File name:

Driver USB to serial (1).EXE

Full analysis: https://app.any.run/tasks/25b50912-7b91-4b8e-bc4d-b0d0ebb321a5
Verdict: Malicious activity
Analysis date: May 15, 2025, 16:53:29
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, RAR self-extracting archive, 4 sections
MD5:

EB3AE641AF53431260E4D77B635E5187

SHA1:

84DDDF900AB86F470D269D06DDD48A8897DB847C

SHA256:

D12109675109512B6825C283E13F673B2F24F5E7E0791C1D64E73EBBECA263E2

SSDEEP:

6144:O8U2qy6rRZb7jxGYXGG+alpQE63f8igy2BDEtgnY9UPiH4aYufJFvDJW:Qzy6rRxEm+hwdzagY9Ut4U

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • SETUP.EXE (PID: 6108)
      • DRVSETUP64.exe (PID: 632)
      • SETUP.EXE (PID: 4620)
  • SUSPICIOUS

    • Drops a system driver (possible attempt to evade defenses)

      • Driver USB to serial (1).EXE.exe (PID: 6824)
      • DRVSETUP64.exe (PID: 632)
      • drvinst.exe (PID: 4024)
      • drvinst.exe (PID: 2088)
    • Creates file in the systems drive root

      • Driver USB to serial (1).EXE.exe (PID: 6824)
    • Executable content was dropped or overwritten

      • Driver USB to serial (1).EXE.exe (PID: 6824)
      • DRVSETUP64.exe (PID: 632)
      • drvinst.exe (PID: 4024)
      • drvinst.exe (PID: 2088)
    • Reads security settings of Internet Explorer

      • Driver USB to serial (1).EXE.exe (PID: 6824)
      • DRVSETUP64.exe (PID: 632)
    • Creates files in the driver directory

      • drvinst.exe (PID: 4024)
      • drvinst.exe (PID: 2088)
  • INFO

    • Reads the computer name

      • Driver USB to serial (1).EXE.exe (PID: 6824)
      • DRVSETUP64.exe (PID: 632)
    • Checks supported languages

      • Driver USB to serial (1).EXE.exe (PID: 6824)
      • SETUP.EXE (PID: 4620)
      • DRVSETUP64.exe (PID: 632)
      • drvinst.exe (PID: 4024)
    • The sample compiled with chinese language support

      • Driver USB to serial (1).EXE.exe (PID: 6824)
    • The sample compiled with english language support

      • Driver USB to serial (1).EXE.exe (PID: 6824)
      • DRVSETUP64.exe (PID: 632)
      • drvinst.exe (PID: 4024)
      • drvinst.exe (PID: 2088)
    • Process checks computer location settings

      • Driver USB to serial (1).EXE.exe (PID: 6824)
    • Create files in a temporary directory

      • DRVSETUP64.exe (PID: 632)
    • Reads the machine GUID from the registry

      • drvinst.exe (PID: 4024)
      • DRVSETUP64.exe (PID: 632)
      • drvinst.exe (PID: 2088)
    • Reads the software policy settings

      • drvinst.exe (PID: 2088)
      • DRVSETUP64.exe (PID: 632)
      • drvinst.exe (PID: 4024)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | WinRAR Self Extracting archive (94.8)
.scr | Windows screen saver (2.3)
.dll | Win32 Dynamic Link Library (generic) (1.2)
.exe | Win32 Executable (generic) (0.8)
.exe | Generic Win/DOS Executable (0.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2007:05:22 04:59:14+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 5
CodeSize: 81920
InitializedDataSize: 17920
UninitializedDataSize: -
EntryPoint: 0x1000
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
140
Monitored processes
8
Malicious processes
5
Suspicious processes
1

Behavior graph

Click at the process to see the details
start driver usb to serial (1).exe.exe setup.exe no specs setup.exe drvsetup64.exe sppextcomobj.exe no specs slui.exe no specs drvinst.exe drvinst.exe

Process information

PID
CMD
Path
Indicators
Parent process
632C:\WCH.CN\CH341SER\DRVSETUP64\DRVSETUP64.EXEC:\WCH.CN\CH341SER\DRVSETUP64\DRVSETUP64.exe
SETUP.EXE
User:
admin
Integrity Level:
HIGH
Description:
EXE For Driver Installation
Exit code:
1
Version:
1, 6, 8, 0
Modules
Images
c:\wch.cn\ch341ser\drvsetup64\drvsetup64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
2088DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{0bc682a7-29f5-e54a-9a54-b21881122307}\CH341SER.INF" "9" "4dbd0d02f" "0000000000000200" "WinSta0\Default" "0000000000000204" "208" "C:\WCH.CN\CH341SER"C:\Windows\System32\drvinst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
3758096967
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\drvstore.dll
4024DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{8eb630aa-6acc-8f49-95cc-77a6856bd635}\CH341SER.INF" "9" "4dbd0d02f" "00000000000001D0" "WinSta0\Default" "00000000000001E0" "208" "C:\WCH.CN\CH341SER"C:\Windows\System32\drvinst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
3758096967
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\drvstore.dll
4620"C:\WCH.CN\CH341SER\SETUP.EXE" C:\WCH.CN\CH341SER\SETUP.EXE
Driver USB to serial (1).EXE.exe
User:
admin
Integrity Level:
HIGH
Description:
EXE For Driver Installation
Exit code:
0
Version:
1, 6, 8, 0
Modules
Images
c:\wch.cn\ch341ser\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acgenral.dll
6080"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exeSppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
6108"C:\WCH.CN\CH341SER\SETUP.EXE" C:\WCH.CN\CH341SER\SETUP.EXEDriver USB to serial (1).EXE.exe
User:
admin
Integrity Level:
MEDIUM
Description:
EXE For Driver Installation
Exit code:
3221226540
Version:
1, 6, 8, 0
Modules
Images
c:\wch.cn\ch341ser\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
6592C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
6824"C:\Users\admin\AppData\Local\Temp\Driver USB to serial (1).EXE.exe" C:\Users\admin\AppData\Local\Temp\Driver USB to serial (1).EXE.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\driver usb to serial (1).exe.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
Total events
9 572
Read events
9 570
Write events
2
Delete events
0

Modification events

(PID) Process:(6824) Driver USB to serial (1).EXE.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR SFX
Operation:writeName:C%%WCH.CN%CH341SER
Value:
C:\WCH.CN\CH341SER
(PID) Process:(632) DRVSETUP64.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\Setup\SetupapiLogStatus
Operation:writeName:setupapi.dev.log
Value:
4096
Executable files
16
Suspicious files
18
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
6824Driver USB to serial (1).EXE.exeC:\WCH.CN\CH341SER\CH341SER.INFbinary
MD5:35E7C67A6522DED6611EDE19C37241C5
SHA256:11B026414C2AF50CED5DCE6B5749F20E1432D7DCDEB19F4B7BD8DC14D272DF4B
6824Driver USB to serial (1).EXE.exeC:\WCH.CN\CH341SER\CH341SER.VXDexecutable
MD5:BE7438420F1DA854917F58CAD557476D
SHA256:2A946F316EDD7E1185DEEAFDC2DE52B2D2843198BE098A724233C12F9CCD0DAE
6824Driver USB to serial (1).EXE.exeC:\WCH.CN\CH341SER\CH341SER.SYSexecutable
MD5:ED9001EF992D89810F060CBA66A07FB0
SHA256:593A5169E2F1E78505BE588E3D57F76003D7E318117D0932BA138308BFC8801C
6824Driver USB to serial (1).EXE.exeC:\WCH.CN\CH341SER\DRVSETUP64\DRVSETUP64.exeexecutable
MD5:0F0E6EFC2860EF57AEC282522C6B9D94
SHA256:30B7CDBE1AC2E0BA7F8A532D9E92429E8B6B522D922DE81C89FA9BADAF6AFA92
632DRVSETUP64.exeC:\Users\admin\AppData\Local\Temp\{8eb630aa-6acc-8f49-95cc-77a6856bd635}\CH341SER.INFbinary
MD5:35E7C67A6522DED6611EDE19C37241C5
SHA256:11B026414C2AF50CED5DCE6B5749F20E1432D7DCDEB19F4B7BD8DC14D272DF4B
632DRVSETUP64.exeC:\Users\admin\AppData\Local\Temp\{8eb630aa-6acc-8f49-95cc-77a6856bd635}\CH341SER.CATbinary
MD5:DBC4F08F8350F0B8FF95420B352B506A
SHA256:65C95FAEE9777E4C2E658F7DCEFB8F6EF484D37473F169A04F5E5AB67D895F1E
632DRVSETUP64.exeC:\Users\admin\AppData\Local\Temp\{8eb630aa-6acc-8f49-95cc-77a6856bd635}\SETFD5E.tmpbinary
MD5:35E7C67A6522DED6611EDE19C37241C5
SHA256:11B026414C2AF50CED5DCE6B5749F20E1432D7DCDEB19F4B7BD8DC14D272DF4B
6824Driver USB to serial (1).EXE.exeC:\WCH.CN\CH341SER\SETUP.EXEexecutable
MD5:BAE3BE76CC10ABAE31EB562ABAFE28DE
SHA256:11B24C6CF02A68CCAA07061B2128DE1A3C071C3C16F7C508DD1C5FDA88939179
6824Driver USB to serial (1).EXE.exeC:\WCH.CN\CH341SER\CH341SER.CATbinary
MD5:DBC4F08F8350F0B8FF95420B352B506A
SHA256:65C95FAEE9777E4C2E658F7DCEFB8F6EF484D37473F169A04F5E5AB67D895F1E
6824Driver USB to serial (1).EXE.exeC:\WCH.CN\CH341SER\CH341PT.DLLexecutable
MD5:7D1EF8C5BA7151A98CD694F522A0BE6C
SHA256:7A905A8FC29D43623C1A7EEC32CF37392B6C0DEC002022229AD09AA15B1602D4
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
21
DNS requests
15
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
2.19.11.120:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6544
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
2040
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
2040
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2104
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2.19.11.120:80
crl.microsoft.com
Elisa Oyj
NL
whitelisted
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
172.211.123.250:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
4380
RUXIMICS.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6544
svchost.exe
20.190.160.65:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6544
svchost.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
4
System
192.168.100.255:137
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 40.127.240.158
  • 51.104.136.2
  • 4.231.128.59
whitelisted
google.com
  • 216.58.212.174
whitelisted
crl.microsoft.com
  • 2.19.11.120
  • 2.19.11.105
whitelisted
www.microsoft.com
  • 95.101.149.131
  • 23.35.229.160
whitelisted
client.wns.windows.com
  • 172.211.123.250
whitelisted
login.live.com
  • 20.190.160.65
  • 40.126.32.74
  • 20.190.160.5
  • 20.190.160.128
  • 40.126.32.140
  • 40.126.32.68
  • 20.190.160.131
  • 40.126.32.134
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
slscr.update.microsoft.com
  • 52.149.20.212
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 40.69.42.241
whitelisted

Threats

No threats detected
No debug info