File name:

OLYMPUS-OSTE_FTDI-USB-Driver_2.12.28_WHQL_Wizard.exe

Full analysis: https://app.any.run/tasks/e55e711e-fbf8-4192-8d90-cf673a265a0c
Verdict: Malicious activity
Analysis date: June 04, 2025, 13:18:04
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, RAR self-extracting archive, 4 sections
MD5:

0484D5EE3E97C112D6AA395AD5F1D969

SHA1:

728330F01FFD6A9E6555837E723340CD1B36EEFD

SHA256:

1E777993A741B41588841D7CD9578AF05ED1E8A2CF1E4453D059EC9E41C7728F

SSDEEP:

98304:rqFvtU3H/RSPtcGWZ8BcysLv2tAnALFSSIVsrNq2J1ydcMf7Aiga5vuWojp4omIR:CM0

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • OLYMPUS-OSTE_FTDI-USB-Driver_2.12.28_WHQL_Wizard.exe (PID: 3208)
    • Reads security settings of Internet Explorer

      • OLYMPUS-OSTE_FTDI-USB-Driver_2.12.28_WHQL_Wizard.exe (PID: 3208)
      • dpinst-amd64.exe (PID: 2040)
    • Drops a system driver (possible attempt to evade defenses)

      • OLYMPUS-OSTE_FTDI-USB-Driver_2.12.28_WHQL_Wizard.exe (PID: 3208)
      • dpinst-amd64.exe (PID: 2040)
      • drvinst.exe (PID: 4404)
      • drvinst.exe (PID: 5760)
    • Executable content was dropped or overwritten

      • OLYMPUS-OSTE_FTDI-USB-Driver_2.12.28_WHQL_Wizard.exe (PID: 3208)
      • dpinst-amd64.exe (PID: 2040)
      • drvinst.exe (PID: 4404)
      • drvinst.exe (PID: 5760)
    • Starts a Microsoft application from unusual location

      • dpinst-amd64.exe (PID: 2332)
      • dpinst-amd64.exe (PID: 2040)
    • Creates files in the driver directory

      • drvinst.exe (PID: 4404)
      • drvinst.exe (PID: 5760)
    • There is functionality for taking screenshot (YARA)

      • OLYMPUS-OSTE_FTDI-USB-Driver_2.12.28_WHQL_Wizard.exe (PID: 3208)
  • INFO

    • Reads the computer name

      • OLYMPUS-OSTE_FTDI-USB-Driver_2.12.28_WHQL_Wizard.exe (PID: 3208)
      • dp-chooser.exe (PID: 2616)
      • dpinst-amd64.exe (PID: 2040)
    • Checks supported languages

      • OLYMPUS-OSTE_FTDI-USB-Driver_2.12.28_WHQL_Wizard.exe (PID: 3208)
      • dp-chooser.exe (PID: 2616)
      • dpinst-amd64.exe (PID: 2040)
      • drvinst.exe (PID: 4404)
      • drvinst.exe (PID: 5760)
    • Create files in a temporary directory

      • OLYMPUS-OSTE_FTDI-USB-Driver_2.12.28_WHQL_Wizard.exe (PID: 3208)
      • dpinst-amd64.exe (PID: 2040)
    • The sample compiled with arabic language support

      • OLYMPUS-OSTE_FTDI-USB-Driver_2.12.28_WHQL_Wizard.exe (PID: 3208)
    • Process checks computer location settings

      • OLYMPUS-OSTE_FTDI-USB-Driver_2.12.28_WHQL_Wizard.exe (PID: 3208)
    • The sample compiled with english language support

      • OLYMPUS-OSTE_FTDI-USB-Driver_2.12.28_WHQL_Wizard.exe (PID: 3208)
      • dpinst-amd64.exe (PID: 2040)
      • drvinst.exe (PID: 4404)
      • drvinst.exe (PID: 5760)
    • Reads the software policy settings

      • drvinst.exe (PID: 4404)
      • dpinst-amd64.exe (PID: 2040)
      • drvinst.exe (PID: 5760)
    • Reads the machine GUID from the registry

      • drvinst.exe (PID: 4404)
      • dpinst-amd64.exe (PID: 2040)
      • drvinst.exe (PID: 5760)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2015:02:15 08:00:31+00:00
ImageFileCharacteristics: No relocs, Executable, 32-bit
PEType: PE32
LinkerVersion: 9
CodeSize: 165888
InitializedDataSize: 176128
UninitializedDataSize: -
EntryPoint: 0x1d7cb
OSVersion: 5
ImageVersion: -
SubsystemVersion: 5
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
135
Monitored processes
8
Malicious processes
3
Suspicious processes
1

Behavior graph

Click at the process to see the details
start olympus-oste_ftdi-usb-driver_2.12.28_whql_wizard.exe dp-chooser.exe no specs dpinst-amd64.exe no specs dpinst-amd64.exe sppextcomobj.exe no specs slui.exe no specs drvinst.exe drvinst.exe

Process information

PID
CMD
Path
Indicators
Parent process
2040C:\Users\admin\AppData\Local\Temp\RarSFX0\dpinst-amd64.exe /saC:\Users\admin\AppData\Local\Temp\RarSFX0\dpinst-amd64.exe
dp-chooser.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Driver Package Installer
Exit code:
2147614720
Version:
2.1
Modules
Images
c:\users\admin\appdata\local\temp\rarsfx0\dpinst-amd64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
2332C:\Users\admin\AppData\Local\Temp\RarSFX0\dpinst-amd64.exe /saC:\Users\admin\AppData\Local\Temp\RarSFX0\dpinst-amd64.exedp-chooser.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Driver Package Installer
Exit code:
3221226540
Version:
2.1
Modules
Images
c:\users\admin\appdata\local\temp\rarsfx0\dpinst-amd64.exe
c:\windows\system32\ntdll.dll
2616"C:\Users\admin\AppData\Local\Temp\RarSFX0\dp-chooser.exe" C:\Users\admin\AppData\Local\Temp\RarSFX0\dp-chooser.exeOLYMPUS-OSTE_FTDI-USB-Driver_2.12.28_WHQL_Wizard.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
1
Modules
Images
c:\users\admin\appdata\local\temp\rarsfx0\dp-chooser.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
3208"C:\Users\admin\AppData\Local\Temp\OLYMPUS-OSTE_FTDI-USB-Driver_2.12.28_WHQL_Wizard.exe" C:\Users\admin\AppData\Local\Temp\OLYMPUS-OSTE_FTDI-USB-Driver_2.12.28_WHQL_Wizard.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\olympus-oste_ftdi-usb-driver_2.12.28_whql_wizard.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
4404DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{c5f632ff-5bde-8f48-b0c3-5f1823cdedc5}\ftdibus_olympus_21228.inf" "9" "4504e0faf" "00000000000001BC" "WinSta0\Default" "00000000000001DC" "208" "c:\users\admin\appdata\local\temp\rarsfx0"C:\Windows\System32\drvinst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
3758096967
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\drvstore.dll
5760DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{a85365c9-d1e3-9a41-bccf-0c9ad21e5299}\ftdiport_olympus_21228.inf" "9" "414172e23" "0000000000000200" "WinSta0\Default" "0000000000000204" "208" "c:\users\admin\appdata\local\temp\rarsfx0"C:\Windows\System32\drvinst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
3758096967
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\drvstore.dll
5956C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
6044"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exeSppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
Total events
9 951
Read events
9 950
Write events
1
Delete events
0

Modification events

(PID) Process:(2040) dpinst-amd64.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\Setup\SetupapiLogStatus
Operation:writeName:setupapi.dev.log
Value:
4096
Executable files
49
Suspicious files
0
Text files
15
Unknown types
14

Dropped files

PID
Process
Filename
Type
3208OLYMPUS-OSTE_FTDI-USB-Driver_2.12.28_WHQL_Wizard.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\amd64\ftd2xx64.dllexecutable
MD5:5AAB68257385BF14B29AB06AF9028875
SHA256:2063A67B534D35180C3567A897441745F25F94FAB7D8AEDA3ED180647DFAEB2F
3208OLYMPUS-OSTE_FTDI-USB-Driver_2.12.28_WHQL_Wizard.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\amd64\ftcserco.dllexecutable
MD5:C2D30B253B5ADDC0BBC416038FDA74E0
SHA256:1ED710D8748A0D34D4FF3F0805A6A22D9998AAD487A3613D8648617EC882F7DE
3208OLYMPUS-OSTE_FTDI-USB-Driver_2.12.28_WHQL_Wizard.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\amd64\ftser2k.sysexecutable
MD5:394D35D9161C144731FB94C77B92766C
SHA256:DF00A2E5290C2BC97ADFEABB940AD369CEEBA287992E4347B55B18D14E81D929
3208OLYMPUS-OSTE_FTDI-USB-Driver_2.12.28_WHQL_Wizard.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\dp-chooser.exeexecutable
MD5:E1C3BA5CF21F8CAA7712E3D582AF9572
SHA256:3EB330339B09DCA6259EB9888B6D46396BF2052096F62DE6DCE2A19E2DB68E69
3208OLYMPUS-OSTE_FTDI-USB-Driver_2.12.28_WHQL_Wizard.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\amd64\ftdibus.sysexecutable
MD5:1403FE95CB5879C3F1FFFC6D42ED733F
SHA256:0493892CD57262ADF359FBBEB7449E9CC7BA4F20653770A505665996422122AD
3208OLYMPUS-OSTE_FTDI-USB-Driver_2.12.28_WHQL_Wizard.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\Bitmaps\OLYMPUS_Logo_24bit.bmpimage
MD5:DDFD7C752AEE9A4EEF7C312BD39CD0A3
SHA256:A17017ACEAC7CF0B728642E70B2564F97D80240014BBE825207D61E4764DF1C4
3208OLYMPUS-OSTE_FTDI-USB-Driver_2.12.28_WHQL_Wizard.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\amd64\ftserui2.dllexecutable
MD5:5459493895BBAD632108211E0F8DC00D
SHA256:83593263F561E726FA1DD2B49AA48021FF62253ADF6B91CF130ACF9BE2C0299E
3208OLYMPUS-OSTE_FTDI-USB-Driver_2.12.28_WHQL_Wizard.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\amd64\ftd2xx.libobj
MD5:D8B31806632C9E2DC4BB79E87C98C0B2
SHA256:260A37AA3966AEEE901DC8819C98E47BF47E61D5F724472559D33B55F4F9C271
3208OLYMPUS-OSTE_FTDI-USB-Driver_2.12.28_WHQL_Wizard.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\ftdibus_olympus_21228.catcat
MD5:894B0F5BF9084DB2CC19F37ACE624FD8
SHA256:5912D1B6012AC038643CB7A26EB7ABE5F81CB995C480232538AA38BF42CCE33A
3208OLYMPUS-OSTE_FTDI-USB-Driver_2.12.28_WHQL_Wizard.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\dpinst-amd64.exeexecutable
MD5:14B0EDCA300315AB0ABFA7B7426D4F3B
SHA256:93DC12B5A502B81F00D164E494299CAF05BF64ADF80486A409E78670D36C03B8
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
19
DNS requests
11
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5496
MoUsoCoreWorker.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
184.25.50.8:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
6544
svchost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6820
SIHClient.exe
GET
200
2.23.181.156:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
6820
SIHClient.exe
GET
200
2.23.181.156:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
20.73.194.208:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:137
whitelisted
4164
svchost.exe
20.73.194.208:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5496
MoUsoCoreWorker.exe
184.25.50.8:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
1180
RUXIMICS.exe
20.73.194.208:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5496
MoUsoCoreWorker.exe
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
5496
MoUsoCoreWorker.exe
20.73.194.208:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2112
svchost.exe
20.73.194.208:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
4164
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted

DNS requests

Domain
IP
Reputation
crl.microsoft.com
  • 184.25.50.8
  • 184.25.50.10
whitelisted
www.microsoft.com
  • 95.101.149.131
  • 2.23.181.156
whitelisted
settings-win.data.microsoft.com
  • 51.124.78.146
whitelisted
login.live.com
  • 20.190.160.4
  • 20.190.160.128
  • 40.126.32.68
  • 20.190.160.22
  • 20.190.160.65
  • 20.190.160.2
  • 20.190.160.132
  • 40.126.32.140
whitelisted
ocsp.digicert.com
  • 2.23.77.188
whitelisted
client.wns.windows.com
  • 172.211.123.249
whitelisted
slscr.update.microsoft.com
  • 4.245.163.56
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 20.242.39.171
whitelisted

Threats

No threats detected
No debug info