File name:

Ch341a Programmer V2.2.0.0.rar

Full analysis: https://app.any.run/tasks/e0527007-9147-4073-907c-fd1ccf049b90
Verdict: Malicious activity
Analysis date: January 09, 2024, 13:57:22
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

3B7AB456F978D1006D4AA99241871A2F

SHA1:

719F58CCB123E5A0BD3E75624FF9586BF7A5DE38

SHA256:

49C307A6648C65B17A3D2BD8DB2A94A380EAAA6810A96E4575B57430996B7A72

SSDEEP:

98304:/ZV8QkzDkOiUtUjcitlJ4N0BH0ccjIm6vFi2WEj0rjaMYROSZe1Z5u6N34Tc6tuN:KqRSpFSBsq8gjZT2

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Creates a writable file in the system directory

      • drvinst.exe (PID: 956)
      • SETUP.EXE (PID: 764)
  • SUSPICIOUS

    • Drops a system driver (possible attempt to evade defenses)

      • WinRAR.exe (PID: 2044)
      • WinRAR.exe (PID: 2068)
      • SETUP.EXE (PID: 764)
      • drvinst.exe (PID: 956)
    • Creates files in the driver directory

      • drvinst.exe (PID: 956)
      • SETUP.EXE (PID: 764)
    • Checks Windows Trust Settings

      • drvinst.exe (PID: 956)
  • INFO

    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 2044)
      • WinRAR.exe (PID: 2068)
      • SETUP.EXE (PID: 764)
      • drvinst.exe (PID: 956)
    • Create files in a temporary directory

      • Ch341a V2.2.0.0.exe (PID: 864)
      • SETUP.EXE (PID: 764)
    • Checks supported languages

      • Ch341a V2.2.0.0.exe (PID: 864)
      • SETUP.EXE (PID: 764)
      • drvinst.exe (PID: 956)
    • Application launched itself

      • WinRAR.exe (PID: 2044)
    • Reads the computer name

      • SETUP.EXE (PID: 764)
      • drvinst.exe (PID: 956)
    • Reads the machine GUID from the registry

      • SETUP.EXE (PID: 764)
      • drvinst.exe (PID: 956)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
41
Monitored processes
6
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe no specs ch341a v2.2.0.0.exe no specs winrar.exe no specs setup.exe no specs setup.exe drvinst.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
764"C:\Users\admin\AppData\Local\Temp\Rar$EXa2068.17961\Ch341a V2.2.0.0\Drivers\CH341A\SETUP.EXE" C:\Users\admin\AppData\Local\Temp\Rar$EXa2068.17961\Ch341a V2.2.0.0\Drivers\CH341A\SETUP.EXE
WinRAR.exe
User:
admin
Integrity Level:
HIGH
Description:
EXE For Driver Installation
Exit code:
0
Version:
1, 6, 8, 0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2068.17961\ch341a v2.2.0.0\drivers\ch341a\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
864"C:\Users\admin\AppData\Local\Temp\Rar$EXa2044.15079\Ch341a V2.2.0.0\Ch341a V2.2.0.0.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa2044.15079\Ch341a V2.2.0.0\Ch341a V2.2.0.0.exeWinRAR.exe
User:
admin
Company:
TTAV134
Integrity Level:
MEDIUM
Exit code:
0
Version:
2.2.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2044.15079\ch341a v2.2.0.0\ch341a v2.2.0.0.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
956DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{430eb28f-9f4f-00bc-245f-6b7ea1019a5e}\CH341WDM.INF" "0" "6eddea6cf" "00000558" "WinSta0\Default" "00000550" "208" "C:\Users\admin\AppData\Local\Temp\Rar$EXa2068.17961\Ch341a V2.2.0.0\Drivers\CH341A"C:\Windows\System32\drvinst.exesvchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
2016"C:\Users\admin\AppData\Local\Temp\Rar$EXa2068.17961\Ch341a V2.2.0.0\Drivers\CH341A\SETUP.EXE" C:\Users\admin\AppData\Local\Temp\Rar$EXa2068.17961\Ch341a V2.2.0.0\Drivers\CH341A\SETUP.EXEWinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Description:
EXE For Driver Installation
Exit code:
3221226540
Version:
1, 6, 8, 0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2068.17961\ch341a v2.2.0.0\drivers\ch341a\setup.exe
c:\windows\system32\ntdll.dll
2044"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Ch341a Programmer V2.2.0.0.rar"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2068"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\Rar$DIa2044.16277\chiplist.zipC:\Program Files\WinRAR\WinRAR.exeWinRAR.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
Total events
5 539
Read events
5 459
Write events
80
Delete events
0

Modification events

(PID) Process:(2044) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2044) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(2044) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(2044) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(2044) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(2044) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2044) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2044) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2044) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2044) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
Executable files
36
Suspicious files
54
Text files
80
Unknown types
0

Dropped files

PID
Process
Filename
Type
2044WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2044.15079\Ch341a V2.2.0.0\chiplist.datbinary
MD5:1044EB8F916765FE612871409BB7FA66
SHA256:BDAC37BE8483BE6740FC49AAC85FBA5D1E104E3275119AADC6974468AC48E9A8
2044WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2044.15079\Ch341a V2.2.0.0\Ch341a_changes_RU.txttext
MD5:5F23794E35A4B57D83F626D719CF3F22
SHA256:BF1E27CA3EFF0A0A9BF3C7A1A2D56FF40B088F1E388224F1A26E63C90A63B548
2044WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2044.15079\Ch341a V2.2.0.0\Ch341a V2.2.0.0.exeexecutable
MD5:153B4817CB6AD256768CC27B6D4CC6FD
SHA256:FA95A5BA0096B82A70265E566B4A69D10C428D491F6512BFE5C762BB4FC04BED
2044WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2044.15079\Ch341a V2.2.0.0\Ch341a_changes.txttext
MD5:CC9BBC36295B055D322039886048ABC5
SHA256:5E79AFC3D4CF552439785C44E4A82B9BC121CE4D3ABB9D3B85E7E82AFF17DB1B
2044WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2044.15079\Ch341a V2.2.0.0\devicelist.txttext
MD5:F230554240177FC903DC4D4B76533B2F
SHA256:5F917BB41B947FBEE9E5147A2ED983700B4B7F6078A14E4379E8DBEEA4D47E9A
2044WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2044.15079\Ch341a V2.2.0.0\Doc\CH341\Programmers\ch341a_programmer_black_3.3v_5.0v_EN.pdfpdf
MD5:9D8950090702A3D89122194CE8794DFA
SHA256:4CA5358E278AC25ABCD090A2730E94F18B834FF7AA70406418FE462307EED720
2044WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2044.15079\Ch341a V2.2.0.0\Drivers\CH341A\CH341DLL.DLLexecutable
MD5:D84B4C0F270EA6EA91A0DDAD53B88C2B
SHA256:48E025E8D4D3320B273B3A2F029FB33A877EA94EE0A2A7943EE181209FC412A2
2044WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2044.15079\Ch341a V2.2.0.0\Doc\CH341\Programmers\CH341_v2.0.jpgimage
MD5:43924BE060B2861802396BDD3550AF72
SHA256:1480331ED2EF3C47393FCA34C5CA8A3C3D817CBF193196D22EF2519CAA8A2E04
2044WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2044.15079\Ch341a V2.2.0.0\Doc\CH341\Adapters\SPI45xx ADAPTER FOR CH341 (EN).pdfpdf
MD5:E09291E842990378BF9B872308E2D4C3
SHA256:D5D2EBABC15E51158610B6FCCA8658EE4AD49F26194047F87DFB9A8A2B95B203
2044WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2044.15079\Ch341a V2.2.0.0\Doc\CH341\Adapters\SPI45xx АДАПТЕР ДЛЯ CH341 (RU).pdfpdf
MD5:23B02AC4322A39E11F4B8C7C7AC6CD70
SHA256:AB675A9B866401BED60DF2B96BBE0A8630437B8A121D5D1F37B24BCF37B2229D
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
whitelisted

DNS requests

No data

Threats

No threats detected
No debug info