| File name: | PenMount-Windows-Universal-Driver-V2.4.6.387-WHQL.zip |
| Full analysis: | https://app.any.run/tasks/ed4e1e29-2e22-4675-ada6-0f2c322a2d03 |
| Verdict: | Malicious activity |
| Analysis date: | December 09, 2019, 11:26:26 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract |
| MD5: | 7C280DFDCF99132E479B60ED0AF32432 |
| SHA1: | 74A2460CCA5B3B955622CC84D732AE06AAC8C1CF |
| SHA256: | DA9F29AECABE4EE322D35EDE5F6F06568B9C42A42E6740D04BF5F43556107337 |
| SSDEEP: | 98304:U8Z/GizoQO1iL54S3Bn302d+06CX4LBkWafzReHXGSEh1Z3XFNdTRsOa+KrkfQ75:USGizoFi5d3BEv1+WewHXGSeXFNdTKpd |
| .xpi | | | Mozilla Firefox browser extension (66.6) |
|---|---|---|
| .zip | | | ZIP compressed archive (33.3) |
| ZipRequiredVersion: | 20 |
|---|---|
| ZipBitFlag: | - |
| ZipCompression: | None |
| ZipModifyDate: | 2019:09:18 16:50:19 |
| ZipCRC: | 0x00000000 |
| ZipCompressedSize: | - |
| ZipUncompressedSize: | - |
| ZipFileName: | PenMount Windows Universal Driver V2.4.6.387 (WHQL)/ |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 328 | DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{558790d0-4981-0289-b1d4-5852144c933f}\pmhidser.inf" "0" "6192458b7" "00000568" "WinSta0\Default" "0000052C" "208" "C:\Program Files\PenMount Windows Universal Driver" | C:\Windows\system32\DrvInst.exe | — | svchost.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Driver Installation Module Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 840 | C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted | C:\Windows\System32\svchost.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Host Process for Windows Services Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1216 | "C:\Windows\System32\grpconv.exe" -o | C:\Windows\System32\grpconv.exe | — | runonce.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Progman Group Converter Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1708 | sc start tabletinputservice | C:\Windows\system32\sc.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: A tool to aid in developing services for WindowsNT Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2096 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa4016.33696\PenMount Windows Universal Driver V2.4.6.387 (WHQL)\Setup.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa4016.33696\PenMount Windows Universal Driver V2.4.6.387 (WHQL)\Setup.exe | — | WinRAR.exe | |||||||||||
User: admin Company: PenMount Touch Solutions Integrity Level: MEDIUM Description: PenMount Device Driver Setup Program Exit code: 3221226540 Version: 2.4.6.27 Modules
| |||||||||||||||
| 2232 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa4016.33696\PenMount Windows Universal Driver V2.4.6.387 (WHQL)\Setup.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa4016.33696\PenMount Windows Universal Driver V2.4.6.387 (WHQL)\Setup.exe | WinRAR.exe | ||||||||||||
User: admin Company: PenMount Touch Solutions Integrity Level: HIGH Description: PenMount Device Driver Setup Program Exit code: 0 Version: 2.4.6.27 Modules
| |||||||||||||||
| 2788 | "C:\Windows\system32\rundll32.exe" C:\Windows\system32\shell32.dll,OpenAs_RunDLL C:\Users\admin\AppData\Local\Temp\PenMount-Windows-Universal-Driver-V2.4.6.387-WHQL.zip.xpi | C:\Windows\system32\rundll32.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows host process (Rundll32) Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2916 | DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{5671e559-9c70-73d4-ee65-f529818b2408}\pmHidUsb.inf" "0" "61780d823" "0000052C" "WinSta0\Default" "00000060" "208" "C:\Program Files\PenMount Windows Universal Driver" | C:\Windows\system32\DrvInst.exe | svchost.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Driver Installation Module Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3028 | "C:\Program Files\PenMount Windows Universal Driver\install.exe" /Install | C:\Program Files\PenMount Windows Universal Driver\install.exe | Setup.exe | ||||||||||||
User: admin Company: PenMount Touch Solutions Integrity Level: HIGH Description: PenMount Device Driver Installer Exit code: 0 Version: 2.4.6.27 built by: WinDDK Modules
| |||||||||||||||
| 3092 | "C:\Program Files\PenMount Windows Universal Driver\PMonitor.exe" | C:\Program Files\PenMount Windows Universal Driver\PMonitor.exe | — | explorer.exe | |||||||||||
User: admin Company: Salt Integrity Level: MEDIUM Description: PenMount Monitor Exit code: 0 Version: 1.0.0.92 Modules
| |||||||||||||||
| (PID) Process: | (840) svchost.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\{4040CF00-1B3E-486A-B407-FA14C56B6FC0}\Connection |
| Operation: | write | Name: | PnpInstanceID |
Value: PCI\VEN_8086&DEV_100E&SUBSYS_11001AF4&REV_03\3&13C0B0C5&0&18 | |||
| (PID) Process: | (2788) rundll32.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache |
| Operation: | write | Name: | LangID |
Value: 0904 | |||
| (PID) Process: | (2788) rundll32.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache |
| Operation: | write | Name: | C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe |
Value: Adobe Acrobat Reader DC | |||
| (PID) Process: | (2788) rundll32.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache |
| Operation: | write | Name: | C:\Windows\eHome\ehshell.exe |
Value: Windows Media Center | |||
| (PID) Process: | (2788) rundll32.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache |
| Operation: | write | Name: | C:\Program Files\Internet Explorer\iexplore.exe |
Value: Internet Explorer | |||
| (PID) Process: | (2788) rundll32.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache |
| Operation: | write | Name: | C:\Windows\system32\mspaint.exe |
Value: Paint | |||
| (PID) Process: | (2788) rundll32.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache |
| Operation: | write | Name: | C:\Windows\system32\NOTEPAD.EXE |
Value: Notepad | |||
| (PID) Process: | (2788) rundll32.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache |
| Operation: | write | Name: | C:\PROGRA~1\MICROS~1\Office14\OIS.EXE |
Value: Microsoft Office 2010 | |||
| (PID) Process: | (2788) rundll32.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache |
| Operation: | write | Name: | C:\Program Files\Opera\Opera.exe |
Value: Opera Internet Browser | |||
| (PID) Process: | (2788) rundll32.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache |
| Operation: | write | Name: | C:\Program Files\Windows Photo Viewer\PhotoViewer.dll |
Value: Windows Photo Viewer | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 4016 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa4016.33696\PenMount Windows Universal Driver V2.4.6.387 (WHQL)\Driver\amd64\pmhidusb.sys | executable | |
MD5:— | SHA256:— | |||
| 4016 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa4016.33696\PenMount Windows Universal Driver V2.4.6.387 (WHQL)\Driver\amd64\pmhidmini.sys | executable | |
MD5:— | SHA256:— | |||
| 4016 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa4016.33696\PenMount Windows Universal Driver V2.4.6.387 (WHQL)\Driver\amd64\pmmouhid.sys | executable | |
MD5:— | SHA256:— | |||
| 4016 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa4016.33696\PenMount Windows Universal Driver V2.4.6.387 (WHQL)\Driver\Install64.exe | executable | |
MD5:— | SHA256:— | |||
| 4016 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa4016.33696\PenMount Windows Universal Driver V2.4.6.387 (WHQL)\Driver\amd64\pmmouser.sys | executable | |
MD5:— | SHA256:— | |||
| 4016 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa4016.33696\PenMount Windows Universal Driver V2.4.6.387 (WHQL)\Driver\amd64\pmserenum.sys | executable | |
MD5:— | SHA256:— | |||
| 4016 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa4016.33696\PenMount Windows Universal Driver V2.4.6.387 (WHQL)\Driver\i386\PenMount.dll | executable | |
MD5:— | SHA256:— | |||
| 4016 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa4016.33696\PenMount Windows Universal Driver V2.4.6.387 (WHQL)\Driver\i386\pmCoInstlr.dll | executable | |
MD5:— | SHA256:— | |||
| 4016 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa4016.33696\PenMount Windows Universal Driver V2.4.6.387 (WHQL)\Driver\amd64\WdfCoInstaller01009.dll | executable | |
MD5:— | SHA256:— | |||
| 4016 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa4016.33696\PenMount Windows Universal Driver V2.4.6.387 (WHQL)\Driver\i386\pmhidmini.sys | executable | |
MD5:— | SHA256:— | |||
Process | Message |
|---|---|
Setup.exe | ExecShellAsUser: got desktop |
Setup.exe | ExecShellAsUser: elevated process detected |
Setup.exe | ExecShellAsUser: DLL_PROCESS_DETACH |
Setup.exe | ExecShellAsUser: thread finished |