File name: | CH341A Programmer Special Edition v1.43.7z |
Full analysis: | https://app.any.run/tasks/42aa8e97-a689-4e07-b01f-093cb28991d5 |
Verdict: | Malicious activity |
Analysis date: | January 09, 2024, 10:42:10 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | application/x-7z-compressed |
File info: | 7-zip archive data, version 0.4 |
MD5: | A51FC4C9B3CA6C88AD52B690B893809C |
SHA1: | 3EF5978A33268E23D17813A265EB967D8D7C8BB7 |
SHA256: | 1AAA8C0C25CFBE30011AE605473D488399D53F839915749D4869897C20D6E9E9 |
SSDEEP: | 98304:stsTdvy5Lo9qqAV0DxmHURT9MmZrBwG9NwIQdRuW8K4K6nFiQPQ+SWpjkHCoPvMK:RC5n8TCfRXOE5ce |
.7z | | | 7-Zip compressed archive (v0.4) (57.1) |
---|---|---|
.7z | | | 7-Zip compressed archive (gen) (42.8) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
324 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa2184.44106\Installer.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa2184.44106\Installer.exe | — | WinRAR.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: Installer Application Exit code: 3221226540 Version: 1.0.0.4 Modules
| |||||||||||||||
784 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa2184.44106\Installer.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa2184.44106\Installer.exe | WinRAR.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: Installer Application Exit code: 3221225547 Version: 1.0.0.4 Modules
| |||||||||||||||
1892 | SETUP /S | C:\Program Files\CH341Programmer\DrvSetup86.exe | — | Installer.exe | |||||||||||
User: admin Integrity Level: HIGH Description: EXE For Driver Installation Exit code: 0 Version: 1, 6, 8, 0 Modules
| |||||||||||||||
2184 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\CH341A Programmer Special Edition v1.43.7z" | C:\Program Files\WinRAR\WinRAR.exe | — | explorer.exe | |||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
2628 | DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{10790b04-5bf1-633a-a78a-1412d92c340c}\CH341WDM.INF" "0" "6c8f1af03" "00000558" "WinSta0\Default" "000005D8" "208" "C:\Program Files\CH341Programmer" | C:\Windows\System32\drvinst.exe | — | svchost.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Driver Installation Module Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
|
(PID) Process: | (2184) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
Operation: | write | Name: | LanguageList |
Value: en-US | |||
(PID) Process: | (2184) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip | |||
(PID) Process: | (2184) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\phacker.zip | |||
(PID) Process: | (2184) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
(PID) Process: | (2184) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip | |||
(PID) Process: | (2184) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | name |
Value: 120 | |||
(PID) Process: | (2184) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | size |
Value: 80 | |||
(PID) Process: | (2184) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | type |
Value: 120 | |||
(PID) Process: | (2184) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | mtime |
Value: 100 | |||
(PID) Process: | (2184) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | ProxyBypass |
Value: 1 |
PID | Process | Filename | Type | |
---|---|---|---|---|
784 | Installer.exe | C:\Users\admin\AppData\Local\Temp\melo.mp3 | — | |
MD5:— | SHA256:— | |||
784 | Installer.exe | C:\Users\admin\AppData\Local\Temp\Exit.mp3 | binary | |
MD5:2B6A460BF2C0EB02BDCF3F3DBB72B338 | SHA256:7E4A729840C58E0F4D879D0FB0489B17F43925CA2D03B0E9ACC65C46AF6A3C68 | |||
784 | Installer.exe | C:\Program Files\CH341Programmer\Uninstaller.exe | executable | |
MD5:B93AD8C881A7504823521E6320E02048 | SHA256:49C55D6BD066BC517DCED2F9C404B371C27A14B66F7BF09B5B14362415EAC2A4 | |||
784 | Installer.exe | C:\Users\admin\AppData\Local\Temp\hollow.mp3 | binary | |
MD5:95159E2450765082DA15F9FAB538F3E9 | SHA256:34F682606A43AACBF9DF3E43FC190AF07E99544C3B92080B5BC56E899D21EC53 | |||
2184 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2184.44106\Installer.exe | executable | |
MD5:646FE7A8A3D64B95956B366969370D8A | SHA256:C797C439E404109266D09E9B3F5268EE8805BAB28E01DA70ABA3E26E2E9991ED | |||
784 | Installer.exe | C:\Program Files\CH341Programmer\DrvSetup64.exe | executable | |
MD5:1FE688688C2082B37827DB54C4282AF0 | SHA256:A5A07EE7B5195497BE4796845CB05B38618DAAF2AF98884B29EEAD6D073353B8 | |||
784 | Installer.exe | C:\Program Files\CH341Programmer\CH341WDM.CAT | binary | |
MD5:71BDCA7F420EA6C2AAC393040624349D | SHA256:1D25C1A1B550E94789CD9A7E3FA01C11B3C7B75737D1C0BE1AC08626C76111FB | |||
784 | Installer.exe | C:\Program Files\CH341Programmer\CH341WDM.SYS | executable | |
MD5:E6E76D443E2925F7AE9D9FBF4255B50C | SHA256:A3045A4F29A8C86E6FE5AF9E5C9225294D266C6218D65BBFCAA5A7D1C683ABD7 | |||
784 | Installer.exe | C:\Program Files\CH341Programmer\CH341W64.SYS | executable | |
MD5:2E8E48AD2CA64024C20C67C747F217F6 | SHA256:AED7640E2195F5A52E788844D38B08F906264D2E740BD362DB76C241CBB27F7E | |||
784 | Installer.exe | C:\Users\admin\AppData\Local\Temp\InstOk.mp3 | binary | |
MD5:DC216D421D6F96B199B7FF769D9F3846 | SHA256:E23DF7E49AADAF745B2F4B136BF2096FF258A01E299A56076EF480DBA6BD5155 |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | unknown |
4 | System | 192.168.100.255:137 | — | — | — | unknown |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |