File name:

dshidmini_v2.2.282.0.zip

Full analysis: https://app.any.run/tasks/b70791f4-9f65-47ee-9858-10d5016e091e
Verdict: Malicious activity
Analysis date: May 18, 2025, 17:35:01
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=deflate
MD5:

821E201A124350D183FC6F7EA9EC463F

SHA1:

3E4AA8CE9378C1562E361F4AEA1389C2EC3C64D6

SHA256:

27FCDC6C92D661A101CEBCBE5E673E620F7723DDEE4092D894D275AF91A8A06A

SSDEEP:

98304:z9bV28rYvl8jrom2/FHkepfk1R4V5vYCuWGp3ZGvfnRHXubd3wVMJ241o9+bryiE:EJgbZSnF8wL

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Drops a system driver (possible attempt to evade defenses)

      • WinRAR.exe (PID: 1600)
      • InfDefaultInstall.exe (PID: 6660)
      • drvinst.exe (PID: 4728)
    • Executable content was dropped or overwritten

      • InfDefaultInstall.exe (PID: 2908)
      • drvinst.exe (PID: 4560)
      • drvinst.exe (PID: 4728)
      • InfDefaultInstall.exe (PID: 6660)
    • Creates files in the driver directory

      • drvinst.exe (PID: 4560)
      • drvinst.exe (PID: 4728)
    • Creates or modifies Windows services

      • drvinst.exe (PID: 5984)
    • Reads security settings of Internet Explorer

      • DSHMC.exe (PID: 7048)
      • DSHMC.exe (PID: 4464)
  • INFO

    • The sample compiled with english language support

      • WinRAR.exe (PID: 1600)
      • drvinst.exe (PID: 4560)
      • InfDefaultInstall.exe (PID: 2908)
      • InfDefaultInstall.exe (PID: 6660)
      • drvinst.exe (PID: 4728)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 1600)
    • Manual execution by a user

      • notepad.exe (PID: 5756)
      • InfDefaultInstall.exe (PID: 5228)
      • notepad.exe (PID: 1452)
      • InfDefaultInstall.exe (PID: 2908)
      • InfDefaultInstall.exe (PID: 4024)
      • InfDefaultInstall.exe (PID: 6660)
      • DSHMC.exe (PID: 7048)
      • DSHMC.exe (PID: 4464)
    • Reads security settings of Internet Explorer

      • notepad.exe (PID: 5756)
      • notepad.exe (PID: 1452)
      • rundll32.exe (PID: 1072)
    • Checks supported languages

      • drvinst.exe (PID: 4560)
      • drvinst.exe (PID: 4728)
      • drvinst.exe (PID: 5984)
      • DSHMC.exe (PID: 7048)
      • DSHMC.exe (PID: 4464)
    • Create files in a temporary directory

      • InfDefaultInstall.exe (PID: 2908)
      • InfDefaultInstall.exe (PID: 6660)
    • Reads the software policy settings

      • drvinst.exe (PID: 4560)
      • rundll32.exe (PID: 1072)
      • slui.exe (PID: 4932)
      • drvinst.exe (PID: 4728)
      • DSHMC.exe (PID: 7048)
      • DSHMC.exe (PID: 4464)
    • Reads the computer name

      • drvinst.exe (PID: 4560)
      • drvinst.exe (PID: 5984)
      • DSHMC.exe (PID: 7048)
      • DSHMC.exe (PID: 4464)
      • drvinst.exe (PID: 4728)
    • Reads the machine GUID from the registry

      • drvinst.exe (PID: 4560)
      • drvinst.exe (PID: 4728)
      • DSHMC.exe (PID: 7048)
      • DSHMC.exe (PID: 4464)
    • Disables trace logs

      • DSHMC.exe (PID: 7048)
      • DSHMC.exe (PID: 4464)
    • Checks proxy server information

      • DSHMC.exe (PID: 7048)
      • DSHMC.exe (PID: 4464)
    • Adds/modifies Windows certificates

      • drvinst.exe (PID: 4560)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2021:11:08 18:08:22
ZipCRC: 0xe9cc8b04
ZipCompressedSize: 3284068
ZipUncompressedSize: 3556832
ZipFileName: DSHMC.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
150
Monitored processes
17
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe sppextcomobj.exe no specs slui.exe rundll32.exe no specs notepad.exe no specs notepad.exe no specs infdefaultinstall.exe no specs infdefaultinstall.exe drvinst.exe rundll32.exe no specs slui.exe no specs infdefaultinstall.exe no specs infdefaultinstall.exe drvinst.exe drvinst.exe no specs dshmc.exe dshmc.exe

Process information

PID
CMD
Path
Indicators
Parent process
664C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -EmbeddingC:\Windows\System32\rundll32.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shcore.dll
c:\windows\system32\imagehlp.dll
1072rundll32.exe C:\WINDOWS\system32\pnpui.dll,InstallSecurityPromptRunDllW 20 Global\{2b3851f3-255c-5d41-9a32-6123fef9c02a} Global\{c5bf7a78-09ca-5745-adb3-5100df8fecac} C:\WINDOWS\System32\DriverStore\Temp\{f986a96f-91c4-af4b-a128-ab39aa42e1d5}\dshidmini.inf C:\WINDOWS\System32\DriverStore\Temp\{f986a96f-91c4-af4b-a128-ab39aa42e1d5}\dshidmini.catC:\Windows\System32\rundll32.exedrvinst.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shcore.dll
c:\windows\system32\imagehlp.dll
1312C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
1452"C:\WINDOWS\system32\NOTEPAD.EXE" C:\Users\admin\Desktop\x64\dshidmini\dshidmini.infC:\Windows\System32\notepad.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\notepad.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
1600"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\dshidmini_v2.2.282.0.zipC:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
2908"C:\WINDOWS\System32\InfDefaultInstall.exe" "C:\Users\admin\Desktop\x64\dshidmini\dshidmini.inf"C:\Windows\System32\InfDefaultInstall.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
INF Default Install
Exit code:
0
Version:
5.2.3668.0
Modules
Images
c:\windows\system32\infdefaultinstall.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
4024"C:\WINDOWS\System32\InfDefaultInstall.exe" "C:\Users\admin\Desktop\x64\dshidmini\igfilter.inf"C:\Windows\System32\InfDefaultInstall.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
INF Default Install
Exit code:
3221226540
Version:
5.2.3668.0
Modules
Images
c:\windows\system32\infdefaultinstall.exe
c:\windows\system32\ntdll.dll
4464"C:\Users\admin\Desktop\DSHMC.exe" C:\Users\admin\Desktop\DSHMC.exe
explorer.exe
User:
admin
Company:
Nefarius Software Solutions e.U.
Integrity Level:
HIGH
Description:
DsHidMini Control
Version:
2.2.282.0
Modules
Images
c:\users\admin\desktop\dshmc.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
4560DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{cdc81991-8b5f-c548-9d5a-fe5748dd9f34}\dshidmini.inf" "9" "4e5cb8d47" "00000000000001D4" "WinSta0\Default" "00000000000001E4" "208" "C:\Users\admin\Desktop\x64\dshidmini"C:\Windows\System32\drvinst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\drvstore.dll
4728DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{99d914b8-2221-fe44-b2fc-293aa6c89d95}\igfilter.inf" "9" "4dfe561fb" "00000000000001F8" "WinSta0\Default" "00000000000001F4" "208" "C:\Users\admin\Desktop\x64\dshidmini"C:\Windows\System32\drvinst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\drvstore.dll
Total events
15 077
Read events
15 035
Write events
40
Delete events
2

Modification events

(PID) Process:(1600) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(1600) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(1600) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(1600) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\dshidmini_v2.2.282.0.zip
(PID) Process:(1600) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(1600) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(1600) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(1600) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(1600) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF3D0000002D000000FD03000016020000
(PID) Process:(1600) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\ArcColumnWidths
Operation:writeName:name
Value:
256
Executable files
18
Suspicious files
29
Text files
4
Unknown types
0

Dropped files

PID
Process
Filename
Type
1600WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1600.3089\DSHMC.pdbbinary
MD5:92A54B0D173CBA8483D92B1B59875602
SHA256:B837D2FFD9DE52E8CFCA49B5960D468CC8C73951B3F580D9C68F44299B0C1C75
1600WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1600.3089\x64\dshidmini.pdbbinary
MD5:EF4F2A74F44BBB4EC7758B32EB4DB89F
SHA256:BE1AE0483D9D4512543258D195777A523052AF8D60E73D22383F5CAE2FBB903C
1600WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1600.3089\x64\dshidmini\igfilter.catbinary
MD5:58E865C54CD2C2F3038704A97C3920F9
SHA256:2B58C673FD36F3DFBD0D4D4AD0D5853ADC827CCBC5BF31D086C485242A8D628D
1600WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1600.3089\x64\dshidmini\igfilter.infbinary
MD5:F4EACD01294A9ED7C482C193C3B3B3B7
SHA256:765B40637270F4361FCB3F231626C9D14C989EF0D8BC63FB76BC7F47DF99ABD3
1600WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1600.3089\x64\dshidmini\dshidmini.dllexecutable
MD5:CE1BA56FD413818C5EDE3E4FC9138321
SHA256:C5FE1228126E1384B8EBAAFB7AE253007BB1484624DB6F7EBEBA9FE3F6B338F1
1600WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1600.3089\x86\dshidmini\dshidmini.infbinary
MD5:4FC7E21A95FFCAE116C9216709F94577
SHA256:D2008AF1E8B5CB9EFC7D7A9560886EF2510933DE0DD928394F2CCD4EB22EBB6C
1600WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1600.3089\x64\dshidmini\LICENSEtext
MD5:AC2529ED2F45E675368CB56112C18F71
SHA256:C868DF89B6321BD7BF291B45FA6D8A0436F7053883C68EBAF0545ED98A2C7025
1600WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1600.3089\x64\dshidmini\nssmkig.sysexecutable
MD5:1C6A558FD14C1ACF7AEC6D494D68997E
SHA256:4B05DADB715E1ADE09B921706936088AF0999285AC76528BC6179A38D8284CE7
1600WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1600.3089\x64\dshidmini\dshidmini.catbinary
MD5:77CD0EEFC220429AEA7F2457EC29F324
SHA256:08A0123C8DCD5A04C7A7639210784DAB83692967EB053E664C6380F4F6F76327
1600WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1600.3089\x86\dshidmini.pdbbinary
MD5:7DB7CA58A4964A8C5C9DC2C0B5A82E98
SHA256:2A145B2ED3BBD5FC1A3559AC22CD3414E5EB663D848D6DC4943BFFC6382CBB4B
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
21
DNS requests
15
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
2.16.168.124:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
6544
svchost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
4120
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
4120
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2.16.168.124:80
crl.microsoft.com
Akamai International B.V.
RU
whitelisted
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
6544
svchost.exe
20.190.159.128:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6544
svchost.exe
2.23.77.188:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
4120
SIHClient.exe
20.109.210.53:443
slscr.update.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4120
SIHClient.exe
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
4120
SIHClient.exe
52.165.164.15:443
fe3cr.delivery.mp.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 40.127.240.158
whitelisted
crl.microsoft.com
  • 2.16.168.124
  • 2.16.168.114
whitelisted
www.microsoft.com
  • 95.101.149.131
whitelisted
google.com
  • 142.250.186.174
whitelisted
login.live.com
  • 20.190.159.128
  • 20.190.159.130
  • 40.126.31.131
  • 20.190.159.131
  • 40.126.31.130
  • 40.126.31.73
  • 40.126.31.0
  • 20.190.159.68
whitelisted
ocsp.digicert.com
  • 2.23.77.188
whitelisted
slscr.update.microsoft.com
  • 20.109.210.53
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 52.165.164.15
whitelisted
activation-v2.sls.microsoft.com
  • 40.91.76.224
whitelisted
nexusrules.officeapps.live.com
  • 52.111.236.22
whitelisted

Threats

No threats detected
No debug info