| File name: | POS_58_Driver-11.3.0.0.zip |
| Full analysis: | https://app.any.run/tasks/1f8a5fcf-de18-4bde-b335-8e8835a247b2 |
| Verdict: | Malicious activity |
| Analysis date: | November 30, 2024, 11:23:13 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract, compression method=deflate |
| MD5: | D406E61CE6C15C4558337C60085B031C |
| SHA1: | 2226435AB30DB569DFE1E0C520F8A697D84AC535 |
| SHA256: | 3311D75B494565766A477F5DDE3DCA9426939956EE576C4E843E37821B958D8B |
| SSDEEP: | 98304:ir1j/LxIxb77UGvXKpAO8KX+AkZP1Gs1xv7gyPjskVpmRWbnyvjtzRwaigSbnhKJ:wWhDj4 |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 20 |
|---|---|
| ZipBitFlag: | - |
| ZipCompression: | Deflated |
| ZipModifyDate: | 2018:04:26 17:44:46 |
| ZipCRC: | 0x2f004fbc |
| ZipCompressedSize: | 2833479 |
| ZipUncompressedSize: | 2907120 |
| ZipFileName: | POS_58_Driver-11.3.0.0.exe |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 4640 | "C:\POS Printer Driver V11.3.0.0\PrinterTestDemo.exe" eng ZJNEWPOS58 ZJNEWPOS58 | C:\POS Printer Driver V11.3.0.0\PrinterTestDemo.exe | — | POS_58_Driver-11.3.0.0.tmp | |||||||||||
User: admin Integrity Level: HIGH Description: PrinterTestDemo Microsoft 基础类应用程序 Exit code: 0 Version: 1, 0, 0, 1 Modules
| |||||||||||||||
| 6232 | "C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\POS_58_Driver-11.3.0.0.zip | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Version: 5.91.0 Modules
| |||||||||||||||
| 6864 | "C:\Users\admin\Desktop\POS_58_Driver-11.3.0.0.exe" | C:\Users\admin\Desktop\POS_58_Driver-11.3.0.0.exe | explorer.exe | ||||||||||||
User: admin Company: Integrity Level: MEDIUM Description: Exit code: 0 Version: 1.3.0.0 Modules
| |||||||||||||||
| 6884 | "C:\Users\admin\AppData\Local\Temp\is-O7HOC.tmp\POS_58_Driver-11.3.0.0.tmp" /SL5="$802A8,2263740,121344,C:\Users\admin\Desktop\POS_58_Driver-11.3.0.0.exe" | C:\Users\admin\AppData\Local\Temp\is-O7HOC.tmp\POS_58_Driver-11.3.0.0.tmp | — | POS_58_Driver-11.3.0.0.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 Modules
| |||||||||||||||
| 6964 | "C:\Users\admin\Desktop\POS_58_Driver-11.3.0.0.exe" /SPAWNWND=$901FE /NOTIFYWND=$802A8 | C:\Users\admin\Desktop\POS_58_Driver-11.3.0.0.exe | POS_58_Driver-11.3.0.0.tmp | ||||||||||||
User: admin Company: Integrity Level: HIGH Description: Exit code: 0 Version: 1.3.0.0 Modules
| |||||||||||||||
| 6984 | "C:\Users\admin\AppData\Local\Temp\is-52I0B.tmp\POS_58_Driver-11.3.0.0.tmp" /SL5="$802C8,2263740,121344,C:\Users\admin\Desktop\POS_58_Driver-11.3.0.0.exe" /SPAWNWND=$901FE /NOTIFYWND=$802A8 | C:\Users\admin\AppData\Local\Temp\is-52I0B.tmp\POS_58_Driver-11.3.0.0.tmp | POS_58_Driver-11.3.0.0.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 Modules
| |||||||||||||||
| (PID) Process: | (6232) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\preferences.zip | |||
| (PID) Process: | (6232) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\chromium_ext.zip | |||
| (PID) Process: | (6232) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\omni_23_10_2024_.zip | |||
| (PID) Process: | (6232) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\POS_58_Driver-11.3.0.0.zip | |||
| (PID) Process: | (6232) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (6232) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (6232) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (6232) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (6984) POS_58_Driver-11.3.0.0.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{5B643BF5-11A2-4A75-86D4-8F522DE92AA2}_is1 |
| Operation: | write | Name: | Inno Setup: Setup Version |
Value: 5.5.9 (u) | |||
| (PID) Process: | (6984) POS_58_Driver-11.3.0.0.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{5B643BF5-11A2-4A75-86D4-8F522DE92AA2}_is1 |
| Operation: | write | Name: | Inno Setup: App Path |
Value: C:\POS Printer Driver V11.3.0.0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6984 | POS_58_Driver-11.3.0.0.tmp | C:\Users\admin\AppData\Local\Temp\is-UAMD3.tmp\_isetup\_setup64.tmp | executable | |
MD5:E4211D6D009757C078A9FAC7FF4F03D4 | SHA256:388A796580234EFC95F3B1C70AD4CB44BFDDC7BA0F9203BF4902B9929B136F95 | |||
| 6964 | POS_58_Driver-11.3.0.0.exe | C:\Users\admin\AppData\Local\Temp\is-52I0B.tmp\POS_58_Driver-11.3.0.0.tmp | executable | |
MD5:90FC739C83CD19766ACB562C66A7D0E2 | SHA256:821BD11693BF4B4B2B9F3C196036E1F4902ABD95FB26873EA6C43E123B8C9431 | |||
| 6864 | POS_58_Driver-11.3.0.0.exe | C:\Users\admin\AppData\Local\Temp\is-O7HOC.tmp\POS_58_Driver-11.3.0.0.tmp | executable | |
MD5:90FC739C83CD19766ACB562C66A7D0E2 | SHA256:821BD11693BF4B4B2B9F3C196036E1F4902ABD95FB26873EA6C43E123B8C9431 | |||
| 6232 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa6232.11566\POS_58_Driver-11.3.0.0.exe | executable | |
MD5:08B5C46CD969A695832984FD9D41E637 | SHA256:6DFF1188BAEE908AA54242629A2669BAEBA2F6172E7D3F32AC2D9348B7AFF916 | |||
| 6984 | POS_58_Driver-11.3.0.0.tmp | C:\POS Printer Driver V11.3.0.0\is-4VM7S.tmp | executable | |
MD5:B30BB62407CF78CF3F1B79BC5610F25F | SHA256:5246030F8AA7A502E6C53DD7D54F10F4361DC0B6A6FFA7D5140B2860FEF08D65 | |||
| 6984 | POS_58_Driver-11.3.0.0.tmp | C:\POS Printer Driver V11.3.0.0\rc_eng.dll | executable | |
MD5:E2316C572724D26EC75F7B99CFA75BAC | SHA256:34F1418B511B183541C6AAAC2DBC84A6968FA345E20E470850740F1F3A5590F8 | |||
| 6984 | POS_58_Driver-11.3.0.0.tmp | C:\POS Printer Driver V11.3.0.0\unins000.exe | executable | |
MD5:70357CFD8962A845759D2896C488EA7B | SHA256:2DA0477291BBE152E4DFCAA59A77D2224595494120CADC9531BC640AD30752FE | |||
| 6984 | POS_58_Driver-11.3.0.0.tmp | C:\POS Printer Driver V11.3.0.0\PrinterTestDemo.exe | executable | |
MD5:66F175F3EC56884B7B17E422E7A94FF2 | SHA256:EEC7D55D05B4CC089015F00916D5D572FDDCD6AD97580B936F15F31778825EAA | |||
| 6984 | POS_58_Driver-11.3.0.0.tmp | C:\POS Printer Driver V11.3.0.0\is-OITSF.tmp | executable | |
MD5:70357CFD8962A845759D2896C488EA7B | SHA256:2DA0477291BBE152E4DFCAA59A77D2224595494120CADC9531BC640AD30752FE | |||
| 6984 | POS_58_Driver-11.3.0.0.tmp | C:\POS Printer Driver V11.3.0.0\is-PCUTG.tmp | executable | |
MD5:66F175F3EC56884B7B17E422E7A94FF2 | SHA256:EEC7D55D05B4CC089015F00916D5D572FDDCD6AD97580B936F15F31778825EAA | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | GET | 200 | 88.221.169.152:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
— | — | GET | 200 | 2.16.164.9:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
1176 | svchost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
— | — | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D | unknown | — | — | whitelisted |
1200 | backgroundTaskHost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D | unknown | — | — | whitelisted |
5872 | SIHClient.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
5872 | SIHClient.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
2160 | svchost.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4712 | MoUsoCoreWorker.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
— | — | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
— | — | 2.16.164.9:80 | crl.microsoft.com | Akamai International B.V. | NL | whitelisted |
— | — | 88.221.169.152:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
5064 | SearchApp.exe | 2.23.209.179:443 | www.bing.com | Akamai International B.V. | GB | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
— | — | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
1176 | svchost.exe | 40.126.31.71:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
www.bing.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
login.live.com |
| whitelisted |
go.microsoft.com |
| whitelisted |
arc.msn.com |
| whitelisted |
fd.api.iris.microsoft.com |
| whitelisted |