| File name: | driveridentifier_setup.exe |
| Full analysis: | https://app.any.run/tasks/fa65b612-3ad4-4ca6-a828-a6f4e0cb3d6d |
| Verdict: | Malicious activity |
| Analysis date: | June 15, 2024, 18:56:48 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | BBB1AB345527B79D388AAF8C413FFE01 |
| SHA1: | 7D3C7A62404FA0E2AAD1343D4A2F9C7B06051846 |
| SHA256: | 07BB70C93CF1886213C4D89A00C0B88A2FBA8DD86E248765831EC7866CE6F67C |
| SSDEEP: | 98304:a+cD4dnZLlr7OyUXrLQGKe89UqcOQmAWrjTiZ2SHH/KID5kQwV+V8DFP2sWgX674:he2xCHK6K |
| .exe | | | Inno Setup installer (65.1) |
|---|---|---|
| .exe | | | Win32 EXE PECompact compressed (generic) (24.6) |
| .dll | | | Win32 Dynamic Link Library (generic) (3.9) |
| .exe | | | Win32 Executable (generic) (2.6) |
| .exe | | | Win16/32 Executable Delphi generic (1.2) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2023:02:15 14:54:16+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi |
| PEType: | PE32 |
| LinkerVersion: | 2.25 |
| CodeSize: | 741888 |
| InitializedDataSize: | 35840 |
| UninitializedDataSize: | - |
| EntryPoint: | 0xb5eec |
| OSVersion: | 6.1 |
| ImageVersion: | 6 |
| SubsystemVersion: | 6.1 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 6.1.0.0 |
| ProductVersionNumber: | 6.1.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| Comments: | This installation was built with Inno Setup. |
| CompanyName: | DriverIdentifier |
| FileDescription: | DriverIdentifier Setup |
| FileVersion: | 6.1 |
| LegalCopyright: | |
| OriginalFileName: | |
| ProductName: | DriverIdentifier |
| ProductVersion: | 6.1 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 240 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=31 --mojo-platform-channel-handle=7056 --field-trial-handle=2288,i,11628020431075708695,1113200570723625691,262144 --variations-seed-version /prefetch:1 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| 308 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=5680 --field-trial-handle=2288,i,11628020431075708695,1113200570723625691,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| 528 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --single-argument C:\Users\admin\AppData\Local\Temp\driveridentifier\driver.html | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | DriverIdentifier.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| 1008 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=5616 --field-trial-handle=2288,i,11628020431075708695,1113200570723625691,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| 1508 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=6320 --field-trial-handle=2288,i,11628020431075708695,1113200570723625691,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| 1568 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=2652 --field-trial-handle=2252,i,10292565488568588934,3419972839720770123,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Version: 122.0.2365.59 Modules
| |||||||||||||||
| 1712 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --flag-switches-begin --flag-switches-end --do-not-de-elevate --single-argument https://www.driveridentifier.com/?cmd=start&v=6.2&cmd_line=declined | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| 1720 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=6264 --field-trial-handle=2288,i,11628020431075708695,1113200570723625691,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| 1720 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=35 --mojo-platform-channel-handle=5924 --field-trial-handle=2288,i,11628020431075708695,1113200570723625691,262144 --variations-seed-version /prefetch:1 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| 2088 | wmic OS get OSArchitecture | C:\Windows\SysWOW64\wbem\WMIC.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: WMI Commandline Utility Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| (PID) Process: | (6716) driveridentifier_setup.tmp | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | Owner |
Value: 3C1A0000CBC118CE55BFDA01 | |||
| (PID) Process: | (6716) driveridentifier_setup.tmp | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | SessionHash |
Value: 2014F6B93000F5FFCA042A4E4B24CFC66B09DF1AC0E7943EC14DEF34AA8D7B36 | |||
| (PID) Process: | (6716) driveridentifier_setup.tmp | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | Sequence |
Value: 1 | |||
| (PID) Process: | (6716) driveridentifier_setup.tmp | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | RegFiles0000 |
Value: C:\Program Files (x86)\Driver Identifier\DriverIdentifier.exe | |||
| (PID) Process: | (6716) driveridentifier_setup.tmp | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | RegFilesHash |
Value: F49210BC8EECF357743EACAB436F3E76FC2C61129CC19A3FA9D4D14697627C9F | |||
| (PID) Process: | (6716) driveridentifier_setup.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\driveruploader |
| Operation: | write | Name: | URL Protocol |
Value: | |||
| (PID) Process: | (6716) driveridentifier_setup.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{40A3E5DB-5EF8-4F04-BF3E-7AB87C4AE85A}_is1 |
| Operation: | write | Name: | Inno Setup: Setup Version |
Value: 6.2.2 | |||
| (PID) Process: | (6716) driveridentifier_setup.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{40A3E5DB-5EF8-4F04-BF3E-7AB87C4AE85A}_is1 |
| Operation: | write | Name: | Inno Setup: App Path |
Value: C:\Program Files (x86)\Driver Identifier | |||
| (PID) Process: | (6716) driveridentifier_setup.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{40A3E5DB-5EF8-4F04-BF3E-7AB87C4AE85A}_is1 |
| Operation: | write | Name: | InstallLocation |
Value: C:\Program Files (x86)\Driver Identifier\ | |||
| (PID) Process: | (6716) driveridentifier_setup.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{40A3E5DB-5EF8-4F04-BF3E-7AB87C4AE85A}_is1 |
| Operation: | write | Name: | Inno Setup: Icon Group |
Value: Driver Identifier | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6716 | driveridentifier_setup.tmp | C:\Users\admin\AppData\Local\Temp\is-9VRK3.tmp\psvince.dll | executable | |
MD5:A4E5C512B047A6D9DC38549161CAC4DE | SHA256:C7F1E7E866834D9024F97C2B145C09D106E447E8ABD65A10A1732116D178E44E | |||
| 6716 | driveridentifier_setup.tmp | C:\Program Files (x86)\Driver Identifier\DriverIdentifier.exe | executable | |
MD5:16ADC25067286FDA14E2BA02D3C77912 | SHA256:B28F9D39A99E39DD85F00EF9677B7CCFEA457E7A3D092200604B32DB726682D2 | |||
| 6716 | driveridentifier_setup.tmp | C:\Program Files (x86)\Driver Identifier\is-Q3QAI.tmp | executable | |
MD5:16ADC25067286FDA14E2BA02D3C77912 | SHA256:B28F9D39A99E39DD85F00EF9677B7CCFEA457E7A3D092200604B32DB726682D2 | |||
| 6716 | driveridentifier_setup.tmp | C:\Program Files (x86)\Driver Identifier\is-J39LF.tmp | executable | |
MD5:A4E5C512B047A6D9DC38549161CAC4DE | SHA256:C7F1E7E866834D9024F97C2B145C09D106E447E8ABD65A10A1732116D178E44E | |||
| 6716 | driveridentifier_setup.tmp | C:\Program Files (x86)\Driver Identifier\is-40TOG.tmp | executable | |
MD5:C8DCF04597C913AF685A770572EA2A8E | SHA256:AF2FBE36915E9E6FAF7CC69856798C8C246135E7962CF55AE9619B16D29374DF | |||
| 6672 | driveridentifier_setup.exe | C:\Users\admin\AppData\Local\Temp\is-023QN.tmp\driveridentifier_setup.tmp | executable | |
MD5:926935272B2860B2EC3CD3485D96F0AA | SHA256:9695C7A46E91654083E822EB30971E1A1AC51E8B2500B22DF89237469729687B | |||
| 6716 | driveridentifier_setup.tmp | C:\Program Files (x86)\Driver Identifier\is-5QAN8.tmp | executable | |
MD5:78490B09625B2ED0E8ADE069DA835F7C | SHA256:B535885340E807BCFA95CE539E55E07672E8D0DECBF7C9F65DECDAE96E596255 | |||
| 6716 | driveridentifier_setup.tmp | C:\Program Files (x86)\Driver Identifier\unins000.exe | executable | |
MD5:81C4970314760D1669F7F85E802A8833 | SHA256:1F3B6997FA8BD24569F361E9B44690DA6A00F2F42F659EB1C84D165C324155F5 | |||
| 6532 | driveridentifier_setup.exe | C:\Users\admin\AppData\Local\Temp\is-FF4MJ.tmp\driveridentifier_setup.tmp | executable | |
MD5:926935272B2860B2EC3CD3485D96F0AA | SHA256:9695C7A46E91654083E822EB30971E1A1AC51E8B2500B22DF89237469729687B | |||
| 6716 | driveridentifier_setup.tmp | C:\Users\admin\AppData\Local\Temp\is-9VRK3.tmp\_isetup\_setup64.tmp | executable | |
MD5:E4211D6D009757C078A9FAC7FF4F03D4 | SHA256:388A796580234EFC95F3B1C70AD4CB44BFDDC7BA0F9203BF4902B9929B136F95 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
5952 | svchost.exe | GET | — | 23.223.17.198:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | unknown |
5140 | MoUsoCoreWorker.exe | GET | 200 | 23.223.17.198:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | unknown |
5228 | RUXIMICS.exe | GET | 200 | 23.223.17.198:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | unknown |
5140 | MoUsoCoreWorker.exe | GET | 200 | 2.17.0.227:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | unknown |
5228 | RUXIMICS.exe | GET | 200 | 2.17.0.227:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | unknown |
— | — | GET | 401 | 13.107.6.158:443 | https://business.bing.com/api/v1/user/token/microsoftgraph?&clienttype=edge-omnibox | unknown | — | — | unknown |
— | — | OPTIONS | 200 | 23.223.17.205:443 | https://bzib.nelreports.net/api/report?cat=bingbusiness | unknown | — | — | unknown |
— | — | GET | 200 | 13.107.42.16:443 | https://config.edge.skype.com/config/v1/Edge/122.0.2365.59?clientId=4489578223053569932&agents=EdgeFirstRun%2CEdgeFirstRunConfig&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=27&mngd=0&installdate=1661339457&edu=0&bphint=2&soobedate=1504771245&fg=1 | unknown | binary | 1.15 Kb | unknown |
— | — | GET | 200 | 13.107.21.239:443 | https://edge.microsoft.com/serviceexperimentation/v3/?osname=win&channel=stable&osver=10.0.19045&devicefamily=desktop&installdate=1661339457&clientversion=122.0.2365.59&experimentationmode=2&scpguard=0&scpfull=0&scpver=0 | unknown | binary | 1.12 Kb | unknown |
— | — | GET | 401 | 13.107.6.158:443 | https://business.bing.com/work/api/v2/tenant/my/settingswithflights?&clienttype=edge-omnibox | unknown | binary | 583 b | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4364 | svchost.exe | 239.255.255.250:1900 | — | — | — | unknown |
5952 | svchost.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
5140 | MoUsoCoreWorker.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
5228 | RUXIMICS.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
5228 | RUXIMICS.exe | 23.223.17.198:80 | crl.microsoft.com | AKAMAI-AS | US | unknown |
5952 | svchost.exe | 23.223.17.198:80 | crl.microsoft.com | AKAMAI-AS | US | unknown |
5140 | MoUsoCoreWorker.exe | 23.223.17.198:80 | crl.microsoft.com | AKAMAI-AS | US | unknown |
5140 | MoUsoCoreWorker.exe | 2.17.0.227:80 | www.microsoft.com | AKAMAI-AS | DK | unknown |
5228 | RUXIMICS.exe | 2.17.0.227:80 | www.microsoft.com | AKAMAI-AS | DK | unknown |
Domain | IP | Reputation |
|---|---|---|
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
settings-win.data.microsoft.com |
| whitelisted |
www.driveridentifier.com |
| unknown |
edge.microsoft.com |
| whitelisted |
config.edge.skype.com |
| whitelisted |
edge-mobile-static.azureedge.net |
| unknown |
business.bing.com |
| whitelisted |
bzib.nelreports.net |
| whitelisted |
www.bing.com |
| whitelisted |