File name:

Speedlink Strike Gamepad Driver.zip

Full analysis: https://app.any.run/tasks/481d893f-62f4-436f-b175-5a7101a86cdf
Verdict: Malicious activity
Analysis date: August 23, 2020, 17:19:59
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v1.0 to extract
MD5:

13BC5F01962B7C3B3A0C36FFB0CE5662

SHA1:

AD6BBD4A5758EA1CF1F9B3ED2B23F574CB8A27E7

SHA256:

FB68305B0F45E7D0C02AEF6FF223E22EDB697380EF70206A931C0B5A80305B59

SSDEEP:

98304:s4c0WVv6bKgekjtyKhH0fpJiEnW59KdTDzHR+PIzmwdTuhn0Sw45:s4zWyHoKhH0BhxdH4Iluhn7wc

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • Setup.exe (PID: 3208)
      • setup.exe (PID: 2808)
    • Application was dropped or rewritten from another process

      • Setup.exe (PID: 3416)
      • Setup.exe (PID: 3208)
      • setup.exe (PID: 2808)
      • setup.exe (PID: 3932)
      • simplicheck.exe (PID: 3100)
    • Actions looks like stealing of personal data

      • WinRAR.exe (PID: 2956)
      • Setup.exe (PID: 3208)
    • Changes settings of System certificates

      • msiexec.exe (PID: 2908)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • Setup.exe (PID: 3208)
      • WinRAR.exe (PID: 2956)
      • setup.exe (PID: 2808)
      • setup.exe (PID: 3932)
      • simplicheck.exe (PID: 3100)
    • Creates files in the user directory

      • setup.exe (PID: 2808)
      • setup.exe (PID: 3932)
    • Executed via COM

      • DllHost.exe (PID: 3368)
    • Searches for installed software

      • setup.exe (PID: 2808)
    • Creates files in the program directory

      • setup.exe (PID: 2808)
    • Creates a software uninstall entry

      • setup.exe (PID: 2808)
    • Creates COM task schedule object

      • setup.exe (PID: 2808)
    • Adds / modifies Windows certificates

      • msiexec.exe (PID: 2908)
    • Starts Microsoft Installer

      • simplicheck.exe (PID: 3100)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 10
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2013:09:16 11:33:25
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: Simplicheck/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
48
Monitored processes
8
Malicious processes
3
Suspicious processes
3

Behavior graph

Click at the process to see the details
drop and start drop and start start winrar.exe setup.exe no specs setup.exe setup.exe setup.exe SPPSurrogate no specs simplicheck.exe msiexec.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2808"C:\Users\admin\AppData\Local\Temp\Rar$EXa2956.5828\Driver/setup.exe"C:\Users\admin\AppData\Local\Temp\Rar$EXa2956.5828\Driver\setup.exe
Setup.exe
User:
admin
Company:
Macrovision Corporation
Integrity Level:
HIGH
Description:
Setup.exe
Exit code:
0
Version:
12.0.49974
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2956.5828\driver\setup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2908"C:\Windows\system32\msiexec.exe" /i C:\Users\admin\AppData\Local\Temp\mgxa07zwkcm\simplicheck.msiC:\Windows\system32\msiexec.exesimplicheck.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2956"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Speedlink Strike Gamepad Driver.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3100"C:\Users\admin\AppData\Local\Temp\Rar$EXa2956.5828\Simplicheck/simplicheck.exe"C:\Users\admin\AppData\Local\Temp\Rar$EXa2956.5828\Simplicheck\simplicheck.exe
Setup.exe
User:
admin
Company:
simplitec GmbH
Integrity Level:
HIGH
Description:
simplitec simplicheck (en-US)
Exit code:
0
Version:
1.3.10.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2956.5828\simplicheck\simplicheck.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3208"C:\Users\admin\AppData\Local\Temp\Rar$EXa2956.5828\Setup.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa2956.5828\Setup.exe
WinRAR.exe
User:
admin
Company:
Macromedia, Inc.
Integrity Level:
HIGH
Description:
Macromedia Projector
Exit code:
0
Version:
9.0r383
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2956.5828\setup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
3368C:\Windows\system32\DllHost.exe /Processid:{F32D97DF-E3E5-4CB9-9E3E-0EB5B4E49801}C:\Windows\system32\DllHost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
COM Surrogate
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\dllhost.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3416"C:\Users\admin\AppData\Local\Temp\Rar$EXa2956.5828\Setup.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa2956.5828\Setup.exeWinRAR.exe
User:
admin
Company:
Macromedia, Inc.
Integrity Level:
MEDIUM
Description:
Macromedia Projector
Exit code:
3221226540
Version:
9.0r383
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2956.5828\setup.exe
c:\systemroot\system32\ntdll.dll
3932"C:\Users\admin\AppData\Local\Temp\Rar$EXa2956.5828\Driver/setup.exe"C:\Users\admin\AppData\Local\Temp\Rar$EXa2956.5828\Driver\setup.exe
Setup.exe
User:
admin
Company:
Macrovision Corporation
Integrity Level:
HIGH
Description:
Setup.exe
Exit code:
0
Version:
12.0.49974
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2956.5828\driver\setup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
Total events
907
Read events
734
Write events
173
Delete events
0

Modification events

(PID) Process:(2956) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2956) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2956) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\137\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2956) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\137\52C64B7E
Operation:writeName:@C:\Windows\system32\NetworkExplorer.dll,-1
Value:
Network
(PID) Process:(2956) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Speedlink Strike Gamepad Driver.zip
(PID) Process:(2956) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2956) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2956) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2956) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2956) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
Executable files
35
Suspicious files
17
Text files
42
Unknown types
2

Dropped files

PID
Process
Filename
Type
3208Setup.exeC:\Users\admin\AppData\Local\Temp\TempFolder.aaa\xtras\NetFile.x32executable
MD5:54C13B08DE727B951B6F939F274AFC3B
SHA256:B15E895EF5D426D1A56FC6481252732E47CEAEA8DA5601F3A36FE151A52FF642
2956WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2956.5828\Setup.exeexecutable
MD5:730BF3D067B9F50851AB90F258F49270
SHA256:87AAE36066CC1EECC355D1A4355B2DFEC651AD4E25ED71C95631FF06FC5A1701
2956WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2956.5828\Simplicheck\Simplicheck.exeexecutable
MD5:3232B760884B8DB88F055DB890C9C727
SHA256:B15A66FDCD6E7E32C47C045A9E60BA24AFCCCEAE2591739DC985D97313206192
2956WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2956.5828\Driver\Setup.exeexecutable
MD5:94036B81782CE7FCE1F2482DC07DF0D9
SHA256:11550B733F6B11299363396FF25933F7EC9553BFE84FCADF9157E54918F4AE22
3208Setup.exeC:\Users\admin\AppData\Local\Temp\TempFolder.aaa\xtras\Sound Control.x32executable
MD5:1A03BE0567D724722081B7E604415E00
SHA256:169B008438B8CBE9C083E51F9F1BAE47714F8673E5C4107FC8EAF901692656F6
3208Setup.exeC:\Users\admin\AppData\Local\Temp\TempFolder.aaa\msvcrt.dllexecutable
MD5:63DA4613383EC70E047B4CD5C48F0B05
SHA256:D4287AB5E4988DFE99BD54243D50DBE8744094F11FE5F9809A1A6FB9728C2124
3208Setup.exeC:\Users\admin\AppData\Local\Temp\TempFolder.aaa\xtras\SWADCmpr.x32executable
MD5:A25BB47F798F0BF6C71E2A8DBD6B3EA4
SHA256:DD00493DDCA594DB4167EFAFBA25CF124DFBB0A64C428BBEE528E6E3A5933DCD
3208Setup.exeC:\Users\admin\AppData\Local\Temp\TempFolder.aaa\xtras\INetURL.x32executable
MD5:BBF9E409B202D855DC0478787E61F020
SHA256:62E5870DF9E8602D230EA9F645139816DC49BA0DD71FA6334A4A85C1A1758667
3208Setup.exeC:\Users\admin\AppData\Local\Temp\TempFolder.aaa\xtras\MacroMix.x32executable
MD5:E06B6B6294F0D67202C8682C6EA3DE3C
SHA256:A0A353B65DC799315E22952A0089C5DEEBCA780B9BFC05210A4D62760BB52B21
3208Setup.exeC:\Users\admin\AppData\Local\Temp\TempFolder.aaa\xtras\NetLingo.x32executable
MD5:0F1A473ED662C3615DB39CFD19B2A15D
SHA256:829D70B5685977246DCE2EC0CC8EA23F9280E397A63F78FFB97CE00573721722
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info