| File name: | MSDisplay_MultiDev_v1.0.1.60.exe |
| Full analysis: | https://app.any.run/tasks/9e8669c8-33c3-49d6-b684-3f40f5d9584f |
| Verdict: | Malicious activity |
| Analysis date: | March 11, 2024, 10:06:42 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 3DCE81A37ADC36622DCF5EB2F869C1EB |
| SHA1: | D4B220E0A5E4EB0DA64FAB8C9F982DAF65118DD3 |
| SHA256: | F22255C6D52F89E94CAD7AE5E303E52A38209F2D536902DA6F9F532E7CBACE24 |
| SSDEEP: | 98304:dXfEuCQYdT8FCIuqpTd4DER3tD3L1WCCSCJAR2C4uiDLPg8CvZ1/cwWYoHwZgVtb:q3hF |
| .exe | | | Inno Setup installer (53.5) |
|---|---|---|
| .exe | | | InstallShield setup (21) |
| .exe | | | Win32 EXE PECompact compressed (generic) (20.2) |
| .exe | | | Win32 Executable (generic) (2.1) |
| .exe | | | Win16/32 Executable Delphi generic (1) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2019:04:30 03:47:23+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi |
| PEType: | PE32 |
| LinkerVersion: | 2.25 |
| CodeSize: | 679936 |
| InitializedDataSize: | 125952 |
| UninitializedDataSize: | - |
| EntryPoint: | 0xa6ed0 |
| OSVersion: | 6 |
| ImageVersion: | 6 |
| SubsystemVersion: | 6 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.0.1.60 |
| ProductVersionNumber: | 1.0.1.60 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Chinese (Simplified) |
| CharacterSet: | ASCII |
| Comments: | ´Ë°²×°³ÌÐòÓÉ Inno Setup ¹¹½¨¡£ |
| CompanyName: | MS |
| FileDescription: | MS USB Display Setup |
| FileVersion: | 1.0.1.60 |
| LegalCopyright: | Copyright © MS 2020 |
| OriginalFileName: | |
| ProductName: | MS USB Display |
| ProductVersion: | 1.0.1.60 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1040 | "C:\Program Files\MS USB Display\tool\x86\devcon.exe" dp_add "C:\Program Files\MS USB Display\lib_usb\MSUSBDisplay.inf" USB\VID_534D&PID_6021&MI_03 | C:\Program Files\MS USB Display\tool\x86\devcon.exe | MSDisplay_MultiDev_v1.0.1.60.tmp | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Setup API Exit code: 0 Version: 10.0.10586.0 (th2_release.151029-1700) Modules
| |||||||||||||||
| 1900 | "C:\Program Files\MS USB Display\WinUsbDisplay.exe" firstinstall | C:\Program Files\MS USB Display\WinUsbDisplay.exe | — | MSDisplay_MultiDev_v1.0.1.60.tmp | |||||||||||
User: admin Company: MS Integrity Level: HIGH Description: Windows USB Display Exit code: 0 Version: 1.0.1.6 Modules
| |||||||||||||||
| 2340 | DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{340e795f-f1b1-7ed3-1bd0-8e5ae69ff361}\MSUSBDisplay.inf" "0" "610771dbb" "000003F8" "WinSta0\Default" "00000550" "208" "C:\Program Files\MS USB Display\lib_usb" | C:\Windows\System32\drvinst.exe | svchost.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Driver Installation Module Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2572 | C:\Windows\system32\vssvc.exe | C:\Windows\System32\VSSVC.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft® Volume Shadow Copy Service Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2752 | "C:\Users\admin\AppData\Local\Temp\is-OK871.tmp\MSDisplay_MultiDev_v1.0.1.60.tmp" /SL5="$100130,2288616,806912,C:\Users\admin\AppData\Local\Temp\MSDisplay_MultiDev_v1.0.1.60.exe" /SPAWNWND=$17013E /NOTIFYWND=$E0170 | C:\Users\admin\AppData\Local\Temp\is-OK871.tmp\MSDisplay_MultiDev_v1.0.1.60.tmp | MSDisplay_MultiDev_v1.0.1.60.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: Setup Exit code: 0 Version: 1.0.0.0 Modules
| |||||||||||||||
| 2904 | "C:\Program Files\MS USB Display\tool\x86\devcon.exe" restart =display | C:\Program Files\MS USB Display\tool\x86\devcon.exe | — | MSDisplay_MultiDev_v1.0.1.60.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Setup API Exit code: 1 Version: 10.0.10586.0 (th2_release.151029-1700) Modules
| |||||||||||||||
| 2964 | "C:\Users\admin\AppData\Local\Temp\MSDisplay_MultiDev_v1.0.1.60.exe" /SPAWNWND=$17013E /NOTIFYWND=$E0170 | C:\Users\admin\AppData\Local\Temp\MSDisplay_MultiDev_v1.0.1.60.exe | MSDisplay_MultiDev_v1.0.1.60.tmp | ||||||||||||
User: admin Company: MS Integrity Level: HIGH Description: MS USB Display Setup Exit code: 0 Version: 1.0.1.60 Modules
| |||||||||||||||
| 3672 | "C:\Users\admin\AppData\Local\Temp\MSDisplay_MultiDev_v1.0.1.60.exe" | C:\Users\admin\AppData\Local\Temp\MSDisplay_MultiDev_v1.0.1.60.exe | explorer.exe | ||||||||||||
User: admin Company: MS Integrity Level: MEDIUM Description: MS USB Display Setup Exit code: 0 Version: 1.0.1.60 Modules
| |||||||||||||||
| 4008 | rundll32.exe C:\Windows\system32\pnpui.dll,InstallSecurityPromptRunDllW 20 Global\{17465105-6b69-38e0-f978-0454ca171166} Global\{74fe671a-a4dd-6080-988b-2827e67bf371} C:\Windows\System32\DriverStore\Temp\{41315687-1ef7-0bbb-a4ac-d0228fc01b7a}\MSUSBDisplay.inf C:\Windows\System32\DriverStore\Temp\{41315687-1ef7-0bbb-a4ac-d0228fc01b7a}\MSUSBDisplay.cat | C:\Windows\System32\rundll32.exe | — | drvinst.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows host process (Rundll32) Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 4052 | "C:\Users\admin\AppData\Local\Temp\is-75POS.tmp\MSDisplay_MultiDev_v1.0.1.60.tmp" /SL5="$E0170,2288616,806912,C:\Users\admin\AppData\Local\Temp\MSDisplay_MultiDev_v1.0.1.60.exe" | C:\Users\admin\AppData\Local\Temp\is-75POS.tmp\MSDisplay_MultiDev_v1.0.1.60.tmp | — | MSDisplay_MultiDev_v1.0.1.60.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: Setup Exit code: 0 Version: 1.0.0.0 Modules
| |||||||||||||||
| (PID) Process: | (2752) MSDisplay_MultiDev_v1.0.1.60.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | Owner |
Value: C00A0000666B78D99B73DA01 | |||
| (PID) Process: | (2752) MSDisplay_MultiDev_v1.0.1.60.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | SessionHash |
Value: 21B6EC3C63A2D43F72EC356126B4658FE1C8EE5E8739718542FF54139D1B3195 | |||
| (PID) Process: | (2752) MSDisplay_MultiDev_v1.0.1.60.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | Sequence |
Value: 1 | |||
| (PID) Process: | (2752) MSDisplay_MultiDev_v1.0.1.60.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | RegFiles0000 |
Value: C:\Program Files\MS USB Display\WinUsbDisplay.exe | |||
| (PID) Process: | (2752) MSDisplay_MultiDev_v1.0.1.60.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | RegFilesHash |
Value: 110DD1FA98514240272F711E9916E2A73955EE24EF6D1D4F72B732FF3C02AC8C | |||
| (PID) Process: | (2752) MSDisplay_MultiDev_v1.0.1.60.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run |
| Operation: | write | Name: | Windows Usb Display |
Value: C:\Program Files\MS USB Display\WinUsbDisplay.exe | |||
| (PID) Process: | (2752) MSDisplay_MultiDev_v1.0.1.60.tmp | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Hardware Profiles\0001\System\CurrentControlSet\SERVICES\dfmirage\DEVICE0 |
| Operation: | write | Name: | Attach.ToDesktop |
Value: 0 | |||
| (PID) Process: | (2752) MSDisplay_MultiDev_v1.0.1.60.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers |
| Operation: | write | Name: | C:\Program Files\MS USB Display\WinUsbDisplay.exe |
Value: HIGHDPIAWARE | |||
| (PID) Process: | (2752) MSDisplay_MultiDev_v1.0.1.60.tmp | Key: | HKEY_CURRENT_USER\Software\WinUsbDisplay\Server |
| Operation: | write | Name: | LogLevel |
Value: 1 | |||
| (PID) Process: | (2752) MSDisplay_MultiDev_v1.0.1.60.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{509DC88F-BC75-4AED-B511-9892EAD1AE48}}_is1 |
| Operation: | write | Name: | Inno Setup: Setup Version |
Value: 6.0.2 (u) | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2752 | MSDisplay_MultiDev_v1.0.1.60.tmp | C:\Program Files\MS USB Display\is-7TRMO.tmp | executable | |
MD5:7EC9CFAB450831249D70152183B3E844 | SHA256:664938FC6169E37700C45C0242006EDE97219AA0B873CC26C8DAF19647DBAA77 | |||
| 2752 | MSDisplay_MultiDev_v1.0.1.60.tmp | C:\Program Files\MS USB Display\unins000.exe | executable | |
MD5:DEF2E0EFA04057381F04119980D6D4E4 | SHA256:3E9EE9509BB992CFE08EF8605B2F10F0B633D8B26BF6D2DCC2C5D2C94F37A3D4 | |||
| 2752 | MSDisplay_MultiDev_v1.0.1.60.tmp | C:\Program Files\MS USB Display\is-MHFJP.tmp | text | |
MD5:7F4207EA1304993E8533B7A58F3A51B0 | SHA256:EE8078A7D68D5F9B702C1F5E322D67227A6512E75247D9E950D497E753C62565 | |||
| 3672 | MSDisplay_MultiDev_v1.0.1.60.exe | C:\Users\admin\AppData\Local\Temp\is-75POS.tmp\MSDisplay_MultiDev_v1.0.1.60.tmp | executable | |
MD5:7EC9CFAB450831249D70152183B3E844 | SHA256:664938FC6169E37700C45C0242006EDE97219AA0B873CC26C8DAF19647DBAA77 | |||
| 2752 | MSDisplay_MultiDev_v1.0.1.60.tmp | C:\Program Files\MS USB Display\is-Q2CD4.tmp | image | |
MD5:2098EF97358FBBDFAE0206BBCB4E2234 | SHA256:DE96747834EF6ED07618AA7EB89F643444F3BA01140EED263468C08A0B7BF8FE | |||
| 2752 | MSDisplay_MultiDev_v1.0.1.60.tmp | C:\Program Files\MS USB Display\logo.ico | image | |
MD5:2098EF97358FBBDFAE0206BBCB4E2234 | SHA256:DE96747834EF6ED07618AA7EB89F643444F3BA01140EED263468C08A0B7BF8FE | |||
| 2752 | MSDisplay_MultiDev_v1.0.1.60.tmp | C:\Program Files\MS USB Display\is-L1Q5G.tmp | executable | |
MD5:17D0F91A0F4FDC3DED309B9BE6EECE62 | SHA256:B4A4F9105A5975A7BBB6D3B03742605D82132083209E11E403226B294D753F4D | |||
| 2752 | MSDisplay_MultiDev_v1.0.1.60.tmp | C:\Program Files\MS USB Display\WinUsbDisplay.exe | executable | |
MD5:17D0F91A0F4FDC3DED309B9BE6EECE62 | SHA256:B4A4F9105A5975A7BBB6D3B03742605D82132083209E11E403226B294D753F4D | |||
| 2752 | MSDisplay_MultiDev_v1.0.1.60.tmp | C:\Program Files\MS USB Display\libusb0.dll | executable | |
MD5:6C12D8B1AA5E44AF62EFAC5A5B25C6DA | SHA256:FA16629B7C112C2A22FAD27C2D5E5867866FD49E534F4A5161F97467C09698C3 | |||
| 2752 | MSDisplay_MultiDev_v1.0.1.60.tmp | C:\Program Files\MS USB Display\is-LVPV8.tmp | executable | |
MD5:6C12D8B1AA5E44AF62EFAC5A5B25C6DA | SHA256:FA16629B7C112C2A22FAD27C2D5E5867866FD49E534F4A5161F97467C09698C3 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
— | — | 224.0.0.252:5355 | — | — | — | unknown |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |