File name:

Speedlink Strike Gamepad Driver.zip

Full analysis: https://app.any.run/tasks/481d893f-62f4-436f-b175-5a7101a86cdf
Verdict: Malicious activity
Analysis date: August 23, 2020, 17:19:59
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v1.0 to extract
MD5:

13BC5F01962B7C3B3A0C36FFB0CE5662

SHA1:

AD6BBD4A5758EA1CF1F9B3ED2B23F574CB8A27E7

SHA256:

FB68305B0F45E7D0C02AEF6FF223E22EDB697380EF70206A931C0B5A80305B59

SSDEEP:

98304:s4c0WVv6bKgekjtyKhH0fpJiEnW59KdTDzHR+PIzmwdTuhn0Sw45:s4zWyHoKhH0BhxdH4Iluhn7wc

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • Setup.exe (PID: 3208)
      • setup.exe (PID: 2808)
    • Actions looks like stealing of personal data

      • WinRAR.exe (PID: 2956)
      • Setup.exe (PID: 3208)
    • Application was dropped or rewritten from another process

      • Setup.exe (PID: 3416)
      • Setup.exe (PID: 3208)
      • setup.exe (PID: 2808)
      • setup.exe (PID: 3932)
      • simplicheck.exe (PID: 3100)
    • Changes settings of System certificates

      • msiexec.exe (PID: 2908)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2956)
      • Setup.exe (PID: 3208)
      • setup.exe (PID: 2808)
      • setup.exe (PID: 3932)
      • simplicheck.exe (PID: 3100)
    • Creates files in the user directory

      • setup.exe (PID: 2808)
      • setup.exe (PID: 3932)
    • Searches for installed software

      • setup.exe (PID: 2808)
    • Executed via COM

      • DllHost.exe (PID: 3368)
    • Creates COM task schedule object

      • setup.exe (PID: 2808)
    • Adds / modifies Windows certificates

      • msiexec.exe (PID: 2908)
    • Starts Microsoft Installer

      • simplicheck.exe (PID: 3100)
    • Creates a software uninstall entry

      • setup.exe (PID: 2808)
    • Creates files in the program directory

      • setup.exe (PID: 2808)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 10
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2013:09:16 11:33:25
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: Simplicheck/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
48
Monitored processes
8
Malicious processes
3
Suspicious processes
3

Behavior graph

Click at the process to see the details
drop and start drop and start start winrar.exe setup.exe no specs setup.exe setup.exe setup.exe SPPSurrogate no specs simplicheck.exe msiexec.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2808"C:\Users\admin\AppData\Local\Temp\Rar$EXa2956.5828\Driver/setup.exe"C:\Users\admin\AppData\Local\Temp\Rar$EXa2956.5828\Driver\setup.exe
Setup.exe
User:
admin
Company:
Macrovision Corporation
Integrity Level:
HIGH
Description:
Setup.exe
Exit code:
0
Version:
12.0.49974
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2956.5828\driver\setup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2908"C:\Windows\system32\msiexec.exe" /i C:\Users\admin\AppData\Local\Temp\mgxa07zwkcm\simplicheck.msiC:\Windows\system32\msiexec.exesimplicheck.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2956"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Speedlink Strike Gamepad Driver.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3100"C:\Users\admin\AppData\Local\Temp\Rar$EXa2956.5828\Simplicheck/simplicheck.exe"C:\Users\admin\AppData\Local\Temp\Rar$EXa2956.5828\Simplicheck\simplicheck.exe
Setup.exe
User:
admin
Company:
simplitec GmbH
Integrity Level:
HIGH
Description:
simplitec simplicheck (en-US)
Exit code:
0
Version:
1.3.10.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2956.5828\simplicheck\simplicheck.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3208"C:\Users\admin\AppData\Local\Temp\Rar$EXa2956.5828\Setup.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa2956.5828\Setup.exe
WinRAR.exe
User:
admin
Company:
Macromedia, Inc.
Integrity Level:
HIGH
Description:
Macromedia Projector
Exit code:
0
Version:
9.0r383
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2956.5828\setup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
3368C:\Windows\system32\DllHost.exe /Processid:{F32D97DF-E3E5-4CB9-9E3E-0EB5B4E49801}C:\Windows\system32\DllHost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
COM Surrogate
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\dllhost.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3416"C:\Users\admin\AppData\Local\Temp\Rar$EXa2956.5828\Setup.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa2956.5828\Setup.exeWinRAR.exe
User:
admin
Company:
Macromedia, Inc.
Integrity Level:
MEDIUM
Description:
Macromedia Projector
Exit code:
3221226540
Version:
9.0r383
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2956.5828\setup.exe
c:\systemroot\system32\ntdll.dll
3932"C:\Users\admin\AppData\Local\Temp\Rar$EXa2956.5828\Driver/setup.exe"C:\Users\admin\AppData\Local\Temp\Rar$EXa2956.5828\Driver\setup.exe
Setup.exe
User:
admin
Company:
Macrovision Corporation
Integrity Level:
HIGH
Description:
Setup.exe
Exit code:
0
Version:
12.0.49974
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2956.5828\driver\setup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
Total events
907
Read events
734
Write events
173
Delete events
0

Modification events

(PID) Process:(2956) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2956) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2956) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\137\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2956) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\137\52C64B7E
Operation:writeName:@C:\Windows\system32\NetworkExplorer.dll,-1
Value:
Network
(PID) Process:(2956) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Speedlink Strike Gamepad Driver.zip
(PID) Process:(2956) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2956) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2956) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2956) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2956) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
Executable files
35
Suspicious files
17
Text files
42
Unknown types
2

Dropped files

PID
Process
Filename
Type
2956WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2956.5828\Driver\Setup.exeexecutable
MD5:94036B81782CE7FCE1F2482DC07DF0D9
SHA256:11550B733F6B11299363396FF25933F7EC9553BFE84FCADF9157E54918F4AE22
3208Setup.exeC:\Users\admin\AppData\Local\Temp\TempFolder.aaa\iml32.dllexecutable
MD5:9A0211146CE87037A18206C702BB01CB
SHA256:C21D2130A29AEF1F3E606914DD187BD8B39481C01C964E705299E7CA6F5F13BA
3208Setup.exeC:\Users\admin\AppData\Local\Temp\TempFolder.aaa\dirapi.dllexecutable
MD5:718E778A97FC8CF6694821F724A0FCA0
SHA256:B355EC36769AB2375C060CFE9797C1398BFBB340B5032C7DAB0E10139B35D777
3208Setup.exeC:\Users\admin\AppData\Local\Temp\TempFolder.aaa\proj.dllexecutable
MD5:1A9B1D8B21AE6F6A5428B4D23DBFB03E
SHA256:66527D87422569A5975A95920589452D4A9E8CEAA85F004D3DE8BC1FD303DC9A
3208Setup.exeC:\Users\admin\AppData\Local\Temp\TempFolder.aaa\xtras\SWADCmpr.x32executable
MD5:A25BB47F798F0BF6C71E2A8DBD6B3EA4
SHA256:DD00493DDCA594DB4167EFAFBA25CF124DFBB0A64C428BBEE528E6E3A5933DCD
3208Setup.exeC:\Users\admin\AppData\Local\Temp\TempFolder.aaa\xtras\NetLingo.x32executable
MD5:0F1A473ED662C3615DB39CFD19B2A15D
SHA256:829D70B5685977246DCE2EC0CC8EA23F9280E397A63F78FFB97CE00573721722
3208Setup.exeC:\Users\admin\AppData\Local\Temp\TempFolder.aaa\xtras\NetFile.x32executable
MD5:54C13B08DE727B951B6F939F274AFC3B
SHA256:B15E895EF5D426D1A56FC6481252732E47CEAEA8DA5601F3A36FE151A52FF642
3208Setup.exeC:\Users\admin\AppData\Local\Temp\TempFolder.aaa\xtras\MacroMix.x32executable
MD5:E06B6B6294F0D67202C8682C6EA3DE3C
SHA256:A0A353B65DC799315E22952A0089C5DEEBCA780B9BFC05210A4D62760BB52B21
3208Setup.exeC:\Users\admin\AppData\Local\Temp\TempFolder.aaa\xtras\DirectSound.x32executable
MD5:5D1F1D69AD0D81988B666FC2D4561D86
SHA256:DDEAE51512CBD39D3C4C4862F5D5CAE228D88461A8A345A5859024F136522840
2956WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2956.5828\Simplicheck\Simplicheck.exeexecutable
MD5:3232B760884B8DB88F055DB890C9C727
SHA256:B15A66FDCD6E7E32C47C045A9E60BA24AFCCCEAE2591739DC985D97313206192
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info