File name:

RTK_NIC_DRIVER_INSTALLER.sfx.exe

Full analysis: https://app.any.run/tasks/765946dc-07b4-454a-9226-18cf23a8ce6d
Verdict: Malicious activity
Analysis date: March 14, 2025, 00:55:43
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 4 sections
MD5:

3E50F76F18D1A7B77D4B4CEEC0C555F4

SHA1:

23E5B4DEFD101C16214A7FC8FF11D2BCFE363985

SHA256:

D4484FC908DC07DF99B2737D8638AAB628A58D6172C52F76E1C8499F67E89155

SSDEEP:

49152:lfnWkiYnsmdhHVrlFCT8zl4AgEumPkVWoj4axLE4QdNl4VQzeR/T+BtcYvzghnvP:lf5PdzrlOAgtmF7ALEhl4VQqRiX7+n+Q

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • The executable file from the user directory is run by the CMD process

      • RTK_NIC_DRIVER_INSTALLER.sfx.exe (PID: 3156)
      • RTK_NIC_DRIVER_INSTALLER.sfx.exe (PID: 6640)
      • RTK_NIC_DRIVER_INSTALLER.sfx.exe (PID: 7188)
    • Drops a system driver (possible attempt to evade defenses)

      • RTK_NIC_DRIVER_INSTALLER.sfx.exe (PID: 7188)
      • Setup.exe (PID: 7256)
      • drvinst.exe (PID: 7324)
    • Reads security settings of Internet Explorer

      • RTK_NIC_DRIVER_INSTALLER.sfx.exe (PID: 7188)
    • Executable content was dropped or overwritten

      • RTK_NIC_DRIVER_INSTALLER.sfx.exe (PID: 7188)
      • Setup.exe (PID: 7256)
      • drvinst.exe (PID: 7324)
    • Creates files in the driver directory

      • drvinst.exe (PID: 7324)
  • INFO

    • The sample compiled with english language support

      • RTK_NIC_DRIVER_INSTALLER.sfx.exe (PID: 7188)
      • Setup.exe (PID: 7256)
      • drvinst.exe (PID: 7324)
    • Reads the computer name

      • RTK_NIC_DRIVER_INSTALLER.sfx.exe (PID: 7188)
      • Setup.exe (PID: 7256)
      • drvinst.exe (PID: 7324)
    • Create files in a temporary directory

      • RTK_NIC_DRIVER_INSTALLER.sfx.exe (PID: 7188)
      • Setup.exe (PID: 7256)
    • Process checks computer location settings

      • RTK_NIC_DRIVER_INSTALLER.sfx.exe (PID: 7188)
    • Checks supported languages

      • RTK_NIC_DRIVER_INSTALLER.sfx.exe (PID: 7188)
      • Setup.exe (PID: 7256)
      • drvinst.exe (PID: 7324)
    • Reads the software policy settings

      • drvinst.exe (PID: 7324)
    • Reads the machine GUID from the registry

      • drvinst.exe (PID: 7324)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic Win/DOS Executable (50)
.exe | DOS Executable Generic (49.9)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2010:06:27 07:06:38+00:00
ImageFileCharacteristics: No relocs, Executable, 32-bit
PEType: PE32
LinkerVersion: 8
CodeSize: 70656
InitializedDataSize: 77312
UninitializedDataSize: -
EntryPoint: 0x11def
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 1.2.0.715
ProductVersionNumber: 1.2.0.715
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
CompanyName: Realtek
FileDescription: RtuInstall
FileVersion: 1.0.0.7
LegalCopyright: COPYRIGHT (C) 2007-2020 Realtek CORPORATION
OriginalFileName: RtuInstall.exe
ProductName: RtuInstall
ProductVersion: 1.0.0.7
No data.
screenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
134
Monitored processes
9
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start cmd.exe no specs conhost.exe no specs rtk_nic_driver_installer.sfx.exe no specs rtk_nic_driver_installer.sfx.exe no specs rtk_nic_driver_installer.sfx.exe setup.exe drvinst.exe sppextcomobj.exe no specs slui.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
3156"C:\Users\admin\AppData\Local\Temp\RTK_NIC_DRIVER_INSTALLER.sfx.exe" C:\Users\admin\AppData\Local\Temp\RTK_NIC_DRIVER_INSTALLER.sfx.execmd.exe
User:
admin
Company:
Realtek
Integrity Level:
MEDIUM
Description:
RtuInstall
Exit code:
3221226540
Version:
1.0.0.7
Modules
Images
c:\users\admin\appdata\local\temp\rtk_nic_driver_installer.sfx.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
5380\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
5972"C:\Windows\System32\cmd.exe" /k C:\Users\admin\AppData\Local\Temp\RTK_NIC_DRIVER_INSTALLER.sfx.exeC:\Windows\System32\cmd.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\system32\bcrypt.dll
6640C:\Users\admin\AppData\Local\Temp\RTK_NIC_DRIVER_INSTALLER.sfx.exeC:\Users\admin\AppData\Local\Temp\RTK_NIC_DRIVER_INSTALLER.sfx.execmd.exe
User:
admin
Company:
Realtek
Integrity Level:
MEDIUM
Description:
RtuInstall
Exit code:
3221226540
Version:
1.0.0.7
Modules
Images
c:\users\admin\appdata\local\temp\rtk_nic_driver_installer.sfx.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
7188"C:\Users\admin\AppData\Local\Temp\RTK_NIC_DRIVER_INSTALLER.sfx.exe" C:\Users\admin\AppData\Local\Temp\RTK_NIC_DRIVER_INSTALLER.sfx.exe
cmd.exe
User:
admin
Company:
Realtek
Integrity Level:
HIGH
Description:
RtuInstall
Exit code:
0
Version:
1.0.0.7
Modules
Images
c:\users\admin\appdata\local\temp\rtk_nic_driver_installer.sfx.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
7256"C:\Users\admin\AppData\Local\Temp\RTK_NIC_DRIVER_INSTALLER\setup.exe" -sC:\Users\admin\AppData\Local\Temp\RTK_NIC_DRIVER_INSTALLER\Setup.exe
RTK_NIC_DRIVER_INSTALLER.sfx.exe
User:
admin
Company:
Realtek Semiconductor Corp.
Integrity Level:
HIGH
Description:
USB NIC Driver Auto Installer
Exit code:
0
Version:
1.0.0.15
Modules
Images
c:\users\admin\appdata\local\temp\rtk_nic_driver_installer\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acgenral.dll
7324DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{7ff2a6a3-a318-f54f-b4fa-50c79674c24f}\rtux64w10sta.INF" "9" "4cf620adf" "00000000000001E0" "WinSta0\Default" "00000000000001F0" "208" "C:\Users\admin\AppData\Local\Temp\RTK_NIC_DRIVER_INSTALLER\WIN10\64"C:\Windows\System32\drvinst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\drvstore.dll
7344C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
7376"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exeSppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
Total events
3 880
Read events
3 879
Write events
1
Delete events
0

Modification events

(PID) Process:(7256) Setup.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\Setup\SetupapiLogStatus
Operation:writeName:setupapi.dev.log
Value:
4096
Executable files
16
Suspicious files
21
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
7188RTK_NIC_DRIVER_INSTALLER.sfx.exeC:\Users\admin\AppData\Local\Temp\RTK_NIC_DRIVER_INSTALLER\WIN7\32\rtux86w7.catbinary
MD5:C139CCA969D5AB24B1B758270D190E27
SHA256:299F21174D0E68B64AB33E0A43816A5A912F4EBD05225207C9E1DC88BD9D5152
7188RTK_NIC_DRIVER_INSTALLER.sfx.exeC:\Users\admin\AppData\Local\Temp\RTK_NIC_DRIVER_INSTALLER\WIN10\64\rtux64w10sta.INFbinary
MD5:1867D00A37C2188A4AD4AB7A27F210DA
SHA256:79D4DDA749C1F8FE1CAA678D1B37D934666108DB720278DF0785B6A8DC12B5EE
7188RTK_NIC_DRIVER_INSTALLER.sfx.exeC:\Users\admin\AppData\Local\Temp\RTK_NIC_DRIVER_INSTALLER\WIN10\64\rtux64w10.catbinary
MD5:963F99022AEF6F054D1E6DA421AACD08
SHA256:BC09B317A8333A6858D12A572E186EB156C297CA2EEC7029931F1EEFD0C7B086
7188RTK_NIC_DRIVER_INSTALLER.sfx.exeC:\Users\admin\AppData\Local\Temp\RTK_NIC_DRIVER_INSTALLER\WIN7\64\rtux64w7.catbinary
MD5:C6CABE67CDBA3DD24818C256D59D6706
SHA256:AADBE98546772D27E922699598D35F3FF5A21F4AAE5F056D0F4E57E30FC31F5E
7188RTK_NIC_DRIVER_INSTALLER.sfx.exeC:\Users\admin\AppData\Local\Temp\RTK_NIC_DRIVER_INSTALLER\WIN10\32\rtux86w10sta.INFbinary
MD5:F7085127F5913BDB382A307F85AEC6A1
SHA256:8EBE0CA8CC044FE47862818062FF8181C8F5F126C90C030EE0998F07448D97D2
7188RTK_NIC_DRIVER_INSTALLER.sfx.exeC:\Users\admin\AppData\Local\Temp\RTK_NIC_DRIVER_INSTALLER\WIN7\32\rtux86w7sta.INFbinary
MD5:3ACF5B37E3DD71898E74A53EAB227A31
SHA256:727E5C12E49AFB2D98086E20011E29781F8968D8E29CE7A8A172EBA2D280B382
7188RTK_NIC_DRIVER_INSTALLER.sfx.exeC:\Users\admin\AppData\Local\Temp\RTK_NIC_DRIVER_INSTALLER\WIN7\64\rtux64w7sta.INFbinary
MD5:9A11C0C8D115A5FA00728D3B03CB3870
SHA256:9E668ABEBC069097DC5334F801DAAC822AFBD3587D5896785BA8AD87F62CBC7F
7188RTK_NIC_DRIVER_INSTALLER.sfx.exeC:\Users\admin\AppData\Local\Temp\RTK_NIC_DRIVER_INSTALLER\WIN10\32\rtux86w10.catbinary
MD5:B2396083187EC556BA2A2240203F2985
SHA256:91EE7038143DB12B178EE08DEFFCD1805676B238C96F0C4CC34AC3626819E35E
7188RTK_NIC_DRIVER_INSTALLER.sfx.exeC:\Users\admin\AppData\Local\Temp\RTK_NIC_DRIVER_INSTALLER\WIN10\64\rtux64w10.sysexecutable
MD5:F1FD80B91AD551E014A9B34EC37089C0
SHA256:D49CD2A1316824E027AEF4378B28586BD5F7457DD5E9530E989901FE8508F692
7188RTK_NIC_DRIVER_INSTALLER.sfx.exeC:\Users\admin\AppData\Local\Temp\RTK_NIC_DRIVER_INSTALLER\WIN10\32\rtux86w10.sysexecutable
MD5:5C5E25AC792FA7EA5F93426F21FB60DE
SHA256:3F06A31A01A1098ACF52DA4E51E2CF6407B0A2D7BE74C427AEA63BD2835E53F2
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
24
DNS requests
5
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
5496
MoUsoCoreWorker.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2112
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2104
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 51.104.136.2
whitelisted
google.com
  • 142.250.184.238
whitelisted

Threats

No threats detected
No debug info