| File name: | CH341A Programmer Special Edition v1.38.7z |
| Full analysis: | https://app.any.run/tasks/5c30774a-7c55-477f-8305-28e1c7d4baad |
| Verdict: | Malicious activity |
| Analysis date: | January 09, 2024, 13:34:19 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-7z-compressed |
| File info: | 7-zip archive data, version 0.4 |
| MD5: | BCB60261F583E4D5EB9C7DFB80F211D4 |
| SHA1: | 6E029C8CC83011367AB24DF5D2A6F657D0BDB2FF |
| SHA256: | 71B59AF8CF4EC0C2F2D4229F2310491E217E4F681D56B7170CE62E65EF5B199C |
| SSDEEP: | 98304:wGbb262EvfUa4GD93dRrBWNeQ4If+tYEtMpN/empOm35E3++nGywXNnDG7Ybs080:P8sUIOvDf/p/DpJ |
| .7z | | | 7-Zip compressed archive (v0.4) (57.1) |
|---|---|---|
| .7z | | | 7-Zip compressed archive (gen) (42.8) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 188 | SETUP /S | C:\Program Files\CH341Programmer\DrvSetup86.exe | — | Installer.exe | |||||||||||
User: admin Integrity Level: HIGH Description: EXE For Driver Installation Exit code: 0 Version: 1, 6, 8, 0 Modules
| |||||||||||||||
| 668 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa2044.25538\Installer.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa2044.25538\Installer.exe | WinRAR.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: Installer Application Exit code: 3221225547 Version: 1.0.0.4 Modules
| |||||||||||||||
| 864 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa2044.25538\Installer.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa2044.25538\Installer.exe | — | WinRAR.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: Installer Application Exit code: 3221226540 Version: 1.0.0.4 Modules
| |||||||||||||||
| 2044 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\CH341A Programmer Special Edition v1.38.7z" | C:\Program Files\WinRAR\WinRAR.exe | — | explorer.exe | |||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| 2260 | "C:\Program Files\CH341Programmer\Ch341Programmer.exe" | C:\Program Files\CH341Programmer\Ch341Programmer.exe | — | explorer.exe | |||||||||||
User: admin Company: Kovzhun Mikhail Alexandrovich Integrity Level: MEDIUM Description: Программатор Spi Flash Eeprom Exit code: 0 Version: 1.38.0.0 Modules
| |||||||||||||||
| 2620 | DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{7a340a88-b532-1c38-963d-1d1894ed2b55}\CH341WDM.INF" "0" "6c8f1af03" "00000558" "WinSta0\Default" "000005D8" "208" "C:\Program Files\CH341Programmer" | C:\Windows\System32\drvinst.exe | — | svchost.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Driver Installation Module Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (2044) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2044) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip | |||
| (PID) Process: | (2044) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\phacker.zip | |||
| (PID) Process: | (2044) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (2044) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip | |||
| (PID) Process: | (2044) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (2044) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (2044) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (2044) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (2044) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 668 | Installer.exe | C:\Users\admin\AppData\Local\Temp\melo.mp3 | — | |
MD5:— | SHA256:— | |||
| 2044 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2044.25538\Installer.exe | executable | |
MD5:37DE0A028C464D20470B5335FA47EE21 | SHA256:2A9D9A3B727D38F5AB35C431C3B0CCD8B6599FAE5C4662222ED3C7A556496B1A | |||
| 668 | Installer.exe | C:\Users\admin\AppData\Local\Temp\Next.mp3 | binary | |
MD5:D5DF696B74342B6ED902DBE9E9AC80E8 | SHA256:685199EA1582F17CB00C01A7EDDCC9D456A17C34BD6D96BD3EA6295AF4BC852B | |||
| 668 | Installer.exe | C:\Program Files\CH341Programmer\CH341DLL.DLL | executable | |
MD5:D84B4C0F270EA6EA91A0DDAD53B88C2B | SHA256:48E025E8D4D3320B273B3A2F029FB33A877EA94EE0A2A7943EE181209FC412A2 | |||
| 668 | Installer.exe | C:\Users\admin\AppData\Local\Temp\InstOk.mp3 | binary | |
MD5:DC216D421D6F96B199B7FF769D9F3846 | SHA256:E23DF7E49AADAF745B2F4B136BF2096FF258A01E299A56076EF480DBA6BD5155 | |||
| 668 | Installer.exe | C:\Users\admin\AppData\Local\Temp\Show.mp3 | binary | |
MD5:9B079829520C9641DE22766D400182C1 | SHA256:2D02E807A76E122DE35892297066740A271479BB836290421CE4A9BD6444E90A | |||
| 668 | Installer.exe | C:\Users\admin\AppData\Local\Temp\Exit.mp3 | binary | |
MD5:2B6A460BF2C0EB02BDCF3F3DBB72B338 | SHA256:7E4A729840C58E0F4D879D0FB0489B17F43925CA2D03B0E9ACC65C46AF6A3C68 | |||
| 668 | Installer.exe | C:\Program Files\CH341Programmer\CH341WDM.CAT | binary | |
MD5:71BDCA7F420EA6C2AAC393040624349D | SHA256:1D25C1A1B550E94789CD9A7E3FA01C11B3C7B75737D1C0BE1AC08626C76111FB | |||
| 668 | Installer.exe | C:\Users\admin\AppData\Local\Temp\hollow.mp3 | binary | |
MD5:95159E2450765082DA15F9FAB538F3E9 | SHA256:34F682606A43AACBF9DF3E43FC190AF07E99544C3B92080B5BC56E899D21EC53 | |||
| 188 | DrvSetup86.exe | C:\Users\admin\AppData\Local\Temp\{7a340a88-b532-1c38-963d-1d1894ed2b55}\CH341DLL.DLL | executable | |
MD5:D84B4C0F270EA6EA91A0DDAD53B88C2B | SHA256:48E025E8D4D3320B273B3A2F029FB33A877EA94EE0A2A7943EE181209FC412A2 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |