| File name: | laser_1200dpi_v2.zip |
| Full analysis: | https://app.any.run/tasks/6bc28bca-af3e-4c42-ba56-15e87e60921a |
| Verdict: | Malicious activity |
| Analysis date: | August 13, 2019, 16:30:37 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract |
| MD5: | 621BBE9AB87694D59C071C92B96298E2 |
| SHA1: | A5C8321A8DA4311E7705C921C92AA713CACC1068 |
| SHA256: | DE7DA73FC203E195266379C1E3B58D829D77886E2D33FD0699023BFFEB48F539 |
| SSDEEP: | 98304:xfi1UkEBa7RN/e5pRB+YYursw6ONPWQhM83D0GBn/6bOh44/:Unfl9e5pRwYYursZenz0M/Jyq |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 20 |
|---|---|
| ZipBitFlag: | - |
| ZipCompression: | Deflated |
| ZipModifyDate: | 2015:07:02 11:14:17 |
| ZipCRC: | 0xa8256bc1 |
| ZipCompressedSize: | 4951437 |
| ZipUncompressedSize: | 5013886 |
| ZipFileName: | laser_1200dpi_v2/1200laserv2setup.exe |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 352 | "C:\Users\admin\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe" __IRAOFF:662050 "__IRAFN:C:\Users\admin\AppData\Local\Temp\Rar$EXa2072.42106\laser_1200dpi_v2\1200laserv2setup.exe" "__IRCT:1" "__IRTSS:0" "__IRSID:S-1-5-21-1302019708-1500728564-335382590-1000" | C:\Users\admin\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe | 1200laserv2setup.exe | ||||||||||||
User: admin Company: Indigo Rose Corporation Integrity Level: HIGH Description: Setup Application Exit code: 0 Version: 8.2.1.0 Modules
| |||||||||||||||
| 356 | "C:\Users\admin\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe" __IRAOFF:662050 "__IRAFN:C:\Users\admin\AppData\Local\Temp\Rar$EXa2072.36772\laser_1200dpi_v2\1200laserv2setup.exe" "__IRCT:1" "__IRTSS:0" "__IRSID:S-1-5-21-1302019708-1500728564-335382590-1000" | C:\Users\admin\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe | 1200laserv2setup.exe | ||||||||||||
User: admin Company: Indigo Rose Corporation Integrity Level: HIGH Description: Setup Application Exit code: 0 Version: 8.2.1.0 Modules
| |||||||||||||||
| 456 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa2072.36772\laser_1200dpi_v2\1200laserv2setup.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa2072.36772\laser_1200dpi_v2\1200laserv2setup.exe | WinRAR.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: Setup Application Exit code: 0 Version: 8.2.1.0 Modules
| |||||||||||||||
| 1088 | "C:\Program Files\Switch Mouse Driver\UsbGlcsSrv.exe" /start | C:\Program Files\Switch Mouse Driver\UsbGlcsSrv.exe | — | irsetup.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 2072 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\laser_1200dpi_v2.zip" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.60.0 Modules
| |||||||||||||||
| 2168 | "C:\Program Files\Switch Mouse Driver\UsbGlcsSrv.exe" /install /silent | C:\Program Files\Switch Mouse Driver\UsbGlcsSrv.exe | — | irsetup.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 2312 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa2072.42106\laser_1200dpi_v2\1200laserv2setup.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa2072.42106\laser_1200dpi_v2\1200laserv2setup.exe | WinRAR.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: Setup Application Exit code: 0 Version: 8.2.1.0 Modules
| |||||||||||||||
| 2316 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa2072.42106\laser_1200dpi_v2\1200laserv2setup.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa2072.42106\laser_1200dpi_v2\1200laserv2setup.exe | — | WinRAR.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: Setup Application Exit code: 3221226540 Version: 8.2.1.0 Modules
| |||||||||||||||
| 2508 | "C:\Program Files\Switch Mouse Driver\UsbGlcsSrv.exe" /start | C:\Program Files\Switch Mouse Driver\UsbGlcsSrv.exe | — | irsetup.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 2556 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa2072.36772\laser_1200dpi_v2\1200laserv2setup.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa2072.36772\laser_1200dpi_v2\1200laserv2setup.exe | — | WinRAR.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: Setup Application Exit code: 3221226540 Version: 8.2.1.0 Modules
| |||||||||||||||
| (PID) Process: | (2072) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (2072) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (2072) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\72\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2072) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\laser_1200dpi_v2.zip | |||
| (PID) Process: | (2072) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (2072) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (2072) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (2072) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (2072) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
| (PID) Process: | (2072) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 356 | irsetup.exe | C:\Users\admin\AppData\Local\Temp\_ir_sf_temp_0\irsetup.dat | — | |
MD5:— | SHA256:— | |||
| 356 | irsetup.exe | C:\Program Files\SwitchMouseSupportFiles\Uninstall\uniFCC8.tmp | — | |
MD5:— | SHA256:— | |||
| 356 | irsetup.exe | C:\Windows\Switch Mouse Driver Setup Log.txt | text | |
MD5:— | SHA256:— | |||
| 356 | irsetup.exe | C:\Program Files\SwitchMouseSupportFiles\DriverInstallFiles\config.ini | text | |
MD5:E55F9378BBF905CF2F700BC26E475CAF | SHA256:C0AC420FAE36A3D8A96054AC91F77ED8B2BC199AAEE09AF6EAAE171E87B8CF18 | |||
| 2072 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2072.36772\laser_1200dpi_v2\1200laserv2setup.exe | executable | |
MD5:2EC35FB183DFF844AB110163C47EA0B6 | SHA256:0AAF3DF86BD968C9C7032D4607A058204DE439816D3B7A0F9168E0E390A36EF9 | |||
| 356 | irsetup.exe | C:\Program Files\SwitchMouseSupportFiles\DRIVERINSTALL.exe | executable | |
MD5:6FD30EF07C69F29E3CF88E5307E0DAF0 | SHA256:FE3FFAE8899C44632CFCEA619B48DE2202D79C124E16DC0F621185AF26673C0D | |||
| 356 | irsetup.exe | C:\Windows\Switch Mouse Driver\uninstall.exe | executable | |
MD5:3FE7C92DBA5C9240B4AB0D6A87E6166A | SHA256:A7818C1E0DAD1CBBA4D17809688887ADEEAFE940A3CB53A6AEABDFCD196F7258 | |||
| 356 | irsetup.exe | C:\Program Files\SwitchMouseSupportFiles\Uninstall\uninstall.dat | binary | |
MD5:9096991587D8B3D7952383F74C76184C | SHA256:0640FE69D48EDF9D4B10A963D3D92135DCB5EBE6F793679F41436E2E5FC82311 | |||
| 356 | irsetup.exe | C:\Program Files\SwitchMouseSupportFiles\Uninstall\uninstall.xml | xml | |
MD5:BF126A4C7BDE1CCD3F1680FCD11482C5 | SHA256:DBF592EE33F062F3523DDA84D05A355694B620DAFB140AB5BD6500D91ADD8F30 | |||
| 356 | irsetup.exe | C:\Program Files\SwitchMouseSupportFiles\DRIVERUNINSTALL.exe | executable | |
MD5:90E1A57E2AF5BCEF495830DDD79B9DE8 | SHA256:6ABBC43407F999A8CD4F7698A73E093243D2A4BEDB7CF7CB69D68786AC86AC5B | |||