| File name: | CDM v2.12.06 WHQL Certified.exe |
| Full analysis: | https://app.any.run/tasks/3336a2fb-6018-441c-9319-4ff4d884b408 |
| Verdict: | No threats detected |
| Analysis date: | February 05, 2020, 06:42:01 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed |
| MD5: | E0DBE354D8A6CDDE8C1D7E5366D90E43 |
| SHA1: | 8E052A3BF930737FA8E9EE1B6DE1406380474DEB |
| SHA256: | 7D69618B17C6F56C53B539225EB88F715A693E809B7DBB86F35B817FD988DC00 |
| SSDEEP: | 49152:8l1lBmGrRBlkFSeii0Mt9Ic96SXF4EiNNn9xtJB4E58RhyaDmZi:ol1vlPyiM4EiHnDt74E58yaDui |
| .exe | | | UPX compressed Win32 Executable (39.3) |
|---|---|---|
| .exe | | | Win32 EXE Yoda's Crypter (38.6) |
| .dll | | | Win32 Dynamic Link Library (generic) (9.5) |
| .exe | | | Win32 Executable (generic) (6.5) |
| .exe | | | Generic Win/DOS Executable (2.9) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2001:03:20 07:35:57+01:00 |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 24576 |
| InitializedDataSize: | 4096 |
| UninitializedDataSize: | 77824 |
| EntryPoint: | 0x19200 |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| Architecture: | IMAGE_FILE_MACHINE_I386 |
|---|---|
| Subsystem: | IMAGE_SUBSYSTEM_WINDOWS_GUI |
| Compilation Date: | 20-Mar-2001 06:35:57 |
| Detected languages: |
|
| Magic number: | MZ |
|---|---|
| Bytes on last page of file: | 0x0090 |
| Pages in file: | 0x0003 |
| Relocations: | 0x0000 |
| Size of header: | 0x0004 |
| Min extra paragraphs: | 0x0000 |
| Max extra paragraphs: | 0xFFFF |
| Initial SS value: | 0x0000 |
| Initial SP value: | 0x00B8 |
| Checksum: | 0x0000 |
| Initial IP value: | 0x0000 |
| Initial CS value: | 0x0000 |
| Overlay number: | 0x0000 |
| OEM identifier: | 0x0000 |
| OEM information: | 0x0000 |
| Address of NE header: | 0x000000E0 |
| Signature: | PE |
|---|---|
| Machine: | IMAGE_FILE_MACHINE_I386 |
| Number of sections: | 3 |
| Time date stamp: | 20-Mar-2001 06:35:57 |
| Pointer to Symbol Table: | 0x00000000 |
| Number of symbols: | 0 |
| Size of Optional Header: | 0x00E0 |
| Characteristics: |
|
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
|---|---|---|---|---|---|
UPX0 | 0x00001000 | 0x00013000 | 0x00000000 | IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0 |
UPX1 | 0x00014000 | 0x00006000 | 0x00005400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 7.8552 |
.rsrc | 0x0001A000 | 0x00001000 | 0x00000E00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.69797 |
Title | Entropy | Size | Codepage | Language | Type |
|---|---|---|---|---|---|
1 | 7.20474 | 308 | UNKNOWN | English - United States | RT_CURSOR |
2 | 5.41113 | 2216 | UNKNOWN | English - United States | RT_ICON |
101 | 1.9815 | 20 | UNKNOWN | English - United States | RT_GROUP_ICON |
102 | 7.40615 | 386 | UNKNOWN | English - United States | RT_DIALOG |
103 | 7.98259 | 26286 | UNKNOWN | English - United States | RT_BITMAP |
104 | 6.7639 | 160 | UNKNOWN | English - United States | RT_DIALOG |
105 | 7.5182 | 476 | UNKNOWN | English - United States | RT_DIALOG |
106 | 7.30898 | 298 | UNKNOWN | English - United States | RT_DIALOG |
113 | 4.8125 | 32 | UNKNOWN | English - United States | RT_MENU |
123 | 4.22193 | 20 | UNKNOWN | English - United States | RT_GROUP_CURSOR |
ADVAPI32.dll |
GDI32.dll |
KERNEL32.DLL |
SHELL32.dll |
USER32.dll |
ole32.dll |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 3264 | C:\Users\admin\AppData\Local\Temp\FTDI-Driver\dp-chooser.exe | C:\Users\admin\AppData\Local\Temp\FTDI-Driver\dp-chooser.exe | — | CDM v2.12.06 WHQL Certified.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 1 Modules
| |||||||||||||||
| 3456 | C:\Users\admin\AppData\Local\Temp\FTDI-Driver\dpinst-x86.exe /sa | C:\Users\admin\AppData\Local\Temp\FTDI-Driver\dpinst-x86.exe | — | dp-chooser.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Driver Package Installer Exit code: 3221226540 Version: 2.1 Modules
| |||||||||||||||
| 3772 | "C:\Users\admin\AppData\Local\Temp\CDM v2.12.06 WHQL Certified.exe" | C:\Users\admin\AppData\Local\Temp\CDM v2.12.06 WHQL Certified.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 1 Modules
| |||||||||||||||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3772 | CDM v2.12.06 WHQL Certified.exe | C:\Users\admin\AppData\Local\Temp\FE5F00.tmp | — | |
MD5:— | SHA256:— | |||
| 3772 | CDM v2.12.06 WHQL Certified.exe | C:\Users\admin\AppData\Local\Temp\FTDI-Driver\amd64\ftdibus.sys | executable | |
MD5:A826F9AEEB66F61E3BE813E5E03402A5 | SHA256:DDAAA5F92B8A66A37D9DD3C1AB27292B374663E92105E7D5DC65C0CC29046603 | |||
| 3772 | CDM v2.12.06 WHQL Certified.exe | C:\Users\admin\AppData\Local\Temp\FTDI-Driver\dpinst-amd64.exe | executable | |
MD5:051CFC801AEBF138613E2AAC61DD4321 | SHA256:D770482F49E8825F9339DDE01E98BA8085A901D1F56137015BFC159191F43BA3 | |||
| 3772 | CDM v2.12.06 WHQL Certified.exe | C:\Users\admin\AppData\Local\Temp\FTDI-Driver\dpinst.xml | xml | |
MD5:BBB46E3360F3FCABC5D03CA33DC10458 | SHA256:65E9BC1F59DE53462ED2E6B002C0BE26CD3F37B1E360938A0A32AA452ED58030 | |||
| 3772 | CDM v2.12.06 WHQL Certified.exe | C:\Users\admin\AppData\Local\Temp\FTDI-Driver\ftd2xx.h | text | |
MD5:6500AE976DC43F89D6763B399DA9BAD4 | SHA256:82AD828AB8AC283C6087010CC6EDB900EE95F02DEFF50BAB93AF03C4406655D4 | |||
| 3772 | CDM v2.12.06 WHQL Certified.exe | C:\Users\admin\AppData\Local\Temp\FTDI-Driver\ftdiport.inf | text | |
MD5:AA4BA218896E868957C204CC418C341E | SHA256:472DCB2B18A3B503EA36D1AE8562523D7B08601EB20AB80C11CBBAB47B54E7C2 | |||
| 3772 | CDM v2.12.06 WHQL Certified.exe | C:\Users\admin\AppData\Local\Temp\FTDI-Driver\ftdibus.inf | text | |
MD5:1C39D2E92A9C06A54F4755724894503B | SHA256:56AAC923A3FC816E21006ACEB48AA70824D35FF8615B0FEAF5D76B98E7B12153 | |||
| 3772 | CDM v2.12.06 WHQL Certified.exe | C:\Users\admin\AppData\Local\Temp\FTDI-Driver\ftdiport.cat | cat | |
MD5:777E80D6EF15C65027E20DE771BA3D89 | SHA256:233C0CAF59F3D0B2AB5E80A357CD946EC3138A19FFEFA9A5B5548C0FFCB0A964 | |||
| 3772 | CDM v2.12.06 WHQL Certified.exe | C:\Users\admin\AppData\Local\Temp\FTDI-Driver\amd64\ftbusui.dll | executable | |
MD5:6BA791D085A1505E4365BE6E1799C745 | SHA256:FA07AA18C0ECAF96AAC88556BA6BCB1D845CEA654B543AE7C18CA6C99DF7DD12 | |||
| 3772 | CDM v2.12.06 WHQL Certified.exe | C:\Users\admin\AppData\Local\Temp\FTDI-Driver\amd64\ftserui2.dll | executable | |
MD5:4F3725428FD109FB94049A263D4A0DE9 | SHA256:DB56C054FB887299E67329ED89C9B778A15BA04CBAEA5666DB4852FB7CE7B549 | |||