File name:

activator.zip

Full analysis: https://app.any.run/tasks/74e1113d-12df-409a-9bcd-6f89e7170020
Verdict: Malicious activity
Analysis date: July 05, 2018, 04:44:02
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

9A942C07B6A88B43612D1F7EA1D79ADB

SHA1:

54EA1E2071CC3516E5543529F781359CBE4D8FDD

SHA256:

EE791763A0BEA206BC32F72899206B9A2425952EFB204A58866AC3722E76E954

SSDEEP:

98304:aU3LNO6RFGKur16hvbDpUbva4pdaN0ueDPJCWoe84VoNXu:a4Ls6RsUUbvpp+0u4BCp4VoNXu

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • usb_network_gate.exe (PID: 3200)
      • usb_network_gate.exe (PID: 2720)
      • setup_server_ung.exe (PID: 2136)
      • activator.exe (PID: 3000)
      • UsbService.exe (PID: 3608)
      • UsbService.exe (PID: 2756)
      • UsbService.exe (PID: 2480)
      • activator.exe (PID: 2180)
      • UsbService.exe (PID: 2024)
    • Loads dropped or rewritten executable

      • UsbService.exe (PID: 3608)
      • UsbService.exe (PID: 2756)
      • UsbService.exe (PID: 2024)
    • Changes settings of System certificates

      • UsbService.exe (PID: 2756)
      • UsbService.exe (PID: 3608)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • usb_network_gate.exe (PID: 3200)
      • usb_network_gate.exe (PID: 2720)
      • usb_network_gate.tmp (PID: 3584)
      • DrvInst.exe (PID: 3252)
      • setup_server_ung.exe (PID: 2136)
      • 7zFM.exe (PID: 1172)
      • DrvInst.exe (PID: 2824)
      • DrvInst.exe (PID: 3560)
      • DllHost.exe (PID: 3816)
      • activator.exe (PID: 2180)
    • Reads the Windows organization settings

      • usb_network_gate.tmp (PID: 3584)
    • Reads Windows owner settings

      • usb_network_gate.tmp (PID: 3584)
    • Creates files in the Windows directory

      • DrvInst.exe (PID: 3252)
      • setup_server_ung.exe (PID: 2136)
      • DrvInst.exe (PID: 2824)
      • DrvInst.exe (PID: 3560)
      • DrvInst.exe (PID: 2884)
      • UsbService.exe (PID: 2756)
      • UsbService.exe (PID: 2024)
    • Removes files from Windows directory

      • DrvInst.exe (PID: 3252)
      • setup_server_ung.exe (PID: 2136)
      • DrvInst.exe (PID: 3560)
      • DrvInst.exe (PID: 2824)
      • UsbService.exe (PID: 2756)
      • UsbService.exe (PID: 2024)
    • Creates files in the driver directory

      • DrvInst.exe (PID: 3252)
      • setup_server_ung.exe (PID: 2136)
      • DrvInst.exe (PID: 2824)
      • DrvInst.exe (PID: 3560)
    • Creates or modifies windows services

      • setup_server_ung.exe (PID: 2136)
    • Creates files in the program directory

      • UsbService.exe (PID: 2756)
    • Adds / modifies Windows certificates

      • UsbService.exe (PID: 3608)
      • UsbService.exe (PID: 2756)
    • Uses NETSH.EXE for network configuration

      • usb_network_gate.tmp (PID: 3584)
    • Low-level read access rights to disk partition

      • UsbService.exe (PID: 2756)
      • UsbService.exe (PID: 2024)
  • INFO

    • Application was dropped or rewritten from another process

      • usb_network_gate.tmp (PID: 3584)
      • usb_network_gate.tmp (PID: 4048)
    • Creates files in the program directory

      • usb_network_gate.tmp (PID: 3584)
    • Loads dropped or rewritten executable

      • usb_network_gate.tmp (PID: 3584)
    • Dropped object may contain URL's

      • DrvInst.exe (PID: 2824)
      • DrvInst.exe (PID: 3252)
      • usb_network_gate.tmp (PID: 3584)
      • DrvInst.exe (PID: 3560)
      • setup_server_ung.exe (PID: 2136)
      • UsbService.exe (PID: 2024)
      • UsbService.exe (PID: 2756)
    • Reads settings of System Certificates

      • DrvInst.exe (PID: 2104)
      • DrvInst.exe (PID: 2884)
    • Creates a software uninstall entry

      • usb_network_gate.tmp (PID: 3584)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2015:12:29 17:15:00
ZipCRC: 0xe24ff983
ZipCompressedSize: 3676
ZipUncompressedSize: 6144
ZipFileName: activator.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
73
Monitored processes
20
Malicious processes
9
Suspicious processes
3

Behavior graph

Click at the process to see the details
start drop and start drop and start drop and start drop and start drop and start 7zfm.exe usb_network_gate.exe usb_network_gate.tmp no specs usb_network_gate.exe usb_network_gate.tmp setup_server_ung.exe drvinst.exe drvinst.exe drvinst.exe activator.exe drvinst.exe no specs drvinst.exe no specs usbservice.exe usbservice.exe no specs usbservice.exe netsh.exe no specs netsh.exe no specs Copy/Move/Rename/Delete/Link Object activator.exe usbservice.exe

Process information

PID
CMD
Path
Indicators
Parent process
1172"C:\Program Files\7-Zip\7zFM.exe" "C:\Users\admin\AppData\Local\Temp\activator.zip"C:\Program Files\7-Zip\7zFM.exe
explorer.exe
User:
admin
Company:
Igor Pavlov
Integrity Level:
MEDIUM
Description:
7-Zip File Manager
Exit code:
0
Version:
16.04
Modules
Images
c:\program files\7-zip\7zfm.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1380"C:\Windows\system32\netsh.exe" advfirewall firewall add rule name=u2ec_service dir=in action=allow program="C:\Program Files\Eltima Software\USB Network Gate\UsbService.exe" enable=yesC:\Windows\system32\netsh.exeusb_network_gate.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Network Command Shell
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\netsh.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\credui.dll
c:\windows\system32\user32.dll
2024"C:\Program Files\Eltima Software\USB Network Gate\UsbService.exe"C:\Program Files\Eltima Software\USB Network Gate\UsbService.exe
services.exe
User:
SYSTEM
Company:
ELTIMA Software
Integrity Level:
SYSTEM
Description:
USB Network Gate
Exit code:
0
Version:
8.0.1859
Modules
Images
c:\program files\eltima software\usb network gate\usbservice.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\user32.dll
2104DrvInst.exe "1" "200" "UsbEStub\Devices\0004" "" "" "6c5c6bf7f" "00000000" "000005F8" "000005FC"C:\Windows\system32\DrvInst.exesvchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\drvinst.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
2136"C:\Program Files\Eltima Software\USB Network Gate\drv\NT6\setup_server_ung.exe"C:\Program Files\Eltima Software\USB Network Gate\drv\NT6\setup_server_ung.exe
usb_network_gate.tmp
User:
admin
Integrity Level:
HIGH
Description:
Setup USB drivers
Exit code:
1
Version:
2.5.0.
Modules
Images
c:\program files\eltima software\usb network gate\drv\nt6\setup_server_ung.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2148"C:\Windows\system32\netsh.exe" advfirewall firewall add rule name=u2ec_gui dir=in action=allow program="C:\Program Files\Eltima Software\USB Network Gate\UsbConfig.exe" enable=yesC:\Windows\system32\netsh.exeusb_network_gate.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Network Command Shell
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\netsh.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\credui.dll
c:\windows\system32\user32.dll
2180"C:\Program Files\Eltima Software\USB Network Gate\activator.exe" C:\Program Files\Eltima Software\USB Network Gate\activator.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\program files\eltima software\usb network gate\activator.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2480"C:\Program Files\Eltima Software\USB Network Gate\UsbService.exe" enableC:\Program Files\Eltima Software\USB Network Gate\UsbService.exeusb_network_gate.tmp
User:
admin
Company:
ELTIMA Software
Integrity Level:
HIGH
Description:
USB Network Gate
Exit code:
4294967295
Version:
8.0.1859
Modules
Images
c:\program files\eltima software\usb network gate\usbservice.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\user32.dll
2720"C:\Users\admin\Desktop\usb_network_gate.exe" C:\Users\admin\Desktop\usb_network_gate.exe
explorer.exe
User:
admin
Company:
ELTIMA Software
Integrity Level:
MEDIUM
Description:
USB Network Gate
Exit code:
0
Version:
Usb Network Gate 8.0
Modules
Images
c:\users\admin\desktop\usb_network_gate.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2756"C:\Program Files\Eltima Software\USB Network Gate\UsbService.exe"C:\Program Files\Eltima Software\USB Network Gate\UsbService.exe
services.exe
User:
SYSTEM
Company:
ELTIMA Software
Integrity Level:
SYSTEM
Description:
USB Network Gate
Exit code:
0
Version:
8.0.1859
Modules
Images
c:\program files\eltima software\usb network gate\usbservice.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\user32.dll
Total events
747
Read events
497
Write events
250
Delete events
0

Modification events

(PID) Process:(3584) usb_network_gate.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
000E0000482C53DE1A14D401
(PID) Process:(3584) usb_network_gate.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:SessionHash
Value:
C8A46D3D40BF90AFD8BDFB016B8199263D69D5E80D9EE42830E6742245DFDD87
(PID) Process:(3584) usb_network_gate.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Sequence
Value:
1
(PID) Process:(3584) usb_network_gate.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:RegFiles0000
Value:
C:\Program Files\Eltima Software\USB Network Gate\usb4citrix.dll
(PID) Process:(3584) usb_network_gate.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:RegFilesHash
Value:
E20296DFBC3E9A8F5B82AE01468D86DF7D709DCFFEE154EB04FD5361E9D13DCF
(PID) Process:(2136) setup_server_ung.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\Setup\SetupapiLogStatus
Operation:writeName:setupapi.dev.log
Value:
4096
(PID) Process:(2136) setup_server_ung.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\93\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3584) usb_network_gate.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\ELTIMA Software\UsbToEthernetConnector
Operation:writeName:u2ec_log
Value:
C:\Program Files\Eltima Software\USB Network Gate\u2ec.log
(PID) Process:(3584) usb_network_gate.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Terminal Server Client\Default\AddIns\usb4rdp
Operation:writeName:Name
Value:
C:\Program Files\Eltima Software\USB Network Gate\usb4rdp32.dll
(PID) Process:(3584) usb_network_gate.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\ELTIMA Software\UsbToEthernetConnector
Operation:writeName:settingsPath
Value:
C:\ProgramData\Eltima Software\UNG
Executable files
27
Suspicious files
46
Text files
242
Unknown types
19

Dropped files

PID
Process
Filename
Type
11727zFM.exeC:\Users\admin\AppData\Local\Temp\7zE494256AA\usb_network_gate.exe
MD5:
SHA256:
3584usb_network_gate.tmpC:\Program Files\Eltima Software\USB Network Gate\is-ADNM9.tmp
MD5:
SHA256:
3584usb_network_gate.tmpC:\Program Files\Eltima Software\USB Network Gate\is-2JEED.tmp
MD5:
SHA256:
3584usb_network_gate.tmpC:\Program Files\Eltima Software\USB Network Gate\is-TA4B9.tmp
MD5:
SHA256:
3584usb_network_gate.tmpC:\Program Files\Eltima Software\USB Network Gate\is-OAEGQ.tmp
MD5:
SHA256:
3584usb_network_gate.tmpC:\Program Files\Eltima Software\USB Network Gate\is-GJOMN.tmp
MD5:
SHA256:
3584usb_network_gate.tmpC:\Program Files\Eltima Software\USB Network Gate\is-5R87I.tmp
MD5:
SHA256:
3584usb_network_gate.tmpC:\Program Files\Eltima Software\USB Network Gate\is-UOCS0.tmp
MD5:
SHA256:
3584usb_network_gate.tmpC:\Program Files\Eltima Software\USB Network Gate\is-08V3D.tmp
MD5:
SHA256:
3584usb_network_gate.tmpC:\Program Files\Eltima Software\USB Network Gate\is-GV9EL.tmp
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
7
DNS requests
3
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2756
UsbService.exe
GET
304
2.16.186.56:80
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab
unknown
whitelisted
2024
UsbService.exe
GET
304
2.16.186.56:80
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2756
UsbService.exe
2.16.186.56:80
www.download.windowsupdate.com
Akamai International B.V.
whitelisted
2756
UsbService.exe
188.40.191.126:443
activate.eltima.com
Hetzner Online GmbH
DE
suspicious
2756
UsbService.exe
78.46.96.38:443
appstatico.eltima.com
Hetzner Online GmbH
DE
suspicious
2024
UsbService.exe
2.16.186.56:80
www.download.windowsupdate.com
Akamai International B.V.
whitelisted
2024
UsbService.exe
78.46.96.38:443
appstatico.eltima.com
Hetzner Online GmbH
DE
suspicious
3608
UsbService.exe
78.46.96.38:443
appstatico.eltima.com
Hetzner Online GmbH
DE
suspicious

DNS requests

Domain
IP
Reputation
appstatico.eltima.com
  • 78.46.96.38
suspicious
www.download.windowsupdate.com
  • 2.16.186.56
  • 2.16.186.81
whitelisted
activate.eltima.com
  • 188.40.191.126
suspicious

Threats

No threats detected
No debug info