| File name: | MarsWiFi_Setup_3.1.1.2.rar |
| Full analysis: | https://app.any.run/tasks/39be8ee2-5995-4e2a-b0c3-c474094d12d7 |
| Verdict: | Malicious activity |
| Analysis date: | February 10, 2019, 23:35:26 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-rar |
| File info: | RAR archive data, v5 |
| MD5: | 846D7BCA8809482B04524A8C805C7B04 |
| SHA1: | BBE66C49BD7F4913C57E046A3BE99754EFDF7AB0 |
| SHA256: | A461F198B83BA05F9D0582D68A8E570C965639DEF2E092476E365A1E741885A0 |
| SSDEEP: | 49152:JEnI2Zz7mv0QdpcWN/0gDmV66cqGRevJ1DsZ/Iow0hQC1+O233ANTee0G1:JCTQdni66cxox1YZwoJQxXJ81 |
| .rar | | | RAR compressed archive (v5.0) (61.5) |
|---|---|---|
| .rar | | | RAR compressed archive (gen) (38.4) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 340 | "C:\Program Files\zksoft\marswifi\zkservice.exe" /service zkservice | C:\Program Files\zksoft\marswifi\zkservice.exe | — | services.exe | |||||||||||
User: SYSTEM Company: ZhangKong Soft Integrity Level: SYSTEM Description: zk core service Exit code: 0 Version: 1.0.0.1 Modules
| |||||||||||||||
| 1948 | DrvInst.exe "1" "200" "STORAGE\VolumeSnapshot\HarddiskVolumeSnapshot18" "" "" "6792c44eb" "00000000" "000005C8" "000005C4" | C:\Windows\system32\DrvInst.exe | — | svchost.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Driver Installation Module Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2188 | "C:\Program Files\zksoft\marswifi\zkservice.exe" /install /name zkservice /dispname zksrvc /description "zk net core service" /order zkservice | C:\Program Files\zksoft\marswifi\zkservice.exe | — | MarsWiFi_Setup_3.1.1.2.exe | |||||||||||
User: admin Company: ZhangKong Soft Integrity Level: HIGH Description: zk core service Exit code: 1 Version: 1.0.0.1 Modules
| |||||||||||||||
| 2192 | "C:\Users\admin\Desktop\MarsWiFi_Setup_3.1.1.2\MarsWiFi_Setup_3.1.1.2.exe" | C:\Users\admin\Desktop\MarsWiFi_Setup_3.1.1.2\MarsWiFi_Setup_3.1.1.2.exe | explorer.exe | ||||||||||||
User: admin Company: ZhangKong Soft Integrity Level: HIGH Description: zksetup Exit code: 0 Version: 1.0.0.1 Modules
| |||||||||||||||
| 2236 | "C:\Program Files\zksoft\marswifi\marswifi.exe" -f:installer | C:\Program Files\zksoft\marswifi\marswifi.exe | MarsWiFi_Setup_3.1.1.2.exe | ||||||||||||
User: admin Company: ZhangKong Soft Integrity Level: HIGH Description: marswifi Exit code: 0 Version: 2.0.0.1 Modules
| |||||||||||||||
| 2612 | DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{18fb58f0-a63b-526c-a120-791a0c847d6a}\zknetdrv.inf" "0" "6aa438bf7" "000005AC" "WinSta0\Default" "000002D0" "208" "C:\Program Files\zksoft\marswifi\drivers\win7" | C:\Windows\system32\DrvInst.exe | — | svchost.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Driver Installation Module Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2692 | "C:\Program Files\zksoft\marswifi\drivers\zkdrvinst.exe" -v -l zknetdrv.inf -c s -i zknetdrv | C:\Program Files\zksoft\marswifi\drivers\zkdrvinst.exe | — | marswifi.exe | |||||||||||
User: admin Company: ZK Internet Technology Co., Ltd. Integrity Level: HIGH Description: driver install Exit code: 0 Version: 1,0,0,1 Modules
| |||||||||||||||
| 3112 | "C:\Program Files\zksoft\marswifi\zkservice.exe" /start zkservice | C:\Program Files\zksoft\marswifi\zkservice.exe | — | MarsWiFi_Setup_3.1.1.2.exe | |||||||||||
User: admin Company: ZhangKong Soft Integrity Level: HIGH Description: zk core service Exit code: 1 Version: 1.0.0.1 Modules
| |||||||||||||||
| 3324 | "C:\Program Files\zksoft\marswifi\marswifi.exe" -a:inst | C:\Program Files\zksoft\marswifi\marswifi.exe | MarsWiFi_Setup_3.1.1.2.exe | ||||||||||||
User: admin Company: ZhangKong Soft Integrity Level: HIGH Description: marswifi Exit code: 0 Version: 2.0.0.1 Modules
| |||||||||||||||
| 3584 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\MarsWiFi_Setup_3.1.1.2.rar" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.60.0 Modules
| |||||||||||||||
| (PID) Process: | (3584) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (3584) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (3584) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3584) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop\MarsWiFi_Setup_3.1.1.2.rar | |||
| (PID) Process: | (3584) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (3584) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (3584) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (3584) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (3584) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\DialogEditHistory\ExtrPath |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop\MarsWiFi_Setup_3.1.1.2 | |||
| (PID) Process: | (3584) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin |
| Operation: | write | Name: | Placement |
Value: 2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2692 | zkdrvinst.exe | C:\Users\admin\AppData\Local\Temp\{18fb58f0-a63b-526c-a120-791a0c847d6a}\SET1A01.tmp | — | |
MD5:— | SHA256:— | |||
| 2692 | zkdrvinst.exe | C:\Users\admin\AppData\Local\Temp\{18fb58f0-a63b-526c-a120-791a0c847d6a}\SET1A12.tmp | — | |
MD5:— | SHA256:— | |||
| 2612 | DrvInst.exe | C:\Windows\System32\DriverStore\Temp\{2ef4a033-5f64-5d49-18e7-566e77ccdc4b}\SET1A9E.tmp | — | |
MD5:— | SHA256:— | |||
| 2612 | DrvInst.exe | C:\Windows\System32\DriverStore\Temp\{2ef4a033-5f64-5d49-18e7-566e77ccdc4b}\SET1AAE.tmp | — | |
MD5:— | SHA256:— | |||
| 2612 | DrvInst.exe | C:\Windows\TEMP\Cab1AEC.tmp | — | |
MD5:— | SHA256:— | |||
| 2612 | DrvInst.exe | C:\Windows\TEMP\Tar1AED.tmp | — | |
MD5:— | SHA256:— | |||
| 2612 | DrvInst.exe | C:\Windows\TEMP\Cab1AFD.tmp | — | |
MD5:— | SHA256:— | |||
| 2612 | DrvInst.exe | C:\Windows\TEMP\Tar1AFE.tmp | — | |
MD5:— | SHA256:— | |||
| 2612 | DrvInst.exe | C:\Windows\TEMP\Cab1B2E.tmp | — | |
MD5:— | SHA256:— | |||
| 2612 | DrvInst.exe | C:\Windows\TEMP\Tar1B2F.tmp | — | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3324 | marswifi.exe | POST | 200 | 101.200.194.233:80 | http://ien.zkytech.com/report/ | CN | text | 15 b | unknown |
2236 | marswifi.exe | POST | 200 | 101.200.194.233:80 | http://ien.zkytech.com/report_open/ | CN | text | 8 b | unknown |
2236 | marswifi.exe | POST | 200 | 101.200.194.233:80 | http://ien.zkytech.com/report_open/ | CN | text | 8 b | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2236 | marswifi.exe | 101.200.194.233:80 | ien.zkytech.com | Hangzhou Alibaba Advertising Co.,Ltd. | CN | unknown |
3324 | marswifi.exe | 101.200.194.233:80 | ien.zkytech.com | Hangzhou Alibaba Advertising Co.,Ltd. | CN | unknown |
Domain | IP | Reputation |
|---|---|---|
ien.zkytech.com |
| unknown |
Process | Message |
|---|---|
MarsWiFi_Setup_3.1.1.2.exe | exec count:8
|
marswifi.exe | install complete, code=0
|
marswifi.exe | RtlIhvOid :: WlanOpenHandle hClientHandle
|
marswifi.exe | RtlIhvOid :: WlanOpenHandle hClientHandle
|