File name: | CDM212364_Setup.zip |
Full analysis: | https://app.any.run/tasks/b577b587-4ade-4932-b5b5-8d92b0d49c21 |
Verdict: | Malicious activity |
Analysis date: | March 19, 2024, 11:25:37 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | application/zip |
File info: | Zip archive data, at least v2.0 to extract, compression method=deflate |
MD5: | 09B8D1E4F64828A2012AE54A7746D6D5 |
SHA1: | 1B1FA041EFF7B6FAB10E9FE73D3149C4DB750886 |
SHA256: | 10C399AC784D2B68B1BB2BA598BAB7FE00CFDFD267B4CC14A3E3240FE9499FB1 |
SSDEEP: | 49152:8GehdaQ/cr5lWZGiPsM3eg2FF56gtGRzDHaNTC4jt92Wh:padfioGiUMH2bLt6LaNTCGt92Wh |
.zip | | | ZIP compressed archive (100) |
---|
ZipRequiredVersion: | 20 |
---|---|
ZipBitFlag: | - |
ZipCompression: | Deflated |
ZipModifyDate: | 2021:07:12 13:11:30 |
ZipCRC: | 0x1986ce3c |
ZipCompressedSize: | 2209307 |
ZipUncompressedSize: | 2264632 |
ZipFileName: | CDM212364_Setup.exe |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
240 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa3992.4664\CDM212364_Setup.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa3992.4664\CDM212364_Setup.exe | — | WinRAR.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 3221226540 Modules
| |||||||||||||||
1696 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa3992.3393\CDM212364_Setup.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa3992.3393\CDM212364_Setup.exe | — | WinRAR.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 3221226540 Modules
| |||||||||||||||
1976 | DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{3a17e0e5-1a11-1902-8066-4b55b7d10d56}\ftdiport.inf" "0" "6960183e3" "000003DC" "WinSta0\Default" "00000338" "208" "c:\users\admin\appdata\local\temp\ftdi-driver" | C:\Windows\System32\drvinst.exe | svchost.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Driver Installation Module Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
2440 | DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{45eeb962-38cf-7bb2-d66a-8f706e67b057}\ftdibus.inf" "0" "657f6b0d3" "000005C0" "WinSta0\Default" "000003DC" "208" "c:\users\admin\appdata\local\temp\ftdi-driver" | C:\Windows\System32\drvinst.exe | svchost.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Driver Installation Module Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
2488 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa3992.4664\CDM212364_Setup.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa3992.4664\CDM212364_Setup.exe | WinRAR.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
2672 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa3992.3393\CDM212364_Setup.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa3992.3393\CDM212364_Setup.exe | WinRAR.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 1 Modules
| |||||||||||||||
2792 | C:\Users\admin\AppData\Local\Temp\FTDI-Driver\dpinst-x86.exe /sa | C:\Users\admin\AppData\Local\Temp\FTDI-Driver\dpinst-x86.exe | dp-chooser.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Driver Package Installer Exit code: 512 Version: 2.1 Modules
| |||||||||||||||
3180 | C:\Users\admin\AppData\Local\Temp\FTDI-Driver\dp-chooser.exe | C:\Users\admin\AppData\Local\Temp\FTDI-Driver\dp-chooser.exe | — | CDM212364_Setup.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
3992 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\CDM212364_Setup.zip" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
|
(PID) Process: | (3992) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
Operation: | write | Name: | ShellExtBMP |
Value: | |||
(PID) Process: | (3992) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
Operation: | write | Name: | ShellExtIcon |
Value: | |||
(PID) Process: | (3992) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
Operation: | write | Name: | LanguageList |
Value: en-US | |||
(PID) Process: | (3992) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\phacker.zip | |||
(PID) Process: | (3992) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
(PID) Process: | (3992) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip | |||
(PID) Process: | (3992) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\CDM212364_Setup.zip | |||
(PID) Process: | (3992) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | name |
Value: 120 | |||
(PID) Process: | (3992) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | size |
Value: 80 | |||
(PID) Process: | (3992) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | type |
Value: 120 |
PID | Process | Filename | Type | |
---|---|---|---|---|
2672 | CDM212364_Setup.exe | C:\Users\admin\AppData\Local\Temp\FTDI-Driver\amd64\ftdibus.sys | executable | |
MD5:AB7418C8DFBBB97BEFB4F0ADED3D4663 | SHA256:3BD5BB7E646E67469EC25A37CAA5131CF992759703B0FC170DF7AF265B9F8E74 | |||
3992 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3992.3393\CDM212364_Setup.exe | executable | |
MD5:0C97E7B5DE1B46FB723BED38F0DE28A2 | SHA256:835DD64B199190D20DC37C0CADEB064B7EAAAEF271703781B2B259B7085437A4 | |||
2672 | CDM212364_Setup.exe | C:\Users\admin\AppData\Local\Temp\FTDI-Driver\amd64\ftd2xx.lib | binary | |
MD5:2C6C133941002E602D1AC6831CBB7368 | SHA256:7C3A73D3A2441B460F03358BC8CC81E5F3FB43523BFA35E4EEF3BBE8BAD5788D | |||
2672 | CDM212364_Setup.exe | C:\Users\admin\AppData\Local\Temp\FTDI-Driver\amd64\ftcserco.dll | executable | |
MD5:AA69BF96E10F463082A0664B7A2E9FAE | SHA256:C0224B9EF14365F6DDA96134CC77D978E69FBD61EFDADE6FD1EB676418C41023 | |||
2672 | CDM212364_Setup.exe | C:\Users\admin\AppData\Local\Temp\FTDI-Driver\amd64\ftd2xx64.dll | executable | |
MD5:BEFBC1A8F6C2B8E143DDD97CCB6561B5 | SHA256:774AF8B12C85D03562742ACDF222AF5E0432167BF107BA4B260757E4A5E36866 | |||
2672 | CDM212364_Setup.exe | C:\Users\admin\AppData\Local\Temp\FTDI-Driver\amd64\ftbusui.dll | executable | |
MD5:D79A5E34F684B547FA2F963DFCC15A21 | SHA256:4BBC0B301A7C5A6B1B73878CE3AEEB191F5FCEAC05835372142206D79AC81559 | |||
2672 | CDM212364_Setup.exe | C:\Users\admin\AppData\Local\Temp\FTDI-Driver\amd64\ftlang.dll | executable | |
MD5:662679682F491FBAF3D15953D13EC72E | SHA256:C2729911C4B82D8F9E22E057A1570D0265D7A9ECA44D6FE8DC0658F47263CE12 | |||
2672 | CDM212364_Setup.exe | C:\Users\admin\AppData\Local\Temp\FTDI-Driver\amd64\ftser2k.sys | executable | |
MD5:B66678FF4E347E22146609B3D5B7B2C4 | SHA256:7A303AA880CC746D13F71E565874FB7C174747372CCF358B928A72219D2A50DD | |||
2672 | CDM212364_Setup.exe | C:\Users\admin\AppData\Local\Temp\FTDI-Driver\amd64\ftserui2.dll | executable | |
MD5:3E5BCD980AF8B20313005D9A492CEC8A | SHA256:55A23A2AC263E10B77D7E95601439F771062F2C248A8D93039A968D66100C39C | |||
2672 | CDM212364_Setup.exe | C:\Users\admin\AppData\Local\Temp\FTDI-Driver\dp-chooser.exe | executable | |
MD5:461A3CE2E77143EC0E0015D80675911B | SHA256:003310B93A1A237FB022C7D7F40515DAF25FA1B91690965D3B98C1829A92ED37 |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | unknown |
4 | System | 192.168.100.255:138 | — | — | — | unknown |
— | — | 224.0.0.252:5355 | — | — | — | unknown |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |