| File name: | CDM21228_Setup.exe |
| Full analysis: | https://app.any.run/tasks/37ffe155-72af-489e-a812-4e0471d51f16 |
| Verdict: | Malicious activity |
| Analysis date: | December 01, 2023, 15:19:27 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 7ACD865CF6180D0D099B74D5BAB70FEB |
| SHA1: | C44678C7459798C800332273C74049CEA204A604 |
| SHA256: | 15C30AA807D3763DE63B383533D197C218066EEFC979B3611CA200F09B9CB7EE |
| SSDEEP: | 49152:bFcT+BU13Gb6zv50SYIC06A0D7Uy25CHP8M7c4EfSHA8JO8Pz1bCP:bla2uLySrC03U7UkPRoz/keP |
| .exe | | | Win32 Executable MS Visual C++ (generic) (42.2) |
|---|---|---|
| .exe | | | Win64 Executable (generic) (37.3) |
| .dll | | | Win32 Dynamic Link Library (generic) (8.8) |
| .exe | | | Win32 Executable (generic) (6) |
| .exe | | | Generic Win/DOS Executable (2.7) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2016:02:15 11:04:57+01:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 12 |
| CodeSize: | 24064 |
| InitializedDataSize: | 66560 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x6700 |
| OSVersion: | 5.1 |
| ImageVersion: | - |
| SubsystemVersion: | 5.1 |
| Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 124 | "C:\Users\admin\Desktop\CDM21228_Setup.exe" | C:\Users\admin\Desktop\CDM21228_Setup.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 1 Modules
| |||||||||||||||
| 844 | "C:\Users\admin\Desktop\CDM21228_Setup.exe" | C:\Users\admin\Desktop\CDM21228_Setup.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 3221226540 Modules
| |||||||||||||||
| 1036 | DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{0c4f515b-267a-35ec-55e4-0c5b786ca525}\ftdibus.inf" "0" "657f6b0d3" "000004AC" "WinSta0\Default" "000005B4" "208" "c:\users\admin\appdata\local\temp\ftdi-driver" | C:\Windows\System32\drvinst.exe | — | svchost.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Driver Installation Module Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1116 | C:\Users\admin\AppData\Local\Temp\FTDI-Driver\dp-chooser.exe | C:\Users\admin\AppData\Local\Temp\FTDI-Driver\dp-chooser.exe | — | CDM21228_Setup.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 1344 | "C:\Program Files\Windows Media Player\wmpnscfg.exe" | C:\Program Files\Windows Media Player\wmpnscfg.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Network Sharing Service Configuration Application Exit code: 0 Version: 12.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3784 | C:\Users\admin\AppData\Local\Temp\FTDI-Driver\dpinst-x86.exe /sa | C:\Users\admin\AppData\Local\Temp\FTDI-Driver\dpinst-x86.exe | — | dp-chooser.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Driver Package Installer Exit code: 512 Version: 2.1 Modules
| |||||||||||||||
| 3892 | DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{46d3bad7-d030-37a7-f37d-fe689c654537}\ftdiport.inf" "0" "6960183e3" "000005B4" "WinSta0\Default" "00000074" "208" "c:\users\admin\appdata\local\temp\ftdi-driver" | C:\Windows\System32\drvinst.exe | — | svchost.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Driver Installation Module Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (3784) dpinst-x86.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\17F\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (1036) drvinst.exe | Key: | HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\17F\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3892) drvinst.exe | Key: | HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\17F\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 124 | CDM21228_Setup.exe | C:\Users\admin\AppData\Local\Temp\FTDI-Driver\ftdibus.cat | binary | |
MD5:3CA2599748CC29523831EACE03806D8C | SHA256:51E4DE8D95DE60A7B20B516192F9A3EF26D9FF5AFDE04032F92D6F6E5288E657 | |||
| 124 | CDM21228_Setup.exe | C:\Users\admin\AppData\Local\Temp\FTDI-Driver\amd64\ftdibus.sys | executable | |
MD5:D5F53AFCD0D6E0A2925BFFF9E2605552 | SHA256:8C494A63B270D8605AB9A4AD7D5AE074F7D466D64ADBA36F5E559210ECB35617 | |||
| 124 | CDM21228_Setup.exe | C:\Users\admin\AppData\Local\Temp\FTDI-Driver\amd64\ftcserco.dll | executable | |
MD5:39E2638AF413C84609BC851D942CCA8C | SHA256:50DA92AF5BE9BE519A4648B2C1109A30E3D2341E85C928A58C1AF8B4B830D4F3 | |||
| 124 | CDM21228_Setup.exe | C:\Users\admin\AppData\Local\Temp\FTDI-Driver\amd64\ftd2xx64.dll | executable | |
MD5:7832F9DF38BF967E60EE067A780D0201 | SHA256:9C282C4580AAC9388ADADF8C2D9794CCA2F953AF36331AEDF814E936CFED97AD | |||
| 124 | CDM21228_Setup.exe | C:\Users\admin\AppData\Local\Temp\FTDI-Driver\amd64\ftd2xx.lib | binary | |
MD5:D8B31806632C9E2DC4BB79E87C98C0B2 | SHA256:260A37AA3966AEEE901DC8819C98E47BF47E61D5F724472559D33B55F4F9C271 | |||
| 124 | CDM21228_Setup.exe | C:\Users\admin\AppData\Local\Temp\FTDI-Driver\dpinst-amd64.exe | executable | |
MD5:BE3C79033FA8302002D9D3A6752F2263 | SHA256:181BF85D3B5900FF8ABED34BC415AFC37FC322D9D7702E14D144F96A908F5CAB | |||
| 124 | CDM21228_Setup.exe | C:\Users\admin\AppData\Local\Temp\FTDI-Driver\amd64\ftser2k.sys | executable | |
MD5:FBD982A8B9B94FC17D37EDEBA40B71E9 | SHA256:2D07F14812AF8D0796A2056808C092A71275DF3138378AEB2C22A396BEC67051 | |||
| 124 | CDM21228_Setup.exe | C:\Users\admin\AppData\Local\Temp\FTDI-Driver\amd64\ftlang.dll | executable | |
MD5:8BB75F1ED68C88D6B32C67E86BBB66E4 | SHA256:84B22F61827D448946977B259CE06B0A8E83BC1DC7B9D8A208D3E32525F08507 | |||
| 124 | CDM21228_Setup.exe | C:\Users\admin\AppData\Local\Temp\FTDI-Driver\ftd2xx.h | text | |
MD5:D00E424FB587281C98E0CD1D420A007C | SHA256:CF2AD290C68137373B26629BF9FEED6F4847F4E9E5CDE4B980A212CEBEB4FF6A | |||
| 124 | CDM21228_Setup.exe | C:\Users\admin\AppData\Local\Temp\FTDI-Driver\dpinst.xml | xml | |
MD5:BBB46E3360F3FCABC5D03CA33DC10458 | SHA256:65E9BC1F59DE53462ED2E6B002C0BE26CD3F37B1E360938A0A32AA452ED58030 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
2588 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |