| File name: | Hyper Tweaks Master Pack.zip |
| Full analysis: | https://app.any.run/tasks/2c58d9ef-110e-4287-a56b-5f3cec615425 |
| Verdict: | Malicious activity |
| Analysis date: | June 30, 2023, 13:36:38 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract |
| MD5: | EA9764A83951A28442AC196036D2539C |
| SHA1: | E01AD89433CF19738ADB7126A5556DB105C48B06 |
| SHA256: | F68108593F8AD32D28D214E22BBA4CBC2395975F9D54E63C2E7775FB885BCB3B |
| SSDEEP: | 98304:B24OUljZMZzpr2LBNljZMZzpkS+ffNs+ff3:B2ajCZzpr2hjCZzpkSCfNsCf3 |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipFileName: | Hyper Tweaks Master Pack/ |
|---|---|
| ZipUncompressedSize: | - |
| ZipCompressedSize: | - |
| ZipCRC: | 0x00000000 |
| ZipModifyDate: | 2023:06:30 03:12:00 |
| ZipCompression: | Deflated |
| ZipBitFlag: | 0x0808 |
| ZipRequiredVersion: | 20 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 116 | wevtutil.exe cl "Microsoft-Windows-Diagnostics-Performance/Diagnostic" | C:\Windows\System32\wevtutil.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Eventing Command Line Utility Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 116 | REG ADD "HKCU\SOFTWARE\Sysinternals\Process Explorer" /v "ShowCpuFractions" /t REG_DWORD /d "1" /f | C:\Windows\System32\reg.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Registry Console Tool Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 116 | POWERSHELL Disable-NetAdapterPowerManagement -Name "*" -ErrorAction SilentlyContinue | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows PowerShell Exit code: 1 Version: 10.0.14409.1005 (rs1_srvoob.161208-1155) Modules
| |||||||||||||||
| 116 | REG ADD "HKLM\System\CurrentControlSet\Services\Volmgrx" /v "Start" /t REG_DWORD /d "4" /f | C:\Windows\System32\reg.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Registry Console Tool Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 120 | findstr /L "VEN_" | C:\Windows\System32\findstr.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Find String (QGREP) Utility Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 120 | REG ADD "HKLM\System\CurrentControlSet\Services\UEFI" /v "Start" /t REG_DWORD /d "4" /f | C:\Windows\System32\reg.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Registry Console Tool Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 120 | REG ADD "HKLM\SYSTEM\CurrentControlSet\Control\GraphicsDrivers\Power" /v "DisableWriteCombining" /t REG_DWORD /d "1" /f | C:\Windows\System32\reg.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Registry Console Tool Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 124 | REG ADD "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ngen.exe\PerfOptions" /v "CpuPriorityClass" /t REG_DWORD /d "1" /f | C:\Windows\System32\reg.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Registry Console Tool Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 124 | BCDEDIT /set allowedinmemorysettings 0x0 | C:\Windows\System32\bcdedit.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Boot Configuration Data Editor Exit code: 1 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 124 | REG ADD "HKLM\Software\Policies\Microsoft\Windows\System" /v "DisableHHDEP" /t REG_DWORD /d "1" /f | C:\Windows\System32\reg.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Registry Console Tool Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (3336) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\16D\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3336) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip | |||
| (PID) Process: | (3336) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (3336) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop\phacker.zip | |||
| (PID) Process: | (3336) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (3336) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (3336) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (3336) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (3336) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin |
| Operation: | write | Name: | Placement |
Value: 2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000 | |||
| (PID) Process: | (3336) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\General |
| Operation: | write | Name: | LastFolder |
Value: C:\Users\admin\Desktop | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3336 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3336.19689\Hyper Tweaks Master Pack\HYPER TWEAKS MASTER PACK\GOD Windows tweaks\dir\Enable_Photo_viewer.reg | text | |
MD5:DB258A23A8E84385E3E2EEB5A4CB08BD | SHA256:43DE47D128E00EE8D3A8D7187ACDC55DE1171683E754C84E0FBF1EC208CC48A6 | |||
| 3336 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3336.19689\Hyper Tweaks Master Pack\HYPER TWEAKS MASTER PACK\Clean files HYPER TWEAKS\Clean bat\Cache Cleaner.bat | text | |
MD5:F3A60B82F758EA4E7ECB9CA473C1E99D | SHA256:7BDF3CFCD458FE5DE706DCEB5873343046E481233ABE9F60EA63633D788027AD | |||
| 3336 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3336.19689\Hyper Tweaks Master Pack\HYPER TWEAKS MASTER PACK\FilterKeys MASTER TWEAKS\KEYBOARD TWEAKS\FilterKeysSetter.exe | executable | |
MD5:154BE5241FCFD60A6D87D955DF5EFA6D | SHA256:08594A3E6DDF07D21F1F8392574ECEF0C80E2D8B18CFEA9F791EAF5977DF0CCB | |||
| 3336 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3336.19689\Hyper Tweaks Master Pack\HYPER TWEAKS MASTER PACK\Clean files HYPER TWEAKS\Clean\13 Disk Cleanup (Clean Up System Files).lnk | binary | |
MD5:052EBE462113C605DC34896953098C6D | SHA256:9531896EEB920DD6382A79AECF2F86F6975EF5C06617617A5A1E8D039DBBF1D8 | |||
| 3336 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3336.19689\Hyper Tweaks Master Pack\HYPER TWEAKS MASTER PACK\Clean files HYPER TWEAKS\Clean bat\Clean.bat | text | |
MD5:1C8A46E47F30C1A94A451B4187E3D36B | SHA256:FC4EA2D360DE896E3AE5AD1D7831FCFEFDD18A2E7754CCF0D6271A034A4284C2 | |||
| 3336 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3336.19689\Hyper Tweaks Master Pack\HYPER TWEAKS MASTER PACK\Clean files HYPER TWEAKS\Clean bat\Delete Log Files.bat | text | |
MD5:1A77A87536950F7B5BCE7A7A81A00486 | SHA256:E1EF04BCFF94FD02A606A6AB267027D4E799F9510B3F8CEC32ED8DD32B5A6A88 | |||
| 3336 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3336.19689\Hyper Tweaks Master Pack\HYPER TWEAKS MASTER PACK\GOD Windows tweaks\dir\Disable_Cortana.reg | text | |
MD5:A34759BA52A2E6484421B2892A56B14F | SHA256:1EEE313DB91C13A19EAF54B8604FE4921545D6B983E065A6CD39020A3128F07A | |||
| 3336 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3336.19689\Hyper Tweaks Master Pack\HYPER TWEAKS MASTER PACK\Clean files HYPER TWEAKS\Clean\10 Delete _Temp_ Files.lnk | binary | |
MD5:0172D7A6C2810707C634975454C55604 | SHA256:3FC5A52A42A780040E220A826ACC5B77813F8CF6DD646585E89C88A080B95C15 | |||
| 3336 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3336.19689\Hyper Tweaks Master Pack\HYPER TWEAKS MASTER PACK\Controller overclock\Tutorial.txt | text | |
MD5:200010478540898461C6E80FC0EEFEC8 | SHA256:3D7B1C4B4079511ABEC8EA7B22C90CA971AE533AE2FCEFE62700725509D4067E | |||
| 3336 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3336.19689\Hyper Tweaks Master Pack\HYPER TWEAKS MASTER PACK\Clean files HYPER TWEAKS\Clean\DeviceCleanup.ini | text | |
MD5:FFBF201CBC7423B9C6879516ADD1A09A | SHA256:17FE9B56CB79BFC615A72CAD7FAF87FCC12AD39BCB83BDF63681F61311E91704 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
2756 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
1076 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
Process | Message |
|---|---|
Dism.exe | PID=3556 Instantiating the Provider Store. - CDISMImageSession::get_ProviderStore |
Dism.exe | PID=3556 Initializing a provider store for the LOCAL session type. - CDISMProviderStore::Final_OnConnect |
Dism.exe | PID=3556 Attempting to initialize the logger from the Image Session. - CDISMProviderStore::Final_OnConnect |
Dism.exe | PID=3556 Provider has not previously been encountered. Attempting to initialize the provider. - CDISMProviderStore::Internal_GetProvider |
Dism.exe | PID=3556 Loading Provider from location C:\Windows\System32\Dism\LogProvider.dll - CDISMProviderStore::Internal_GetProvider |
Dism.exe | PID=3556 Connecting to the provider located at C:\Windows\System32\Dism\LogProvider.dll. - CDISMProviderStore::Internal_LoadProvider |
Dism.exe | PID=3556 Getting Provider OSServices - CDISMProviderStore::GetProvider |
Dism.exe | PID=3556 The requested provider was not found in the Provider Store. - CDISMProviderStore::Internal_GetProvider(hr:0x80004005) |
Dism.exe | PID=3556 Failed to get an OSServices provider. Must be running in local store. Falling back to checking alongside the log provider for wdscore.dll. - CDISMLogger::FindWdsCore(hr:0x80004005) |
DismHost.exe | PID=1956 Encountered a loaded provider DISMLogger. - CDISMProviderStore::Internal_DisconnectProvider |