| File name: | Realtek Audio Driver.exe |
| Full analysis: | https://app.any.run/tasks/d00fdbed-8971-4b85-a87d-9abf012afaa4 |
| Verdict: | Malicious activity |
| Analysis date: | December 24, 2023, 06:46:43 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, RAR self-extracting archive |
| MD5: | 0C7C03AEC1CB412775406FFC309928E7 |
| SHA1: | 5561B66C1B13607646569845A50E47E12725F7A3 |
| SHA256: | F8D5C6FEEA4568090BE39DBCDE0260C5DE4C47FE08598D0693981401D7E057E3 |
| SSDEEP: | 49152:t4CTss7LuO1Bq2nJ9z5RtLkLbtj8uZctFMk:+CXuiBq2BRtLWbtj8Yk |
| .exe | | | WinRAR Self Extracting archive (94.8) |
|---|---|---|
| .scr | | | Windows screen saver (2.3) |
| .dll | | | Win32 Dynamic Link Library (generic) (1.2) |
| .exe | | | Win32 Executable (generic) (0.8) |
| .exe | | | Generic Win/DOS Executable (0.3) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2008:09:16 16:17:44+02:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 5 |
| CodeSize: | 81920 |
| InitializedDataSize: | 388096 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x1000 |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 240 | "cmd.exe" | C:\Windows\System32\cmd.exe | — | rtkdriver.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 1 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 664 | "cmd.exe" | C:\Windows\System32\cmd.exe | — | rtkdriver.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 1 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 980 | "cmd.exe" | C:\Windows\System32\cmd.exe | — | rtkdriver.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 1 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 1168 | "cmd.exe" | C:\Windows\System32\cmd.exe | — | rtkdriver.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 1 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 1316 | "cmd.exe" | C:\Windows\System32\cmd.exe | — | rtkdriver.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 1 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 1388 | "cmd.exe" | C:\Windows\System32\cmd.exe | — | rtkdriver.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 1 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 1408 | "cmd.exe" | C:\Windows\System32\cmd.exe | — | rtkdriver.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 1 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 1576 | "cmd.exe" | C:\Windows\System32\cmd.exe | — | rtkdriver.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 1 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 1728 | "C:\Users\admin\Desktop\Realtek Audio Driver.exe" -el -s2 "-dC:\Program Files\Realtek" "-p" "-sp" | C:\Users\admin\Desktop\Realtek Audio Driver.exe | Realtek Audio Driver.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 1832 | "cmd.exe" | C:\Windows\System32\cmd.exe | — | rtkdriver.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 1 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| (PID) Process: | (2044) Realtek Audio Driver.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | write | Name: | ProxyEnable |
Value: 0 | |||
| (PID) Process: | (2044) Realtek Audio Driver.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections |
| Operation: | write | Name: | SavedLegacySettings |
Value: 460000005B010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (2044) Realtek Audio Driver.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (2044) Realtek Audio Driver.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (2044) Realtek Audio Driver.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (2044) Realtek Audio Driver.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (2044) Realtek Audio Driver.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (2044) Realtek Audio Driver.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (1728) Realtek Audio Driver.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (1728) Realtek Audio Driver.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1728 | Realtek Audio Driver.exe | C:\Program Files\Realtek\SetupMetrics\vshost.exe | executable | |
MD5:822CA271DF6D11ED2E80BCF3616B5238 | SHA256:02083C06381B3062F7DBA0FF30A69CD029F0DC7D6BD10E63D7F5835883CAEC9B | |||
| 1728 | Realtek Audio Driver.exe | C:\Program Files\Realtek\rtkdriver.exe | executable | |
MD5:1422FD365C017873E134A302CB608160 | SHA256:81363B99B6FB36AB2CE9C0C0CFCD27A0F3EBB7E39C50763747C6A48E04BF6DD4 | |||
| 1728 | Realtek Audio Driver.exe | C:\Program Files\Realtek\config.ini | text | |
MD5:E64CD711D68BDD11AD4AE6773E113BE3 | SHA256:1CEBC4A5FA08CD246191F75B8524F1CC63FABBAB70BA86052A65E24DB2B46313 | |||
| 1728 | Realtek Audio Driver.exe | C:\Program Files\Realtek\svchost.exe | executable | |
MD5:931137B80B392D1A8EF1DAF976076A01 | SHA256:C605C90AF10DBC8033E7F4D9AA6F999583A419D699907A14D8D72D08FFDB9E4C | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |