File name:

XVX M87 Pro Driver V1.0(2).exe

Full analysis: https://app.any.run/tasks/b8461613-4d8e-493d-9006-5f7c755f0d46
Verdict: Malicious activity
Analysis date: January 15, 2024, 16:32:44
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

714A90066C8344E4FBFBBE78DE5B842D

SHA1:

4E8A1216FDE6DDEC2A18D3965AB73B678E12D6F7

SHA256:

F80603E30328E45F54A01D4CAE1F71861B6C817A2BE15A299404330DF1366F89

SSDEEP:

98304:h+QqZ8fHRnQiaYsfImX1Ovw8iYbBlkwecXmBvQ6YMP86zEAq8lg2p5jWvMFn2wEl:hPNCIoBDo

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • XVX M87 Pro Driver V1.0(2).exe (PID: 2020)
      • XVX M87 Pro Driver V1.0(2).tmp (PID: 492)
  • SUSPICIOUS

    • Reads the Windows owner or organization settings

      • XVX M87 Pro Driver V1.0(2).tmp (PID: 492)
    • Uses TASKKILL.EXE to kill process

      • XVX M87 Pro Driver V1.0(2).tmp (PID: 492)
    • Executable content was dropped or overwritten

      • XVX M87 Pro Driver V1.0(2).tmp (PID: 492)
      • XVX M87 Pro Driver V1.0(2).exe (PID: 2020)
    • Reads the Internet Settings

      • XVX M87 Pro Driver V1.0(2).tmp (PID: 492)
    • The process drops C-runtime libraries

      • XVX M87 Pro Driver V1.0(2).tmp (PID: 492)
    • Process drops legitimate windows executable

      • XVX M87 Pro Driver V1.0(2).tmp (PID: 492)
  • INFO

    • Checks supported languages

      • XVX M87 Pro Driver V1.0(2).exe (PID: 2020)
      • XVX M87 Pro Driver V1.0(2).tmp (PID: 492)
      • DeviceDriver.exe (PID: 1848)
    • Reads the computer name

      • XVX M87 Pro Driver V1.0(2).tmp (PID: 492)
      • DeviceDriver.exe (PID: 1848)
    • Create files in a temporary directory

      • XVX M87 Pro Driver V1.0(2).exe (PID: 2020)
    • Creates files in the program directory

      • XVX M87 Pro Driver V1.0(2).tmp (PID: 492)
    • Reads the machine GUID from the registry

      • DeviceDriver.exe (PID: 1848)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (67.7)
.exe | Win32 EXE PECompact compressed (generic) (25.6)
.exe | Win32 Executable (generic) (2.7)
.exe | Win16/32 Executable Delphi generic (1.2)
.exe | Generic Win/DOS Executable (1.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2021:06:03 10:09:11+02:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 741376
InitializedDataSize: 100864
UninitializedDataSize: -
EntryPoint: 0xb5eec
OSVersion: 6
ImageVersion: 6
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 0.0.0.0
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: XVX, Inc.
FileDescription: XVX M87 Pro Driver V1.0 Setup
FileVersion:
LegalCopyright:
OriginalFileName:
ProductName: XVX M87 Pro Driver V1.0
ProductVersion: V1.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
43
Monitored processes
5
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start xvx m87 pro driver v1.0(2).exe xvx m87 pro driver v1.0(2).tmp taskkill.exe no specs devicedriver.exe no specs xvx m87 pro driver v1.0(2).exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
492"C:\Users\admin\AppData\Local\Temp\is-HRVAQ.tmp\XVX M87 Pro Driver V1.0(2).tmp" /SL5="$401AA,6541054,843264,C:\Users\admin\AppData\Local\Temp\XVX M87 Pro Driver V1.0(2).exe" C:\Users\admin\AppData\Local\Temp\is-HRVAQ.tmp\XVX M87 Pro Driver V1.0(2).tmp
XVX M87 Pro Driver V1.0(2).exe
User:
admin
Company:
XVX, Inc.
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-hrvaq.tmp\xvx m87 pro driver v1.0(2).tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
784"C:\Windows\System32\taskkill.exe" /f /im DeviceDriver.exeC:\Windows\System32\taskkill.exeXVX M87 Pro Driver V1.0(2).tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Terminates Processes
Exit code:
128
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
1848"C:\Program Files\XVX M87 Pro Driver V1.0\DeviceDriver.exe"C:\Program Files\XVX M87 Pro Driver V1.0\DeviceDriver.exeXVX M87 Pro Driver V1.0(2).tmp
User:
admin
Integrity Level:
HIGH
Exit code:
0
Version:
1.0.1.2
Modules
Images
c:\program files\xvx m87 pro driver v1.0\devicedriver.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
2020"C:\Users\admin\AppData\Local\Temp\XVX M87 Pro Driver V1.0(2).exe" C:\Users\admin\AppData\Local\Temp\XVX M87 Pro Driver V1.0(2).exe
explorer.exe
User:
admin
Company:
XVX, Inc.
Integrity Level:
HIGH
Description:
XVX M87 Pro Driver V1.0 Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\appdata\local\temp\xvx m87 pro driver v1.0(2).exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2036"C:\Users\admin\AppData\Local\Temp\XVX M87 Pro Driver V1.0(2).exe" C:\Users\admin\AppData\Local\Temp\XVX M87 Pro Driver V1.0(2).exeexplorer.exe
User:
admin
Company:
XVX, Inc.
Integrity Level:
MEDIUM
Description:
XVX M87 Pro Driver V1.0 Setup
Exit code:
3221226540
Version:
Modules
Images
c:\users\admin\appdata\local\temp\xvx m87 pro driver v1.0(2).exe
c:\windows\system32\ntdll.dll
Total events
575
Read events
560
Write events
9
Delete events
6

Modification events

(PID) Process:(492) XVX M87 Pro Driver V1.0(2).tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(492) XVX M87 Pro Driver V1.0(2).tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(492) XVX M87 Pro Driver V1.0(2).tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(492) XVX M87 Pro Driver V1.0(2).tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(492) XVX M87 Pro Driver V1.0(2).tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
Operation:writeName:GlobalAssocChangedCounter
Value:
115
(PID) Process:(492) XVX M87 Pro Driver V1.0(2).tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:RegFilesHash
Value:
F587A2FA2BA4AD3FABA93CE17D65F44D2625C3B59FEBC592E28E116AF75AE9FF
(PID) Process:(492) XVX M87 Pro Driver V1.0(2).tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:RegFiles0000
Value:
C:\Program Files\XVX M87 Pro Driver V1.0\DeviceDriver.exe
(PID) Process:(492) XVX M87 Pro Driver V1.0(2).tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:Sequence
Value:
1
(PID) Process:(492) XVX M87 Pro Driver V1.0(2).tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:SessionHash
Value:
7813F15F252AAFE27B20B167B72A3A6442CFDECEFC5E065C56D0DE4AA53A99EB
(PID) Process:(492) XVX M87 Pro Driver V1.0(2).tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:Owner
Value:
EC010000AC9DDF7DD047DA01
Executable files
17
Suspicious files
10
Text files
288
Unknown types
0

Dropped files

PID
Process
Filename
Type
492XVX M87 Pro Driver V1.0(2).tmpC:\Program Files\XVX M87 Pro Driver V1.0\is-KGT6S.tmpexecutable
MD5:C56C25D42B9826842393E570AD9B0DBC
SHA256:5DA1CA0A2520F991B147158B635F5FACC0DBF64D9CB601236CDB3E72B069DFB9
2020XVX M87 Pro Driver V1.0(2).exeC:\Users\admin\AppData\Local\Temp\is-HRVAQ.tmp\XVX M87 Pro Driver V1.0(2).tmpexecutable
MD5:AB635A71EAA2824419825AF9800E1D19
SHA256:F17F5BCB745D07327E499B3BCD9946DA05B4621A26C3CF64B3E4D400AE668D04
492XVX M87 Pro Driver V1.0(2).tmpC:\Program Files\XVX M87 Pro Driver V1.0\DeviceDriver.exeexecutable
MD5:3219B97B74BDF63E3C263223D5D71790
SHA256:74748FFE6CE0811A1B958E6800132674343DF1087FC0C1FA8BE223E42BE49838
492XVX M87 Pro Driver V1.0(2).tmpC:\Program Files\XVX M87 Pro Driver V1.0\is-G9J88.tmpexecutable
MD5:3219B97B74BDF63E3C263223D5D71790
SHA256:74748FFE6CE0811A1B958E6800132674343DF1087FC0C1FA8BE223E42BE49838
492XVX M87 Pro Driver V1.0(2).tmpC:\Program Files\XVX M87 Pro Driver V1.0\is-1NJKV.tmpexecutable
MD5:3219B97B74BDF63E3C263223D5D71790
SHA256:74748FFE6CE0811A1B958E6800132674343DF1087FC0C1FA8BE223E42BE49838
492XVX M87 Pro Driver V1.0(2).tmpC:\Program Files\XVX M87 Pro Driver V1.0\is-UCU5H.tmpexecutable
MD5:BFB60035E942B8F233644E58E00C6622
SHA256:509BA971EB97651AE6FA07B8B2278C932BE49F6014120CC20DDF7BC601CE5854
492XVX M87 Pro Driver V1.0(2).tmpC:\Program Files\XVX M87 Pro Driver V1.0\is-GDHBP.tmpexecutable
MD5:B6AE2ADC46F9DF57C0E8D7C6B59BAF74
SHA256:5A8065893CDB9B68D1BB730585A3B0310E394BA6BFFDD036C92690E6EA78B5DC
492XVX M87 Pro Driver V1.0(2).tmpC:\Program Files\XVX M87 Pro Driver V1.0\mfc140u.dllexecutable
MD5:40472886D1E76C78A0C0F615FE422FBC
SHA256:9B62DD0681A0200190FEF394A8719E4E0F62BE7DDBDD07C81C730E98FDA972F0
492XVX M87 Pro Driver V1.0(2).tmpC:\Program Files\XVX M87 Pro Driver V1.0\KeyboardLayout.xmlxml
MD5:2AA109199A22FE76BAF1FE99BCD68E2F
SHA256:4DFDB441F510F8F8970592AA3CC0F0067570EDF6DFE6035070492CC5A291BB9B
492XVX M87 Pro Driver V1.0(2).tmpC:\Program Files\XVX M87 Pro Driver V1.0\msvcp140.dllexecutable
MD5:B6AE2ADC46F9DF57C0E8D7C6B59BAF74
SHA256:5A8065893CDB9B68D1BB730585A3B0310E394BA6BFFDD036C92690E6EA78B5DC
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
whitelisted

DNS requests

No data

Threats

No threats detected
No debug info