| File name: | Speedlink Strike Gamepad Driver.zip |
| Full analysis: | https://app.any.run/tasks/481d893f-62f4-436f-b175-5a7101a86cdf |
| Verdict: | Malicious activity |
| Analysis date: | August 23, 2020, 17:19:59 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v1.0 to extract |
| MD5: | 13BC5F01962B7C3B3A0C36FFB0CE5662 |
| SHA1: | AD6BBD4A5758EA1CF1F9B3ED2B23F574CB8A27E7 |
| SHA256: | FB68305B0F45E7D0C02AEF6FF223E22EDB697380EF70206A931C0B5A80305B59 |
| SSDEEP: | 98304:s4c0WVv6bKgekjtyKhH0fpJiEnW59KdTDzHR+PIzmwdTuhn0Sw45:s4zWyHoKhH0BhxdH4Iluhn7wc |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 10 |
|---|---|
| ZipBitFlag: | - |
| ZipCompression: | None |
| ZipModifyDate: | 2013:09:16 11:33:25 |
| ZipCRC: | 0x00000000 |
| ZipCompressedSize: | - |
| ZipUncompressedSize: | - |
| ZipFileName: | Simplicheck/ |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2808 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa2956.5828\Driver/setup.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa2956.5828\Driver\setup.exe | Setup.exe | ||||||||||||
User: admin Company: Macrovision Corporation Integrity Level: HIGH Description: Setup.exe Exit code: 0 Version: 12.0.49974 Modules
| |||||||||||||||
| 2908 | "C:\Windows\system32\msiexec.exe" /i C:\Users\admin\AppData\Local\Temp\mgxa07zwkcm\simplicheck.msi | C:\Windows\system32\msiexec.exe | — | simplicheck.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2956 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Speedlink Strike Gamepad Driver.zip" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.60.0 Modules
| |||||||||||||||
| 3100 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa2956.5828\Simplicheck/simplicheck.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa2956.5828\Simplicheck\simplicheck.exe | Setup.exe | ||||||||||||
User: admin Company: simplitec GmbH Integrity Level: HIGH Description: simplitec simplicheck (en-US) Exit code: 0 Version: 1.3.10.0 Modules
| |||||||||||||||
| 3208 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa2956.5828\Setup.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa2956.5828\Setup.exe | WinRAR.exe | ||||||||||||
User: admin Company: Macromedia, Inc. Integrity Level: HIGH Description: Macromedia Projector Exit code: 0 Version: 9.0r383 Modules
| |||||||||||||||
| 3368 | C:\Windows\system32\DllHost.exe /Processid:{F32D97DF-E3E5-4CB9-9E3E-0EB5B4E49801} | C:\Windows\system32\DllHost.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: COM Surrogate Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3416 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa2956.5828\Setup.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa2956.5828\Setup.exe | — | WinRAR.exe | |||||||||||
User: admin Company: Macromedia, Inc. Integrity Level: MEDIUM Description: Macromedia Projector Exit code: 3221226540 Version: 9.0r383 Modules
| |||||||||||||||
| 3932 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa2956.5828\Driver/setup.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa2956.5828\Driver\setup.exe | Setup.exe | ||||||||||||
User: admin Company: Macrovision Corporation Integrity Level: HIGH Description: Setup.exe Exit code: 0 Version: 12.0.49974 Modules
| |||||||||||||||
| (PID) Process: | (2956) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (2956) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (2956) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\137\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2956) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\137\52C64B7E |
| Operation: | write | Name: | @C:\Windows\system32\NetworkExplorer.dll,-1 |
Value: Network | |||
| (PID) Process: | (2956) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\Speedlink Strike Gamepad Driver.zip | |||
| (PID) Process: | (2956) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (2956) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (2956) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (2956) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (2956) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2956 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2956.5828\Driver\Setup.exe | executable | |
MD5:94036B81782CE7FCE1F2482DC07DF0D9 | SHA256:11550B733F6B11299363396FF25933F7EC9553BFE84FCADF9157E54918F4AE22 | |||
| 3208 | Setup.exe | C:\Users\admin\AppData\Local\Temp\TempFolder.aaa\iml32.dll | executable | |
MD5:9A0211146CE87037A18206C702BB01CB | SHA256:C21D2130A29AEF1F3E606914DD187BD8B39481C01C964E705299E7CA6F5F13BA | |||
| 3208 | Setup.exe | C:\Users\admin\AppData\Local\Temp\TempFolder.aaa\dirapi.dll | executable | |
MD5:718E778A97FC8CF6694821F724A0FCA0 | SHA256:B355EC36769AB2375C060CFE9797C1398BFBB340B5032C7DAB0E10139B35D777 | |||
| 3208 | Setup.exe | C:\Users\admin\AppData\Local\Temp\TempFolder.aaa\proj.dll | executable | |
MD5:1A9B1D8B21AE6F6A5428B4D23DBFB03E | SHA256:66527D87422569A5975A95920589452D4A9E8CEAA85F004D3DE8BC1FD303DC9A | |||
| 3208 | Setup.exe | C:\Users\admin\AppData\Local\Temp\TempFolder.aaa\xtras\SWADCmpr.x32 | executable | |
MD5:A25BB47F798F0BF6C71E2A8DBD6B3EA4 | SHA256:DD00493DDCA594DB4167EFAFBA25CF124DFBB0A64C428BBEE528E6E3A5933DCD | |||
| 3208 | Setup.exe | C:\Users\admin\AppData\Local\Temp\TempFolder.aaa\xtras\NetLingo.x32 | executable | |
MD5:0F1A473ED662C3615DB39CFD19B2A15D | SHA256:829D70B5685977246DCE2EC0CC8EA23F9280E397A63F78FFB97CE00573721722 | |||
| 3208 | Setup.exe | C:\Users\admin\AppData\Local\Temp\TempFolder.aaa\xtras\NetFile.x32 | executable | |
MD5:54C13B08DE727B951B6F939F274AFC3B | SHA256:B15E895EF5D426D1A56FC6481252732E47CEAEA8DA5601F3A36FE151A52FF642 | |||
| 3208 | Setup.exe | C:\Users\admin\AppData\Local\Temp\TempFolder.aaa\xtras\MacroMix.x32 | executable | |
MD5:E06B6B6294F0D67202C8682C6EA3DE3C | SHA256:A0A353B65DC799315E22952A0089C5DEEBCA780B9BFC05210A4D62760BB52B21 | |||
| 3208 | Setup.exe | C:\Users\admin\AppData\Local\Temp\TempFolder.aaa\xtras\DirectSound.x32 | executable | |
MD5:5D1F1D69AD0D81988B666FC2D4561D86 | SHA256:DDEAE51512CBD39D3C4C4862F5D5CAE228D88461A8A345A5859024F136522840 | |||
| 2956 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2956.5828\Simplicheck\Simplicheck.exe | executable | |
MD5:3232B760884B8DB88F055DB890C9C727 | SHA256:B15A66FDCD6E7E32C47C045A9E60BA24AFCCCEAE2591739DC985D97313206192 | |||