File name:

MarsWiFi_Setup_3.1.1.2.rar

Full analysis: https://app.any.run/tasks/39be8ee2-5995-4e2a-b0c3-c474094d12d7
Verdict: Malicious activity
Analysis date: February 10, 2019, 23:35:26
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

846D7BCA8809482B04524A8C805C7B04

SHA1:

BBE66C49BD7F4913C57E046A3BE99754EFDF7AB0

SHA256:

A461F198B83BA05F9D0582D68A8E570C965639DEF2E092476E365A1E741885A0

SSDEEP:

49152:JEnI2Zz7mv0QdpcWN/0gDmV66cqGRevJ1DsZ/Iow0hQC1+O233ANTee0G1:JCTQdni66cxox1YZwoJQxXJ81

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • MarsWiFi_Setup_3.1.1.2.exe (PID: 2192)
    • Changes settings of System certificates

      • marswifi.exe (PID: 3324)
    • Changes the autorun value in the registry

      • MarsWiFi_Setup_3.1.1.2.exe (PID: 2192)
  • SUSPICIOUS

    • Creates files in the program directory

      • MarsWiFi_Setup_3.1.1.2.exe (PID: 2192)
      • marswifi.exe (PID: 2236)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3584)
      • marswifi.exe (PID: 3324)
    • Creates files in the driver directory

      • marswifi.exe (PID: 3324)
      • DrvInst.exe (PID: 2612)
    • Creates files in the Windows directory

      • DrvInst.exe (PID: 2612)
      • zkdrvinst.exe (PID: 2692)
      • marswifi.exe (PID: 3324)
    • Removes files from Windows directory

      • DrvInst.exe (PID: 2612)
    • Searches for installed software

      • DrvInst.exe (PID: 2612)
    • Creates a software uninstall entry

      • MarsWiFi_Setup_3.1.1.2.exe (PID: 2192)
  • INFO

    • Low-level read access rights to disk partition

      • vssvc.exe (PID: 3776)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
49
Monitored processes
11
Malicious processes
2
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe marswifi_setup_3.1.1.2.exe marswifi.exe zkdrvinst.exe no specs drvinst.exe no specs vssvc.exe no specs drvinst.exe no specs zkservice.exe no specs zkservice.exe no specs zkservice.exe no specs marswifi.exe

Process information

PID
CMD
Path
Indicators
Parent process
340"C:\Program Files\zksoft\marswifi\zkservice.exe" /service zkserviceC:\Program Files\zksoft\marswifi\zkservice.exeservices.exe
User:
SYSTEM
Company:
ZhangKong Soft
Integrity Level:
SYSTEM
Description:
zk core service
Exit code:
0
Version:
1.0.0.1
Modules
Images
c:\program files\zksoft\marswifi\zkservice.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
1948DrvInst.exe "1" "200" "STORAGE\VolumeSnapshot\HarddiskVolumeSnapshot18" "" "" "6792c44eb" "00000000" "000005C8" "000005C4"C:\Windows\system32\DrvInst.exesvchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\drvinst.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
2188"C:\Program Files\zksoft\marswifi\zkservice.exe" /install /name zkservice /dispname zksrvc /description "zk net core service" /order zkserviceC:\Program Files\zksoft\marswifi\zkservice.exeMarsWiFi_Setup_3.1.1.2.exe
User:
admin
Company:
ZhangKong Soft
Integrity Level:
HIGH
Description:
zk core service
Exit code:
1
Version:
1.0.0.1
Modules
Images
c:\program files\zksoft\marswifi\zkservice.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2192"C:\Users\admin\Desktop\MarsWiFi_Setup_3.1.1.2\MarsWiFi_Setup_3.1.1.2.exe" C:\Users\admin\Desktop\MarsWiFi_Setup_3.1.1.2\MarsWiFi_Setup_3.1.1.2.exe
explorer.exe
User:
admin
Company:
ZhangKong Soft
Integrity Level:
HIGH
Description:
zksetup
Exit code:
0
Version:
1.0.0.1
Modules
Images
c:\users\admin\desktop\marswifi_setup_3.1.1.2\marswifi_setup_3.1.1.2.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\gdi32.dll
2236"C:\Program Files\zksoft\marswifi\marswifi.exe" -f:installerC:\Program Files\zksoft\marswifi\marswifi.exe
MarsWiFi_Setup_3.1.1.2.exe
User:
admin
Company:
ZhangKong Soft
Integrity Level:
HIGH
Description:
marswifi
Exit code:
0
Version:
2.0.0.1
Modules
Images
c:\program files\zksoft\marswifi\marswifi.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
2612DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{18fb58f0-a63b-526c-a120-791a0c847d6a}\zknetdrv.inf" "0" "6aa438bf7" "000005AC" "WinSta0\Default" "000002D0" "208" "C:\Program Files\zksoft\marswifi\drivers\win7"C:\Windows\system32\DrvInst.exesvchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\drvinst.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
2692"C:\Program Files\zksoft\marswifi\drivers\zkdrvinst.exe" -v -l zknetdrv.inf -c s -i zknetdrvC:\Program Files\zksoft\marswifi\drivers\zkdrvinst.exemarswifi.exe
User:
admin
Company:
ZK Internet Technology Co., Ltd.
Integrity Level:
HIGH
Description:
driver install
Exit code:
0
Version:
1,0,0,1
Modules
Images
c:\program files\zksoft\marswifi\drivers\zkdrvinst.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
3112"C:\Program Files\zksoft\marswifi\zkservice.exe" /start zkserviceC:\Program Files\zksoft\marswifi\zkservice.exeMarsWiFi_Setup_3.1.1.2.exe
User:
admin
Company:
ZhangKong Soft
Integrity Level:
HIGH
Description:
zk core service
Exit code:
1
Version:
1.0.0.1
Modules
Images
c:\program files\zksoft\marswifi\zkservice.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
3324"C:\Program Files\zksoft\marswifi\marswifi.exe" -a:instC:\Program Files\zksoft\marswifi\marswifi.exe
MarsWiFi_Setup_3.1.1.2.exe
User:
admin
Company:
ZhangKong Soft
Integrity Level:
HIGH
Description:
marswifi
Exit code:
0
Version:
2.0.0.1
Modules
Images
c:\program files\zksoft\marswifi\marswifi.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
3584"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\MarsWiFi_Setup_3.1.1.2.rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
Total events
1 013
Read events
722
Write events
289
Delete events
2

Modification events

(PID) Process:(3584) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3584) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3584) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3584) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\MarsWiFi_Setup_3.1.1.2.rar
(PID) Process:(3584) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3584) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3584) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3584) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3584) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\DialogEditHistory\ExtrPath
Operation:writeName:0
Value:
C:\Users\admin\Desktop\MarsWiFi_Setup_3.1.1.2
(PID) Process:(3584) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000
Executable files
2
Suspicious files
12
Text files
163
Unknown types
11

Dropped files

PID
Process
Filename
Type
2692zkdrvinst.exeC:\Users\admin\AppData\Local\Temp\{18fb58f0-a63b-526c-a120-791a0c847d6a}\SET1A01.tmp
MD5:
SHA256:
2692zkdrvinst.exeC:\Users\admin\AppData\Local\Temp\{18fb58f0-a63b-526c-a120-791a0c847d6a}\SET1A12.tmp
MD5:
SHA256:
2612DrvInst.exeC:\Windows\System32\DriverStore\Temp\{2ef4a033-5f64-5d49-18e7-566e77ccdc4b}\SET1A9E.tmp
MD5:
SHA256:
2612DrvInst.exeC:\Windows\System32\DriverStore\Temp\{2ef4a033-5f64-5d49-18e7-566e77ccdc4b}\SET1AAE.tmp
MD5:
SHA256:
2612DrvInst.exeC:\Windows\TEMP\Cab1AEC.tmp
MD5:
SHA256:
2612DrvInst.exeC:\Windows\TEMP\Tar1AED.tmp
MD5:
SHA256:
2612DrvInst.exeC:\Windows\TEMP\Cab1AFD.tmp
MD5:
SHA256:
2612DrvInst.exeC:\Windows\TEMP\Tar1AFE.tmp
MD5:
SHA256:
2612DrvInst.exeC:\Windows\TEMP\Cab1B2E.tmp
MD5:
SHA256:
2612DrvInst.exeC:\Windows\TEMP\Tar1B2F.tmp
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
3
TCP/UDP connections
3
DNS requests
2
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3324
marswifi.exe
POST
200
101.200.194.233:80
http://ien.zkytech.com/report/
CN
text
15 b
unknown
2236
marswifi.exe
POST
200
101.200.194.233:80
http://ien.zkytech.com/report_open/
CN
text
8 b
unknown
2236
marswifi.exe
POST
200
101.200.194.233:80
http://ien.zkytech.com/report_open/
CN
text
8 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2236
marswifi.exe
101.200.194.233:80
ien.zkytech.com
Hangzhou Alibaba Advertising Co.,Ltd.
CN
unknown
3324
marswifi.exe
101.200.194.233:80
ien.zkytech.com
Hangzhou Alibaba Advertising Co.,Ltd.
CN
unknown

DNS requests

Domain
IP
Reputation
ien.zkytech.com
  • 101.200.194.233
unknown

Threats

No threats detected
Process
Message
MarsWiFi_Setup_3.1.1.2.exe
exec count:8
marswifi.exe
install complete, code=0
marswifi.exe
RtlIhvOid :: WlanOpenHandle hClientHandle
marswifi.exe
RtlIhvOid :: WlanOpenHandle hClientHandle