| File name: | eecd9bb65cbcd06804d16c0cacc020ba5e321067dc670d2ed6661bbd1903ed4a |
| Full analysis: | https://app.any.run/tasks/67c5cc92-bbff-48aa-b743-075bebfc598f |
| Verdict: | Malicious activity |
| Analysis date: | February 24, 2019, 15:12:33 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract |
| MD5: | A85A3C56B1B9BF5F16E2786B4A2ACF74 |
| SHA1: | 9F2B46F7C2429495576B1BD06352ACEF40AD470C |
| SHA256: | EECD9BB65CBCD06804D16C0CACC020BA5E321067DC670D2ED6661BBD1903ED4A |
| SSDEEP: | 393216:sN6pidn58JyNJnbR4WyjHPzKHyth/eczN6KqXKIiv:scun5nhqWQP2HyDWcp6nK/v |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 20 |
|---|---|
| ZipBitFlag: | - |
| ZipCompression: | None |
| ZipModifyDate: | 2013:07:01 09:10:14 |
| ZipCRC: | 0x00000000 |
| ZipCompressedSize: | - |
| ZipUncompressedSize: | - |
| ZipFileName: | Photon 3G/ |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 312 | cmd /c NtSetP.bat | C:\Windows\system32\cmd.exe | — | NtSetP.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 504 | "C:\ProgramData\DatacardService\DCService.exe" -install | C:\ProgramData\DatacardService\DCService.exe | — | AutoRunSetup.exe | |||||||||||
User: admin Integrity Level: HIGH Description: RunDCSer 应用程序 Exit code: 0 Version: 2, 0, 0, 47 Modules
| |||||||||||||||
| 1824 | cacls "C:\Program Files\Photon 3G\Huawei\E177" /t /e /c /p Users:f | C:\Windows\system32\cacls.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Control ACLs Program Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2252 | DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{0f042c4b-7047-5128-727d-ca40b721381f}\ew_busfilter.inf" "0" "675f9f793" "00000574" "WinSta0\Default" "000005AC" "208" "C:\Program Files\Photon 3G\Huawei\E177\driver\Driver\X86" | C:\Windows\system32\DrvInst.exe | svchost.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Driver Installation Module Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2280 | /install /debug | C:\Program Files\Photon 3G\Huawei\E177\driver\devsetup32.exe | driversetup.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: Huawei(R) DevSetup Version 1.0.2.3 for Windows 2K, XP, Vista, Win7. Exit code: 0 Version: 1.0.2.3 Modules
| |||||||||||||||
| 2308 | cacls "C:\Program Files\Photon 3G\Huawei\E177" /t /e /c /p everyone:f | C:\Windows\system32\cacls.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Control ACLs Program Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2352 | DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{30d3049c-786e-6ce4-1809-e45bcf09e87c}\ew_hwusbdev.inf" "0" "6e5997267" "0000053C" "WinSta0\Default" "00000574" "208" "C:\Program Files\Photon 3G\Huawei\E177\driver\Driver\X86" | C:\Windows\system32\DrvInst.exe | — | svchost.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Driver Installation Module Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2372 | "C:\Program Files\Photon 3G\Huawei\E177\AddPbk.exe" | C:\Program Files\Photon 3G\Huawei\E177\AddPbk.exe | — | Setup.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 3221225547 Modules
| |||||||||||||||
| 2392 | "C:\Program Files\Photon 3G\Huawei\E177\subinacl.exe" /Subdirectories "C:\Program Files\Photon 3G\Huawei\E177\*.*" /GRANT=s-1-5-32-545=F | C:\Program Files\Photon 3G\Huawei\E177\subinacl.exe | — | Setup.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: SubInAcl Exit code: 0 Version: 5.2.3790.1180 Modules
| |||||||||||||||
| 2500 | "C:\Program Files\Photon 3G\Huawei\E177\subinacl.exe" /Subdirectories "C:\Program Files\Photon 3G\Huawei\E177" /GRANT=s-1-5-32-545=F | C:\Program Files\Photon 3G\Huawei\E177\subinacl.exe | — | Setup.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: SubInAcl Exit code: 0 Version: 5.2.3790.1180 Modules
| |||||||||||||||
| (PID) Process: | (3300) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (3300) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (3300) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3300) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\eecd9bb65cbcd06804d16c0cacc020ba5e321067dc670d2ed6661bbd1903ed4a.zip | |||
| (PID) Process: | (3300) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (3300) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (3300) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (3300) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (3260) Setup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Persisted |
| Operation: | write | Name: | C:\Users\admin\Desktop\Photon 3G\Setup.exe |
Value: 1 | |||
| (PID) Process: | (3260) Setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Huawei Photon 3G |
| Operation: | write | Name: | NSIS:Language |
Value: 1033 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3300 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3300.21519\Photon 3G\data.bin | — | |
MD5:— | SHA256:— | |||
| 3300 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3300.21519\Photon 3G\Setup.exe | — | |
MD5:— | SHA256:— | |||
| 3260 | Setup.exe | C:\Users\admin\AppData\Local\Temp\nsz2E47.tmp\lib7zEx.dll | executable | |
MD5:— | SHA256:— | |||
| 3260 | Setup.exe | C:\Users\admin\AppData\Local\Temp\UTPS\common\plugins\Language\1031.ini | text | |
MD5:— | SHA256:— | |||
| 3260 | Setup.exe | C:\Users\admin\AppData\Local\Temp\UTPS\SysConfig.dat | text | |
MD5:— | SHA256:— | |||
| 3260 | Setup.exe | C:\Users\admin\AppData\Local\Temp\UTPS\common\plugins\Language\1043.ini | text | |
MD5:— | SHA256:— | |||
| 3260 | Setup.exe | C:\Users\admin\AppData\Local\Temp\UTPS\common\plugins\Language\1038.ini | text | |
MD5:— | SHA256:— | |||
| 3260 | Setup.exe | C:\Users\admin\AppData\Local\Temp\UTPS\common\plugins\Language\1030.ini | text | |
MD5:— | SHA256:— | |||
| 3260 | Setup.exe | C:\Users\admin\AppData\Local\Temp\UTPS\common\plugins\Language\1037.ini | text | |
MD5:— | SHA256:— | |||
| 3260 | Setup.exe | C:\Users\admin\AppData\Local\Temp\UTPS\common\plugins\Language\1026.ini | text | |
MD5:— | SHA256:— | |||
Process | Message |
|---|---|
HWDeviceService.exe | InstallService Start |
Photon 3G.exe | 15:14:31:446: ..\..\src\mobilepartner\MobilePartner.cpp: MobilePartnerMain: app path = C:/Program Files/Photon 3G/Huawei/E177
|
Photon 3G.exe | 15:14:31:446 : ..\..\src\sdk\UTPS_SDK.cpp : UTPS_SDK_INIT : Entered
|
Photon 3G.exe | ..\..\src\sdk\UTPS_SDK.cpp: UTPS_SDK_INIT: loading proxy lib...
|
Photon 3G.exe | ..\..\src\sdk\UTPS_SDK.cpp: UTPS_SDK_INIT: setting load hints...
|
Photon 3G.exe | ..\..\src\sdk\UTPS_CALL.cpp: UTPS_CALL_INIT: enter
|
Photon 3G.exe | ..\..\src\sdk\UTPS_CALL.cpp: UTPS_CALL_INIT: enter
|
Photon 3G.exe | ..\..\src\sdk\UTPS_CALLLOG.cpp: UTPS_CALLLOG_INIT: enter
|
Photon 3G.exe | ..\..\src\sdk\UTPS_COMMON.cpp: UTPS_COMMON_INIT: enter
|
Photon 3G.exe | ..\..\src\sdk\UTPS_DEVICE.cpp: UTPS_DEVICE_INIT: enter
|