| File name: | CH341A Programmer Special Edition v1.43.7z |
| Full analysis: | https://app.any.run/tasks/42aa8e97-a689-4e07-b01f-093cb28991d5 |
| Verdict: | Malicious activity |
| Analysis date: | January 09, 2024, 10:42:10 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-7z-compressed |
| File info: | 7-zip archive data, version 0.4 |
| MD5: | A51FC4C9B3CA6C88AD52B690B893809C |
| SHA1: | 3EF5978A33268E23D17813A265EB967D8D7C8BB7 |
| SHA256: | 1AAA8C0C25CFBE30011AE605473D488399D53F839915749D4869897C20D6E9E9 |
| SSDEEP: | 98304:stsTdvy5Lo9qqAV0DxmHURT9MmZrBwG9NwIQdRuW8K4K6nFiQPQ+SWpjkHCoPvMK:RC5n8TCfRXOE5ce |
| .7z | | | 7-Zip compressed archive (v0.4) (57.1) |
|---|---|---|
| .7z | | | 7-Zip compressed archive (gen) (42.8) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 324 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa2184.44106\Installer.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa2184.44106\Installer.exe | — | WinRAR.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: Installer Application Exit code: 3221226540 Version: 1.0.0.4 Modules
| |||||||||||||||
| 784 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa2184.44106\Installer.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa2184.44106\Installer.exe | WinRAR.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: Installer Application Exit code: 3221225547 Version: 1.0.0.4 Modules
| |||||||||||||||
| 1892 | SETUP /S | C:\Program Files\CH341Programmer\DrvSetup86.exe | — | Installer.exe | |||||||||||
User: admin Integrity Level: HIGH Description: EXE For Driver Installation Exit code: 0 Version: 1, 6, 8, 0 Modules
| |||||||||||||||
| 2184 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\CH341A Programmer Special Edition v1.43.7z" | C:\Program Files\WinRAR\WinRAR.exe | — | explorer.exe | |||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| 2628 | DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{10790b04-5bf1-633a-a78a-1412d92c340c}\CH341WDM.INF" "0" "6c8f1af03" "00000558" "WinSta0\Default" "000005D8" "208" "C:\Program Files\CH341Programmer" | C:\Windows\System32\drvinst.exe | — | svchost.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Driver Installation Module Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (2184) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2184) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip | |||
| (PID) Process: | (2184) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\phacker.zip | |||
| (PID) Process: | (2184) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (2184) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip | |||
| (PID) Process: | (2184) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (2184) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (2184) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (2184) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (2184) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 784 | Installer.exe | C:\Users\admin\AppData\Local\Temp\melo.mp3 | — | |
MD5:— | SHA256:— | |||
| 784 | Installer.exe | C:\Users\admin\AppData\Local\Temp\Exit.mp3 | binary | |
MD5:2B6A460BF2C0EB02BDCF3F3DBB72B338 | SHA256:7E4A729840C58E0F4D879D0FB0489B17F43925CA2D03B0E9ACC65C46AF6A3C68 | |||
| 784 | Installer.exe | C:\Users\admin\AppData\Local\Temp\Next.mp3 | binary | |
MD5:D5DF696B74342B6ED902DBE9E9AC80E8 | SHA256:685199EA1582F17CB00C01A7EDDCC9D456A17C34BD6D96BD3EA6295AF4BC852B | |||
| 784 | Installer.exe | C:\Program Files\CH341Programmer\CH341WDM.INF | binary | |
MD5:92AA65B747DC242E8CC3B50264147D21 | SHA256:466D05703A3CD24C9A4C7E7329A46205543D342474D80384894FE7748D53556D | |||
| 2184 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2184.44106\Installer.exe | executable | |
MD5:646FE7A8A3D64B95956B366969370D8A | SHA256:C797C439E404109266D09E9B3F5268EE8805BAB28E01DA70ABA3E26E2E9991ED | |||
| 784 | Installer.exe | C:\Users\admin\AppData\Local\Temp\Show.mp3 | binary | |
MD5:9B079829520C9641DE22766D400182C1 | SHA256:2D02E807A76E122DE35892297066740A271479BB836290421CE4A9BD6444E90A | |||
| 784 | Installer.exe | C:\Program Files\CH341Programmer\DrvSetup64.exe | executable | |
MD5:1FE688688C2082B37827DB54C4282AF0 | SHA256:A5A07EE7B5195497BE4796845CB05B38618DAAF2AF98884B29EEAD6D073353B8 | |||
| 784 | Installer.exe | C:\Users\admin\AppData\Local\Temp\InstOk.mp3 | binary | |
MD5:DC216D421D6F96B199B7FF769D9F3846 | SHA256:E23DF7E49AADAF745B2F4B136BF2096FF258A01E299A56076EF480DBA6BD5155 | |||
| 784 | Installer.exe | C:\Program Files\CH341Programmer\CH341WDM.SYS | executable | |
MD5:E6E76D443E2925F7AE9D9FBF4255B50C | SHA256:A3045A4F29A8C86E6FE5AF9E5C9225294D266C6218D65BBFCAA5A7D1C683ABD7 | |||
| 784 | Installer.exe | C:\Program Files\CH341Programmer\SiberiaProg-CH341A.exe | executable | |
MD5:DC6668286A20061AE05B05FDABF15614 | SHA256:19861ADB99B18E5D55536806F9B21956CC8079DC3D48AA564AAED67F0D326D2D | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |