File name: | Speedlink Strike Gamepad Driver.zip |
Full analysis: | https://app.any.run/tasks/481d893f-62f4-436f-b175-5a7101a86cdf |
Verdict: | Malicious activity |
Analysis date: | August 23, 2020, 17:19:59 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | application/zip |
File info: | Zip archive data, at least v1.0 to extract |
MD5: | 13BC5F01962B7C3B3A0C36FFB0CE5662 |
SHA1: | AD6BBD4A5758EA1CF1F9B3ED2B23F574CB8A27E7 |
SHA256: | FB68305B0F45E7D0C02AEF6FF223E22EDB697380EF70206A931C0B5A80305B59 |
SSDEEP: | 98304:s4c0WVv6bKgekjtyKhH0fpJiEnW59KdTDzHR+PIzmwdTuhn0Sw45:s4zWyHoKhH0BhxdH4Iluhn7wc |
.zip | | | ZIP compressed archive (100) |
---|
ZipRequiredVersion: | 10 |
---|---|
ZipBitFlag: | - |
ZipCompression: | None |
ZipModifyDate: | 2013:09:16 11:33:25 |
ZipCRC: | 0x00000000 |
ZipCompressedSize: | - |
ZipUncompressedSize: | - |
ZipFileName: | Simplicheck/ |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
2808 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa2956.5828\Driver/setup.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa2956.5828\Driver\setup.exe | Setup.exe | ||||||||||||
User: admin Company: Macrovision Corporation Integrity Level: HIGH Description: Setup.exe Exit code: 0 Version: 12.0.49974 Modules
| |||||||||||||||
2908 | "C:\Windows\system32\msiexec.exe" /i C:\Users\admin\AppData\Local\Temp\mgxa07zwkcm\simplicheck.msi | C:\Windows\system32\msiexec.exe | — | simplicheck.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
2956 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Speedlink Strike Gamepad Driver.zip" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.60.0 Modules
| |||||||||||||||
3100 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa2956.5828\Simplicheck/simplicheck.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa2956.5828\Simplicheck\simplicheck.exe | Setup.exe | ||||||||||||
User: admin Company: simplitec GmbH Integrity Level: HIGH Description: simplitec simplicheck (en-US) Exit code: 0 Version: 1.3.10.0 Modules
| |||||||||||||||
3208 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa2956.5828\Setup.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa2956.5828\Setup.exe | WinRAR.exe | ||||||||||||
User: admin Company: Macromedia, Inc. Integrity Level: HIGH Description: Macromedia Projector Exit code: 0 Version: 9.0r383 Modules
| |||||||||||||||
3368 | C:\Windows\system32\DllHost.exe /Processid:{F32D97DF-E3E5-4CB9-9E3E-0EB5B4E49801} | C:\Windows\system32\DllHost.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: COM Surrogate Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
3416 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa2956.5828\Setup.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa2956.5828\Setup.exe | — | WinRAR.exe | |||||||||||
User: admin Company: Macromedia, Inc. Integrity Level: MEDIUM Description: Macromedia Projector Exit code: 3221226540 Version: 9.0r383 Modules
| |||||||||||||||
3932 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa2956.5828\Driver/setup.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa2956.5828\Driver\setup.exe | Setup.exe | ||||||||||||
User: admin Company: Macrovision Corporation Integrity Level: HIGH Description: Setup.exe Exit code: 0 Version: 12.0.49974 Modules
|
(PID) Process: | (2956) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
Operation: | write | Name: | ShellExtBMP |
Value: | |||
(PID) Process: | (2956) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
Operation: | write | Name: | ShellExtIcon |
Value: | |||
(PID) Process: | (2956) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\137\52C64B7E |
Operation: | write | Name: | LanguageList |
Value: en-US | |||
(PID) Process: | (2956) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\137\52C64B7E |
Operation: | write | Name: | @C:\Windows\system32\NetworkExplorer.dll,-1 |
Value: Network | |||
(PID) Process: | (2956) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\Speedlink Strike Gamepad Driver.zip | |||
(PID) Process: | (2956) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | name |
Value: 120 | |||
(PID) Process: | (2956) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | size |
Value: 80 | |||
(PID) Process: | (2956) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | type |
Value: 120 | |||
(PID) Process: | (2956) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | mtime |
Value: 100 | |||
(PID) Process: | (2956) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | UNCAsIntranet |
Value: 0 |
PID | Process | Filename | Type | |
---|---|---|---|---|
3208 | Setup.exe | C:\Users\admin\AppData\Local\Temp\TempFolder.aaa\xtras\NetFile.x32 | executable | |
MD5:54C13B08DE727B951B6F939F274AFC3B | SHA256:B15E895EF5D426D1A56FC6481252732E47CEAEA8DA5601F3A36FE151A52FF642 | |||
2956 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2956.5828\Setup.exe | executable | |
MD5:730BF3D067B9F50851AB90F258F49270 | SHA256:87AAE36066CC1EECC355D1A4355B2DFEC651AD4E25ED71C95631FF06FC5A1701 | |||
2956 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2956.5828\Simplicheck\Simplicheck.exe | executable | |
MD5:3232B760884B8DB88F055DB890C9C727 | SHA256:B15A66FDCD6E7E32C47C045A9E60BA24AFCCCEAE2591739DC985D97313206192 | |||
2956 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2956.5828\Driver\Setup.exe | executable | |
MD5:94036B81782CE7FCE1F2482DC07DF0D9 | SHA256:11550B733F6B11299363396FF25933F7EC9553BFE84FCADF9157E54918F4AE22 | |||
3208 | Setup.exe | C:\Users\admin\AppData\Local\Temp\TempFolder.aaa\xtras\Sound Control.x32 | executable | |
MD5:1A03BE0567D724722081B7E604415E00 | SHA256:169B008438B8CBE9C083E51F9F1BAE47714F8673E5C4107FC8EAF901692656F6 | |||
3208 | Setup.exe | C:\Users\admin\AppData\Local\Temp\TempFolder.aaa\msvcrt.dll | executable | |
MD5:63DA4613383EC70E047B4CD5C48F0B05 | SHA256:D4287AB5E4988DFE99BD54243D50DBE8744094F11FE5F9809A1A6FB9728C2124 | |||
3208 | Setup.exe | C:\Users\admin\AppData\Local\Temp\TempFolder.aaa\xtras\SWADCmpr.x32 | executable | |
MD5:A25BB47F798F0BF6C71E2A8DBD6B3EA4 | SHA256:DD00493DDCA594DB4167EFAFBA25CF124DFBB0A64C428BBEE528E6E3A5933DCD | |||
3208 | Setup.exe | C:\Users\admin\AppData\Local\Temp\TempFolder.aaa\xtras\INetURL.x32 | executable | |
MD5:BBF9E409B202D855DC0478787E61F020 | SHA256:62E5870DF9E8602D230EA9F645139816DC49BA0DD71FA6334A4A85C1A1758667 | |||
3208 | Setup.exe | C:\Users\admin\AppData\Local\Temp\TempFolder.aaa\xtras\MacroMix.x32 | executable | |
MD5:E06B6B6294F0D67202C8682C6EA3DE3C | SHA256:A0A353B65DC799315E22952A0089C5DEEBCA780B9BFC05210A4D62760BB52B21 | |||
3208 | Setup.exe | C:\Users\admin\AppData\Local\Temp\TempFolder.aaa\xtras\NetLingo.x32 | executable | |
MD5:0F1A473ED662C3615DB39CFD19B2A15D | SHA256:829D70B5685977246DCE2EC0CC8EA23F9280E397A63F78FFB97CE00573721722 |