| File name: | PL23XX_Prolific_DriverInstaller_v202.zip |
| Full analysis: | https://app.any.run/tasks/46440b82-cfc0-4a58-b440-fc58523e58fb |
| Verdict: | Malicious activity |
| Analysis date: | June 18, 2020, 20:23:24 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract |
| MD5: | 0C8CEAFFE1B0F106BDC13316290901FF |
| SHA1: | 6A7B3FB201B1555F95CBB66999751ACF2CE9CDDA |
| SHA256: | F4A37971BF8FAFE9DFB5F6288F2458C68735DEAA144C46060E690514BA8C6ED0 |
| SSDEEP: | 196608:9wDDEcHC/noaxW1slOA9+v5QkVFKJOCqumDsFcx4sobrSdIima7IvM8xGpdb6M1O:90FHC/noax+sQA9yVMMCqxsFlbmKimaq |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 20 |
|---|---|
| ZipBitFlag: | - |
| ZipCompression: | None |
| ZipModifyDate: | 2020:05:27 15:49:12 |
| ZipCRC: | 0x00000000 |
| ZipCompressedSize: | - |
| ZipUncompressedSize: | - |
| ZipFileName: | PL23XX_Prolific_DriverInstaller_v202/ |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1032 | DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{11d0f242-18c2-60f3-42dc-002091415f12}\ser2pl.inf" "0" "68ac47307" "000003F8" "WinSta0\Default" "000005A4" "208" "c:\users\admin\appdata\local\temp\{31d7442e-958c-47ab-9cbc-ea922a318511}\{bc40b9a3-568c-4e39-8ef5-b3883d7152ac}\vista" | C:\Windows\system32\DrvInst.exe | svchost.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Driver Installation Module Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2444 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa3184.17440\PL23XX_Prolific_DriverInstaller_v202\PL23XX-M_LogoDriver_Setup_v202_20200527.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa3184.17440\PL23XX_Prolific_DriverInstaller_v202\PL23XX-M_LogoDriver_Setup_v202_20200527.exe | WinRAR.exe | ||||||||||||
User: admin Company: Macrovision Corporation Integrity Level: HIGH Description: Setup.exe Exit code: 0 Version: 14.0.162 Modules
| |||||||||||||||
| 2480 | C:\Windows\system32\DllHost.exe /Processid:{F32D97DF-E3E5-4CB9-9E3E-0EB5B4E49801} | C:\Windows\system32\DllHost.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: COM Surrogate Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2752 | rundll32.exe C:\Windows\system32\pnpui.dll,InstallSecurityPromptRunDllW 20 Global\{4d6b5831-e1c4-277e-f769-d7779b4e0024} Global\{78547585-7eb7-54a7-7c41-3d7fbfef1369} C:\Windows\System32\DriverStore\Temp\{03cb649b-eef6-35a5-02f0-40786fc0957c}\ser2pl.inf C:\Windows\System32\DriverStore\Temp\{03cb649b-eef6-35a5-02f0-40786fc0957c}\ser2pl.cat | C:\Windows\system32\rundll32.exe | — | DrvInst.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows host process (Rundll32) Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3184 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\PL23XX_Prolific_DriverInstaller_v202.zip" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.60.0 Modules
| |||||||||||||||
| 3340 | C:\Users\admin\AppData\Local\Temp\{31D7442E-958C-47AB-9CBC-EA922A318511}\{BC40B9A3-568C-4E39-8EF5-B3883D7152AC}\dpinst32.exe /PATH C:\Users\admin\AppData\Local\Temp\{31D7442E-958C-47AB-9CBC-EA922A318511}\{BC40B9A3-568C-4E39-8EF5-B3883D7152AC}\VISTA\ /SW /LM /SA | C:\Users\admin\AppData\Local\Temp\{31D7442E-958C-47AB-9CBC-EA922A318511}\{BC40B9A3-568C-4E39-8EF5-B3883D7152AC}\dpinst32.exe | PL23XX-M_LogoDriver_Setup_v202_20200527.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Driver Package Installer Exit code: 512 Version: 2.1 Modules
| |||||||||||||||
| 3368 | C:\Windows\system32\vssvc.exe | C:\Windows\system32\vssvc.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft® Volume Shadow Copy Service Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3524 | rundll32.exe C:\Windows\system32\pnpui.dll,InstallSecurityPromptRunDllW 20 Global\{14cb892e-6462-7de4-edb1-5f61225b9b5b} Global\{5953bc51-fa40-1a11-4211-0f552fb19601} C:\Windows\System32\DriverStore\Temp\{33884946-a023-5b43-8f47-f233de926504}\plser.inf C:\Windows\System32\DriverStore\Temp\{33884946-a023-5b43-8f47-f233de926504}\plser.cat | C:\Windows\system32\rundll32.exe | — | DrvInst.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows host process (Rundll32) Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3816 | DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{125f4191-90e2-0f4d-0326-a129b5d04918}\plser.inf" "0" "678fc1f77" "00000550" "WinSta0\Default" "000003F8" "208" "c:\users\admin\appdata\local\temp\{31d7442e-958c-47ab-9cbc-ea922a318511}\{bc40b9a3-568c-4e39-8ef5-b3883d7152ac}\vista" | C:\Windows\system32\DrvInst.exe | svchost.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Driver Installation Module Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3844 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa3184.17440\PL23XX_Prolific_DriverInstaller_v202\PL23XX-M_LogoDriver_Setup_v202_20200527.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa3184.17440\PL23XX_Prolific_DriverInstaller_v202\PL23XX-M_LogoDriver_Setup_v202_20200527.exe | — | WinRAR.exe | |||||||||||
User: admin Company: Macrovision Corporation Integrity Level: MEDIUM Description: Setup.exe Exit code: 3221226540 Version: 14.0.162 Modules
| |||||||||||||||
| (PID) Process: | (3184) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (3184) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (3184) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\12F\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3184) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\12F\52C64B7E |
| Operation: | write | Name: | @C:\Windows\system32\NetworkExplorer.dll,-1 |
Value: Network | |||
| (PID) Process: | (3184) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\PL23XX_Prolific_DriverInstaller_v202.zip | |||
| (PID) Process: | (3184) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (3184) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (3184) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (3184) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (3184) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\12F\52C64B7E |
| Operation: | write | Name: | @C:\Windows\system32\notepad.exe,-469 |
Value: Text Document | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2444 | PL23XX-M_LogoDriver_Setup_v202_20200527.exe | C:\Users\admin\AppData\Local\Temp\{31D7442E-958C-47AB-9CBC-EA922A318511}\{BC40B9A3-568C-4E39-8EF5-B3883D7152AC}\setu470a.rra | — | |
MD5:— | SHA256:— | |||
| 2444 | PL23XX-M_LogoDriver_Setup_v202_20200527.exe | C:\Users\admin\AppData\Local\Temp\{31D7442E-958C-47AB-9CBC-EA922A318511}\{BC40B9A3-568C-4E39-8EF5-B3883D7152AC}\Lice470a.rra | — | |
MD5:— | SHA256:— | |||
| 2444 | PL23XX-M_LogoDriver_Setup_v202_20200527.exe | C:\Users\admin\AppData\Local\Temp\{31D7442E-958C-47AB-9CBC-EA922A318511}\{BC40B9A3-568C-4E39-8EF5-B3883D7152AC}\dpin4719.rra | — | |
MD5:— | SHA256:— | |||
| 3184 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3184.17440\PL23XX_Prolific_DriverInstaller_v202\PL2303 Windows Driver Manual v1.23.0.pdf | ||
MD5:2B7E8222A57ADAD60E0D1B1166162741 | SHA256:6BE6F8F0E6195682C55506B0CEFBB8BEBFA66144ECA18BC9DFFB159021BCCD56 | |||
| 2444 | PL23XX-M_LogoDriver_Setup_v202_20200527.exe | C:\Users\admin\AppData\Local\Temp\{31D7442E-958C-47AB-9CBC-EA922A318511}\{BC40B9A3-568C-4E39-8EF5-B3883D7152AC}\dpin4739.rra | — | |
MD5:— | SHA256:— | |||
| 3184 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3184.17440\PL23XX_Prolific_DriverInstaller_v202\PL2303CheckChipVersion_ReadMe.txt | text | |
MD5:DD492ADC19B46415F0C938574A2C45D3 | SHA256:1F12AD0D28C866EDE018C9EE40CCE6E9E7ABA959D543488B2DCA9A29BFAAB139 | |||
| 2444 | PL23XX-M_LogoDriver_Setup_v202_20200527.exe | C:\Users\admin\AppData\Local\Temp\{31D7442E-958C-47AB-9CBC-EA922A318511}\{BC40B9A3-568C-4E39-8EF5-B3883D7152AC}\Rele4758.rra | — | |
MD5:— | SHA256:— | |||
| 3184 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3184.17440\PL23XX_Prolific_DriverInstaller_v202\PL2303G_DriverInstallerv1.4.0_ReleaseNote.txt | text | |
MD5:A1A35E852D914DCA40B540EB545A8BB6 | SHA256:A3F8C4429323DBA51B901DE62992E15FD7214C648AF0408AED1FB69206453A66 | |||
| 2444 | PL23XX-M_LogoDriver_Setup_v202_20200527.exe | C:\Users\admin\AppData\Local\Temp\{31D7442E-958C-47AB-9CBC-EA922A318511}\{BC40B9A3-568C-4E39-8EF5-B3883D7152AC}\Setu4777.rra | — | |
MD5:— | SHA256:— | |||
| 3184 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3184.17440\PL23XX_Prolific_DriverInstaller_v202\PL2303_CheckChipVersion_v1006.exe | executable | |
MD5:7CA5C3E079FC7ED8D64BF53908ECFE0C | SHA256:C6A97348CEEB69BF694AF5C2B051AE7CEFC8F3F7DBEF508E8AFA23FBDEF79722 | |||