| File name: | VBCABLE_Driver_Pack43.zip |
| Full analysis: | https://app.any.run/tasks/2a6b93fb-40f7-4533-a383-92de2fbe56a0 |
| Verdict: | Malicious activity |
| Analysis date: | August 02, 2020, 11:30:40 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract |
| MD5: | 3E2F6DDF5A06C66DC4DAED708F8BB2A6 |
| SHA1: | 0FC70FD364B76B3DBDF6C9780369A834ED9EFD3E |
| SHA256: | 66FD0A4D9F4896FF41632B7E3D53892C085C4561F53E8AE8D0F0BC10EEDD1CDD |
| SSDEEP: | 24576:dqtBKwfPZ5JLfG/Dtl27gdahBUV1G7h4si2KRayG81atW8:dsKwZ5ZfG/Bo72aQVeh4siZaA4tW8 |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 20 |
|---|---|
| ZipBitFlag: | - |
| ZipCompression: | Deflated |
| ZipModifyDate: | 2014:09:02 17:16:17 |
| ZipCRC: | 0xe613802d |
| ZipCompressedSize: | 1275 |
| ZipUncompressedSize: | 4146 |
| ZipFileName: | vbMmeCable64_win7.inf |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1296 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa1864.20292\VBCABLE_Setup.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa1864.20292\VBCABLE_Setup.exe | — | WinRAR.exe | |||||||||||
User: admin Company: VB-AUDIO Software Integrity Level: MEDIUM Description: VB-AUDIO Virtual Cable Installer Exit code: 3221226540 Version: 1, 0, 3, 8 Modules
| |||||||||||||||
| 1324 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa1864.20292\VBCABLE_Setup.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa1864.20292\VBCABLE_Setup.exe | WinRAR.exe | ||||||||||||
User: admin Company: VB-AUDIO Software Integrity Level: HIGH Description: VB-AUDIO Virtual Cable Installer Exit code: 0 Version: 1, 0, 3, 8 Modules
| |||||||||||||||
| 1524 | "C:\Program Files\Internet Explorer\iexplore.exe" http://vb-audio.pagesperso-orange.fr/Services/ThankYou.htm | C:\Program Files\Internet Explorer\iexplore.exe | VBCABLE_Setup.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Internet Explorer Exit code: 1 Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
| 1664 | "C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:1524 CREDAT:275457 /prefetch:2 | C:\Program Files\Internet Explorer\iexplore.exe | iexplore.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Internet Explorer Exit code: 0 Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
| 1864 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\VBCABLE_Driver_Pack43.zip" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.60.0 Modules
| |||||||||||||||
| 2080 | C:\Windows\system32\vssvc.exe | C:\Windows\system32\vssvc.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft® Volume Shadow Copy Service Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2152 | "C:\Program Files\Opera\opera.exe" | C:\Program Files\Opera\opera.exe | explorer.exe | ||||||||||||
User: admin Company: Opera Software Integrity Level: MEDIUM Description: Opera Internet Browser Exit code: 0 Version: 1748 Modules
| |||||||||||||||
| 2296 | rundll32.exe C:\Windows\system32\pnpui.dll,InstallSecurityPromptRunDllW 20 Global\{202e5e7b-2cbf-4d71-937c-4154d4f9052a} Global\{0e07ae70-e62f-62e3-7b5e-2e20623d6513} C:\Windows\System32\DriverStore\Temp\{13653d62-67e7-42e4-958c-ed165041245b}\vbmmecable_win7.inf C:\Windows\System32\DriverStore\Temp\{13653d62-67e7-42e4-958c-ed165041245b}\vbaudio_cable_win7.cat | C:\Windows\system32\rundll32.exe | — | DrvInst.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows host process (Rundll32) Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2540 | DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{0dec23f9-614a-557b-13cc-d474f767ba46}\vbmmecable_win7.inf" "0" "612cfd737" "000005C8" "WinSta0\Default" "000005B8" "208" "c:\users\admin\appdata\local\temp\rar$exa1864.20292" | C:\Windows\system32\DrvInst.exe | svchost.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Driver Installation Module Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2724 | DrvInst.exe "2" "211" "ROOT\MEDIA\0000" "C:\Windows\INF\oem4.inf" "vbmmecable_win7.inf:VBCable:VBCableInst:1.0.3.5:vbaudiovacwdm" "612cfd737" "000005C8" "000005E8" "000005EC" | C:\Windows\system32\DrvInst.exe | svchost.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Driver Installation Module Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (1864) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (1864) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (1864) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\132\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (1864) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\VBCABLE_Driver_Pack43.zip | |||
| (PID) Process: | (1864) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (1864) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (1864) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (1864) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (1864) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\132\52C64B7E |
| Operation: | write | Name: | @C:\Windows\system32\notepad.exe,-469 |
Value: Text Document | |||
| (PID) Process: | (1864) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\132\52C64B7E |
| Operation: | write | Name: | @cryptext.dll,-6145 |
Value: Security Catalog | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1864 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa1864.20292\pin_in.ico | image | |
MD5:E442346F22DA9A5BB15DFABA67A360B8 | SHA256:934865449455103C1C5997D8220ACD160C3891F8A870F8E745B743D12681AC42 | |||
| 1864 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa1864.20292\vbMmeCable64_win7.inf | ini | |
MD5:498FAEE2DE63C1C428900920203FDF9B | SHA256:DA35387CCFE813F5C553BB7E0CAF4E67ADBB4429E742C2BD3C2014F80E6EC516 | |||
| 1864 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa1864.20292\vbaudio_cable_2003.cat | cat | |
MD5:F3D83B61A6ECCE5DC90687496AABA335 | SHA256:23A10E3BCD6FFE0DE6D3D67830BE4C447724B3299E13E954DD6BD2257CF55DA1 | |||
| 1864 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa1864.20292\vbaudio_cable_2003.sys | executable | |
MD5:AF264799CA75A33DB63F3761BAD046FF | SHA256:9650E20C38429D4680A7E603ECBE6601914EC4C94F8473112F21515BF53B84CF | |||
| 1864 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa1864.20292\vbaudio_cable64_win7.cat | cat | |
MD5:CCC4FAA1DC627221BD57272444B4E71F | SHA256:800B541F06BBA3925BA058E7CC7CA837CFD4D845E073309EB2A9D36A2626403A | |||
| 1864 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa1864.20292\vbaudio_cable_vista.sys | executable | |
MD5:6CC2CE471671F7665BA15A177A3CCF10 | SHA256:8B02C26313B75CEB8FB9BD16B6B167CF70D7F3BC977DFC1986C0859F8C72B49F | |||
| 1864 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa1864.20292\pin_out.ico | image | |
MD5:235559DE67569EBC8FDCF5D51D753B57 | SHA256:E8728A811E1F1AF7D2BA31F77E47D449D5BBA091E3E89A0DF325AC7A3E67652C | |||
| 1864 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa1864.20292\vbaudio_cable_vista.cat | cat | |
MD5:40401678D0272A448795432615F8B762 | SHA256:810B30193A400B1559302C23F81EF8AAADF038B3CAF3AFF9BF200B59688A2DEF | |||
| 1864 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa1864.20292\vbaudio_cable_win7.cat | cat | |
MD5:9CC8F7A387484C49A6F1296586CD1DDB | SHA256:1C38AFACF115818C925BC26FAF216E3563E85BBC4D6D793E5F76F2AA670D08E7 | |||
| 1864 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa1864.20292\vbaudio_cable64_2003.cat | cat | |
MD5:1A938E376ABA87FD3D4285A261146923 | SHA256:70F88E34C857C999367EB5B0303E23F5676B15A79ED4054F374749232BAA0E3A | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
1664 | iexplore.exe | GET | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQQX6Z6gAidtSefNc6DC0OInqPHDQQUD4BhHIIxYdUvKOeNRji0LOHG2eICEAymzRibNxDS4Bzoe5WpI%2FM%3D | US | der | 471 b | whitelisted |
1664 | iexplore.exe | GET | 301 | 193.252.121.241:80 | http://pages.perso.orange.fr/php/compteur.php?url=vb-audio&df=ThankYou&dd=E&frgb=noir&ft=0&tr=Oui&pad=Non&comma=Oui | FR | html | 352 b | unknown |
1664 | iexplore.exe | GET | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQQX6Z6gAidtSefNc6DC0OInqPHDQQUD4BhHIIxYdUvKOeNRji0LOHG2eICEAOPlIv8IO0vtOE%2Fujvol7E%3D | US | der | 471 b | whitelisted |
1664 | iexplore.exe | GET | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQQX6Z6gAidtSefNc6DC0OInqPHDQQUD4BhHIIxYdUvKOeNRji0LOHG2eICEAfHxhHnkMBjFmx7tQC%2B5yg%3D | US | der | 471 b | whitelisted |
1664 | iexplore.exe | GET | 200 | 2.16.107.73:80 | http://isrg.trustid.ocsp.identrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRv9GhNQxLSSGKBnMArPUcsHYovpgQUxKexpHsscfrb4UuQdf%2FEFWCFiRACEAoBQUIAAAFThXNqC4Xspwg%3D | unknown | der | 1.37 Kb | whitelisted |
1524 | iexplore.exe | GET | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEA8sEMlbBsCTf7jUSfg%2BhWk%3D | US | der | 1.47 Kb | whitelisted |
1524 | iexplore.exe | GET | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEA8sEMlbBsCTf7jUSfg%2BhWk%3D | US | der | 1.47 Kb | whitelisted |
1524 | iexplore.exe | GET | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEA8sEMlbBsCTf7jUSfg%2BhWk%3D | US | der | 1.47 Kb | whitelisted |
1664 | iexplore.exe | GET | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAH9o%2BtuynXIiEOLckvPvJE%3D | US | der | 471 b | whitelisted |
1664 | iexplore.exe | GET | 301 | 193.252.121.242:80 | http://vb-audio.pagesperso-orange.fr/Services/ThankYou.htm | FR | html | 267 b | suspicious |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2152 | opera.exe | 185.26.182.94:443 | certs.opera.com | Opera Software AS | — | whitelisted |
2152 | opera.exe | 93.184.220.29:80 | crl4.digicert.com | MCI Communications Services, Inc. d/b/a Verizon Business | US | whitelisted |
1664 | iexplore.exe | 193.252.121.242:80 | vb-audio.pagesperso-orange.fr | Orange | FR | suspicious |
1664 | iexplore.exe | 193.252.121.242:443 | vb-audio.pagesperso-orange.fr | Orange | FR | suspicious |
1664 | iexplore.exe | 93.184.220.29:80 | crl4.digicert.com | MCI Communications Services, Inc. d/b/a Verizon Business | US | whitelisted |
1664 | iexplore.exe | 193.70.46.215:443 | shop.vb-audio.com | OVH SAS | FR | unknown |
1664 | iexplore.exe | 193.252.121.241:80 | pages.perso.orange.fr | Orange | FR | unknown |
1664 | iexplore.exe | 193.252.121.241:443 | pages.perso.orange.fr | Orange | FR | unknown |
1664 | iexplore.exe | 2.16.107.73:80 | isrg.trustid.ocsp.identrust.com | Akamai International B.V. | — | suspicious |
1664 | iexplore.exe | 193.252.148.221:443 | s.gstat.orange.fr | Orange | FR | suspicious |
Domain | IP | Reputation |
|---|---|---|
certs.opera.com |
| whitelisted |
crl4.digicert.com |
| whitelisted |
vb-audio.pagesperso-orange.fr |
| suspicious |
ocsp.digicert.com |
| whitelisted |
shop.vb-audio.com |
| unknown |
pages.perso.orange.fr |
| unknown |
isrg.trustid.ocsp.identrust.com |
| whitelisted |
s.gstat.orange.fr |
| suspicious |
api.bing.com |
| whitelisted |
www.bing.com |
| whitelisted |