| File name: | patch-pawel97.rar |
| Full analysis: | https://app.any.run/tasks/54dfe09f-b5e7-4989-a96b-ab245694b197 |
| Verdict: | Malicious activity |
| Analysis date: | July 13, 2021, 16:54:29 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-rar |
| File info: | RAR archive data, v5 |
| MD5: | 41301B1C0600EBBCF9BEE7E0A693143B |
| SHA1: | B11CB26C4DE503B75F87336C9E0426ABF6F6E8FD |
| SHA256: | FEAC0F0AF15DE4069B8CF77B80923ECBFFC9A1B6B028F814279B5DBEC438CF87 |
| SSDEEP: | 384:QrgKDZB3g6kLKYQ7w38jPYN2r7F5Ng64BbjiF8/d6yNSR4MvFpccheDoaHc+WI9:Qte6kL0s215NgzbjiF8mztScheDkfs |
| .rar | | | RAR compressed archive (v5.0) (61.5) |
|---|---|---|
| .rar | | | RAR compressed archive (gen) (38.4) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 980 | "C:\Users\admin\Desktop\Patch-IDM637+-2020.exe" | C:\Users\admin\Desktop\Patch-IDM637+-2020.exe | Explorer.EXE | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 1648 | "C:\Users\admin\Desktop\Patch-IDM637+-2020.exe" | C:\Users\admin\Desktop\Patch-IDM637+-2020.exe | — | Explorer.EXE | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 3221226540 Modules
| |||||||||||||||
| 3476 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\patch-pawel97.rar" | C:\Program Files\WinRAR\WinRAR.exe | Explorer.EXE | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| (PID) Process: | (3476) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (3476) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (3476) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3476) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip | |||
| (PID) Process: | (3476) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\patch-pawel97.rar | |||
| (PID) Process: | (3476) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (3476) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (3476) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (3476) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (980) Patch-IDM637+-2020.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\FirstFolder |
| Operation: | write | Name: | 0 |
Value: 43003A005C00550073006500720073005C00610064006D0069006E005C004400650073006B0074006F0070005C00500061007400630068002D00490044004D003600330037002B002D0032003000320030002E00650078006500000043003A005C00550073006500720073005C00610064006D0069006E005C004400650073006B0074006F0070000000 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 980 | Patch-IDM637+-2020.exe | C:\Users\admin\AppData\Local\Temp\C5E3399ED9A072FE864748D49BA96094.dll | executable | |
MD5:13249BC6AA781475CDE4A1C90F95EFD4 | SHA256:3922A8C1B0F58B74FC3D89D7EEC3FE5C5B0E8BDA6B36491D2380431DD8E8284A | |||
| 3476 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3476.12544\Patch-IDM637+-2020.exe | executable | |
MD5:D4A4EBD73C7B73D38942CB935DCAFDB0 | SHA256:0337238EEE215586E58575D52C4D93055311ECEA574F32E98FA31A89EC7DFE1E | |||
| 980 | Patch-IDM637+-2020.exe | C:\Users\admin\AppData\Local\Temp\dup2patcher.dll | executable | |
MD5:BF2A62AEF3C7349012E19BD311EE1D69 | SHA256:5C5CA06898375A082CC19500B56458A29D11F92A83A8766E0CE00FF95514B903 | |||