File name:

sentinel system driver installer 7.6.0.exe

Full analysis: https://app.any.run/tasks/ed2e3fc8-8203-4c8c-a8a4-cc045f3146b7
Verdict: Malicious activity
Analysis date: February 28, 2024, 18:55:23
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

E3006EADEC01D29CFDECDF62D3DB8F19

SHA1:

688BF60EEA3F28CA5A85E30721DC981FFDF4071D

SHA256:

B4CA8929F476DAE2BA666F34C129E6D9D2459A7D11186472C4338CB8AF91C006

SSDEEP:

49152:GKJxfxwO8snmTQs932d+NXf1lhftB7ut/XiB6PO2GkaV9WKe:BJnwO8snPExbuh/PO2naVAt

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • sentinel system driver installer 7.6.0.exe (PID: 1776)
      • drvinst.exe (PID: 1860)
    • Creates a writable file in the system directory

      • drvinst.exe (PID: 1860)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • sentinel system driver installer 7.6.0.exe (PID: 1776)
      • drvinst.exe (PID: 1860)
    • Executes as Windows Service

      • VSSVC.exe (PID: 4008)
    • Drops a system driver (possible attempt to evade defenses)

      • drvinst.exe (PID: 1860)
    • Creates files in the driver directory

      • drvinst.exe (PID: 1860)
    • Reads the Internet Settings

      • sipnotify.exe (PID: 1676)
    • Reads settings of System Certificates

      • sipnotify.exe (PID: 1676)
    • The process executes via Task Scheduler

      • sipnotify.exe (PID: 1676)
      • ctfmon.exe (PID: 1688)
    • Checks Windows Trust Settings

      • drvinst.exe (PID: 1860)
  • INFO

    • Checks supported languages

      • sentinel system driver installer 7.6.0.exe (PID: 1776)
      • drvinst.exe (PID: 1860)
      • IMEKLMG.EXE (PID: 2032)
      • IMEKLMG.EXE (PID: 1552)
      • wmpnscfg.exe (PID: 2268)
      • wmpnscfg.exe (PID: 2296)
      • wmpnscfg.exe (PID: 2448)
    • Create files in a temporary directory

      • sentinel system driver installer 7.6.0.exe (PID: 1776)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 3848)
    • Reads the machine GUID from the registry

      • sentinel system driver installer 7.6.0.exe (PID: 1776)
      • drvinst.exe (PID: 1860)
    • Drops the executable file immediately after the start

      • msiexec.exe (PID: 3848)
    • Reads the computer name

      • drvinst.exe (PID: 1860)
      • IMEKLMG.EXE (PID: 2032)
      • IMEKLMG.EXE (PID: 1552)
      • wmpnscfg.exe (PID: 2268)
      • wmpnscfg.exe (PID: 2448)
      • wmpnscfg.exe (PID: 2296)
    • Process checks whether UAC notifications are on

      • IMEKLMG.EXE (PID: 2032)
      • IMEKLMG.EXE (PID: 1552)
    • Manual execution by a user

      • IMEKLMG.EXE (PID: 1552)
      • IMEKLMG.EXE (PID: 2032)
      • ctfmon.exe (PID: 1944)
      • wmpnscfg.exe (PID: 2296)
      • wmpnscfg.exe (PID: 2268)
      • wmpnscfg.exe (PID: 2448)
    • Reads the software policy settings

      • sipnotify.exe (PID: 1676)
      • drvinst.exe (PID: 1860)
    • Reads security settings of Internet Explorer

      • sipnotify.exe (PID: 1676)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | InstallShield setup (36.8)
.exe | Win32 Executable MS Visual C++ (generic) (26.6)
.exe | Win64 Executable (generic) (23.6)
.dll | Win32 Dynamic Link Library (generic) (5.6)
.exe | Win32 Executable (generic) (3.8)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2004:04:19 21:49:29+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 159744
InitializedDataSize: 106496
UninitializedDataSize: -
EntryPoint: 0x1d92c
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 9.50.98.0
ProductVersionNumber: 9.50.0.0
FileFlagsMask: 0x0002
FileFlags: Pre-release
FileOS: Windows 16-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
Comments:
CompanyName: SafeNet, Inc.
FileDescription: Sentinel System Driver Installer 7.6.0
FileVersion: 7.6.0
InternalName: setup.exe
OriginalFileName: setup.exe
LegalCopyright: Copyright (C) 2015 SafeNet, Inc.
ProductName: Sentinel System Driver Installer 7.6.0
ProductVersion: 7.6.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
100
Monitored processes
13
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start sentinel system driver installer 7.6.0.exe msiexec.exe vssvc.exe no specs drvinst.exe ctfmon.exe no specs sipnotify.exe imeklmg.exe no specs imeklmg.exe no specs ctfmon.exe no specs wmpnscfg.exe no specs wmpnscfg.exe no specs wmpnscfg.exe no specs sentinel system driver installer 7.6.0.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1552"C:\Program Files\Common Files\microsoft shared\IME14\SHARED\IMEKLMG.EXE" /SetPreload /JPN /LogC:\Program Files\Common Files\microsoft shared\IME14\SHARED\IMEKLMG.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Office IME 2010
Exit code:
1
Version:
14.0.4734.1000
Modules
Images
c:\program files\common files\microsoft shared\ime14\shared\imeklmg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\userenv.dll
1676C:\Windows\system32\sipnotify.exe -LogonOrUnlockC:\Windows\System32\sipnotify.exe
taskeng.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
sipnotify
Exit code:
0
Version:
6.1.7602.20480 (win7sp1_ldr_escrow.191010-1716)
Modules
Images
c:\windows\system32\sipnotify.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1688C:\Windows\System32\ctfmon.exe C:\Windows\System32\ctfmon.exetaskeng.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
CTF Loader
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ctfmon.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msctfmonitor.dll
c:\windows\system32\msctf.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
1776"C:\Users\admin\AppData\Local\Temp\sentinel system driver installer 7.6.0.exe" C:\Users\admin\AppData\Local\Temp\sentinel system driver installer 7.6.0.exe
explorer.exe
User:
admin
Company:
SafeNet, Inc.
Integrity Level:
HIGH
Description:
Sentinel System Driver Installer 7.6.0
Exit code:
1073807364
Version:
7.6.0
Modules
Images
c:\users\admin\appdata\local\temp\sentinel system driver installer 7.6.0.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1860DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{670c3c2d-d3ec-766a-5bbe-8459dad2361f}\sntnlusb.inf" "0" "6dd04a27f" "00000558" "WinSta0\Default" "00000550" "208" "C:\Program Files\Common Files\SafeNet Sentinel\Sentinel System Driver"C:\Windows\System32\drvinst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1944"C:\Windows\System32\ctfmon.exe" C:\Windows\System32\ctfmon.exe C:\Windows\System32\ctfmon.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
CTF Loader
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ctfmon.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msctfmonitor.dll
c:\windows\system32\msctf.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
2032"C:\Program Files\Common Files\microsoft shared\IME14\SHARED\IMEKLMG.EXE" /SetPreload /KOR /LogC:\Program Files\Common Files\microsoft shared\IME14\SHARED\IMEKLMG.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Office IME 2010
Exit code:
1
Version:
14.0.4734.1000
Modules
Images
c:\program files\common files\microsoft shared\ime14\shared\imeklmg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\userenv.dll
2268"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2296"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2448"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
Total events
8 618
Read events
8 455
Write events
159
Delete events
4

Modification events

(PID) Process:(4008) VSSVC.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
Operation:writeName:IDENTIFY (Enter)
Value:
4000000000000000EA5164BF776ADA01A80F0000740F0000E8030000010000000100000000000000000000000000000000000000000000000000000000000000
(PID) Process:(4008) VSSVC.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
Operation:writeName:IDENTIFY (Enter)
Value:
4000000000000000EA5164BF776ADA01A80F0000A00F0000E8030000010000000100000000000000000000000000000000000000000000000000000000000000
(PID) Process:(4008) VSSVC.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\ASR Writer
Operation:writeName:IDENTIFY (Enter)
Value:
4000000000000000EA5164BF776ADA01A80F00002C070000E8030000010000000100000000000000000000000000000000000000000000000000000000000000
(PID) Process:(4008) VSSVC.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
Operation:writeName:IDENTIFY (Enter)
Value:
4000000000000000EA5164BF776ADA01A80F0000400D0000E8030000010000000100000000000000000000000000000000000000000000000000000000000000
(PID) Process:(4008) VSSVC.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
Operation:writeName:IDENTIFY (Leave)
Value:
4000000000000000EA5164BF776ADA01A80F0000A00F0000E8030000000000000100000000000000000000000000000000000000000000000000000000000000
(PID) Process:(4008) VSSVC.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
Operation:writeName:IDENTIFY (Leave)
Value:
400000000000000044B466BF776ADA01A80F0000400D0000E8030000000000000100000000000000000000000000000000000000000000000000000000000000
(PID) Process:(4008) VSSVC.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
Operation:writeName:IDENTIFY (Leave)
Value:
40000000000000009E1669BF776ADA01A80F0000740F0000E8030000000000000100000000000000000000000000000000000000000000000000000000000000
(PID) Process:(4008) VSSVC.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\ASR Writer
Operation:writeName:IDENTIFY (Leave)
Value:
40000000000000009E1669BF776ADA01A80F00002C070000E8030000000000000100000000000000000000000000000000000000000000000000000000000000
(PID) Process:(4008) VSSVC.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
Operation:writeName:PROVIDER_BEGINPREPARE (Enter)
Value:
40000000000000004C90C7C0776ADA01A80F00002C070000010400000100000000000000000000003081AD75033E3542972D5C2DFCFBAAD20000000000000000
(PID) Process:(4008) VSSVC.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
Operation:writeName:PROVIDER_BEGINPREPARE (Leave)
Value:
40000000000000004C90C7C0776ADA01A80F00002C070000010400000000000000000000000000003081AD75033E3542972D5C2DFCFBAAD20000000000000000
Executable files
5
Suspicious files
6
Text files
6
Unknown types
12

Dropped files

PID
Process
Filename
Type
1776sentinel system driver installer 7.6.0.exeC:\Users\admin\AppData\Local\Temp\~F7FC.tmpbinary
MD5:9737C9B19D56DC226C7FBBF72316176C
SHA256:1D155FF4359B8F8D6EC08B6D1A960B35B19760AADA45609F93E9DBD6A393C0FE
1860drvinst.exeC:\Windows\System32\DriverStore\Temp\{72ee2f5b-d31a-6c80-7468-402d60297d16}\SET4DCD.tmpcat
MD5:B80FE4DD69D644361C56A2DE2BAF64D2
SHA256:E7AD638D1008DE24D1D1339EFCBCC0B7BD09847D48974044F3945A314289CE2B
1860drvinst.exeC:\Windows\System32\DriverStore\infstor.datbinary
MD5:DADD32A2AFE5361C14CEE345C58EAF24
SHA256:001F7F45D832D634676ED3CC6F8D4AD083B0E8EF9F33AB0215376C68DDC70D2A
1860drvinst.exeC:\Windows\System32\DriverStore\infstrng.datbinary
MD5:567FC2E5F42A1E812FF00FF43598D907
SHA256:AEBCAC424431E4DF0E164CCFD6C402E00DAF2952885078E8A203FBFBF1E35663
3848msiexec.exeC:\Users\admin\AppData\Local\Temp\MSI57A.tmpexecutable
MD5:17ABC6EBEB355C504B51146CAD37AC1B
SHA256:0EAAEBC9257CCA697798450D3070B9E1D92A72C11A4A666B6399CB331D9B8028
1776sentinel system driver installer 7.6.0.exeC:\Users\admin\Documents\Downloaded Installations\{32E654DB-EB4D-4D74-8F88-E4DD8275CB63}\Sentinel System Driver Installer 7.6.0.msiexecutable
MD5:5E4E0F30D3D8E83F0B4060066B961499
SHA256:D160505304BA3016AB60399C65F5176ACBF4465D815C4A5E8D8873BF2E265AFA
1860drvinst.exeC:\Windows\INF\oem2.infbinary
MD5:E730B57B00AE49976C1A67A1D5ED7C42
SHA256:287548CC7747F3B165C32E89FEE746A9D74E18600444A58A70AF4CE66EFF1D3A
1860drvinst.exeC:\Windows\System32\DriverStore\INFCACHE.2binary
MD5:ABB638661D737D9457D78D28C4145066
SHA256:7602F549ABBAC7DE5CD8125329869D02A0C82AA8C9AAF78011162175AA319261
1860drvinst.exeC:\Windows\System32\DriverStore\FileRepository\sntnlusb.inf_x86_neutral_e2b9d692753e507e\sntnlusb.PNFbinary
MD5:33F7FFCAB1AD94D556F01021648F4720
SHA256:B423C095ED45505CD61594B1523D4B93DC8800F513180336E60A45867125A039
1860drvinst.exeC:\Windows\System32\DriverStore\infpub.datbinary
MD5:477C7D34A9B3E1C4CFA7463DE773EE98
SHA256:8817486958C68BAF291833EFCCC8CF166F6553E75287778E057E82B520B06BD9
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
11
DNS requests
2
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1676
sipnotify.exe
HEAD
200
23.197.138.118:80
http://query.prod.cms.rt.microsoft.com/cms/api/am/binary/RE2JgkA?v=133536201864370000
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
1112
svchost.exe
224.0.0.252:5355
unknown
1676
sipnotify.exe
23.197.138.118:80
query.prod.cms.rt.microsoft.com
Akamai International B.V.
US
unknown

DNS requests

Domain
IP
Reputation
query.prod.cms.rt.microsoft.com
  • 23.197.138.118
whitelisted

Threats

No threats detected
No debug info