File name:

CDM212364_Setup.zip

Full analysis: https://app.any.run/tasks/b577b587-4ade-4932-b5b5-8d92b0d49c21
Verdict: Malicious activity
Analysis date: March 19, 2024, 11:25:37
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=deflate
MD5:

09B8D1E4F64828A2012AE54A7746D6D5

SHA1:

1B1FA041EFF7B6FAB10E9FE73D3149C4DB750886

SHA256:

10C399AC784D2B68B1BB2BA598BAB7FE00CFDFD267B4CC14A3E3240FE9499FB1

SSDEEP:

49152:8GehdaQ/cr5lWZGiPsM3eg2FF56gtGRzDHaNTC4jt92Wh:padfioGiUMH2bLt6LaNTCGt92Wh

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 3992)
      • CDM212364_Setup.exe (PID: 2672)
      • dpinst-x86.exe (PID: 2792)
      • drvinst.exe (PID: 1976)
      • drvinst.exe (PID: 2440)
    • Creates a writable file in the system directory

      • drvinst.exe (PID: 2440)
      • drvinst.exe (PID: 1976)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • WinRAR.exe (PID: 3992)
    • Executable content was dropped or overwritten

      • CDM212364_Setup.exe (PID: 2672)
      • dpinst-x86.exe (PID: 2792)
      • drvinst.exe (PID: 2440)
      • drvinst.exe (PID: 1976)
    • Drops a system driver (possible attempt to evade defenses)

      • CDM212364_Setup.exe (PID: 2672)
      • dpinst-x86.exe (PID: 2792)
      • drvinst.exe (PID: 2440)
      • drvinst.exe (PID: 1976)
    • Process drops legitimate windows executable

      • CDM212364_Setup.exe (PID: 2672)
    • Starts a Microsoft application from unusual location

      • dpinst-x86.exe (PID: 2792)
    • Creates files in the driver directory

      • drvinst.exe (PID: 2440)
      • drvinst.exe (PID: 1976)
    • Checks Windows Trust Settings

      • drvinst.exe (PID: 2440)
      • drvinst.exe (PID: 1976)
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3992)
    • Checks supported languages

      • CDM212364_Setup.exe (PID: 2672)
      • dp-chooser.exe (PID: 3180)
      • dpinst-x86.exe (PID: 2792)
      • drvinst.exe (PID: 2440)
      • drvinst.exe (PID: 1976)
      • CDM212364_Setup.exe (PID: 2488)
    • Create files in a temporary directory

      • CDM212364_Setup.exe (PID: 2672)
      • dpinst-x86.exe (PID: 2792)
      • CDM212364_Setup.exe (PID: 2488)
    • Reads the machine GUID from the registry

      • dpinst-x86.exe (PID: 2792)
      • drvinst.exe (PID: 1976)
      • drvinst.exe (PID: 2440)
    • Reads the computer name

      • dpinst-x86.exe (PID: 2792)
      • drvinst.exe (PID: 2440)
      • drvinst.exe (PID: 1976)
    • Reads the software policy settings

      • drvinst.exe (PID: 2440)
      • drvinst.exe (PID: 1976)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2021:07:12 13:11:30
ZipCRC: 0x1986ce3c
ZipCompressedSize: 2209307
ZipUncompressedSize: 2264632
ZipFileName: CDM212364_Setup.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
50
Monitored processes
9
Malicious processes
6
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe cdm212364_setup.exe no specs cdm212364_setup.exe dp-chooser.exe no specs dpinst-x86.exe drvinst.exe drvinst.exe cdm212364_setup.exe no specs cdm212364_setup.exe

Process information

PID
CMD
Path
Indicators
Parent process
240"C:\Users\admin\AppData\Local\Temp\Rar$EXa3992.4664\CDM212364_Setup.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3992.4664\CDM212364_Setup.exeWinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3992.4664\cdm212364_setup.exe
c:\windows\system32\ntdll.dll
1696"C:\Users\admin\AppData\Local\Temp\Rar$EXa3992.3393\CDM212364_Setup.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3992.3393\CDM212364_Setup.exeWinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3992.3393\cdm212364_setup.exe
c:\windows\system32\ntdll.dll
1976DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{3a17e0e5-1a11-1902-8066-4b55b7d10d56}\ftdiport.inf" "0" "6960183e3" "000003DC" "WinSta0\Default" "00000338" "208" "c:\users\admin\appdata\local\temp\ftdi-driver"C:\Windows\System32\drvinst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
2440DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{45eeb962-38cf-7bb2-d66a-8f706e67b057}\ftdibus.inf" "0" "657f6b0d3" "000005C0" "WinSta0\Default" "000003DC" "208" "c:\users\admin\appdata\local\temp\ftdi-driver"C:\Windows\System32\drvinst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
2488"C:\Users\admin\AppData\Local\Temp\Rar$EXa3992.4664\CDM212364_Setup.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3992.4664\CDM212364_Setup.exe
WinRAR.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3992.4664\cdm212364_setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
2672"C:\Users\admin\AppData\Local\Temp\Rar$EXa3992.3393\CDM212364_Setup.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3992.3393\CDM212364_Setup.exe
WinRAR.exe
User:
admin
Integrity Level:
HIGH
Exit code:
1
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3992.3393\cdm212364_setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
2792C:\Users\admin\AppData\Local\Temp\FTDI-Driver\dpinst-x86.exe /saC:\Users\admin\AppData\Local\Temp\FTDI-Driver\dpinst-x86.exe
dp-chooser.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Driver Package Installer
Exit code:
512
Version:
2.1
Modules
Images
c:\users\admin\appdata\local\temp\ftdi-driver\dpinst-x86.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3180C:\Users\admin\AppData\Local\Temp\FTDI-Driver\dp-chooser.exeC:\Users\admin\AppData\Local\Temp\FTDI-Driver\dp-chooser.exeCDM212364_Setup.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\ftdi-driver\dp-chooser.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
3992"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\CDM212364_Setup.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
Total events
10 094
Read events
10 026
Write events
65
Delete events
3

Modification events

(PID) Process:(3992) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3992) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3992) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3992) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(3992) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(3992) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(3992) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\CDM212364_Setup.zip
(PID) Process:(3992) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3992) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3992) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
Executable files
48
Suspicious files
10
Text files
19
Unknown types
17

Dropped files

PID
Process
Filename
Type
2672CDM212364_Setup.exeC:\Users\admin\AppData\Local\Temp\FTDI-Driver\amd64\ftdibus.sysexecutable
MD5:AB7418C8DFBBB97BEFB4F0ADED3D4663
SHA256:3BD5BB7E646E67469EC25A37CAA5131CF992759703B0FC170DF7AF265B9F8E74
3992WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3992.3393\CDM212364_Setup.exeexecutable
MD5:0C97E7B5DE1B46FB723BED38F0DE28A2
SHA256:835DD64B199190D20DC37C0CADEB064B7EAAAEF271703781B2B259B7085437A4
2672CDM212364_Setup.exeC:\Users\admin\AppData\Local\Temp\FTDI-Driver\amd64\ftd2xx.libbinary
MD5:2C6C133941002E602D1AC6831CBB7368
SHA256:7C3A73D3A2441B460F03358BC8CC81E5F3FB43523BFA35E4EEF3BBE8BAD5788D
2672CDM212364_Setup.exeC:\Users\admin\AppData\Local\Temp\FTDI-Driver\amd64\ftcserco.dllexecutable
MD5:AA69BF96E10F463082A0664B7A2E9FAE
SHA256:C0224B9EF14365F6DDA96134CC77D978E69FBD61EFDADE6FD1EB676418C41023
2672CDM212364_Setup.exeC:\Users\admin\AppData\Local\Temp\FTDI-Driver\amd64\ftd2xx64.dllexecutable
MD5:BEFBC1A8F6C2B8E143DDD97CCB6561B5
SHA256:774AF8B12C85D03562742ACDF222AF5E0432167BF107BA4B260757E4A5E36866
2672CDM212364_Setup.exeC:\Users\admin\AppData\Local\Temp\FTDI-Driver\amd64\ftbusui.dllexecutable
MD5:D79A5E34F684B547FA2F963DFCC15A21
SHA256:4BBC0B301A7C5A6B1B73878CE3AEEB191F5FCEAC05835372142206D79AC81559
2672CDM212364_Setup.exeC:\Users\admin\AppData\Local\Temp\FTDI-Driver\amd64\ftlang.dllexecutable
MD5:662679682F491FBAF3D15953D13EC72E
SHA256:C2729911C4B82D8F9E22E057A1570D0265D7A9ECA44D6FE8DC0658F47263CE12
2672CDM212364_Setup.exeC:\Users\admin\AppData\Local\Temp\FTDI-Driver\amd64\ftser2k.sysexecutable
MD5:B66678FF4E347E22146609B3D5B7B2C4
SHA256:7A303AA880CC746D13F71E565874FB7C174747372CCF358B928A72219D2A50DD
2672CDM212364_Setup.exeC:\Users\admin\AppData\Local\Temp\FTDI-Driver\amd64\ftserui2.dllexecutable
MD5:3E5BCD980AF8B20313005D9A492CEC8A
SHA256:55A23A2AC263E10B77D7E95601439F771062F2C248A8D93039A968D66100C39C
2672CDM212364_Setup.exeC:\Users\admin\AppData\Local\Temp\FTDI-Driver\dp-chooser.exeexecutable
MD5:461A3CE2E77143EC0E0015D80675911B
SHA256:003310B93A1A237FB022C7D7F40515DAF25FA1B91690965D3B98C1829A92ED37
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
unknown
4
System
192.168.100.255:138
unknown
224.0.0.252:5355
unknown
1080
svchost.exe
224.0.0.252:5355
unknown

DNS requests

No data

Threats

No threats detected
No debug info