracklog.json.tmp | — | |
MD5:— | SHA256:— | |||
| 3540 | javaw.exe | C:\Users\admin\AppData\Local\Temp\tmp\update\JDU\updatePackage.id.bac | — | |
MD5:— | SHA256:— | |||
| 3540 | javaw.exe | C:\Users\admin\AppData\Local\Temp\tmp\update\JD\updatePackage.id.bac | — | |
MD5:— | SHA256:— | |||
| 3540 | javaw.exe | C:\Users\admin\AppData\Local\Temp\tmp\update\JD\updatePackage | — | |
MD5:— | SHA256:— | |||
| 3540 | javaw.exe | C:\Users\admin\AppData\Local\Temp\tmp\update\JD\updatePackage.awf | — | |
MD5:— | SHA256:— | |||
| 3540 | javaw.exe | C:\Users\admin\AppData\Local\Temp\tmp\update\package_1558276412800.awf | — | |
MD5:— | SHA256:— | |||
| 3540 | javaw.exe | C:\Users\admin\AppData\Local\Temp\tmp\update\package_1558276412800.awf.info.bac | — | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2548 | javaw.exe | GET | 302 | 176.9.34.43:80 | http://update.appwork.org/jcgi/lastchance?app=JD&pkh=12f1848a883e733ed40fffff0dae2f35&jh=46c499ebb994dd3b0aeaf87c3eca7061&rev=-1&srev=-1&urev=-1&surev=-1&rt=ST&st=1 | DE | — | — | suspicious |
3540 | javaw.exe | GET | 200 | 176.9.34.43:80 | http://update.appwork.org/jcgi/pkg?rt=SO&jn=JDownloader.jar&pv=5&cv=2100000001&ping=&uid=1558276382800_5866539752646505053_jd&pkh=12f1848a883e733ed40fffff0dae2f35&app=JD&os=WINDOWS&arch=X86&os64=0&jvm64=0&urev=-1&srev=-1&surev=-1&ct=Normal&rev=-1&dst=-1&lng=en_US&chlg=0&jdiff=1&dedup=INTRA&awfcxz=1&1558276382816 | DE | text | 10 b | suspicious |
3540 | javaw.exe | GET | 200 | 88.99.115.62:80 | http://cdn9.appwork.org/JDU/12912/155807416238478a624a5635106ce069fbe40a9023346_0b37679a4a51628aa541b05521fe6bda2dce22915-0 | DE | binary | 3.16 Mb | suspicious |
3540 | javaw.exe | GET | 200 | 176.9.34.43:80 | http://update.appwork.org/jcgi/pkg?rt=SO&jn=JDownloader.jar&pv=5&cv=2100000001&ping=&uid=1558276383128_-7031943599767362181_jds&pkh=12f1848a883e733ed40fffff0dae2f35&app=JDU&os=WINDOWS&arch=X86&os64=0&jvm64=0&ct=Normal&rev=-1&dst=-1&lng=en_US&chlg=0&jdiff=1&dedup=INTRA&awfcxz=1&1558276383128 | DE | text | 4.38 Kb | suspicious |
3540 | javaw.exe | GET | 200 | 176.9.34.43:80 | http://update.appwork.org/jcgi/pkg?rt=SO&jn=JDownloader.jar&pv=5&cv=2100000001&ping=&uid=1558276382800_5866539752646505053_jd&pkh=12f1848a883e733ed40fffff0dae2f35&app=JD&os=WINDOWS&arch=X86&os64=0&jvm64=0&urev=2147483647&srev=-1&surev=-1&ct=Normal&rev=-1&dst=-1&lng=en_US&chlg=0&jdiff=1&dedup=INTRA&awfcxz=1&1558276383253 | DE | text | 4.37 Kb | suspicious |
3540 | javaw.exe | GET | 200 | 85.131.130.150:80 | http://cdn10.appwork.org/JD/12885/1558074481296622a27004d7ac38e09e5e50a40d3616e_028db838fe4fcfcf529efa74d00c0ff10c83d56ae-0 | DE | binary | 32.7 Mb | suspicious |
2548 | javaw.exe | GET | 200 | 176.9.34.43:80 | http://cdn4.appwork.org/JD/JD_lastChanceRescueMe.jar.enc | DE | binary | 1.66 Kb | suspicious |
3540 | javaw.exe | GET | 200 | 176.9.34.43:80 | http://update.appwork.org/jcgi/track?rt=SO&jn=JDownloader.jar&pv=5&cv=2100000001&ping=&uid=1558276382800_5866539752646505053_jd&pkh=12f1848a883e733ed40fffff0dae2f35&app=JD&os=WINDOWS&arch=X86&os64=0&jvm64=0&urev=2147483647&srev=-1&surev=-1&ct=Normal&data=%7B%22json%22%3A%22%7B%5C%22timeStamp%5C%22%3A1558276383426%2C%5C%22data%5C%22%3A%5C%22%7B%5C%5C%5C%22resume%5C%5C%5C%22%3Afalse%2C%5C%5C%5C%22expectedBytes%5C%5C%5C%22%3A34316704%2C%5C%5C%5C%22clientRepo%5C%5C%5C%22%3A%5C%5C%5C%22JDownloader%2F201707061810%5C%5C%5C%22%2C%5C%5C%5C%22cdnSignature%5C%5C%5C%22%3A%5C%5C%5C%22VALID%5C%5C%5C%22%2C%5C%5C%5C%22serverTag%5C%5C%5C%22%3A%5C%5C%5C%22nginx%2F1.15.10%5C%5C%5C%22%2C%5C%5C%5C%22url%5C%5C%5C%22%3A%5C%5C%5C%22http%3A%2F%2Fcdn10.appwork.org%2FJD%2F12885%2F1558074481296622a27004d7ac38e09e5e50a40d3616e_028db838fe4fcfcf529efa74d00c0ff10c83d56ae-0%5C%5C%5C%22%2C%5C%5C%5C%22responseCode%5C%5C%5C%22%3A200%2C%5C%5C%5C%22timeStamp%5C%5C%5C%22%3A1558276383426%2C%5C%5C%5C%22duration%5C%5C%5C%22%3A21015%2C%5C%5C%5C%22responseBytes%5C%5C%5C%22%3A34316704%2C%5C%5C%5C%22resumeFrom%5C%5C%5C%22%3A0%2C%5C%5C%5C%22bytes%5C%5C%5C%22%3A34316704%2C%5C%5C%5C%22host%5C%5C%5C%22%3A%5C%5C%5C%22cdn10.appwork.org%5C%5C%5C%22%2C%5C%5C%5C%22logVersion%5C%5C%5C%22%3A1%2C%5C%5C%5C%22contentType%5C%5C%5C%22%3A%5C%5C%5C%22application%2Foctet-stream%5C%5C%5C%22%2C%5C%5C%5C%22status%5C%5C%5C%22%3A%5C%5C%5C%22OK%5C%5C%5C%22%7D%5C%22%2C%5C%22id%5C%22%3A1558276383397%2C%5C%22type%5C%22%3A%5C%22TRAFFIC_LOG%5C%22%7D%22%2C%22type%22%3A%22TRAFFIC_LOG%22%7D&1558276404441 | DE | text | 2 b | suspicious |
2560 | javaw.exe | GET | 200 | 176.9.34.43:80 | http://update.appwork.org/jcgi/pkg?st=0&rt=SO&jn=JDownloader.jar&pv=9&cv=20190425001&pkh=12f1848a883e733ed40fffff0dae2f35&app=JD&os=WINDOWS&osr=WINDOWS_7&arch=X86&os64=0&jvm64=0&java=18092014&uid=dnt_&urev=12912&srev=-1&surev=12912&ct=Normal&rev=12885&dedup=INTRA&awfcxz=1&dst=-1&lng=en_US&chlg=0&jdiff=1&1558276418987 | DE | text | 163 b | suspicious |
556 | javaw.exe | GET | 404 | 176.9.34.43:80 | http://update.appwork.org/jcgi/lastchance?app=JD&pkh=12f1848a883e733ed40fffff0dae2f35&jh=46c499ebb994dd3b0aeaf87c3eca7061&rev=12885&srev=12885&urev=12912&surev=12912 | DE | — | — | suspicious |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2560 | javaw.exe | 176.9.34.43:80 | update.appwork.org | Hetzner Online GmbH | DE | suspicious |
556 | javaw.exe | 176.9.34.43:80 | update.appwork.org | Hetzner Online GmbH | DE | suspicious |
— | — | 176.9.34.43:80 | update.appwork.org | Hetzner Online GmbH | DE | suspicious |
3540 | javaw.exe | 85.131.130.150:80 | cdn10.appwork.org | Link11 GmbH | DE | unknown |
3540 | javaw.exe | 176.9.34.43:80 | update.appwork.org | Hetzner Online GmbH | DE | suspicious |
3540 | javaw.exe | 88.99.115.62:80 | cdn9.appwork.org | Hetzner Online GmbH | DE | suspicious |
2548 | javaw.exe | 176.9.34.43:80 | update.appwork.org | Hetzner Online GmbH | DE | suspicious |
Domain | IP | Reputation |
|---|---|---|
update.appwork.org |
| suspicious |
cdn10.appwork.org |
| suspicious |
cdn9.appwork.org |
| suspicious |
cdn4.appwork.org |
| suspicious |