File name:

Acrylic WiFi Professional 3.0.5770.30583 + Crack {B4tman}.rar

Full analysis: https://app.any.run/tasks/0ffdf3a3-66f5-4c4d-8a12-10c5a3d3cd98
Verdict: Suspicious activity
Analysis date: December 06, 2019, 15:57:26
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v4, os: Win32, flags: Solid
MD5:

6430D2F8A762170295455304A6C48997

SHA1:

186CF76397B5095F8D1020BE07454005B0C1034A

SHA256:

F685FD37EDB362DB46D69F7E9D76092B12CD07045541CF1D1F41E4409276E3C1

SSDEEP:

196608:EWAVf2aE4rcFO8h3I10Hk80UfXrwW3FVzcXeQ3tWIhH:VgfXEguI10Hk80UfXlMXEIhH

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Acrylic.exe (PID: 2520)
      • Acrylic.exe (PID: 2580)
    • Changes settings of System certificates

      • Acrylic.exe (PID: 2580)
    • Starts Visual C# compiler

      • Acrylic.exe (PID: 2580)
    • Loads dropped or rewritten executable

      • Acrylic.exe (PID: 2580)
      • Acrylic.exe (PID: 2520)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • Setup.tmp (PID: 720)
      • Setup.exe (PID: 2112)
      • Setup.exe (PID: 2600)
      • Setup.tmp (PID: 2744)
      • Setup.tmp (PID: 2528)
      • Setup.exe (PID: 1792)
      • Setup.exe (PID: 3820)
      • Setup.tmp (PID: 2004)
    • Reads the Windows organization settings

      • Setup.tmp (PID: 720)
      • Setup.tmp (PID: 2528)
      • Setup.tmp (PID: 2744)
      • Setup.tmp (PID: 2004)
    • Reads Windows owner or organization settings

      • Setup.tmp (PID: 720)
      • Setup.tmp (PID: 2528)
      • Setup.tmp (PID: 2744)
      • Setup.tmp (PID: 2004)
    • Creates files in the user directory

      • Setup.tmp (PID: 2004)
      • Acrylic.exe (PID: 2580)
      • Setup.tmp (PID: 2744)
    • Adds / modifies Windows certificates

      • Acrylic.exe (PID: 2580)
    • Reads Environment values

      • Acrylic.exe (PID: 2580)
  • INFO

    • Manual execution by user

      • Setup.exe (PID: 2600)
      • Setup.exe (PID: 2112)
    • Application was dropped or rewritten from another process

      • Setup.tmp (PID: 2528)
      • Setup.tmp (PID: 720)
      • Setup.tmp (PID: 2744)
      • Setup.tmp (PID: 2004)
    • Loads dropped or rewritten executable

      • Setup.tmp (PID: 2528)
      • Setup.tmp (PID: 720)
      • Setup.tmp (PID: 2744)
      • Setup.tmp (PID: 2004)
    • Creates a software uninstall entry

      • Setup.tmp (PID: 2744)
      • Setup.tmp (PID: 2004)
    • Creates files in the program directory

      • Setup.tmp (PID: 2744)
      • Setup.tmp (PID: 2004)
    • Reads settings of System Certificates

      • Acrylic.exe (PID: 2580)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v-4.x) (58.3)
.rar | RAR compressed archive (gen) (41.6)

EXIF

ZIP

CompressedSize: 247
UncompressedSize: 110
OperatingSystem: Win32
ModifyDate: 2014:01:22 11:40:24
PackingMethod: Best Compression
ArchivedFileName: Acrylic WiFi Professional 3.0.5770.30583 + Crack {B4tman}\informacion.txt
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
55
Monitored processes
13
Malicious processes
8
Suspicious processes
1

Behavior graph

Click at the process to see the details
start drop and start drop and start drop and start drop and start drop and start winrar.exe no specs setup.exe setup.tmp setup.exe setup.tmp setup.exe setup.tmp setup.exe setup.tmp acrylic.exe acrylic.exe no specs csc.exe no specs cvtres.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
436"C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe" /noconfig /fullpaths @"C:\Users\admin\AppData\Local\Temp\mivnii2i\mivnii2i.cmdline"C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeAcrylic.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Visual C# Command Line Compiler
Exit code:
0
Version:
4.7.3062.0 built by: NET472REL1
Modules
Images
c:\windows\microsoft.net\framework\v4.0.30319\csc.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\msvcr120_clr0400.dll
c:\windows\system32\ole32.dll
720"C:\Users\admin\AppData\Local\Temp\is-4176A.tmp\Setup.tmp" /SL5="$30194,8014445,265216,C:\Users\admin\Desktop\Acrylic WiFi Professional 3.0.5770.30583 + Crack {B4tman}\Setup.exe" C:\Users\admin\AppData\Local\Temp\is-4176A.tmp\Setup.tmp
Setup.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-4176a.tmp\setup.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1252C:\Windows\Microsoft.NET\Framework\v4.0.30319\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 "/OUT:C:\Users\admin\AppData\Local\Temp\RES8CA5.tmp" "c:\Users\admin\AppData\Local\Temp\mivnii2i\CSCE36896249EB44A9994E5D72471259C82.TMP"C:\Windows\Microsoft.NET\Framework\v4.0.30319\cvtres.execsc.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft® Resource File To COFF Object Conversion Utility
Exit code:
0
Version:
12.00.52519.0 built by: VSWINSERVICING
Modules
Images
c:\windows\microsoft.net\framework\v4.0.30319\cvtres.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\msvcr120_clr0400.dll
c:\windows\system32\cryptsp.dll
1792"C:\Users\admin\Desktop\Acrylic WiFi Professional 3.0.5770.30583 + Crack {B4tman}\Setup.exe" /DIR="C:\Program Files\Acrylic Wi-Fi Professional" /ELEVATEC:\Users\admin\Desktop\Acrylic WiFi Professional 3.0.5770.30583 + Crack {B4tman}\Setup.exe
Setup.tmp
User:
admin
Company:
Tarlogic Security S.L.
Integrity Level:
HIGH
Description:
Acrylic Wi-Fi Professional Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\desktop\acrylic wifi professional 3.0.5770.30583 + crack {b4tman}\setup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2004"C:\Users\admin\AppData\Local\Temp\is-1RSKT.tmp\Setup.tmp" /SL5="$401EA,8014445,265216,C:\Users\admin\Desktop\Acrylic WiFi Professional 3.0.5770.30583 + Crack {B4tman}\Setup.exe" /DIR="C:\Program Files\Acrylic Wi-Fi Professional" /ELEVATEC:\Users\admin\AppData\Local\Temp\is-1RSKT.tmp\Setup.tmp
Setup.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-1rskt.tmp\setup.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2112"C:\Users\admin\Desktop\Acrylic WiFi Professional 3.0.5770.30583 + Crack {B4tman}\Setup.exe" C:\Users\admin\Desktop\Acrylic WiFi Professional 3.0.5770.30583 + Crack {B4tman}\Setup.exe
explorer.exe
User:
admin
Company:
Tarlogic Security S.L.
Integrity Level:
MEDIUM
Description:
Acrylic Wi-Fi Professional Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\desktop\acrylic wifi professional 3.0.5770.30583 + crack {b4tman}\setup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2188"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Acrylic WiFi Professional 3.0.5770.30583 + Crack {B4tman}.rar"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2520"C:\Program Files\Acrylic Wi-Fi Professional\Acrylic.exe"C:\Program Files\Acrylic Wi-Fi Professional\Acrylic.exeSetup.tmp
User:
admin
Company:
Tarlogic Security S.L.
Integrity Level:
HIGH
Description:
Acrylic Wi-Fi Professional
Exit code:
0
Version:
3.0
Modules
Images
c:\program files\acrylic wi-fi professional\acrylic.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2528"C:\Users\admin\AppData\Local\Temp\is-MB8HD.tmp\Setup.tmp" /SL5="$301E4,8014445,265216,C:\Users\admin\Desktop\Acrylic WiFi Professional 3.0.5770.30583 + Crack {B4tman}\Setup.exe" C:\Users\admin\AppData\Local\Temp\is-MB8HD.tmp\Setup.tmp
Setup.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-mb8hd.tmp\setup.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2580"C:\Program Files\Acrylic Wi-Fi Professional\Acrylic.exe"C:\Program Files\Acrylic Wi-Fi Professional\Acrylic.exe
Setup.tmp
User:
admin
Company:
Tarlogic Security S.L.
Integrity Level:
HIGH
Description:
Acrylic Wi-Fi Professional
Exit code:
0
Version:
3.0
Modules
Images
c:\program files\acrylic wi-fi professional\acrylic.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
Total events
1 233
Read events
1 086
Write events
128
Delete events
19

Modification events

(PID) Process:(2188) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2188) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2188) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2188) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Acrylic WiFi Professional 3.0.5770.30583 + Crack {B4tman}.rar
(PID) Process:(2188) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2188) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2188) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2188) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2188) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000
(PID) Process:(2188) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\General
Operation:writeName:LastFolder
Value:
C:\Users\admin\AppData\Local\Temp
Executable files
86
Suspicious files
7
Text files
72
Unknown types
13

Dropped files

PID
Process
Filename
Type
2188WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2188.38186\Acrylic WiFi Professional 3.0.5770.30583 + Crack {B4tman}\Setup.exe
MD5:
SHA256:
2188WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2188.38186\Acrylic WiFi Professional 3.0.5770.30583 + Crack {B4tman}\Crack\Tarlogic.Common.dll
MD5:
SHA256:
2188WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2188.38186\Acrylic WiFi Professional 3.0.5770.30583 + Crack {B4tman}\Crack\Tarlogic.Gui.dll
MD5:
SHA256:
2188WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2188.38186\Acrylic WiFi Professional 3.0.5770.30583 + Crack {B4tman}\Crack\Crack - Shortcut.lnk
MD5:
SHA256:
2188WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2188.38186\Acrylic WiFi Professional 3.0.5770.30583 + Crack {B4tman}\aletinte.png
MD5:
SHA256:
2744Setup.tmpC:\Program Files\Acrylic Wi-Fi Professional\is-RGIJ2.tmp
MD5:
SHA256:
2744Setup.tmpC:\Program Files\Acrylic Wi-Fi Professional\is-KTVKG.tmp
MD5:
SHA256:
2744Setup.tmpC:\Program Files\Acrylic Wi-Fi Professional\is-EANOS.tmp
MD5:
SHA256:
2744Setup.tmpC:\Program Files\Acrylic Wi-Fi Professional\Libs\is-P0B12.tmp
MD5:
SHA256:
2744Setup.tmpC:\Program Files\Acrylic Wi-Fi Professional\Libs\is-PJO56.tmp
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
3
DNS requests
3
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2580
Acrylic.exe
GET
200
2.16.186.114:80
http://aia.startssl.com/certs/ca.crt
unknown
der
1.95 Kb
whitelisted
2580
Acrylic.exe
GET
200
93.184.221.240:80
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab
US
compressed
57.4 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2580
Acrylic.exe
2.16.186.114:80
aia.startssl.com
Akamai International B.V.
whitelisted
2580
Acrylic.exe
54.74.23.184:443
licensing.acrylicwifi.com
Amazon.com, Inc.
IE
unknown
2580
Acrylic.exe
93.184.221.240:80
www.download.windowsupdate.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted

DNS requests

Domain
IP
Reputation
aia.startssl.com
  • 2.16.186.114
  • 2.16.186.82
whitelisted
www.download.windowsupdate.com
  • 93.184.221.240
whitelisted
licensing.acrylicwifi.com
  • 54.74.23.184
unknown

Threats

No threats detected
No debug info