File name:

Amlogic_Driver (1).zip

Full analysis: https://app.any.run/tasks/3f571879-8091-4d24-8add-d69b2ced6c0b
Verdict: Malicious activity
Analysis date: April 13, 2025, 12:47:42
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
arch-exec
arch-doc
Indicators:
MIME: application/zip
File info: Zip archive data, at least v1.0 to extract, compression method=store
MD5:

684CA089E636B9FBAC29502472943256

SHA1:

ED110579A3BB16D819722118013B390A68194A31

SHA256:

CA29B6D5D4774301E3B3D0234990D93661C0EF3ED181009BC4F91C2826B68823

SSDEEP:

49152:VCjSwg7w/T6tIQ0fKLLojLNl09XMWSEknTvLC7MDP6KgYE8Sj24zoxGg0vpy9u9y:VC8o6tIjhvNW9Xc/nTvL4MDvgY3xGjyx

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • dpscat.exe (PID: 1228)
      • dpinst64.exe (PID: 2108)
      • dpinst64.exe (PID: 4200)
      • dpinst64.exe (PID: 812)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • WinRAR.exe (PID: 1760)
      • InstallDriver.exe (PID: 6272)
      • dpinst64.exe (PID: 2108)
    • Drops a system driver (possible attempt to evade defenses)

      • WinRAR.exe (PID: 1760)
      • InstallDriver.exe (PID: 6272)
      • drvinst.exe (PID: 5400)
      • dpinst64.exe (PID: 2108)
    • Executable content was dropped or overwritten

      • InstallDriver.exe (PID: 6272)
      • drvinst.exe (PID: 5400)
      • dpinst64.exe (PID: 2108)
    • Reads security settings of Internet Explorer

      • InstallDriver.exe (PID: 6272)
    • Creates files in the driver directory

      • drvinst.exe (PID: 5400)
    • Adds/modifies Windows certificates

      • dpscat.exe (PID: 1228)
    • Starts a Microsoft application from unusual location

      • dpinst64.exe (PID: 2108)
      • dpinst64.exe (PID: 812)
      • dpinst64.exe (PID: 4200)
    • Creates a software uninstall entry

      • dpinst64.exe (PID: 2108)
  • INFO

    • The sample compiled with arabic language support

      • WinRAR.exe (PID: 1760)
      • InstallDriver.exe (PID: 6272)
      • dpinst64.exe (PID: 2108)
    • The sample compiled with english language support

      • WinRAR.exe (PID: 1760)
      • InstallDriver.exe (PID: 6272)
      • dpinst64.exe (PID: 2108)
      • drvinst.exe (PID: 5400)
    • Manual execution by a user

      • InstallDriver.exe (PID: 6712)
      • InstallDriver.exe (PID: 6272)
      • dpinst64.exe (PID: 4200)
      • dpinst64.exe (PID: 812)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 1760)
    • Create files in a temporary directory

      • dpscat.exe (PID: 1228)
      • InstallDriver.exe (PID: 6272)
      • dpinst64.exe (PID: 2108)
    • Reads the machine GUID from the registry

      • dpscat.exe (PID: 1228)
      • drvinst.exe (PID: 5400)
      • dpinst64.exe (PID: 2108)
    • Creates files in the program directory

      • dpscat.exe (PID: 1228)
      • dpinst64.exe (PID: 2108)
    • Checks supported languages

      • InstallDriver.exe (PID: 6272)
      • dpscat.exe (PID: 1228)
      • dpinst64.exe (PID: 2108)
      • drvinst.exe (PID: 5400)
      • dpinst64.exe (PID: 812)
    • Reads the computer name

      • InstallDriver.exe (PID: 6272)
      • drvinst.exe (PID: 5400)
      • dpscat.exe (PID: 1228)
      • dpinst64.exe (PID: 2108)
      • dpinst64.exe (PID: 812)
    • Process checks computer location settings

      • InstallDriver.exe (PID: 6272)
    • Reads the software policy settings

      • dpscat.exe (PID: 1228)
      • drvinst.exe (PID: 5400)
      • slui.exe (PID: 3956)
      • dpinst64.exe (PID: 2108)
      • slui.exe (PID: 6324)
    • Adds/modifies Windows certificates

      • drvinst.exe (PID: 5400)
    • Checks proxy server information

      • slui.exe (PID: 6324)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 10
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2019:11:07 22:54:10
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: Amlogic_Driver/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
149
Monitored processes
12
Malicious processes
4
Suspicious processes
3

Behavior graph

Click at the process to see the details
start winrar.exe sppextcomobj.exe no specs slui.exe rundll32.exe no specs installdriver.exe no specs installdriver.exe dpscat.exe no specs dpinst64.exe drvinst.exe dpinst64.exe no specs dpinst64.exe slui.exe

Process information

PID
CMD
Path
Indicators
Parent process
644C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -EmbeddingC:\Windows\System32\rundll32.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shcore.dll
c:\windows\system32\imagehlp.dll
812"C:\Users\admin\Desktop\dpinst64.exe" C:\Users\admin\Desktop\dpinst64.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Driver Package Installer
Exit code:
256
Version:
2.1
Modules
Images
c:\users\admin\desktop\dpinst64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
1228"C:\Users\admin\AppData\Local\Temp\7ZipSfx_000\dpscat.exe" C:\Users\admin\AppData\Local\Temp\7ZipSfx_000\dpscat.exeInstallDriver.exe
User:
admin
Company:
http://libusb-win32.sourceforge.net
Integrity Level:
HIGH
Description:
Inf catalog and signing tool
Exit code:
0
Version:
3.0.6.0
Modules
Images
c:\users\admin\appdata\local\temp\7zipsfx_000\dpscat.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
1760"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Amlogic_Driver (1).zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
2108"C:\Users\admin\AppData\Local\Temp\7ZipSfx_000\dpinst64.exe" C:\Users\admin\AppData\Local\Temp\7ZipSfx_000\dpinst64.exe
InstallDriver.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Driver Package Installer
Exit code:
256
Version:
2.1
Modules
Images
c:\users\admin\appdata\local\temp\7zipsfx_000\dpinst64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
3956"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exe
SppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
4200"C:\Users\admin\Desktop\dpinst64.exe" C:\Users\admin\Desktop\dpinst64.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Driver Package Installer
Exit code:
3221226540
Version:
2.1
Modules
Images
c:\users\admin\desktop\dpinst64.exe
c:\windows\system32\ntdll.dll
5400DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{322fe88e-0c1f-c848-b91f-1a2e7ae41a7c}\worldcup_device.inf" "9" "4cb8e3da3" "00000000000001BC" "WinSta0\Default" "00000000000001D4" "208" "c:\users\admin\appdata\local\temp\7zipsfx_000"C:\Windows\System32\drvinst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\drvstore.dll
6272"C:\Users\admin\Desktop\InstallDriver.exe" C:\Users\admin\Desktop\InstallDriver.exe
explorer.exe
User:
admin
Company:
Oleg N. Scherbakov
Integrity Level:
HIGH
Description:
7z Setup SFX (x86)
Exit code:
256
Version:
1.4.1.2100
Modules
Images
c:\users\admin\desktop\installdriver.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
6324C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
Total events
17 093
Read events
17 048
Write events
34
Delete events
11

Modification events

(PID) Process:(1760) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(1760) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(1760) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(1760) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Amlogic_Driver (1).zip
(PID) Process:(1760) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(1760) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(1760) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(1760) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(1760) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF3D0000002D000000FD03000016020000
(PID) Process:(1760) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\ArcColumnWidths
Operation:writeName:name
Value:
256
Executable files
41
Suspicious files
14
Text files
5
Unknown types
0

Dropped files

PID
Process
Filename
Type
1760WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1760.28738\Amlogic_Driver\amd64\libusb0.sysexecutable
MD5:16E18CED459B1824234890386EE66CD5
SHA256:8058F2AFE6EF96A7D2DED432997FD8655970C9EA75A938EE4557D6A2CB4CC989
1760WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1760.28738\Amlogic_Driver\amd64\libusb0.dllexecutable
MD5:1D8215F7F8CD02A553499B534CCFB4D5
SHA256:4F18B5D2C28AA66B648C8683C6D09B52B92CBBEE85984BBEFAD5F38A64BC2A14
1760WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1760.28738\Amlogic_Driver\x86\libusbK_x86.dllexecutable
MD5:1BD4A96D2D682A8C0BB92B8C5491B876
SHA256:A90E3D6961D1C8AFB5BD6D73A5719177A3565215B7EC9B4C535A5F1347853FE9
1760WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1760.28738\Amlogic_Driver\Credits.txttext
MD5:99AA1C5F3E3D7F1BE40EE1B947AFA0DA
SHA256:D59398E658920D16A34FC4A9B3727C0DD6A4200F395E71CEA47A60393ED3EF5A
1760WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1760.28738\Amlogic_Driver\dpscat.exeexecutable
MD5:F5B7C11020FC963662745991F0292C71
SHA256:7619B1E57BA38FB43ADF3B975B5B838AE64BB3896BA94D774E8BBFEB9FE63DCE
1760WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1760.28738\Amlogic_Driver\amd64\libusbK.dllexecutable
MD5:E9E5AAF77A56FA64C700E6F6776C9702
SHA256:15A476D769A3D67668475284FC35EE6EB840AD332CEF800BA8E3BFB35450E17A
1760WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1760.28738\Amlogic_Driver\dpinst.xmltext
MD5:83F46EF4F06D32F8B3201A2EA2189E19
SHA256:127B6D24415B513C1F3B5FFE63AF1B395DBF868DAFEC44C4CBB367D81DB9AE0C
1760WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1760.28738\Amlogic_Driver\InstallDriver.exeexecutable
MD5:BAF9D2FF03436375B4739DC5A86F7DE0
SHA256:CBD3A0DE2862DA2D86DB5012AC984B60B97A8EFC3D29C9D75C7609BAEE99638D
1760WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1760.28738\Amlogic_Driver\WorldCup_Device.infbinary
MD5:89D7CBF94872947C99D1880EE7A7BCCD
SHA256:7F8F41819C3F4185F1D0510EDC1D130ABD4D1B34701240A5A42F21794C7B3B03
1760WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1760.28738\Amlogic_Driver\x86\libusb0.sysexecutable
MD5:C8C9800179AF00C90629514E30873D80
SHA256:AA7D75A4D01B405AAB7C848674BBED392B64C6E374E20FD72ADC3C96294E2F00
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
22
DNS requests
18
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6544
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
GET
200
23.216.77.42:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
2140
SIHClient.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
2140
SIHClient.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:137
whitelisted
23.216.77.42:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
3216
svchost.exe
172.211.123.250:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
6544
svchost.exe
20.190.160.22:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6544
svchost.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
2104
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2140
SIHClient.exe
4.245.163.56:443
slscr.update.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
2140
SIHClient.exe
2.23.246.101:80
www.microsoft.com
Ooredoo Q.S.C.
QA
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
whitelisted
crl.microsoft.com
  • 23.216.77.42
  • 23.216.77.30
  • 23.216.77.25
  • 23.216.77.18
  • 23.216.77.8
  • 23.216.77.6
  • 23.216.77.19
  • 23.216.77.20
  • 23.216.77.28
whitelisted
google.com
  • 142.250.186.110
whitelisted
client.wns.windows.com
  • 172.211.123.250
whitelisted
login.live.com
  • 20.190.160.22
  • 40.126.32.138
  • 40.126.32.72
  • 20.190.160.3
  • 20.190.160.67
  • 40.126.32.134
  • 20.190.160.5
  • 40.126.32.68
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
slscr.update.microsoft.com
  • 4.245.163.56
whitelisted
www.microsoft.com
  • 2.23.246.101
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 52.165.164.15
whitelisted
activation-v2.sls.microsoft.com
  • 20.83.72.98
whitelisted

Threats

No threats detected
No debug info