analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

laser_1200dpi_v2.zip

Full analysis: https://app.any.run/tasks/6bc28bca-af3e-4c42-ba56-15e87e60921a
Verdict: Malicious activity
Analysis date: August 13, 2019, 16:30:37
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

621BBE9AB87694D59C071C92B96298E2

SHA1:

A5C8321A8DA4311E7705C921C92AA713CACC1068

SHA256:

DE7DA73FC203E195266379C1E3B58D829D77886E2D33FD0699023BFFEB48F539

SSDEEP:

98304:xfi1UkEBa7RN/e5pRB+YYursw6ONPWQhM83D0GBn/6bOh44/:Unfl9e5pRwYYursZenz0M/Jyq

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • irsetup.exe (PID: 356)
      • 1200laserv2setup.exe (PID: 456)
      • 1200laserv2setup.exe (PID: 2556)
      • DRIVERINSTALL.exe (PID: 4020)
      • UsbGlcsSrv.exe (PID: 1088)
      • UsbGlcsSrv.exe (PID: 2848)
      • UsbGlcsSrv.exe (PID: 2944)
      • irsetup.exe (PID: 352)
      • 1200laserv2setup.exe (PID: 2312)
      • 1200laserv2setup.exe (PID: 2316)
      • DRIVERINSTALL.exe (PID: 2936)
      • UsbGlcsSrv.exe (PID: 2168)
      • UsbGlcsSrv.exe (PID: 2508)
    • Changes the autorun value in the registry

      • irsetup.exe (PID: 356)
      • irsetup.exe (PID: 352)
    • Loads dropped or rewritten executable

      • irsetup.exe (PID: 352)
  • SUSPICIOUS

    • Creates files in the Windows directory

      • irsetup.exe (PID: 356)
      • irsetup.exe (PID: 352)
    • Executable content was dropped or overwritten

      • irsetup.exe (PID: 356)
      • WinRAR.exe (PID: 2072)
      • 1200laserv2setup.exe (PID: 456)
      • DRIVERINSTALL.exe (PID: 4020)
      • 1200laserv2setup.exe (PID: 2312)
      • irsetup.exe (PID: 352)
      • DRIVERINSTALL.exe (PID: 2936)
    • Creates files in the program directory

      • irsetup.exe (PID: 356)
      • DRIVERINSTALL.exe (PID: 4020)
      • irsetup.exe (PID: 352)
      • DRIVERINSTALL.exe (PID: 2936)
    • Creates files in the user directory

      • irsetup.exe (PID: 356)
      • irsetup.exe (PID: 352)
    • Creates a software uninstall entry

      • irsetup.exe (PID: 356)
      • irsetup.exe (PID: 352)
    • Executed as Windows Service

      • UsbGlcsSrv.exe (PID: 2944)
    • Removes files from Windows directory

      • irsetup.exe (PID: 352)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipFileName: laser_1200dpi_v2/1200laserv2setup.exe
ZipUncompressedSize: 5013886
ZipCompressedSize: 4951437
ZipCRC: 0xa8256bc1
ZipModifyDate: 2015:07:02 11:14:17
ZipCompression: Deflated
ZipBitFlag: -
ZipRequiredVersion: 20
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
53
Monitored processes
14
Malicious processes
7
Suspicious processes
2

Behavior graph

Click at the process to see the details
drop and start drop and start drop and start drop and start start drop and start drop and start drop and start drop and start drop and start winrar.exe 1200laserv2setup.exe no specs 1200laserv2setup.exe irsetup.exe driverinstall.exe usbglcssrv.exe no specs usbglcssrv.exe no specs usbglcssrv.exe no specs 1200laserv2setup.exe no specs 1200laserv2setup.exe irsetup.exe driverinstall.exe usbglcssrv.exe no specs usbglcssrv.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2072"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\laser_1200dpi_v2.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.60.0
2556"C:\Users\admin\AppData\Local\Temp\Rar$EXa2072.36772\laser_1200dpi_v2\1200laserv2setup.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa2072.36772\laser_1200dpi_v2\1200laserv2setup.exeWinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup Application
Exit code:
3221226540
Version:
8.2.1.0
456"C:\Users\admin\AppData\Local\Temp\Rar$EXa2072.36772\laser_1200dpi_v2\1200laserv2setup.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa2072.36772\laser_1200dpi_v2\1200laserv2setup.exe
WinRAR.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup Application
Exit code:
0
Version:
8.2.1.0
356"C:\Users\admin\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe" __IRAOFF:662050 "__IRAFN:C:\Users\admin\AppData\Local\Temp\Rar$EXa2072.36772\laser_1200dpi_v2\1200laserv2setup.exe" "__IRCT:1" "__IRTSS:0" "__IRSID:S-1-5-21-1302019708-1500728564-335382590-1000"C:\Users\admin\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe
1200laserv2setup.exe
User:
admin
Company:
Indigo Rose Corporation
Integrity Level:
HIGH
Description:
Setup Application
Exit code:
0
Version:
8.2.1.0
4020"C:\Program Files\SwitchMouseSupportFiles\DRIVERINSTALL.exe"C:\Program Files\SwitchMouseSupportFiles\DRIVERINSTALL.exe
irsetup.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
2848"C:\Program Files\Switch Mouse Driver\UsbGlcsSrv.exe" /install /silentC:\Program Files\Switch Mouse Driver\UsbGlcsSrv.exeirsetup.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
1088"C:\Program Files\Switch Mouse Driver\UsbGlcsSrv.exe" /startC:\Program Files\Switch Mouse Driver\UsbGlcsSrv.exeirsetup.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
2944"C:\Program Files\Switch Mouse Driver\UsbGlcsSrv.exe"C:\Program Files\Switch Mouse Driver\UsbGlcsSrv.exeservices.exe
User:
SYSTEM
Integrity Level:
SYSTEM
2316"C:\Users\admin\AppData\Local\Temp\Rar$EXa2072.42106\laser_1200dpi_v2\1200laserv2setup.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa2072.42106\laser_1200dpi_v2\1200laserv2setup.exeWinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup Application
Exit code:
3221226540
Version:
8.2.1.0
2312"C:\Users\admin\AppData\Local\Temp\Rar$EXa2072.42106\laser_1200dpi_v2\1200laserv2setup.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa2072.42106\laser_1200dpi_v2\1200laserv2setup.exe
WinRAR.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup Application
Exit code:
0
Version:
8.2.1.0
Total events
1 463
Read events
1 409
Write events
54
Delete events
0

Modification events

(PID) Process:(2072) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2072) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2072) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\72\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2072) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\laser_1200dpi_v2.zip
(PID) Process:(2072) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2072) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2072) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2072) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2072) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(2072) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
Executable files
52
Suspicious files
10
Text files
36
Unknown types
10

Dropped files

PID
Process
Filename
Type
356irsetup.exeC:\Users\admin\AppData\Local\Temp\_ir_sf_temp_0\irsetup.dat
MD5:
SHA256:
356irsetup.exeC:\Program Files\SwitchMouseSupportFiles\Uninstall\uniFCC8.tmp
MD5:
SHA256:
2072WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2072.36772\laser_1200dpi_v2\1200laserv2setup.exeexecutable
MD5:2EC35FB183DFF844AB110163C47EA0B6
SHA256:0AAF3DF86BD968C9C7032D4607A058204DE439816D3B7A0F9168E0E390A36EF9
356irsetup.exeC:\Windows\Switch Mouse Driver Setup Log.txttext
MD5:3DD17342F96AE2E0ED0591BB99702306
SHA256:16F499FD95B67CED62085BEDFD87FF3EB0AC8543A6C87B08CCB2A7644D7A6749
356irsetup.exeC:\Program Files\SwitchMouseSupportFiles\DriverInstallFiles\SwitchMouseMonitor.exeexecutable
MD5:1CD7F01673F6E33161770ABC38A3A5BE
SHA256:EE504002B79B50E3DF1EABA99ACB2CDD8976197772A10EEDB691336A658BE6DB
356irsetup.exeC:\Program Files\SwitchMouseSupportFiles\DriverInstallFiles\SwitchMouseConfig.exeexecutable
MD5:668ADB0111F04E5994FC9B72C9E42B0F
SHA256:2F9DA8A2ACA639A3556B681C01D4BC9EC89A6538440E496FC0AB2D7321668C7C
356irsetup.exeC:\Program Files\SwitchMouseSupportFiles\DriverInstallFiles\DRIVERX64\DIFxCmd.exeexecutable
MD5:50E054487573E93D58692EF33C3AA9F2
SHA256:B5F7D55DC5768F8A8FB82AC09A5D4DDD19088678A82F5015D60C1A667FDA9D54
356irsetup.exeC:\Program Files\SwitchMouseSupportFiles\DRIVERINSTALL.exeexecutable
MD5:6FD30EF07C69F29E3CF88E5307E0DAF0
SHA256:FE3FFAE8899C44632CFCEA619B48DE2202D79C124E16DC0F621185AF26673C0D
356irsetup.exeC:\Program Files\SwitchMouseSupportFiles\DRIVERUNINSTALL.exeexecutable
MD5:90E1A57E2AF5BCEF495830DDD79B9DE8
SHA256:6ABBC43407F999A8CD4F7698A73E093243D2A4BEDB7CF7CB69D68786AC86AC5B
356irsetup.exeC:\Program Files\SwitchMouseSupportFiles\DriverInstallFiles\DRIVERX64\devcon.exeexecutable
MD5:163DD046B55D1EBACBFFB631875397F1
SHA256:B2D703AB7263F80876AEBD8AB17D144A0631D8599CA3E3D9FAC26200045D958B
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info