| File name: | CDM212364_Setup.zip |
| Full analysis: | https://app.any.run/tasks/b577b587-4ade-4932-b5b5-8d92b0d49c21 |
| Verdict: | Malicious activity |
| Analysis date: | March 19, 2024, 11:25:37 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract, compression method=deflate |
| MD5: | 09B8D1E4F64828A2012AE54A7746D6D5 |
| SHA1: | 1B1FA041EFF7B6FAB10E9FE73D3149C4DB750886 |
| SHA256: | 10C399AC784D2B68B1BB2BA598BAB7FE00CFDFD267B4CC14A3E3240FE9499FB1 |
| SSDEEP: | 49152:8GehdaQ/cr5lWZGiPsM3eg2FF56gtGRzDHaNTC4jt92Wh:padfioGiUMH2bLt6LaNTCGt92Wh |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 20 |
|---|---|
| ZipBitFlag: | - |
| ZipCompression: | Deflated |
| ZipModifyDate: | 2021:07:12 13:11:30 |
| ZipCRC: | 0x1986ce3c |
| ZipCompressedSize: | 2209307 |
| ZipUncompressedSize: | 2264632 |
| ZipFileName: | CDM212364_Setup.exe |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 240 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa3992.4664\CDM212364_Setup.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa3992.4664\CDM212364_Setup.exe | — | WinRAR.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 3221226540 Modules
| |||||||||||||||
| 1696 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa3992.3393\CDM212364_Setup.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa3992.3393\CDM212364_Setup.exe | — | WinRAR.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 3221226540 Modules
| |||||||||||||||
| 1976 | DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{3a17e0e5-1a11-1902-8066-4b55b7d10d56}\ftdiport.inf" "0" "6960183e3" "000003DC" "WinSta0\Default" "00000338" "208" "c:\users\admin\appdata\local\temp\ftdi-driver" | C:\Windows\System32\drvinst.exe | svchost.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Driver Installation Module Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2440 | DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{45eeb962-38cf-7bb2-d66a-8f706e67b057}\ftdibus.inf" "0" "657f6b0d3" "000005C0" "WinSta0\Default" "000003DC" "208" "c:\users\admin\appdata\local\temp\ftdi-driver" | C:\Windows\System32\drvinst.exe | svchost.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Driver Installation Module Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2488 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa3992.4664\CDM212364_Setup.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa3992.4664\CDM212364_Setup.exe | WinRAR.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 2672 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa3992.3393\CDM212364_Setup.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa3992.3393\CDM212364_Setup.exe | WinRAR.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 1 Modules
| |||||||||||||||
| 2792 | C:\Users\admin\AppData\Local\Temp\FTDI-Driver\dpinst-x86.exe /sa | C:\Users\admin\AppData\Local\Temp\FTDI-Driver\dpinst-x86.exe | dp-chooser.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Driver Package Installer Exit code: 512 Version: 2.1 Modules
| |||||||||||||||
| 3180 | C:\Users\admin\AppData\Local\Temp\FTDI-Driver\dp-chooser.exe | C:\Users\admin\AppData\Local\Temp\FTDI-Driver\dp-chooser.exe | — | CDM212364_Setup.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 3992 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\CDM212364_Setup.zip" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| (PID) Process: | (3992) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (3992) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (3992) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3992) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\phacker.zip | |||
| (PID) Process: | (3992) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (3992) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip | |||
| (PID) Process: | (3992) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\CDM212364_Setup.zip | |||
| (PID) Process: | (3992) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (3992) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (3992) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2672 | CDM212364_Setup.exe | C:\Users\admin\AppData\Local\Temp\FTDI-Driver\amd64\ftserui2.dll | executable | |
MD5:3E5BCD980AF8B20313005D9A492CEC8A | SHA256:55A23A2AC263E10B77D7E95601439F771062F2C248A8D93039A968D66100C39C | |||
| 2672 | CDM212364_Setup.exe | C:\Users\admin\AppData\Local\Temp\FTDI-Driver\amd64\ftbusui.dll | executable | |
MD5:D79A5E34F684B547FA2F963DFCC15A21 | SHA256:4BBC0B301A7C5A6B1B73878CE3AEEB191F5FCEAC05835372142206D79AC81559 | |||
| 2672 | CDM212364_Setup.exe | C:\Users\admin\AppData\Local\Temp\FTDI-Driver\amd64\ftd2xx.lib | binary | |
MD5:2C6C133941002E602D1AC6831CBB7368 | SHA256:7C3A73D3A2441B460F03358BC8CC81E5F3FB43523BFA35E4EEF3BBE8BAD5788D | |||
| 2672 | CDM212364_Setup.exe | C:\Users\admin\AppData\Local\Temp\FTDI-Driver\amd64\ftd2xx64.dll | executable | |
MD5:BEFBC1A8F6C2B8E143DDD97CCB6561B5 | SHA256:774AF8B12C85D03562742ACDF222AF5E0432167BF107BA4B260757E4A5E36866 | |||
| 2672 | CDM212364_Setup.exe | C:\Users\admin\AppData\Local\Temp\FE3321.tmp | text | |
MD5:50F2BBF24A14BE4E408F94BC3849C38D | SHA256:D99B9414E6B4C20127BD62BB105010BF980A5F1C2922B1D900629F498473095A | |||
| 2672 | CDM212364_Setup.exe | C:\Users\admin\AppData\Local\Temp\FTDI-Driver\dpinst-x86.exe | executable | |
MD5:C2F2C1398C5CDB55A67676527EA29404 | SHA256:2BCA1650E3F7B9F98B06ED894CFD5EBC758E2B96EEB5D6C340D96E3F137D4472 | |||
| 2672 | CDM212364_Setup.exe | C:\Users\admin\AppData\Local\Temp\FTDI-Driver\amd64\ftcserco.dll | executable | |
MD5:AA69BF96E10F463082A0664B7A2E9FAE | SHA256:C0224B9EF14365F6DDA96134CC77D978E69FBD61EFDADE6FD1EB676418C41023 | |||
| 2672 | CDM212364_Setup.exe | C:\Users\admin\AppData\Local\Temp\FTDI-Driver\amd64\ftlang.dll | executable | |
MD5:662679682F491FBAF3D15953D13EC72E | SHA256:C2729911C4B82D8F9E22E057A1570D0265D7A9ECA44D6FE8DC0658F47263CE12 | |||
| 2672 | CDM212364_Setup.exe | C:\Users\admin\AppData\Local\Temp\FTDI-Driver\amd64\ftdibus.sys | executable | |
MD5:AB7418C8DFBBB97BEFB4F0ADED3D4663 | SHA256:3BD5BB7E646E67469EC25A37CAA5131CF992759703B0FC170DF7AF265B9F8E74 | |||
| 2672 | CDM212364_Setup.exe | C:\Users\admin\AppData\Local\Temp\FTDI-Driver\dp-chooser.exe | executable | |
MD5:461A3CE2E77143EC0E0015D80675911B | SHA256:003310B93A1A237FB022C7D7F40515DAF25FA1B91690965D3B98C1829A92ED37 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
— | — | 224.0.0.252:5355 | — | — | — | unknown |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |