File name:

BEHRINGER_2902_X64_2.8.40.zip

Full analysis: https://app.any.run/tasks/59008256-1a27-405b-b3f3-bdc71879e605
Verdict: Malicious activity
Analysis date: January 18, 2025, 20:47:02
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
arch-doc
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=store
MD5:

E4462F7F5B17586F6201856F2A882975

SHA1:

CBD4E0865464FC7158A8ACBF437AD7DFE2C90F8D

SHA256:

7C2367B685EE233BF17617845A8609F7F09F48AA511842A4B17EA1D09043F061

SSDEEP:

24576:uCh9ruVwh9HAO7Mt4ZmfaUiWDOIYoRYCAAMFuW3o+paPUW17HQg/uFBB/XsNCr22:uCh96Vwh9HAO7Mt4ZmfaaDOIYoRYCApt

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Drops a system driver (possible attempt to evade defenses)

      • WinRAR.exe (PID: 6424)
      • Setup.exe (PID: 6320)
    • Creates files in the driver directory

      • Setup.exe (PID: 6320)
    • Creates or modifies Windows services

      • Setup.exe (PID: 6320)
    • Executable content was dropped or overwritten

      • Setup.exe (PID: 6320)
  • INFO

    • The process uses the downloaded file

      • WinRAR.exe (PID: 6424)
    • Manual execution by a user

      • Setup.exe (PID: 6252)
      • Setup.exe (PID: 6320)
    • Reads the computer name

      • Setup.exe (PID: 6320)
    • Sends debugging messages

      • Setup.exe (PID: 6320)
    • The sample compiled with german language support

      • WinRAR.exe (PID: 6424)
    • Checks supported languages

      • Setup.exe (PID: 6320)
    • Reads Environment values

      • Setup.exe (PID: 6320)
    • Create files in a temporary directory

      • Setup.exe (PID: 6320)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 6424)
    • The sample compiled with english language support

      • WinRAR.exe (PID: 6424)
      • Setup.exe (PID: 6320)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2014:02:27 10:09:30
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: BEHRINGER_2902_X64_2.8.40/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
133
Monitored processes
4
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe rundll32.exe no specs setup.exe no specs setup.exe

Process information

PID
CMD
Path
Indicators
Parent process
6252"C:\Users\admin\Desktop\BEHRINGER_2902_X64_2.8.40\BEHRINGER_2902_X64_2.8.40\Setup.exe" C:\Users\admin\Desktop\BEHRINGER_2902_X64_2.8.40\BEHRINGER_2902_X64_2.8.40\Setup.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
usb-audio.de Installer
Exit code:
3221226540
Version:
v2.8.40
Modules
Images
c:\users\admin\desktop\behringer_2902_x64_2.8.40\behringer_2902_x64_2.8.40\setup.exe
c:\windows\system32\ntdll.dll
6320"C:\Users\admin\Desktop\BEHRINGER_2902_X64_2.8.40\BEHRINGER_2902_X64_2.8.40\Setup.exe" C:\Users\admin\Desktop\BEHRINGER_2902_X64_2.8.40\BEHRINGER_2902_X64_2.8.40\Setup.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Description:
usb-audio.de Installer
Version:
v2.8.40
Modules
Images
c:\users\admin\desktop\behringer_2902_x64_2.8.40\behringer_2902_x64_2.8.40\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\wininet.dll
c:\windows\system32\ucrtbase.dll
6424"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\BEHRINGER_2902_X64_2.8.40.zipC:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
7156C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -EmbeddingC:\Windows\System32\rundll32.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shcore.dll
c:\windows\system32\imagehlp.dll
Total events
2 339
Read events
2 313
Write events
13
Delete events
13

Modification events

(PID) Process:(6424) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(6424) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(6424) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(6424) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\BEHRINGER_2902_X64_2.8.40.zip
(PID) Process:(6424) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(6424) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(6424) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(6424) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(6424) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\DialogEditHistory\ExtrPath
Operation:delete valueName:15
Value:
(PID) Process:(6424) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\DialogEditHistory\ExtrPath
Operation:delete valueName:14
Value:
Executable files
19
Suspicious files
4
Text files
47
Unknown types
0

Dropped files

PID
Process
Filename
Type
6424WinRAR.exeC:\Users\admin\AppData\Local\Temp\BEHRINGER_2902_X64_2.8.40\BEHRINGER_2902_X64_2.8.40\BEHRINGER_2902_X64_2.8.40\busbasio.dllexecutable
MD5:1D01343955E3FBD494B797B8A3735589
SHA256:E7E34100A8134D2BF83F7E714C628C062D415782958A4F191496C60BBE50E98F
6424WinRAR.exeC:\Users\admin\AppData\Local\Temp\BEHRINGER_2902_X64_2.8.40\BEHRINGER_2902_X64_2.8.40\BEHRINGER_2902_X64_2.8.40\busbwdm.inftext
MD5:60815615217C3534946ED8951869A66B
SHA256:475891530FC78E220F9AE949BC16C8EFA9DCB40B09D8E029A22C794A29C8C955
6424WinRAR.exeC:\Users\admin\AppData\Local\Temp\BEHRINGER_2902_X64_2.8.40\BEHRINGER_2902_X64_2.8.40\BEHRINGER_2902_X64_2.8.40\busb2902.catbinary
MD5:A3B4E9A21DD797611F40B4019A1A62B3
SHA256:A91E69C26B740EAE4467349D20D858E75CB71544A2A2371CC8B1CDC6E5B3B28F
6424WinRAR.exeC:\Users\admin\AppData\Local\Temp\BEHRINGER_2902_X64_2.8.40\BEHRINGER_2902_X64_2.8.40\BEHRINGER_2902_X64_2.8.40\Images\Status_1_2.bmpimage
MD5:AC28378EAE215E090A2FF9CFAF75F5D1
SHA256:786DB8CA84E30FC9BFCC4D5740F8BD4D1048C02C008C1FD85AE4048EE87737DE
6424WinRAR.exeC:\Users\admin\AppData\Local\Temp\BEHRINGER_2902_X64_2.8.40\BEHRINGER_2902_X64_2.8.40\BEHRINGER_2902_X64_2.8.40\busbasio_x64.dllexecutable
MD5:41C98D45C1F5148BB877E43AF02A12C3
SHA256:D4E6238EF2233EB6622B513BA5F74C33DB7981B1BFA8E3B7B3A587B98F3E230A
6424WinRAR.exeC:\Users\admin\AppData\Local\Temp\BEHRINGER_2902_X64_2.8.40\BEHRINGER_2902_X64_2.8.40\BEHRINGER_2902_X64_2.8.40\busbwdm.catbinary
MD5:ABB92FD0607BD4F9A228ABE3B7585C93
SHA256:C463DE3B065A59EA4EA2D2C6AFD3B18E6AB876FE66FE1FB78C1BE920E14C7012
6424WinRAR.exeC:\Users\admin\AppData\Local\Temp\BEHRINGER_2902_X64_2.8.40\BEHRINGER_2902_X64_2.8.40\BEHRINGER_2902_X64_2.8.40\Images\Status_1_4.bmpimage
MD5:DA42645BAD1877FCA30CBB05EBF3AFF9
SHA256:DD9C0B891AD9591931E8C19C213C4E63886EDDAD6BACD9DF55559A4950C4368D
6424WinRAR.exeC:\Users\admin\AppData\Local\Temp\BEHRINGER_2902_X64_2.8.40\BEHRINGER_2902_X64_2.8.40\BEHRINGER_2902_X64_2.8.40\Images\Status_1_1.bmpimage
MD5:1759DC299F167186FEF04EEE434E2738
SHA256:D5CC9D241CE73AF4D9A52FC6633CD59ED4F5DD70E55E7842D88AF34D2FE9C7A9
6424WinRAR.exeC:\Users\admin\AppData\Local\Temp\BEHRINGER_2902_X64_2.8.40\BEHRINGER_2902_X64_2.8.40\BEHRINGER_2902_X64_2.8.40\Images\Status_1_3.bmpimage
MD5:AC28378EAE215E090A2FF9CFAF75F5D1
SHA256:786DB8CA84E30FC9BFCC4D5740F8BD4D1048C02C008C1FD85AE4048EE87737DE
6424WinRAR.exeC:\Users\admin\AppData\Local\Temp\BEHRINGER_2902_X64_2.8.40\BEHRINGER_2902_X64_2.8.40\BEHRINGER_2902_X64_2.8.40\Images\Status_1_6.bmpimage
MD5:B20EE20A5CDBBCFC1506846FE98E4976
SHA256:06FD1C481DE0E7068F5C5F1AFA4FC625BD191DB33FF4D39FFC00DB57811E887B
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
34
DNS requests
18
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
23.48.23.158:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6016
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
6672
backgroundTaskHost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
6016
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
5064
SearchApp.exe
2.16.110.171:443
www.bing.com
Akamai International B.V.
DE
whitelisted
6068
svchost.exe
51.104.136.2:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4712
MoUsoCoreWorker.exe
51.104.136.2:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
51.104.136.2:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
23.48.23.158:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
20.190.159.71:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
www.bing.com
  • 2.16.110.171
  • 2.16.110.121
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
crl.microsoft.com
  • 23.48.23.158
  • 23.48.23.140
  • 23.48.23.150
  • 23.48.23.147
  • 23.48.23.156
  • 23.48.23.153
  • 23.48.23.145
  • 23.48.23.138
  • 23.48.23.149
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
login.live.com
  • 20.190.159.71
  • 20.190.159.23
  • 20.190.159.73
  • 20.190.159.68
  • 40.126.31.69
  • 20.190.159.2
  • 40.126.31.73
  • 20.190.159.64
whitelisted
go.microsoft.com
  • 2.23.242.9
whitelisted
settings-win.data.microsoft.com
  • 4.231.128.59
whitelisted
arc.msn.com
  • 20.223.35.26
whitelisted
fd.api.iris.microsoft.com
  • 20.223.35.26
whitelisted
slscr.update.microsoft.com
  • 20.12.23.50
whitelisted

Threats

No threats detected
Process
Message
Setup.exe
System\CurrentControlSet\SERVICES\BEHRINGER_2902
Setup.exe
System\CurrentControlSet\SERVICES\BUSB_AUDIO_WDM