File name:

dshidmini_v2.2.282.0.zip

Full analysis: https://app.any.run/tasks/feb75065-c4c3-4961-bd23-99985e77445d
Verdict: Malicious activity
Analysis date: May 18, 2025, 17:33:25
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=deflate
MD5:

821E201A124350D183FC6F7EA9EC463F

SHA1:

3E4AA8CE9378C1562E361F4AEA1389C2EC3C64D6

SHA256:

27FCDC6C92D661A101CEBCBE5E673E620F7723DDEE4092D894D275AF91A8A06A

SSDEEP:

98304:z9bV28rYvl8jrom2/FHkepfk1R4V5vYCuWGp3ZGvfnRHXubd3wVMJ241o9+bryiE:EJgbZSnF8wL

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Drops a system driver (possible attempt to evade defenses)

      • WinRAR.exe (PID: 6040)
    • Executable content was dropped or overwritten

      • InfDefaultInstall.exe (PID: 5260)
      • drvinst.exe (PID: 6080)
    • Creates files in the driver directory

      • drvinst.exe (PID: 6080)
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 6040)
    • The sample compiled with english language support

      • WinRAR.exe (PID: 6040)
      • InfDefaultInstall.exe (PID: 5260)
      • drvinst.exe (PID: 6080)
    • Manual execution by a user

      • InfDefaultInstall.exe (PID: 5260)
      • InfDefaultInstall.exe (PID: 6676)
    • Create files in a temporary directory

      • InfDefaultInstall.exe (PID: 5260)
    • Checks supported languages

      • drvinst.exe (PID: 6080)
    • Reads the software policy settings

      • rundll32.exe (PID: 736)
      • drvinst.exe (PID: 6080)
    • Reads security settings of Internet Explorer

      • rundll32.exe (PID: 736)
    • Reads the machine GUID from the registry

      • drvinst.exe (PID: 6080)
    • Reads the computer name

      • drvinst.exe (PID: 6080)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2021:11:08 18:08:22
ZipCRC: 0xe9cc8b04
ZipCompressedSize: 3284068
ZipUncompressedSize: 3556832
ZipFileName: DSHMC.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
136
Monitored processes
6
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe rundll32.exe no specs infdefaultinstall.exe no specs infdefaultinstall.exe drvinst.exe rundll32.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
736rundll32.exe C:\WINDOWS\system32\pnpui.dll,InstallSecurityPromptRunDllW 20 Global\{88d715f4-ec00-8947-964a-2c86ca30c3c8} Global\{045da93a-0d9b-a141-aedd-d01d2f9e7dd6} C:\WINDOWS\System32\DriverStore\Temp\{7dccc8de-66a2-c94c-bd3d-09fa0f4de331}\dshidmini.inf C:\WINDOWS\System32\DriverStore\Temp\{7dccc8de-66a2-c94c-bd3d-09fa0f4de331}\dshidmini.catC:\Windows\System32\rundll32.exedrvinst.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows host process (Rundll32)
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shcore.dll
c:\windows\system32\imagehlp.dll
1052C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -EmbeddingC:\Windows\System32\rundll32.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shcore.dll
c:\windows\system32\imagehlp.dll
5260"C:\WINDOWS\System32\InfDefaultInstall.exe" "C:\Users\admin\Desktop\x64\dshidmini\dshidmini.inf"C:\Windows\System32\InfDefaultInstall.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
INF Default Install
Version:
5.2.3668.0
Modules
Images
c:\windows\system32\infdefaultinstall.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
6040"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\dshidmini_v2.2.282.0.zipC:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
6080DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{7337e31a-0e6e-7e42-a7d5-eb2bf6022fc8}\dshidmini.inf" "9" "4e5cb8d47" "00000000000001E0" "WinSta0\Default" "00000000000001F0" "208" "C:\Users\admin\Desktop\x64\dshidmini"C:\Windows\System32\drvinst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\drvstore.dll
6676"C:\WINDOWS\System32\InfDefaultInstall.exe" "C:\Users\admin\Desktop\x64\dshidmini\dshidmini.inf"C:\Windows\System32\InfDefaultInstall.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
INF Default Install
Exit code:
3221226540
Version:
5.2.3668.0
Modules
Images
c:\windows\system32\infdefaultinstall.exe
c:\windows\system32\ntdll.dll
Total events
10 730
Read events
10 700
Write events
30
Delete events
0

Modification events

(PID) Process:(6040) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(6040) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(6040) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(6040) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\dshidmini_v2.2.282.0.zip
(PID) Process:(6040) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(6040) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(6040) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(6040) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(6040) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\ArcColumnWidths
Operation:writeName:name
Value:
256
(PID) Process:(6040) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\ArcColumnWidths
Operation:writeName:size
Value:
80
Executable files
14
Suspicious files
19
Text files
3
Unknown types
0

Dropped files

PID
Process
Filename
Type
6040WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6040.45143\DSHMC.pdbbinary
MD5:92A54B0D173CBA8483D92B1B59875602
SHA256:B837D2FFD9DE52E8CFCA49B5960D468CC8C73951B3F580D9C68F44299B0C1C75
6040WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6040.45143\DSHMC.exeexecutable
MD5:A8FAC715901CFA315425FE12876B5814
SHA256:10E03A6FD23C96790A89D2001B323F77D8EFB46290948D984FB325B58BC88CC5
6040WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6040.45143\x64\dshidmini.pdbbinary
MD5:EF4F2A74F44BBB4EC7758B32EB4DB89F
SHA256:BE1AE0483D9D4512543258D195777A523052AF8D60E73D22383F5CAE2FBB903C
6040WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6040.45143\x64\dshidmini.dllexecutable
MD5:590DAEBA78F0E711FCFF5C784FC6EE98
SHA256:CACD7E2ABE5955C8EADF0C80AC72C4B2741BBE84522E88C14336D155A343EEBC
6040WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6040.45143\x64\dshidmini\dshidmini.dllexecutable
MD5:CE1BA56FD413818C5EDE3E4FC9138321
SHA256:C5FE1228126E1384B8EBAAFB7AE253007BB1484624DB6F7EBEBA9FE3F6B338F1
6040WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6040.45143\x64\dshidmini\igfilter.catbinary
MD5:58E865C54CD2C2F3038704A97C3920F9
SHA256:2B58C673FD36F3DFBD0D4D4AD0D5853ADC827CCBC5BF31D086C485242A8D628D
6040WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6040.45143\x64\dshidmini\dshidmini.infbinary
MD5:FCFEE1D3202BAB69D68A1F8A3CAD4742
SHA256:1490B82EA99509C9BF18605C3245D9B572D9C69EF7819F8E4D43BBC66F7FDFA5
6040WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6040.45143\x64\dshidmini\dshidmini.catbinary
MD5:77CD0EEFC220429AEA7F2457EC29F324
SHA256:08A0123C8DCD5A04C7A7639210784DAB83692967EB053E664C6380F4F6F76327
6040WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6040.45143\DSHMC.jsontext
MD5:4CB66DF591A9DF32444B2D46A03B592E
SHA256:74151CFAD882CEB1A8D540A8C6CA8453DF59BF99D3011963C711D351DE82E00C
6040WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6040.45143\x86\dshidmini\dshidmini.catbinary
MD5:9CB5E64362F85CDCA9E5A1D6850FD00C
SHA256:5D924F79B89C44F92B0C127EA370F8D82619E7F8D1FF47BD3E18F571788C45CA
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
18
DNS requests
13
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
23.48.23.143:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
6544
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
4272
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
4272
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
23.48.23.143:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
3216
svchost.exe
172.211.123.248:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
6544
svchost.exe
20.190.160.130:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6544
svchost.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
2104
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4272
SIHClient.exe
4.245.163.56:443
slscr.update.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.185.174
whitelisted
settings-win.data.microsoft.com
  • 51.104.136.2
  • 20.73.194.208
whitelisted
crl.microsoft.com
  • 23.48.23.143
  • 23.48.23.156
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
client.wns.windows.com
  • 172.211.123.248
whitelisted
login.live.com
  • 20.190.160.130
  • 20.190.160.67
  • 20.190.160.14
  • 20.190.160.64
  • 40.126.32.140
  • 20.190.160.4
  • 40.126.32.74
  • 20.190.160.131
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
slscr.update.microsoft.com
  • 4.245.163.56
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 20.242.39.171
whitelisted

Threats

No threats detected
No debug info