File name:

CameraFirmwareUpdatedTool_1.8.19.zip

Full analysis: https://app.any.run/tasks/11726715-8c9d-4409-9c5e-19c942c5ecb5
Verdict: Malicious activity
Analysis date: January 04, 2024, 15:30:23
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

642025247C71B0754565A1C0B3EFC5C3

SHA1:

203D211E4DC87B942E25CE0808ADFC9D427A4ADD

SHA256:

8DD81373464D56F40E2A839CE6EA77E7D1D817EE755E9F2401CA37223C43D8C7

SSDEEP:

196608:4AvJPf25/pXcKLccaFEjEfmCkh3vcDUUcAY914ptS71CDyxZt:65/xcRFH2h/cDUYi14psIDybt

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Creates a writable file in the system directory

      • RTK197F.tmp.exe (PID: 532)
      • RTK3B3F.tmp.exe (PID: 1928)
      • RTK5B89.tmp.exe (PID: 1880)
      • RTK754B.tmp.exe (PID: 984)
      • RTKE7CB.tmp.exe (PID: 2364)
  • SUSPICIOUS

    • Reads the Internet Settings

      • CameraFirmwareUpdatedTool.exe (PID: 1392)
      • CameraFirmwareUpdatedTool.exe (PID: 1816)
      • CameraFirmwareUpdatedTool.exe (PID: 2628)
      • CameraFirmwareUpdatedTool.exe (PID: 3060)
      • CameraFirmwareUpdatedTool.exe (PID: 2052)
    • Drops a system driver (possible attempt to evade defenses)

      • RTK197F.tmp.exe (PID: 532)
      • RTK3B3F.tmp.exe (PID: 1928)
      • RTK5B89.tmp.exe (PID: 1880)
      • RTK754B.tmp.exe (PID: 984)
      • RTKE7CB.tmp.exe (PID: 2364)
    • Creates files in the driver directory

      • RTK197F.tmp.exe (PID: 532)
      • RTK3B3F.tmp.exe (PID: 1928)
      • RTK5B89.tmp.exe (PID: 1880)
      • RTK754B.tmp.exe (PID: 984)
      • RTKE7CB.tmp.exe (PID: 2364)
  • INFO

    • Checks supported languages

      • CameraFirmwareUpdatedTool.exe (PID: 1392)
      • RTK197F.tmp.exe (PID: 532)
      • CameraFirmwareUpdatedTool.exe (PID: 2628)
      • CameraFirmwareUpdatedTool.exe (PID: 1816)
      • RTK3B3F.tmp.exe (PID: 1928)
      • RTK5B89.tmp.exe (PID: 1880)
      • CameraFirmwareUpdatedTool.exe (PID: 2052)
      • CameraFirmwareUpdatedTool.exe (PID: 3060)
      • RTKE7CB.tmp.exe (PID: 2364)
      • RTK754B.tmp.exe (PID: 984)
    • Reads the computer name

      • CameraFirmwareUpdatedTool.exe (PID: 1392)
      • RTK197F.tmp.exe (PID: 532)
      • RTK3B3F.tmp.exe (PID: 1928)
      • CameraFirmwareUpdatedTool.exe (PID: 2628)
      • CameraFirmwareUpdatedTool.exe (PID: 1816)
      • RTK5B89.tmp.exe (PID: 1880)
      • CameraFirmwareUpdatedTool.exe (PID: 2052)
      • CameraFirmwareUpdatedTool.exe (PID: 3060)
      • RTKE7CB.tmp.exe (PID: 2364)
      • RTK754B.tmp.exe (PID: 984)
    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 2184)
      • CameraFirmwareUpdatedTool.exe (PID: 1392)
      • RTK197F.tmp.exe (PID: 532)
      • RTK3B3F.tmp.exe (PID: 1928)
      • CameraFirmwareUpdatedTool.exe (PID: 1816)
      • RTK5B89.tmp.exe (PID: 1880)
      • CameraFirmwareUpdatedTool.exe (PID: 2052)
      • CameraFirmwareUpdatedTool.exe (PID: 2628)
      • CameraFirmwareUpdatedTool.exe (PID: 3060)
      • RTK754B.tmp.exe (PID: 984)
      • RTKE7CB.tmp.exe (PID: 2364)
    • Create files in a temporary directory

      • CameraFirmwareUpdatedTool.exe (PID: 1392)
      • RTK197F.tmp.exe (PID: 532)
      • RTK3B3F.tmp.exe (PID: 1928)
      • CameraFirmwareUpdatedTool.exe (PID: 1816)
      • RTK5B89.tmp.exe (PID: 1880)
      • CameraFirmwareUpdatedTool.exe (PID: 2052)
      • CameraFirmwareUpdatedTool.exe (PID: 2628)
      • CameraFirmwareUpdatedTool.exe (PID: 3060)
      • RTK754B.tmp.exe (PID: 984)
      • RTKE7CB.tmp.exe (PID: 2364)
    • Manual execution by a user

      • CameraFirmwareUpdatedTool.exe (PID: 2296)
      • CameraFirmwareUpdatedTool.exe (PID: 2628)
      • CameraFirmwareUpdatedTool.exe (PID: 1816)
      • CameraFirmwareUpdatedTool.exe (PID: 2052)
      • cmd.exe (PID: 908)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2021:08:19 20:17:02
ZipCRC: 0x3f8bc7d2
ZipCompressedSize: 7508798
ZipUncompressedSize: 15439360
ZipFileName: CameraFirmwareUpdatedTool.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
63
Monitored processes
14
Malicious processes
1
Suspicious processes
9

Behavior graph

Click at the process to see the details
start winrar.exe no specs camerafirmwareupdatedtool.exe no specs camerafirmwareupdatedtool.exe rtk197f.tmp.exe camerafirmwareupdatedtool.exe rtk3b3f.tmp.exe camerafirmwareupdatedtool.exe no specs camerafirmwareupdatedtool.exe rtk5b89.tmp.exe camerafirmwareupdatedtool.exe rtk754b.tmp.exe cmd.exe camerafirmwareupdatedtool.exe no specs rtke7cb.tmp.exe

Process information

PID
CMD
Path
Indicators
Parent process
532"C:\Users\admin\AppData\Local\Temp\RTK197F.tmp.exe" C:\Users\admin\AppData\Local\Temp\RTK197F.tmp.exe
CameraFirmwareUpdatedTool.exe
User:
admin
Company:
Realtek Semiconductor
Integrity Level:
HIGH
Description:
Realtek Camera firmware update tool
Exit code:
1
Version:
1.7.23.0
Modules
Images
c:\users\admin\appdata\local\temp\rtk197f.tmp.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
908"C:\Windows\System32\cmd.exe" C:\Windows\System32\cmd.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
984"C:\Users\admin\AppData\Local\Temp\RTK754B.tmp.exe" C:\Users\admin\AppData\Local\Temp\RTK754B.tmp.exe
CameraFirmwareUpdatedTool.exe
User:
admin
Company:
Realtek Semiconductor
Integrity Level:
HIGH
Description:
Realtek Camera firmware update tool
Exit code:
1
Version:
1.7.23.0
Modules
Images
c:\users\admin\appdata\local\temp\rtk754b.tmp.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1392"C:\Users\admin\AppData\Local\Temp\Rar$EXa2184.22234\CameraFirmwareUpdatedTool.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa2184.22234\CameraFirmwareUpdatedTool.exe
WinRAR.exe
User:
admin
Company:
Realtek Semiconductor Corp.
Integrity Level:
HIGH
Description:
CameraFirmwareUpdatedTool_Dell
Exit code:
0
Version:
1.8.19.1
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2184.22234\camerafirmwareupdatedtool.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msimg32.dll
1404"C:\Users\admin\AppData\Local\Temp\Rar$EXa2184.22234\CameraFirmwareUpdatedTool.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa2184.22234\CameraFirmwareUpdatedTool.exeWinRAR.exe
User:
admin
Company:
Realtek Semiconductor Corp.
Integrity Level:
MEDIUM
Description:
CameraFirmwareUpdatedTool_Dell
Exit code:
3221226540
Version:
1.8.19.1
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2184.22234\camerafirmwareupdatedtool.exe
c:\windows\system32\ntdll.dll
1816"C:\Users\admin\Desktop\CameraFirmwareUpdatedTool.exe" C:\Users\admin\Desktop\CameraFirmwareUpdatedTool.exe
explorer.exe
User:
admin
Company:
Realtek Semiconductor Corp.
Integrity Level:
HIGH
Description:
CameraFirmwareUpdatedTool_Dell
Exit code:
0
Version:
1.8.19.1
Modules
Images
c:\users\admin\desktop\camerafirmwareupdatedtool.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msimg32.dll
1880"C:\Users\admin\AppData\Local\Temp\RTK5B89.tmp.exe" C:\Users\admin\AppData\Local\Temp\RTK5B89.tmp.exe
CameraFirmwareUpdatedTool.exe
User:
admin
Company:
Realtek Semiconductor
Integrity Level:
HIGH
Description:
Realtek Camera firmware update tool
Exit code:
1
Version:
1.7.23.0
Modules
Images
c:\users\admin\appdata\local\temp\rtk5b89.tmp.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1928"C:\Users\admin\AppData\Local\Temp\RTK3B3F.tmp.exe" C:\Users\admin\AppData\Local\Temp\RTK3B3F.tmp.exe
CameraFirmwareUpdatedTool.exe
User:
admin
Company:
Realtek Semiconductor
Integrity Level:
HIGH
Description:
Realtek Camera firmware update tool
Exit code:
1
Version:
1.7.23.0
Modules
Images
c:\users\admin\appdata\local\temp\rtk3b3f.tmp.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
2052"C:\Users\admin\Desktop\CameraFirmwareUpdatedTool.exe" C:\Users\admin\Desktop\CameraFirmwareUpdatedTool.exe
explorer.exe
User:
admin
Company:
Realtek Semiconductor Corp.
Integrity Level:
HIGH
Description:
CameraFirmwareUpdatedTool_Dell
Exit code:
0
Version:
1.8.19.1
Modules
Images
c:\users\admin\desktop\camerafirmwareupdatedtool.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msimg32.dll
2184"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\CameraFirmwareUpdatedTool_1.8.19.zip"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
Total events
5 186
Read events
5 118
Write events
68
Delete events
0

Modification events

(PID) Process:(2184) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2184) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(2184) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(2184) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(2184) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(2184) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2184) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2184) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2184) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2184) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
Executable files
19
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
1392CameraFirmwareUpdatedTool.exeC:\Users\admin\AppData\Local\Temp\RTK197F.tmp.exeexecutable
MD5:33BC056756C61C33686CB9340F40E4CA
SHA256:2A1E6426A52ACC3881886C5F430D843151E4CE37E456A82D8A155F7B3CC52648
532RTK197F.tmp.exeC:\Windows\system32\drivers\RtsUpx.sysexecutable
MD5:F5468C18887C1560D2D425725593B7C9
SHA256:2BDDAD4026875DA8A2C101D1556C7E4660B57D7CBFDE82C91E34764B561D6972
532RTK197F.tmp.exeC:\Users\admin\AppData\Local\Temp\RtsUpx_n.sysexecutable
MD5:F5468C18887C1560D2D425725593B7C9
SHA256:2BDDAD4026875DA8A2C101D1556C7E4660B57D7CBFDE82C91E34764B561D6972
1392CameraFirmwareUpdatedTool.exeC:\Users\admin\AppData\Local\Temp\config.initext
MD5:3B93EB7BF73AAAF9B86D42FBB805B31F
SHA256:600C2585135A4A1C3272A1925E3036064BAE71C560A5DA27DD65C90D3F266141
2184WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2184.22234\CameraFirmwareUpdatedTool.exeexecutable
MD5:25FD330F8559E65919D5412352DBE6FE
SHA256:ED68BD73C4EF3953016539AEBE99FB379421117545631F0F75528DB74C39A232
2628CameraFirmwareUpdatedTool.exeC:\Users\admin\AppData\Local\Temp\RTK5B89.tmp.exeexecutable
MD5:33BC056756C61C33686CB9340F40E4CA
SHA256:2A1E6426A52ACC3881886C5F430D843151E4CE37E456A82D8A155F7B3CC52648
3060CameraFirmwareUpdatedTool.exeC:\Users\admin\AppData\Local\Temp\RTKE7CB.tmp.exeexecutable
MD5:33BC056756C61C33686CB9340F40E4CA
SHA256:2A1E6426A52ACC3881886C5F430D843151E4CE37E456A82D8A155F7B3CC52648
984RTK754B.tmp.exeC:\Users\admin\AppData\Local\Temp\RtsUpx_s.sysexecutable
MD5:F5468C18887C1560D2D425725593B7C9
SHA256:2BDDAD4026875DA8A2C101D1556C7E4660B57D7CBFDE82C91E34764B561D6972
1880RTK5B89.tmp.exeC:\Windows\system32\drivers\RtsUpx.sysexecutable
MD5:F5468C18887C1560D2D425725593B7C9
SHA256:2BDDAD4026875DA8A2C101D1556C7E4660B57D7CBFDE82C91E34764B561D6972
2364RTKE7CB.tmp.exeC:\Windows\system32\drivers\RtsUpx.sysexecutable
MD5:F5468C18887C1560D2D425725593B7C9
SHA256:2BDDAD4026875DA8A2C101D1556C7E4660B57D7CBFDE82C91E34764B561D6972
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown

DNS requests

No data

Threats

No threats detected
Process
Message
RTK197F.tmp.exe
Before SetEvent
RTK197F.tmp.exe
CDevFlow::DEV_GetDefaultDeviceForAllInOne()
RTK197F.tmp.exe
CDevFlow::DEV_CloseDevice()
RTK3B3F.tmp.exe
Before SetEvent
RTK3B3F.tmp.exe
CDevFlow::DEV_GetDefaultDeviceForAllInOne()
RTK3B3F.tmp.exe
CDevFlow::DEV_CloseDevice()
RTK5B89.tmp.exe
CDevFlow::DEV_GetDefaultDeviceForAllInOne()
RTK5B89.tmp.exe
Before SetEvent
RTK5B89.tmp.exe
CDevFlow::DEV_CloseDevice()
RTK754B.tmp.exe
CDevFlow::DEV_GetDefaultDeviceForAllInOne()