File name:

jopb-injector-89335040.zip

Full analysis: https://app.any.run/tasks/4155bcbd-37f3-43d8-a0f8-4f7dd6778706
Verdict: Malicious activity
Analysis date: November 21, 2020, 16:17:19
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

22FD474318828860662113BF0040511D

SHA1:

4767FA9BEAED4619B527CBC61D760ADC20C178AD

SHA256:

885884C23210E13D101FDB32CCE503452754DFF7CA8DF5E2777DA9219825ED10

SSDEEP:

393216:ZSREC0bltQ8O1cRVTmCcmW1Hh7XLdDOtmODBJ:Yv0xtQ8OiRVgmWNRXLdDOt/Dz

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • CaretVisible.exe (PID: 2996)
      • CaretVisible.exe (PID: 2216)
      • inst.exe (PID: 4040)
      • PcSetup.exe (PID: 536)
    • Drops executable file immediately after starts

      • CaretVisible.exe (PID: 2996)
      • CaretVisible.exe (PID: 2216)
      • PcSetup.exe (PID: 536)
      • DrvInst.exe (PID: 3376)
    • Changes settings of System certificates

      • inst.exe (PID: 4040)
  • SUSPICIOUS

    • Reads the computer name

      • WinRAR.exe (PID: 3344)
      • CaretVisible.tmp (PID: 3104)
      • PcSetup.exe (PID: 536)
      • inst.exe (PID: 4040)
      • CaretVisible.tmp (PID: 2276)
      • DrvInst.exe (PID: 3376)
    • Drops a file with too old compile date

      • WinRAR.exe (PID: 3344)
      • CaretVisible.tmp (PID: 2276)
      • PcSetup.exe (PID: 536)
      • DrvInst.exe (PID: 3376)
      • inst.exe (PID: 4040)
    • Checks supported languages

      • WinRAR.exe (PID: 3344)
      • CaretVisible.tmp (PID: 2276)
      • PcSetup.exe (PID: 536)
    • Reads the date of Windows installation

      • CaretVisible.tmp (PID: 3104)
    • Executable content was dropped or overwritten

      • CaretVisible.exe (PID: 2216)
      • WinRAR.exe (PID: 3344)
      • CaretVisible.exe (PID: 2996)
      • CaretVisible.tmp (PID: 2276)
      • PcSetup.exe (PID: 536)
      • inst.exe (PID: 4040)
      • DrvInst.exe (PID: 3376)
    • Drops a file that was compiled in debug mode

      • CaretVisible.tmp (PID: 2276)
      • PcSetup.exe (PID: 536)
      • inst.exe (PID: 4040)
      • DrvInst.exe (PID: 3376)
    • Reads the Windows organization settings

      • CaretVisible.tmp (PID: 2276)
    • Reads Windows owner or organization settings

      • CaretVisible.tmp (PID: 2276)
    • Creates a directory in Program Files

      • CaretVisible.tmp (PID: 2276)
    • Creates files in the user directory

      • CaretVisible.tmp (PID: 2276)
      • PcSetup.exe (PID: 536)
    • Adds / modifies Windows certificates

      • inst.exe (PID: 4040)
    • Removes files from Windows directory

      • DrvInst.exe (PID: 3376)
    • Creates files in the Windows directory

      • DrvInst.exe (PID: 3376)
    • Creates files in the driver directory

      • DrvInst.exe (PID: 3376)
    • Uses RUNDLL32.EXE to load library

      • DrvInst.exe (PID: 3376)
    • Executed via COM

      • DrvInst.exe (PID: 3376)
      • DrvInst.exe (PID: 3304)
      • DrvInst.exe (PID: 4028)
    • Executed as Windows Service

      • vssvc.exe (PID: 2712)
    • Reads Environment values

      • vssvc.exe (PID: 2712)
  • INFO

    • Application was dropped or rewritten from another process

      • CaretVisible.tmp (PID: 3104)
      • CaretVisible.tmp (PID: 2276)
    • Creates files in the program directory

      • CaretVisible.tmp (PID: 2276)
    • Creates a software uninstall entry

      • CaretVisible.tmp (PID: 2276)
    • Checks Windows Trust Settings

      • inst.exe (PID: 4040)
      • DrvInst.exe (PID: 3376)
      • rundll32.exe (PID: 3752)
    • Reads settings of System Certificates

      • inst.exe (PID: 4040)
      • DrvInst.exe (PID: 3376)
      • rundll32.exe (PID: 3752)
    • Loads dropped or rewritten executable

      • CaretVisible.tmp (PID: 2276)
    • Reads the computer name

      • rundll32.exe (PID: 3752)
      • vssvc.exe (PID: 2712)
    • Checks supported languages

      • rundll32.exe (PID: 3752)
    • Searches for installed software

      • DrvInst.exe (PID: 3376)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2020:10:21 21:24:14
ZipCRC: 0x09f882c6
ZipCompressedSize: 2916667
ZipUncompressedSize: 3000008
ZipFileName: CaretVisible.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
51
Monitored processes
12
Malicious processes
7
Suspicious processes
1

Behavior graph

Click at the process to see the details
drop and start start drop and start drop and start drop and start drop and start winrar.exe caretvisible.exe caretvisible.tmp no specs caretvisible.exe caretvisible.tmp pcsetup.exe inst.exe drvinst.exe rundll32.exe no specs vssvc.exe no specs drvinst.exe no specs drvinst.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
536"C:\Program Files\vso\tools\..\pcsetup\PcSetup.exe" /install2C:\Program Files\vso\pcsetup\PcSetup.exe
CaretVisible.tmp
User:
admin
Company:
VSO Software SARL
Integrity Level:
HIGH
Description:
Patin-couffin drivers installation and configuration tool
Exit code:
0
Version:
1.37.0.94
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\sechost.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\winmm.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msctf.dll
c:\windows\system32\user32.dll
2216"C:\Users\admin\AppData\Local\Temp\Rar$EXa3344.30734\CaretVisible.exe" /SPAWNWND=$20174 /NOTIFYWND=$40156 C:\Users\admin\AppData\Local\Temp\Rar$EXa3344.30734\CaretVisible.exe
CaretVisible.tmp
User:
admin
Company:
VSO-Software SARL
Integrity Level:
HIGH
Description:
VSO Inspector Setup
Exit code:
0
Version:
Modules
Images
c:\windows\system32\shell32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\imm32.dll
c:\windows\system32\shlwapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\sechost.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\lpk.dll
2276"C:\Users\admin\AppData\Local\Temp\is-CMQCP.tmp\CaretVisible.tmp" /SL5="$30172,2571070,140800,C:\Users\admin\AppData\Local\Temp\Rar$EXa3344.30734\CaretVisible.exe" /SPAWNWND=$20174 /NOTIFYWND=$40156 C:\Users\admin\AppData\Local\Temp\is-CMQCP.tmp\CaretVisible.tmp
CaretVisible.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\windows\system32\msctf.dll
c:\windows\system32\imm32.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\mpr.dll
c:\windows\system32\version.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\sechost.dll
2712C:\Windows\system32\vssvc.exeC:\Windows\system32\vssvc.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft� Volume Shadow Copy Service
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\xolehlp.dll
c:\windows\system32\cryptdll.dll
c:\windows\system32\clusapi.dll
c:\windows\system32\samcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\netutils.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\vsstrace.dll
c:\windows\system32\vssapi.dll
2996"C:\Users\admin\AppData\Local\Temp\Rar$EXa3344.30734\CaretVisible.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3344.30734\CaretVisible.exe
WinRAR.exe
User:
admin
Company:
VSO-Software SARL
Integrity Level:
MEDIUM
Description:
VSO Inspector Setup
Exit code:
0
Version:
Modules
Images
c:\windows\system32\sechost.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\usp10.dll
c:\windows\system32\lpk.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
3104"C:\Users\admin\AppData\Local\Temp\is-SGE0N.tmp\CaretVisible.tmp" /SL5="$40156,2571070,140800,C:\Users\admin\AppData\Local\Temp\Rar$EXa3344.30734\CaretVisible.exe" C:\Users\admin\AppData\Local\Temp\is-SGE0N.tmp\CaretVisible.tmpCaretVisible.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\windows\system32\cryptbase.dll
c:\windows\system32\msctf.dll
c:\windows\system32\imm32.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\mpr.dll
c:\windows\system32\version.dll
c:\windows\system32\msimg32.dll
3304DrvInst.exe "1" "200" "STORAGE\VolumeSnapshot\HarddiskVolumeSnapshot26" "" "" "605d6575f" "00000000" "0000060C" "00000614"C:\Windows\system32\DrvInst.exesvchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\sechost.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\drvinst.exe
3344"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\jopb-injector-89335040.zip"C:\Program Files\WinRAR\WinRAR.exe
Explorer.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\msimg32.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\devobj.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\setupapi.dll
3376DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{64ac08d9-0927-1819-d181-eb7f5b7a1f3b}\pcouffin.inf" "0" "66dafaa73" "000005E0" "WinSta0\Default" "000005E4" "208" "c:\users\admin\appdata\roaming"C:\Windows\system32\DrvInst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\cryptsp.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\drvstore.dll
c:\windows\system32\msctf.dll
c:\windows\system32\imm32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\ole32.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\oleaut32.dll
3752rundll32.exe C:\Windows\system32\pnpui.dll,InstallSecurityPromptRunDllW 20 Global\{42b4ae03-77d4-5be3-330f-5a0699fa965b} Global\{4722f4bb-b185-0573-1863-ce0596175a5d} C:\Windows\System32\DriverStore\Temp\{33b3e23b-bc80-6e28-b841-71012125850c}\pcouffin.inf C:\Windows\System32\DriverStore\Temp\{33b3e23b-bc80-6e28-b841-71012125850c}\pcouffin.catC:\Windows\system32\rundll32.exeDrvInst.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msctf.dll
c:\windows\system32\winspool.drv
c:\windows\system32\imm32.dll
c:\windows\system32\mpr.dll
c:\windows\system32\profapi.dll
c:\windows\system32\userenv.dll
c:\windows\system32\oleaut32.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\ole32.dll
c:\windows\system32\shell32.dll
Total events
21 145
Read events
20 856
Write events
289
Delete events
0

Modification events

(PID) Process:(3344) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3344) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3344) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\13D\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3344) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3344) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3344) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3344) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3344) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\jopb-injector-89335040.zip
(PID) Process:(3344) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(3344) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
Executable files
13
Suspicious files
22
Text files
57
Unknown types
26

Dropped files

PID
Process
Filename
Type
3344WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3344.30734\jopb-injector-89335040.exeexecutable
MD5:
SHA256:
2276CaretVisible.tmpC:\Program Files\vso\pcsetup\is-D06DG.tmpexecutable
MD5:9338A77C9FA83B346D3C32B0CE76DB52
SHA256:04EBC1EE4769A50452AE5C7656F8A0F1D807AAB2DFD8AB7AA69066A2596C4F23
2996CaretVisible.exeC:\Users\admin\AppData\Local\Temp\is-SGE0N.tmp\CaretVisible.tmpexecutable
MD5:8FD32D871DFD28C4519CD9C96A120026
SHA256:0C340A0C550CDE8D73F7B109416FAF9A1243C5BEBCC5477123CB97028BA01088
2276CaretVisible.tmpC:\Users\admin\AppData\Local\Temp\is-FN75H.tmp\_isetup\_shfoldr.dllexecutable
MD5:92DC6EF532FBB4A5C3201469A5B5EB63
SHA256:9884E9D1B4F8A873CCBD81F8AD0AE257776D2348D027D811A56475E028360D87
2276CaretVisible.tmpC:\Program Files\vso\tools\is-DPRA5.tmpexecutable
MD5:2FC6E65E55CB23F5EB4D84CFE4FA4DE2
SHA256:6C7B801E4CB603F6C2462F856E0C2BF7B6FDC8F2CC9F08B2CED8659547EA7BEC
2276CaretVisible.tmpC:\Program Files\vso\tools\is-TJVNL.tmptext
MD5:3910760606AB91E89408EBC9A33F690A
SHA256:DA9909AA268596794FD50494BC122AC0CA4ACA61F79CA3256D120DFC4755A192
3344WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3344.30734\CaretVisible.exeexecutable
MD5:A01ED0BB98D773CA0E62EAE975D0B432
SHA256:1451C3D4AC1A6A35F94211264A0FF9494AD15145820B81B0E48C69E0C24629E3
2276CaretVisible.tmpC:\Program Files\vso\tools\Lang\is-7TOCB.tmpimage
MD5:7E31A50D2B9DC868CDD1BC8F8F6F795C
SHA256:53FCBB89235AA5815A41CF340C13A57A9BBDC954810772AFAB9526DEB4930F13
2276CaretVisible.tmpC:\Program Files\vso\tools\Lang\is-42LUK.tmpimage
MD5:B2F7BB9F65F3159CC18F003CA172E8E7
SHA256:F77C22EA23EB99BA6CA997188F95A36FC07EAE0B288C6B1226F556D0D1020E3E
2276CaretVisible.tmpC:\Program Files\vso\tools\Lang\is-CRFKF.tmpimage
MD5:A2680E901DFD0BBDD8886398F5ECBE48
SHA256:06D77C6B014961FF3B82D71EE6CA5F621E9ED20823B1742A584CB5907126C254
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info