File name:

Users_nvasquez_Downloads_DriverScanner_driverscanner.exe_.zip

Full analysis: https://app.any.run/tasks/dd2f11bb-878b-49f8-9250-c4bb9f06fb23
Verdict: Malicious activity
Analysis date: January 19, 2024, 14:28:45
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v1.0 to extract
MD5:

619E4BCB62CBC78757A91F2B0C2A2AA9

SHA1:

79A96C24FEDD42359B5119E239AD738EF4126729

SHA256:

01C57467E8E520FA1901C4A93ECF9DD85DAE53AE674C6C27AF34E581A85A6DDD

SSDEEP:

98304:aIGRgtuIxqA0HAjo8fLxFj9LCJxRIIlzKQuQ9dVHe4tK1dxDTBWa0WN8xqxNakYu:455h9m

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • driverscanner.exe (PID: 2068)
      • driverscanner.exe (PID: 584)
      • driverscanner.tmp (PID: 1772)
  • SUSPICIOUS

    • Application launched itself

      • WinRAR.exe (PID: 116)
    • Executable content was dropped or overwritten

      • driverscanner.exe (PID: 584)
      • driverscanner.exe (PID: 2068)
      • driverscanner.tmp (PID: 1772)
    • Reads the Windows owner or organization settings

      • driverscanner.tmp (PID: 1772)
    • Process drops legitimate windows executable

      • driverscanner.tmp (PID: 1772)
    • Executes as Windows Service

      • VSSVC.exe (PID: 1112)
    • Searches for installed software

      • dllhost.exe (PID: 2344)
      • driverscanner.tmp (PID: 1772)
    • The process drops C-runtime libraries

      • driverscanner.tmp (PID: 1772)
    • Reads the Internet Settings

      • driverscanner.tmp (PID: 1772)
      • driverscanner.exe (PID: 2572)
    • The process executes via Task Scheduler

      • dsmonitor.exe (PID: 1984)
    • Reads Microsoft Outlook installation path

      • driverscanner.exe (PID: 2572)
    • Reads Internet Explorer settings

      • driverscanner.exe (PID: 2572)
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 1288)
    • Checks supported languages

      • driverscanner.exe (PID: 2068)
      • driverscanner.tmp (PID: 2076)
      • driverscanner.exe (PID: 584)
      • driverscanner.tmp (PID: 1772)
      • dsmonitor.exe (PID: 2692)
      • ds_move_serial.exe (PID: 2636)
      • driverscanner.exe (PID: 2572)
      • dsmonitor.exe (PID: 1984)
    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 1288)
    • Reads the computer name

      • driverscanner.tmp (PID: 2076)
      • driverscanner.tmp (PID: 1772)
      • ds_move_serial.exe (PID: 2636)
      • dsmonitor.exe (PID: 2692)
      • dsmonitor.exe (PID: 1984)
      • driverscanner.exe (PID: 2572)
    • Create files in a temporary directory

      • driverscanner.exe (PID: 2068)
      • driverscanner.exe (PID: 584)
      • driverscanner.tmp (PID: 1772)
    • Creates files in the program directory

      • driverscanner.tmp (PID: 1772)
      • driverscanner.exe (PID: 2572)
    • Reads the machine GUID from the registry

      • driverscanner.tmp (PID: 1772)
      • ds_move_serial.exe (PID: 2636)
      • dsmonitor.exe (PID: 2692)
      • dsmonitor.exe (PID: 1984)
      • driverscanner.exe (PID: 2572)
    • Creates files or folders in the user directory

      • driverscanner.tmp (PID: 1772)
      • dsmonitor.exe (PID: 2692)
      • driverscanner.exe (PID: 2572)
    • Reads Environment values

      • ds_move_serial.exe (PID: 2636)
      • dsmonitor.exe (PID: 2692)
      • dsmonitor.exe (PID: 1984)
      • driverscanner.exe (PID: 2572)
    • Checks proxy server information

      • driverscanner.exe (PID: 2572)
    • Reads CPU info

      • driverscanner.exe (PID: 2572)
    • Reads product name

      • driverscanner.exe (PID: 2572)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 10
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2024:01:19 09:19:26
ZipCRC: 0xf7545a08
ZipCompressedSize: 5312386
ZipUncompressedSize: 5312386
ZipFileName: AVSamples.zip
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
52
Monitored processes
12
Malicious processes
6
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe no specs winrar.exe driverscanner.exe driverscanner.tmp no specs driverscanner.exe driverscanner.tmp vssvc.exe no specs SPPSurrogate no specs ds_move_serial.exe no specs dsmonitor.exe no specs driverscanner.exe dsmonitor.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
116"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Users_nvasquez_Downloads_DriverScanner_driverscanner.exe_.zip"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
584"C:\Users\admin\AppData\Local\Temp\Rar$EXb1288.2657\Users\nvasquez\Downloads\DriverScanner\driverscanner.exe" /SPAWNWND=$30146 /NOTIFYWND=$5015C C:\Users\admin\AppData\Local\Temp\Rar$EXb1288.2657\Users\nvasquez\Downloads\DriverScanner\driverscanner.exe
driverscanner.tmp
User:
admin
Company:
Uniblue Systems Ltd
Integrity Level:
HIGH
Description:
DriverScanner Setup
Exit code:
0
Version:
4.0.10.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exb1288.2657\users\nvasquez\downloads\driverscanner\driverscanner.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1112C:\Windows\system32\vssvc.exeC:\Windows\System32\VSSVC.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Volume Shadow Copy Service
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\vssvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1288"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\Rar$DIa116.2241\AVSamples.zipC:\Program Files\WinRAR\WinRAR.exe
WinRAR.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
1772"C:\Users\admin\AppData\Local\Temp\is-UEUPG.tmp\driverscanner.tmp" /SL5="$5013A,5160607,434176,C:\Users\admin\AppData\Local\Temp\Rar$EXb1288.2657\Users\nvasquez\Downloads\DriverScanner\driverscanner.exe" /SPAWNWND=$30146 /NOTIFYWND=$5015C C:\Users\admin\AppData\Local\Temp\is-UEUPG.tmp\driverscanner.tmp
driverscanner.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-ueupg.tmp\driverscanner.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1984"C:\Program Files\Uniblue\DriverScanner\dsmonitor.exe" C:\Program Files\Uniblue\DriverScanner\dsmonitor.exetaskeng.exe
User:
admin
Company:
Uniblue Systems Ltd
Integrity Level:
HIGH
Description:
Uniblue DriverScanner Monitor
Exit code:
0
Version:
4.0.10.0
Modules
Images
c:\program files\uniblue\driverscanner\dsmonitor.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
2068"C:\Users\admin\AppData\Local\Temp\Rar$EXb1288.2657\Users\nvasquez\Downloads\DriverScanner\driverscanner.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXb1288.2657\Users\nvasquez\Downloads\DriverScanner\driverscanner.exe
WinRAR.exe
User:
admin
Company:
Uniblue Systems Ltd
Integrity Level:
MEDIUM
Description:
DriverScanner Setup
Exit code:
0
Version:
4.0.10.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exb1288.2657\users\nvasquez\downloads\driverscanner\driverscanner.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2076"C:\Users\admin\AppData\Local\Temp\is-I1UNP.tmp\driverscanner.tmp" /SL5="$5015C,5160607,434176,C:\Users\admin\AppData\Local\Temp\Rar$EXb1288.2657\Users\nvasquez\Downloads\DriverScanner\driverscanner.exe" C:\Users\admin\AppData\Local\Temp\is-I1UNP.tmp\driverscanner.tmpdriverscanner.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-i1unp.tmp\driverscanner.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2344C:\Windows\system32\DllHost.exe /Processid:{F32D97DF-E3E5-4CB9-9E3E-0EB5B4E49801}C:\Windows\System32\dllhost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
COM Surrogate
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\dllhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2572"C:\Program Files\Uniblue\DriverScanner\driverscanner.exe"C:\Program Files\Uniblue\DriverScanner\driverscanner.exe
driverscanner.tmp
User:
admin
Company:
Uniblue Systems Ltd
Integrity Level:
HIGH
Description:
Uniblue DriverScanner
Exit code:
0
Version:
4.0.10.0
Modules
Images
c:\program files\uniblue\driverscanner\driverscanner.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
Total events
12 487
Read events
12 410
Write events
77
Delete events
0

Modification events

(PID) Process:(116) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(116) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(116) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(116) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(116) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(116) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(116) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(116) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(116) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(116) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
Executable files
62
Suspicious files
41
Text files
84
Unknown types
0

Dropped files

PID
Process
Filename
Type
116WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DIa116.2241\AVSamples.zipcompressed
MD5:B4DAC61FD95D8CF5397ED276ACB6F612
SHA256:8665BE240D20CBEE768D1914CD50139ADC7696A02E691B7A21375B073171348D
584driverscanner.exeC:\Users\admin\AppData\Local\Temp\is-UEUPG.tmp\driverscanner.tmpexecutable
MD5:C5F1D0079D95476A8D7BDAA3460607E0
SHA256:F2EE976243FB42233203A235AE1D1F7C221D363CD216485F0BC75D97B13E9051
1772driverscanner.tmpC:\Program Files\Uniblue\DriverScanner\unins000.exeexecutable
MD5:C5F1D0079D95476A8D7BDAA3460607E0
SHA256:F2EE976243FB42233203A235AE1D1F7C221D363CD216485F0BC75D97B13E9051
1772driverscanner.tmpC:\Program Files\Uniblue\DriverScanner\is-QTS54.tmpexecutable
MD5:C5F1D0079D95476A8D7BDAA3460607E0
SHA256:F2EE976243FB42233203A235AE1D1F7C221D363CD216485F0BC75D97B13E9051
1772driverscanner.tmpC:\Program Files\Uniblue\DriverScanner\is-0S27K.tmpxml
MD5:6BB5D2AAD0AE1B4A82E7DDF7CF58802A
SHA256:9E0220511D4EBDB014CC17ECB8319D57E3B0FEA09681A80D8084AA8647196582
1772driverscanner.tmpC:\Users\admin\AppData\Local\Temp\is-9O2PM.tmp\license.en.rtftext
MD5:E915A8938FFB77EE74DCCFD245138BA3
SHA256:7B782DB6342A2FEF08FA896BD823EDF765E77E2D3A511A08C86A2243874E2234
1772driverscanner.tmpC:\Program Files\Uniblue\DriverScanner\is-PDFPG.tmpexecutable
MD5:7EAB5E8118CC12F8A051181EC315A672
SHA256:4B75BA46379A38E7BB32B8932A36F21FC3742CDA24394C885FBAECD4D2E804C2
1772driverscanner.tmpC:\Program Files\Uniblue\DriverScanner\is-DNNNG.tmpexecutable
MD5:6DE5C66E434A9C1729575763D891C6C2
SHA256:4F7ED27B532888CE72B96E52952073EAB2354160D1156924489054B7FA9B0B1A
2068driverscanner.exeC:\Users\admin\AppData\Local\Temp\is-I1UNP.tmp\driverscanner.tmpexecutable
MD5:C5F1D0079D95476A8D7BDAA3460607E0
SHA256:F2EE976243FB42233203A235AE1D1F7C221D363CD216485F0BC75D97B13E9051
1772driverscanner.tmpC:\Program Files\Uniblue\DriverScanner\msvcp90.dllexecutable
MD5:6DE5C66E434A9C1729575763D891C6C2
SHA256:4F7ED27B532888CE72B96E52952073EAB2354160D1156924489054B7FA9B0B1A
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
11
DNS requests
3
Threats
4

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2572
driverscanner.exe
POST
410
3.64.163.50:80
http://ubds.uniblue.com/ubds/lookup_dst/
unknown
html
110 b
2572
driverscanner.exe
GET
404
52.217.134.153:80
http://ds.uniblue.com.s3.amazonaws.com/latest_updates/application.txt
unknown
xml
304 b
2572
driverscanner.exe
POST
410
3.64.163.50:80
http://ubdsreporthandler.uniblue.com/report/submit/
unknown
html
123 b
2572
driverscanner.exe
POST
410
3.64.163.50:80
http://ubds.uniblue.com/ubds/lookup_dst/
unknown
html
110 b
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
unknown
224.0.0.252:5355
unknown
4
System
192.168.100.255:137
unknown
1080
svchost.exe
224.0.0.252:5355
unknown
2572
driverscanner.exe
3.64.163.50:80
ubdsreporthandler.uniblue.com
AMAZON-02
DE
unknown
2572
driverscanner.exe
52.217.134.153:80
ds.uniblue.com.s3.amazonaws.com
AMAZON-02
US
unknown

DNS requests

Domain
IP
Reputation
ubdsreporthandler.uniblue.com
  • 3.64.163.50
unknown
ds.uniblue.com.s3.amazonaws.com
  • 52.217.134.153
  • 3.5.16.207
  • 16.182.65.169
  • 16.182.99.9
  • 52.217.103.108
  • 3.5.24.128
  • 52.216.37.97
  • 52.216.187.59
unknown
ubds.uniblue.com
  • 3.64.163.50
unknown

Threats

PID
Process
Class
Message
Attempted Information Leak
ET POLICY Python-urllib/ Suspicious User Agent
Attempted Information Leak
ET POLICY Python-urllib/ Suspicious User Agent
Attempted Information Leak
ET POLICY Python-urllib/ Suspicious User Agent
Attempted Information Leak
ET POLICY Python-urllib/ Suspicious User Agent
No debug info