Click to jump to signature section
Source: USB-DRIVERS-ALL-11-14-13.exe | Static PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE |
Source: USB-DRIVERS-ALL-11-14-13.exe | Static PE information: DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE |
Source: | Binary string: c:\develo~1\cdm2_2_4\pp\ftserui2\objfre_wnet_amd64\amd64\ftserui2.pdb source: ftserui2.dll |
Source: | Binary string: C:\DEVELO~1\ftdi.whq\BUS\objfre\i386\ftdibus.pdb source: ftdibus.sys |
Source: | Binary string: c:\develo~1\cdm2_2_4\devices\ftser2k\objfre_wnet_x86\i386\ftser2k.pdb_ source: ftser2k.sys |
Source: | Binary string: c:\dev\development\fixedfunction\cp210x\drivers\vcp\windows_2k_xp_s2k3_vista_7\objfre_wnet_amd64\amd64\silabser.pdb source: silabser.sys |
Source: | Binary string: c:\develo~1\cdm2_2_4\devices\ftser2k\objfre_wnet_amd64\amd64\ftser2k.pdb source: ftser2k.sys |
Source: | Binary string: c:\develo~1\cdm2_2_4\coinst\ftcserco\objfre_wnet_amd64\amd64\ftcserco.pdb source: ftcserco.dll |
Source: | Binary string: c:\Development\cdm2_2_4\FTBUSUI\x64\Release\FTBUSUI.pdb source: ftbusui.dll |
Source: | Binary string: c:\Development\cdm2_2_4\FTBUSUI\x64\Release\FTBUSUI.pdb! source: ftbusui.dll |
Source: | Binary string: C:\Development\Windows\PropertyPage\objfre\i386\ftserui2.pdb source: ftserui2.dll |
Source: | Binary string: c:\develo~1\cdm2_2_4\d2xx\d2xx\objfre_wnet_amd64\amd64\FTDIBUS.pdb source: ftdibus.sys |
Source: | Binary string: c:\develo~1\cdm2_2_4\coinst\ftcserco\objfre_wnet_x86\i386\ftcserco.pdb source: ftcserco.dll |
Source: | Binary string: c:\Development\cdm2_2_4\FTLang\Release\FTLang.pdbp* source: ftlang.dll |
Source: | Binary string: c:\develo~1\cdm2_2_4\d2xx\d2xx\objfre_wnet_x86\i386\FTDIBUS.pdb-o source: ftdibus.sys |
Source: | Binary string: C:\98DDK\src\ftdi.800\FTSERMOU\obj\i386\ftsermou.pdb source: FTSERMOU.VXD |
Source: | Binary string: DpInst.pdb source: CP210xVCPInstaller_32_Bit.exe, CP210xVCPInstaller_64_Bit.exe |
Source: | Binary string: DpInst.pdbp source: CP210xVCPInstaller_32_Bit.exe |
Source: | Binary string: WdfCoInstaller01009.pdbE3 source: WdfCoInstaller01009.dll |
Source: | Binary string: c:\develo~1\cdm2_2_4\d2xx\d2xx\objfre_wnet_x86\i386\FTDIBUS.pdb source: ftdibus.sys |
Source: | Binary string: c:\Development\cdm2_2_4\FTLang\Release\FTLang.pdb source: ftlang.dll |
Source: | Binary string: WdfCoInstaller01009.pdb source: WdfCoInstaller01009.dll |
Source: | Binary string: C:\DEVELO~1\ftdi.whq\DEVICES\SERIAL\objfre\i386\ftser2k.pdb source: ftser2k.sys |
Source: | Binary string: c:\dev\development\fixedfunction\cp210x\drivers\serialenumerationfilter\windows_xp_s2k3_vista_7\objfre_wnet_amd64\amd64\silabenm.pdb source: silabenm.sys |
Source: | Binary string: c:\develo~1\cdm2_2_4\devices\ftser2k\objfre_wnet_x86\i386\ftser2k.pdb source: ftser2k.sys |
Source: | Binary string: c:\develo~1\cdm2_2_4\pp\ftserui2\objfre_wnet_amd64\amd64\ftserui2.pdbH source: ftserui2.dll |
Source: | Binary string: c:\Development\cdm2_2_4\d2xxdll\x64\Release\FTD2XX64.pdb source: ftd2xx64.dll |
Source: | Binary string: c:\Development\cdm2_2_4\d2xxdll\Release\FTD2XX.pdb source: ftd2xx.dll |
Source: | Binary string: DpInst.pdbH source: CP210xVCPInstaller_64_Bit.exe |
Source: | Binary string: c:\develo~1\cdm2_2_4\pp\ftserui2\objfre_wnet_x86\i386\ftserui2.pdb source: ftserui2.dll |
Source: | Binary string: c:\dev\development\fixedfunction\cp210x\drivers\serialenumerationfilter\windows_xp_s2k3_vista_7\objchk_wxp_x86\i386\silabenm.pdb source: silabenm.sys |
Source: | Binary string: c:\develo~1\cdm2_2_4\coinst\ftcserco\objfre_wnet_amd64\amd64\ftcserco.pdbH source: ftcserco.dll |
Source: | Binary string: c:\dev\development\fixedfunction\cp210x\drivers\vcp\windows_2k_xp_s2k3_vista_7\objfre_wxp_x86\i386\silabser.pdb source: silabser.sys |
Source: | Binary string: c:\Development\cdm2_2_4\FTLang\x64\Release\FTLang.pdb source: ftlang.dll |
Source: | Binary string: c:\Development\cdm2_2_4\FTBUSUI\Release\FTBUSUI.pdb source: ftbusui.dll |
Source: Network traffic | Suricata IDS: 2022930 - Severity 1 - ET EXPLOIT Possible CVE-2016-2211 Symantec Cab Parsing Buffer Overflow : 52.149.20.212:443 -> 192.168.2.5:49704 |
Source: Network traffic | Suricata IDS: 2022930 - Severity 1 - ET EXPLOIT Possible CVE-2016-2211 Symantec Cab Parsing Buffer Overflow : 52.149.20.212:443 -> 192.168.2.5:49911 |
Source: USB_FTDI_Setup.exe | String found in binary or memory: http://nsis.sf.net/NSIS_Error |
Source: USB_FTDI_Setup.exe | String found in binary or memory: http://nsis.sf.net/NSIS_ErrorError |
Source: USB-DRIVERS-ALL-11-14-13.exe | String found in binary or memory: http://www.winzip.com |
Source: USB-DRIVERS-ALL-11-14-13.exe | Static PE information: Resource name: RT_STRING type: MIPSEB-LE MIPS-II ECOFF executable not stripped - version 0.101 |
Source: USB-DRIVERS-ALL-11-14-13.exe | Static PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE |
Source: FTSERIAL.SYS | Binary string: \Device\Ftdiport_Com_0\FTDIBUS\FTDIBUS&VID_0403+PID_8373+F0000000A&0000U |
Source: ftdibus.sys | Binary string: ParentIdPrefixCompositeSubKeyCompositeDriverInterface\Registry\Machine\SYSTEM\CurrentControlSet\Enum\USBPID_FTDIBUS\VID_&PID_FTDIBUS\COMPORT&VID_FTDIBUS\0000\DosDevices\Ftdiport_Com_0\Device\Ftdiport_Com_0\COMPortNameENUM\0000Enum\FriendlyName) (DeviceDescRtlIsNtDdiVersionAvailable |
Source: FTSERIAL.SYS | Binary string: \DosDevices\FTSERI-0\Device\FTSERI-0U |
Source: silabser.sys | Binary string: \Device\Silabser |
Source: ftdibus.sys | Binary string: \Device\Ftdiport_Com_0 |
Source: ftser2k.sys | Binary string: \Device\VCP |
Source: ftser2k.sys | Binary string: @\Device\VCPU |
Source: ftdibus.sys | Binary string: \Device\FTE2USB0\REGISTRY\Machine\System\CurrentControlSet\SERVICES\FTDIBUS\ParametersU |
Source: silabser.sys | Binary string: SerialRelinquishPowerPolicy%ws%d\Device\Silabser-->SerialEvtDeviceAdd |
Source: FTSERIAL.SYS | Binary string: \Device\FTSERI-0U |
Source: ftdibus.sys | Binary string: \Device\Ftdiport_Com_0\DosDevices\Ftdiport_Com_0AFTDIBUS\0000U |
Source: FTSERIAL.SYS | Binary string: \Device\Ftdiport_Com_0\FTDIBUS\1111U |
Source: ftser2k.sys | Binary string: EmulationModeLatencyTimerTerminateDelayMinWriteTimeoutMinReadTimeoutTxBufferRxBufferConfigDataSERIALCOMMDosDevices\IdentifierPortNameSerialSkipExternalNaming\Device\VCPSerialRelinquishPowerPolicy*PNP0501*PNP0502MultiportDevice |
Source: classification engine | Classification label: clean1.winEXE@1/0@0/0 |
Source: USB-DRIVERS-ALL-11-14-13.exe | Static PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
Source: C:\Users\user\Desktop\USB-DRIVERS-ALL-11-14-13.exe | File read: C:\Users\user\Desktop\desktop.ini | Jump to behavior |
Source: C:\Users\user\Desktop\USB-DRIVERS-ALL-11-14-13.exe | Key opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers | Jump to behavior |
Source: CP210xVCPInstaller_32_Bit.exe | String found in binary or memory: ERROR: (Error code 0x%X.) (Error code 0x%X: %s)%02d/%02d/%04d %02d:%02d:%02dNon-Interactive Windows StationInteractive Windows StationFailed to check if running under Local System AccountRunning under Local System AccountArchitecture: X86.Suite: 0x%04x, Product Type: %uService Pack: %u.%uPlatform ID: %u (%s)9XNTVersion: %u.%u.%u %sProduct Version %s.****************************************Failed to delete 'Add or Remove Programs' entry '%s'.User cancelled uninstall of driver package '%s'Access denied to Non-admin user to install/uninstall driver package.System requires 64-bit version of DPInst.exe.DPInst.exe not supported on current OS.Requested language 0x%X is not supported on current systemDescriptor (DPInst.xml) does not support requested language 0x%X.Will read descriptor(DPInst.xml) elements in language 0x%X, but some or all of the other elements might be in the UI default language 0x%X.Will read descriptor(DPInst.xml) elements in language 0x%X.Running with language 0x%X.Current configuration does not support UI language 0x%X.Will enable language 0x%X although not listed in descriptor.User UI Language is 0x%X.Invalid path '%ws'Install option set: using scan hardware display mode. Will only display successfull installs or failures.Install option set: test wizard cycling through all finish pages.Install option set: uninstall will be set to delete driver binaries.Install option set: Install all driver packages or none.Install option set: Suppress Add or Remove Programs entries.Install option set: Suppress pre-install of Plug and Play drivers if no matching devices are present.Install option set: Force install if driver is not better.Install option set: Prompt if driver is not better.Install option set: create user uninstall script file '%s'.Install option set: Suppressing EULA.Install option set: legacy mode on.Install option set: Running in quiet mode. Suppressing Wizard and OS popups.Install option set: Suppressing Wizard but no OS popups.Install option refused: can't test wizard because quiet mode enabled.Install option refused: 'Scan Hardware Display' will be ignored because not running in 'Scan Hardware Mode'.Install option refused: Can't run in Quiet mode, UI will be shown because a EULA is required and not suppressed!Install option refused: Can't run in Quiet mode, command to prompt user in case driver is not better is set!Install option refused: will not force install if driver is not better because of command to |