| download: | qualcomm_driver.zip |
| Full analysis: | https://app.any.run/tasks/a8d8fc85-b3bb-46de-9a72-b7353dc90616 |
| Verdict: | Malicious activity |
| Analysis date: | January 15, 2020, 10:41:33 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v1.0 to extract |
| MD5: | 7CD57AD817C8AFA6741D711E59B12EA2 |
| SHA1: | 6BFB71FC99C1D11F15DADEAA4FEB88FFB3C93C41 |
| SHA256: | 31DB78D709B3BF3BBBADE97DF6A1D42B5730BBF8273962EB5A5B77EA4ECCA893 |
| SSDEEP: | 393216:txxIPZsUOoOzEyAeIQExrSnPc2SGdHLHbdrbObEK5bq5NOA7Kt36:p04oOkpVxrm/ldjbdrboeNL7p |
| .xpi | | | Mozilla Firefox browser extension (66.6) |
|---|---|---|
| .zip | | | ZIP compressed archive (33.3) |
| ZipRequiredVersion: | 10 |
|---|---|
| ZipBitFlag: | - |
| ZipCompression: | None |
| ZipModifyDate: | 2019:04:08 04:46:03 |
| ZipCRC: | 0x00000000 |
| ZipCompressedSize: | - |
| ZipUncompressedSize: | - |
| ZipFileName: | qualcomm_driver/ |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 320 | C:\Windows\system32\MsiExec.exe -Embedding 38C731D002FC4232DDC12403E0C2A700 M Global\MSI0000 | C:\Windows\system32\MsiExec.exe | msiexec.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 444 | "C:\Program Files\QUALCOMM Incorporated\Qualcomm USB Drivers For Windows\DriverPackage\Qualcomm\Tools\qcmtusvc.exe" | C:\Program Files\QUALCOMM Incorporated\Qualcomm USB Drivers For Windows\DriverPackage\Qualcomm\Tools\qcmtusvc.exe | services.exe | ||||||||||||
User: SYSTEM Company: QUALCOMM, Inc. Integrity Level: SYSTEM Description: qcmtusvc Exit code: 0 Version: 1,0,0,0 Modules
| |||||||||||||||
| 624 | DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{03cf992d-c083-5aa8-91ff-9d2b1396e17b}\qdbusb.inf" "0" "6813678db" "000005CC" "WinSta0\Default" "0000052C" "208" "C:\Program Files\QUALCOMM Incorporated\Qualcomm USB Drivers For Windows\DriverPackage\Qualcomm\fre\Windows7" | C:\Windows\system32\DrvInst.exe | svchost.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Driver Installation Module Exit code: 3758096963 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1104 | msiexec.exe /x {D9FB7F91-9687-4B09-894D-072903CADEA4} /passive | C:\Windows\system32\msiexec.exe | — | Qualcomm USB Driver V1.0.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1412 | rundll32.exe C:\Windows\system32\pnpui.dll,InstallSecurityPromptRunDllW 20 Global\{29661675-0def-18dd-8241-8b634955fd15} Global\{1132e7da-41c9-0881-9264-3500e12f2547} C:\Windows\System32\DriverStore\Temp\{57c1bcc0-4182-638b-7fed-3e7c92643500}\qcwwan.inf C:\Windows\System32\DriverStore\Temp\{57c1bcc0-4182-638b-7fed-3e7c92643500}\qcwwan.cat | C:\Windows\system32\rundll32.exe | — | DrvInst.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows host process (Rundll32) Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1516 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa3160.2207\qualcomm_driver\Qualcomm USB Driver V1.0.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa3160.2207\qualcomm_driver\Qualcomm USB Driver V1.0.exe | WinRAR.exe | ||||||||||||
User: admin Company: QUALCOMM, Inc. Integrity Level: HIGH Description: QUALCOMM Setup Exit code: 0 Version: 1.0.0.0 Modules
| |||||||||||||||
| 1728 | rundll32.exe C:\Windows\system32\pnpui.dll,InstallSecurityPromptRunDllW 20 Global\{5c43aa81-02a5-033e-dcf9-432e29d0a345} Global\{54273fc4-288b-2d94-a473-e53385678044} C:\Windows\System32\DriverStore\Temp\{3f386e45-51fa-2e04-06bf-6e6e14b4184c}\qcwwan.inf C:\Windows\System32\DriverStore\Temp\{3f386e45-51fa-2e04-06bf-6e6e14b4184c}\qcwwan.cat | C:\Windows\system32\rundll32.exe | — | DrvInst.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows host process (Rundll32) Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1800 | "C:\Program Files\QUALCOMM Incorporated\Qualcomm USB Drivers For Windows\DriverPackage\Qualcomm\Tools\qcmtusvc.exe" | C:\Program Files\QUALCOMM Incorporated\Qualcomm USB Drivers For Windows\DriverPackage\Qualcomm\Tools\qcmtusvc.exe | services.exe | ||||||||||||
User: SYSTEM Company: QUALCOMM, Inc. Integrity Level: SYSTEM Description: qcmtusvc Exit code: 0 Version: 1,0,0,0 Modules
| |||||||||||||||
| 1892 | rundll32.exe C:\Windows\system32\pnpui.dll,InstallSecurityPromptRunDllW 20 Global\{62372b64-e0ff-43e5-d2c8-5603e924113a} Global\{76f16bcd-aa67-7cb9-44bf-360a55b93065} C:\Windows\System32\DriverStore\Temp\{21c34fb4-7685-0e67-387c-d733064f1872}\qcmdm.inf C:\Windows\System32\DriverStore\Temp\{21c34fb4-7685-0e67-387c-d733064f1872}\qcser.cat | C:\Windows\system32\rundll32.exe | — | DrvInst.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows host process (Rundll32) Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1904 | C:\Windows\system32\vssvc.exe | C:\Windows\system32\vssvc.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft® Volume Shadow Copy Service Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (3160) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (3160) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (3160) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3160) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\qualcomm_driver.zip | |||
| (PID) Process: | (3160) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (3160) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (3160) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (3160) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (3160) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E |
| Operation: | write | Name: | @C:\Windows\System32\ieframe.dll,-10046 |
Value: Internet Shortcut | |||
| (PID) Process: | (3160) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2608 | Qualcomm USB Driver V1.0.exe | C:\Users\admin\AppData\Local\Temp\QualcommWindowsDriverInstaller.msi | — | |
MD5:— | SHA256:— | |||
| 2436 | msiexec.exe | C:\System Volume Information\SPP\metadata-2 | — | |
MD5:— | SHA256:— | |||
| 2436 | msiexec.exe | C:\Windows\Installer\3a5809.msi | — | |
MD5:— | SHA256:— | |||
| 2436 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\~DF601A617332C6354A.TMP | — | |
MD5:— | SHA256:— | |||
| 3600 | MsiExec.exe | C:\Users\admin\AppData\Local\Temp\{6670C3D3-6783-41D6-A34F-146F73031470}\IsConfig.ini | text | |
MD5:— | SHA256:— | |||
| 3600 | MsiExec.exe | C:\Users\admin\AppData\Local\Temp\{6670C3D3-6783-41D6-A34F-146F73031470}\String1033.txt | text | |
MD5:— | SHA256:— | |||
| 3160 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3160.43938\qualcomm_driver\How to Install.url | text | |
MD5:— | SHA256:— | |||
| 3160 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3160.43938\qualcomm_driver\Qualcomm USB Driver V1.0.exe | executable | |
MD5:076DA86444087703D095A60605635E8D | SHA256:79327E6CFE4A07590FBD0503456C21E3705E892A2A85655008D6E707738F62AF | |||
| 3600 | MsiExec.exe | C:\Users\admin\AppData\Local\Temp\{6670C3D3-6783-41D6-A34F-146F73031470}\_isres_0x0409.dll | executable | |
MD5:D6BBF7FF6984213C7F1F0F8F07C51E6A | SHA256:6366E18A8CBF609C9573F341004E5C2725C23A12973AFFA90EE7BCC7934AE1B2 | |||
| 3600 | MsiExec.exe | C:\Users\admin\AppData\Local\Temp\{6670C3D3-6783-41D6-A34F-146F73031470}\setup.inx | binary | |
MD5:90A44895149D99261AD24D09734A7CE1 | SHA256:B89B7478DB2C5DDBEACBAA41857984111D7C0F98E7DC4018A2A83EBA3F03034A | |||
Process | Message |
|---|---|
qcmtusvc.exe | Qualcomm MTU Service running in service mode.
|
qcmtusvc.exe | Startup event signaled: 0
|
qcmtusvc.exe | Start MTU device monitor thread
|
qcmtusvc.exe | Starting: Qualcomm MTU Service
|
qcmtusvc.exe | DevMon_THREAD_REG_CHANGE
|
qcmtusvc.exe | MTU instance running...
|
qcmtusvc.exe | DevMon_WAIT_TIMEOUT: scanning system...
|
qcmtusvc.exe | Scanned system, 0 total adapters
|
qcmtusvc.exe | DevMon_WAIT_TIMEOUT: scanning system...
|
qcmtusvc.exe | Scanned system, 0 total adapters
|