| URL: | https://www.synaptics.com/products/displaylink-graphics/downloads |
| Full analysis: | https://app.any.run/tasks/af7e558d-1b29-4e10-8eab-c8b15b19ea3d |
| Verdict: | Malicious activity |
| Analysis date: | January 30, 2025, 19:23:17 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Tags: | |
| Indicators: | |
| MD5: | E4FDA2CED4F22FA7CB2F93131149E9BA |
| SHA1: | 2E90F5DC48AC91ABB22D677F06C62698BF2CEFF7 |
| SHA256: | BFAFFF179835D88FC50A27EC234E172CB9193662CE601CF41917D58B4CB03CDA |
| SSDEEP: | 3:N8DSLQWLzXaQGRWaMS4ZN8Sen:2OLDyRWHRX8X |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 520 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --disable-quic --no-appcompat-clear --mojo-platform-channel-handle=4352 --field-trial-handle=1972,i,7037620568209568456,2112744534112982427,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 122.0.6261.70 Modules
| |||||||||||||||
| 1076 | C:\Windows\syswow64\MsiExec.exe -Embedding B563D0BEDCDB49D34E3454078251D77A C | C:\Windows\SysWOW64\msiexec.exe | msiexec.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows® installer Exit code: 0 Version: 5.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1328 | DLDF52.exe /exelang 1033 DL_INSTALL_AUDIO=Yes DL_NO_EULA=Yes DL_PROMOTE_STORE_APP=Yes DL_PRODUCT_NAME="DisplayLink Graphics" DL_BRANDING_UPGRADE_CODE="{78A36ACD-80D5-490f-B4C4-83D7FCC08391}" DL_BRANDING_PRODUCT_CODE="{7A240486-2EFA-42D9-AF37-590752CD6413}" DL_BRANDING_CAB="C:\Users\admin\AppData\Local\Temp\DL2.tmp\DLE0CA.tmp" DL_BRANDING_NEW_DEVICE_ACTIVITY=mirror0 DL_ID_USBDRIVER_PATH="C:\Users\admin\AppData\Local\Temp\DL2.tmp\DLIDUSB\x64" DL_HOTDESK_SERVICE="No" DL_INSTALL_ANALYTICS=Yes DL_VMM_FIRMWARE_INCLUDED="No" DL_TEMP_DIR="C:\Users\admin\AppData\Local\Temp\DL2.tmp\" /lv "C:\Users\admin\AppData\Local\Temp\DLC7333.LOG" | C:\Users\admin\AppData\Local\Temp\DL2.tmp\DLDF52.exe | DisplayLink USB Graphics Software for Windows11.6 M0-EXE.exe | ||||||||||||
User: admin Company: DisplayLink Corp. Integrity Level: HIGH Description: DisplayLink Graphics Installer Exit code: 1626 Version: 11.6.7168.0 Modules
| |||||||||||||||
| 1400 | "C:\Users\admin\AppData\Local\Temp\DL2.tmp\additional.exe" -y -o"C:\Users\admin\AppData\Local\Temp\DL2.tmp\" | C:\Users\admin\AppData\Local\Temp\DL2.tmp\additional.exe | DisplayLink USB Graphics Software for Windows11.6 M0-EXE.exe | ||||||||||||
User: admin Company: Igor Pavlov Integrity Level: HIGH Description: 7z Console SFX Exit code: 0 Version: 19.00 Modules
| |||||||||||||||
| 1540 | "C:\Users\admin\Downloads\DisplayLink USB Graphics Software for Windows11.6 M0-EXE.exe" | C:\Users\admin\Downloads\DisplayLink USB Graphics Software for Windows11.6 M0-EXE.exe | — | chrome.exe | |||||||||||
User: admin Company: DisplayLink Corp. Integrity Level: MEDIUM Description: Installs DisplayLink Software Exit code: 3221226540 Version: 11, 6, 7312, 0 Modules
| |||||||||||||||
| 1576 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | SrTasks.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2148 | C:\Windows\System32\MsiExec.exe -Embedding A3F417ECABF0889A9AC89D45C43064A3 C | C:\Windows\System32\msiexec.exe | — | msiexec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows® installer Exit code: 0 Version: 5.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2996 | "C:\Users\admin\AppData\Local\Temp\DL2.tmp\DLDF52.exe" /i C:\Users\admin\AppData\Local\Temp\{5CA463B2-C561-4414-B785-EDD51ACE9F95}\ACE9F95\DisplayLinkIDD.msi /lv C:\Users\admin\AppData\Local\Temp\DLC7333.LOG AI_EUIMSI=1 APPDIR="C:\Program Files\DisplayLink Core Software" M_DIR="C:\ProgramData\Microsoft" SECONDSEQUENCE="1" CLIENTPROCESSID="1328" AI_MORE_CMD_LINE=1 | C:\Users\admin\AppData\Local\Temp\DL2.tmp\DLDF52.exe | DLDF52.exe | ||||||||||||
User: admin Company: DisplayLink Corp. Integrity Level: HIGH Description: DisplayLink Graphics Installer Exit code: 0 Version: 11.6.7168.0 Modules
| |||||||||||||||
| 3124 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --disable-quic --no-appcompat-clear --mojo-platform-channel-handle=4352 --field-trial-handle=1972,i,7037620568209568456,2112744534112982427,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 122.0.6261.70 | |||||||||||||||
| 3172 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=chrome.mojom.ProcessorMetrics --lang=en-US --service-sandbox-type=none --disable-quic --no-appcompat-clear --mojo-platform-channel-handle=5724 --field-trial-handle=1972,i,7037620568209568456,2112744534112982427,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Exit code: 0 Version: 122.0.6261.70 Modules
| |||||||||||||||
| (PID) Process: | (4164) chrome.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\BLBeacon |
| Operation: | write | Name: | failed_count |
Value: 0 | |||
| (PID) Process: | (4164) chrome.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\BLBeacon |
| Operation: | write | Name: | state |
Value: 2 | |||
| (PID) Process: | (4164) chrome.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\BLBeacon |
| Operation: | write | Name: | state |
Value: 1 | |||
| (PID) Process: | (4164) chrome.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\StabilityMetrics |
| Operation: | write | Name: | user_experience_metrics.stability.exited_cleanly |
Value: 0 | |||
| (PID) Process: | (4164) chrome.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96} |
| Operation: | write | Name: | usagestats |
Value: 0 | |||
| (PID) Process: | (5064) SearchApp.exe | Key: | \REGISTRY\A\{ee080948-b2ea-145a-6870-f9164b908eb9}\LocalState\ConstraintIndex |
| Operation: | write | Name: | CurrentConstraintIndexCabPath |
Value: 43003A005C00550073006500720073005C00610064006D0069006E005C0041007000700044006100740061005C004C006F00630061006C005C005000610063006B0061006700650073005C004D006900630072006F0073006F00660074002E00570069006E0064006F00770073002E005300650061007200630068005F006300770035006E003100680032007400780079006500770079005C004C006F00630061006C00530074006100740065005C0043006F006E00730074007200610069006E00740049006E006400650078005C0049006E007000750074005F007B00380033003200620036003800640032002D0037006600650032002D0034006500370031002D0061003300610064002D003200360031003600360062003600350036006500630036007D000000276707754C73DB01 | |||
| (PID) Process: | (5064) SearchApp.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Feeds\DSB |
| Operation: | write | Name: | DynamicText |
Value: | |||
| (PID) Process: | (5064) SearchApp.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Feeds\DSB |
| Operation: | write | Name: | DynamicTextTruncated |
Value: | |||
| (PID) Process: | (5064) SearchApp.exe | Key: | \REGISTRY\A\{ee080948-b2ea-145a-6870-f9164b908eb9}\LocalState\AppsConstraintIndex |
| Operation: | write | Name: | LatestConstraintIndexFolder |
Value: 43003A005C00550073006500720073005C00610064006D0069006E005C0041007000700044006100740061005C004C006F00630061006C005C005000610063006B0061006700650073005C004D006900630072006F0073006F00660074002E00570069006E0064006F00770073002E005300650061007200630068005F006300770035006E003100680032007400780079006500770079005C004C006F00630061006C00530074006100740065005C0043006F006E00730074007200610069006E00740049006E006400650078005C0041007000700073005F007B00320035003500370038003200350037002D0030003500660039002D0034003900630066002D0062003200310063002D006400340064003700310066003500650039003600650036007D0000004BB90B754C73DB01 | |||
| (PID) Process: | (5064) SearchApp.exe | Key: | \REGISTRY\A\{ee080948-b2ea-145a-6870-f9164b908eb9}\LocalState\AppsConstraintIndex |
| Operation: | write | Name: | LastConstraintIndexBuildCompleted |
Value: AB290C754C73DB01EE070C754C73DB01 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 4164 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\parcel_tracking_db\LOG.old~RF1383f8.TMP | — | |
MD5:— | SHA256:— | |||
| 4164 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\chrome_cart_db\LOG.old~RF1383f8.TMP | — | |
MD5:— | SHA256:— | |||
| 4164 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\parcel_tracking_db\LOG.old | — | |
MD5:— | SHA256:— | |||
| 4164 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\chrome_cart_db\LOG.old | — | |
MD5:— | SHA256:— | |||
| 4164 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\commerce_subscription_db\LOG.old~RF1383f8.TMP | — | |
MD5:— | SHA256:— | |||
| 4164 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\commerce_subscription_db\LOG.old | — | |
MD5:— | SHA256:— | |||
| 4164 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\coupon_db\LOG.old~RF138408.TMP | — | |
MD5:— | SHA256:— | |||
| 4164 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\discounts_db\LOG.old~RF138408.TMP | — | |
MD5:— | SHA256:— | |||
| 4164 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\PersistentOriginTrials\LOG.old~RF138418.TMP | — | |
MD5:— | SHA256:— | |||
| 4164 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\coupon_db\LOG.old | — | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
4128 | SIHClient.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
7004 | backgroundTaskHost.exe | GET | 200 | 2.23.77.188:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D | unknown | — | — | whitelisted |
4128 | SIHClient.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
6816 | svchost.exe | HEAD | 200 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/ac5bmzdhlhvn4ze6ejhjgkdvap2a_20250110.715577970.14/obedbbhbpmojnkanicioggnmelmoomoc_20250110.715577970.14_all_ENUS500000_adkcjtzzwmnya3mar52st73ev4qa.crx3 | unknown | — | — | whitelisted |
6816 | svchost.exe | GET | 206 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/ac5bmzdhlhvn4ze6ejhjgkdvap2a_20250110.715577970.14/obedbbhbpmojnkanicioggnmelmoomoc_20250110.715577970.14_all_ENUS500000_adkcjtzzwmnya3mar52st73ev4qa.crx3 | unknown | — | — | whitelisted |
6816 | svchost.exe | GET | 206 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/ac5bmzdhlhvn4ze6ejhjgkdvap2a_20250110.715577970.14/obedbbhbpmojnkanicioggnmelmoomoc_20250110.715577970.14_all_ENUS500000_adkcjtzzwmnya3mar52st73ev4qa.crx3 | unknown | — | — | whitelisted |
6816 | svchost.exe | GET | 206 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/ac5bmzdhlhvn4ze6ejhjgkdvap2a_20250110.715577970.14/obedbbhbpmojnkanicioggnmelmoomoc_20250110.715577970.14_all_ENUS500000_adkcjtzzwmnya3mar52st73ev4qa.crx3 | unknown | — | — | whitelisted |
6816 | svchost.exe | GET | 206 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/ac5bmzdhlhvn4ze6ejhjgkdvap2a_20250110.715577970.14/obedbbhbpmojnkanicioggnmelmoomoc_20250110.715577970.14_all_ENUS500000_adkcjtzzwmnya3mar52st73ev4qa.crx3 | unknown | — | — | whitelisted |
6816 | svchost.exe | GET | 206 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/ac5bmzdhlhvn4ze6ejhjgkdvap2a_20250110.715577970.14/obedbbhbpmojnkanicioggnmelmoomoc_20250110.715577970.14_all_ENUS500000_adkcjtzzwmnya3mar52st73ev4qa.crx3 | unknown | — | — | whitelisted |
6816 | svchost.exe | GET | 206 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/ac5bmzdhlhvn4ze6ejhjgkdvap2a_20250110.715577970.14/obedbbhbpmojnkanicioggnmelmoomoc_20250110.715577970.14_all_ENUS500000_adkcjtzzwmnya3mar52st73ev4qa.crx3 | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
— | — | 104.126.37.145:443 | r.bing.com | Akamai International B.V. | DE | whitelisted |
4164 | chrome.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
6336 | chrome.exe | 50.112.41.9:443 | www.synaptics.com | AMAZON-02 | US | whitelisted |
6336 | chrome.exe | 108.177.127.84:443 | accounts.google.com | GOOGLE | US | whitelisted |
6336 | chrome.exe | 172.217.23.100:443 | www.google.com | GOOGLE | US | whitelisted |
6336 | chrome.exe | 151.101.65.229:443 | cdn.jsdelivr.net | FASTLY | US | whitelisted |
6336 | chrome.exe | 108.138.36.77:443 | consent.trustarc.com | AMAZON-02 | US | shared |
6336 | chrome.exe | 151.101.130.217:443 | cdn.bfldr.com | FASTLY | US | suspicious |
Domain | IP | Reputation |
|---|---|---|
www.synaptics.com |
| whitelisted |
accounts.google.com |
| whitelisted |
www.google.com |
| whitelisted |
consent.trustarc.com |
| shared |
cdn.jsdelivr.net |
| whitelisted |
cdn.bfldr.com |
| unknown |
www.gstatic.com |
| whitelisted |
fonts.googleapis.com |
| whitelisted |
fonts.gstatic.com |
| whitelisted |
players.brightcove.net |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
6336 | chrome.exe | Not Suspicious Traffic | INFO [ANY.RUN] Requests to a free CDN for open source projects (jsdelivr .net) |
6336 | chrome.exe | Not Suspicious Traffic | INFO [ANY.RUN] Requests to a free CDN for open source projects (jsdelivr .net) |
6336 | chrome.exe | Not Suspicious Traffic | INFO [ANY.RUN] Requests to a free CDN for open source projects (jsdelivr .net) |
6336 | chrome.exe | Not Suspicious Traffic | INFO [ANY.RUN] Requests to a free CDN for open source projects (jsdelivr .net) |
Process | Message |
|---|---|
DLDF52.exe | MSI (c) (B4:04) [19:25:12:614]: Entering MsiOpenPackageEx. szPackagePath: C:\Users\admin\AppData\Local\Temp\{5CA463B2-C561-4414-B785-EDD51ACE9F95}\ACE9F95\DisplayLinkIDD.msi, dwOptions: 0, hProduct: D3F1AC |
DLDF52.exe | MSI (c) (B4:04) [19:25:12:614]: Entering MsiOpenPackage. szPackagePath: C:\Users\admin\AppData\Local\Temp\{5CA463B2-C561-4414-B785-EDD51ACE9F95}\ACE9F95\DisplayLinkIDD.msi, hProduct: D3F1AC |
DLDF52.exe | |
DLDF52.exe | |
DLDF52.exe | |
DLDF52.exe | MSI (c) (B4:04) [19:25:12:614]: Machine policy value 'Timeout' is 1800 |
DLDF52.exe | MSI (c) (B4:04) [19:25:12:630]: SOFTWARE RESTRICTION POLICY: C:\Users\admin\AppData\Local\Temp\{5CA463B2-C561-4414-B785-EDD51ACE9F95}\ACE9F95\DisplayLinkIDD.msi has a digital signature |
DLDF52.exe | MSI (c) (B4:04) [19:25:12:630]: SOFTWARE RESTRICTION POLICY: Verifying package --> 'C:\Users\admin\AppData\Local\Temp\{5CA463B2-C561-4414-B785-EDD51ACE9F95}\ACE9F95\DisplayLinkIDD.msi' against software restriction policy |
DLDF52.exe | |
DLDF52.exe | |