File name:

stc-isp-15xx-v6.86D.zip

Full analysis: https://app.any.run/tasks/ccaa1456-617a-4a89-a555-80c5b04baa19
Verdict: No threats detected
Analysis date: February 14, 2019, 10:01:14
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

B932AD98797FBC2F0DC5AB2A7FC91421

SHA1:

5A844B90F129711CA8274BA8A65E9509915788F0

SHA256:

2D8B124F8EFDE92049120C2AB2C447F8A401630DB9DCDFFD53F1BE02D9DE739E

SSDEEP:

98304:izz8lP0/aL5Luql14pEofbjSsluKV1bUF8zkX:R10/uu2OdfqsluCG

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • stc-isp-15xx-v6.86D.exe (PID: 3836)
      • stc-isp-15xx-v6.86D.exe (PID: 3324)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3080)
      • stc-isp-15xx-v6.86D.exe (PID: 3836)
    • Creates files in the Windows directory

      • stc-isp-15xx-v6.86D.exe (PID: 3836)
    • Creates files in the driver directory

      • stc-isp-15xx-v6.86D.exe (PID: 3836)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipFileName: stc-isp-15xx-v6.86D.exe
ZipUncompressedSize: 4171660
ZipCompressedSize: 3714806
ZipCRC: 0xee21e269
ZipModifyDate: 2017:05:26 13:42:00
ZipCompression: Deflated
ZipBitFlag: 0x0009
ZipRequiredVersion: 20
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
35
Monitored processes
3
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
drop and start drop and start start winrar.exe stc-isp-15xx-v6.86d.exe no specs stc-isp-15xx-v6.86d.exe

Process information

PID
CMD
Path
Indicators
Parent process
3080"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\stc-isp-15xx-v6.86D.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3324"C:\Users\admin\AppData\Local\Temp\Rar$EXb3080.1623\stc-isp-15xx-v6.86D.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXb3080.1623\stc-isp-15xx-v6.86D.exeWinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Description:
STC-ISP
Exit code:
3221226540
Version:
0, 6, 0, 86
Modules
Images
c:\users\admin\appdata\local\temp\rar$exb3080.1623\stc-isp-15xx-v6.86d.exe
c:\systemroot\system32\ntdll.dll
3836"C:\Users\admin\AppData\Local\Temp\Rar$EXb3080.1623\stc-isp-15xx-v6.86D.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXb3080.1623\stc-isp-15xx-v6.86D.exe
WinRAR.exe
User:
admin
Integrity Level:
HIGH
Description:
STC-ISP
Version:
0, 6, 0, 86
Modules
Images
c:\users\admin\appdata\local\temp\rar$exb3080.1623\stc-isp-15xx-v6.86d.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mfc42.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
Total events
531
Read events
437
Write events
94
Delete events
0

Modification events

(PID) Process:(3080) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3080) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3080) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3080) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\stc-isp-15xx-v6.86D.zip
(PID) Process:(3080) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3080) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3080) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3080) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3080) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface
Operation:writeName:ShowPassword
Value:
0
(PID) Process:(3080) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
Executable files
10
Suspicious files
1
Text files
4
Unknown types
1

Dropped files

PID
Process
Filename
Type
3080WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb3080.1623\stc-isp-15xx-v6.86D.exeexecutable
MD5:6CAD67C147650683F9EE9905E7CDAE74
SHA256:9A9FD42DC876076D0ED9740F58307199565D70E9C7D04200D708A3430635DBC8
3836stc-isp-15xx-v6.86D.exeC:\Windows\inf\stcusb0.infini
MD5:F4CFC601F9D1E18FD73ACE1CF92ADCFE
SHA256:D041500623E89FFE443E9398FED80E035DE794542D4E203671E175FA288ED58F
3836stc-isp-15xx-v6.86D.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RB73MZ6Y\STC-ISP-UPDATE[1].TXTtext
MD5:A8ED582FAA6B1AC6924089E66E7CE658
SHA256:E3A6F3DBA03D69A83940E055F3B08B351A237ABA06174D7ADA921BA6EA98ACE3
3836stc-isp-15xx-v6.86D.exeC:\Windows\system32\drivers\ch341s64.sysexecutable
MD5:C58EC27035731337ADD1326880086B16
SHA256:1A48A57D7FF5332AD380AF7884F516548DB535CFE23F3AE7D5AF291307CBC435
3836stc-isp-15xx-v6.86D.exeC:\Windows\system32\ser9pl.sysexecutable
MD5:F3463F0C4A48809F0D0A9A4C348FF34E
SHA256:057D508E4C765B6D30B126CAD8AD8EB0E8E088D5AB7CF490A255FCBC147C4819
3836stc-isp-15xx-v6.86D.exeC:\Windows\inf\serwpl.inftext
MD5:450FEF25BA546A5469165C39A37BCDB5
SHA256:5119D16ECFB80527A7EAE8BA7155DA5854744A642A52E983C2CE4844B6B9F3EC
3836stc-isp-15xx-v6.86D.exeC:\Windows\system32\drivers\ch341s98.sysexecutable
MD5:B6F4A83911336E84BEAD8F8905285FAB
SHA256:0ECD1222627271EA31D3B64796992B6DAF5133D64CC26D43B3873CBE32FD59CB
3836stc-isp-15xx-v6.86D.exeC:\Windows\system32\drivers\ch341ser.sysexecutable
MD5:4798C1AD22BAF6FF25451E2194E034D1
SHA256:1E2DD8EB6CC1095F8113448724354567AA8CEAC269391CC72B7ADCBF657CD53A
3836stc-isp-15xx-v6.86D.exeC:\Windows\system32\ser2pl.sysexecutable
MD5:E42F03D1081C4F60D3DB6C38235B1456
SHA256:6BD7329980E72E1D341AEA5B090BCD53CAF465B2FD4DE7C511E63922D7EB29F0
3836stc-isp-15xx-v6.86D.exeC:\Windows\inf\serspl.infbinary
MD5:17DE8259180E3D155D0707C59C14DAB5
SHA256:F30933634C144A41DC3007146CF05E4B40F314114863A54240EC695F629B84A5
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
1
DNS requests
1
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3836
stc-isp-15xx-v6.86D.exe
GET
200
119.28.59.51:80
http://www.STCMCU.com/STCISP/STC-ISP-UPDATE.TXT
CN
text
24.3 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3836
stc-isp-15xx-v6.86D.exe
119.28.59.51:80
www.stcmcu.com
Tencent Cloud Computing (Beijing) Co., Ltd
CN
unknown

DNS requests

Domain
IP
Reputation
www.stcmcu.com
  • 119.28.59.51
unknown

Threats

No threats detected
No debug info