File name:

POS_58_Driver-11.3.0.0.zip

Full analysis: https://app.any.run/tasks/1f8a5fcf-de18-4bde-b335-8e8835a247b2
Verdict: Malicious activity
Analysis date: November 30, 2024, 11:23:13
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
arch-exec
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=deflate
MD5:

D406E61CE6C15C4558337C60085B031C

SHA1:

2226435AB30DB569DFE1E0C520F8A697D84AC535

SHA256:

3311D75B494565766A477F5DDE3DCA9426939956EE576C4E843E37821B958D8B

SSDEEP:

98304:ir1j/LxIxb77UGvXKpAO8KX+AkZP1Gs1xv7gyPjskVpmRWbnyvjtzRwaigSbnhKJ:wWhDj4

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Generic archive extractor

      • WinRAR.exe (PID: 6232)
    • Executing a file with an untrusted certificate

      • PrinterTestDemo.exe (PID: 4640)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • POS_58_Driver-11.3.0.0.exe (PID: 6864)
      • POS_58_Driver-11.3.0.0.exe (PID: 6964)
      • POS_58_Driver-11.3.0.0.tmp (PID: 6984)
    • Reads security settings of Internet Explorer

      • POS_58_Driver-11.3.0.0.tmp (PID: 6884)
      • POS_58_Driver-11.3.0.0.tmp (PID: 6984)
    • Reads the Windows owner or organization settings

      • POS_58_Driver-11.3.0.0.tmp (PID: 6984)
    • Process drops legitimate windows executable

      • POS_58_Driver-11.3.0.0.tmp (PID: 6984)
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 6232)
    • The process uses the downloaded file

      • WinRAR.exe (PID: 6232)
      • POS_58_Driver-11.3.0.0.tmp (PID: 6984)
    • Checks supported languages

      • POS_58_Driver-11.3.0.0.tmp (PID: 6884)
      • POS_58_Driver-11.3.0.0.exe (PID: 6864)
      • POS_58_Driver-11.3.0.0.exe (PID: 6964)
      • POS_58_Driver-11.3.0.0.tmp (PID: 6984)
      • PrinterTestDemo.exe (PID: 4640)
    • Manual execution by a user

      • POS_58_Driver-11.3.0.0.exe (PID: 6864)
    • Create files in a temporary directory

      • POS_58_Driver-11.3.0.0.exe (PID: 6864)
      • POS_58_Driver-11.3.0.0.exe (PID: 6964)
      • POS_58_Driver-11.3.0.0.tmp (PID: 6984)
    • Process checks computer location settings

      • POS_58_Driver-11.3.0.0.tmp (PID: 6884)
      • POS_58_Driver-11.3.0.0.tmp (PID: 6984)
    • Reads the computer name

      • POS_58_Driver-11.3.0.0.tmp (PID: 6884)
      • POS_58_Driver-11.3.0.0.tmp (PID: 6984)
      • PrinterTestDemo.exe (PID: 4640)
    • Creates a software uninstall entry

      • POS_58_Driver-11.3.0.0.tmp (PID: 6984)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2018:04:26 17:44:46
ZipCRC: 0x2f004fbc
ZipCompressedSize: 2833479
ZipUncompressedSize: 2907120
ZipFileName: POS_58_Driver-11.3.0.0.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
136
Monitored processes
6
Malicious processes
2
Suspicious processes
3

Behavior graph

Click at the process to see the details
start winrar.exe pos_58_driver-11.3.0.0.exe pos_58_driver-11.3.0.0.tmp no specs pos_58_driver-11.3.0.0.exe pos_58_driver-11.3.0.0.tmp printertestdemo.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
4640"C:\POS Printer Driver V11.3.0.0\PrinterTestDemo.exe" eng ZJNEWPOS58 ZJNEWPOS58C:\POS Printer Driver V11.3.0.0\PrinterTestDemo.exePOS_58_Driver-11.3.0.0.tmp
User:
admin
Integrity Level:
HIGH
Description:
PrinterTestDemo Microsoft 基础类应用程序
Exit code:
0
Version:
1, 0, 0, 1
Modules
Images
c:\pos printer driver v11.3.0.0\printertestdemo.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\setupapi.dll
6232"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\POS_58_Driver-11.3.0.0.zipC:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
6864"C:\Users\admin\Desktop\POS_58_Driver-11.3.0.0.exe" C:\Users\admin\Desktop\POS_58_Driver-11.3.0.0.exe
explorer.exe
User:
admin
Company:
Integrity Level:
MEDIUM
Description:
Exit code:
0
Version:
1.3.0.0
Modules
Images
c:\users\admin\desktop\pos_58_driver-11.3.0.0.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\oleaut32.dll
6884"C:\Users\admin\AppData\Local\Temp\is-O7HOC.tmp\POS_58_Driver-11.3.0.0.tmp" /SL5="$802A8,2263740,121344,C:\Users\admin\Desktop\POS_58_Driver-11.3.0.0.exe" C:\Users\admin\AppData\Local\Temp\is-O7HOC.tmp\POS_58_Driver-11.3.0.0.tmpPOS_58_Driver-11.3.0.0.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-o7hoc.tmp\pos_58_driver-11.3.0.0.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\oleaut32.dll
6964"C:\Users\admin\Desktop\POS_58_Driver-11.3.0.0.exe" /SPAWNWND=$901FE /NOTIFYWND=$802A8 C:\Users\admin\Desktop\POS_58_Driver-11.3.0.0.exe
POS_58_Driver-11.3.0.0.tmp
User:
admin
Company:
Integrity Level:
HIGH
Description:
Exit code:
0
Version:
1.3.0.0
Modules
Images
c:\users\admin\desktop\pos_58_driver-11.3.0.0.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\oleaut32.dll
6984"C:\Users\admin\AppData\Local\Temp\is-52I0B.tmp\POS_58_Driver-11.3.0.0.tmp" /SL5="$802C8,2263740,121344,C:\Users\admin\Desktop\POS_58_Driver-11.3.0.0.exe" /SPAWNWND=$901FE /NOTIFYWND=$802A8 C:\Users\admin\AppData\Local\Temp\is-52I0B.tmp\POS_58_Driver-11.3.0.0.tmp
POS_58_Driver-11.3.0.0.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-52i0b.tmp\pos_58_driver-11.3.0.0.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\oleaut32.dll
Total events
2 177
Read events
2 151
Write events
26
Delete events
0

Modification events

(PID) Process:(6232) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(6232) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(6232) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(6232) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\POS_58_Driver-11.3.0.0.zip
(PID) Process:(6232) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(6232) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(6232) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(6232) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(6984) POS_58_Driver-11.3.0.0.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{5B643BF5-11A2-4A75-86D4-8F522DE92AA2}_is1
Operation:writeName:Inno Setup: Setup Version
Value:
5.5.9 (u)
(PID) Process:(6984) POS_58_Driver-11.3.0.0.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{5B643BF5-11A2-4A75-86D4-8F522DE92AA2}_is1
Operation:writeName:Inno Setup: App Path
Value:
C:\POS Printer Driver V11.3.0.0
Executable files
122
Suspicious files
16
Text files
34
Unknown types
1

Dropped files

PID
Process
Filename
Type
6984POS_58_Driver-11.3.0.0.tmpC:\Users\admin\AppData\Local\Temp\is-UAMD3.tmp\_isetup\_setup64.tmpexecutable
MD5:E4211D6D009757C078A9FAC7FF4F03D4
SHA256:388A796580234EFC95F3B1C70AD4CB44BFDDC7BA0F9203BF4902B9929B136F95
6964POS_58_Driver-11.3.0.0.exeC:\Users\admin\AppData\Local\Temp\is-52I0B.tmp\POS_58_Driver-11.3.0.0.tmpexecutable
MD5:90FC739C83CD19766ACB562C66A7D0E2
SHA256:821BD11693BF4B4B2B9F3C196036E1F4902ABD95FB26873EA6C43E123B8C9431
6864POS_58_Driver-11.3.0.0.exeC:\Users\admin\AppData\Local\Temp\is-O7HOC.tmp\POS_58_Driver-11.3.0.0.tmpexecutable
MD5:90FC739C83CD19766ACB562C66A7D0E2
SHA256:821BD11693BF4B4B2B9F3C196036E1F4902ABD95FB26873EA6C43E123B8C9431
6232WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6232.11566\POS_58_Driver-11.3.0.0.exeexecutable
MD5:08B5C46CD969A695832984FD9D41E637
SHA256:6DFF1188BAEE908AA54242629A2669BAEBA2F6172E7D3F32AC2D9348B7AFF916
6984POS_58_Driver-11.3.0.0.tmpC:\POS Printer Driver V11.3.0.0\is-4VM7S.tmpexecutable
MD5:B30BB62407CF78CF3F1B79BC5610F25F
SHA256:5246030F8AA7A502E6C53DD7D54F10F4361DC0B6A6FFA7D5140B2860FEF08D65
6984POS_58_Driver-11.3.0.0.tmpC:\POS Printer Driver V11.3.0.0\rc_eng.dllexecutable
MD5:E2316C572724D26EC75F7B99CFA75BAC
SHA256:34F1418B511B183541C6AAAC2DBC84A6968FA345E20E470850740F1F3A5590F8
6984POS_58_Driver-11.3.0.0.tmpC:\POS Printer Driver V11.3.0.0\unins000.exeexecutable
MD5:70357CFD8962A845759D2896C488EA7B
SHA256:2DA0477291BBE152E4DFCAA59A77D2224595494120CADC9531BC640AD30752FE
6984POS_58_Driver-11.3.0.0.tmpC:\POS Printer Driver V11.3.0.0\PrinterTestDemo.exeexecutable
MD5:66F175F3EC56884B7B17E422E7A94FF2
SHA256:EEC7D55D05B4CC089015F00916D5D572FDDCD6AD97580B936F15F31778825EAA
6984POS_58_Driver-11.3.0.0.tmpC:\POS Printer Driver V11.3.0.0\is-OITSF.tmpexecutable
MD5:70357CFD8962A845759D2896C488EA7B
SHA256:2DA0477291BBE152E4DFCAA59A77D2224595494120CADC9531BC640AD30752FE
6984POS_58_Driver-11.3.0.0.tmpC:\POS Printer Driver V11.3.0.0\is-PCUTG.tmpexecutable
MD5:66F175F3EC56884B7B17E422E7A94FF2
SHA256:EEC7D55D05B4CC089015F00916D5D572FDDCD6AD97580B936F15F31778825EAA
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
32
DNS requests
18
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
2.16.164.9:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
1176
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
1200
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
5872
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
5872
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
2160
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4712
MoUsoCoreWorker.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2.16.164.9:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
88.221.169.152:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
5064
SearchApp.exe
2.23.209.179:443
www.bing.com
Akamai International B.V.
GB
whitelisted
4
System
192.168.100.255:138
whitelisted
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
1176
svchost.exe
40.126.31.71:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
  • 20.73.194.208
  • 51.124.78.146
whitelisted
crl.microsoft.com
  • 2.16.164.9
  • 2.16.164.106
  • 2.16.164.49
  • 2.16.164.43
whitelisted
google.com
  • 142.250.185.174
whitelisted
www.microsoft.com
  • 88.221.169.152
  • 184.30.21.171
whitelisted
www.bing.com
  • 2.23.209.179
  • 2.23.209.182
  • 2.23.209.189
  • 2.23.209.177
  • 2.23.209.140
  • 2.23.209.149
  • 2.23.209.133
  • 2.23.209.187
  • 2.23.209.130
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
login.live.com
  • 40.126.31.71
  • 40.126.31.69
  • 40.126.31.73
  • 40.126.31.67
  • 20.190.159.0
  • 20.190.159.71
  • 20.190.159.75
  • 20.190.159.68
whitelisted
go.microsoft.com
  • 23.32.186.57
whitelisted
arc.msn.com
  • 20.199.58.43
whitelisted
fd.api.iris.microsoft.com
  • 20.74.47.205
whitelisted

Threats

No threats detected
No debug info