File name:

ASUSLiveUpdate_V3.6.15_13688_1.zip

Full analysis: https://app.any.run/tasks/ab13fba0-fb4f-41a3-9e1f-4b772ee62dbd
Verdict: Malicious activity
Analysis date: June 15, 2024, 07:45:42
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=store
MD5:

0E8EEFAA41381CA2673CFCE7A032F48C

SHA1:

6CE43D9C43B40FAEB89E18A929D2CE12F17B8331

SHA256:

5E7E135084732109CA7EDE691778A0B5D3EC23FBBAA69FC4E51C0CD28323A25B

SSDEEP:

98304:lKPpibLT8TpGCIo/MsiHi0L/SOBw/JtMTFWWNUGmbW3k//vuwm1/wvZCMKSZR5Eb:caJgSn13DDo23xnnhf

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 3988)
      • msiexec.exe (PID: 1592)
      • Setup.exe (PID: 1432)
    • Uses Task Scheduler to run other applications

      • rundll32.exe (PID: 2344)
  • SUSPICIOUS

    • Creates file in the systems drive root

      • WinRAR.exe (PID: 3988)
    • Reads security settings of Internet Explorer

      • Setup.exe (PID: 1432)
    • Checks Windows Trust Settings

      • Setup.exe (PID: 1432)
      • msiexec.exe (PID: 1592)
    • Reads settings of System Certificates

      • Setup.exe (PID: 1432)
    • Searches for installed software

      • Setup.exe (PID: 1432)
    • Executable content was dropped or overwritten

      • Setup.exe (PID: 1432)
      • rundll32.exe (PID: 2344)
    • Reads the Internet Settings

      • Setup.exe (PID: 1432)
    • The process drops C-runtime libraries

      • msiexec.exe (PID: 1592)
    • Executes as Windows Service

      • VSSVC.exe (PID: 2064)
    • Process drops legitimate windows executable

      • msiexec.exe (PID: 1592)
    • Uses RUNDLL32.EXE to load library

      • msiexec.exe (PID: 1980)
  • INFO

    • Manual execution by a user

      • Setup.exe (PID: 1020)
      • Setup.exe (PID: 1432)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3988)
      • msiexec.exe (PID: 1592)
    • Reads the computer name

      • Setup.exe (PID: 1432)
      • msiexec.exe (PID: 1592)
    • Checks supported languages

      • Setup.exe (PID: 1432)
      • msiexec.exe (PID: 1592)
    • Reads the software policy settings

      • Setup.exe (PID: 1432)
      • msiexec.exe (PID: 1488)
    • Creates files in the program directory

      • Setup.exe (PID: 1432)
    • Reads the machine GUID from the registry

      • Setup.exe (PID: 1432)
      • msiexec.exe (PID: 1592)
    • Reads security settings of Internet Explorer

      • msiexec.exe (PID: 1488)
    • Drops the executable file immediately after the start

      • rundll32.exe (PID: 2344)
    • Application launched itself

      • msiexec.exe (PID: 1592)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2021:10:14 10:57:18
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: data_win8/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
47
Monitored processes
9
Malicious processes
2
Suspicious processes
2

Behavior graph

Click at the process to see the details
start winrar.exe setup.exe no specs setup.exe msiexec.exe no specs msiexec.exe vssvc.exe no specs msiexec.exe no specs rundll32.exe schtasks.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1020"C:\Users\admin\Desktop\test\Setup.exe" C:\Users\admin\Desktop\test\Setup.exeexplorer.exe
User:
admin
Company:
ASUSTek Computer Inc.
Integrity Level:
MEDIUM
Description:
Installer Application
Exit code:
3221226540
Version:
1.0.6.0
Modules
Images
c:\users\admin\desktop\test\setup.exe
c:\windows\system32\ntdll.dll
1432"C:\Users\admin\Desktop\test\Setup.exe" C:\Users\admin\Desktop\test\Setup.exe
explorer.exe
User:
admin
Company:
ASUSTek Computer Inc.
Integrity Level:
HIGH
Description:
Installer Application
Version:
1.0.6.0
Modules
Images
c:\users\admin\desktop\test\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msimg32.dll
1488"C:\Windows\System32\msiexec.exe" /i "C:\Users\admin\Desktop\test\data_win8\409.msi" C:\Windows\System32\msiexec.exeSetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1592C:\Windows\system32\msiexec.exe /VC:\Windows\System32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1696"schtasks.exe" /CREATE /TN "Update Checker" /XML "C:\Windows\Installer\MSI1442.tmp-\UpdateCheckerTask.xml"C:\Windows\System32\schtasks.exerundll32.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Manages scheduled tasks
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
1980C:\Windows\system32\MsiExec.exe -Embedding 38DE31F4D0333481A389B629C19FD003 E Global\MSI0000C:\Windows\System32\msiexec.exemsiexec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
2064C:\Windows\system32\vssvc.exeC:\Windows\System32\VSSVC.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Volume Shadow Copy Service
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\vssvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2344rundll32.exe "C:\Windows\Installer\MSI1442.tmp",zzzzInvokeManagedCustomActionOutOfProc SfxCA_1119375 1 SetupCustomAction!SetupCustomAction.CustomActions.SetupTaskScheduleC:\Windows\System32\rundll32.exe
msiexec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
3988"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\ASUSLiveUpdate_V3.6.15_13688_1.zipC:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
Total events
13 589
Read events
13 390
Write events
196
Delete events
3

Modification events

(PID) Process:(3988) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3988) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3988) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3988) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(3988) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(3988) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(3988) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\ASUSLiveUpdate_V3.6.15_13688_1.zip
(PID) Process:(3988) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3988) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3988) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
Executable files
16
Suspicious files
6
Text files
8
Unknown types
0

Dropped files

PID
Process
Filename
Type
3988WinRAR.exeC:\Users\admin\Desktop\test\data_win8\409.msi
MD5:
SHA256:
1592msiexec.exeC:\System Volume Information\SPP\metadata-2
MD5:
SHA256:
1592msiexec.exeC:\Windows\Installer\110fdb.msi
MD5:
SHA256:
1592msiexec.exeC:\Program Files\ASUS\ASUS Live Update\adrvld.dllexecutable
MD5:A4C703EA1321B8B059573D8290EC2709
SHA256:5DC5EBA32CEA994AC5060F880BDCCBA513447F435B32EBC670E3C4BF1BDA308F
1432Setup.exeC:\Program Files\ASUS\HotfixChecker\HotfixChecker.exeexecutable
MD5:91DF7ADFCAF7DAB8B323ADA62F549586
SHA256:CFFA01BF66ECEB946979E40524C946A6A0792250AB6345E22B022C450E08F8BE
3988WinRAR.exeC:\Users\admin\Desktop\test\HotfixChecker.exeexecutable
MD5:91DF7ADFCAF7DAB8B323ADA62F549586
SHA256:CFFA01BF66ECEB946979E40524C946A6A0792250AB6345E22B022C450E08F8BE
1592msiexec.exeC:\Program Files\ASUS\ASUS Live Update\restore.tmp
MD5:
SHA256:
1592msiexec.exeC:\Program Files\ASUS\ASUS Live Update\alvupdt.dllexecutable
MD5:F07D145CD1E558E27CA7833D7CB0945C
SHA256:D94DF2ED65C232FBC58F8D97495CF1B85026337B4431117B9767C429299DD4BA
1592msiexec.exeC:\Program Files\ASUS\ASUS Live Update\tempfile.tmp
MD5:
SHA256:
1592msiexec.exeC:\Program Files\ASUS\ASUS Live Update\ETW.dllexecutable
MD5:BE5118D9DEDA69E647D63364A3B3B587
SHA256:60C0457805A6244DFBCE2A52C35A90DA69E04958CD70DEB6F21ECF7998AA328D
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1088
svchost.exe
224.0.0.252:5355
unknown

DNS requests

No data

Threats

No threats detected
Process
Message
Setup.exe
<alvupdt><MSIstarter> [3.4.9] Start MSIStarter
Setup.exe
<alvupdt><MSIstarter> Connected to ROOT\CIMV2 WMI namespace
Setup.exe
<alvupdt><MSIstarter> EnableTriggerLogon: _blMode = RELEASE
Setup.exe
<alvupdt><MSIstarter> Group: Administrators
Setup.exe
<alvupdt><MSIstarter> Task successfully registered.
Setup.exe
<alvupdt><MSIstarter> Try to launch C:\Users\admin\Desktop\test\data_win8\409.msi
Setup.exe
<alvupdt><MSIstarter> Install new version
Setup.exe
<alvupdt><MSIstarter> 3.3.7 Write m_dwCriticalUpdate 0
Setup.exe
<alvupdt><MSIstarter> 3.3.7 SetDefaultSetting
Setup.exe
<alvupdt><MSIstarter> 3.3.7 Write m_dwRecommUpdate 1