File name:

SMIUSBDisplaySW.msi

Full analysis: https://app.any.run/tasks/b9617ff5-d92b-4a61-9921-4dc9fc381305
Verdict: Malicious activity
Analysis date: May 13, 2025, 02:58:22
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/x-msi
File info: Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, MSI Installer, Create Time/Date: Mon Jun 21 07:00:00 1999, Name of Creating Application: Windows Installer, Security: 1, Code page: 1252, Template: Intel;1033, Number of Pages: 200, Revision Number: {A9AD5715-00D6-42DC-956D-F1C9ED6A80C6}, Title: Silicon Motion USB Display Driver, Author: Silicon Motion Inc, Number of Words: 2, Last Saved Time/Date: Tue Dec 10 02:30:02 2024, Last Printed: Tue Dec 10 02:30:02 2024
MD5:

A9D7DC97209C714366B8609C93D33CEB

SHA1:

4C8AB403A5196956E098B4D8D5AE29FAAB275449

SHA256:

4703E690431C478D638AA71AFEE92268EDE858718E1BB69220139BC8818A8616

SSDEEP:

98304:HJuHJseOIax0K37LZLvyMoSLVFg+SFTyE/o81u/fik9G0+jmmu4NS65+EeqkGMDI:vr4jeNQ

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • ScanforhardwareChanges.exe (PID: 6760)
  • SUSPICIOUS

    • Executes as Windows Service

      • VSSVC.exe (PID: 896)
    • Process drops legitimate windows executable

      • msiexec.exe (PID: 4220)
    • Executable content was dropped or overwritten

      • drvinst.exe (PID: 6960)
  • INFO

    • Creates files or folders in the user directory

      • msiexec.exe (PID: 5244)
    • Reads the software policy settings

      • msiexec.exe (PID: 5244)
    • Reads security settings of Internet Explorer

      • msiexec.exe (PID: 5244)
    • Checks supported languages

      • msiexec.exe (PID: 4220)
    • Checks proxy server information

      • msiexec.exe (PID: 5244)
    • Reads the computer name

      • msiexec.exe (PID: 4220)
    • Manages system restore points

      • SrTasks.exe (PID: 2552)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 4220)
    • The sample compiled with arabic language support

      • msiexec.exe (PID: 4220)
    • The sample compiled with chinese language support

      • msiexec.exe (PID: 4220)
    • The sample compiled with english language support

      • msiexec.exe (PID: 4220)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.msi | Microsoft Windows Installer (98.5)
.msi | Microsoft Installer (100)

EXIF

FlashPix

CreateDate: 1999:06:21 07:00:00
Software: Windows Installer
Security: Password protected
CodePage: Windows Latin 1 (Western European)
Template: Intel;1033
Pages: 200
RevisionNumber: {A9AD5715-00D6-42DC-956D-F1C9ED6A80C6}
Title: Silicon Motion USB Display Driver
Subject: -
Author: Silicon Motion Inc
Keywords: -
Comments: -
Words: 2
ModifyDate: 2024:12:10 02:30:02
LastPrinted: 2024:12:10 02:30:02
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
153
Monitored processes
22
Malicious processes
0
Suspicious processes
2

Behavior graph

Click at the process to see the details
start msiexec.exe msiexec.exe sppextcomobj.exe no specs slui.exe no specs vssvc.exe no specs srtasks.exe no specs conhost.exe no specs uninstalldockingformsi.exe no specs conhost.exe driverinstall.exe no specs conhost.exe driverinstall.exe no specs conhost.exe drvinst.exe driverinstall.exe no specs conhost.exe driverinstall.exe no specs conhost.exe driverinstall.exe no specs conhost.exe scanforhardwarechanges.exe no specs conhost.exe

Process information

PID
CMD
Path
Indicators
Parent process
896C:\WINDOWS\system32\vssvc.exeC:\Windows\System32\VSSVC.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Volume Shadow Copy Service
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\vssvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
928"C:\Program Files (x86)\Silicon Motion USB Display Driver\UninstallDockingForMsi.exe"C:\Program Files (x86)\Silicon Motion USB Display Driver\UninstallDockingForMsi.exemsiexec.exe
User:
admin
Company:
Silicon Motion
Integrity Level:
MEDIUM
Description:
SMI DriverInstall
Exit code:
0
Version:
0.0.1.0
Modules
Images
c:\program files (x86)\silicon motion usb display driver\uninstalldockingformsi.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
2092\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exe
DriverInstall.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2316\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exe
DriverInstall.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2392C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
2552C:\WINDOWS\system32\srtasks.exe ExecuteScopeRestorePoint /WaitForRestorePoint:11C:\Windows\System32\SrTasks.exemsiexec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Windows System Protection background tasks.
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\srtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
2564\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exe
DriverInstall.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2984\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeSrTasks.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Console Window Host
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
4164"C:\Program Files (x86)\Silicon Motion USB Display Driver\x64\DriverInstall.exe" "C:\Program Files (x86)\Silicon Motion USB Display Driver\x64\SMIIddX.inf" "USB\VID_090C&PID_0760"C:\Program Files (x86)\Silicon Motion USB Display Driver\x64\DriverInstall.exemsiexec.exe
User:
admin
Company:
Silicon Motion
Integrity Level:
MEDIUM
Description:
SMI DriverInstall
Exit code:
0
Version:
0.0.1.0
Modules
Images
c:\program files (x86)\silicon motion usb display driver\x64\driverinstall.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\difxapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
4220C:\WINDOWS\system32\msiexec.exe /VC:\Windows\System32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
Total events
12 975
Read events
12 693
Write events
265
Delete events
17

Modification events

(PID) Process:(4220) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppEnumGroups (Leave)
Value:
48000000000000004A91D5ECB2C3DB017C100000D4090000D10700000100000000000000010000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(4220) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SystemRestore
Operation:writeName:SrCreateRp (Enter)
Value:
48000000000000002C138EECB2C3DB017C100000D4090000D50700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(4220) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppGetSnapshots (Enter)
Value:
48000000000000002C138EECB2C3DB017C100000D4090000D20700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(4220) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppGetSnapshots (Leave)
Value:
48000000000000003E2ED3ECB2C3DB017C100000D4090000D20700000100000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(4220) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppEnumGroups (Enter)
Value:
48000000000000003E2ED3ECB2C3DB017C100000D4090000D10700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(4220) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppCreate (Enter)
Value:
480000000000000080F5D7ECB2C3DB017C100000D4090000D00700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(4220) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP
Operation:writeName:LastIndex
Value:
11
(PID) Process:(4220) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppGatherWriterMetadata (Enter)
Value:
4800000000000000C31099EDB2C3DB017C100000D4090000D30700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(4220) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\VssapiPublisher
Operation:writeName:IDENTIFY (Enter)
Value:
48000000000000002E749BEDB2C3DB017C100000E0170000E8030000010000000000000000000000C32FD28EC789DD43A8BE469C8036D48B00000000000000000000000000000000
(PID) Process:(896) VSSVC.exeKey:HKEY_LOCAL_MACHINE\BCD00000000\Objects\{9dea862c-5cdd-4e70-acc1-f32b344d4795}\Elements\11000001
Operation:delete keyName:(default)
Value:
Executable files
14
Suspicious files
32
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
4220msiexec.exeC:\System Volume Information\SPP\metadata-2
MD5:
SHA256:
4220msiexec.exeC:\System Volume Information\SPP\OnlineMetadataCache\{8ed22fc3-89c7-43dd-a8be-469c8036d48b}_OnDiskSnapshotPropbinary
MD5:88678A8B8B01011C3DB178CA05AD1D10
SHA256:CB32B713429C3A65D3E90C1CA4C476D06E6EE31A835A34E88D131E4C79F16463
4220msiexec.exeC:\System Volume Information\SPP\snapshot-2binary
MD5:88678A8B8B01011C3DB178CA05AD1D10
SHA256:CB32B713429C3A65D3E90C1CA4C476D06E6EE31A835A34E88D131E4C79F16463
5244msiexec.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\C8E534EE129F27D55460CE17FD628216_1130D9B25898B0DB0D4F04DC5B93F141binary
MD5:DA6D88DBC40C11EAF3785A7B22086C82
SHA256:234E501FDEAD54D0E190010919D40E84594EFBFA2B66E4D6A9D6EB23CEDED7F5
5244msiexec.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\8EC9B1D0ABBD7F98B401D425828828CE_3C3D3D241D8905D3080E467F0BC4A22Bbinary
MD5:186AD3FFC45290BFA842249DA89625CB
SHA256:7EDB69AA0523AFA392A6C79C669363772EE7C0FAC9E2CC0CCD093FADE0166BD1
5244msiexec.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\8EC9B1D0ABBD7F98B401D425828828CE_3C3D3D241D8905D3080E467F0BC4A22Bbinary
MD5:DA5B286BB5FC8CFDC2FC847FFFB94B72
SHA256:650C8585446596391F54DF4059CD68BD82D9BDFF79EAD42F448BE52FD5A172FC
4220msiexec.exeC:\Windows\Installer\inprogressinstallinfo.ipibinary
MD5:F96F43CADAF783BF316CCF13FD2423AA
SHA256:0A448D43E69AB5E3850BD68976ADD2BA44ED22370F4EA9B67C6A9A4D07A2EBBD
4220msiexec.exeC:\Windows\Installer\MSI223B.tmpbinary
MD5:3D8A955DB2748711D7694B1048DEC037
SHA256:E4B303D6B4F4F8DDBABFCD90C3399D67FD614242D9B1A7CE6366FD62C550911C
4220msiexec.exeC:\Windows\Temp\~DF9308F8B8099F638D.TMPbinary
MD5:F96F43CADAF783BF316CCF13FD2423AA
SHA256:0A448D43E69AB5E3850BD68976ADD2BA44ED22370F4EA9B67C6A9A4D07A2EBBD
5244msiexec.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\C8E534EE129F27D55460CE17FD628216_1130D9B25898B0DB0D4F04DC5B93F141binary
MD5:A857CA8CFBD241795BE7A4A207B99148
SHA256:94C91B4917B5DED0C167DEF7C99A16E58C109F2A3D79931A709597FB63B89850
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
8
TCP/UDP connections
27
DNS requests
16
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
23.216.77.29:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
5244
msiexec.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT3xL4LQLXDRDM9P665TW442vrsUQQUReuir%2FSSy4IxLVGLp6chnfNtyA8CEA6bGI750C3n79tQ4ghAGFo%3D
unknown
whitelisted
5244
msiexec.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfIs%2BLjDtGwQ09XEB1Yeq%2BtX%2BBgQQU7NfjgtJxXWRM3y5nP%2Be6mK4cD08CEAitQLJg0pxMn17Nqb2Trtk%3D
unknown
whitelisted
5244
msiexec.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSRXerF0eFeSWRripTgTkcJWMm7iQQUaDfg67Y7%2BF8Rhvv%2BYXsIiGX0TkICEAXD6tBLVs2Mk2cT7myl7Ek%3D
unknown
whitelisted
6544
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
4120
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
4120
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2104
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
23.216.77.29:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
5244
msiexec.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
2112
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
3216
svchost.exe
172.211.123.250:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
6544
svchost.exe
40.126.32.140:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
  • 51.124.78.146
  • 40.127.240.158
whitelisted
crl.microsoft.com
  • 23.216.77.29
  • 23.216.77.19
  • 23.216.77.18
  • 23.216.77.21
  • 23.216.77.43
  • 23.216.77.4
whitelisted
www.microsoft.com
  • 23.35.229.160
  • 95.101.149.131
whitelisted
google.com
  • 142.250.181.238
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
client.wns.windows.com
  • 172.211.123.250
whitelisted
login.live.com
  • 40.126.32.140
  • 40.126.32.72
  • 20.190.160.131
  • 20.190.160.128
  • 40.126.32.133
  • 20.190.160.2
  • 20.190.160.20
  • 20.190.160.130
whitelisted
go.microsoft.com
  • 95.100.186.9
whitelisted
slscr.update.microsoft.com
  • 52.149.20.212
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 20.242.39.171
whitelisted

Threats

No threats detected
No debug info