URL:

https://sourceforge.net/projects/libusb-win32/

Full analysis: https://app.any.run/tasks/cd3edea4-5661-4206-93cd-c87727a1c105
Verdict: Malicious activity
Analysis date: January 29, 2024, 23:26:35
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

9B8A2842ED5C8E674816DD0E14D145FC

SHA1:

2B19254EEC30351F91EB430EF17C3F36ACA99A48

SHA256:

048C4FE74E787A91294CB8DF8FF425F4B78A6CD41191155E9AF2DAAB1567CD46

SSDEEP:

3:N8HCGSuLAuUtaQtDf:2iGnCtRDf

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • libusb-win32-devel-filter-1.2.7.3.exe (PID: 3704)
      • libusb-win32-devel-filter-1.2.7.3.exe (PID: 2536)
      • libusb-win32-devel-filter-1.2.7.3.tmp (PID: 1192)
    • Creates a writable file in the system directory

      • libusb-win32-devel-filter-1.2.7.3.tmp (PID: 1192)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • libusb-win32-devel-filter-1.2.7.3.exe (PID: 3704)
      • libusb-win32-devel-filter-1.2.7.3.exe (PID: 2536)
      • libusb-win32-devel-filter-1.2.7.3.tmp (PID: 1192)
    • Reads the Windows owner or organization settings

      • libusb-win32-devel-filter-1.2.7.3.tmp (PID: 1192)
    • Creates files in the driver directory

      • libusb-win32-devel-filter-1.2.7.3.tmp (PID: 1192)
    • Drops a system driver (possible attempt to evade defenses)

      • libusb-win32-devel-filter-1.2.7.3.tmp (PID: 1192)
  • INFO

    • Executable content was dropped or overwritten

      • iexplore.exe (PID: 3484)
      • iexplore.exe (PID: 1652)
    • Application launched itself

      • iexplore.exe (PID: 1652)
    • The process uses the downloaded file

      • iexplore.exe (PID: 1652)
    • Drops the executable file immediately after the start

      • iexplore.exe (PID: 3484)
      • iexplore.exe (PID: 1652)
    • Checks supported languages

      • libusb-win32-devel-filter-1.2.7.3.exe (PID: 3704)
      • libusb-win32-devel-filter-1.2.7.3.tmp (PID: 3816)
      • libusb-win32-devel-filter-1.2.7.3.exe (PID: 2536)
      • libusb-win32-devel-filter-1.2.7.3.tmp (PID: 1192)
      • install-filter-win.exe (PID: 3740)
    • Create files in a temporary directory

      • libusb-win32-devel-filter-1.2.7.3.exe (PID: 3704)
      • libusb-win32-devel-filter-1.2.7.3.exe (PID: 2536)
    • Reads the computer name

      • libusb-win32-devel-filter-1.2.7.3.tmp (PID: 3816)
      • libusb-win32-devel-filter-1.2.7.3.tmp (PID: 1192)
      • install-filter-win.exe (PID: 3740)
    • Creates files in the program directory

      • libusb-win32-devel-filter-1.2.7.3.tmp (PID: 1192)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
48
Monitored processes
8
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe libusb-win32-devel-filter-1.2.7.3.exe libusb-win32-devel-filter-1.2.7.3.tmp no specs libusb-win32-devel-filter-1.2.7.3.exe libusb-win32-devel-filter-1.2.7.3.tmp install-filter-win.exe no specs rundll32.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1192"C:\Users\admin\AppData\Local\Temp\is-26R1V.tmp\libusb-win32-devel-filter-1.2.7.3.tmp" /SL5="$50204,274884,121344,C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\libusb-win32-devel-filter-1.2.7.3.exe" /SPAWNWND=$5021A /NOTIFYWND=$80244 C:\Users\admin\AppData\Local\Temp\is-26R1V.tmp\libusb-win32-devel-filter-1.2.7.3.tmp
libusb-win32-devel-filter-1.2.7.3.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-26r1v.tmp\libusb-win32-devel-filter-1.2.7.3.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1652"C:\Program Files\Internet Explorer\iexplore.exe" "https://sourceforge.net/projects/libusb-win32/"C:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
2536"C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\libusb-win32-devel-filter-1.2.7.3.exe" /SPAWNWND=$5021A /NOTIFYWND=$80244 C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\libusb-win32-devel-filter-1.2.7.3.exe
libusb-win32-devel-filter-1.2.7.3.tmp
User:
admin
Company:
LibUSB-Win32
Integrity Level:
HIGH
Description:
LibUSB-Win32 Setup
Exit code:
0
Version:
1.2.7.3
Modules
Images
c:\users\admin\appdata\local\microsoft\windows\temporary internet files\content.ie5\po2hn1x2\libusb-win32-devel-filter-1.2.7.3.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
3008C:\Windows\System32\rundll32.exe shell32.dll,SHCreateLocalServerRunDll {995C996E-D918-4a8c-A302-45719A6F4EA7} -EmbeddingC:\Windows\System32\rundll32.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
3484"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:1652 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
3704"C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\libusb-win32-devel-filter-1.2.7.3.exe" C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\libusb-win32-devel-filter-1.2.7.3.exe
iexplore.exe
User:
admin
Company:
LibUSB-Win32
Integrity Level:
MEDIUM
Description:
LibUSB-Win32 Setup
Exit code:
0
Version:
1.2.7.3
Modules
Images
c:\users\admin\appdata\local\microsoft\windows\temporary internet files\content.ie5\po2hn1x2\libusb-win32-devel-filter-1.2.7.3.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
3740"C:\Program Files\LibUSB-Win32\bin\install-filter-win.exe"C:\Program Files\LibUSB-Win32\bin\install-filter-win.exelibusb-win32-devel-filter-1.2.7.3.tmp
User:
admin
Company:
http://libusb-win32.sourceforge.net
Integrity Level:
HIGH
Description:
libusb-win32 filter installer
Exit code:
0
Version:
1.2.7.3
Modules
Images
c:\program files\libusb-win32\bin\install-filter-win.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3816"C:\Users\admin\AppData\Local\Temp\is-MVG1E.tmp\libusb-win32-devel-filter-1.2.7.3.tmp" /SL5="$80244,274884,121344,C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\libusb-win32-devel-filter-1.2.7.3.exe" C:\Users\admin\AppData\Local\Temp\is-MVG1E.tmp\libusb-win32-devel-filter-1.2.7.3.tmplibusb-win32-devel-filter-1.2.7.3.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-mvg1e.tmp\libusb-win32-devel-filter-1.2.7.3.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
Total events
23 272
Read events
23 149
Write events
111
Delete events
12

Modification events

(PID) Process:(1652) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPDaysSinceLastAutoMigration
Value:
0
(PID) Process:(1652) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchHighDateTime
Value:
30847387
(PID) Process:(1652) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
30847437
(PID) Process:(1652) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(1652) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(1652) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(1652) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(1652) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(1652) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(1652) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
Executable files
20
Suspicious files
56
Text files
169
Unknown types
0

Dropped files

PID
Process
Filename
Type
3484iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:5B1FB8ED1525EFDC06E01E17C44D0020
SHA256:CD2A5FE7A3DB8776E3E8C96CF351BAAB67290D2FD69F9B33B7FF16EC7D61D0A0
3484iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\6BADA8974A10C4BD62CC921D13E43B18_28DEA62A0AE77228DD387E155AD0BA27binary
MD5:44AB0E35CFC61850E647850308EA9554
SHA256:94B52F83D05EFC20DEEDF98991C1554F4FF22421EC0B9C0921DBC0B23C331FD2
3484iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\libusb-win32[1].htmhtml
MD5:7F2A0FE1E2AD1128E989449405653978
SHA256:92113DF265FC5AD9DDD94376E8CCEDE995DD7664EDB7A3D33828A271A405EFA1
3484iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\v84a3a4012de94ce1a686ba8c167c359c1696973893317[1].jstext
MD5:DD1D068FDB5FE90B6C05A5B3940E088C
SHA256:6153D13804862B0FC1C016CF1129F34CB7C6185F2CF4BF1A3A862EECDAB50101
3484iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YTOWV792\sf.sandiego-foundation-base[1].jstext
MD5:F23FBD469BB0D9569486B62E2C50D996
SHA256:D30C030593AEE31E4BDD1A458E6739DF804F6D50012D2E3141D585B4ACF91A08
3484iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\sf.sandiego-foundation-tooltip[1].jstext
MD5:4A124B39D226B45BD81EBE53D6F2E404
SHA256:E71F9ED65E086AB36B4243D164B94D967AF8C2D646D8D892BF6AE91CF5DDF28B
3484iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\sf.sandiego-base[1].jstext
MD5:80F2419F055A74A6B18626ACA93E971F
SHA256:B7547012DE798D3F335199320469E3D42C57BA965D790E62BBC6FA223230DD0F
3484iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YTOWV792\sandiego[1].csstext
MD5:A6DFAC963C9CB5C78419368BB2F01181
SHA256:449B4F2CD3FA9B86687F33289C625A0BB112E22B25ACB936406838F75B822E6A
3484iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5IWPIAR9\github-sync[1].pngimage
MD5:4A6DCE1E1233DA9CE4605000A63B81DC
SHA256:DA0649DC53EAE2E0F5982186C3D53DFBF9D11BE57B69127C6BB2DC18D11BF309
3484iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\cmp[1].csstext
MD5:38C8ACF2B4EF7DEF65BACFB6E9A26E8E
SHA256:4BAAE150A27BC5716BA8F5160FBD2414F5B731C470D8EE0956612DAFA106E950
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
26
TCP/UDP connections
88
DNS requests
35
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3484
iexplore.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEAo3h2ReX7SMIk79G%2B0UDDw%3D
unknown
binary
1.47 Kb
unknown
3484
iexplore.exe
GET
304
184.24.77.202:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?245ab6ffaf4de696
unknown
unknown
3484
iexplore.exe
GET
304
184.24.77.202:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?94efb324901b4675
unknown
unknown
3484
iexplore.exe
GET
200
184.24.77.202:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?60489f733d028aa3
unknown
compressed
65.2 Kb
unknown
3484
iexplore.exe
GET
200
184.24.77.202:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?230fc945f26544e8
unknown
compressed
65.2 Kb
unknown
3484
iexplore.exe
GET
200
184.24.77.202:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?18897510c51d3684
unknown
compressed
65.2 Kb
unknown
3484
iexplore.exe
GET
200
184.24.77.202:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?9dfe4a8c1d9b0985
unknown
compressed
65.2 Kb
unknown
3484
iexplore.exe
GET
200
69.192.161.44:80
http://x1.c.lencr.org/
unknown
binary
717 b
unknown
3484
iexplore.exe
GET
200
184.24.77.83:80
http://r3.o.lencr.org/MFMwUTBPME0wSzAJBgUrDgMCGgUABBRI2smg%2ByvTLU%2Fw3mjS9We3NfmzxAQUFC6zF7dYVsuuUAlA5h%2BvnYsUwsYCEgR%2B5rJNDRLPmf6wKNriwkmuQQ%3D%3D
unknown
binary
503 b
unknown
3484
iexplore.exe
GET
200
142.250.185.67:80
http://ocsp.pki.goog/gsr1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCEHe9DWzbNvka6iEPxPBY0w0%3D
unknown
binary
1.41 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
224.0.0.252:5355
unknown
3484
iexplore.exe
104.18.37.111:443
sourceforge.net
CLOUDFLARENET
unknown
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
3484
iexplore.exe
184.24.77.202:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown
3484
iexplore.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
3484
iexplore.exe
172.64.147.47:443
a.fsdn.com
CLOUDFLARENET
US
unknown
3484
iexplore.exe
104.16.57.101:443
static.cloudflareinsights.com
CLOUDFLARENET
unknown
3484
iexplore.exe
87.230.98.76:443
d.delivery.consentmanager.net
PlusServer GmbH
DE
unknown
3484
iexplore.exe
195.181.175.40:443
cdn.consentmanager.net
Datacamp Limited
DE
unknown

DNS requests

Domain
IP
Reputation
sourceforge.net
  • 104.18.37.111
  • 172.64.150.145
whitelisted
ctldl.windowsupdate.com
  • 184.24.77.202
  • 184.24.77.194
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
a.fsdn.com
  • 172.64.147.47
  • 104.18.40.209
whitelisted
static.cloudflareinsights.com
  • 104.16.57.101
  • 104.16.56.101
whitelisted
d.delivery.consentmanager.net
  • 87.230.98.76
unknown
cdn.consentmanager.net
  • 195.181.175.40
  • 212.102.56.179
  • 195.181.170.19
  • 156.146.33.138
  • 195.181.175.16
  • 212.102.56.182
  • 156.146.33.140
malicious
c.sf-syn.com
  • 104.18.33.97
  • 172.64.154.159
whitelisted
x1.c.lencr.org
  • 69.192.161.44
whitelisted
r3.o.lencr.org
  • 184.24.77.83
  • 184.24.77.46
  • 184.24.77.53
  • 184.24.77.56
  • 184.24.77.65
  • 184.24.77.45
shared

Threats

No threats detected
No debug info