File name:

Users_nvasquez_Downloads_DriverScanner_driverscanner.exe_.zip

Full analysis: https://app.any.run/tasks/dd2f11bb-878b-49f8-9250-c4bb9f06fb23
Verdict: Malicious activity
Analysis date: January 19, 2024, 14:28:45
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v1.0 to extract
MD5:

619E4BCB62CBC78757A91F2B0C2A2AA9

SHA1:

79A96C24FEDD42359B5119E239AD738EF4126729

SHA256:

01C57467E8E520FA1901C4A93ECF9DD85DAE53AE674C6C27AF34E581A85A6DDD

SSDEEP:

98304:aIGRgtuIxqA0HAjo8fLxFj9LCJxRIIlzKQuQ9dVHe4tK1dxDTBWa0WN8xqxNakYu:455h9m

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • driverscanner.exe (PID: 2068)
      • driverscanner.exe (PID: 584)
      • driverscanner.tmp (PID: 1772)
  • SUSPICIOUS

    • Application launched itself

      • WinRAR.exe (PID: 116)
    • Executable content was dropped or overwritten

      • driverscanner.exe (PID: 2068)
      • driverscanner.exe (PID: 584)
      • driverscanner.tmp (PID: 1772)
    • Reads the Windows owner or organization settings

      • driverscanner.tmp (PID: 1772)
    • Process drops legitimate windows executable

      • driverscanner.tmp (PID: 1772)
    • Executes as Windows Service

      • VSSVC.exe (PID: 1112)
    • Searches for installed software

      • dllhost.exe (PID: 2344)
      • driverscanner.tmp (PID: 1772)
    • The process drops C-runtime libraries

      • driverscanner.tmp (PID: 1772)
    • The process executes via Task Scheduler

      • dsmonitor.exe (PID: 1984)
    • Reads the Internet Settings

      • driverscanner.tmp (PID: 1772)
      • driverscanner.exe (PID: 2572)
    • Reads Microsoft Outlook installation path

      • driverscanner.exe (PID: 2572)
    • Reads Internet Explorer settings

      • driverscanner.exe (PID: 2572)
  • INFO

    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 1288)
    • Checks supported languages

      • driverscanner.exe (PID: 2068)
      • driverscanner.tmp (PID: 2076)
      • driverscanner.exe (PID: 584)
      • driverscanner.tmp (PID: 1772)
      • dsmonitor.exe (PID: 2692)
      • ds_move_serial.exe (PID: 2636)
      • driverscanner.exe (PID: 2572)
      • dsmonitor.exe (PID: 1984)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 1288)
    • Create files in a temporary directory

      • driverscanner.exe (PID: 2068)
      • driverscanner.exe (PID: 584)
      • driverscanner.tmp (PID: 1772)
    • Reads the computer name

      • driverscanner.tmp (PID: 2076)
      • driverscanner.tmp (PID: 1772)
      • ds_move_serial.exe (PID: 2636)
      • dsmonitor.exe (PID: 2692)
      • dsmonitor.exe (PID: 1984)
      • driverscanner.exe (PID: 2572)
    • Creates files in the program directory

      • driverscanner.tmp (PID: 1772)
      • driverscanner.exe (PID: 2572)
    • Reads the machine GUID from the registry

      • driverscanner.tmp (PID: 1772)
      • ds_move_serial.exe (PID: 2636)
      • dsmonitor.exe (PID: 2692)
      • dsmonitor.exe (PID: 1984)
      • driverscanner.exe (PID: 2572)
    • Creates files or folders in the user directory

      • driverscanner.tmp (PID: 1772)
      • dsmonitor.exe (PID: 2692)
      • driverscanner.exe (PID: 2572)
    • Reads Environment values

      • ds_move_serial.exe (PID: 2636)
      • dsmonitor.exe (PID: 2692)
      • dsmonitor.exe (PID: 1984)
      • driverscanner.exe (PID: 2572)
    • Checks proxy server information

      • driverscanner.exe (PID: 2572)
    • Reads product name

      • driverscanner.exe (PID: 2572)
    • Reads CPU info

      • driverscanner.exe (PID: 2572)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 10
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2024:01:19 09:19:26
ZipCRC: 0xf7545a08
ZipCompressedSize: 5312386
ZipUncompressedSize: 5312386
ZipFileName: AVSamples.zip
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
52
Monitored processes
12
Malicious processes
6
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe no specs winrar.exe driverscanner.exe driverscanner.tmp no specs driverscanner.exe driverscanner.tmp vssvc.exe no specs SPPSurrogate no specs ds_move_serial.exe no specs dsmonitor.exe no specs driverscanner.exe dsmonitor.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
116"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Users_nvasquez_Downloads_DriverScanner_driverscanner.exe_.zip"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
584"C:\Users\admin\AppData\Local\Temp\Rar$EXb1288.2657\Users\nvasquez\Downloads\DriverScanner\driverscanner.exe" /SPAWNWND=$30146 /NOTIFYWND=$5015C C:\Users\admin\AppData\Local\Temp\Rar$EXb1288.2657\Users\nvasquez\Downloads\DriverScanner\driverscanner.exe
driverscanner.tmp
User:
admin
Company:
Uniblue Systems Ltd
Integrity Level:
HIGH
Description:
DriverScanner Setup
Exit code:
0
Version:
4.0.10.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exb1288.2657\users\nvasquez\downloads\driverscanner\driverscanner.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1112C:\Windows\system32\vssvc.exeC:\Windows\System32\VSSVC.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Volume Shadow Copy Service
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\vssvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1288"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\Rar$DIa116.2241\AVSamples.zipC:\Program Files\WinRAR\WinRAR.exe
WinRAR.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
1772"C:\Users\admin\AppData\Local\Temp\is-UEUPG.tmp\driverscanner.tmp" /SL5="$5013A,5160607,434176,C:\Users\admin\AppData\Local\Temp\Rar$EXb1288.2657\Users\nvasquez\Downloads\DriverScanner\driverscanner.exe" /SPAWNWND=$30146 /NOTIFYWND=$5015C C:\Users\admin\AppData\Local\Temp\is-UEUPG.tmp\driverscanner.tmp
driverscanner.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-ueupg.tmp\driverscanner.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1984"C:\Program Files\Uniblue\DriverScanner\dsmonitor.exe" C:\Program Files\Uniblue\DriverScanner\dsmonitor.exetaskeng.exe
User:
admin
Company:
Uniblue Systems Ltd
Integrity Level:
HIGH
Description:
Uniblue DriverScanner Monitor
Exit code:
0
Version:
4.0.10.0
Modules
Images
c:\program files\uniblue\driverscanner\dsmonitor.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
2068"C:\Users\admin\AppData\Local\Temp\Rar$EXb1288.2657\Users\nvasquez\Downloads\DriverScanner\driverscanner.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXb1288.2657\Users\nvasquez\Downloads\DriverScanner\driverscanner.exe
WinRAR.exe
User:
admin
Company:
Uniblue Systems Ltd
Integrity Level:
MEDIUM
Description:
DriverScanner Setup
Exit code:
0
Version:
4.0.10.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exb1288.2657\users\nvasquez\downloads\driverscanner\driverscanner.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2076"C:\Users\admin\AppData\Local\Temp\is-I1UNP.tmp\driverscanner.tmp" /SL5="$5015C,5160607,434176,C:\Users\admin\AppData\Local\Temp\Rar$EXb1288.2657\Users\nvasquez\Downloads\DriverScanner\driverscanner.exe" C:\Users\admin\AppData\Local\Temp\is-I1UNP.tmp\driverscanner.tmpdriverscanner.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-i1unp.tmp\driverscanner.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2344C:\Windows\system32\DllHost.exe /Processid:{F32D97DF-E3E5-4CB9-9E3E-0EB5B4E49801}C:\Windows\System32\dllhost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
COM Surrogate
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\dllhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2572"C:\Program Files\Uniblue\DriverScanner\driverscanner.exe"C:\Program Files\Uniblue\DriverScanner\driverscanner.exe
driverscanner.tmp
User:
admin
Company:
Uniblue Systems Ltd
Integrity Level:
HIGH
Description:
Uniblue DriverScanner
Exit code:
0
Version:
4.0.10.0
Modules
Images
c:\program files\uniblue\driverscanner\driverscanner.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
Total events
12 487
Read events
12 410
Write events
77
Delete events
0

Modification events

(PID) Process:(116) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(116) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(116) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(116) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(116) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(116) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(116) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(116) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(116) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(116) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
Executable files
62
Suspicious files
41
Text files
84
Unknown types
0

Dropped files

PID
Process
Filename
Type
1772driverscanner.tmpC:\Users\admin\AppData\Local\Temp\is-9O2PM.tmp\_isetup\_shfoldr.dllexecutable
MD5:92DC6EF532FBB4A5C3201469A5B5EB63
SHA256:9884E9D1B4F8A873CCBD81F8AD0AE257776D2348D027D811A56475E028360D87
2068driverscanner.exeC:\Users\admin\AppData\Local\Temp\is-I1UNP.tmp\driverscanner.tmpexecutable
MD5:C5F1D0079D95476A8D7BDAA3460607E0
SHA256:F2EE976243FB42233203A235AE1D1F7C221D363CD216485F0BC75D97B13E9051
1288WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb1288.2657\Users\nvasquez\Downloads\DriverScanner\driverscanner.exeexecutable
MD5:133EC4F08A2B245210F297705CB96F0A
SHA256:09753916A9335189B4DBC49636FBD06A89097FD6A7520FFD6ABE504C293AE5F4
1772driverscanner.tmpC:\Users\admin\AppData\Local\Temp\is-9O2PM.tmp\certified.bmpimage
MD5:E3237084AE579244B66CE80053E90032
SHA256:1753EE1E6FC6BDFB1DDC1F8844808205E385F9E635A5F906FAB6F162BEF0730B
1772driverscanner.tmpC:\Program Files\Uniblue\DriverScanner\Microsoft.VC90.CRT.manifestxml
MD5:6BB5D2AAD0AE1B4A82E7DDF7CF58802A
SHA256:9E0220511D4EBDB014CC17ECB8319D57E3B0FEA09681A80D8084AA8647196582
1772driverscanner.tmpC:\Users\admin\AppData\Local\Temp\is-9O2PM.tmp\license.en.rtftext
MD5:E915A8938FFB77EE74DCCFD245138BA3
SHA256:7B782DB6342A2FEF08FA896BD823EDF765E77E2D3A511A08C86A2243874E2234
1772driverscanner.tmpC:\Users\admin\AppData\Local\Temp\is-9O2PM.tmp\printer.bmpimage
MD5:07605954DA75A167D8DD482995957510
SHA256:6F8EE6C1465A727E6DC64FE17983B6728B0D6E402F1C937117763A069E7B55EE
1772driverscanner.tmpC:\Program Files\Uniblue\DriverScanner\is-QTS54.tmpexecutable
MD5:C5F1D0079D95476A8D7BDAA3460607E0
SHA256:F2EE976243FB42233203A235AE1D1F7C221D363CD216485F0BC75D97B13E9051
1772driverscanner.tmpC:\Program Files\Uniblue\DriverScanner\unins000.exeexecutable
MD5:C5F1D0079D95476A8D7BDAA3460607E0
SHA256:F2EE976243FB42233203A235AE1D1F7C221D363CD216485F0BC75D97B13E9051
1772driverscanner.tmpC:\Program Files\Uniblue\DriverScanner\is-PDFPG.tmpexecutable
MD5:7EAB5E8118CC12F8A051181EC315A672
SHA256:4B75BA46379A38E7BB32B8932A36F21FC3742CDA24394C885FBAECD4D2E804C2
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
11
DNS requests
3
Threats
4

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2572
driverscanner.exe
GET
404
52.217.134.153:80
http://ds.uniblue.com.s3.amazonaws.com/latest_updates/application.txt
unknown
xml
304 b
unknown
2572
driverscanner.exe
POST
410
3.64.163.50:80
http://ubdsreporthandler.uniblue.com/report/submit/
unknown
html
123 b
unknown
2572
driverscanner.exe
POST
410
3.64.163.50:80
http://ubds.uniblue.com/ubds/lookup_dst/
unknown
html
110 b
unknown
2572
driverscanner.exe
POST
410
3.64.163.50:80
http://ubds.uniblue.com/ubds/lookup_dst/
unknown
html
110 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
224.0.0.252:5355
unknown
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
2572
driverscanner.exe
3.64.163.50:80
ubdsreporthandler.uniblue.com
AMAZON-02
DE
unknown
2572
driverscanner.exe
52.217.134.153:80
ds.uniblue.com.s3.amazonaws.com
AMAZON-02
US
shared

DNS requests

Domain
IP
Reputation
ubdsreporthandler.uniblue.com
  • 3.64.163.50
unknown
ds.uniblue.com.s3.amazonaws.com
  • 52.217.134.153
  • 3.5.16.207
  • 16.182.65.169
  • 16.182.99.9
  • 52.217.103.108
  • 3.5.24.128
  • 52.216.37.97
  • 52.216.187.59
shared
ubds.uniblue.com
  • 3.64.163.50
unknown

Threats

PID
Process
Class
Message
2572
driverscanner.exe
Attempted Information Leak
ET POLICY Python-urllib/ Suspicious User Agent
2572
driverscanner.exe
Attempted Information Leak
ET POLICY Python-urllib/ Suspicious User Agent
2572
driverscanner.exe
Attempted Information Leak
ET POLICY Python-urllib/ Suspicious User Agent
2572
driverscanner.exe
Attempted Information Leak
ET POLICY Python-urllib/ Suspicious User Agent
No debug info