| File name: | Splashtop_Wired_XDisplay_Agent_v1.5.8.3.exe |
| Full analysis: | https://app.any.run/tasks/da1e5c1b-5055-4e54-913f-28608e340ded |
| Verdict: | Malicious activity |
| Analysis date: | February 16, 2024, 14:34:20 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 961795E6F576C203ACF26756248B1061 |
| SHA1: | 2A1EBF419DE2B5B5E4B7F34BFB9C4FBEB2A060F2 |
| SHA256: | FB7D9A5CF6AE1B52786827AB9357062EC5A7A9B49D1FAAAAEBC4B2E2B1C5F182 |
| SSDEEP: | 196608:BozgrggXBBj7QlBWIf+qivj62uKjMaaEusDCB3djS/YP0IAHIWyfuEZLNjdT1c/N:KgkgMMyXivjCKbavsDM3qqFAoW6uEZJ2 |
| .exe | | | NSIS - Nullsoft Scriptable Install System (61.2) |
|---|---|---|
| .ax | | | DirectShow filter (14.5) |
| .exe | | | Win32 EXE PECompact compressed (v2.x) (4.2) |
| .exe | | | InstallShield setup (3.1) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2020:12:14 15:13:03+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 9 |
| CodeSize: | 158720 |
| InitializedDataSize: | 219136 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x105b2 |
| OSVersion: | 5 |
| ImageVersion: | - |
| SubsystemVersion: | 5 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.58.9.6924 |
| ProductVersionNumber: | 1.5.8.3 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Windows, Latin1 |
| CompanyName: | Splashtop Inc. |
| FileDescription: | Splashtop® Wired XDisplay Agent |
| FileVersion: | 1.58.9.6924 |
| LegalCopyright: | Copyright © Splashtop Inc. All Rights Reserved. |
| ProductName: | Splashtop® Wired XDisplay - Extend & Mirror |
| ProductVersion: | 1.5.8.3 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 316 | rundll32 x86\my_setup.dll do_install_lci_proxywddm | C:\Windows\System32\rundll32.exe | cmd.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows host process (Rundll32) Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1040 | C:\Windows\system32\vssvc.exe | C:\Windows\System32\VSSVC.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft® Volume Shadow Copy Service Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1776 | "C:\Windows\System32\cmd.exe" /c run.bat > C:\Users\admin\AppData\Local\Temp\unpack.log.txt | C:\Windows\System32\cmd.exe | — | Splashtop_Wired_XDisplay_Agent_v1.5.8.3.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 1816 | "C:\Windows\System32\cmd.exe" /c "C:\Program Files\Splashtop\Splashtop Wired XDisplay\Agent\Driver\install.bat" | C:\Windows\System32\cmd.exe | — | SWXDAgent.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 2176 | C:\Windows\system32\cmd.exe /c ver | C:\Windows\System32\cmd.exe | — | cmd.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 2376 | DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{54554f6a-55e8-3def-6bf5-2b25873b4a7a}\lci_proxywddm.inf" "0" "6a8a251e7" "000003EC" "WinSta0\Default" "000005C8" "208" "c:\program files\splashtop\splashtop wired xdisplay\agent\driver\win7" | C:\Windows\System32\drvinst.exe | svchost.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Driver Installation Module Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2592 | "C:\Program Files\Splashtop\Splashtop Software Updater\SSUService.exe" | C:\Program Files\Splashtop\Splashtop Software Updater\SSUService.exe | services.exe | ||||||||||||
User: SYSTEM Company: Splashtop Inc. Integrity Level: SYSTEM Description: Splashtop Software Updater Service Exit code: 0 Version: 1.5.5.7 Modules
| |||||||||||||||
| 2668 | timeout /t 2 /nobreak | C:\Windows\System32\timeout.exe | — | cmd.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: timeout - pauses command processing Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3216 | "C:\Users\admin\AppData\Local\Temp\Splashtop_Wired_XDisplay_Agent_v1.5.8.3.exe" | C:\Users\admin\AppData\Local\Temp\Splashtop_Wired_XDisplay_Agent_v1.5.8.3.exe | explorer.exe | ||||||||||||
User: admin Company: Splashtop Inc. Integrity Level: HIGH Description: Splashtop® Wired XDisplay Agent Exit code: 0 Version: 1.58.9.6924 Modules
| |||||||||||||||
| 3240 | "C:\Users\admin\AppData\Local\Temp\Splashtop_Wired_XDisplay_Agent_v1.5.8.3.exe" | C:\Users\admin\AppData\Local\Temp\Splashtop_Wired_XDisplay_Agent_v1.5.8.3.exe | — | explorer.exe | |||||||||||
User: admin Company: Splashtop Inc. Integrity Level: MEDIUM Description: Splashtop® Wired XDisplay Agent Exit code: 3221226540 Version: 1.58.9.6924 Modules
| |||||||||||||||
| (PID) Process: | (3216) Splashtop_Wired_XDisplay_Agent_v1.5.8.3.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (3216) Splashtop_Wired_XDisplay_Agent_v1.5.8.3.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (3216) Splashtop_Wired_XDisplay_Agent_v1.5.8.3.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (3216) Splashtop_Wired_XDisplay_Agent_v1.5.8.3.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (1040) VSSVC.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 40000000000000008AFFF440E560DA01100400008C090000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (1040) VSSVC.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 40000000000000008AFFF440E560DA0110040000400A0000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (1040) VSSVC.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 40000000000000008AFFF440E560DA01100400002C070000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (1040) VSSVC.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\ASR Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 40000000000000008AFFF440E560DA0110040000B8080000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (1040) VSSVC.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer |
| Operation: | write | Name: | IDENTIFY (Leave) |
Value: 40000000000000008AFFF440E560DA0110040000400A0000E8030000000000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (1040) VSSVC.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer |
| Operation: | write | Name: | IDENTIFY (Leave) |
Value: 4000000000000000E461F740E560DA01100400002C070000E8030000000000000100000000000000000000000000000000000000000000000000000000000000 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3216 | Splashtop_Wired_XDisplay_Agent_v1.5.8.3.exe | C:\Users\admin\AppData\Local\Temp\unpack\setup.msi | — | |
MD5:— | SHA256:— | |||
| 3216 | Splashtop_Wired_XDisplay_Agent_v1.5.8.3.exe | C:\Users\admin\AppData\Local\Temp\unpack\setup.ini | ini | |
MD5:CE3FB3221DF283E1B86F1D6E448907F7 | SHA256:253D4FECB0901274851EC461A555A5AB4CCB2718EFB1E4650AD8FAC63F4A3C1E | |||
| 316 | rundll32.exe | C:\Windows\INF\setupapi.app.log | text | |
MD5:E4346E25AB358B690CFAF2214D06C93A | SHA256:4C1A346A546C9959EE88BB9ECB0FB2213816EC39A6DDD05DF794035158C5F8AD | |||
| 3216 | Splashtop_Wired_XDisplay_Agent_v1.5.8.3.exe | C:\Users\admin\AppData\Local\Temp\unpack.log | ini | |
MD5:5067C73CCBDA05A46C053C8400E4F8DC | SHA256:DF11BEB94DA313F968D35F242E1295B38C9A8751CB7FD6D30D3A6640B6E4FA19 | |||
| 3848 | PreVerCheck.exe | C:\Users\admin\AppData\Local\Temp\PreVerC.log | ini | |
MD5:54C89E01C24718DDBB57420B555F5C42 | SHA256:6680A9F39B5A433E32BEA4475902CBA5E443DE543DFAA95D2A49513EF82D3D69 | |||
| 2376 | drvinst.exe | C:\Windows\System32\DriverStore\Temp\{78164d54-2cb9-2378-7068-07442bbde212}\x86\lci_proxyumd.dll | executable | |
MD5:F67D8A541D407C6886D6358248014B8E | SHA256:919ACBEDDCBFE27D12EE44ECD38044D880A68622D7BC412FF81B089746C79E5F | |||
| 2376 | drvinst.exe | C:\Windows\System32\DriverStore\Temp\{78164d54-2cb9-2378-7068-07442bbde212}\x86\SET44E4.tmp | executable | |
MD5:F67D8A541D407C6886D6358248014B8E | SHA256:919ACBEDDCBFE27D12EE44ECD38044D880A68622D7BC412FF81B089746C79E5F | |||
| 2376 | drvinst.exe | C:\Windows\System32\DriverStore\Temp\{78164d54-2cb9-2378-7068-07442bbde212}\x86\SET44E5.tmp | executable | |
MD5:B36B39A2AA5C15D0167A7D8454AE71A6 | SHA256:01871A132386F81DFD4894E9DAEB9433C4BE2A99EBE8FEC954E5182A43E96AF0 | |||
| 316 | rundll32.exe | C:\Users\admin\AppData\Local\Temp\{54554f6a-55e8-3def-6bf5-2b25873b4a7a}\SET4498.tmp | binary | |
MD5:07DC873615C74141FB8A646F6FE1D378 | SHA256:F97F4A79BF9ACB0D7FFB257CB3E16687F6281B8687C79361B680764F3427EF61 | |||
| 316 | rundll32.exe | C:\Users\admin\AppData\Local\Temp\{54554f6a-55e8-3def-6bf5-2b25873b4a7a}\x86\lci_proxywddm.sys | executable | |
MD5:B36B39A2AA5C15D0167A7D8454AE71A6 | SHA256:01871A132386F81DFD4894E9DAEB9433C4BE2A99EBE8FEC954E5182A43E96AF0 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2592 | SSUService.exe | GET | 301 | 107.23.150.199:80 | http://sn.splashtop.com/file_system/apt_repository/dists/ProtoSSU01/released/binary-i386/Packages.gz | unknown | html | 134 b | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
2592 | SSUService.exe | 107.23.150.199:80 | sn.splashtop.com | AMAZON-AES | US | unknown |
2592 | SSUService.exe | 107.23.150.199:443 | sn.splashtop.com | AMAZON-AES | US | unknown |
2592 | SSUService.exe | 107.22.247.100:80 | ds1.devicevm.com | AMAZON-AES | US | unknown |
Domain | IP | Reputation |
|---|---|---|
sn.splashtop.com |
| unknown |
ds1.devicevm.com |
| unknown |
dns.msftncsi.com |
| shared |
PID | Process | Class | Message |
|---|---|---|---|
1080 | svchost.exe | Misc activity | ET INFO Splashtop Domain in DNS Lookup (splashtop .com) |
2592 | SSUService.exe | Misc activity | ET INFO Splashtop Domain (splashtop .com) in TLS SNI |
Process | Message |
|---|---|
Splashtop_Wired_XDisplay_Agent_v1.5.8.3.exe | [3216]2024-02-16 14:34:30 [CUtility::OSInfo] OS 6.1(7601) Service Pack 1 x64:0 Err:0 |
Splashtop_Wired_XDisplay_Agent_v1.5.8.3.exe | [3216]2024-02-16 14:34:30 [CUnPack::FindHeader] Name:C:\Users\admin\AppData\Local\Temp\Splashtop_Wired_XDisplay_Agent_v1.5.8.3.exe Err:0 |
Splashtop_Wired_XDisplay_Agent_v1.5.8.3.exe | [3216]2024-02-16 14:34:30 [CUnPack::FindHeader] Sign Size:6096 Err:0 |
Splashtop_Wired_XDisplay_Agent_v1.5.8.3.exe | [3216]2024-02-16 14:34:30 [CUnPack::FindHeader] Header offset:378880 Err:183 |
Splashtop_Wired_XDisplay_Agent_v1.5.8.3.exe | [3216]2024-02-16 14:34:30 [CUnPack::UnPackFiles] FreeSpace:232989581312 FileSize:11297280 Err:0 |
Splashtop_Wired_XDisplay_Agent_v1.5.8.3.exe | [3216]2024-02-16 14:34:30 [CUnPack::UnPackFiles] (1/4)UnPack file name:C:\Users\admin\AppData\Local\Temp\unpack\setup.msi (11297280) Err:2 |
Splashtop_Wired_XDisplay_Agent_v1.5.8.3.exe | [3216]2024-02-16 14:34:31 [CUnPack::UnPackFiles] UnPack count:1 len:11297280 File:(null) Err:0 |
Splashtop_Wired_XDisplay_Agent_v1.5.8.3.exe | [3216]2024-02-16 14:34:31 [CUnPack::UnPackFiles] FreeSpace:232978280448 FileSize:15 Err:183 |
Splashtop_Wired_XDisplay_Agent_v1.5.8.3.exe | [3216]2024-02-16 14:34:31 [CUnPack::UnPackFiles] (2/4)UnPack file name:C:\Users\admin\AppData\Local\Temp\unpack\run.bat (15) Err:122 |
Splashtop_Wired_XDisplay_Agent_v1.5.8.3.exe | [3216]2024-02-16 14:34:31 [CUnPack::UnPackFiles] UnPack count:2 len:15 File:(null) Err:0 |