File name:

zebra-gx430t-zpl-1244889.zip

Full analysis: https://app.any.run/tasks/750efcb7-6dc7-4ff3-b7ce-684f7cde9e4a
Verdict: Malicious activity
Analysis date: March 12, 2024, 16:16:59
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=deflate
MD5:

48036532B03D1D35717021E1D79B6B7F

SHA1:

BC0552B18C2C3BFCA334314AE0226D71918BD0B1

SHA256:

0F7382E9A6DE0C4DBFF539209505260AA6CDFA6A8739C0705301C761C95B76D8

SSDEEP:

98304:n/4JYJrD+83nOL2fgVvW1yNZStvM7szw7Mp/6onufcVPtPaf516kD12j0MAI2GVZ:CQg/eCCxw9K+cyK

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 1432)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • WinRAR.exe (PID: 1432)
      • driver-hub-install__28.exe (PID: 3228)
      • driver-hub-install__28.exe (PID: 2892)
      • driver-hub-install__28.exe (PID: 2384)
      • driver-hub-install__28.exe (PID: 2376)
    • Application launched itself

      • WinRAR.exe (PID: 1432)
      • driver-hub-install__28.exe (PID: 3228)
      • driver-hub-install__28.exe (PID: 2384)
    • Reads the Internet Settings

      • driver-hub-install__28.exe (PID: 3228)
      • driver-hub-install__28.exe (PID: 2892)
      • driver-hub-install__28.exe (PID: 2384)
      • driver-hub-install__28.exe (PID: 2376)
    • Reads Microsoft Outlook installation path

      • driver-hub-install__28.exe (PID: 3228)
      • driver-hub-install__28.exe (PID: 2892)
      • driver-hub-install__28.exe (PID: 2384)
      • driver-hub-install__28.exe (PID: 2376)
    • Reads Internet Explorer settings

      • driver-hub-install__28.exe (PID: 3228)
      • driver-hub-install__28.exe (PID: 2892)
      • driver-hub-install__28.exe (PID: 2384)
      • driver-hub-install__28.exe (PID: 2376)
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 1432)
      • WinRAR.exe (PID: 2888)
    • Checks supported languages

      • driver-hub-install__28.exe (PID: 3228)
      • driver-hub-install__28.exe (PID: 2892)
      • driver-hub-install__28.exe (PID: 2384)
      • driver-hub-install__28.exe (PID: 2376)
    • Reads the computer name

      • driver-hub-install__28.exe (PID: 3228)
      • driver-hub-install__28.exe (PID: 2892)
      • driver-hub-install__28.exe (PID: 2384)
      • driver-hub-install__28.exe (PID: 2376)
    • Reads the machine GUID from the registry

      • driver-hub-install__28.exe (PID: 3228)
      • driver-hub-install__28.exe (PID: 2892)
      • driver-hub-install__28.exe (PID: 2376)
      • driver-hub-install__28.exe (PID: 2384)
    • Manual execution by a user

      • driver-hub-install__28.exe (PID: 3228)
      • WinRAR.exe (PID: 2888)
    • Checks proxy server information

      • driver-hub-install__28.exe (PID: 3228)
      • driver-hub-install__28.exe (PID: 2892)
      • driver-hub-install__28.exe (PID: 2384)
      • driver-hub-install__28.exe (PID: 2376)
    • Process checks whether UAC notifications are on

      • driver-hub-install__28.exe (PID: 2892)
      • driver-hub-install__28.exe (PID: 2376)
    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 2888)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2023:09:19 17:11:34
ZipCRC: 0xbaa2e993
ZipCompressedSize: 3228659
ZipUncompressedSize: 3343312
ZipFileName: driver-hub-install__28.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
51
Monitored processes
7
Malicious processes
4
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe winrar.exe no specs driver-hub-install__28.exe driver-hub-install__28.exe winrar.exe driver-hub-install__28.exe driver-hub-install__28.exe

Process information

PID
CMD
Path
Indicators
Parent process
1432"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\zebra-gx430t-zpl-1244889.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2376"C:\Users\admin\AppData\Local\Temp\Rar$EXa1432.39568\driver-hub-install__28.exe" /screen=proc /pos=240,46 /lang=enC:\Users\admin\AppData\Local\Temp\Rar$EXa1432.39568\driver-hub-install__28.exe
driver-hub-install__28.exe
User:
admin
Company:
ROSTPAY LTD.
Integrity Level:
HIGH
Description:
Install DriverHub
Exit code:
0
Version:
3.2.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa1432.39568\driver-hub-install__28.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
2384"C:\Users\admin\AppData\Local\Temp\Rar$EXa1432.39568\driver-hub-install__28.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa1432.39568\driver-hub-install__28.exe
WinRAR.exe
User:
admin
Company:
ROSTPAY LTD.
Integrity Level:
MEDIUM
Description:
Install DriverHub
Exit code:
0
Version:
3.2.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa1432.39568\driver-hub-install__28.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
2888"C:\Program Files\WinRAR\WinRAR.exe" x -iext -ow -ver -- "C:\Users\admin\Desktop\zebra-gx430t-zpl-1244889.zip" C:\Users\admin\Desktop\C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2892"C:\Users\admin\Desktop\driver-hub-install__28.exe" /screen=proc /pos=240,46 /lang=enC:\Users\admin\Desktop\driver-hub-install__28.exe
driver-hub-install__28.exe
User:
admin
Company:
ROSTPAY LTD.
Integrity Level:
HIGH
Description:
Install DriverHub
Exit code:
0
Version:
3.2.0
Modules
Images
c:\users\admin\desktop\driver-hub-install__28.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
2920"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\Rar$DIa1432.23462\zebra-gx430t-zpl-1244889.zipC:\Program Files\WinRAR\WinRAR.exeWinRAR.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3228"C:\Users\admin\Desktop\driver-hub-install__28.exe" C:\Users\admin\Desktop\driver-hub-install__28.exe
explorer.exe
User:
admin
Company:
ROSTPAY LTD.
Integrity Level:
MEDIUM
Description:
Install DriverHub
Exit code:
0
Version:
3.2.0
Modules
Images
c:\users\admin\desktop\driver-hub-install__28.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
Total events
15 821
Read events
15 720
Write events
101
Delete events
0

Modification events

(PID) Process:(1432) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(1432) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(1432) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1432) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(1432) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(1432) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(1432) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\zebra-gx430t-zpl-1244889.zip
(PID) Process:(1432) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(1432) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(1432) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
Executable files
56
Suspicious files
5
Text files
574
Unknown types
2

Dropped files

PID
Process
Filename
Type
2888WinRAR.exeC:\Users\admin\Desktop\Common\AndaleS.MMFini
MD5:D10ADAEE855C107A8F81B59030B4970C
SHA256:8FF2342F4008CB40D1B69BC5367232F8D581497277DC55831C855E0DAF48B7CB
1432WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DIa1432.23462\zebra-gx430t-zpl-1244889.zipcompressed
MD5:1B27A2C5E270F69758E76A5490AA4FF6
SHA256:F98CAB37E83A52C43190BC37F44A73F1D611C75CC215AA68193A86E4E365D17C
2888WinRAR.exeC:\Users\admin\Desktop\Common\AndaleK.MMFini
MD5:28FA70B15F3A073FC2F2D2DA5AC57768
SHA256:0844C5416FB2D3C88E96A37A7A3B7990D23D7D288879ED6DB9428CDCAF788FD1
2888WinRAR.exeC:\Users\admin\Desktop\Common\AndaleJ.MMFini
MD5:21C405A9A3F49F691168A942EF4C8CA0
SHA256:264259B5D1538B085AD8012DF47EF5C091FCF68E49BB2C344D8CD72EE6D3DA1E
2888WinRAR.exeC:\Users\admin\Desktop\Common\B17XI3P2.BA0ini
MD5:65636D2CD3BA0EE7D6A7EB7116A451F9
SHA256:F13F624E4440DF9BC1BADEFD04FD37D5068F734EF6FA288BD717C1CB17D7D25D
2888WinRAR.exeC:\Users\admin\Desktop\Common\Angsana.MMFini
MD5:A76D521AF9D4EAEA89B67C1EBA0F9E63
SHA256:C440A4E50DB54B6418E85D9D0A5F34A8C6257AEF83A45AB67896AF5A69C60368
1432WinRAR.exeC:\Users\admin\Desktop\driver-hub-install__28.exeexecutable
MD5:C6C6FD0A80B977EE666A6BD1ED1D9FC3
SHA256:B877CF61BF6022AA3ADDE6A521A7D2D356AC07FC1A0F9967977B5037532E3354
1432WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1432.36379\zebra-gx430t-zpl-1244889.zipcompressed
MD5:1B27A2C5E270F69758E76A5490AA4FF6
SHA256:F98CAB37E83A52C43190BC37F44A73F1D611C75CC215AA68193A86E4E365D17C
2888WinRAR.exeC:\Users\admin\Desktop\Common\About.bmpimage
MD5:79E9D314BB3F1040E042F814603EBA55
SHA256:C4D975F8A2A6B50AB5BF34D4A018270F54323C135FFE421BC712F2A1194D40DA
2888WinRAR.exeC:\Users\admin\Desktop\Common\BA105SL2.BA0ini
MD5:65636D2CD3BA0EE7D6A7EB7116A451F9
SHA256:F13F624E4440DF9BC1BADEFD04FD37D5068F734EF6FA288BD717C1CB17D7D25D
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
33
DNS requests
3
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
unknown
224.0.0.252:5355
unknown
3228
driver-hub-install__28.exe
188.130.153.32:443
api.az-partners.net
Rostpay Ltd
RU
unknown
2892
driver-hub-install__28.exe
188.130.153.32:443
api.az-partners.net
Rostpay Ltd
RU
unknown
2384
driver-hub-install__28.exe
188.130.153.32:443
api.az-partners.net
Rostpay Ltd
RU
unknown
2376
driver-hub-install__28.exe
188.130.153.32:443
api.az-partners.net
Rostpay Ltd
RU
unknown

DNS requests

Domain
IP
Reputation
api.az-partners.net
  • 188.130.153.32
  • 188.130.153.33
unknown
dns.msftncsi.com
  • 131.107.255.255
shared
www.drvhub.net
  • 188.130.153.33
  • 188.130.153.32
unknown

Threats

No threats detected
No debug info