File name:

csaudiointcsof.1.0.4-installer.exe

Full analysis: https://app.any.run/tasks/4d5f9f5f-4ae4-4f84-84fc-155d719c10b3
Verdict: Malicious activity
Analysis date: May 29, 2025, 21:52:16
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive, 5 sections
MD5:

379D8A3FA074A375A7E0D4D2D38AB853

SHA1:

7058AC9045ABD2D27A58DCAF49E771CFD218ACEE

SHA256:

70C440F0EF3712D1D00ABCAE7815F2281676A7DD80DAD3A3AD6F82044CE5326D

SSDEEP:

98304:yyFUS/0g8tY2yFneiayvTBiq8m6fAsSccr1fOerbR8axpwlCvBvwxjuA9c630hxz:l1Z

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Starts NET.EXE for service management

      • csaudiointcsof.1.0.4-installer.exe (PID: 4784)
      • net.exe (PID: 5400)
      • net.exe (PID: 5544)
  • SUSPICIOUS

    • The process creates files with name similar to system file names

      • csaudiointcsof.1.0.4-installer.exe (PID: 4784)
    • Drops a system driver (possible attempt to evade defenses)

      • csaudiointcsof.1.0.4-installer.exe (PID: 4784)
      • dpinst.exe (PID: 4408)
      • drvinst.exe (PID: 3888)
      • dpinst.exe (PID: 2236)
      • dpinst.exe (PID: 3888)
      • drvinst.exe (PID: 4892)
      • drvinst.exe (PID: 7084)
      • dpinst.exe (PID: 2432)
      • drvinst.exe (PID: 5124)
      • dpinst.exe (PID: 840)
      • drvinst.exe (PID: 1228)
      • dpinst.exe (PID: 5640)
      • drvinst.exe (PID: 2096)
      • dpinst.exe (PID: 5548)
      • drvinst.exe (PID: 7144)
      • dpinst.exe (PID: 6132)
      • dpinst.exe (PID: 1812)
      • drvinst.exe (PID: 6728)
      • drvinst.exe (PID: 2152)
      • dpinst.exe (PID: 6540)
      • drvinst.exe (PID: 6388)
      • dpinst.exe (PID: 2516)
      • dpinst.exe (PID: 2240)
      • drvinst.exe (PID: 5384)
      • drvinst.exe (PID: 6080)
    • Process drops legitimate windows executable

      • csaudiointcsof.1.0.4-installer.exe (PID: 4784)
      • dpinst.exe (PID: 4408)
    • Executable content was dropped or overwritten

      • csaudiointcsof.1.0.4-installer.exe (PID: 4784)
      • dpinst.exe (PID: 4408)
      • drvinst.exe (PID: 3888)
      • dpinst.exe (PID: 2236)
      • drvinst.exe (PID: 7084)
      • dpinst.exe (PID: 3888)
      • dpinst.exe (PID: 2432)
      • drvinst.exe (PID: 5124)
      • drvinst.exe (PID: 4892)
      • dpinst.exe (PID: 840)
      • drvinst.exe (PID: 1228)
      • dpinst.exe (PID: 5640)
      • drvinst.exe (PID: 2096)
      • dpinst.exe (PID: 5548)
      • drvinst.exe (PID: 7144)
      • drvinst.exe (PID: 6728)
      • dpinst.exe (PID: 6132)
      • dpinst.exe (PID: 1812)
      • drvinst.exe (PID: 2152)
      • dpinst.exe (PID: 6540)
      • dpinst.exe (PID: 2516)
      • drvinst.exe (PID: 6388)
      • dpinst.exe (PID: 2240)
      • drvinst.exe (PID: 5384)
      • drvinst.exe (PID: 6080)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • csaudiointcsof.1.0.4-installer.exe (PID: 4784)
    • Creates files in the driver directory

      • drvinst.exe (PID: 3888)
      • drvinst.exe (PID: 4892)
      • drvinst.exe (PID: 7084)
      • drvinst.exe (PID: 5124)
      • drvinst.exe (PID: 1228)
      • drvinst.exe (PID: 2096)
      • drvinst.exe (PID: 7144)
      • drvinst.exe (PID: 6728)
      • drvinst.exe (PID: 2152)
      • drvinst.exe (PID: 6388)
      • drvinst.exe (PID: 5384)
      • drvinst.exe (PID: 6080)
    • Creates a software uninstall entry

      • dpinst.exe (PID: 4408)
      • dpinst.exe (PID: 2236)
      • dpinst.exe (PID: 3888)
      • dpinst.exe (PID: 2432)
      • dpinst.exe (PID: 840)
      • dpinst.exe (PID: 5640)
      • dpinst.exe (PID: 5548)
      • dpinst.exe (PID: 1812)
      • dpinst.exe (PID: 6132)
      • dpinst.exe (PID: 6540)
      • dpinst.exe (PID: 2516)
      • dpinst.exe (PID: 2240)
      • csaudiointcsof.1.0.4-installer.exe (PID: 4784)
    • There is functionality for taking screenshot (YARA)

      • csaudiointcsof.1.0.4-installer.exe (PID: 4784)
    • Creates a new Windows service

      • sc.exe (PID: 6148)
    • Windows service management via SC.EXE

      • sc.exe (PID: 1184)
    • Executes as Windows Service

      • csaudioendpointswitcher.exe (PID: 1072)
  • INFO

    • Checks supported languages

      • csaudiointcsof.1.0.4-installer.exe (PID: 4784)
      • dpinst.exe (PID: 4408)
      • drvinst.exe (PID: 3888)
      • dpinst.exe (PID: 2236)
      • dpinst.exe (PID: 3888)
      • drvinst.exe (PID: 7084)
      • drvinst.exe (PID: 4892)
      • dpinst.exe (PID: 2432)
      • drvinst.exe (PID: 5124)
      • dpinst.exe (PID: 840)
      • drvinst.exe (PID: 1228)
      • dpinst.exe (PID: 5640)
      • drvinst.exe (PID: 2096)
      • dpinst.exe (PID: 5548)
      • drvinst.exe (PID: 7144)
      • dpinst.exe (PID: 1812)
      • dpinst.exe (PID: 6132)
      • drvinst.exe (PID: 6728)
      • drvinst.exe (PID: 2152)
      • dpinst.exe (PID: 6540)
      • drvinst.exe (PID: 6388)
      • dpinst.exe (PID: 2516)
      • drvinst.exe (PID: 6080)
      • drvinst.exe (PID: 5384)
      • dpinst.exe (PID: 2240)
      • csaudioendpointswitcher.exe (PID: 1072)
    • Reads the computer name

      • csaudiointcsof.1.0.4-installer.exe (PID: 4784)
      • dpinst.exe (PID: 4408)
      • drvinst.exe (PID: 3888)
      • dpinst.exe (PID: 2236)
      • drvinst.exe (PID: 7084)
      • dpinst.exe (PID: 3888)
      • drvinst.exe (PID: 4892)
      • dpinst.exe (PID: 2432)
      • drvinst.exe (PID: 5124)
      • dpinst.exe (PID: 840)
      • drvinst.exe (PID: 1228)
      • dpinst.exe (PID: 5640)
      • drvinst.exe (PID: 2096)
      • dpinst.exe (PID: 5548)
      • dpinst.exe (PID: 1812)
      • drvinst.exe (PID: 7144)
      • drvinst.exe (PID: 6728)
      • dpinst.exe (PID: 6132)
      • drvinst.exe (PID: 2152)
      • dpinst.exe (PID: 6540)
      • drvinst.exe (PID: 6388)
      • dpinst.exe (PID: 2516)
      • drvinst.exe (PID: 5384)
      • dpinst.exe (PID: 2240)
      • drvinst.exe (PID: 6080)
      • csaudioendpointswitcher.exe (PID: 1072)
    • Create files in a temporary directory

      • csaudiointcsof.1.0.4-installer.exe (PID: 4784)
      • dpinst.exe (PID: 4408)
      • dpinst.exe (PID: 2236)
      • dpinst.exe (PID: 3888)
      • dpinst.exe (PID: 2432)
      • dpinst.exe (PID: 840)
      • dpinst.exe (PID: 5640)
      • dpinst.exe (PID: 5548)
      • dpinst.exe (PID: 6132)
      • dpinst.exe (PID: 1812)
      • dpinst.exe (PID: 6540)
      • dpinst.exe (PID: 2516)
      • dpinst.exe (PID: 2240)
    • Creates files in the program directory

      • csaudiointcsof.1.0.4-installer.exe (PID: 4784)
      • dpinst.exe (PID: 4408)
    • The sample compiled with arabic language support

      • csaudiointcsof.1.0.4-installer.exe (PID: 4784)
      • dpinst.exe (PID: 4408)
    • The sample compiled with english language support

      • csaudiointcsof.1.0.4-installer.exe (PID: 4784)
      • dpinst.exe (PID: 4408)
      • drvinst.exe (PID: 3888)
      • dpinst.exe (PID: 2236)
      • drvinst.exe (PID: 7084)
      • dpinst.exe (PID: 3888)
      • drvinst.exe (PID: 4892)
      • dpinst.exe (PID: 2432)
      • drvinst.exe (PID: 5124)
      • dpinst.exe (PID: 840)
      • drvinst.exe (PID: 1228)
      • dpinst.exe (PID: 5640)
      • drvinst.exe (PID: 2096)
      • dpinst.exe (PID: 5548)
      • drvinst.exe (PID: 7144)
      • dpinst.exe (PID: 1812)
      • drvinst.exe (PID: 6728)
      • drvinst.exe (PID: 2152)
      • dpinst.exe (PID: 6132)
      • drvinst.exe (PID: 6388)
      • dpinst.exe (PID: 2516)
      • dpinst.exe (PID: 6540)
      • drvinst.exe (PID: 5384)
      • drvinst.exe (PID: 6080)
      • dpinst.exe (PID: 2240)
    • Reads the software policy settings

      • drvinst.exe (PID: 3888)
      • dpinst.exe (PID: 4408)
      • drvinst.exe (PID: 7084)
      • dpinst.exe (PID: 2236)
      • drvinst.exe (PID: 4892)
      • dpinst.exe (PID: 3888)
      • drvinst.exe (PID: 5124)
      • dpinst.exe (PID: 2432)
      • drvinst.exe (PID: 1228)
      • dpinst.exe (PID: 840)
      • drvinst.exe (PID: 2096)
      • dpinst.exe (PID: 5640)
      • drvinst.exe (PID: 7144)
      • dpinst.exe (PID: 5548)
      • dpinst.exe (PID: 1812)
      • drvinst.exe (PID: 6728)
      • dpinst.exe (PID: 6132)
      • drvinst.exe (PID: 2152)
      • drvinst.exe (PID: 6388)
      • dpinst.exe (PID: 6540)
      • drvinst.exe (PID: 5384)
      • dpinst.exe (PID: 2516)
      • drvinst.exe (PID: 6080)
      • dpinst.exe (PID: 2240)
    • Reads the machine GUID from the registry

      • dpinst.exe (PID: 4408)
      • drvinst.exe (PID: 3888)
      • dpinst.exe (PID: 2236)
      • drvinst.exe (PID: 7084)
      • drvinst.exe (PID: 4892)
      • dpinst.exe (PID: 3888)
      • drvinst.exe (PID: 1228)
      • drvinst.exe (PID: 5124)
      • dpinst.exe (PID: 2432)
      • dpinst.exe (PID: 840)
      • drvinst.exe (PID: 2096)
      • dpinst.exe (PID: 5640)
      • drvinst.exe (PID: 7144)
      • dpinst.exe (PID: 5548)
      • dpinst.exe (PID: 1812)
      • drvinst.exe (PID: 6728)
      • dpinst.exe (PID: 6132)
      • drvinst.exe (PID: 2152)
      • drvinst.exe (PID: 6388)
      • dpinst.exe (PID: 6540)
      • dpinst.exe (PID: 2516)
      • drvinst.exe (PID: 5384)
      • drvinst.exe (PID: 6080)
      • dpinst.exe (PID: 2240)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2021:09:25 21:57:46+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 27136
InitializedDataSize: 186880
UninitializedDataSize: 2048
EntryPoint: 0x352d
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
171
Monitored processes
39
Malicious processes
14
Suspicious processes
11

Behavior graph

Click at the process to see the details
start csaudiointcsof.1.0.4-installer.exe sppextcomobj.exe no specs slui.exe no specs dpinst.exe drvinst.exe dpinst.exe drvinst.exe dpinst.exe drvinst.exe dpinst.exe drvinst.exe dpinst.exe drvinst.exe dpinst.exe drvinst.exe dpinst.exe drvinst.exe dpinst.exe drvinst.exe dpinst.exe drvinst.exe dpinst.exe drvinst.exe dpinst.exe drvinst.exe dpinst.exe drvinst.exe net.exe no specs conhost.exe no specs net1.exe no specs sc.exe no specs conhost.exe no specs sc.exe no specs conhost.exe no specs net.exe no specs conhost.exe no specs net1.exe no specs csaudioendpointswitcher.exe no specs csaudiointcsof.1.0.4-installer.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
840"C:\Program Files\csaudiointcsof\drivers\dpinst.exe" /sw /f /path "C:\Program Files\csaudiointcsof\drivers\cs42l42"C:\Program Files\csaudiointcsof\drivers\dpinst.exe
csaudiointcsof.1.0.4-installer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Driver Package Installer
Exit code:
256
Version:
2.1
Modules
Images
c:\program files\csaudiointcsof\drivers\dpinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
1072"C:\Program Files\csaudiointcsof\utils\csaudioendpointswitcher.exe"C:\Program Files\csaudiointcsof\utils\csaudioendpointswitcher.exeservices.exe
User:
SYSTEM
Integrity Level:
SYSTEM
Modules
Images
c:\program files\csaudiointcsof\utils\csaudioendpointswitcher.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
1184sc delete csaudioswitcherC:\Windows\SysWOW64\sc.execsaudiointcsof.1.0.4-installer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Service Control Manager Configuration Tool
Exit code:
1060
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\sc.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
1228DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{f0064764-80a4-2a47-ba95-5b430ebe66c3}\cs42l42.inf" "9" "477887aa7" "0000000000000224" "WinSta0\Default" "0000000000000220" "208" "c:\program files\csaudiointcsof\drivers\cs42l42"C:\Windows\System32\drvinst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\drvstore.dll
1812"C:\Program Files\csaudiointcsof\drivers\dpinst.exe" /sw /f /path "C:\Program Files\csaudiointcsof\drivers\max98357a"C:\Program Files\csaudiointcsof\drivers\dpinst.exe
csaudiointcsof.1.0.4-installer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Driver Package Installer
Exit code:
256
Version:
2.1
Modules
Images
c:\program files\csaudiointcsof\drivers\dpinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
2040C:\WINDOWS\system32\net1 STOP "csaudioswitcher"C:\Windows\SysWOW64\net1.exenet.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Net Command
Exit code:
2
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\net1.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\sechost.dll
2096DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{3818d38a-e417-b54a-82c1-75f78b507adf}\rt5682s.inf" "9" "4f2615b03" "0000000000000230" "WinSta0\Default" "000000000000022C" "208" "c:\program files\csaudiointcsof\drivers\rt5682s"C:\Windows\System32\drvinst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\drvstore.dll
2152DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{b0bb3c55-4454-6746-bf69-b3b756253287}\max98390.inf" "9" "481d0f32f" "0000000000000254" "WinSta0\Default" "0000000000000250" "208" "c:\program files\csaudiointcsof\drivers\max98390"C:\Windows\System32\drvinst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\drvstore.dll
2236"C:\Program Files\csaudiointcsof\drivers\dpinst.exe" /sw /f /path "C:\Program Files\csaudiointcsof\drivers\csaudiointcsof"C:\Program Files\csaudiointcsof\drivers\dpinst.exe
csaudiointcsof.1.0.4-installer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Driver Package Installer
Exit code:
256
Version:
2.1
Modules
Images
c:\program files\csaudiointcsof\drivers\dpinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
2240"C:\Program Files\csaudiointcsof\drivers\dpinst.exe" /sw /f /path "C:\Program Files\csaudiointcsof\drivers\rt1015"C:\Program Files\csaudiointcsof\drivers\dpinst.exe
csaudiointcsof.1.0.4-installer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Driver Package Installer
Exit code:
256
Version:
2.1
Modules
Images
c:\program files\csaudiointcsof\drivers\dpinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
Total events
73 080
Read events
73 016
Write events
64
Delete events
0

Modification events

(PID) Process:(4408) dpinst.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\Setup\SetupapiLogStatus
Operation:writeName:setupapi.dev.log
Value:
4096
(PID) Process:(4408) dpinst.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\7D206C0A1B8EFBE6B87EC55B22F4279BB2E0195F
Operation:writeName:UninstallString
Value:
C:\PROGRA~1\DIFX\D29FE547208FE130\dpinst.exe /u C:\WINDOWS\System32\DriverStore\FileRepository\sklhdaudbus.inf_amd64_0dd9bdb3393d93e5\sklhdaudbus.inf
(PID) Process:(4408) dpinst.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\7D206C0A1B8EFBE6B87EC55B22F4279BB2E0195F
Operation:writeName:DisplayName
Value:
Windows Driver Package - CoolStar (SklHDAudBus) System (05/05/2024 1.0.5.0)
(PID) Process:(4408) dpinst.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\7D206C0A1B8EFBE6B87EC55B22F4279BB2E0195F
Operation:writeName:DisplayIcon
Value:
C:\PROGRA~1\DIFX\D29FE547208FE130\dpinst.exe,0
(PID) Process:(4408) dpinst.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\7D206C0A1B8EFBE6B87EC55B22F4279BB2E0195F
Operation:writeName:DisplayVersion
Value:
05/05/2024 1.0.5.0
(PID) Process:(4408) dpinst.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\7D206C0A1B8EFBE6B87EC55B22F4279BB2E0195F
Operation:writeName:Publisher
Value:
CoolStar
(PID) Process:(2236) dpinst.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\0DA4E1F95713D51E4CF4523FDDE4A573308F4938
Operation:writeName:UninstallString
Value:
C:\PROGRA~1\DIFX\D29FE547208FE130\dpinst.exe /u C:\WINDOWS\System32\DriverStore\FileRepository\csaudiointcsof.inf_amd64_79c94fce15657a09\csaudiointcsof.inf
(PID) Process:(2236) dpinst.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\0DA4E1F95713D51E4CF4523FDDE4A573308F4938
Operation:writeName:DisplayName
Value:
Windows Driver Package - CoolStar (CsAudioIntcSOF) MEDIA (04/23/2024 1.0.4.0)
(PID) Process:(2236) dpinst.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\0DA4E1F95713D51E4CF4523FDDE4A573308F4938
Operation:writeName:DisplayIcon
Value:
C:\PROGRA~1\DIFX\D29FE547208FE130\dpinst.exe,0
(PID) Process:(2236) dpinst.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\0DA4E1F95713D51E4CF4523FDDE4A573308F4938
Operation:writeName:DisplayVersion
Value:
04/23/2024 1.0.4.0
Executable files
72
Suspicious files
211
Text files
3
Unknown types
0

Dropped files

PID
Process
Filename
Type
4784csaudiointcsof.1.0.4-installer.exeC:\Program Files\csaudiointcsof\drivers\dpinst.exeexecutable
MD5:4192A5B905374E423EC1E545599AA86E
SHA256:567F40A09F1D9E72396296AD194FA7CF48B72361D6E259D6B99DA774C2CD8981
4784csaudiointcsof.1.0.4-installer.exeC:\Program Files\csaudiointcsof\drivers\cs42l42\cs42l42.catbinary
MD5:0BFAF62B95BEEC809DF72227BB91AC27
SHA256:1812033B3C8862D4875AAC0A8B452B6B0A2A3441C71FC2A42640DDB530A54457
4784csaudiointcsof.1.0.4-installer.exeC:\Program Files\csaudiointcsof\drivers\csaudiointcsof\csaudiointcsof.catbinary
MD5:C2799A0735F1511F63A17E3FC8561464
SHA256:7F7C758A72D1703322FB717F7132279237B377DBB72D4F91536D21DD6D0060B9
4784csaudiointcsof.1.0.4-installer.exeC:\Users\admin\AppData\Local\Temp\nsbB9AE.tmp\System.dllexecutable
MD5:CFF85C549D536F651D4FB8387F1976F2
SHA256:8DC562CDA7217A3A52DB898243DE3E2ED68B80E62DDCB8619545ED0B4E7F65A8
4784csaudiointcsof.1.0.4-installer.exeC:\Program Files\csaudiointcsof\drivers\cs42l42\cs42l42.infbinary
MD5:B51F0AC464E7EC6296A6F7CB19A88642
SHA256:F4320F6F8EEE510B9EE5D11B3942822DBE856696C35EF3BC8C9071EC0BD7EA92
4784csaudiointcsof.1.0.4-installer.exeC:\Program Files\csaudiointcsof\drivers\da7219\da7219.infbinary
MD5:327DF7CA827AF0999DF617E661B4F7F4
SHA256:6BD342CD4A48FA11AA8F6F5F5576A8DFE32092B5E32270934478ECDD3277B1DC
4784csaudiointcsof.1.0.4-installer.exeC:\Program Files\csaudiointcsof\drivers\da7219\da7219.catbinary
MD5:4646D149CEB88AA2FD89688F9C4DB5AE
SHA256:3EFFF5E188D754D0C103BEED9DBAAE0E14BBE8F10B530442D10F6F40FA772192
4784csaudiointcsof.1.0.4-installer.exeC:\Program Files\csaudiointcsof\drivers\da7219\da7219.sysexecutable
MD5:B0CBD0885D632F90F969158BA26C832B
SHA256:F03223B0281BB1941F8BD54C7ED9356F1FFEAC96C6C59B579B8865247855E95B
4784csaudiointcsof.1.0.4-installer.exeC:\Program Files\csaudiointcsof\drivers\max98357a\max98357a.catbinary
MD5:302DDA7D9AED955C40187917053C5473
SHA256:B995BDD518EBCFB525247087BD9B758DB87DBCD20784F208819D9481B32E4FE7
4784csaudiointcsof.1.0.4-installer.exeC:\Program Files\csaudiointcsof\drivers\max98357a\max98357a.infbinary
MD5:A86C8A5266DBF5A991EBEDE2AEF73080
SHA256:8BC1E5997AE0A66F3EEF098ECADB6D70A1077CA88BF3E4658010CF39B0C2FFC5
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
18
DNS requests
13
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
2.16.168.124:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
RU
binary
825 b
whitelisted
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
QA
binary
868 b
whitelisted
6544
svchost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
DE
binary
471 b
whitelisted
5964
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
DE
binary
407 b
whitelisted
5964
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
DE
binary
419 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
192.168.100.255:137
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2.16.168.124:80
crl.microsoft.com
Akamai International B.V.
RU
whitelisted
2.23.246.101:80
www.microsoft.com
Ooredoo Q.S.C.
QA
whitelisted
4
System
192.168.100.255:138
whitelisted
3216
svchost.exe
172.211.123.248:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
6544
svchost.exe
20.190.159.4:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6544
svchost.exe
2.23.77.188:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
2104
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5964
SIHClient.exe
20.109.210.53:443
slscr.update.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 51.104.136.2
whitelisted
crl.microsoft.com
  • 2.16.168.124
  • 2.16.168.114
whitelisted
www.microsoft.com
  • 2.23.246.101
  • 23.35.229.160
whitelisted
google.com
  • 142.250.186.142
whitelisted
client.wns.windows.com
  • 172.211.123.248
whitelisted
login.live.com
  • 20.190.159.4
  • 20.190.159.68
  • 20.190.159.75
  • 20.190.159.64
  • 20.190.159.73
  • 40.126.31.2
  • 40.126.31.69
  • 20.190.159.131
whitelisted
ocsp.digicert.com
  • 2.23.77.188
whitelisted
slscr.update.microsoft.com
  • 20.109.210.53
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 13.85.23.206
whitelisted

Threats

No threats detected
No debug info