File name:

samsung-samsung-mobile-usb-modem-outbyte-driver-updater.zip

Full analysis: https://app.any.run/tasks/68126a3b-1d64-4261-ab79-5aab3dfb061c
Verdict: Malicious activity
Analysis date: April 27, 2022, 00:56:05
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

AF0E399A9BBD51688A3151400209561C

SHA1:

0DF8CA0F7E607F70A94AF71FBC394B64EA4E5A3A

SHA256:

B945AEA3A2D123A925F4035529013C5D1EB5F85C618EB4122A3FA44A280749C2

SSDEEP:

196608:9Yq73RcpKFX+SkzrvmovPTvtuJqUb8l1al4/Toic2nM62h9jUdJCFHdFiYK+IPU+:9qWXSrv9MJdKalKTlu/jO0FH2BPjr/jr

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops executable file immediately after starts

      • WinRAR.exe (PID: 3304)
      • samsung-samsung-mobile-usb-modem-outbyte-driver-updater.exe (PID: 2176)
      • Installer.exe (PID: 4076)
      • DriverUpdater.exe (PID: 588)
    • Application was dropped or rewritten from another process

      • samsung-samsung-mobile-usb-modem-outbyte-driver-updater.exe (PID: 1764)
      • samsung-samsung-mobile-usb-modem-outbyte-driver-updater.exe (PID: 2176)
      • Installer.exe (PID: 4076)
      • DriverUpdater.exe (PID: 2556)
      • DriverUpdater.exe (PID: 588)
    • Loads dropped or rewritten executable

      • Installer.exe (PID: 4076)
      • samsung-samsung-mobile-usb-modem-outbyte-driver-updater.exe (PID: 2176)
      • DriverUpdater.exe (PID: 2556)
      • DriverUpdater.exe (PID: 588)
    • Steals credentials from Web Browsers

      • Installer.exe (PID: 4076)
      • DriverUpdater.exe (PID: 2556)
      • DriverUpdater.exe (PID: 588)
    • Actions looks like stealing of personal data

      • Installer.exe (PID: 4076)
      • DriverUpdater.exe (PID: 588)
      • DriverUpdater.exe (PID: 2556)
    • Changes settings of System certificates

      • Installer.exe (PID: 4076)
      • DriverUpdater.exe (PID: 2556)
      • DriverUpdater.exe (PID: 588)
    • Loads the Task Scheduler COM API

      • DriverUpdater.exe (PID: 2556)
      • DriverUpdater.exe (PID: 588)
  • SUSPICIOUS

    • Reads the computer name

      • samsung-samsung-mobile-usb-modem-outbyte-driver-updater.exe (PID: 2176)
      • WinRAR.exe (PID: 3304)
      • Installer.exe (PID: 4076)
      • DriverUpdater.exe (PID: 588)
      • DriverUpdater.exe (PID: 2556)
    • Executable content was dropped or overwritten

      • samsung-samsung-mobile-usb-modem-outbyte-driver-updater.exe (PID: 2176)
      • WinRAR.exe (PID: 3304)
      • Installer.exe (PID: 4076)
      • DriverUpdater.exe (PID: 588)
    • Checks supported languages

      • Installer.exe (PID: 4076)
      • samsung-samsung-mobile-usb-modem-outbyte-driver-updater.exe (PID: 2176)
      • WinRAR.exe (PID: 3304)
      • DriverUpdater.exe (PID: 2556)
      • DriverUpdater.exe (PID: 588)
    • Drops a file with a compile date too recent

      • samsung-samsung-mobile-usb-modem-outbyte-driver-updater.exe (PID: 2176)
      • WinRAR.exe (PID: 3304)
      • Installer.exe (PID: 4076)
      • DriverUpdater.exe (PID: 588)
    • Reads Windows Product ID

      • Installer.exe (PID: 4076)
      • DriverUpdater.exe (PID: 2556)
      • DriverUpdater.exe (PID: 588)
    • Creates files in the program directory

      • Installer.exe (PID: 4076)
      • DriverUpdater.exe (PID: 2556)
      • DriverUpdater.exe (PID: 588)
    • Reads the Windows organization settings

      • Installer.exe (PID: 4076)
      • DriverUpdater.exe (PID: 588)
    • Reads Windows owner or organization settings

      • Installer.exe (PID: 4076)
      • DriverUpdater.exe (PID: 588)
    • Creates a directory in Program Files

      • Installer.exe (PID: 4076)
    • Creates a software uninstall entry

      • Installer.exe (PID: 4076)
    • Changes default file association

      • DriverUpdater.exe (PID: 2556)
    • Adds / modifies Windows certificates

      • DriverUpdater.exe (PID: 588)
    • Searches for installed software

      • DriverUpdater.exe (PID: 2556)
      • DriverUpdater.exe (PID: 588)
  • INFO

    • Checks Windows Trust Settings

      • Installer.exe (PID: 4076)
      • DriverUpdater.exe (PID: 2556)
      • DriverUpdater.exe (PID: 588)
    • Reads settings of System Certificates

      • Installer.exe (PID: 4076)
      • samsung-samsung-mobile-usb-modem-outbyte-driver-updater.exe (PID: 2176)
      • DriverUpdater.exe (PID: 2556)
      • DriverUpdater.exe (PID: 588)
    • Manual execution by user

      • samsung-samsung-mobile-usb-modem-outbyte-driver-updater.exe (PID: 1764)
      • samsung-samsung-mobile-usb-modem-outbyte-driver-updater.exe (PID: 2176)
    • Reads Microsoft Office registry keys

      • DriverUpdater.exe (PID: 588)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipFileName: samsung-samsung-mobile-usb-modem-outbyte-driver-updater.exe
ZipUncompressedSize: 17055312
ZipCompressedSize: 16670204
ZipCRC: 0x7df6e51e
ZipModifyDate: 2022:04:27 09:54:26
ZipCompression: Deflated
ZipBitFlag: -
ZipRequiredVersion: 20
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
49
Monitored processes
6
Malicious processes
4
Suspicious processes
2

Behavior graph

Click at the process to see the details
start drop and start drop and start drop and start winrar.exe samsung-samsung-mobile-usb-modem-outbyte-driver-updater.exe no specs samsung-samsung-mobile-usb-modem-outbyte-driver-updater.exe installer.exe driverupdater.exe driverupdater.exe

Process information

PID
CMD
Path
Indicators
Parent process
588"C:\Program Files\Outbyte\Driver Updater\DriverUpdater.exe" /FromInstaller /AutoScanC:\Program Files\Outbyte\Driver Updater\DriverUpdater.exe
Installer.exe
User:
admin
Company:
Outbyte
Integrity Level:
HIGH
Description:
Driver Updater
Exit code:
0
Version:
2.1.17.5814
Modules
Images
c:\program files\outbyte\driver updater\driverupdater.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\outbyte\driver updater\axcomponentsvcl.bpl
c:\program files\outbyte\driver updater\axcomponentsrtl.bpl
c:\windows\system32\wininet.dll
c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
1764"C:\Users\admin\Desktop\samsung-samsung-mobile-usb-modem-outbyte-driver-updater.exe" C:\Users\admin\Desktop\samsung-samsung-mobile-usb-modem-outbyte-driver-updater.exeExplorer.EXE
User:
admin
Company:
Outbyte
Integrity Level:
MEDIUM
Description:
Outbyte Driver Updater Installation File
Exit code:
3221226540
Version:
2.1.17.5814
Modules
Images
c:\users\admin\desktop\samsung-samsung-mobile-usb-modem-outbyte-driver-updater.exe
c:\windows\system32\ntdll.dll
2176"C:\Users\admin\Desktop\samsung-samsung-mobile-usb-modem-outbyte-driver-updater.exe" C:\Users\admin\Desktop\samsung-samsung-mobile-usb-modem-outbyte-driver-updater.exe
Explorer.EXE
User:
admin
Company:
Outbyte
Integrity Level:
HIGH
Description:
Outbyte Driver Updater Installation File
Exit code:
0
Version:
2.1.17.5814
Modules
Images
c:\users\admin\desktop\samsung-samsung-mobile-usb-modem-outbyte-driver-updater.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\usp10.dll
2556"C:\Program Files\Outbyte\Driver Updater\DriverUpdater.exe" /Install /SendInfo /AutoStartC:\Program Files\Outbyte\Driver Updater\DriverUpdater.exe
Installer.exe
User:
admin
Company:
Outbyte
Integrity Level:
HIGH
Description:
Driver Updater
Exit code:
0
Version:
2.1.17.5814
Modules
Images
c:\program files\outbyte\driver updater\driverupdater.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\outbyte\driver updater\axcomponentsrtl.bpl
c:\program files\outbyte\driver updater\axcomponentsvcl.bpl
c:\windows\system32\wininet.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
c:\windows\system32\user32.dll
3304"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\samsung-samsung-mobile-usb-modem-outbyte-driver-updater.zip"C:\Program Files\WinRAR\WinRAR.exe
Explorer.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
c:\windows\system32\comdlg32.dll
4076"C:\Users\admin\AppData\Local\Temp\is-6807847.tmp\Installer.exe" /spid:2176 /splha:20523328C:\Users\admin\AppData\Local\Temp\is-6807847.tmp\Installer.exe
samsung-samsung-mobile-usb-modem-outbyte-driver-updater.exe
User:
admin
Company:
Outbyte
Integrity Level:
HIGH
Description:
Installer
Exit code:
0
Version:
2.1.17.5814
Modules
Images
c:\users\admin\appdata\local\temp\is-6807847.tmp\installer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\temp\is-6807847.tmp\axcomponentsvcl.bpl
c:\users\admin\appdata\local\temp\is-6807847.tmp\axcomponentsrtl.bpl
c:\windows\system32\wininet.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
c:\windows\system32\user32.dll
Total events
47 576
Read events
47 341
Write events
232
Delete events
3

Modification events

(PID) Process:(3304) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3304) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3304) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3304) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(3304) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(3304) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\samsung-samsung-mobile-usb-modem-outbyte-driver-updater.zip
(PID) Process:(3304) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3304) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3304) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3304) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
Executable files
84
Suspicious files
61
Text files
15
Unknown types
16

Dropped files

PID
Process
Filename
Type
3304WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3304.15698\samsung-samsung-mobile-usb-modem-outbyte-driver-updater.exeexecutable
MD5:
SHA256:
2176samsung-samsung-mobile-usb-modem-outbyte-driver-updater.exeC:\Users\admin\AppData\Local\Temp\is-6807847.tmp\Lang\deu.lngbinary
MD5:
SHA256:
2176samsung-samsung-mobile-usb-modem-outbyte-driver-updater.exeC:\Users\admin\AppData\Local\Temp\is-6807847.tmp\Lang\ptb.lngbinary
MD5:
SHA256:
2176samsung-samsung-mobile-usb-modem-outbyte-driver-updater.exeC:\Users\admin\AppData\Local\Temp\is-6807847.tmp\Lang\enu.lngbinary
MD5:
SHA256:
2176samsung-samsung-mobile-usb-modem-outbyte-driver-updater.exeC:\Users\admin\AppData\Local\Temp\is-6807847.tmp\Localizer.dllexecutable
MD5:
SHA256:
2176samsung-samsung-mobile-usb-modem-outbyte-driver-updater.exeC:\Users\admin\AppData\Local\Temp\is-6807847.tmp\CommonForms.Site.dllexecutable
MD5:
SHA256:
2176samsung-samsung-mobile-usb-modem-outbyte-driver-updater.exeC:\Users\admin\AppData\Local\Temp\is-6807847.tmp\SetupHelper.dllexecutable
MD5:
SHA256:
2176samsung-samsung-mobile-usb-modem-outbyte-driver-updater.exeC:\Users\admin\AppData\Local\Temp\is-6807847.tmp\GoogleAnalyticsHelper.dllexecutable
MD5:
SHA256:
2176samsung-samsung-mobile-usb-modem-outbyte-driver-updater.exeC:\Users\admin\AppData\Local\Temp\is-6807847.tmp\InstallerUtils.dllexecutable
MD5:
SHA256:
2176samsung-samsung-mobile-usb-modem-outbyte-driver-updater.exeC:\Users\admin\AppData\Local\Temp\is-6807847.tmp\Installer.exeodttf
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
156
TCP/UDP connections
23
DNS requests
14
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4076
Installer.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAeYNgOt45kIIZygDCe8imw%3D
US
der
471 b
whitelisted
488
lsass.exe
GET
200
65.9.58.194:80
http://o.ss2.us//MEowSDBGMEQwQjAJBgUrDgMCGgUABBSLwZ6EW5gdYc9UaSEaaLjjETNtkAQUv1%2B30c7dH4b0W1Ws3NcQwg6piOcCCQCnDkpMNIK3fw%3D%3D
US
der
1.70 Kb
whitelisted
4076
Installer.exe
GET
200
209.197.3.8:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?c5888855d0234fc8
US
compressed
4.70 Kb
whitelisted
4076
Installer.exe
POST
200
172.217.18.110:80
http://www.google-analytics.com/collect
US
image
35 b
whitelisted
4076
Installer.exe
POST
200
172.217.18.110:80
http://www.google-analytics.com/collect
US
image
35 b
whitelisted
4076
Installer.exe
POST
200
172.217.18.110:80
http://www.google-analytics.com/collect
US
image
35 b
whitelisted
4076
Installer.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBR0tOcjGcdlkhVARHvHzj6Qwhh26wQUpI3lvnx55HAjbS4pNK0jWNz1MX8CEA%2F2i1mkgFikrMhtVqD%2FhM0%3D
US
der
471 b
whitelisted
4076
Installer.exe
POST
200
172.217.18.110:80
http://www.google-analytics.com/collect
US
image
35 b
whitelisted
4076
Installer.exe
POST
200
172.217.18.110:80
http://www.google-analytics.com/collect
US
image
35 b
whitelisted
4076
Installer.exe
POST
200
172.217.18.110:80
http://www.google-analytics.com/collect
US
image
35 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4076
Installer.exe
45.33.97.245:443
outbyte.com
Linode, LLC
US
unknown
4076
Installer.exe
209.197.3.8:80
ctldl.windowsupdate.com
Highwinds Network Group, Inc.
US
whitelisted
488
lsass.exe
65.9.58.194:80
o.ss2.us
AT&T Services, Inc.
US
suspicious
488
lsass.exe
99.86.1.61:80
ocsp.rootg2.amazontrust.com
AT&T Services, Inc.
US
whitelisted
488
lsass.exe
143.204.214.142:80
ocsp.sca1b.amazontrust.com
US
whitelisted
588
DriverUpdater.exe
34.224.134.35:80
ws.driverhive.com
Amazon.com, Inc.
US
unknown
588
DriverUpdater.exe
52.41.132.197:443
outbyteapp.com
Amazon.com, Inc.
US
unknown
588
DriverUpdater.exe
51.222.203.38:443
du.outbyte.com
GB
malicious
588
DriverUpdater.exe
45.33.97.245:443
outbyte.com
Linode, LLC
US
unknown
488
lsass.exe
99.86.1.226:80
ocsp.rootg2.amazontrust.com
AT&T Services, Inc.
US
whitelisted

DNS requests

Domain
IP
Reputation
outbyte.com
  • 45.33.97.245
suspicious
ctldl.windowsupdate.com
  • 209.197.3.8
whitelisted
ocsp.digicert.com
  • 93.184.220.29
whitelisted
www.google-analytics.com
  • 172.217.18.110
whitelisted
outbyteapp.com
  • 52.41.132.197
  • 44.240.24.156
unknown
o.ss2.us
  • 65.9.58.194
  • 65.9.58.231
  • 65.9.58.56
  • 65.9.58.66
whitelisted
ocsp.rootg2.amazontrust.com
  • 99.86.1.226
  • 99.86.1.91
  • 99.86.1.190
  • 99.86.1.61
whitelisted
ocsp.rootca1.amazontrust.com
  • 99.86.1.61
  • 99.86.1.226
  • 99.86.1.91
  • 99.86.1.190
shared
ocsp.sca1b.amazontrust.com
  • 143.204.214.142
  • 143.204.214.169
  • 143.204.214.74
  • 143.204.214.141
whitelisted
ws.driverhive.com
  • 34.224.134.35
  • 52.54.206.195
unknown

Threats

No threats detected
Process
Message
DriverUpdater.exe
Begin logger initialization...
DriverUpdater.exe
Initializing thread ID = 0x23C - Context: DriverHiveEngine - entry point
DriverUpdater.exe
Executable: C:\Program Files\Outbyte\Driver Updater\DriverUpdater.exe
DriverUpdater.exe
Version: 1.0.20.23
DriverUpdater.exe
Maximum filesize set to 4194304 bytes
DriverUpdater.exe
ME not enabled
DriverUpdater.exe
EL not enabled
DriverUpdater.exe
End logger initialization
DriverUpdater.exe
[2022-04-27 00:58:21:201] [dhEngineInit] Windows version: 6.1.7601 Platform: 2
DriverUpdater.exe
[2022-04-27 00:58:21:201] [dhEngineInit] Default Locale ID: 1033