| File name: | RTK_NIC_DRIVER_INSTALLER.sfx.exe |
| Full analysis: | https://app.any.run/tasks/e85ddce7-da81-42ae-ba2e-ca4f816cd29b |
| Verdict: | Malicious activity |
| Analysis date: | January 22, 2024, 17:00:18 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 3139A6B7AC5C7DF144B28DCD489EB6D7 |
| SHA1: | 873851F0E8D641EAC7FDF807919E1F984964DFB2 |
| SHA256: | 28E465120BD979055D5CD0E4A1A4690DA55C4A3E21565B7616E3438B46F4D5A7 |
| SSDEEP: | 49152:BfJgDmsa43h4/MYTBRCzuDkrRXIYY1LP5H163r1ZywUpEgSCi53TLDp1IRBY6af0:BfJgDmsa43cvNDkhIrJ16b1ZyV/itVCr |
| .exe | | | Generic Win/DOS Executable (50) |
|---|---|---|
| .exe | | | DOS Executable Generic (49.9) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2010:06:27 09:06:38+02:00 |
| ImageFileCharacteristics: | No relocs, Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 8 |
| CodeSize: | 70656 |
| InitializedDataSize: | 115712 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x11def |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 316 | DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{30ba8587-ca1e-76d8-a69e-6e4f1a009b4b}\rtux86w7.inf" "0" "69369bd0f" "000003DC" "WinSta0\Default" "000005C0" "208" "C:\Users\admin\AppData\Local\Temp\RTK_NIC_DRIVER_INSTALLER\WIN7\32" | C:\Windows\System32\drvinst.exe | svchost.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Driver Installation Module Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 492 | "C:\Users\admin\AppData\Local\Temp\RTK_NIC_DRIVER_INSTALLER\Setup.exe" -s | C:\Users\admin\AppData\Local\Temp\RTK_NIC_DRIVER_INSTALLER\Setup.exe | RTK_NIC_DRIVER_INSTALLER.sfx.exe | ||||||||||||
User: admin Company: Realtek Semiconductor Corp. Integrity Level: HIGH Description: USB NIC Driver Auto Installer Exit code: 0 Version: 1.0.0.10 Modules
| |||||||||||||||
| 2184 | "C:\Users\admin\AppData\Local\Temp\RTK_NIC_DRIVER_INSTALLER.sfx.exe" | C:\Users\admin\AppData\Local\Temp\RTK_NIC_DRIVER_INSTALLER.sfx.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 3221226540 Modules
| |||||||||||||||
| 2208 | "C:\Users\admin\AppData\Local\Temp\RTK_NIC_DRIVER_INSTALLER.sfx.exe" | C:\Users\admin\AppData\Local\Temp\RTK_NIC_DRIVER_INSTALLER.sfx.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| (PID) Process: | (2208) RTK_NIC_DRIVER_INSTALLER.sfx.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (2208) RTK_NIC_DRIVER_INSTALLER.sfx.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (2208) RTK_NIC_DRIVER_INSTALLER.sfx.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (2208) RTK_NIC_DRIVER_INSTALLER.sfx.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (492) Setup.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (316) drvinst.exe | Key: | HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2208 | RTK_NIC_DRIVER_INSTALLER.sfx.exe | C:\Users\admin\AppData\Local\Temp\RTK_NIC_DRIVER_INSTALLER\WIN10\64\rtux64w10.INF | binary | |
MD5:F023CDCC0B170E70A8686F9030406B14 | SHA256:5508DA72D5EFB45A2EB96894D86024645ACD2BA88E2ADA6320CF7911BFFCAEF9 | |||
| 2208 | RTK_NIC_DRIVER_INSTALLER.sfx.exe | C:\Users\admin\AppData\Local\Temp\RTK_NIC_DRIVER_INSTALLER\WIN7\64\rtux64w7.cat | binary | |
MD5:0D660C36087540F1965C84B3339EB212 | SHA256:3534196D98A0539CF81DA163508A446D8940CA80568F56F76A2B5694DC696C9E | |||
| 2208 | RTK_NIC_DRIVER_INSTALLER.sfx.exe | C:\Users\admin\AppData\Local\Temp\RTK_NIC_DRIVER_INSTALLER\WIN8\32\rtux86w8.INF | binary | |
MD5:A1963BB98E1740489B10EE8B9615ADA9 | SHA256:FDB96FB8DA22F36DC084D123CEEF5E01746E30607CC02BE20336A0B09F609D60 | |||
| 2208 | RTK_NIC_DRIVER_INSTALLER.sfx.exe | C:\Users\admin\AppData\Local\Temp\RTK_NIC_DRIVER_INSTALLER\WIN7\64\rtux64w7.INF | binary | |
MD5:B2E25C6ADC493A18B81A09455D020B7A | SHA256:D6EE23E484C010F0B14E26E3DE36D271D25694A9AC8CFFE0B7E45F155492EAC0 | |||
| 2208 | RTK_NIC_DRIVER_INSTALLER.sfx.exe | C:\Users\admin\AppData\Local\Temp\RTK_NIC_DRIVER_INSTALLER\WIN8\32\rtux86w8.cat | binary | |
MD5:3420485CE3DB44253D4038F74226B2A2 | SHA256:8E88B6A995E0C4D36414E1F495C650FABC27E70D178CA390D64EC7BC120C2ACE | |||
| 2208 | RTK_NIC_DRIVER_INSTALLER.sfx.exe | C:\Users\admin\AppData\Local\Temp\RTK_NIC_DRIVER_INSTALLER\WIN8\64\rtux64w8.INF | binary | |
MD5:28ACA719C6FAD417AF7FDB7A8E7C34FB | SHA256:178986E1979BA5D596A06110599B7333081B332AB00407332B5CE9184ACF845F | |||
| 2208 | RTK_NIC_DRIVER_INSTALLER.sfx.exe | C:\Users\admin\AppData\Local\Temp\RTK_NIC_DRIVER_INSTALLER\WIN10\64\rtux64w10.cat | binary | |
MD5:02221650B872819E1AD2B9D7277563A0 | SHA256:7A7C14946D4F406D3FEBD7F05DEB393B05F9F7E1C0ABDE0DA00E4BE880D3E2FB | |||
| 2208 | RTK_NIC_DRIVER_INSTALLER.sfx.exe | C:\Users\admin\AppData\Local\Temp\RTK_NIC_DRIVER_INSTALLER\WIN8\64\rtux64w8.cat | binary | |
MD5:9D4CC364EA49A08675ADD04E67847CE5 | SHA256:EC037157B401E39316F7C65BD3D1602550D5F14B52E8DD1FAD2E05DF7321251C | |||
| 2208 | RTK_NIC_DRIVER_INSTALLER.sfx.exe | C:\Users\admin\AppData\Local\Temp\RTK_NIC_DRIVER_INSTALLER\WIN7\32\rtux86w7.cat | binary | |
MD5:15091E2FAC93675589FF326EDE17E9EA | SHA256:08E9BE151FA446C1965CC8627F672021E7B4D186E7B9867AA6C7EAF8DC838016 | |||
| 2208 | RTK_NIC_DRIVER_INSTALLER.sfx.exe | C:\Users\admin\AppData\Local\Temp\RTK_NIC_DRIVER_INSTALLER\WINVISTA\64\rtux64lh.cat | binary | |
MD5:35AF19AF287109968457BF623AE25159 | SHA256:6FA76F0D0D7788A4C5D8AE92FBCA280589021B824821CADC3B0C77D87F05B327 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |