File name:

CDM212364_Setup.zip

Full analysis: https://app.any.run/tasks/b577b587-4ade-4932-b5b5-8d92b0d49c21
Verdict: Malicious activity
Analysis date: March 19, 2024, 11:25:37
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=deflate
MD5:

09B8D1E4F64828A2012AE54A7746D6D5

SHA1:

1B1FA041EFF7B6FAB10E9FE73D3149C4DB750886

SHA256:

10C399AC784D2B68B1BB2BA598BAB7FE00CFDFD267B4CC14A3E3240FE9499FB1

SSDEEP:

49152:8GehdaQ/cr5lWZGiPsM3eg2FF56gtGRzDHaNTC4jt92Wh:padfioGiUMH2bLt6LaNTCGt92Wh

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 3992)
      • CDM212364_Setup.exe (PID: 2672)
      • dpinst-x86.exe (PID: 2792)
      • drvinst.exe (PID: 2440)
      • drvinst.exe (PID: 1976)
    • Creates a writable file in the system directory

      • drvinst.exe (PID: 1976)
      • drvinst.exe (PID: 2440)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • CDM212364_Setup.exe (PID: 2672)
    • Executable content was dropped or overwritten

      • dpinst-x86.exe (PID: 2792)
      • CDM212364_Setup.exe (PID: 2672)
      • drvinst.exe (PID: 2440)
      • drvinst.exe (PID: 1976)
    • Drops a system driver (possible attempt to evade defenses)

      • CDM212364_Setup.exe (PID: 2672)
      • dpinst-x86.exe (PID: 2792)
      • drvinst.exe (PID: 2440)
      • drvinst.exe (PID: 1976)
    • Reads security settings of Internet Explorer

      • WinRAR.exe (PID: 3992)
    • Starts a Microsoft application from unusual location

      • dpinst-x86.exe (PID: 2792)
    • Creates files in the driver directory

      • drvinst.exe (PID: 2440)
      • drvinst.exe (PID: 1976)
    • Checks Windows Trust Settings

      • drvinst.exe (PID: 2440)
      • drvinst.exe (PID: 1976)
  • INFO

    • Checks supported languages

      • CDM212364_Setup.exe (PID: 2672)
      • dp-chooser.exe (PID: 3180)
      • dpinst-x86.exe (PID: 2792)
      • drvinst.exe (PID: 2440)
      • drvinst.exe (PID: 1976)
      • CDM212364_Setup.exe (PID: 2488)
    • Reads the computer name

      • dpinst-x86.exe (PID: 2792)
      • drvinst.exe (PID: 2440)
      • drvinst.exe (PID: 1976)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3992)
    • Reads the machine GUID from the registry

      • dpinst-x86.exe (PID: 2792)
      • drvinst.exe (PID: 1976)
      • drvinst.exe (PID: 2440)
    • Create files in a temporary directory

      • dpinst-x86.exe (PID: 2792)
      • CDM212364_Setup.exe (PID: 2672)
      • CDM212364_Setup.exe (PID: 2488)
    • Reads the software policy settings

      • drvinst.exe (PID: 2440)
      • drvinst.exe (PID: 1976)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2021:07:12 13:11:30
ZipCRC: 0x1986ce3c
ZipCompressedSize: 2209307
ZipUncompressedSize: 2264632
ZipFileName: CDM212364_Setup.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
50
Monitored processes
9
Malicious processes
6
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe cdm212364_setup.exe no specs cdm212364_setup.exe dp-chooser.exe no specs dpinst-x86.exe drvinst.exe drvinst.exe cdm212364_setup.exe no specs cdm212364_setup.exe

Process information

PID
CMD
Path
Indicators
Parent process
240"C:\Users\admin\AppData\Local\Temp\Rar$EXa3992.4664\CDM212364_Setup.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3992.4664\CDM212364_Setup.exeWinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3992.4664\cdm212364_setup.exe
c:\windows\system32\ntdll.dll
1696"C:\Users\admin\AppData\Local\Temp\Rar$EXa3992.3393\CDM212364_Setup.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3992.3393\CDM212364_Setup.exeWinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3992.3393\cdm212364_setup.exe
c:\windows\system32\ntdll.dll
1976DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{3a17e0e5-1a11-1902-8066-4b55b7d10d56}\ftdiport.inf" "0" "6960183e3" "000003DC" "WinSta0\Default" "00000338" "208" "c:\users\admin\appdata\local\temp\ftdi-driver"C:\Windows\System32\drvinst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
2440DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{45eeb962-38cf-7bb2-d66a-8f706e67b057}\ftdibus.inf" "0" "657f6b0d3" "000005C0" "WinSta0\Default" "000003DC" "208" "c:\users\admin\appdata\local\temp\ftdi-driver"C:\Windows\System32\drvinst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
2488"C:\Users\admin\AppData\Local\Temp\Rar$EXa3992.4664\CDM212364_Setup.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3992.4664\CDM212364_Setup.exe
WinRAR.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3992.4664\cdm212364_setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
2672"C:\Users\admin\AppData\Local\Temp\Rar$EXa3992.3393\CDM212364_Setup.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3992.3393\CDM212364_Setup.exe
WinRAR.exe
User:
admin
Integrity Level:
HIGH
Exit code:
1
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3992.3393\cdm212364_setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
2792C:\Users\admin\AppData\Local\Temp\FTDI-Driver\dpinst-x86.exe /saC:\Users\admin\AppData\Local\Temp\FTDI-Driver\dpinst-x86.exe
dp-chooser.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Driver Package Installer
Exit code:
512
Version:
2.1
Modules
Images
c:\users\admin\appdata\local\temp\ftdi-driver\dpinst-x86.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3180C:\Users\admin\AppData\Local\Temp\FTDI-Driver\dp-chooser.exeC:\Users\admin\AppData\Local\Temp\FTDI-Driver\dp-chooser.exeCDM212364_Setup.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\ftdi-driver\dp-chooser.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
3992"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\CDM212364_Setup.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
Total events
10 094
Read events
10 026
Write events
65
Delete events
3

Modification events

(PID) Process:(3992) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3992) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3992) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3992) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(3992) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(3992) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(3992) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\CDM212364_Setup.zip
(PID) Process:(3992) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3992) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3992) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
Executable files
48
Suspicious files
10
Text files
19
Unknown types
17

Dropped files

PID
Process
Filename
Type
2672CDM212364_Setup.exeC:\Users\admin\AppData\Local\Temp\FTDI-Driver\amd64\ftbusui.dllexecutable
MD5:D79A5E34F684B547FA2F963DFCC15A21
SHA256:4BBC0B301A7C5A6B1B73878CE3AEEB191F5FCEAC05835372142206D79AC81559
2672CDM212364_Setup.exeC:\Users\admin\AppData\Local\Temp\FTDI-Driver\amd64\ftser2k.sysexecutable
MD5:B66678FF4E347E22146609B3D5B7B2C4
SHA256:7A303AA880CC746D13F71E565874FB7C174747372CCF358B928A72219D2A50DD
2672CDM212364_Setup.exeC:\Users\admin\AppData\Local\Temp\FTDI-Driver\dpinst-amd64.exeexecutable
MD5:0E7E8820A977D3B4B81C5188FA841C52
SHA256:65054D27C91C21AF7C7F1838427A0AC64089DC51DD27EB220B589C26B94903A1
2672CDM212364_Setup.exeC:\Users\admin\AppData\Local\Temp\FTDI-Driver\amd64\ftd2xx64.dllexecutable
MD5:BEFBC1A8F6C2B8E143DDD97CCB6561B5
SHA256:774AF8B12C85D03562742ACDF222AF5E0432167BF107BA4B260757E4A5E36866
2672CDM212364_Setup.exeC:\Users\admin\AppData\Local\Temp\FTDI-Driver\dpinst-x86.exeexecutable
MD5:C2F2C1398C5CDB55A67676527EA29404
SHA256:2BCA1650E3F7B9F98B06ED894CFD5EBC758E2B96EEB5D6C340D96E3F137D4472
2672CDM212364_Setup.exeC:\Users\admin\AppData\Local\Temp\FTDI-Driver\ftd2xx.htext
MD5:08FBBF757A92B079CA66FF62D99A6C82
SHA256:EE0C6358BA2F13015EC7B07AEA16BF3ADA33508851CC494FC256A8B28AF31147
2672CDM212364_Setup.exeC:\Users\admin\AppData\Local\Temp\FTDI-Driver\amd64\ftcserco.dllexecutable
MD5:AA69BF96E10F463082A0664B7A2E9FAE
SHA256:C0224B9EF14365F6DDA96134CC77D978E69FBD61EFDADE6FD1EB676418C41023
2672CDM212364_Setup.exeC:\Users\admin\AppData\Local\Temp\FTDI-Driver\amd64\ftdibus.sysexecutable
MD5:AB7418C8DFBBB97BEFB4F0ADED3D4663
SHA256:3BD5BB7E646E67469EC25A37CAA5131CF992759703B0FC170DF7AF265B9F8E74
2672CDM212364_Setup.exeC:\Users\admin\AppData\Local\Temp\FTDI-Driver\amd64\ftd2xx.libbinary
MD5:2C6C133941002E602D1AC6831CBB7368
SHA256:7C3A73D3A2441B460F03358BC8CC81E5F3FB43523BFA35E4EEF3BBE8BAD5788D
3992WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3992.3393\CDM212364_Setup.exeexecutable
MD5:0C97E7B5DE1B46FB723BED38F0DE28A2
SHA256:835DD64B199190D20DC37C0CADEB064B7EAAAEF271703781B2B259B7085437A4
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
224.0.0.252:5355
unknown
1080
svchost.exe
224.0.0.252:5355
unknown

DNS requests

No data

Threats

No threats detected
No debug info