| File name: | USBGuardSetupfullversion.zip |
| Full analysis: | https://app.any.run/tasks/39ddb496-946b-4d63-8bcb-79d32a4f64cd |
| Verdict: | Malicious activity |
| Analysis date: | November 18, 2023, 14:56:37 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract |
| MD5: | CD815AC01CD38A8B433E210109728B45 |
| SHA1: | 7E3595844F84952BB4426D9E6E2A10F4B4260E04 |
| SHA256: | B6431AE7CAAC4601E2D7D1E0A14B6A05A65EC80E17EA8D24C5D203B19CEC4A19 |
| SSDEEP: | 98304:uauC/94awGDeI0KY/FSyIgmdSDZxaMafpMUKLmE/s2zIMtMa5UcwPuL6nalKPFIq:+XtJgt |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 20 |
|---|---|
| ZipBitFlag: | - |
| ZipCompression: | Deflated |
| ZipModifyDate: | 2021:08:18 01:00:18 |
| ZipCRC: | 0xfc530a30 |
| ZipCompressedSize: | 3962926 |
| ZipUncompressedSize: | 4041496 |
| ZipFileName: | USBGuardSetup6.9.exe |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 148 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=15 --mojo-platform-channel-handle=3908 --field-trial-handle=1272,i,8807216944793268330,5275858575790483158,131072 /prefetch:1 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 284 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=17 --mojo-platform-channel-handle=3768 --field-trial-handle=1272,i,8807216944793268330,5275858575790483158,131072 /prefetch:1 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 528 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=20 --mojo-platform-channel-handle=4280 --field-trial-handle=1272,i,8807216944793268330,5275858575790483158,131072 /prefetch:1 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 556 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=asset_store.mojom.AssetStoreService --lang=en-US --service-sandbox-type=asset_store_service --mojo-platform-channel-handle=4528 --field-trial-handle=1272,i,8807216944793268330,5275858575790483158,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 732 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=12 --mojo-platform-channel-handle=3700 --field-trial-handle=1304,i,8427662061947575658,306904945399043602,131072 /prefetch:1 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 916 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=1628 --field-trial-handle=1304,i,8427662061947575658,306904945399043602,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 984 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=4812 --field-trial-handle=1272,i,8807216944793268330,5275858575790483158,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 988 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3672 --field-trial-handle=1304,i,8427662061947575658,306904945399043602,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1164 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=1644 --field-trial-handle=1272,i,8807216944793268330,5275858575790483158,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1360 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=2304 --field-trial-handle=1304,i,8427662061947575658,306904945399043602,131072 /prefetch:1 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| (PID) Process: | (3448) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\17A\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3448) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip | |||
| (PID) Process: | (3448) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (3448) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop\phacker.zip | |||
| (PID) Process: | (3448) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (3448) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (3448) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (3448) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (3448) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (3448) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3412 | USBGuardSetup6.9.tmp | C:\Program Files\USB Disk Security\USBGuard.exe | executable | |
MD5:B7FFEAA4CD513D5D0EF80A8B29C3FF3E | SHA256:744DBE2B0082E3FC76C194B8665CC7BB5830685EF8908E1F5D3DA1D1E0C83020 | |||
| 3412 | USBGuardSetup6.9.tmp | C:\Program Files\USB Disk Security\unins000.exe | executable | |
MD5:4B1B47904748005A65A2B0963DE744B5 | SHA256:2EAC3DB249447C04620449B691AF4B67FA87C9187E54FE6070B5B6EF9684087C | |||
| 3412 | USBGuardSetup6.9.tmp | C:\Users\admin\AppData\Local\Temp\is-C3E7U.tmp\WebNavigation.ico | image | |
MD5:8A1A593C32869F553FC7F79F2A033246 | SHA256:77C91C6FDC2B9E26C93D3858595808D17A0C4CBCA5A7760CB81E5765B1501078 | |||
| 3412 | USBGuardSetup6.9.tmp | C:\Program Files\USB Disk Security\is-4BMII.tmp | executable | |
MD5:B7FFEAA4CD513D5D0EF80A8B29C3FF3E | SHA256:744DBE2B0082E3FC76C194B8665CC7BB5830685EF8908E1F5D3DA1D1E0C83020 | |||
| 3448 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3448.40006\USBGuardSetup6.9.exe | executable | |
MD5:EB2592D2CD1A8C3547E669F25E325604 | SHA256:2975DC65576B71AF4D34F00984CBA37DFD0304B57E878BF0F126CE08C01F39A0 | |||
| 3412 | USBGuardSetup6.9.tmp | C:\Program Files\USB Disk Security\is-KGPAR.tmp | executable | |
MD5:A8861FE13E071367506A64801B7F78EE | SHA256:4531EC95FC017BAE370817122D769EEA8E69804E1B538545267B211533780AAA | |||
| 3412 | USBGuardSetup6.9.tmp | C:\Program Files\USB Disk Security\USBGuard.chm | binary | |
MD5:44CF0B4955BEDE84AE03418B445A5B72 | SHA256:15FA10A5E162D25957D76A6E5A02D5F98C7CA333AE6BC16C26B3F56729BF18F1 | |||
| 3412 | USBGuardSetup6.9.tmp | C:\Program Files\USB Disk Security\is-RP9N3.tmp | executable | |
MD5:5E2BD09FACB151796B9F0A7D4151DC3C | SHA256:9BEB9C29057A07651527B8132D436E0ED1FAD094B82572044CE30C176DC2B7DA | |||
| 3412 | USBGuardSetup6.9.tmp | C:\Program Files\USB Disk Security\BCGCBPRO1500u80.dll | executable | |
MD5:A8861FE13E071367506A64801B7F78EE | SHA256:4531EC95FC017BAE370817122D769EEA8E69804E1B538545267B211533780AAA | |||
| 3612 | USBGuardSetup6.9.exe | C:\Users\admin\AppData\Local\Temp\is-AS11B.tmp\USBGuardSetup6.9.tmp | executable | |
MD5:F18C042968D7CDEC2314EB23E304645A | SHA256:AFEA8AC6608C62FE6F25BCCE59A2E7BEF022303252F58A01FC6601ECF4F02DE6 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3644 | USBGuard.exe | GET | 200 | 50.116.10.192:80 | http://www.zbshareware.net/referrals/setting/remoteref.ini | unknown | text | 1.17 Kb | unknown |
3644 | USBGuard.exe | GET | 404 | 50.116.10.192:80 | http://www.zbshareware.net/updatenew/update6free/version.ini | unknown | html | 162 b | unknown |
3644 | USBGuard.exe | GET | 404 | 50.116.10.192:80 | http://www.zbshareware.com/updatenew/update6free/version.ini | unknown | html | 162 b | unknown |
3644 | USBGuard.exe | GET | 200 | 50.116.10.192:80 | http://www.zbshareware.com/referrals/image/games/fruit.jpg | unknown | image | 30.5 Kb | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
2588 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
3644 | USBGuard.exe | 50.116.10.192:80 | www.zbshareware.net | Linode, LLC | US | unknown |
3560 | msedge.exe | 13.107.42.16:443 | config.edge.skype.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
3560 | msedge.exe | 51.104.176.40:443 | nav-edge.smartscreen.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
3560 | msedge.exe | 204.79.197.239:443 | edge.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | unknown |
3560 | msedge.exe | 188.114.96.3:443 | www.linkzb.com | CLOUDFLARENET | NL | unknown |
3892 | msedge.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
Domain | IP | Reputation |
|---|---|---|
www.zbshareware.net |
| unknown |
www.zbshareware.com |
| malicious |
www.linkzb.com |
| unknown |
config.edge.skype.com |
| whitelisted |
nav-edge.smartscreen.microsoft.com |
| whitelisted |
edge.microsoft.com |
| whitelisted |
www.linkzb.net |
| unknown |
data-edge.smartscreen.microsoft.com |
| whitelisted |
pagead2.googlesyndication.com |
| whitelisted |
www.google-analytics.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
3560 | msedge.exe | Not Suspicious Traffic | INFO [ANY.RUN] Cloudflare Network Error Logging (NEL) |