download:

DCcduino_ch340-drivers.zip

Full analysis: https://app.any.run/tasks/87414982-cf0b-43dc-b2f6-a58f7b6a73b0
Verdict: Malicious activity
Analysis date: April 25, 2019, 11:18:59
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v1.0 to extract
MD5:

BB4B0F3F428B17CCEC69B29E38F5386D

SHA1:

4007B7152907389CA8CC35FF36CFEA49D1710AF6

SHA256:

B9CEDB1C0F122DE38E9A3AEE93ABC02085F91B678077AE75BFCCC594F301BC0C

SSDEEP:

12288:UPi9BYuhKwax04Z6RZHyianxi47XZ5VLe/CgSqvkoSdF:UwSAnyHZze/BSqvkHF

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • ƒ£øÈµ˜ ‘.EXE (PID: 2360)
      • SETUP.EXE (PID: 3176)
      • SETUP.EXE (PID: 1592)
      • ƒ£øÈµ˜ ‘.EXE (PID: 2924)
    • Loads dropped or rewritten executable

      • SETUP.EXE (PID: 1592)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2664)
      • SETUP.EXE (PID: 1592)
    • Creates files in the Windows directory

      • DrvInst.exe (PID: 1472)
      • SETUP.EXE (PID: 1592)
    • Creates files in the driver directory

      • DrvInst.exe (PID: 1472)
      • SETUP.EXE (PID: 1592)
    • Removes files from Windows directory

      • DrvInst.exe (PID: 1472)
      • SETUP.EXE (PID: 1592)
  • INFO

    • Adds / modifies Windows certificates

      • DrvInst.exe (PID: 1472)
    • Changes settings of System certificates

      • DrvInst.exe (PID: 1472)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.xpi | Mozilla Firefox browser extension (66.6)
.zip | ZIP compressed archive (33.3)

EXIF

ZIP

ZipRequiredVersion: 10
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2013:08:09 21:26:06
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: CH341SER_LINUX/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
40
Monitored processes
7
Malicious processes
3
Suspicious processes
1

Behavior graph

Click at the process to see the details
drop and start drop and start drop and start drop and start start winrar.exe ƒ£øèµ˜ ‘.exe no specs notepad.exe no specs setup.exe no specs setup.exe drvinst.exe no specs ƒ£øèµ˜ ‘.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1472DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{789d9362-9a73-169b-4457-d91cd3005365}\CH341SER.INF" "0" "606613b1f" "0000055C" "WinSta0\Default" "000005BC" "208" "C:\Users\admin\AppData\Local\Temp\Rar$EXa2664.26815\CH341SER_WIN\CH341SER"C:\Windows\system32\DrvInst.exesvchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\drvinst.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1592"C:\Users\admin\AppData\Local\Temp\Rar$EXa2664.26815\CH341SER_WIN\CH341SER\SETUP.EXE" C:\Users\admin\AppData\Local\Temp\Rar$EXa2664.26815\CH341SER_WIN\CH341SER\SETUP.EXE
WinRAR.exe
User:
admin
Integrity Level:
HIGH
Description:
EXE For Driver Installation
Exit code:
1
Version:
1, 6, 0, 0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2664.26815\ch341ser_win\ch341ser\setup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
2360"C:\Users\admin\AppData\Local\Temp\Rar$EXa2664.18750\CH341SER_WIN\INSTALL\ƒ£øÈµ˜ ‘.EXE" C:\Users\admin\AppData\Local\Temp\Rar$EXa2664.18750\CH341SER_WIN\INSTALL\ƒ£øÈµ˜ ‘.EXEWinRAR.exe
User:
admin
Company:
南京沁恒电子有限公司
Integrity Level:
MEDIUM
Description:
1.5
Exit code:
0
Version:
1.50
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2664.18750\ch341ser_win\install\ƒ£øèµ˜ ‘.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvbvm60.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
2664"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\DCcduino_ch340-drivers.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2924"C:\Users\admin\AppData\Local\Temp\Rar$EXa2664.29089\CH341SER_WIN\INSTALL\ƒ£øÈµ˜ ‘.EXE" C:\Users\admin\AppData\Local\Temp\Rar$EXa2664.29089\CH341SER_WIN\INSTALL\ƒ£øÈµ˜ ‘.EXEWinRAR.exe
User:
admin
Company:
南京沁恒电子有限公司
Integrity Level:
MEDIUM
Description:
1.5
Exit code:
0
Version:
1.50
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2664.29089\ch341ser_win\install\ƒ£øèµ˜ ‘.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvbvm60.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
3176"C:\Users\admin\AppData\Local\Temp\Rar$EXa2664.26815\CH341SER_WIN\CH341SER\SETUP.EXE" C:\Users\admin\AppData\Local\Temp\Rar$EXa2664.26815\CH341SER_WIN\CH341SER\SETUP.EXEWinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Description:
EXE For Driver Installation
Exit code:
3221226540
Version:
1, 6, 0, 0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2664.26815\ch341ser_win\ch341ser\setup.exe
c:\systemroot\system32\ntdll.dll
3360"C:\Windows\system32\NOTEPAD.EXE" C:\Users\admin\AppData\Local\Temp\Rar$DIa2664.25470\README.TXTC:\Windows\system32\NOTEPAD.EXEWinRAR.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\notepad.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
Total events
520
Read events
463
Write events
57
Delete events
0

Modification events

(PID) Process:(2664) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2664) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2664) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\62\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2664) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\DCcduino_ch340-drivers.zip
(PID) Process:(2664) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2664) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2664) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2664) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2664) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\62\52C64B7E
Operation:writeName:@C:\Windows\system32\notepad.exe,-469
Value:
Text Document
(PID) Process:(2664) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
Executable files
32
Suspicious files
13
Text files
153
Unknown types
93

Dropped files

PID
Process
Filename
Type
2664WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2664.18750\CH341SER_LINUX\ch34x.ctext
MD5:
SHA256:
2664WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2664.18750\__MACOSX\CH341SER_LINUX\._ch34x.cad
MD5:
SHA256:
2664WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2664.18750\__MACOSX\CH341SER_LINUX\._readme.txtad
MD5:
SHA256:
2664WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2664.18750\__MACOSX\._CH341SER_LINUXad
MD5:
SHA256:
2664WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2664.18750\__MACOSX\CH341SER_LINUX\._Makefilead
MD5:
SHA256:
2664WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2664.18750\__MACOSX\CH341SER_MAC\.___MACOSXad
MD5:
SHA256:
2664WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2664.18750\CH341SER_LINUX\readme.txttext
MD5:
SHA256:
2664WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2664.18750\CH341SER_MAC\ch34xInstall.pkgxar
MD5:
SHA256:
2664WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2664.18750\__MACOSX\CH341SER_MAC\._ch34xInstall.pkgad
MD5:
SHA256:
2664WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2664.18750\CH341SER_MAC\readme.pdfpdf
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info