File name:

SETUP.EXE

Full analysis: https://app.any.run/tasks/473af344-2074-42c7-9a78-3fa8d829fcf4
Verdict: Malicious activity
Analysis date: June 02, 2025, 13:48:40
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, RAR self-extracting archive, 4 sections
MD5:

6B563BCFDF745B45E032B650CF0BC5DD

SHA1:

4C7278B4FA144D7FC21ABB3EBEAFCF7B51F06076

SHA256:

7E2665E90B09B6D4C72C5DF7E09433178A0F4042B1313B3C40A876CBD12A247A

SSDEEP:

6144:h8U2qy6rRZb7jxGYXl98pbG/9WFb4XAlfMQEUwPffwWR:5zy6rRxEG98w/9WxvJ4oWR

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • SETUP.EXE (PID: 1164)
      • SETUP.EXE (PID: 3208)
      • DRVSETUP64.exe (PID: 1052)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • SETUP.EXE.exe (PID: 5744)
      • drvinst.exe (PID: 6028)
      • DRVSETUP64.exe (PID: 1052)
    • Drops a system driver (possible attempt to evade defenses)

      • SETUP.EXE.exe (PID: 5744)
      • DRVSETUP64.exe (PID: 1052)
      • drvinst.exe (PID: 6028)
    • Creates file in the systems drive root

      • SETUP.EXE.exe (PID: 5744)
    • Reads security settings of Internet Explorer

      • SETUP.EXE.exe (PID: 5744)
    • Creates files in the driver directory

      • drvinst.exe (PID: 6028)
      • DRVSETUP64.exe (PID: 1052)
  • INFO

    • Checks supported languages

      • SETUP.EXE.exe (PID: 5744)
      • SETUP.EXE (PID: 3208)
      • drvinst.exe (PID: 6028)
      • DRVSETUP64.exe (PID: 1052)
    • Reads the computer name

      • SETUP.EXE.exe (PID: 5744)
      • DRVSETUP64.exe (PID: 1052)
      • drvinst.exe (PID: 6028)
    • Process checks computer location settings

      • SETUP.EXE.exe (PID: 5744)
    • The sample compiled with chinese language support

      • SETUP.EXE.exe (PID: 5744)
    • The sample compiled with english language support

      • SETUP.EXE.exe (PID: 5744)
      • drvinst.exe (PID: 6028)
      • DRVSETUP64.exe (PID: 1052)
    • Create files in a temporary directory

      • DRVSETUP64.exe (PID: 1052)
    • Reads the software policy settings

      • drvinst.exe (PID: 6028)
    • Reads the machine GUID from the registry

      • drvinst.exe (PID: 6028)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | WinRAR Self Extracting archive (94.3)
.scr | Windows screen saver (2.3)
.dll | Win32 Dynamic Link Library (generic) (1.1)
.exe | Win32 Executable (generic) (0.8)
.exe | Win32 Executable Watcom C++ (generic) (0.4)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2007:05:22 04:59:14+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 5
CodeSize: 81920
InitializedDataSize: 22016
UninitializedDataSize: -
EntryPoint: 0x1000
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
136
Monitored processes
7
Malicious processes
4
Suspicious processes
1

Behavior graph

Click at the process to see the details
start setup.exe.exe setup.exe no specs sppextcomobj.exe no specs slui.exe setup.exe drvsetup64.exe drvinst.exe

Process information

PID
CMD
Path
Indicators
Parent process
1052C:\WCH.CN\CH341SER\DRVSETUP64\DRVSETUP64.EXEC:\WCH.CN\CH341SER\DRVSETUP64\DRVSETUP64.exe
SETUP.EXE
User:
admin
Integrity Level:
HIGH
Description:
EXE For Driver Installation
Version:
1, 6, 7, 0
Modules
Images
c:\wch.cn\ch341ser\drvsetup64\drvsetup64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
1164"C:\WCH.CN\CH341SER\SETUP.EXE" C:\WCH.CN\CH341SER\SETUP.EXESETUP.EXE.exe
User:
admin
Integrity Level:
MEDIUM
Description:
EXE For Driver Installation
Exit code:
3221226540
Version:
1, 6, 7, 0
Modules
Images
c:\wch.cn\ch341ser\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
1168"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exe
SppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
3208"C:\WCH.CN\CH341SER\SETUP.EXE" C:\WCH.CN\CH341SER\SETUP.EXE
SETUP.EXE.exe
User:
admin
Integrity Level:
HIGH
Description:
EXE For Driver Installation
Exit code:
0
Version:
1, 6, 7, 0
Modules
Images
c:\wch.cn\ch341ser\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acgenral.dll
3300C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
5744"C:\Users\admin\AppData\Local\Temp\SETUP.EXE.exe" C:\Users\admin\AppData\Local\Temp\SETUP.EXE.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\setup.exe.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
6028DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{2f193558-9021-8b4e-abd3-726aff18495a}\CH341SER.INF" "9" "4dbd0d02f" "00000000000001D4" "WinSta0\Default" "00000000000001C0" "208" "C:\WCH.CN\CH341SER"C:\Windows\System32\drvinst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\drvstore.dll
Total events
3 757
Read events
3 755
Write events
2
Delete events
0

Modification events

(PID) Process:(5744) SETUP.EXE.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR SFX
Operation:writeName:C%%WCH.CN%CH341SER
Value:
C:\WCH.CN\CH341SER
(PID) Process:(1052) DRVSETUP64.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\Setup\SetupapiLogStatus
Operation:writeName:setupapi.dev.log
Value:
4096
Executable files
59
Suspicious files
11
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
1052DRVSETUP64.exeC:\Windows\INF\setupapi.dev.log
MD5:
SHA256:
5744SETUP.EXE.exeC:\WCH.CN\CH341SER\CH341S98.SYSexecutable
MD5:B6F4A83911336E84BEAD8F8905285FAB
SHA256:0ECD1222627271EA31D3B64796992B6DAF5133D64CC26D43B3873CBE32FD59CB
1052DRVSETUP64.exeC:\Users\admin\AppData\Local\Temp\{2f193558-9021-8b4e-abd3-726aff18495a}\CH341SER.CATbinary
MD5:715693624013826D337E792ED86376AC
SHA256:585FCA8AB9C8A13222760D6BBAB62CE4069D24F73BD304D89C54B5298B9420BD
6028drvinst.exeC:\Windows\System32\DriverStore\Temp\{1db75c97-45e4-8248-8cce-cd7e4a6de248}\SETAF6.tmpbinary
MD5:0ECFFBA87B80F54F7016DA633DD9AB1C
SHA256:0CBD34F89B0D11B386E07A825FAB531706F86E9DA44DCC536AC7C98A6D22C383
6028drvinst.exeC:\Windows\System32\catroot2\dberr.txt
MD5:
SHA256:
5744SETUP.EXE.exeC:\WCH.CN\CH341SER\DRVSETUP64\DRVSETUP64.exeexecutable
MD5:2B70D894C0CB09118E2112F7456F24B1
SHA256:F4C4DC1B13072C38C0DA57ECC5C2C552AC4A1A681A9DAC7A9195C794D75998BA
5744SETUP.EXE.exeC:\WCH.CN\CH341SER\CH341S64.SYSexecutable
MD5:3C0A1B6F538E00F318C109F4A3F29515
SHA256:DE6CA1AE927081AC622F99AB9C77B2127CBB2DF597B4123A4AA2F3DA52CD64D5
5744SETUP.EXE.exeC:\WCH.CN\CH341SER\CH341PT.DLLexecutable
MD5:69B6FEC924C30042D329AE56CA8925CC
SHA256:45494CE819C1B5C21ABB72DC47A0CA36807E0ED74CE55B631DA174C77A9B24DB
5744SETUP.EXE.exeC:\WCH.CN\CH341SER\CH341SER.INFbinary
MD5:0ECFFBA87B80F54F7016DA633DD9AB1C
SHA256:0CBD34F89B0D11B386E07A825FAB531706F86E9DA44DCC536AC7C98A6D22C383
5744SETUP.EXE.exeC:\WCH.CN\CH341SER\CH341SER.SYSexecutable
MD5:A9FC675D0029A525335B106487C7D578
SHA256:50877BC8EA82BBAC833D25C9AC248E6FC9A240AB3C6D7E2C115667532C23676F
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
12
DNS requests
6
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
5496
MoUsoCoreWorker.exe
40.127.240.158:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
4
System
192.168.100.255:137
whitelisted
7552
svchost.exe
40.127.240.158:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
616
RUXIMICS.exe
40.127.240.158:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
4
System
192.168.100.255:138
whitelisted
7552
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5496
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2112
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2924
SearchApp.exe
92.123.104.52:443
www.bing.com
Akamai International B.V.
DE
unknown
2924
SearchApp.exe
204.79.197.222:443
fp.msedge.net
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
whitelisted
www.bing.com
  • 92.123.104.52
  • 92.123.104.34
  • 92.123.104.38
  • 92.123.104.19
  • 92.123.104.28
  • 92.123.104.59
  • 92.123.104.32
  • 92.123.104.33
whitelisted
fp.msedge.net
  • 204.79.197.222
whitelisted
activation-v2.sls.microsoft.com
whitelisted

Threats

No threats detected
No debug info