| File name: | SwipeReaderDriversSetup64bit.exe |
| Full analysis: | https://app.any.run/tasks/a8cbd07d-5342-42e1-ba5c-20a365bdb76b |
| Verdict: | Malicious activity |
| Analysis date: | October 22, 2019, 09:13:49 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 1DE2E27876FFBD8BE5821F3F26D27F0C |
| SHA1: | 5087BFACA2FA7D19F78D27CD08A4C0BFD956E18C |
| SHA256: | DF79B0D8C3B3D166152E1A62314CD54824E6614D85621F7A020F932F61DBD635 |
| SSDEEP: | 49152:xLCqgNZ8yYtPbWai/BPvIIQ0vE6pjlk3xkcTjlEvE6pjlk3xkcYKCj7CVD2:A2yYtj/iaB0vE6FMkgEvE6FMkhj7R |
| .exe | | | Wise Installer executable (96.9) |
|---|---|---|
| .dll | | | Win32 Dynamic Link Library (generic) (1.3) |
| .exe | | | Win32 Executable (generic) (0.9) |
| .exe | | | Generic Win/DOS Executable (0.4) |
| .exe | | | DOS Executable Generic (0.4) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2000:04:25 16:37:12+02:00 |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 8704 |
| InitializedDataSize: | 5632 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x21af |
| OSVersion: | 4 |
| ImageVersion: | 4 |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.1.0.0 |
| ProductVersionNumber: | 1.1.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Windows 16-bit |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Windows, Latin1 |
| CompanyName: | Gemalto |
| FileDescription: | Gemalto Swipe Reader Drivers |
| FileVersion: | 1.1 |
| LegalCopyright: | © 2018, Gemalto. All rights reserved |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 532 | "C:\Users\admin\AppData\Local\Temp\SwipeReaderDriversSetup64bit.exe" | C:\Users\admin\AppData\Local\Temp\SwipeReaderDriversSetup64bit.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 3221226540 Modules
| |||||||||||||||
| 1036 | DrvInst.exe "4" "8" "C:\Users\admin\AppData\Local\Temp\{14f6df32-28d5-69b6-b894-63106fefa204}\3m_cr1x0_serial.inf" "0" "68f1fa913" "000003FC" "WinSta0\Default" "000005C8" "208" "c:\users\admin\appdata\local\temp\3mswipedrivers\3m_swipe\sw00342_1_0_1" | C:\Windows\system32\DrvInst.exe | — | svchost.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Driver Installation Module Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1552 | "C:\Users\admin\AppData\Local\Temp\3MSWIP~1\DPinst\RUNTIM~1\DPInst.exe" /lm /q /U C:\Users\admin\AppData\Local\Temp\3MSwipeDrivers\RT_USB_Drivers\ftdibus.inf | C:\Users\admin\AppData\Local\Temp\3MSWIP~1\DPinst\RUNTIM~1\DPInst.exe | — | SwipeReaderDriversSetup64bit.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Driver Package Installer Exit code: 0 Version: 2.01 Modules
| |||||||||||||||
| 1600 | "C:\Users\admin\AppData\Local\Temp\3MSWIP~1\3M_Swipe\GetOS64.exe" | C:\Users\admin\AppData\Local\Temp\3MSWIP~1\3M_Swipe\GetOS64.exe | — | SwipeReaderDriversSetup64bit.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 32 Modules
| |||||||||||||||
| 1636 | DrvInst.exe "4" "8" "C:\Users\admin\AppData\Local\Temp\{409220ea-b068-11de-cbb9-686ab4b76244}\3m_cr1x0_image.inf" "0" "6a3a9dc2b" "000003C4" "WinSta0\Default" "000003FC" "208" "c:\users\admin\appdata\local\temp\3mswipedrivers\3m_swipe\sw00342_1_0_1" | C:\Windows\system32\DrvInst.exe | svchost.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Driver Installation Module Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1772 | "C:\Users\admin\AppData\Local\Temp\3MSWIP~1\DPinst\RUNTIM~1\DPInst.exe" /lm /q /U C:\Users\admin\AppData\Local\Temp\3MSwipeDrivers\RT_USB_Drivers\ftdiport.inf | C:\Users\admin\AppData\Local\Temp\3MSWIP~1\DPinst\RUNTIM~1\DPInst.exe | — | SwipeReaderDriversSetup64bit.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Driver Package Installer Exit code: 0 Version: 2.01 Modules
| |||||||||||||||
| 2868 | "C:\Users\admin\AppData\Local\Temp\3MSWIP~1\DPinst\RUNTIM~1\DPInst.exe" /lm /q /path C:\Users\admin\AppData\Local\Temp\3MSwipeDrivers\RT_USB_Drivers | C:\Users\admin\AppData\Local\Temp\3MSWIP~1\DPinst\RUNTIM~1\DPInst.exe | SwipeReaderDriversSetup64bit.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Driver Package Installer Exit code: 512 Version: 2.01 Modules
| |||||||||||||||
| 3004 | "C:\Users\admin\AppData\Local\Temp\3MSWIP~1\DPinst\RUNTIM~1\DPInst.exe" /lm /q /path C:\Users\admin\AppData\Local\Temp\3MSwipeDrivers\3M_Swipe\SW00342_1_0_1 | C:\Users\admin\AppData\Local\Temp\3MSWIP~1\DPinst\RUNTIM~1\DPInst.exe | SwipeReaderDriversSetup64bit.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Driver Package Installer Exit code: 768 Version: 2.01 Modules
| |||||||||||||||
| 3060 | DrvInst.exe "4" "8" "C:\Users\admin\AppData\Local\Temp\{06a44e3d-acc1-5cae-7198-573e244a3a61}\3m_cr1x0_composite.inf" "0" "6463e9c0f" "00000568" "WinSta0\Default" "0000055C" "208" "c:\users\admin\appdata\local\temp\3mswipedrivers\3m_swipe\sw00342_1_0_1" | C:\Windows\system32\DrvInst.exe | — | svchost.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Driver Installation Module Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3356 | DrvInst.exe "4" "8" "C:\Users\admin\AppData\Local\Temp\{6d2e0683-7b36-0ec5-42ce-6528cbfbf602}\ftdibus.inf" "0" "644db845f" "000004D0" "WinSta0\Default" "000002F0" "208" "c:\users\admin\appdata\local\temp\3mswipedrivers\rt_usb_drivers" | C:\Windows\system32\DrvInst.exe | svchost.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Driver Installation Module Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (3924) SwipeReaderDriversSetup64bit.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Gemalto Swipe Reader Device Drivers |
| Operation: | write | Name: | DisplayName |
Value: Gemalto Swipe Reader Device Drivers | |||
| (PID) Process: | (3924) SwipeReaderDriversSetup64bit.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Gemalto Swipe Reader Device Drivers |
| Operation: | write | Name: | UninstallString |
Value: C:\Windows\System32\SWIPER~1\UNWISE.EXE C:\Windows\System32\SWIPER~1\SwipeReader.LOG | |||
| (PID) Process: | (3924) SwipeReaderDriversSetup64bit.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
| (PID) Process: | (3924) SwipeReaderDriversSetup64bit.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 1 | |||
| (PID) Process: | (1552) DPInst.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3004) DPInst.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\Setup\SetupapiLogStatus |
| Operation: | write | Name: | setupapi.dev.log |
Value: 4096 | |||
| (PID) Process: | (3004) DPInst.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (1772) DPInst.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3060) DrvInst.exe | Key: | HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\12B\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2868) DPInst.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3924 | SwipeReaderDriversSetup64bit.exe | C:\Users\admin\AppData\Local\Temp\~GLH0000.TMP | — | |
MD5:— | SHA256:— | |||
| 3924 | SwipeReaderDriversSetup64bit.exe | C:\Windows\system32\SwipeReader\~GLH0001.TMP | — | |
MD5:— | SHA256:— | |||
| 3924 | SwipeReaderDriversSetup64bit.exe | C:\Windows\system32\~GLH0002.TMP | — | |
MD5:— | SHA256:— | |||
| 3924 | SwipeReaderDriversSetup64bit.exe | C:\Windows\system32\temp.000 | — | |
MD5:— | SHA256:— | |||
| 3924 | SwipeReaderDriversSetup64bit.exe | C:\Windows\system32\~GLH0003.TMP | — | |
MD5:— | SHA256:— | |||
| 3924 | SwipeReaderDriversSetup64bit.exe | C:\Users\admin\AppData\Local\Temp\3MSwipeDrivers\~GLH0004.TMP | — | |
MD5:— | SHA256:— | |||
| 3924 | SwipeReaderDriversSetup64bit.exe | C:\Users\admin\AppData\Local\Temp\3MSwipeDrivers\3M_Swipe\~GLH0005.TMP | — | |
MD5:— | SHA256:— | |||
| 3924 | SwipeReaderDriversSetup64bit.exe | C:\Users\admin\AppData\Local\Temp\3MSwipeDrivers\3M_Swipe\~GLH0006.TMP | — | |
MD5:— | SHA256:— | |||
| 3924 | SwipeReaderDriversSetup64bit.exe | C:\Users\admin\AppData\Local\Temp\3MSwipeDrivers\3M_Swipe\SW00342_1_0_1\~GLH0007.TMP | — | |
MD5:— | SHA256:— | |||
| 3924 | SwipeReaderDriversSetup64bit.exe | C:\Users\admin\AppData\Local\Temp\3MSwipeDrivers\3M_Swipe\SW00342_1_0_1\~GLH0008.TMP | — | |
MD5:— | SHA256:— | |||