| File name: | CameraFirmwareUpdatedTool_1.8.19.zip |
| Full analysis: | https://app.any.run/tasks/11726715-8c9d-4409-9c5e-19c942c5ecb5 |
| Verdict: | Malicious activity |
| Analysis date: | January 04, 2024, 15:30:23 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract |
| MD5: | 642025247C71B0754565A1C0B3EFC5C3 |
| SHA1: | 203D211E4DC87B942E25CE0808ADFC9D427A4ADD |
| SHA256: | 8DD81373464D56F40E2A839CE6EA77E7D1D817EE755E9F2401CA37223C43D8C7 |
| SSDEEP: | 196608:4AvJPf25/pXcKLccaFEjEfmCkh3vcDUUcAY914ptS71CDyxZt:65/xcRFH2h/cDUYi14psIDybt |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 20 |
|---|---|
| ZipBitFlag: | - |
| ZipCompression: | Deflated |
| ZipModifyDate: | 2021:08:19 20:17:02 |
| ZipCRC: | 0x3f8bc7d2 |
| ZipCompressedSize: | 7508798 |
| ZipUncompressedSize: | 15439360 |
| ZipFileName: | CameraFirmwareUpdatedTool.exe |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 532 | "C:\Users\admin\AppData\Local\Temp\RTK197F.tmp.exe" | C:\Users\admin\AppData\Local\Temp\RTK197F.tmp.exe | CameraFirmwareUpdatedTool.exe | ||||||||||||
User: admin Company: Realtek Semiconductor Integrity Level: HIGH Description: Realtek Camera firmware update tool Exit code: 1 Version: 1.7.23.0 Modules
| |||||||||||||||
| 908 | "C:\Windows\System32\cmd.exe" | C:\Windows\System32\cmd.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 984 | "C:\Users\admin\AppData\Local\Temp\RTK754B.tmp.exe" | C:\Users\admin\AppData\Local\Temp\RTK754B.tmp.exe | CameraFirmwareUpdatedTool.exe | ||||||||||||
User: admin Company: Realtek Semiconductor Integrity Level: HIGH Description: Realtek Camera firmware update tool Exit code: 1 Version: 1.7.23.0 Modules
| |||||||||||||||
| 1392 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa2184.22234\CameraFirmwareUpdatedTool.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa2184.22234\CameraFirmwareUpdatedTool.exe | WinRAR.exe | ||||||||||||
User: admin Company: Realtek Semiconductor Corp. Integrity Level: HIGH Description: CameraFirmwareUpdatedTool_Dell Exit code: 0 Version: 1.8.19.1 Modules
| |||||||||||||||
| 1404 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa2184.22234\CameraFirmwareUpdatedTool.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa2184.22234\CameraFirmwareUpdatedTool.exe | — | WinRAR.exe | |||||||||||
User: admin Company: Realtek Semiconductor Corp. Integrity Level: MEDIUM Description: CameraFirmwareUpdatedTool_Dell Exit code: 3221226540 Version: 1.8.19.1 Modules
| |||||||||||||||
| 1816 | "C:\Users\admin\Desktop\CameraFirmwareUpdatedTool.exe" | C:\Users\admin\Desktop\CameraFirmwareUpdatedTool.exe | explorer.exe | ||||||||||||
User: admin Company: Realtek Semiconductor Corp. Integrity Level: HIGH Description: CameraFirmwareUpdatedTool_Dell Exit code: 0 Version: 1.8.19.1 Modules
| |||||||||||||||
| 1880 | "C:\Users\admin\AppData\Local\Temp\RTK5B89.tmp.exe" | C:\Users\admin\AppData\Local\Temp\RTK5B89.tmp.exe | CameraFirmwareUpdatedTool.exe | ||||||||||||
User: admin Company: Realtek Semiconductor Integrity Level: HIGH Description: Realtek Camera firmware update tool Exit code: 1 Version: 1.7.23.0 Modules
| |||||||||||||||
| 1928 | "C:\Users\admin\AppData\Local\Temp\RTK3B3F.tmp.exe" | C:\Users\admin\AppData\Local\Temp\RTK3B3F.tmp.exe | CameraFirmwareUpdatedTool.exe | ||||||||||||
User: admin Company: Realtek Semiconductor Integrity Level: HIGH Description: Realtek Camera firmware update tool Exit code: 1 Version: 1.7.23.0 Modules
| |||||||||||||||
| 2052 | "C:\Users\admin\Desktop\CameraFirmwareUpdatedTool.exe" | C:\Users\admin\Desktop\CameraFirmwareUpdatedTool.exe | explorer.exe | ||||||||||||
User: admin Company: Realtek Semiconductor Corp. Integrity Level: HIGH Description: CameraFirmwareUpdatedTool_Dell Exit code: 0 Version: 1.8.19.1 Modules
| |||||||||||||||
| 2184 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\CameraFirmwareUpdatedTool_1.8.19.zip" | C:\Program Files\WinRAR\WinRAR.exe | — | explorer.exe | |||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| (PID) Process: | (2184) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2184) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip | |||
| (PID) Process: | (2184) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\phacker.zip | |||
| (PID) Process: | (2184) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (2184) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip | |||
| (PID) Process: | (2184) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (2184) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (2184) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (2184) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (2184) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1392 | CameraFirmwareUpdatedTool.exe | C:\Users\admin\AppData\Local\Temp\RTK197F.tmp.exe | executable | |
MD5:33BC056756C61C33686CB9340F40E4CA | SHA256:2A1E6426A52ACC3881886C5F430D843151E4CE37E456A82D8A155F7B3CC52648 | |||
| 532 | RTK197F.tmp.exe | C:\Windows\system32\drivers\RtsUpx.sys | executable | |
MD5:F5468C18887C1560D2D425725593B7C9 | SHA256:2BDDAD4026875DA8A2C101D1556C7E4660B57D7CBFDE82C91E34764B561D6972 | |||
| 532 | RTK197F.tmp.exe | C:\Users\admin\AppData\Local\Temp\RtsUpx_n.sys | executable | |
MD5:F5468C18887C1560D2D425725593B7C9 | SHA256:2BDDAD4026875DA8A2C101D1556C7E4660B57D7CBFDE82C91E34764B561D6972 | |||
| 1392 | CameraFirmwareUpdatedTool.exe | C:\Users\admin\AppData\Local\Temp\config.ini | text | |
MD5:3B93EB7BF73AAAF9B86D42FBB805B31F | SHA256:600C2585135A4A1C3272A1925E3036064BAE71C560A5DA27DD65C90D3F266141 | |||
| 2184 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2184.22234\CameraFirmwareUpdatedTool.exe | executable | |
MD5:25FD330F8559E65919D5412352DBE6FE | SHA256:ED68BD73C4EF3953016539AEBE99FB379421117545631F0F75528DB74C39A232 | |||
| 2628 | CameraFirmwareUpdatedTool.exe | C:\Users\admin\AppData\Local\Temp\RTK5B89.tmp.exe | executable | |
MD5:33BC056756C61C33686CB9340F40E4CA | SHA256:2A1E6426A52ACC3881886C5F430D843151E4CE37E456A82D8A155F7B3CC52648 | |||
| 3060 | CameraFirmwareUpdatedTool.exe | C:\Users\admin\AppData\Local\Temp\RTKE7CB.tmp.exe | executable | |
MD5:33BC056756C61C33686CB9340F40E4CA | SHA256:2A1E6426A52ACC3881886C5F430D843151E4CE37E456A82D8A155F7B3CC52648 | |||
| 984 | RTK754B.tmp.exe | C:\Users\admin\AppData\Local\Temp\RtsUpx_s.sys | executable | |
MD5:F5468C18887C1560D2D425725593B7C9 | SHA256:2BDDAD4026875DA8A2C101D1556C7E4660B57D7CBFDE82C91E34764B561D6972 | |||
| 1880 | RTK5B89.tmp.exe | C:\Windows\system32\drivers\RtsUpx.sys | executable | |
MD5:F5468C18887C1560D2D425725593B7C9 | SHA256:2BDDAD4026875DA8A2C101D1556C7E4660B57D7CBFDE82C91E34764B561D6972 | |||
| 2364 | RTKE7CB.tmp.exe | C:\Windows\system32\drivers\RtsUpx.sys | executable | |
MD5:F5468C18887C1560D2D425725593B7C9 | SHA256:2BDDAD4026875DA8A2C101D1556C7E4660B57D7CBFDE82C91E34764B561D6972 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
Process | Message |
|---|---|
RTK197F.tmp.exe | Before SetEvent
|
RTK197F.tmp.exe | CDevFlow::DEV_GetDefaultDeviceForAllInOne()
|
RTK197F.tmp.exe | CDevFlow::DEV_CloseDevice()
|
RTK3B3F.tmp.exe | Before SetEvent
|
RTK3B3F.tmp.exe | CDevFlow::DEV_GetDefaultDeviceForAllInOne()
|
RTK3B3F.tmp.exe | CDevFlow::DEV_CloseDevice()
|
RTK5B89.tmp.exe | CDevFlow::DEV_GetDefaultDeviceForAllInOne()
|
RTK5B89.tmp.exe | Before SetEvent
|
RTK5B89.tmp.exe | CDevFlow::DEV_CloseDevice()
|
RTK754B.tmp.exe | CDevFlow::DEV_GetDefaultDeviceForAllInOne()
|