File name:

sp39427.exe

Full analysis: https://app.any.run/tasks/3b99f53c-8e7e-4a91-bd52-800441d2a79a
Verdict: Malicious activity
Analysis date: February 08, 2024, 13:22:06
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

BD9FA12C682EC0D17C8CB2AB7D91496D

SHA1:

26916C420D4797D64478164D19A5133F3C64DBB7

SHA256:

02B8FAAFAC85954F9D9C93A04D34A8066B4F209E64123674FD3F642C89D5AC24

SSDEEP:

98304:ygH3Vu6zQF21aU7lv3c3LkWmpKdW6VG50dghttS7zQW1gpYqM0BES9Fqd5l4TVUB:JHMHEO

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • sp39427.exe (PID: 1408)
  • SUSPICIOUS

    • Reads the Internet Settings

      • Firmwareupdate.exe (PID: 3244)
      • sipnotify.exe (PID: 1160)
    • Executable content was dropped or overwritten

      • sp39427.exe (PID: 1408)
    • The process executes via Task Scheduler

      • ctfmon.exe (PID: 1940)
      • sipnotify.exe (PID: 1160)
    • Reads settings of System Certificates

      • sipnotify.exe (PID: 1160)
  • INFO

    • Reads the computer name

      • Firmwareupdate.exe (PID: 3244)
      • IMEKLMG.EXE (PID: 2136)
      • IMEKLMG.EXE (PID: 2144)
    • Checks supported languages

      • sp39427.exe (PID: 1408)
      • Firmwareupdate.exe (PID: 3244)
      • floppy.exe (PID: 2508)
      • HPUSBFW.exe (PID: 3540)
      • IMEKLMG.EXE (PID: 2136)
      • IMEKLMG.EXE (PID: 2144)
    • Create files in a temporary directory

      • sp39427.exe (PID: 1408)
    • Application launched itself

      • msedge.exe (PID: 2944)
      • msedge.exe (PID: 3748)
    • Manual execution by a user

      • msedge.exe (PID: 3748)
      • IMEKLMG.EXE (PID: 2144)
      • IMEKLMG.EXE (PID: 2136)
    • Process checks whether UAC notifications are on

      • IMEKLMG.EXE (PID: 2144)
      • IMEKLMG.EXE (PID: 2136)
    • Reads security settings of Internet Explorer

      • sipnotify.exe (PID: 1160)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | InstallShield setup (36.8)
.exe | Win32 Executable MS Visual C++ (generic) (26.6)
.exe | Win64 Executable (generic) (23.6)
.dll | Win32 Dynamic Link Library (generic) (5.6)
.exe | Win32 Executable (generic) (3.8)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2001:08:29 23:22:49+02:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 73728
InitializedDataSize: 212992
UninitializedDataSize: -
EntryPoint: 0x8927
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 4.0.100.1189
ProductVersionNumber: 4.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
Comments:
CompanyName: Hewlett-Packard Company
FileDescription:
InternalName: stub32
OriginalFileName: stub32i.exe
FileVersion:
LegalCopyright:
ProductName: Rompaq for hp Notebooks
ProductVersion:
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
111
Monitored processes
33
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start sp39427.exe firmwareupdate.exe no specs floppy.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs winrar.exe no specs hpusbfw.exe msedge.exe no specs msedge.exe no specs ctfmon.exe no specs sipnotify.exe imeklmg.exe no specs imeklmg.exe no specs sp39427.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
120"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=asset_store.mojom.AssetStoreService --lang=en-US --service-sandbox-type=asset_store_service --mojo-platform-channel-handle=3324 --field-trial-handle=1396,i,9385248801352219384,9734123908998738035,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
492"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=4460 --field-trial-handle=1396,i,9385248801352219384,9734123908998738035,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1160C:\Windows\system32\sipnotify.exe -LogonOrUnlockC:\Windows\System32\sipnotify.exe
taskeng.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
sipnotify
Exit code:
0
Version:
6.1.7602.20480 (win7sp1_ldr_escrow.191010-1716)
Modules
Images
c:\windows\system32\sipnotify.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1220"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1312 --field-trial-handle=1396,i,9385248801352219384,9734123908998738035,131072 /prefetch:2C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1264"C:\Users\admin\Desktop\sp39427.exe" C:\Users\admin\Desktop\sp39427.exeexplorer.exe
User:
admin
Company:
Hewlett-Packard Company
Integrity Level:
MEDIUM
Description:
Exit code:
3221226540
Version:
Modules
Images
c:\users\admin\desktop\sp39427.exe
c:\windows\system32\ntdll.dll
1408"C:\Users\admin\Desktop\sp39427.exe" C:\Users\admin\Desktop\sp39427.exe
explorer.exe
User:
admin
Company:
Hewlett-Packard Company
Integrity Level:
HIGH
Description:
Exit code:
1073807364
Version:
Modules
Images
c:\users\admin\desktop\sp39427.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
1940C:\Windows\System32\ctfmon.exe C:\Windows\System32\ctfmon.exetaskeng.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
CTF Loader
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ctfmon.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msctfmonitor.dll
c:\windows\system32\msctf.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
2064"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3572 --field-trial-handle=1396,i,9385248801352219384,9734123908998738035,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2072"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=edge_collections.mojom.CollectionsDataManager --lang=en-US --service-sandbox-type=collections --mojo-platform-channel-handle=2812 --field-trial-handle=1396,i,9385248801352219384,9734123908998738035,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2136"C:\Program Files\Common Files\microsoft shared\IME14\SHARED\IMEKLMG.EXE" /SetPreload /JPN /LogC:\Program Files\Common Files\microsoft shared\IME14\SHARED\IMEKLMG.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Office IME 2010
Exit code:
1
Version:
14.0.4734.1000
Modules
Images
c:\program files\common files\microsoft shared\ime14\shared\imeklmg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\userenv.dll
Total events
9 261
Read events
9 166
Write events
91
Delete events
4

Modification events

(PID) Process:(3244) Firmwareupdate.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3244) Firmwareupdate.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(3244) Firmwareupdate.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(3244) Firmwareupdate.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(2944) msedge.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Edge\BLBeacon
Operation:writeName:failed_count
Value:
0
(PID) Process:(2944) msedge.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Edge\BLBeacon
Operation:writeName:state
Value:
1
(PID) Process:(2944) msedge.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Edge\ThirdParty
Operation:writeName:StatusCodes
Value:
01000000
(PID) Process:(2944) msedge.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Edge\BLBeacon
Operation:writeName:state
Value:
2
(PID) Process:(2944) msedge.exeKey:HKEY_CURRENT_USER\Software\Microsoft\EdgeUpdate\ClientState\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}
Operation:writeName:dr
Value:
1
(PID) Process:(2944) msedge.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Edge\StabilityMetrics
Operation:writeName:user_experience_metrics.stability.exited_cleanly
Value:
1
Executable files
6
Suspicious files
87
Text files
55
Unknown types
0

Dropped files

PID
Process
Filename
Type
1408sp39427.exeC:\SWSetup\sp39427\cd.htmlhtml
MD5:BB99D3EBF8D82DE5892D1325BA4DBD99
SHA256:43F5969A05A26BEADE767CE423E6A06DCA489EA613141E869553FA6740AC357C
1408sp39427.exeC:\Users\admin\AppData\Local\Temp\plf4B19.tmptext
MD5:9EFCC61A0BAA38A6D7C67A05A97C7B87
SHA256:7CCB3A50CA08C66A220E4DA614CBABA1D05157359EDD174223C788B86D929EDF
1408sp39427.exeC:\Users\admin\AppData\Local\Temp\ext4B1A.tmptext
MD5:9EFCC61A0BAA38A6D7C67A05A97C7B87
SHA256:7CCB3A50CA08C66A220E4DA614CBABA1D05157359EDD174223C788B86D929EDF
1408sp39427.exeC:\Users\admin\AppData\Local\Temp\ext4B18.tmptext
MD5:8A13DDBCE3BBE26B494D8B45D1E43506
SHA256:83ED43611193820DB904F97C8A48FB42CAA8710C151FF669AF4884A0A59FE18C
1408sp39427.exeC:\SWSetup\sp39427\ISO\rom.isocompressed
MD5:62D642C17B7DF599071631D8FE52E57D
SHA256:7DB38B098080ADEF2634BD65290BEA37E933FA683362D985391142608EFC68C4
1408sp39427.exeC:\Users\admin\AppData\Local\Temp\wel4B17.tmptext
MD5:8A13DDBCE3BBE26B494D8B45D1E43506
SHA256:83ED43611193820DB904F97C8A48FB42CAA8710C151FF669AF4884A0A59FE18C
1408sp39427.exeC:\Users\admin\AppData\Local\Temp\pft7FD7.tmp\pftw1.pkgcompressed
MD5:CA3BF0BE6D95ABA6D110F3CABA952E67
SHA256:F0B58C699389BB5DDB8C8CB8BA0EDE7DCE77EA60F146C9B0BFB0D3895AE9317B
1408sp39427.exeC:\SWSetup\sp39427\HPUSBFW.exeexecutable
MD5:2766E7AB6A29EB559CE597FE5641044A
SHA256:63D93A516FF7F6EB43F2098C346358029EBB9434F8495C72BA1244A8221C19A3
1408sp39427.exeC:\SWSetup\sp39427\floppy.exeexecutable
MD5:C23EFD2996B1939A0A78DC395996A42B
SHA256:6E14B2CAAE6EFAC5CF794C6A43D80F6D180D9ECB0383C861D6C70C388FB6A0FF
1408sp39427.exeC:\SWSetup\sp39427\Rompaq\68mvu.binbinary
MD5:F71751D0CB4DCAA2DA465E58F969861B
SHA256:4661E1E347770DA1418EAB1C544252129CE36EC48B40D70111CF8905049E0D33
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
22
DNS requests
13
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1160
sipnotify.exe
HEAD
200
23.197.138.118:80
http://query.prod.cms.rt.microsoft.com/cms/api/am/binary/RE2JgkA?v=133518722576560000
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
whitelisted
3748
msedge.exe
239.255.255.250:1900
unknown
4036
msedge.exe
13.107.42.16:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4036
msedge.exe
131.253.33.239:443
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
4036
msedge.exe
92.123.104.12:443
www.bing.com
Akamai International B.V.
DE
unknown
3748
msedge.exe
224.0.0.251:5353
unknown
4036
msedge.exe
13.107.22.239:443
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
4036
msedge.exe
152.199.21.175:443
msedgeextensions.sf.tlu.dl.delivery.mp.microsoft.com
EDGECAST
DE
whitelisted

DNS requests

Domain
IP
Reputation
config.edge.skype.com
  • 13.107.42.16
whitelisted
edge.microsoft.com
  • 131.253.33.239
  • 13.107.22.239
whitelisted
www.bing.com
  • 92.123.104.12
  • 92.123.104.11
  • 92.123.104.6
  • 92.123.104.15
  • 92.123.104.7
  • 92.123.104.14
  • 92.123.104.9
  • 92.123.104.16
  • 92.123.104.10
whitelisted
msedgeextensions.sf.tlu.dl.delivery.mp.microsoft.com
  • 152.199.21.175
whitelisted
self.events.data.microsoft.com
  • 13.89.179.9
whitelisted
query.prod.cms.rt.microsoft.com
  • 23.197.138.118
whitelisted

Threats

No threats detected
Process
Message
HPUSBFW.exe
***ERROR*** Unable to query the target volume: The system cannot find the path specified.