File name:

RTK_NIC_DRIVER_INSTALLER.sfx.exe

Full analysis: https://app.any.run/tasks/765946dc-07b4-454a-9226-18cf23a8ce6d
Verdict: Malicious activity
Analysis date: March 14, 2025, 00:55:43
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 4 sections
MD5:

3E50F76F18D1A7B77D4B4CEEC0C555F4

SHA1:

23E5B4DEFD101C16214A7FC8FF11D2BCFE363985

SHA256:

D4484FC908DC07DF99B2737D8638AAB628A58D6172C52F76E1C8499F67E89155

SSDEEP:

49152:lfnWkiYnsmdhHVrlFCT8zl4AgEumPkVWoj4axLE4QdNl4VQzeR/T+BtcYvzghnvP:lf5PdzrlOAgtmF7ALEhl4VQqRiX7+n+Q

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • The executable file from the user directory is run by the CMD process

      • RTK_NIC_DRIVER_INSTALLER.sfx.exe (PID: 6640)
      • RTK_NIC_DRIVER_INSTALLER.sfx.exe (PID: 7188)
      • RTK_NIC_DRIVER_INSTALLER.sfx.exe (PID: 3156)
    • Drops a system driver (possible attempt to evade defenses)

      • RTK_NIC_DRIVER_INSTALLER.sfx.exe (PID: 7188)
      • Setup.exe (PID: 7256)
      • drvinst.exe (PID: 7324)
    • Executable content was dropped or overwritten

      • RTK_NIC_DRIVER_INSTALLER.sfx.exe (PID: 7188)
      • Setup.exe (PID: 7256)
      • drvinst.exe (PID: 7324)
    • Reads security settings of Internet Explorer

      • RTK_NIC_DRIVER_INSTALLER.sfx.exe (PID: 7188)
    • Creates files in the driver directory

      • drvinst.exe (PID: 7324)
  • INFO

    • Create files in a temporary directory

      • RTK_NIC_DRIVER_INSTALLER.sfx.exe (PID: 7188)
      • Setup.exe (PID: 7256)
    • The sample compiled with english language support

      • RTK_NIC_DRIVER_INSTALLER.sfx.exe (PID: 7188)
      • Setup.exe (PID: 7256)
      • drvinst.exe (PID: 7324)
    • Reads the computer name

      • RTK_NIC_DRIVER_INSTALLER.sfx.exe (PID: 7188)
      • Setup.exe (PID: 7256)
      • drvinst.exe (PID: 7324)
    • Process checks computer location settings

      • RTK_NIC_DRIVER_INSTALLER.sfx.exe (PID: 7188)
    • Checks supported languages

      • RTK_NIC_DRIVER_INSTALLER.sfx.exe (PID: 7188)
      • Setup.exe (PID: 7256)
      • drvinst.exe (PID: 7324)
    • Reads the software policy settings

      • drvinst.exe (PID: 7324)
    • Reads the machine GUID from the registry

      • drvinst.exe (PID: 7324)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic Win/DOS Executable (50)
.exe | DOS Executable Generic (49.9)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2010:06:27 07:06:38+00:00
ImageFileCharacteristics: No relocs, Executable, 32-bit
PEType: PE32
LinkerVersion: 8
CodeSize: 70656
InitializedDataSize: 77312
UninitializedDataSize: -
EntryPoint: 0x11def
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 1.2.0.715
ProductVersionNumber: 1.2.0.715
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
CompanyName: Realtek
FileDescription: RtuInstall
FileVersion: 1.0.0.7
LegalCopyright: COPYRIGHT (C) 2007-2020 Realtek CORPORATION
OriginalFileName: RtuInstall.exe
ProductName: RtuInstall
ProductVersion: 1.0.0.7
No data.
screenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
134
Monitored processes
9
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start cmd.exe no specs conhost.exe no specs rtk_nic_driver_installer.sfx.exe no specs rtk_nic_driver_installer.sfx.exe no specs rtk_nic_driver_installer.sfx.exe setup.exe drvinst.exe sppextcomobj.exe no specs slui.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
3156"C:\Users\admin\AppData\Local\Temp\RTK_NIC_DRIVER_INSTALLER.sfx.exe" C:\Users\admin\AppData\Local\Temp\RTK_NIC_DRIVER_INSTALLER.sfx.execmd.exe
User:
admin
Company:
Realtek
Integrity Level:
MEDIUM
Description:
RtuInstall
Exit code:
3221226540
Version:
1.0.0.7
Modules
Images
c:\users\admin\appdata\local\temp\rtk_nic_driver_installer.sfx.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
5380\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
5972"C:\Windows\System32\cmd.exe" /k C:\Users\admin\AppData\Local\Temp\RTK_NIC_DRIVER_INSTALLER.sfx.exeC:\Windows\System32\cmd.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\system32\bcrypt.dll
6640C:\Users\admin\AppData\Local\Temp\RTK_NIC_DRIVER_INSTALLER.sfx.exeC:\Users\admin\AppData\Local\Temp\RTK_NIC_DRIVER_INSTALLER.sfx.execmd.exe
User:
admin
Company:
Realtek
Integrity Level:
MEDIUM
Description:
RtuInstall
Exit code:
3221226540
Version:
1.0.0.7
Modules
Images
c:\users\admin\appdata\local\temp\rtk_nic_driver_installer.sfx.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
7188"C:\Users\admin\AppData\Local\Temp\RTK_NIC_DRIVER_INSTALLER.sfx.exe" C:\Users\admin\AppData\Local\Temp\RTK_NIC_DRIVER_INSTALLER.sfx.exe
cmd.exe
User:
admin
Company:
Realtek
Integrity Level:
HIGH
Description:
RtuInstall
Exit code:
0
Version:
1.0.0.7
Modules
Images
c:\users\admin\appdata\local\temp\rtk_nic_driver_installer.sfx.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
7256"C:\Users\admin\AppData\Local\Temp\RTK_NIC_DRIVER_INSTALLER\setup.exe" -sC:\Users\admin\AppData\Local\Temp\RTK_NIC_DRIVER_INSTALLER\Setup.exe
RTK_NIC_DRIVER_INSTALLER.sfx.exe
User:
admin
Company:
Realtek Semiconductor Corp.
Integrity Level:
HIGH
Description:
USB NIC Driver Auto Installer
Exit code:
0
Version:
1.0.0.15
Modules
Images
c:\users\admin\appdata\local\temp\rtk_nic_driver_installer\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acgenral.dll
7324DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{7ff2a6a3-a318-f54f-b4fa-50c79674c24f}\rtux64w10sta.INF" "9" "4cf620adf" "00000000000001E0" "WinSta0\Default" "00000000000001F0" "208" "C:\Users\admin\AppData\Local\Temp\RTK_NIC_DRIVER_INSTALLER\WIN10\64"C:\Windows\System32\drvinst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\drvstore.dll
7344C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
7376"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exeSppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
Total events
3 880
Read events
3 879
Write events
1
Delete events
0

Modification events

(PID) Process:(7256) Setup.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\Setup\SetupapiLogStatus
Operation:writeName:setupapi.dev.log
Value:
4096
Executable files
16
Suspicious files
21
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
7188RTK_NIC_DRIVER_INSTALLER.sfx.exeC:\Users\admin\AppData\Local\Temp\RTK_NIC_DRIVER_INSTALLER\WIN10\32\rtux86w10sta.INFbinary
MD5:F7085127F5913BDB382A307F85AEC6A1
SHA256:8EBE0CA8CC044FE47862818062FF8181C8F5F126C90C030EE0998F07448D97D2
7188RTK_NIC_DRIVER_INSTALLER.sfx.exeC:\Users\admin\AppData\Local\Temp\RTK_NIC_DRIVER_INSTALLER\WIN8\32\rtux86w8sta.INFbinary
MD5:382AE31E90441334A2DAB789EBF747B4
SHA256:45357B77D5E7D731E44D9CBCCC472A8B16D16B290A406A9F1552045A34959423
7188RTK_NIC_DRIVER_INSTALLER.sfx.exeC:\Users\admin\AppData\Local\Temp\RTK_NIC_DRIVER_INSTALLER\WIN7\64\rtux64w7.catbinary
MD5:C6CABE67CDBA3DD24818C256D59D6706
SHA256:AADBE98546772D27E922699598D35F3FF5A21F4AAE5F056D0F4E57E30FC31F5E
7188RTK_NIC_DRIVER_INSTALLER.sfx.exeC:\Users\admin\AppData\Local\Temp\RTK_NIC_DRIVER_INSTALLER\WIN8\64\rtux64w8.catbinary
MD5:9F572D787D372375CCF9282C42A4F7D7
SHA256:A39C6C8CB3FA27E3FF77A1C7FA996192D8BABE949F57F174DF0C33CE44B4F7D2
7188RTK_NIC_DRIVER_INSTALLER.sfx.exeC:\Users\admin\AppData\Local\Temp\RTK_NIC_DRIVER_INSTALLER\WIN10\64\rtux64w10.catbinary
MD5:963F99022AEF6F054D1E6DA421AACD08
SHA256:BC09B317A8333A6858D12A572E186EB156C297CA2EEC7029931F1EEFD0C7B086
7188RTK_NIC_DRIVER_INSTALLER.sfx.exeC:\Users\admin\AppData\Local\Temp\RTK_NIC_DRIVER_INSTALLER\WIN10\32\rtux86w10.sysexecutable
MD5:5C5E25AC792FA7EA5F93426F21FB60DE
SHA256:3F06A31A01A1098ACF52DA4E51E2CF6407B0A2D7BE74C427AEA63BD2835E53F2
7188RTK_NIC_DRIVER_INSTALLER.sfx.exeC:\Users\admin\AppData\Local\Temp\RTK_NIC_DRIVER_INSTALLER\WIN10\64\rtux64w10.sysexecutable
MD5:F1FD80B91AD551E014A9B34EC37089C0
SHA256:D49CD2A1316824E027AEF4378B28586BD5F7457DD5E9530E989901FE8508F692
7188RTK_NIC_DRIVER_INSTALLER.sfx.exeC:\Users\admin\AppData\Local\Temp\RTK_NIC_DRIVER_INSTALLER\WIN8\64\rtux64w8sta.INFbinary
MD5:BEC585026F198CBC4513A596BD76E2BE
SHA256:BA8A8313A502BCDBEE9353CBEC35E2F88431D8E508698181090A76BD935C584E
7188RTK_NIC_DRIVER_INSTALLER.sfx.exeC:\Users\admin\AppData\Local\Temp\RTK_NIC_DRIVER_INSTALLER\WIN7\64\rtux64w7.sysexecutable
MD5:BCC69525FCD945A41E44590206A1671B
SHA256:54EEAB0B73A07DBA3F1BBC0ED74BD8511D3E2410E40DE39D013E5CD139525C4F
7188RTK_NIC_DRIVER_INSTALLER.sfx.exeC:\Users\admin\AppData\Local\Temp\RTK_NIC_DRIVER_INSTALLER\WIN7\32\RTNicProp32.dllexecutable
MD5:F70BE015F896E5C0A09CEB8FDA505B9B
SHA256:B7F83A3DD46D88EB5BCB69BB6A4A6E87077D2E977E5521A7C145DA6413A37B46
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
24
DNS requests
5
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
5496
MoUsoCoreWorker.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2112
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2104
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 51.104.136.2
whitelisted
google.com
  • 142.250.184.238
whitelisted

Threats

No threats detected
No debug info