| File name: | AutokentMultiDriverMVCI_X64.exe |
| Full analysis: | https://app.any.run/tasks/7f9db274-3f9e-4636-a39d-d1598142e57c |
| Verdict: | Malicious activity |
| Analysis date: | December 02, 2023, 20:35:36 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | D8EEE94E8F2526738972F75EFAA62877 |
| SHA1: | D6B6920743C31D77177C2319E02E8943A9B3ED90 |
| SHA256: | A58FB038D398B06061907D4CA63B48E7D5C7F8ED1BDB93741A4009CCEAA77CF6 |
| SSDEEP: | 98304:faoFGqwtyBBNWPYAncvZ8XTXkzM/2qH5DD+2ATUm0:YkBNWfnlTXkAe++2kK |
| .exe | | | Inno Setup installer (71.1) |
|---|---|---|
| .exe | | | Win32 Executable Delphi generic (9.1) |
| .scr | | | Windows screen saver (8.4) |
| .dll | | | Win32 Dynamic Link Library (generic) (4.2) |
| .exe | | | Win32 Executable (generic) (2.9) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 1992:06:20 00:22:17+02:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi |
| PEType: | PE32 |
| LinkerVersion: | 2.25 |
| CodeSize: | 40448 |
| InitializedDataSize: | 27648 |
| UninitializedDataSize: | - |
| EntryPoint: | 0xa5f8 |
| OSVersion: | 1 |
| ImageVersion: | 6 |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 0.0.0.0 |
| ProductVersionNumber: | 0.0.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| Comments: | This installation was built with Inno Setup. |
| CompanyName: | Autokent |
| FileDescription: | Autokent MVCI MultiDriver X64 Setup |
| FileVersion: | |
| LegalCopyright: | |
| ProductName: | Autokent MVCI MultiDriver X64 |
| ProductVersion: | 1.1 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1116 | "C:\Program Files\Autokent MVCI MultiDriver X64\MVCI_MultiX64.exe" | C:\Program Files\Autokent MVCI MultiDriver X64\MVCI_MultiX64.exe | — | AutokentMultiDriverMVCI_X64.tmp | |||||||||||
User: admin Integrity Level: MEDIUM Description: MVCI_MultiX64 Exit code: 0 Version: 1.0.0.0 Modules
| |||||||||||||||
| 2540 | "C:\Users\admin\AppData\Local\Temp\AutokentMultiDriverMVCI_X64.exe" /SPAWNWND=$10015A /NOTIFYWND=$25013A | C:\Users\admin\AppData\Local\Temp\AutokentMultiDriverMVCI_X64.exe | AutokentMultiDriverMVCI_X64.tmp | ||||||||||||
User: admin Company: Autokent Integrity Level: HIGH Description: Autokent MVCI MultiDriver X64 Setup Exit code: 0 Version: Modules
| |||||||||||||||
| 2644 | "C:\Users\admin\AppData\Local\Temp\is-ORBGD.tmp\AutokentMultiDriverMVCI_X64.tmp" /SL5="$25013A,3506206,69120,C:\Users\admin\AppData\Local\Temp\AutokentMultiDriverMVCI_X64.exe" | C:\Users\admin\AppData\Local\Temp\is-ORBGD.tmp\AutokentMultiDriverMVCI_X64.tmp | — | AutokentMultiDriverMVCI_X64.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: Setup/Uninstall Exit code: 0 Version: 51.52.0.0 Modules
| |||||||||||||||
| 3048 | "C:\Users\admin\AppData\Local\Temp\is-I946R.tmp\AutokentMultiDriverMVCI_X64.tmp" /SL5="$1D0158,3506206,69120,C:\Users\admin\AppData\Local\Temp\AutokentMultiDriverMVCI_X64.exe" /SPAWNWND=$10015A /NOTIFYWND=$25013A | C:\Users\admin\AppData\Local\Temp\is-I946R.tmp\AutokentMultiDriverMVCI_X64.tmp | — | AutokentMultiDriverMVCI_X64.exe | |||||||||||
User: admin Integrity Level: HIGH Description: Setup/Uninstall Exit code: 0 Version: 51.52.0.0 Modules
| |||||||||||||||
| 3060 | "C:\Users\admin\AppData\Local\Temp\AutokentMultiDriverMVCI_X64.exe" | C:\Users\admin\AppData\Local\Temp\AutokentMultiDriverMVCI_X64.exe | — | explorer.exe | |||||||||||
User: admin Company: Autokent Integrity Level: MEDIUM Description: Autokent MVCI MultiDriver X64 Setup Exit code: 0 Version: Modules
| |||||||||||||||
| 3208 | "C:\Program Files\Autokent MVCI MultiDriver X64\MVCI_MultiX64.exe" | C:\Program Files\Autokent MVCI MultiDriver X64\MVCI_MultiX64.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: MVCI_MultiX64 Exit code: 0 Version: 1.0.0.0 Modules
| |||||||||||||||
| (PID) Process: | (3048) AutokentMultiDriverMVCI_X64.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | delete value | Name: | RegFilesHash |
Value: D53FEA3C8669922E4B52C24FFC874492F5622C4D4F654D176BA67234645F0D0F | |||
| (PID) Process: | (3048) AutokentMultiDriverMVCI_X64.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | delete value | Name: | RegFiles0000 |
Value: C:\Program Files\Autokent MVCI MultiDriver X64\MVCI_MultiX64.exe | |||
| (PID) Process: | (3048) AutokentMultiDriverMVCI_X64.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | delete value | Name: | Sequence |
Value: 1 | |||
| (PID) Process: | (3048) AutokentMultiDriverMVCI_X64.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | delete value | Name: | SessionHash |
Value: 723356D95F914AA30F569775147A655CA29CEB14084B2975924052D645B15132 | |||
| (PID) Process: | (3048) AutokentMultiDriverMVCI_X64.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | delete value | Name: | Owner |
Value: E80B000040A51C205F25DA01 | |||
| (PID) Process: | (3048) AutokentMultiDriverMVCI_X64.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | delete key | Name: | (default) |
Value: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3060 | AutokentMultiDriverMVCI_X64.exe | C:\Users\admin\AppData\Local\Temp\is-ORBGD.tmp\AutokentMultiDriverMVCI_X64.tmp | executable | |
MD5:B4EBC9B42BD39411AB6A75B3E7442F95 | SHA256:3834C8EE40F71FA1DC8C3B236588E2FF9926D773609B8B806E1F26AE975B2B48 | |||
| 3048 | AutokentMultiDriverMVCI_X64.tmp | C:\Program Files\Autokent MVCI MultiDriver X64\is-543NS.tmp | executable | |
MD5:63D913D5878954F6B40750EC05954EF8 | SHA256:2A3D1FF8C02C9F14D547E1D3D94243CFF4F180E5DE7BD3490582A15DB5FA09FC | |||
| 3048 | AutokentMultiDriverMVCI_X64.tmp | C:\Program Files\Autokent MVCI MultiDriver X64\unins000.exe | executable | |
MD5:63D913D5878954F6B40750EC05954EF8 | SHA256:2A3D1FF8C02C9F14D547E1D3D94243CFF4F180E5DE7BD3490582A15DB5FA09FC | |||
| 3048 | AutokentMultiDriverMVCI_X64.tmp | C:\Program Files\Autokent MVCI MultiDriver X64\is-QOFP8.tmp | executable | |
MD5:0A27417A233561F63DB1CFAF05EC90B4 | SHA256:D2AB675DF5792130ED26E5FC3B50F159FD3EA2DDCCE9681ABFB56EAA158F2014 | |||
| 3048 | AutokentMultiDriverMVCI_X64.tmp | C:\Program Files\Autokent MVCI MultiDriver X64\MVCI_MultiX64.exe | executable | |
MD5:0A27417A233561F63DB1CFAF05EC90B4 | SHA256:D2AB675DF5792130ED26E5FC3B50F159FD3EA2DDCCE9681ABFB56EAA158F2014 | |||
| 3048 | AutokentMultiDriverMVCI_X64.tmp | C:\Program Files\Autokent MVCI MultiDriver X64\1.4.3\is-2NELG.tmp | executable | |
MD5:5C46E1B62BA9BED54C339CB28FC978EA | SHA256:381117C743766E3A696609BB29CA075772AA603CFF196E16C3854C06EE1AB254 | |||
| 3048 | AutokentMultiDriverMVCI_X64.tmp | C:\Program Files\Autokent MVCI MultiDriver X64\is-BG4GD.tmp | executable | |
MD5:0A27417A233561F63DB1CFAF05EC90B4 | SHA256:D2AB675DF5792130ED26E5FC3B50F159FD3EA2DDCCE9681ABFB56EAA158F2014 | |||
| 3048 | AutokentMultiDriverMVCI_X64.tmp | C:\Program Files\Autokent MVCI MultiDriver X64\1.4.3\ftd2xx.dll | executable | |
MD5:5C46E1B62BA9BED54C339CB28FC978EA | SHA256:381117C743766E3A696609BB29CA075772AA603CFF196E16C3854C06EE1AB254 | |||
| 2540 | AutokentMultiDriverMVCI_X64.exe | C:\Users\admin\AppData\Local\Temp\is-I946R.tmp\AutokentMultiDriverMVCI_X64.tmp | executable | |
MD5:B4EBC9B42BD39411AB6A75B3E7442F95 | SHA256:3834C8EE40F71FA1DC8C3B236588E2FF9926D773609B8B806E1F26AE975B2B48 | |||
| 3048 | AutokentMultiDriverMVCI_X64.tmp | C:\Program Files\Autokent MVCI MultiDriver X64\1.4.4\is-NL91R.tmp | executable | |
MD5:DEF91FB3AC2DED4A564B2CCAAFF5B4F8 | SHA256:32CD7C8ED249D3A04D1488008FC4965BBC2B8285FDE70D481DC8580E5B58B399 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
2588 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |