| File name: | MSDisplay_MultiDev_v1.0.0.18.0.exe |
| Full analysis: | https://app.any.run/tasks/470b0423-c1b1-434f-90dd-7ec695e3c039 |
| Verdict: | Malicious activity |
| Analysis date: | January 29, 2024, 13:01:25 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | F505CBCAB0670A376C866DE177A5C097 |
| SHA1: | 18DED789BC554FDA5941AA2707DF9A78DE44C7C5 |
| SHA256: | 7BE04791DF7CC79FC8427098BF9E3C11206E54D2D613D470E4B4D5855451E816 |
| SSDEEP: | 49152:jNJb0uRDKiHjoapN8J827nsjoRf8HIjkpr6PbdVKeO3dFIyKc+Kq:joKDfD4827MoRf8HnUdyd+yKn |
| .exe | | | Inno Setup installer (53.5) |
|---|---|---|
| .exe | | | InstallShield setup (21) |
| .exe | | | Win32 EXE PECompact compressed (generic) (20.2) |
| .exe | | | Win32 Executable (generic) (2.1) |
| .exe | | | Win16/32 Executable Delphi generic (1) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2019:04:30 05:47:23+02:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi |
| PEType: | PE32 |
| LinkerVersion: | 2.25 |
| CodeSize: | 679936 |
| InitializedDataSize: | 125952 |
| UninitializedDataSize: | - |
| EntryPoint: | 0xa6ed0 |
| OSVersion: | 6 |
| ImageVersion: | 6 |
| SubsystemVersion: | 6 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.0.0.18 |
| ProductVersionNumber: | 1.0.0.18 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Chinese (Simplified) |
| CharacterSet: | ASCII |
| Comments: | ´Ë°²×°³ÌÐòÓÉ Inno Setup ¹¹½¨¡£ |
| CompanyName: | MS |
| FileDescription: | MS USB Display Setup |
| FileVersion: | 1.0.0.18.0 |
| LegalCopyright: | Copyright © MS 2020 |
| OriginalFileName: | |
| ProductName: | MS USB Display |
| ProductVersion: | 1.0.0.18.0 |
PID | CMD | Path | Indicators | Parent process |
|---|---|---|---|---|
| 668 | "C:\Users\admin\Desktop\MSDisplay_MultiDev_v1.0.0.18.0.exe" /SPAWNWND=$1201B4 /NOTIFYWND=$F0184 | C:\Users\admin\Desktop\MSDisplay_MultiDev_v1.0.0.18.0.exe | MSDisplay_MultiDev_v1.0.0.18.0.tmp | |
User: admin Company: MS Integrity Level: HIGH Description: MS USB Display Setup Exit code: 0 Version: 1.0.0.18.0 | ||||
| 796 | "C:\Program Files\MS USB Display\tool\x86\devcon.exe" restart =display | C:\Program Files\MS USB Display\tool\x86\devcon.exe | — | MSDisplay_MultiDev_v1.0.0.18.0.tmp |
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Setup API Exit code: 1 Version: 10.0.10586.0 (th2_release.151029-1700) | ||||
| 1392 | "C:\Users\admin\Desktop\MSDisplay_MultiDev_v1.0.0.18.0.exe" | C:\Users\admin\Desktop\MSDisplay_MultiDev_v1.0.0.18.0.exe | explorer.exe | |
User: admin Company: MS Integrity Level: MEDIUM Description: MS USB Display Setup Exit code: 0 Version: 1.0.0.18.0 | ||||
| 1588 | "C:\Users\admin\AppData\Local\Temp\is-S801M.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp" /SL5="$F0184,2556185,806912,C:\Users\admin\Desktop\MSDisplay_MultiDev_v1.0.0.18.0.exe" | C:\Users\admin\AppData\Local\Temp\is-S801M.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp | — | MSDisplay_MultiDev_v1.0.0.18.0.exe |
User: admin Integrity Level: MEDIUM Description: Setup Exit code: 0 Version: 1.0.0.0 | ||||
| 1776 | DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{2bc5c351-7deb-0010-6194-695cd83ed236}\dfmirage.inf" "0" "670102fe7" "000005D8" "WinSta0\Default" "000005EC" "208" "c:\program files\ms usb display\video_driver" | C:\Windows\System32\drvinst.exe | svchost.exe | |
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Driver Installation Module Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
| 2184 | "C:\Program Files\MS USB Display\WinUsbDisplay.exe" firstinstall | C:\Program Files\MS USB Display\WinUsbDisplay.exe | — | MSDisplay_MultiDev_v1.0.0.18.0.tmp |
User: admin Company: MS Integrity Level: HIGH Description: Windows USB Display Exit code: 0 Version: 1.0.0.7 | ||||
| 2380 | "C:\Users\admin\AppData\Local\Temp\is-JDM77.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp" /SL5="$F0182,2556185,806912,C:\Users\admin\Desktop\MSDisplay_MultiDev_v1.0.0.18.0.exe" /SPAWNWND=$1201B4 /NOTIFYWND=$F0184 | C:\Users\admin\AppData\Local\Temp\is-JDM77.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp | MSDisplay_MultiDev_v1.0.0.18.0.exe | |
User: admin Integrity Level: HIGH Description: Setup Exit code: 0 Version: 1.0.0.0 | ||||
| 2768 | DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{74b29ab0-2a32-6f53-a278-62683355ea17}\MSUSBDisplay.inf" "0" "610771dbb" "00000550" "WinSta0\Default" "000004BC" "208" "C:\Program Files\MS USB Display\lib_usb" | C:\Windows\System32\drvinst.exe | svchost.exe | |
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Driver Installation Module Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
| 2892 | DrvInst.exe "2" "211" "ROOT\DISPLAY\0000" "C:\Windows\INF\oem5.inf" "dfmirage.inf:DFMirage.Mfg.NTx86:DFMirage:2.0.105.0:dfmirage" "670102fe7" "000005D8" "000005F8" "000005E0" | C:\Windows\System32\drvinst.exe | svchost.exe | |
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Driver Installation Module Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
| 2916 | rundll32.exe C:\Windows\system32\pnpui.dll,InstallSecurityPromptRunDllW 10 Global\{46820d8c-be81-50d7-a69a-d45031ce6a7e} Global\{339d4e82-e2da-5406-8db5-ab7b173b6f16} C:\Windows\System32\DriverStore\Temp\{55dee6a1-05e3-0921-1466-525b35add502}\displayproxykmd.inf C:\Windows\System32\DriverStore\Temp\{55dee6a1-05e3-0921-1466-525b35add502}\DisplayProxy.cat | C:\Windows\System32\rundll32.exe | — | drvinst.exe |
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows host process (Rundll32) Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2380 | MSDisplay_MultiDev_v1.0.0.18.0.tmp | C:\Program Files\MS USB Display\is-6R22L.tmp | executable | |
MD5:7EC9CFAB450831249D70152183B3E844 | SHA256:664938FC6169E37700C45C0242006EDE97219AA0B873CC26C8DAF19647DBAA77 | |||
| 1392 | MSDisplay_MultiDev_v1.0.0.18.0.exe | C:\Users\admin\AppData\Local\Temp\is-S801M.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp | executable | |
MD5:7EC9CFAB450831249D70152183B3E844 | SHA256:664938FC6169E37700C45C0242006EDE97219AA0B873CC26C8DAF19647DBAA77 | |||
| 2380 | MSDisplay_MultiDev_v1.0.0.18.0.tmp | C:\Program Files\MS USB Display\WinUsbDisplay.exe | executable | |
MD5:4AAB73E5792E49227E5843C0207E7BFD | SHA256:85AF24188A2040F61F008C50620835B9DDCEA0F4C1707447EC11002D55ED134E | |||
| 2380 | MSDisplay_MultiDev_v1.0.0.18.0.tmp | C:\Program Files\MS USB Display\config.ini | text | |
MD5:AB5BD4D46AA4F19ED52961F81635AD76 | SHA256:A1C6CEDAB9EC5850C98D5FED2CB0A2253FBBCCA7B8C5974F57F34FBDE4DC3C3F | |||
| 668 | MSDisplay_MultiDev_v1.0.0.18.0.exe | C:\Users\admin\AppData\Local\Temp\is-JDM77.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp | executable | |
MD5:7EC9CFAB450831249D70152183B3E844 | SHA256:664938FC6169E37700C45C0242006EDE97219AA0B873CC26C8DAF19647DBAA77 | |||
| 2380 | MSDisplay_MultiDev_v1.0.0.18.0.tmp | C:\Program Files\MS USB Display\libVMonitor.dll | executable | |
MD5:10BB929E9FD8B028738B46F4D3EA741E | SHA256:8817EAF691058E091E3A240547B74C3E396DAFF1312F66971274C1D30C55BDE1 | |||
| 2380 | MSDisplay_MultiDev_v1.0.0.18.0.tmp | C:\Program Files\MS USB Display\libusb0.dll | executable | |
MD5:A969E398CC9319DD9BD9EEDCAE288DA7 | SHA256:3165D5E9212E9C4F009A594F67BD9E6D899B026CE1E3B0D6EBB994F423D6B1D1 | |||
| 2380 | MSDisplay_MultiDev_v1.0.0.18.0.tmp | C:\Program Files\MS USB Display\is-C6RFS.tmp | executable | |
MD5:A969E398CC9319DD9BD9EEDCAE288DA7 | SHA256:3165D5E9212E9C4F009A594F67BD9E6D899B026CE1E3B0D6EBB994F423D6B1D1 | |||
| 2380 | MSDisplay_MultiDev_v1.0.0.18.0.tmp | C:\Program Files\MS USB Display\is-5R67J.tmp | text | |
MD5:AB5BD4D46AA4F19ED52961F81635AD76 | SHA256:A1C6CEDAB9EC5850C98D5FED2CB0A2253FBBCCA7B8C5974F57F34FBDE4DC3C3F | |||
| 2380 | MSDisplay_MultiDev_v1.0.0.18.0.tmp | C:\Program Files\MS USB Display\is-NRDRA.tmp | executable | |
MD5:1954CD248E65C7C5C2D3D93DD7F91604 | SHA256:761EC2283460F3E641F9C815A015698B3EB77090808768A4BF3C17439CCD0018 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |