| File name: | Windows_xp_1.0.8.exe |
| Full analysis: | https://app.any.run/tasks/d4cd8d64-1740-415d-b9c9-469a4a1f777d |
| Verdict: | Malicious activity |
| Analysis date: | February 27, 2024, 11:52:26 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 6F23FF8839102D94B67654941AB620AB |
| SHA1: | ED5462D19012BED0E2D5DF6F9E779FB3FCF26628 |
| SHA256: | 61F6CD23FAFE23A44A41C394321CF9EC445705C8BAF5AA3B50F3C45F12C4594B |
| SSDEEP: | 24576:D7blNima5gbcc77FyFbzjfr1jfoHGIZUjMxOLhTL3ZruoI8B7tcw:D75oT90FydzrlwHGIIaONngo/B7tcw |
| .exe | | | Inno Setup installer (81.5) |
|---|---|---|
| .exe | | | Win32 Executable Delphi generic (10.5) |
| .exe | | | Win32 Executable (generic) (3.3) |
| .exe | | | Win16/32 Executable Delphi generic (1.5) |
| .exe | | | Generic Win/DOS Executable (1.4) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 1992:06:19 22:22:17+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi |
| PEType: | PE32 |
| LinkerVersion: | 2.25 |
| CodeSize: | 41472 |
| InitializedDataSize: | 103936 |
| UninitializedDataSize: | - |
| EntryPoint: | 0xaa98 |
| OSVersion: | 1 |
| ImageVersion: | 6 |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.0.8.0 |
| ProductVersionNumber: | 1.0.8.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| Comments: | This installation was built with Inno Setup. |
| CompanyName: | 深圳市恒亿昌科技有限公司 |
| FileDescription: | USB Display Setup |
| FileVersion: | 1.0.8 |
| LegalCopyright: | Copyright © MS 2019 |
| ProductName: | USB Display |
| ProductVersion: | 1.0.8 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1112 | DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{47f94fe9-7d55-3951-4beb-0745d5b9f24f}\dfmirage.inf" "0" "670102fe7" "000004B0" "WinSta0\Default" "00000558" "208" "c:\program files\usb display\video_driver" | C:\Windows\System32\drvinst.exe | svchost.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Driver Installation Module Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1776 | "C:\Users\admin\AppData\Local\Temp\Windows_xp_1.0.8.exe" /SPAWNWND=$1A01BC /NOTIFYWND=$E0170 | C:\Users\admin\AppData\Local\Temp\Windows_xp_1.0.8.exe | Windows_xp_1.0.8.tmp | ||||||||||||
User: admin Company: 深圳市恒亿昌科技有限公司 Integrity Level: HIGH Description: USB Display Setup Exit code: 0 Version: 1.0.8 Modules
| |||||||||||||||
| 1892 | DrvInst.exe "2" "211" "ROOT\DISPLAY\0000" "C:\Windows\INF\oem4.inf" "dfmirage.inf:DFMirage.Mfg.NTx86:DFMirage:1.0.0.0:dfmirage" "670102fe7" "000004B0" "00000074" "000005EC" | C:\Windows\System32\drvinst.exe | svchost.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Driver Installation Module Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2332 | "C:\Program Files\USB Display\tool\x86\devcon.exe" dp_add "C:\Program Files\USB Display\lib_usb\MSUSBDisplay.inf" USB\VID_534D&PID_6021&MI_03 | C:\Program Files\USB Display\tool\x86\devcon.exe | Windows_xp_1.0.8.tmp | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Setup API Exit code: 0 Version: 6.1.7600.16385 (win7_wdk.100208-1538) Modules
| |||||||||||||||
| 2616 | DrvInst.exe "2" "211" "ROOT\DISPLAY\0001" "C:\Windows\INF\oem5.inf" "virtualmonitor.inf:Model:VirtualMonitorVideo:0.2.1.0:virtualmonitorvideo" "6036fb98f" "000005D4" "000005E4" "000005EC" | C:\Windows\System32\drvinst.exe | svchost.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Driver Installation Module Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2620 | "C:\Program Files\USB Display\tool\x86\WinDrvInstaller.exe" -i | C:\Program Files\USB Display\tool\x86\WinDrvInstaller.exe | Windows_xp_1.0.8.tmp | ||||||||||||
User: admin Company: VirtualMonitor Org Integrity Level: HIGH Description: VirtualMonitor Driver Installer Exit code: 0 Version: . Modules
| |||||||||||||||
| 2856 | C:\Windows\system32\vssvc.exe | C:\Windows\System32\VSSVC.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft® Volume Shadow Copy Service Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2900 | rundll32.exe C:\Windows\system32\pnpui.dll,InstallSecurityPromptRunDllW 20 Global\{6040ed05-7b14-05b0-8dc3-a27b7a5c1262} Global\{40ae3b25-d6c7-5e55-5454-c02f2c08ea6d} C:\Windows\System32\DriverStore\Temp\{1161363f-2f53-472a-f760-ca44b5f97033}\dfmirage.inf C:\Windows\System32\DriverStore\Temp\{1161363f-2f53-472a-f760-ca44b5f97033}\dfmirage.cat | C:\Windows\System32\rundll32.exe | — | drvinst.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows host process (Rundll32) Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2964 | "C:\Users\admin\AppData\Local\Temp\is-VUOB7.tmp\Windows_xp_1.0.8.tmp" /SL5="$19013E,1210479,146432,C:\Users\admin\AppData\Local\Temp\Windows_xp_1.0.8.exe" /SPAWNWND=$1A01BC /NOTIFYWND=$E0170 | C:\Users\admin\AppData\Local\Temp\is-VUOB7.tmp\Windows_xp_1.0.8.tmp | Windows_xp_1.0.8.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: Setup/Uninstall Exit code: 0 Version: 51.52.0.0 Modules
| |||||||||||||||
| 3212 | DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{68039185-3266-0ff0-4c10-d9645176126d}\MSUSBDisplay.inf" "0" "69b557e9f" "000004B0" "WinSta0\Default" "000005D4" "208" "C:\Program Files\USB Display\lib_usb" | C:\Windows\System32\drvinst.exe | svchost.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Driver Installation Module Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (2964) Windows_xp_1.0.8.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | Owner |
Value: 940B000020C5AF757369DA01 | |||
| (PID) Process: | (2964) Windows_xp_1.0.8.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | SessionHash |
Value: FF95589B20B0B43C303045AB3C1349F63085D7761B6558F9EEC930514D26E5F1 | |||
| (PID) Process: | (2964) Windows_xp_1.0.8.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | Sequence |
Value: 1 | |||
| (PID) Process: | (2964) Windows_xp_1.0.8.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | RegFiles0000 |
Value: C:\Program Files\USB Display\msvcr100d.dll | |||
| (PID) Process: | (2964) Windows_xp_1.0.8.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | RegFilesHash |
Value: 6EC4F3B3852C2CEB6A404F74E50A954AE9B97B8A1D486EB719FB554D1247DFD6 | |||
| (PID) Process: | (2964) Windows_xp_1.0.8.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run |
| Operation: | write | Name: | Windows Usb Display |
Value: C:\Program Files\USB Display\WinUsbDisplay.exe | |||
| (PID) Process: | (2964) Windows_xp_1.0.8.tmp | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Hardware Profiles\0001\System\CurrentControlSet\SERVICES\dfmirage\DEVICE0 |
| Operation: | write | Name: | Attach.ToDesktop |
Value: 0 | |||
| (PID) Process: | (2964) Windows_xp_1.0.8.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{509DC88F-BC75-4AED-B511-9892EAD1AE48}}_is1 |
| Operation: | write | Name: | Inno Setup: Setup Version |
Value: 5.5.9 (a) | |||
| (PID) Process: | (2964) Windows_xp_1.0.8.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{509DC88F-BC75-4AED-B511-9892EAD1AE48}}_is1 |
| Operation: | write | Name: | Inno Setup: App Path |
Value: C:\Program Files\USB Display | |||
| (PID) Process: | (2964) Windows_xp_1.0.8.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{509DC88F-BC75-4AED-B511-9892EAD1AE48}}_is1 |
| Operation: | write | Name: | InstallLocation |
Value: C:\Program Files\USB Display\ | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2964 | Windows_xp_1.0.8.tmp | C:\Program Files\USB Display\unins000.exe | executable | |
MD5:9733369807F170DE2AA6962593C349CC | SHA256:EA915669D2317147FFCFED211F228A674294941BA1A9C53FCD3B24D9E0876E2C | |||
| 2964 | Windows_xp_1.0.8.tmp | C:\Program Files\USB Display\is-BOK54.tmp | executable | |
MD5:9733369807F170DE2AA6962593C349CC | SHA256:EA915669D2317147FFCFED211F228A674294941BA1A9C53FCD3B24D9E0876E2C | |||
| 2964 | Windows_xp_1.0.8.tmp | C:\Program Files\USB Display\msvcr100d.dll | executable | |
MD5:D57E2EDA325BAC8081FD054209D736AE | SHA256:5E47C4CF08450EA73D10E705FDCE727ACE66F8BCF4984028B1B17C91B8F630A6 | |||
| 2964 | Windows_xp_1.0.8.tmp | C:\Program Files\USB Display\config.ini | text | |
MD5:ACC6C4AFBACC6F88EF7C079D69B07B0D | SHA256:56FD302584C99D597CD81DB3E874EE310C8FBDCBCE0EE0ACA484B169906C696A | |||
| 2964 | Windows_xp_1.0.8.tmp | C:\Program Files\USB Display\is-BO9J1.tmp | text | |
MD5:ACC6C4AFBACC6F88EF7C079D69B07B0D | SHA256:56FD302584C99D597CD81DB3E874EE310C8FBDCBCE0EE0ACA484B169906C696A | |||
| 3672 | Windows_xp_1.0.8.exe | C:\Users\admin\AppData\Local\Temp\is-5L3KJ.tmp\Windows_xp_1.0.8.tmp | executable | |
MD5:1FDD4368D6B3B32E254143AE65D1FE37 | SHA256:9E366C237E2F6CB880943EAE92BD99BA3190C2976A9FDEC65E875E9EE38D4CF5 | |||
| 2964 | Windows_xp_1.0.8.tmp | C:\Program Files\USB Display\is-DH6H5.tmp | executable | |
MD5:29675ABD5B529FFE9291215A3C3960A9 | SHA256:81C54C760773AE879ABDEA27DDB2876D4820CC3189D9C39BDEB47C0869716472 | |||
| 2964 | Windows_xp_1.0.8.tmp | C:\Program Files\USB Display\WinUsbDisplay.exe | executable | |
MD5:29675ABD5B529FFE9291215A3C3960A9 | SHA256:81C54C760773AE879ABDEA27DDB2876D4820CC3189D9C39BDEB47C0869716472 | |||
| 2964 | Windows_xp_1.0.8.tmp | C:\Program Files\USB Display\is-6KS6R.tmp | executable | |
MD5:D57E2EDA325BAC8081FD054209D736AE | SHA256:5E47C4CF08450EA73D10E705FDCE727ACE66F8BCF4984028B1B17C91B8F630A6 | |||
| 2964 | Windows_xp_1.0.8.tmp | C:\Program Files\USB Display\is-2OJL5.tmp | image | |
MD5:2098EF97358FBBDFAE0206BBCB4E2234 | SHA256:DE96747834EF6ED07618AA7EB89F643444F3BA01140EED263468C08A0B7BF8FE | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |