download: | qualcomm_driver.zip |
Full analysis: | https://app.any.run/tasks/a8d8fc85-b3bb-46de-9a72-b7353dc90616 |
Verdict: | Malicious activity |
Analysis date: | January 15, 2020, 10:41:33 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | application/zip |
File info: | Zip archive data, at least v1.0 to extract |
MD5: | 7CD57AD817C8AFA6741D711E59B12EA2 |
SHA1: | 6BFB71FC99C1D11F15DADEAA4FEB88FFB3C93C41 |
SHA256: | 31DB78D709B3BF3BBBADE97DF6A1D42B5730BBF8273962EB5A5B77EA4ECCA893 |
SSDEEP: | 393216:txxIPZsUOoOzEyAeIQExrSnPc2SGdHLHbdrbObEK5bq5NOA7Kt36:p04oOkpVxrm/ldjbdrboeNL7p |
.xpi | | | Mozilla Firefox browser extension (66.6) |
---|---|---|
.zip | | | ZIP compressed archive (33.3) |
ZipRequiredVersion: | 10 |
---|---|
ZipBitFlag: | - |
ZipCompression: | None |
ZipModifyDate: | 2019:04:08 04:46:03 |
ZipCRC: | 0x00000000 |
ZipCompressedSize: | - |
ZipUncompressedSize: | - |
ZipFileName: | qualcomm_driver/ |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
320 | C:\Windows\system32\MsiExec.exe -Embedding 38C731D002FC4232DDC12403E0C2A700 M Global\MSI0000 | C:\Windows\system32\MsiExec.exe | msiexec.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
444 | "C:\Program Files\QUALCOMM Incorporated\Qualcomm USB Drivers For Windows\DriverPackage\Qualcomm\Tools\qcmtusvc.exe" | C:\Program Files\QUALCOMM Incorporated\Qualcomm USB Drivers For Windows\DriverPackage\Qualcomm\Tools\qcmtusvc.exe | services.exe | ||||||||||||
User: SYSTEM Company: QUALCOMM, Inc. Integrity Level: SYSTEM Description: qcmtusvc Exit code: 0 Version: 1,0,0,0 Modules
| |||||||||||||||
624 | DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{03cf992d-c083-5aa8-91ff-9d2b1396e17b}\qdbusb.inf" "0" "6813678db" "000005CC" "WinSta0\Default" "0000052C" "208" "C:\Program Files\QUALCOMM Incorporated\Qualcomm USB Drivers For Windows\DriverPackage\Qualcomm\fre\Windows7" | C:\Windows\system32\DrvInst.exe | svchost.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Driver Installation Module Exit code: 3758096963 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
1104 | msiexec.exe /x {D9FB7F91-9687-4B09-894D-072903CADEA4} /passive | C:\Windows\system32\msiexec.exe | — | Qualcomm USB Driver V1.0.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
1412 | rundll32.exe C:\Windows\system32\pnpui.dll,InstallSecurityPromptRunDllW 20 Global\{29661675-0def-18dd-8241-8b634955fd15} Global\{1132e7da-41c9-0881-9264-3500e12f2547} C:\Windows\System32\DriverStore\Temp\{57c1bcc0-4182-638b-7fed-3e7c92643500}\qcwwan.inf C:\Windows\System32\DriverStore\Temp\{57c1bcc0-4182-638b-7fed-3e7c92643500}\qcwwan.cat | C:\Windows\system32\rundll32.exe | — | DrvInst.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows host process (Rundll32) Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
1516 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa3160.2207\qualcomm_driver\Qualcomm USB Driver V1.0.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa3160.2207\qualcomm_driver\Qualcomm USB Driver V1.0.exe | WinRAR.exe | ||||||||||||
User: admin Company: QUALCOMM, Inc. Integrity Level: HIGH Description: QUALCOMM Setup Exit code: 0 Version: 1.0.0.0 Modules
| |||||||||||||||
1728 | rundll32.exe C:\Windows\system32\pnpui.dll,InstallSecurityPromptRunDllW 20 Global\{5c43aa81-02a5-033e-dcf9-432e29d0a345} Global\{54273fc4-288b-2d94-a473-e53385678044} C:\Windows\System32\DriverStore\Temp\{3f386e45-51fa-2e04-06bf-6e6e14b4184c}\qcwwan.inf C:\Windows\System32\DriverStore\Temp\{3f386e45-51fa-2e04-06bf-6e6e14b4184c}\qcwwan.cat | C:\Windows\system32\rundll32.exe | — | DrvInst.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows host process (Rundll32) Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
1800 | "C:\Program Files\QUALCOMM Incorporated\Qualcomm USB Drivers For Windows\DriverPackage\Qualcomm\Tools\qcmtusvc.exe" | C:\Program Files\QUALCOMM Incorporated\Qualcomm USB Drivers For Windows\DriverPackage\Qualcomm\Tools\qcmtusvc.exe | services.exe | ||||||||||||
User: SYSTEM Company: QUALCOMM, Inc. Integrity Level: SYSTEM Description: qcmtusvc Exit code: 0 Version: 1,0,0,0 Modules
| |||||||||||||||
1892 | rundll32.exe C:\Windows\system32\pnpui.dll,InstallSecurityPromptRunDllW 20 Global\{62372b64-e0ff-43e5-d2c8-5603e924113a} Global\{76f16bcd-aa67-7cb9-44bf-360a55b93065} C:\Windows\System32\DriverStore\Temp\{21c34fb4-7685-0e67-387c-d733064f1872}\qcmdm.inf C:\Windows\System32\DriverStore\Temp\{21c34fb4-7685-0e67-387c-d733064f1872}\qcser.cat | C:\Windows\system32\rundll32.exe | — | DrvInst.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows host process (Rundll32) Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
1904 | C:\Windows\system32\vssvc.exe | C:\Windows\system32\vssvc.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft® Volume Shadow Copy Service Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
|
(PID) Process: | (3160) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
Operation: | write | Name: | ShellExtBMP |
Value: | |||
(PID) Process: | (3160) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
Operation: | write | Name: | ShellExtIcon |
Value: | |||
(PID) Process: | (3160) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E |
Operation: | write | Name: | LanguageList |
Value: en-US | |||
(PID) Process: | (3160) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\qualcomm_driver.zip | |||
(PID) Process: | (3160) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | name |
Value: 120 | |||
(PID) Process: | (3160) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | size |
Value: 80 | |||
(PID) Process: | (3160) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | type |
Value: 120 | |||
(PID) Process: | (3160) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | mtime |
Value: 100 | |||
(PID) Process: | (3160) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E |
Operation: | write | Name: | @C:\Windows\System32\ieframe.dll,-10046 |
Value: Internet Shortcut | |||
(PID) Process: | (3160) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | UNCAsIntranet |
Value: 0 |
PID | Process | Filename | Type | |
---|---|---|---|---|
2608 | Qualcomm USB Driver V1.0.exe | C:\Users\admin\AppData\Local\Temp\QualcommWindowsDriverInstaller.msi | — | |
MD5:— | SHA256:— | |||
2436 | msiexec.exe | C:\System Volume Information\SPP\metadata-2 | — | |
MD5:— | SHA256:— | |||
2436 | msiexec.exe | C:\Windows\Installer\3a5809.msi | — | |
MD5:— | SHA256:— | |||
2436 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\~DF601A617332C6354A.TMP | — | |
MD5:— | SHA256:— | |||
3160 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3160.43938\qualcomm_driver\How to Install.url | text | |
MD5:— | SHA256:— | |||
3600 | MsiExec.exe | C:\Users\admin\AppData\Local\Temp\{6670C3D3-6783-41D6-A34F-146F73031470}\String1033.txt | text | |
MD5:— | SHA256:— | |||
2436 | msiexec.exe | C:\System Volume Information\SPP\OnlineMetadataCache\{1b87ece3-1caa-477f-ba62-46184424aef3}_OnDiskSnapshotProp | binary | |
MD5:— | SHA256:— | |||
2436 | msiexec.exe | C:\System Volume Information\SPP\snapshot-2 | binary | |
MD5:— | SHA256:— | |||
2896 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\MSIFAD5.tmp | executable | |
MD5:— | SHA256:— | |||
2436 | msiexec.exe | C:\Program Files\QUALCOMM Incorporated\Qualcomm USB Drivers For Windows\DriverPackage\Qualcomm\Fre\Windows7\filter\i386\qcusbfilter.pdb | pdb | |
MD5:— | SHA256:— |
Process | Message |
---|---|
qcmtusvc.exe | Qualcomm MTU Service running in service mode.
|
qcmtusvc.exe | Startup event signaled: 0
|
qcmtusvc.exe | Start MTU device monitor thread
|
qcmtusvc.exe | Starting: Qualcomm MTU Service
|
qcmtusvc.exe | DevMon_THREAD_REG_CHANGE
|
qcmtusvc.exe | MTU instance running...
|
qcmtusvc.exe | DevMon_WAIT_TIMEOUT: scanning system...
|
qcmtusvc.exe | Scanned system, 0 total adapters
|
qcmtusvc.exe | DevMon_WAIT_TIMEOUT: scanning system...
|
qcmtusvc.exe | Scanned system, 0 total adapters
|