File name: | PL23XX_Prolific_DriverInstaller_v202.zip |
Full analysis: | https://app.any.run/tasks/46440b82-cfc0-4a58-b440-fc58523e58fb |
Verdict: | Malicious activity |
Analysis date: | June 18, 2020, 20:23:24 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | application/zip |
File info: | Zip archive data, at least v2.0 to extract |
MD5: | 0C8CEAFFE1B0F106BDC13316290901FF |
SHA1: | 6A7B3FB201B1555F95CBB66999751ACF2CE9CDDA |
SHA256: | F4A37971BF8FAFE9DFB5F6288F2458C68735DEAA144C46060E690514BA8C6ED0 |
SSDEEP: | 196608:9wDDEcHC/noaxW1slOA9+v5QkVFKJOCqumDsFcx4sobrSdIima7IvM8xGpdb6M1O:90FHC/noax+sQA9yVMMCqxsFlbmKimaq |
.zip | | | ZIP compressed archive (100) |
---|
ZipFileName: | PL23XX_Prolific_DriverInstaller_v202/ |
---|---|
ZipUncompressedSize: | - |
ZipCompressedSize: | - |
ZipCRC: | 0x00000000 |
ZipModifyDate: | 2020:05:27 15:49:12 |
ZipCompression: | None |
ZipBitFlag: | - |
ZipRequiredVersion: | 20 |
PID | CMD | Path | Indicators | Parent process |
---|---|---|---|---|
3184 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\PL23XX_Prolific_DriverInstaller_v202.zip" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | |
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Version: 5.60.0 | ||||
3844 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa3184.17440\PL23XX_Prolific_DriverInstaller_v202\PL23XX-M_LogoDriver_Setup_v202_20200527.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa3184.17440\PL23XX_Prolific_DriverInstaller_v202\PL23XX-M_LogoDriver_Setup_v202_20200527.exe | — | WinRAR.exe |
User: admin Company: Macrovision Corporation Integrity Level: MEDIUM Description: Setup.exe Exit code: 3221226540 Version: 14.0.162 | ||||
2444 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa3184.17440\PL23XX_Prolific_DriverInstaller_v202\PL23XX-M_LogoDriver_Setup_v202_20200527.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa3184.17440\PL23XX_Prolific_DriverInstaller_v202\PL23XX-M_LogoDriver_Setup_v202_20200527.exe | WinRAR.exe | |
User: admin Company: Macrovision Corporation Integrity Level: HIGH Description: Setup.exe Version: 14.0.162 | ||||
3368 | C:\Windows\system32\vssvc.exe | C:\Windows\system32\vssvc.exe | — | services.exe |
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft® Volume Shadow Copy Service Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
2480 | C:\Windows\system32\DllHost.exe /Processid:{F32D97DF-E3E5-4CB9-9E3E-0EB5B4E49801} | C:\Windows\system32\DllHost.exe | — | svchost.exe |
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: COM Surrogate Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
3340 | C:\Users\admin\AppData\Local\Temp\{31D7442E-958C-47AB-9CBC-EA922A318511}\{BC40B9A3-568C-4E39-8EF5-B3883D7152AC}\dpinst32.exe /PATH C:\Users\admin\AppData\Local\Temp\{31D7442E-958C-47AB-9CBC-EA922A318511}\{BC40B9A3-568C-4E39-8EF5-B3883D7152AC}\VISTA\ /SW /LM /SA | C:\Users\admin\AppData\Local\Temp\{31D7442E-958C-47AB-9CBC-EA922A318511}\{BC40B9A3-568C-4E39-8EF5-B3883D7152AC}\dpinst32.exe | PL23XX-M_LogoDriver_Setup_v202_20200527.exe | |
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Driver Package Installer Exit code: 512 Version: 2.1 | ||||
3816 | DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{125f4191-90e2-0f4d-0326-a129b5d04918}\plser.inf" "0" "678fc1f77" "00000550" "WinSta0\Default" "000003F8" "208" "c:\users\admin\appdata\local\temp\{31d7442e-958c-47ab-9cbc-ea922a318511}\{bc40b9a3-568c-4e39-8ef5-b3883d7152ac}\vista" | C:\Windows\system32\DrvInst.exe | svchost.exe | |
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Driver Installation Module Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
3524 | rundll32.exe C:\Windows\system32\pnpui.dll,InstallSecurityPromptRunDllW 20 Global\{14cb892e-6462-7de4-edb1-5f61225b9b5b} Global\{5953bc51-fa40-1a11-4211-0f552fb19601} C:\Windows\System32\DriverStore\Temp\{33884946-a023-5b43-8f47-f233de926504}\plser.inf C:\Windows\System32\DriverStore\Temp\{33884946-a023-5b43-8f47-f233de926504}\plser.cat | C:\Windows\system32\rundll32.exe | — | DrvInst.exe |
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows host process (Rundll32) Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
1032 | DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{11d0f242-18c2-60f3-42dc-002091415f12}\ser2pl.inf" "0" "68ac47307" "000003F8" "WinSta0\Default" "000005A4" "208" "c:\users\admin\appdata\local\temp\{31d7442e-958c-47ab-9cbc-ea922a318511}\{bc40b9a3-568c-4e39-8ef5-b3883d7152ac}\vista" | C:\Windows\system32\DrvInst.exe | svchost.exe | |
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Driver Installation Module Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
2752 | rundll32.exe C:\Windows\system32\pnpui.dll,InstallSecurityPromptRunDllW 20 Global\{4d6b5831-e1c4-277e-f769-d7779b4e0024} Global\{78547585-7eb7-54a7-7c41-3d7fbfef1369} C:\Windows\System32\DriverStore\Temp\{03cb649b-eef6-35a5-02f0-40786fc0957c}\ser2pl.inf C:\Windows\System32\DriverStore\Temp\{03cb649b-eef6-35a5-02f0-40786fc0957c}\ser2pl.cat | C:\Windows\system32\rundll32.exe | — | DrvInst.exe |
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows host process (Rundll32) Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) |
PID | Process | Filename | Type | |
---|---|---|---|---|
2444 | PL23XX-M_LogoDriver_Setup_v202_20200527.exe | C:\Users\admin\AppData\Local\Temp\{31D7442E-958C-47AB-9CBC-EA922A318511}\{BC40B9A3-568C-4E39-8EF5-B3883D7152AC}\setu470a.rra | — | |
MD5:— | SHA256:— | |||
2444 | PL23XX-M_LogoDriver_Setup_v202_20200527.exe | C:\Users\admin\AppData\Local\Temp\{31D7442E-958C-47AB-9CBC-EA922A318511}\{BC40B9A3-568C-4E39-8EF5-B3883D7152AC}\Lice470a.rra | — | |
MD5:— | SHA256:— | |||
2444 | PL23XX-M_LogoDriver_Setup_v202_20200527.exe | C:\Users\admin\AppData\Local\Temp\{31D7442E-958C-47AB-9CBC-EA922A318511}\{BC40B9A3-568C-4E39-8EF5-B3883D7152AC}\dpin4719.rra | — | |
MD5:— | SHA256:— | |||
3184 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3184.17440\PL23XX_Prolific_DriverInstaller_v202\PL2303_DriverInstallerv1.23.0_ReleaseNote.txt | text | |
MD5:EC812F5EE92A8DBFD48416BCD1E1C7D3 | SHA256:A2F243C6BD853449AFC9F4B9C7BB4796F8D0D92833861F6E6F2BE23B24519323 | |||
2444 | PL23XX-M_LogoDriver_Setup_v202_20200527.exe | C:\Users\admin\AppData\Local\Temp\{72C497AC-C219-45C8-8DC2-EDBF3378E027}\Disk1\setup.inx | binary | |
MD5:260B04146C388A27B94AF6EFA727A3A0 | SHA256:B97735BBDEA1AAF7050429EA63895A27A391D1F60FD9039CD1110BFF13C14DD8 | |||
2444 | PL23XX-M_LogoDriver_Setup_v202_20200527.exe | C:\Users\admin\AppData\Local\Temp\{31D7442E-958C-47AB-9CBC-EA922A318511}\{BC40B9A3-568C-4E39-8EF5-B3883D7152AC}\dpin4739.rra | — | |
MD5:— | SHA256:— | |||
2444 | PL23XX-M_LogoDriver_Setup_v202_20200527.exe | C:\Users\admin\AppData\Local\Temp\{31D7442E-958C-47AB-9CBC-EA922A318511}\{BC40B9A3-568C-4E39-8EF5-B3883D7152AC}\setup.inx | binary | |
MD5:260B04146C388A27B94AF6EFA727A3A0 | SHA256:B97735BBDEA1AAF7050429EA63895A27A391D1F60FD9039CD1110BFF13C14DD8 | |||
2444 | PL23XX-M_LogoDriver_Setup_v202_20200527.exe | C:\Users\admin\AppData\Local\Temp\{72C497AC-C219-45C8-8DC2-EDBF3378E027}\Disk1\data1.cab | compressed | |
MD5:0C9D73F223AAB4A47320133F9D77C4DD | SHA256:484905F27EA1B7EF25E077DE3DC957FA143705E649DDEE5BA080DFBE7FD7A8EE | |||
3184 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3184.17440\PL23XX_Prolific_DriverInstaller_v202\PL2303G_DriverInstallerv1.4.0_ReleaseNote.txt | text | |
MD5:A1A35E852D914DCA40B540EB545A8BB6 | SHA256:A3F8C4429323DBA51B901DE62992E15FD7214C648AF0408AED1FB69206453A66 | |||
2444 | PL23XX-M_LogoDriver_Setup_v202_20200527.exe | C:\Users\admin\AppData\Local\Temp\{72C497AC-C219-45C8-8DC2-EDBF3378E027}\Disk1\data1.hdr | compressed | |
MD5:DDDD1AB81429F0833EA2CE7C6575CA1D | SHA256:24ABA0A538F5B875833E27B129B9F94E1FB4B07571AD656F1554911419019561 |