File name:

stc-isp-15xx-v6.86D.zip

Full analysis: https://app.any.run/tasks/ccaa1456-617a-4a89-a555-80c5b04baa19
Verdict: No threats detected
Analysis date: February 14, 2019, 10:01:14
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

B932AD98797FBC2F0DC5AB2A7FC91421

SHA1:

5A844B90F129711CA8274BA8A65E9509915788F0

SHA256:

2D8B124F8EFDE92049120C2AB2C447F8A401630DB9DCDFFD53F1BE02D9DE739E

SSDEEP:

98304:izz8lP0/aL5Luql14pEofbjSsluKV1bUF8zkX:R10/uu2OdfqsluCG

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • stc-isp-15xx-v6.86D.exe (PID: 3324)
      • stc-isp-15xx-v6.86D.exe (PID: 3836)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3080)
      • stc-isp-15xx-v6.86D.exe (PID: 3836)
    • Creates files in the Windows directory

      • stc-isp-15xx-v6.86D.exe (PID: 3836)
    • Creates files in the driver directory

      • stc-isp-15xx-v6.86D.exe (PID: 3836)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: 0x0009
ZipCompression: Deflated
ZipModifyDate: 2017:05:26 13:42:00
ZipCRC: 0xee21e269
ZipCompressedSize: 3714806
ZipUncompressedSize: 4171660
ZipFileName: stc-isp-15xx-v6.86D.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
35
Monitored processes
3
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
drop and start drop and start start winrar.exe stc-isp-15xx-v6.86d.exe no specs stc-isp-15xx-v6.86d.exe

Process information

PID
CMD
Path
Indicators
Parent process
3080"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\stc-isp-15xx-v6.86D.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3324"C:\Users\admin\AppData\Local\Temp\Rar$EXb3080.1623\stc-isp-15xx-v6.86D.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXb3080.1623\stc-isp-15xx-v6.86D.exeWinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Description:
STC-ISP
Exit code:
3221226540
Version:
0, 6, 0, 86
Modules
Images
c:\users\admin\appdata\local\temp\rar$exb3080.1623\stc-isp-15xx-v6.86d.exe
c:\systemroot\system32\ntdll.dll
3836"C:\Users\admin\AppData\Local\Temp\Rar$EXb3080.1623\stc-isp-15xx-v6.86D.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXb3080.1623\stc-isp-15xx-v6.86D.exe
WinRAR.exe
User:
admin
Integrity Level:
HIGH
Description:
STC-ISP
Exit code:
0
Version:
0, 6, 0, 86
Modules
Images
c:\users\admin\appdata\local\temp\rar$exb3080.1623\stc-isp-15xx-v6.86d.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mfc42.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
Total events
531
Read events
437
Write events
94
Delete events
0

Modification events

(PID) Process:(3080) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3080) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3080) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3080) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\stc-isp-15xx-v6.86D.zip
(PID) Process:(3080) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3080) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3080) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3080) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3080) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface
Operation:writeName:ShowPassword
Value:
0
(PID) Process:(3080) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
Executable files
10
Suspicious files
1
Text files
4
Unknown types
1

Dropped files

PID
Process
Filename
Type
3836stc-isp-15xx-v6.86D.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RB73MZ6Y\STC-ISP-UPDATE[1].TXTtext
MD5:A8ED582FAA6B1AC6924089E66E7CE658
SHA256:E3A6F3DBA03D69A83940E055F3B08B351A237ABA06174D7ADA921BA6EA98ACE3
3836stc-isp-15xx-v6.86D.exeC:\Windows\inf\stcusb0.infini
MD5:F4CFC601F9D1E18FD73ACE1CF92ADCFE
SHA256:D041500623E89FFE443E9398FED80E035DE794542D4E203671E175FA288ED58F
3080WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb3080.1623\stc-isp-15xx-v6.86D.exeexecutable
MD5:6CAD67C147650683F9EE9905E7CDAE74
SHA256:9A9FD42DC876076D0ED9740F58307199565D70E9C7D04200D708A3430635DBC8
3836stc-isp-15xx-v6.86D.exeC:\Windows\inf\ch341ser.infini
MD5:30A42A07A9ECB6CC954ABD5DB59DBADE
SHA256:4E77459BC3457CD5E86CD8B0EB322A20A37FFF692B33581839445AF0094F1FBA
3836stc-isp-15xx-v6.86D.exeC:\Windows\system32\drivers\ch341s98.sysexecutable
MD5:B6F4A83911336E84BEAD8F8905285FAB
SHA256:0ECD1222627271EA31D3B64796992B6DAF5133D64CC26D43B3873CBE32FD59CB
3836stc-isp-15xx-v6.86D.exeC:\Windows\system32\ch341ser.vxdexecutable
MD5:BE7438420F1DA854917F58CAD557476D
SHA256:2A946F316EDD7E1185DEEAFDC2DE52B2D2843198BE098A724233C12F9CCD0DAE
3836stc-isp-15xx-v6.86D.exeC:\Windows\system32\ch341pt.dllexecutable
MD5:69B6FEC924C30042D329AE56CA8925CC
SHA256:45494CE819C1B5C21ABB72DC47A0CA36807E0ED74CE55B631DA174C77A9B24DB
3836stc-isp-15xx-v6.86D.exeC:\Windows\system32\ser9pl.sysexecutable
MD5:F3463F0C4A48809F0D0A9A4C348FF34E
SHA256:057D508E4C765B6D30B126CAD8AD8EB0E8E088D5AB7CF490A255FCBC147C4819
3836stc-isp-15xx-v6.86D.exeC:\Windows\system32\drivers\ch341s64.sysexecutable
MD5:C58EC27035731337ADD1326880086B16
SHA256:1A48A57D7FF5332AD380AF7884F516548DB535CFE23F3AE7D5AF291307CBC435
3836stc-isp-15xx-v6.86D.exeC:\Windows\system32\ch341ser.catcat
MD5:1F7FE778164D85076E97B10363661CFB
SHA256:18FAB08BA0A79CC57B7A0CE8724CD17E0724B3E0A51BDBA364AE9C236D02DDDC
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
1
DNS requests
1
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3836
stc-isp-15xx-v6.86D.exe
GET
200
119.28.59.51:80
http://www.STCMCU.com/STCISP/STC-ISP-UPDATE.TXT
CN
text
24.3 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3836
stc-isp-15xx-v6.86D.exe
119.28.59.51:80
www.stcmcu.com
Tencent Cloud Computing (Beijing) Co., Ltd
CN
unknown

DNS requests

Domain
IP
Reputation
www.stcmcu.com
  • 119.28.59.51
unknown

Threats

No threats detected
No debug info