| File name: | SR9900_SFX11.exe |
| Full analysis: | https://app.any.run/tasks/814056f9-1c94-45cb-8156-e5c20bddc418 |
| Verdict: | Malicious activity |
| Analysis date: | January 05, 2024, 05:58:14 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | CE52ACAAD2366624D19108C0964B2EF5 |
| SHA1: | 4FA8597E2ADE588B18113891908E3C74299BBB43 |
| SHA256: | 324A828BA8A159384177F41D4B0A6D9910F6FF73EB2C07102B1BB09D8311BC44 |
| SSDEEP: | 1536:FC9z67CdWit6WNIUSpu7J4JPvdubtnQB6GAknq7C0n2B7Gg1830WM9D6td01l:r7CT6SF4J3gnQB6GFnq7C0Odu0HEo |
| .exe | | | Generic Win/DOS Executable (50) |
|---|---|---|
| .exe | | | DOS Executable Generic (49.9) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2010:06:27 09:06:38+02:00 |
| ImageFileCharacteristics: | No relocs, Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 8 |
| CodeSize: | 70656 |
| InitializedDataSize: | 20992 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x11def |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.2.0.715 |
| ProductVersionNumber: | 1.2.0.715 |
| FileFlagsMask: | 0x0000 |
| FileFlags: | (none) |
| FileOS: | Windows NT 32-bit |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| Comments: | SR9900 Driver SfX |
| CompanyName: | CoreChips |
| FileDescription: | sr9900 sfx |
| FileVersion: | 3.0.6 |
| InternalName: | sr9900sfx |
| LegalCopyright: | Copyright © 2019-2020 CoreChips |
| OriginalFileName: | sr9900sfx |
| ProductName: | sr9900sfx |
| ProductVersion: | 3.0.6 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 668 | ".\install.exe" | C:\Users\admin\AppData\Local\Temp\SR9900_SFX\drivers\x86\install.exe | — | Setup.exe | |||||||||||
User: admin Company: CoreChip Semiconductor, Inc Integrity Level: HIGH Description: Install Program for CoreChip USB Ethernet Exit code: 0 Version: 5.00 built by: WinDDK Modules
| |||||||||||||||
| 1044 | DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{1b362dea-02c5-4cf1-e343-0b3fc5424e2e}\SR9900.inf" "0" "65402fe5f" "00000570" "WinSta0\Default" "00000338" "208" "C:\Users\admin\AppData\Local\Temp\SR9900_SFX\drivers\x86" | C:\Windows\System32\drvinst.exe | — | svchost.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Driver Installation Module Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1392 | "C:\Users\admin\AppData\Local\Temp\SR9900_SFX\Setup.exe" | C:\Users\admin\AppData\Local\Temp\SR9900_SFX\Setup.exe | — | SR9900_SFX11.exe | |||||||||||
User: admin Company: CoreChip Semiconductor, Inc Integrity Level: HIGH Description: Install Program for CoreChip USB Ethernet Exit code: 0 Version: 5.00 built by: WinDDK Modules
| |||||||||||||||
| 2044 | "C:\Users\admin\AppData\Local\Temp\SR9900_SFX11.exe" | C:\Users\admin\AppData\Local\Temp\SR9900_SFX11.exe | — | explorer.exe | |||||||||||
User: admin Company: CoreChips Integrity Level: MEDIUM Description: sr9900 sfx Exit code: 3221226540 Version: 3.0.6 Modules
| |||||||||||||||
| 2208 | "C:\Users\admin\AppData\Local\Temp\SR9900_SFX11.exe" | C:\Users\admin\AppData\Local\Temp\SR9900_SFX11.exe | explorer.exe | ||||||||||||
User: admin Company: CoreChips Integrity Level: HIGH Description: sr9900 sfx Exit code: 0 Version: 3.0.6 Modules
| |||||||||||||||
| (PID) Process: | (2208) SR9900_SFX11.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (2208) SR9900_SFX11.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (2208) SR9900_SFX11.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (2208) SR9900_SFX11.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (668) install.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (1044) drvinst.exe | Key: | HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2208 | SR9900_SFX11.exe | C:\Users\admin\AppData\Local\Temp\SR9900_SFX\Setup.exe | executable | |
MD5:E4C61F137BF08F7345F254968B20A850 | SHA256:5EB575A8A2FBC2457DA37180A45E1A3F26D9503CE218943A403EB02DA6C86D0E | |||
| 2208 | SR9900_SFX11.exe | C:\Users\admin\AppData\Local\Temp\SR9900_SFX\drivers\x86\install.exe | executable | |
MD5:3A7B764F0C3DDAF0377A9952949C190E | SHA256:3172A69C5F0B31E6EC059B277B317B1A9D5A5111376304C7846FA794F6072109 | |||
| 668 | install.exe | C:\Users\admin\AppData\Local\Temp\{1b362dea-02c5-4cf1-e343-0b3fc5424e2e}\SETFCFE.tmp | cat | |
MD5:FB206FF01F55CC1D8054596F1723C54C | SHA256:05BB0C02C444AE99EA80AF7B525F3413AA73A3EC32F7D020E7BF11AF50848B35 | |||
| 2208 | SR9900_SFX11.exe | C:\Users\admin\AppData\Local\Temp\SR9900_SFX\drivers\x86\SR9900.inf | binary | |
MD5:2E6C66FD601F2764CC47436F65A70B85 | SHA256:0657CC966B6A15157823A344ABFE46347427DB5DFB27280F9B1710DC44EB9A10 | |||
| 2208 | SR9900_SFX11.exe | C:\Users\admin\AppData\Local\Temp\SR9900_SFX\drivers\x64\sr9900.cat | binary | |
MD5:CEAF5443C374FA00420233850B9A36B5 | SHA256:91751D5461BA05984ADE62F2CEC5400AFFFECBD9C244EC51335FEE9198644D71 | |||
| 2208 | SR9900_SFX11.exe | C:\Users\admin\AppData\Local\Temp\SR9900_SFX\drivers\x86\sr9900.cat | binary | |
MD5:FB206FF01F55CC1D8054596F1723C54C | SHA256:05BB0C02C444AE99EA80AF7B525F3413AA73A3EC32F7D020E7BF11AF50848B35 | |||
| 2208 | SR9900_SFX11.exe | C:\Users\admin\AppData\Local\Temp\SR9900_SFX\drivers\x64\SR9900.inf | binary | |
MD5:05AF1EE3AA134579025796A57982E26F | SHA256:D09602EE7F38AF6A13897C98ACAD518417D30501EA32204821E528B2E4DC688A | |||
| 2208 | SR9900_SFX11.exe | C:\Users\admin\AppData\Local\Temp\SR9900_SFX\drivers\x64\SR9900.sys | executable | |
MD5:A854E5540CC329A034ECAF189204726D | SHA256:C10EA4C866103A6F2637539EBCF9EDB12F65C30EEF46A6221CD04910070E1D7E | |||
| 2208 | SR9900_SFX11.exe | C:\Users\admin\AppData\Local\Temp\SR9900_SFX\drivers\x86\SR9900.sys | executable | |
MD5:735FE1D058B61DB44B94008026FF4B83 | SHA256:EE2E85A2592FE4E1AA0F2547560E619A82A8B9432240D0860F14496D23EFCE82 | |||
| 668 | install.exe | C:\Users\admin\AppData\Local\Temp\{1b362dea-02c5-4cf1-e343-0b3fc5424e2e}\SR9900.cat | cat | |
MD5:FB206FF01F55CC1D8054596F1723C54C | SHA256:05BB0C02C444AE99EA80AF7B525F3413AA73A3EC32F7D020E7BF11AF50848B35 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |