| File name: | samsung-samsung-mobile-usb-modem-outbyte-driver-updater.zip |
| Full analysis: | https://app.any.run/tasks/68126a3b-1d64-4261-ab79-5aab3dfb061c |
| Verdict: | Malicious activity |
| Analysis date: | April 27, 2022, 00:56:05 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract |
| MD5: | AF0E399A9BBD51688A3151400209561C |
| SHA1: | 0DF8CA0F7E607F70A94AF71FBC394B64EA4E5A3A |
| SHA256: | B945AEA3A2D123A925F4035529013C5D1EB5F85C618EB4122A3FA44A280749C2 |
| SSDEEP: | 196608:9Yq73RcpKFX+SkzrvmovPTvtuJqUb8l1al4/Toic2nM62h9jUdJCFHdFiYK+IPU+:9qWXSrv9MJdKalKTlu/jO0FH2BPjr/jr |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipFileName: | samsung-samsung-mobile-usb-modem-outbyte-driver-updater.exe |
|---|---|
| ZipUncompressedSize: | 17055312 |
| ZipCompressedSize: | 16670204 |
| ZipCRC: | 0x7df6e51e |
| ZipModifyDate: | 2022:04:27 09:54:26 |
| ZipCompression: | Deflated |
| ZipBitFlag: | - |
| ZipRequiredVersion: | 20 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 588 | "C:\Program Files\Outbyte\Driver Updater\DriverUpdater.exe" /FromInstaller /AutoScan | C:\Program Files\Outbyte\Driver Updater\DriverUpdater.exe | Installer.exe | ||||||||||||
User: admin Company: Outbyte Integrity Level: HIGH Description: Driver Updater Exit code: 0 Version: 2.1.17.5814 Modules
| |||||||||||||||
| 1764 | "C:\Users\admin\Desktop\samsung-samsung-mobile-usb-modem-outbyte-driver-updater.exe" | C:\Users\admin\Desktop\samsung-samsung-mobile-usb-modem-outbyte-driver-updater.exe | — | Explorer.EXE | |||||||||||
User: admin Company: Outbyte Integrity Level: MEDIUM Description: Outbyte Driver Updater Installation File Exit code: 3221226540 Version: 2.1.17.5814 Modules
| |||||||||||||||
| 2176 | "C:\Users\admin\Desktop\samsung-samsung-mobile-usb-modem-outbyte-driver-updater.exe" | C:\Users\admin\Desktop\samsung-samsung-mobile-usb-modem-outbyte-driver-updater.exe | Explorer.EXE | ||||||||||||
User: admin Company: Outbyte Integrity Level: HIGH Description: Outbyte Driver Updater Installation File Exit code: 0 Version: 2.1.17.5814 Modules
| |||||||||||||||
| 2556 | "C:\Program Files\Outbyte\Driver Updater\DriverUpdater.exe" /Install /SendInfo /AutoStart | C:\Program Files\Outbyte\Driver Updater\DriverUpdater.exe | Installer.exe | ||||||||||||
User: admin Company: Outbyte Integrity Level: HIGH Description: Driver Updater Exit code: 0 Version: 2.1.17.5814 Modules
| |||||||||||||||
| 3304 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\samsung-samsung-mobile-usb-modem-outbyte-driver-updater.zip" | C:\Program Files\WinRAR\WinRAR.exe | Explorer.EXE | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| 4076 | "C:\Users\admin\AppData\Local\Temp\is-6807847.tmp\Installer.exe" /spid:2176 /splha:20523328 | C:\Users\admin\AppData\Local\Temp\is-6807847.tmp\Installer.exe | samsung-samsung-mobile-usb-modem-outbyte-driver-updater.exe | ||||||||||||
User: admin Company: Outbyte Integrity Level: HIGH Description: Installer Exit code: 0 Version: 2.1.17.5814 Modules
| |||||||||||||||
| (PID) Process: | (3304) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (3304) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (3304) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3304) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip | |||
| (PID) Process: | (3304) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (3304) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\samsung-samsung-mobile-usb-modem-outbyte-driver-updater.zip | |||
| (PID) Process: | (3304) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (3304) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (3304) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (3304) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3304 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3304.15698\samsung-samsung-mobile-usb-modem-outbyte-driver-updater.exe | executable | |
MD5:— | SHA256:— | |||
| 2176 | samsung-samsung-mobile-usb-modem-outbyte-driver-updater.exe | C:\Users\admin\AppData\Local\Temp\is-6807847.tmp\Lang\deu.lng | binary | |
MD5:— | SHA256:— | |||
| 2176 | samsung-samsung-mobile-usb-modem-outbyte-driver-updater.exe | C:\Users\admin\AppData\Local\Temp\is-6807847.tmp\Lang\ptb.lng | binary | |
MD5:— | SHA256:— | |||
| 2176 | samsung-samsung-mobile-usb-modem-outbyte-driver-updater.exe | C:\Users\admin\AppData\Local\Temp\is-6807847.tmp\Lang\enu.lng | binary | |
MD5:— | SHA256:— | |||
| 2176 | samsung-samsung-mobile-usb-modem-outbyte-driver-updater.exe | C:\Users\admin\AppData\Local\Temp\is-6807847.tmp\Localizer.dll | executable | |
MD5:— | SHA256:— | |||
| 2176 | samsung-samsung-mobile-usb-modem-outbyte-driver-updater.exe | C:\Users\admin\AppData\Local\Temp\is-6807847.tmp\CommonForms.Site.dll | executable | |
MD5:— | SHA256:— | |||
| 2176 | samsung-samsung-mobile-usb-modem-outbyte-driver-updater.exe | C:\Users\admin\AppData\Local\Temp\is-6807847.tmp\SetupHelper.dll | executable | |
MD5:— | SHA256:— | |||
| 2176 | samsung-samsung-mobile-usb-modem-outbyte-driver-updater.exe | C:\Users\admin\AppData\Local\Temp\is-6807847.tmp\GoogleAnalyticsHelper.dll | executable | |
MD5:— | SHA256:— | |||
| 2176 | samsung-samsung-mobile-usb-modem-outbyte-driver-updater.exe | C:\Users\admin\AppData\Local\Temp\is-6807847.tmp\InstallerUtils.dll | executable | |
MD5:— | SHA256:— | |||
| 2176 | samsung-samsung-mobile-usb-modem-outbyte-driver-updater.exe | C:\Users\admin\AppData\Local\Temp\is-6807847.tmp\Installer.exe | odttf | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
4076 | Installer.exe | GET | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAeYNgOt45kIIZygDCe8imw%3D | US | der | 471 b | whitelisted |
488 | lsass.exe | GET | 200 | 65.9.58.194:80 | http://o.ss2.us//MEowSDBGMEQwQjAJBgUrDgMCGgUABBSLwZ6EW5gdYc9UaSEaaLjjETNtkAQUv1%2B30c7dH4b0W1Ws3NcQwg6piOcCCQCnDkpMNIK3fw%3D%3D | US | der | 1.70 Kb | whitelisted |
4076 | Installer.exe | GET | 200 | 209.197.3.8:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?c5888855d0234fc8 | US | compressed | 4.70 Kb | whitelisted |
4076 | Installer.exe | POST | 200 | 172.217.18.110:80 | http://www.google-analytics.com/collect | US | image | 35 b | whitelisted |
4076 | Installer.exe | POST | 200 | 172.217.18.110:80 | http://www.google-analytics.com/collect | US | image | 35 b | whitelisted |
4076 | Installer.exe | POST | 200 | 172.217.18.110:80 | http://www.google-analytics.com/collect | US | image | 35 b | whitelisted |
4076 | Installer.exe | GET | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBR0tOcjGcdlkhVARHvHzj6Qwhh26wQUpI3lvnx55HAjbS4pNK0jWNz1MX8CEA%2F2i1mkgFikrMhtVqD%2FhM0%3D | US | der | 471 b | whitelisted |
4076 | Installer.exe | POST | 200 | 172.217.18.110:80 | http://www.google-analytics.com/collect | US | image | 35 b | whitelisted |
4076 | Installer.exe | POST | 200 | 172.217.18.110:80 | http://www.google-analytics.com/collect | US | image | 35 b | whitelisted |
4076 | Installer.exe | POST | 200 | 172.217.18.110:80 | http://www.google-analytics.com/collect | US | image | 35 b | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4076 | Installer.exe | 45.33.97.245:443 | outbyte.com | Linode, LLC | US | unknown |
4076 | Installer.exe | 209.197.3.8:80 | ctldl.windowsupdate.com | Highwinds Network Group, Inc. | US | whitelisted |
488 | lsass.exe | 65.9.58.194:80 | o.ss2.us | AT&T Services, Inc. | US | suspicious |
488 | lsass.exe | 99.86.1.61:80 | ocsp.rootg2.amazontrust.com | AT&T Services, Inc. | US | whitelisted |
488 | lsass.exe | 143.204.214.142:80 | ocsp.sca1b.amazontrust.com | — | US | whitelisted |
588 | DriverUpdater.exe | 34.224.134.35:80 | ws.driverhive.com | Amazon.com, Inc. | US | unknown |
588 | DriverUpdater.exe | 52.41.132.197:443 | outbyteapp.com | Amazon.com, Inc. | US | unknown |
588 | DriverUpdater.exe | 51.222.203.38:443 | du.outbyte.com | — | GB | malicious |
588 | DriverUpdater.exe | 45.33.97.245:443 | outbyte.com | Linode, LLC | US | unknown |
488 | lsass.exe | 99.86.1.226:80 | ocsp.rootg2.amazontrust.com | AT&T Services, Inc. | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
outbyte.com |
| suspicious |
ctldl.windowsupdate.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
www.google-analytics.com |
| whitelisted |
outbyteapp.com |
| unknown |
o.ss2.us |
| whitelisted |
ocsp.rootg2.amazontrust.com |
| whitelisted |
ocsp.rootca1.amazontrust.com |
| shared |
ocsp.sca1b.amazontrust.com |
| whitelisted |
ws.driverhive.com |
| unknown |
Process | Message |
|---|---|
DriverUpdater.exe | Begin logger initialization...
|
DriverUpdater.exe | Initializing thread ID = 0x23C - Context: DriverHiveEngine - entry point
|
DriverUpdater.exe | Executable: C:\Program Files\Outbyte\Driver Updater\DriverUpdater.exe
|
DriverUpdater.exe | Version: 1.0.20.23
|
DriverUpdater.exe | Maximum filesize set to 4194304 bytes
|
DriverUpdater.exe | ME not enabled
|
DriverUpdater.exe | EL not enabled
|
DriverUpdater.exe | End logger initialization
|
DriverUpdater.exe | [2022-04-27 00:58:21:201] [dhEngineInit] Windows version: 6.1.7601 Platform: 2
|
DriverUpdater.exe | [2022-04-27 00:58:21:201] [dhEngineInit] Default Locale ID: 1033
|