File name:

stc-isp-15xx-v6.86D.zip

Full analysis: https://app.any.run/tasks/ccaa1456-617a-4a89-a555-80c5b04baa19
Verdict: No threats detected
Analysis date: February 14, 2019, 10:01:14
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

B932AD98797FBC2F0DC5AB2A7FC91421

SHA1:

5A844B90F129711CA8274BA8A65E9509915788F0

SHA256:

2D8B124F8EFDE92049120C2AB2C447F8A401630DB9DCDFFD53F1BE02D9DE739E

SSDEEP:

98304:izz8lP0/aL5Luql14pEofbjSsluKV1bUF8zkX:R10/uu2OdfqsluCG

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • stc-isp-15xx-v6.86D.exe (PID: 3324)
      • stc-isp-15xx-v6.86D.exe (PID: 3836)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3080)
      • stc-isp-15xx-v6.86D.exe (PID: 3836)
    • Creates files in the driver directory

      • stc-isp-15xx-v6.86D.exe (PID: 3836)
    • Creates files in the Windows directory

      • stc-isp-15xx-v6.86D.exe (PID: 3836)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: 0x0009
ZipCompression: Deflated
ZipModifyDate: 2017:05:26 13:42:00
ZipCRC: 0xee21e269
ZipCompressedSize: 3714806
ZipUncompressedSize: 4171660
ZipFileName: stc-isp-15xx-v6.86D.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
35
Monitored processes
3
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
drop and start drop and start start winrar.exe stc-isp-15xx-v6.86d.exe no specs stc-isp-15xx-v6.86d.exe

Process information

PID
CMD
Path
Indicators
Parent process
3080"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\stc-isp-15xx-v6.86D.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3324"C:\Users\admin\AppData\Local\Temp\Rar$EXb3080.1623\stc-isp-15xx-v6.86D.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXb3080.1623\stc-isp-15xx-v6.86D.exeWinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Description:
STC-ISP
Exit code:
3221226540
Version:
0, 6, 0, 86
Modules
Images
c:\users\admin\appdata\local\temp\rar$exb3080.1623\stc-isp-15xx-v6.86d.exe
c:\systemroot\system32\ntdll.dll
3836"C:\Users\admin\AppData\Local\Temp\Rar$EXb3080.1623\stc-isp-15xx-v6.86D.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXb3080.1623\stc-isp-15xx-v6.86D.exe
WinRAR.exe
User:
admin
Integrity Level:
HIGH
Description:
STC-ISP
Exit code:
0
Version:
0, 6, 0, 86
Modules
Images
c:\users\admin\appdata\local\temp\rar$exb3080.1623\stc-isp-15xx-v6.86d.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mfc42.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
Total events
531
Read events
437
Write events
94
Delete events
0

Modification events

(PID) Process:(3080) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3080) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3080) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3080) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\stc-isp-15xx-v6.86D.zip
(PID) Process:(3080) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3080) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3080) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3080) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3080) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface
Operation:writeName:ShowPassword
Value:
0
(PID) Process:(3080) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
Executable files
10
Suspicious files
1
Text files
4
Unknown types
1

Dropped files

PID
Process
Filename
Type
3836stc-isp-15xx-v6.86D.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RB73MZ6Y\STC-ISP-UPDATE[1].TXTtext
MD5:
SHA256:
3080WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb3080.1623\stc-isp-15xx-v6.86D.exeexecutable
MD5:
SHA256:
3836stc-isp-15xx-v6.86D.exeC:\Windows\system32\ch341ser.catcat
MD5:1F7FE778164D85076E97B10363661CFB
SHA256:18FAB08BA0A79CC57B7A0CE8724CD17E0724B3E0A51BDBA364AE9C236D02DDDC
3836stc-isp-15xx-v6.86D.exeC:\Windows\inf\ch341ser.infini
MD5:30A42A07A9ECB6CC954ABD5DB59DBADE
SHA256:4E77459BC3457CD5E86CD8B0EB322A20A37FFF692B33581839445AF0094F1FBA
3836stc-isp-15xx-v6.86D.exeC:\Windows\system32\drivers\ch341s64.sysexecutable
MD5:C58EC27035731337ADD1326880086B16
SHA256:1A48A57D7FF5332AD380AF7884F516548DB535CFE23F3AE7D5AF291307CBC435
3836stc-isp-15xx-v6.86D.exeC:\Windows\inf\stcusb0.infini
MD5:
SHA256:
3836stc-isp-15xx-v6.86D.exeC:\Windows\system32\ch341ser.vxdexecutable
MD5:BE7438420F1DA854917F58CAD557476D
SHA256:2A946F316EDD7E1185DEEAFDC2DE52B2D2843198BE098A724233C12F9CCD0DAE
3836stc-isp-15xx-v6.86D.exeC:\Windows\system32\drivers\usbscan.sysexecutable
MD5:491B0A826A24E32B9B4424CA0CD3D5A8
SHA256:801FE8DD420BE927C3ED795C6B8B432B880D9A52A58EA7A190A6D364E6B492B5
3836stc-isp-15xx-v6.86D.exeC:\Windows\inf\serspl.infbinary
MD5:17DE8259180E3D155D0707C59C14DAB5
SHA256:F30933634C144A41DC3007146CF05E4B40F314114863A54240EC695F629B84A5
3836stc-isp-15xx-v6.86D.exeC:\Windows\system32\drivers\ch341s98.sysexecutable
MD5:B6F4A83911336E84BEAD8F8905285FAB
SHA256:0ECD1222627271EA31D3B64796992B6DAF5133D64CC26D43B3873CBE32FD59CB
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
1
DNS requests
1
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3836
stc-isp-15xx-v6.86D.exe
GET
200
119.28.59.51:80
http://www.STCMCU.com/STCISP/STC-ISP-UPDATE.TXT
CN
text
24.3 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3836
stc-isp-15xx-v6.86D.exe
119.28.59.51:80
www.stcmcu.com
Tencent Cloud Computing (Beijing) Co., Ltd
CN
unknown

DNS requests

Domain
IP
Reputation
www.stcmcu.com
  • 119.28.59.51
unknown

Threats

No threats detected
No debug info