| File name: | Ls_Driver_Installer.exe |
| Full analysis: | https://app.any.run/tasks/f08f9a53-db88-4f20-8aa9-0f8ea1a92df9 |
| Verdict: | Malicious activity |
| Analysis date: | May 28, 2025, 08:41:38 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, 5 sections |
| MD5: | 9CA4993E438E33E7D3543165BE161680 |
| SHA1: | 70148344EDC4191BA2279C144B8B583B88FDC2C9 |
| SHA256: | 18D9693278B2F0E701B02F8A95E97BAA4A48A6F45D631F7808FD6859C9BF0FB2 |
| SSDEEP: | 12288:eVybYTYxaVVVVVVVVVVFmY6pIhVVPLMCH0oxJ9VHlEDCGUXo2DbKNov28/GT0rQm:2CTYLX0fMOmGT0rQ7Zi98KKG |
| .exe | | | Win32 Executable MS Visual C++ (generic) (35.8) |
|---|---|---|
| .exe | | | Win64 Executable (generic) (31.7) |
| .scr | | | Windows screen saver (15) |
| .dll | | | Win32 Dynamic Link Library (generic) (7.5) |
| .exe | | | Win32 Executable (generic) (5.1) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2015:08:07 09:01:27+00:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 9 |
| CodeSize: | 49664 |
| InitializedDataSize: | 2118144 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x2c77 |
| OSVersion: | 5 |
| ImageVersion: | - |
| SubsystemVersion: | 5 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.1.0.0 |
| ProductVersionNumber: | 1.1.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Windows NT 32-bit |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Italian |
| CharacterSet: | Unicode |
| CompanyName: | CTS Electronics - An ARCA company |
| FileDescription: | Cts_Driver_installer - give /u for uninstall /s for silent |
| FileVersion: | 1, 1, 0, 0 |
| InternalName: | Cts_Driver_installer |
| LegalCopyright: | Copyright © 2009 - 2015 CTS Electronics - An ARCA company, All Rights Reserved |
| OriginalFileName: | Cts_Driver_installer.exe |
| ProductName: | CTS Electronis Cts_Driver_installer |
| ProductVersion: | 1, 1, 0, 0 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 132 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --extension-process --renderer-sub-type=extension --no-appcompat-clear --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=7 --mojo-platform-channel-handle=4116 --field-trial-handle=2472,i,8451002947793810590,16318976045692817655,262144 --variations-seed-version /prefetch:2 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| 236 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=4268 --field-trial-handle=2472,i,8451002947793810590,16318976045692817655,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| 300 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=4708 --field-trial-handle=2472,i,8451002947793810590,16318976045692817655,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Version: 122.0.2365.59 Modules
| |||||||||||||||
| 516 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --instant-process --no-appcompat-clear --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=3780 --field-trial-handle=2472,i,8451002947793810590,16318976045692817655,262144 --variations-seed-version /prefetch:1 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| 668 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --no-appcompat-clear --gpu-preferences=WAAAAAAAAADgAAAMAAAAAAAAAAAAAAAAAABgAAAAAAA4AAAAAAAAAAAAAAAEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGAAAAAAAAAAYAAAAAAAAAAgAAAAAAAAACAAAAAAAAAAIAAAAAAAAAA== --mojo-platform-channel-handle=2380 --field-trial-handle=2472,i,8451002947793810590,16318976045692817655,262144 --variations-seed-version /prefetch:2 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Version: 122.0.2365.59 Modules
| |||||||||||||||
| 900 | "C:\Users\admin\Desktop\Ls_Driver_Installer.exe" | C:\Users\admin\Desktop\Ls_Driver_Installer.exe | — | explorer.exe | |||||||||||
User: admin Company: CTS Electronics - An ARCA company Integrity Level: MEDIUM Description: Cts_Driver_installer - give /u for uninstall /s for silent Exit code: 3221226540 Version: 1, 1, 0, 0 Modules
| |||||||||||||||
| 1328 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | pwsh.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1512 | C:\WINDOWS\system32\SppExtComObj.exe -Embedding | C:\Windows\System32\SppExtComObj.Exe | — | svchost.exe | |||||||||||
User: NETWORK SERVICE Company: Microsoft Corporation Integrity Level: SYSTEM Description: KMS Connection Broker Exit code: 0 Version: 10.0.19041.3996 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1568 | "C:\Users\admin\Desktop\Ls_Driver_Installer.exe" | C:\Users\admin\Desktop\Ls_Driver_Installer.exe | explorer.exe | ||||||||||||
User: admin Company: CTS Electronics - An ARCA company Integrity Level: HIGH Description: Cts_Driver_installer - give /u for uninstall /s for silent Exit code: 1 Version: 1, 1, 0, 0 Modules
| |||||||||||||||
| 1616 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=entity_extraction_service.mojom.Extractor --lang=en-US --service-sandbox-type=entity_extraction --onnx-enabled-for-ee --no-appcompat-clear --mojo-platform-channel-handle=5720 --field-trial-handle=2472,i,8451002947793810590,16318976045692817655,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| (PID) Process: | (2088) DPInst_64.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\Setup\SetupapiLogStatus |
| Operation: | write | Name: | setupapi.dev.log |
Value: 4096 | |||
| (PID) Process: | (3156) POWERPNT.EXE | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\Common\ClientTelemetry\Sampling |
| Operation: | write | Name: | 3 |
Value: 011C08000000001000B24E9A3E01000000000000000300000000000000 | |||
| (PID) Process: | (3156) POWERPNT.EXE | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\Common\CrashPersistence\POWERPNT\3156 |
| Operation: | write | Name: | 0 |
Value: 0B0E100E680B94E11B394CA575A7BA3A20D56F2300469BB9999CC7F5F3ED016A04102400449A7D64B29D01008500A907556E6B6E6F776EC906022222CA0DC2190000C91003783634C511D418D2120C70006F0077006500720070006E0074002E00650078006500C51620C517808004C91808323231322D44656300 | |||
| (PID) Process: | (3156) POWERPNT.EXE | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages |
| Operation: | write | Name: | en-US |
Value: 2 | |||
| (PID) Process: | (3156) POWERPNT.EXE | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages |
| Operation: | write | Name: | de-de |
Value: 2 | |||
| (PID) Process: | (3156) POWERPNT.EXE | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages |
| Operation: | write | Name: | fr-fr |
Value: 2 | |||
| (PID) Process: | (3156) POWERPNT.EXE | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages |
| Operation: | write | Name: | es-es |
Value: 2 | |||
| (PID) Process: | (3156) POWERPNT.EXE | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages |
| Operation: | write | Name: | it-it |
Value: 2 | |||
| (PID) Process: | (3156) POWERPNT.EXE | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages |
| Operation: | write | Name: | ja-jp |
Value: 2 | |||
| (PID) Process: | (3156) POWERPNT.EXE | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages |
| Operation: | write | Name: | ko-kr |
Value: 2 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 5404 | Ls_Driver_Installer.exe | C:\Users\admin\Desktop\DPInst_64.exe | executable | |
MD5:BE3C79033FA8302002D9D3A6752F2263 | SHA256:181BF85D3B5900FF8ABED34BC415AFC37FC322D9D7702E14D144F96A908F5CAB | |||
| 6792 | drvinst.exe | C:\Windows\System32\DriverStore\Temp\{e0285d15-19d8-4f43-8fdd-8f39bbbbbb68}\SETADB6.tmp | cat | |
MD5:E57C4991E976EA149E4B9962A12E4721 | SHA256:96259E5423BE3004764206B9ACF92D06FBE77DB1956D9E0CB8DEFDC58DA026DF | |||
| 2088 | DPInst_64.exe | C:\Users\admin\AppData\Local\Temp\{4461803d-c59f-e14c-a251-c2a614d64993}\CTSSCANNERUD_64.sys | executable | |
MD5:508F1B94383E60362C9829E9C6B61702 | SHA256:B020AEE40DB12D1C77CA0CC863937ADB88802898CA37ECC45F0B63107ADD800F | |||
| 2088 | DPInst_64.exe | C:\Users\admin\AppData\Local\Temp\{4461803d-c59f-e14c-a251-c2a614d64993}\SETAD2A.tmp | cat | |
MD5:E57C4991E976EA149E4B9962A12E4721 | SHA256:96259E5423BE3004764206B9ACF92D06FBE77DB1956D9E0CB8DEFDC58DA026DF | |||
| 2088 | DPInst_64.exe | C:\Users\admin\AppData\Local\Temp\{4461803d-c59f-e14c-a251-c2a614d64993}\ctsscannerud_64.inf | binary | |
MD5:C86214D4D060077A19D037B49799411A | SHA256:5ED9E4081C9832DD01896D6E613CC4C0A2E3ABC945DC56BCC9B67AA478F5BC26 | |||
| 6792 | drvinst.exe | C:\Windows\System32\DriverStore\Temp\{e0285d15-19d8-4f43-8fdd-8f39bbbbbb68}\ctsscannerud_64.inf | binary | |
MD5:C86214D4D060077A19D037B49799411A | SHA256:5ED9E4081C9832DD01896D6E613CC4C0A2E3ABC945DC56BCC9B67AA478F5BC26 | |||
| 2088 | DPInst_64.exe | C:\Users\admin\AppData\Local\Temp\{4461803d-c59f-e14c-a251-c2a614d64993}\CtsScannerUd_64.cat | binary | |
MD5:E57C4991E976EA149E4B9962A12E4721 | SHA256:96259E5423BE3004764206B9ACF92D06FBE77DB1956D9E0CB8DEFDC58DA026DF | |||
| 2088 | DPInst_64.exe | C:\Users\admin\AppData\Local\Temp\{4461803d-c59f-e14c-a251-c2a614d64993}\SETAD2B.tmp | binary | |
MD5:C86214D4D060077A19D037B49799411A | SHA256:5ED9E4081C9832DD01896D6E613CC4C0A2E3ABC945DC56BCC9B67AA478F5BC26 | |||
| 5404 | Ls_Driver_Installer.exe | C:\Users\admin\Desktop\CtsScannerUd_64.cat | binary | |
MD5:E57C4991E976EA149E4B9962A12E4721 | SHA256:96259E5423BE3004764206B9ACF92D06FBE77DB1956D9E0CB8DEFDC58DA026DF | |||
| 2088 | DPInst_64.exe | C:\Users\admin\AppData\Local\Temp\{4461803d-c59f-e14c-a251-c2a614d64993}\SETAD3B.tmp | executable | |
MD5:508F1B94383E60362C9829E9C6B61702 | SHA256:B020AEE40DB12D1C77CA0CC863937ADB88802898CA37ECC45F0B63107ADD800F | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
5496 | MoUsoCoreWorker.exe | GET | 200 | 95.101.149.131:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
6544 | svchost.exe | GET | 200 | 2.17.190.73:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
3156 | POWERPNT.EXE | GET | 200 | 2.17.190.73:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D | unknown | — | — | whitelisted |
6668 | svchost.exe | HEAD | 200 | 199.232.210.172:80 | http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/bf8090eb-6e5c-4c51-9250-5bf9b46cf160?P1=1748974388&P2=404&P3=2&P4=Ggv6eo8KUX5QFfaL%2bh8acnNS6jwXTS%2b5n659DOfLClIewwgRh5sdjB2R6Xd9raiSp6df53l0NKA3FMc4%2bmSX4w%3d%3d | unknown | — | — | whitelisted |
6668 | svchost.exe | GET | 206 | 199.232.210.172:80 | http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/be7a09dc-f986-4c67-b2bd-3bae4add30af?P1=1748974389&P2=404&P3=2&P4=PcH3Pw5vZcg3pc8wEMt9eqvYbZaZdQDqpTSTHNhVrF%2b4z%2bUo3E32m4MK1gID86e11SN8Tsivx%2fu088aPsVgMNA%3d%3d | unknown | — | — | whitelisted |
6668 | svchost.exe | GET | 206 | 199.232.210.172:80 | http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/be7a09dc-f986-4c67-b2bd-3bae4add30af?P1=1748974389&P2=404&P3=2&P4=PcH3Pw5vZcg3pc8wEMt9eqvYbZaZdQDqpTSTHNhVrF%2b4z%2bUo3E32m4MK1gID86e11SN8Tsivx%2fu088aPsVgMNA%3d%3d | unknown | — | — | whitelisted |
6668 | svchost.exe | GET | 206 | 199.232.210.172:80 | http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/be7a09dc-f986-4c67-b2bd-3bae4add30af?P1=1748974389&P2=404&P3=2&P4=PcH3Pw5vZcg3pc8wEMt9eqvYbZaZdQDqpTSTHNhVrF%2b4z%2bUo3E32m4MK1gID86e11SN8Tsivx%2fu088aPsVgMNA%3d%3d | unknown | — | — | whitelisted |
5796 | svchost.exe | GET | 200 | 95.101.149.131:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
5496 | MoUsoCoreWorker.exe | GET | 200 | 2.16.241.19:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
5796 | svchost.exe | GET | 200 | 2.16.241.19:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 51.124.78.146:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
5496 | MoUsoCoreWorker.exe | 2.16.241.19:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
5796 | svchost.exe | 2.16.241.19:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
5496 | MoUsoCoreWorker.exe | 95.101.149.131:80 | www.microsoft.com | Akamai International B.V. | NL | whitelisted |
5796 | svchost.exe | 95.101.149.131:80 | www.microsoft.com | Akamai International B.V. | NL | whitelisted |
2268 | RUXIMICS.exe | 51.124.78.146:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
5796 | svchost.exe | 51.124.78.146:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
3216 | svchost.exe | 172.211.123.248:443 | client.wns.windows.com | MICROSOFT-CORP-MSN-AS-BLOCK | FR | whitelisted |
Domain | IP | Reputation |
|---|---|---|
google.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |
fe3cr.delivery.mp.microsoft.com |
| whitelisted |
www.bing.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
login.live.com |
| whitelisted |
fp.msedge.net |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
2064 | pwsh.exe | Not Suspicious Traffic | INFO [ANY.RUN] Azure Front Door domain observed in TLS SNI ( .azurefd .net) |
5488 | msedge.exe | Generic Protocol Command Decode | SURICATA QUIC failed decrypt |
5488 | msedge.exe | Generic Protocol Command Decode | SURICATA QUIC failed decrypt |
5488 | msedge.exe | Generic Protocol Command Decode | SURICATA QUIC failed decrypt |
5488 | msedge.exe | Generic Protocol Command Decode | SURICATA QUIC failed decrypt |
5488 | msedge.exe | Generic Protocol Command Decode | SURICATA QUIC failed decrypt |
5488 | msedge.exe | Generic Protocol Command Decode | SURICATA QUIC failed decrypt |
5488 | msedge.exe | Not Suspicious Traffic | INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com) |
5488 | msedge.exe | Not Suspicious Traffic | INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com) |
5488 | msedge.exe | Not Suspicious Traffic | INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com) |