| File name: | jopb-injector-89335040.zip |
| Full analysis: | https://app.any.run/tasks/4155bcbd-37f3-43d8-a0f8-4f7dd6778706 |
| Verdict: | Malicious activity |
| Analysis date: | November 21, 2020, 16:17:19 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract |
| MD5: | 22FD474318828860662113BF0040511D |
| SHA1: | 4767FA9BEAED4619B527CBC61D760ADC20C178AD |
| SHA256: | 885884C23210E13D101FDB32CCE503452754DFF7CA8DF5E2777DA9219825ED10 |
| SSDEEP: | 393216:ZSREC0bltQ8O1cRVTmCcmW1Hh7XLdDOtmODBJ:Yv0xtQ8OiRVgmWNRXLdDOt/Dz |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 20 |
|---|---|
| ZipBitFlag: | - |
| ZipCompression: | Deflated |
| ZipModifyDate: | 2020:10:21 21:24:14 |
| ZipCRC: | 0x09f882c6 |
| ZipCompressedSize: | 2916667 |
| ZipUncompressedSize: | 3000008 |
| ZipFileName: | CaretVisible.exe |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 536 | "C:\Program Files\vso\tools\..\pcsetup\PcSetup.exe" /install2 | C:\Program Files\vso\pcsetup\PcSetup.exe | CaretVisible.tmp | ||||||||||||
User: admin Company: VSO Software SARL Integrity Level: HIGH Description: Patin-couffin drivers installation and configuration tool Exit code: 0 Version: 1.37.0.94 Modules
| |||||||||||||||
| 2216 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa3344.30734\CaretVisible.exe" /SPAWNWND=$20174 /NOTIFYWND=$40156 | C:\Users\admin\AppData\Local\Temp\Rar$EXa3344.30734\CaretVisible.exe | CaretVisible.tmp | ||||||||||||
User: admin Company: VSO-Software SARL Integrity Level: HIGH Description: VSO Inspector Setup Exit code: 0 Version: Modules
| |||||||||||||||
| 2276 | "C:\Users\admin\AppData\Local\Temp\is-CMQCP.tmp\CaretVisible.tmp" /SL5="$30172,2571070,140800,C:\Users\admin\AppData\Local\Temp\Rar$EXa3344.30734\CaretVisible.exe" /SPAWNWND=$20174 /NOTIFYWND=$40156 | C:\Users\admin\AppData\Local\Temp\is-CMQCP.tmp\CaretVisible.tmp | CaretVisible.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 Modules
| |||||||||||||||
| 2712 | C:\Windows\system32\vssvc.exe | C:\Windows\system32\vssvc.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft� Volume Shadow Copy Service Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2996 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa3344.30734\CaretVisible.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa3344.30734\CaretVisible.exe | WinRAR.exe | ||||||||||||
User: admin Company: VSO-Software SARL Integrity Level: MEDIUM Description: VSO Inspector Setup Exit code: 0 Version: Modules
| |||||||||||||||
| 3104 | "C:\Users\admin\AppData\Local\Temp\is-SGE0N.tmp\CaretVisible.tmp" /SL5="$40156,2571070,140800,C:\Users\admin\AppData\Local\Temp\Rar$EXa3344.30734\CaretVisible.exe" | C:\Users\admin\AppData\Local\Temp\is-SGE0N.tmp\CaretVisible.tmp | — | CaretVisible.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 Modules
| |||||||||||||||
| 3304 | DrvInst.exe "1" "200" "STORAGE\VolumeSnapshot\HarddiskVolumeSnapshot26" "" "" "605d6575f" "00000000" "0000060C" "00000614" | C:\Windows\system32\DrvInst.exe | — | svchost.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Driver Installation Module Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3344 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\jopb-injector-89335040.zip" | C:\Program Files\WinRAR\WinRAR.exe | Explorer.EXE | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.60.0 Modules
| |||||||||||||||
| 3376 | DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{64ac08d9-0927-1819-d181-eb7f5b7a1f3b}\pcouffin.inf" "0" "66dafaa73" "000005E0" "WinSta0\Default" "000005E4" "208" "c:\users\admin\appdata\roaming" | C:\Windows\system32\DrvInst.exe | svchost.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Driver Installation Module Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3752 | rundll32.exe C:\Windows\system32\pnpui.dll,InstallSecurityPromptRunDllW 20 Global\{42b4ae03-77d4-5be3-330f-5a0699fa965b} Global\{4722f4bb-b185-0573-1863-ce0596175a5d} C:\Windows\System32\DriverStore\Temp\{33b3e23b-bc80-6e28-b841-71012125850c}\pcouffin.inf C:\Windows\System32\DriverStore\Temp\{33b3e23b-bc80-6e28-b841-71012125850c}\pcouffin.cat | C:\Windows\system32\rundll32.exe | — | DrvInst.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows host process (Rundll32) Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (3344) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (3344) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (3344) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\13D\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3344) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (3344) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (3344) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (3344) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (3344) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\jopb-injector-89335040.zip | |||
| (PID) Process: | (3344) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip | |||
| (PID) Process: | (3344) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3344 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3344.30734\jopb-injector-89335040.exe | executable | |
MD5:— | SHA256:— | |||
| 2276 | CaretVisible.tmp | C:\Program Files\vso\pcsetup\is-D06DG.tmp | executable | |
MD5:9338A77C9FA83B346D3C32B0CE76DB52 | SHA256:04EBC1EE4769A50452AE5C7656F8A0F1D807AAB2DFD8AB7AA69066A2596C4F23 | |||
| 2996 | CaretVisible.exe | C:\Users\admin\AppData\Local\Temp\is-SGE0N.tmp\CaretVisible.tmp | executable | |
MD5:8FD32D871DFD28C4519CD9C96A120026 | SHA256:0C340A0C550CDE8D73F7B109416FAF9A1243C5BEBCC5477123CB97028BA01088 | |||
| 2276 | CaretVisible.tmp | C:\Users\admin\AppData\Local\Temp\is-FN75H.tmp\_isetup\_shfoldr.dll | executable | |
MD5:92DC6EF532FBB4A5C3201469A5B5EB63 | SHA256:9884E9D1B4F8A873CCBD81F8AD0AE257776D2348D027D811A56475E028360D87 | |||
| 2276 | CaretVisible.tmp | C:\Program Files\vso\tools\is-DPRA5.tmp | executable | |
MD5:2FC6E65E55CB23F5EB4D84CFE4FA4DE2 | SHA256:6C7B801E4CB603F6C2462F856E0C2BF7B6FDC8F2CC9F08B2CED8659547EA7BEC | |||
| 2276 | CaretVisible.tmp | C:\Program Files\vso\tools\is-TJVNL.tmp | text | |
MD5:3910760606AB91E89408EBC9A33F690A | SHA256:DA9909AA268596794FD50494BC122AC0CA4ACA61F79CA3256D120DFC4755A192 | |||
| 3344 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3344.30734\CaretVisible.exe | executable | |
MD5:A01ED0BB98D773CA0E62EAE975D0B432 | SHA256:1451C3D4AC1A6A35F94211264A0FF9494AD15145820B81B0E48C69E0C24629E3 | |||
| 2276 | CaretVisible.tmp | C:\Program Files\vso\tools\Lang\is-7TOCB.tmp | image | |
MD5:7E31A50D2B9DC868CDD1BC8F8F6F795C | SHA256:53FCBB89235AA5815A41CF340C13A57A9BBDC954810772AFAB9526DEB4930F13 | |||
| 2276 | CaretVisible.tmp | C:\Program Files\vso\tools\Lang\is-42LUK.tmp | image | |
MD5:B2F7BB9F65F3159CC18F003CA172E8E7 | SHA256:F77C22EA23EB99BA6CA997188F95A36FC07EAE0B288C6B1226F556D0D1020E3E | |||
| 2276 | CaretVisible.tmp | C:\Program Files\vso\tools\Lang\is-CRFKF.tmp | image | |
MD5:A2680E901DFD0BBDD8886398F5ECBE48 | SHA256:06D77C6B014961FF3B82D71EE6CA5F621E9ED20823B1742A584CB5907126C254 | |||