File name:

PenMount-Windows-Universal-Driver-V2.4.6.387-WHQL.zip

Full analysis: https://app.any.run/tasks/ed4e1e29-2e22-4675-ada6-0f2c322a2d03
Verdict: Malicious activity
Analysis date: December 09, 2019, 11:26:26
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

7C280DFDCF99132E479B60ED0AF32432

SHA1:

74A2460CCA5B3B955622CC84D732AE06AAC8C1CF

SHA256:

DA9F29AECABE4EE322D35EDE5F6F06568B9C42A42E6740D04BF5F43556107337

SSDEEP:

98304:U8Z/GizoQO1iL54S3Bn302d+06CX4LBkWafzReHXGSEh1Z3XFNdTRsOa+KrkfQ75:USGizoFi5d3BEv1+WewHXGSeXFNdTKpd

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Setup.exe (PID: 2096)
      • Setup.exe (PID: 2232)
      • PMonitor.exe (PID: 3092)
      • install.exe (PID: 3028)
    • Loads dropped or rewritten executable

      • Setup.exe (PID: 2232)
      • PMonitor.exe (PID: 3092)
      • svchost.exe (PID: 840)
    • Changes the autorun value in the registry

      • install.exe (PID: 3028)
    • Writes to a start menu file

      • Setup.exe (PID: 2232)
  • SUSPICIOUS

    • Creates files in the Windows directory

      • Setup.exe (PID: 2232)
      • DrvInst.exe (PID: 4092)
      • DrvInst.exe (PID: 328)
      • DrvInst.exe (PID: 2916)
      • install.exe (PID: 3028)
    • Executable content was dropped or overwritten

      • Setup.exe (PID: 2232)
      • WinRAR.exe (PID: 4016)
      • DrvInst.exe (PID: 2916)
      • install.exe (PID: 3028)
    • Creates files in the program directory

      • Setup.exe (PID: 2232)
      • install.exe (PID: 3028)
    • Creates or modifies windows services

      • Setup.exe (PID: 2232)
    • Starts CMD.EXE for commands execution

      • PMonitor.exe (PID: 3092)
    • Starts SC.EXE for service management

      • cmd.exe (PID: 4040)
    • Removes files from Windows directory

      • DrvInst.exe (PID: 4092)
      • DrvInst.exe (PID: 328)
      • DrvInst.exe (PID: 2916)
      • install.exe (PID: 3028)
    • Creates files in the driver directory

      • DrvInst.exe (PID: 328)
      • DrvInst.exe (PID: 2916)
      • DrvInst.exe (PID: 4092)
      • install.exe (PID: 3028)
    • Executed via COM

      • DrvInst.exe (PID: 328)
      • DrvInst.exe (PID: 2916)
      • DrvInst.exe (PID: 4092)
    • Creates a software uninstall entry

      • Setup.exe (PID: 2232)
  • INFO

    • Modifies the open verb of a shell class

      • rundll32.exe (PID: 2788)
    • Manual execution by user

      • PMonitor.exe (PID: 3092)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.xpi | Mozilla Firefox browser extension (66.6)
.zip | ZIP compressed archive (33.3)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2019:09:18 16:50:19
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: PenMount Windows Universal Driver V2.4.6.387 (WHQL)/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
51
Monitored processes
14
Malicious processes
7
Suspicious processes
1

Behavior graph

Click at the process to see the details
start drop and start drop and start drop and start rundll32.exe no specs winrar.exe setup.exe no specs setup.exe install.exe pmonitor.exe no specs cmd.exe no specs sc.exe no specs drvinst.exe no specs svchost.exe no specs drvinst.exe no specs drvinst.exe runonce.exe no specs grpconv.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
328DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{558790d0-4981-0289-b1d4-5852144c933f}\pmhidser.inf" "0" "6192458b7" "00000568" "WinSta0\Default" "0000052C" "208" "C:\Program Files\PenMount Windows Universal Driver"C:\Windows\system32\DrvInst.exesvchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\drvinst.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
840C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestrictedC:\Windows\System32\svchost.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Host Process for Windows Services
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1216"C:\Windows\System32\grpconv.exe" -oC:\Windows\System32\grpconv.exerunonce.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Progman Group Converter
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\grpconv.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1708sc start tabletinputserviceC:\Windows\system32\sc.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
A tool to aid in developing services for WindowsNT
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\sc.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2096"C:\Users\admin\AppData\Local\Temp\Rar$EXa4016.33696\PenMount Windows Universal Driver V2.4.6.387 (WHQL)\Setup.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa4016.33696\PenMount Windows Universal Driver V2.4.6.387 (WHQL)\Setup.exeWinRAR.exe
User:
admin
Company:
PenMount Touch Solutions
Integrity Level:
MEDIUM
Description:
PenMount Device Driver Setup Program
Exit code:
3221226540
Version:
2.4.6.27
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa4016.33696\penmount windows universal driver v2.4.6.387 (whql)\setup.exe
c:\systemroot\system32\ntdll.dll
2232"C:\Users\admin\AppData\Local\Temp\Rar$EXa4016.33696\PenMount Windows Universal Driver V2.4.6.387 (WHQL)\Setup.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa4016.33696\PenMount Windows Universal Driver V2.4.6.387 (WHQL)\Setup.exe
WinRAR.exe
User:
admin
Company:
PenMount Touch Solutions
Integrity Level:
HIGH
Description:
PenMount Device Driver Setup Program
Exit code:
0
Version:
2.4.6.27
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa4016.33696\penmount windows universal driver v2.4.6.387 (whql)\setup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
2788"C:\Windows\system32\rundll32.exe" C:\Windows\system32\shell32.dll,OpenAs_RunDLL C:\Users\admin\AppData\Local\Temp\PenMount-Windows-Universal-Driver-V2.4.6.387-WHQL.zip.xpiC:\Windows\system32\rundll32.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\user32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imagehlp.dll
2916DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{5671e559-9c70-73d4-ee65-f529818b2408}\pmHidUsb.inf" "0" "61780d823" "0000052C" "WinSta0\Default" "00000060" "208" "C:\Program Files\PenMount Windows Universal Driver"C:\Windows\system32\DrvInst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\drvinst.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
3028"C:\Program Files\PenMount Windows Universal Driver\install.exe" /InstallC:\Program Files\PenMount Windows Universal Driver\install.exe
Setup.exe
User:
admin
Company:
PenMount Touch Solutions
Integrity Level:
HIGH
Description:
PenMount Device Driver Installer
Exit code:
0
Version:
2.4.6.27 built by: WinDDK
Modules
Images
c:\program files\penmount windows universal driver\install.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\setupapi.dll
3092"C:\Program Files\PenMount Windows Universal Driver\PMonitor.exe" C:\Program Files\PenMount Windows Universal Driver\PMonitor.exeexplorer.exe
User:
admin
Company:
Salt
Integrity Level:
MEDIUM
Description:
PenMount Monitor
Exit code:
0
Version:
1.0.0.92
Modules
Images
c:\program files\penmount windows universal driver\pmonitor.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
Total events
2 070
Read events
1 745
Write events
321
Delete events
4

Modification events

(PID) Process:(840) svchost.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\{4040CF00-1B3E-486A-B407-FA14C56B6FC0}\Connection
Operation:writeName:PnpInstanceID
Value:
PCI\VEN_8086&DEV_100E&SUBSYS_11001AF4&REV_03\3&13C0B0C5&0&18
(PID) Process:(2788) rundll32.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
Operation:writeName:LangID
Value:
0904
(PID) Process:(2788) rundll32.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
Operation:writeName:C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe
Value:
Adobe Acrobat Reader DC
(PID) Process:(2788) rundll32.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
Operation:writeName:C:\Windows\eHome\ehshell.exe
Value:
Windows Media Center
(PID) Process:(2788) rundll32.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
Operation:writeName:C:\Program Files\Internet Explorer\iexplore.exe
Value:
Internet Explorer
(PID) Process:(2788) rundll32.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
Operation:writeName:C:\Windows\system32\mspaint.exe
Value:
Paint
(PID) Process:(2788) rundll32.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
Operation:writeName:C:\Windows\system32\NOTEPAD.EXE
Value:
Notepad
(PID) Process:(2788) rundll32.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
Operation:writeName:C:\PROGRA~1\MICROS~1\Office14\OIS.EXE
Value:
Microsoft Office 2010
(PID) Process:(2788) rundll32.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
Operation:writeName:C:\Program Files\Opera\Opera.exe
Value:
Opera Internet Browser
(PID) Process:(2788) rundll32.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
Operation:writeName:C:\Program Files\Windows Photo Viewer\PhotoViewer.dll
Value:
Windows Photo Viewer
Executable files
72
Suspicious files
19
Text files
97
Unknown types
40

Dropped files

PID
Process
Filename
Type
4016WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa4016.33696\PenMount Windows Universal Driver V2.4.6.387 (WHQL)\Driver\amd64\pmhidusb.sysexecutable
MD5:
SHA256:
4016WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa4016.33696\PenMount Windows Universal Driver V2.4.6.387 (WHQL)\Driver\amd64\pmhidmini.sysexecutable
MD5:
SHA256:
4016WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa4016.33696\PenMount Windows Universal Driver V2.4.6.387 (WHQL)\Driver\amd64\pmmouhid.sysexecutable
MD5:
SHA256:
4016WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa4016.33696\PenMount Windows Universal Driver V2.4.6.387 (WHQL)\Driver\Install64.exeexecutable
MD5:
SHA256:
4016WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa4016.33696\PenMount Windows Universal Driver V2.4.6.387 (WHQL)\Driver\amd64\pmmouser.sysexecutable
MD5:
SHA256:
4016WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa4016.33696\PenMount Windows Universal Driver V2.4.6.387 (WHQL)\Driver\amd64\pmserenum.sysexecutable
MD5:
SHA256:
4016WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa4016.33696\PenMount Windows Universal Driver V2.4.6.387 (WHQL)\Driver\i386\PenMount.dllexecutable
MD5:
SHA256:
4016WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa4016.33696\PenMount Windows Universal Driver V2.4.6.387 (WHQL)\Driver\i386\pmCoInstlr.dllexecutable
MD5:
SHA256:
4016WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa4016.33696\PenMount Windows Universal Driver V2.4.6.387 (WHQL)\Driver\amd64\WdfCoInstaller01009.dllexecutable
MD5:
SHA256:
4016WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa4016.33696\PenMount Windows Universal Driver V2.4.6.387 (WHQL)\Driver\i386\pmhidmini.sysexecutable
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
Process
Message
Setup.exe
ExecShellAsUser: got desktop
Setup.exe
ExecShellAsUser: elevated process detected
Setup.exe
ExecShellAsUser: DLL_PROCESS_DETACH
Setup.exe
ExecShellAsUser: thread finished