| File name: | SDI_R2201.zip |
| Full analysis: | https://app.any.run/tasks/dfff2499-a39d-4215-80c2-79e4ff06d723 |
| Verdict: | Malicious activity |
| Analysis date: | March 06, 2024, 02:02:40 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract, compression method=store |
| MD5: | B985095D021BADC0B5D1D0B6CC1C4554 |
| SHA1: | BDA8C7489D394B90395CCA9772A8A0D6A932CB62 |
| SHA256: | 44BFE7243DD089F4886545E05EBE7AEBC9ED2BA492E648FD73C53945B0703FCA |
| SSDEEP: | 98304:aC2V3oiOYQlieLMV/WaAKpMgTRenDm2qDyc2nPNXosnWp+aaIBYfJKnhJmU9DEjU:hs1nE4UiGgAJE6k |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 20 |
|---|---|
| ZipBitFlag: | 0x0002 |
| ZipCompression: | None |
| ZipModifyDate: | 2018:09:29 00:24:12 |
| ZipCRC: | 0x00000000 |
| ZipCompressedSize: | - |
| ZipUncompressedSize: | - |
| ZipFileName: | drivers/ |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1348 | "C:\Windows\System32\cmd.exe" /c rd /s /q "C:\Users\admin\AppData\Local\Temp\SDI" | C:\Windows\System32\cmd.exe | — | SDI_R2201.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 2 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 1780 | "C:\Windows\System32\cmd.exe" /c rd /s /q "C:\Users\admin\AppData\Local\Temp\SDI" | C:\Windows\System32\cmd.exe | — | SDI_R2201.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 2 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 1860 | "C:\Windows\System32\cmd.exe" /c rd /s /q "C:\Users\admin\AppData\Local\Temp\SDI" | C:\Windows\System32\cmd.exe | — | SDI_R2201.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 2 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 2036 | "C:\Users\admin\AppData\Local\Temp\SDI_R2201\SDI_R2201.exe" | C:\Users\admin\AppData\Local\Temp\SDI_R2201\SDI_R2201.exe | — | explorer.exe | |||||||||||
User: admin Company: www.SamLab.ws Integrity Level: MEDIUM Description: Snappy Driver Installer Exit code: 3221226540 Version: 1.22 1.22.1 Modules
| |||||||||||||||
| 2072 | "C:\Windows\System32\cmd.exe" /c rd /s /q "C:\Users\admin\AppData\Local\Temp\SDI" | C:\Windows\System32\cmd.exe | — | SDI_R2201.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 2 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 2636 | "C:\Users\admin\AppData\Local\Temp\SDI_R2201\SDI_R2201.exe" | C:\Users\admin\AppData\Local\Temp\SDI_R2201\SDI_R2201.exe | explorer.exe | ||||||||||||
User: admin Company: www.SamLab.ws Integrity Level: HIGH Description: Snappy Driver Installer Exit code: 0 Version: 1.22 1.22.1 Modules
| |||||||||||||||
| 2728 | "C:\Windows\System32\cmd.exe" /c rd /s /q "C:\Users\admin\AppData\Local\Temp\SDI" | C:\Windows\System32\cmd.exe | — | SDI_R2201.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 2 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 2780 | C:\Windows\system32\vssvc.exe | C:\Windows\System32\VSSVC.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft® Volume Shadow Copy Service Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3672 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\SDI_R2201.zip" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| (PID) Process: | (3672) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (3672) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (3672) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3672) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\phacker.zip | |||
| (PID) Process: | (3672) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (3672) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip | |||
| (PID) Process: | (3672) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\SDI_R2201.zip | |||
| (PID) Process: | (3672) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (3672) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (3672) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3672 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\SDI_R2201\tools\SDI\langs\arabic.txt | text | |
MD5:1F6CE2008F0841D4965F4A7D3AA76DD1 | SHA256:12EECF9155829256FE3E8C7A4BA37F1F5C222E961FBAD6945383FAD96A83F0B5 | |||
| 3672 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\SDI_R2201\tools\SDI\langs\chinese_zh.txt | text | |
MD5:EAE8E356B8D4372902F6ACA9959985F2 | SHA256:4206E23A077026C61B0F57B350803327F1B0A33D2BD7B06EA47375A6E82810CD | |||
| 3672 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\SDI_R2201\tools\SDI\langs\czech.txt | text | |
MD5:898076B87800DEA4582E047AD919F128 | SHA256:92E556B79C7A9AA1B8255FDAC3759375D0CF2BA9AA53FA64F53B323730A307EB | |||
| 3672 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\SDI_R2201\tools\SDI\langs\croatian.txt | text | |
MD5:275228CEFEF0757D3C42B060F02519DA | SHA256:88486FD85208FC049604AD08B6786161346AFC4A1B6386C0110E601AF2337830 | |||
| 3672 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\SDI_R2201\tools\SDI\langs\estonian.txt | text | |
MD5:724C5950CEB61C69CD8616600E5E8C18 | SHA256:6F3B89F6EB5D303C5EA644026516E91EC427B9A896599BED4EB015C6A4301689 | |||
| 3672 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\SDI_R2201\tools\SDI\langs\french.txt | text | |
MD5:31DD0A654FF0E3EC327EA116517C87B4 | SHA256:55F1C8AB29E06F7C16D82EB2DB5DC9338C2848306BE3F6BAEF4D39ED63FA6445 | |||
| 3672 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\SDI_R2201\tools\SDI\langs\farsi.txt | text | |
MD5:12FD932E37EC6420EB1E0986662F83CD | SHA256:219E5FBEFEC1D9DAC59EA449802C99842302E3278A770D3068724217222487A4 | |||
| 3672 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\SDI_R2201\tools\SDI\langs\danish.txt | text | |
MD5:BF38AE3F54CFEFE7C25B6E4D819E279F | SHA256:1E9C98C1342B71D50D0A4B4A4FBE90384876B9CABE03E30DBFD46792C89F70EC | |||
| 3672 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\SDI_R2201\tools\SDI\langs\german.txt | text | |
MD5:459A4AA3871C0901A8BB1BCF18A95E9F | SHA256:60F37DEB0A2358C125D661E578EFBAB84B4D00F0ECED4E17694000CA5A8B8F72 | |||
| 3672 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\SDI_R2201\tools\SDI\langs\english.txt | text | |
MD5:3847CA6996306078F53B1BD3D1CDC4A0 | SHA256:CE2E90B7488184CE71B463CBB5EF594BD96FFAEA1F81473ABCC4F28851352249 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2636 | SDI_R2201.exe | GET | 200 | 185.26.122.80:80 | http://driveroff.net/SDI_Update.torrent | unknown | binary | 431 Kb | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
2636 | SDI_R2201.exe | 185.26.122.80:80 | driveroff.net | Hostland LTD | RU | unknown |
Domain | IP | Reputation |
|---|---|---|
router.bittorrent.com |
| shared |
router.utorrent.com |
| whitelisted |
router.bitcomet.com |
| unknown |
driveroff.net |
| unknown |
PID | Process | Class | Message |
|---|---|---|---|
2636 | SDI_R2201.exe | Potential Corporate Privacy Violation | ET P2P Possible Torrent Download via HTTP Request |