File name:

freeocr541 (1).exe

Full analysis: https://app.any.run/tasks/4d9c5f3c-9bd6-47ff-9e8b-e39a0c4b42d1
Verdict: Malicious activity
Analysis date: May 03, 2024, 06:07:50
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

160DDB7233C2A3ACFCE8309A36F4B992

SHA1:

B9C59B59ED325AB0E2182E3EBBB147B0B8F5DD9C

SHA256:

0BF9D979C7BC3774FC6AE39DF31AFC89BFD9AF60120FC2D1BE50B1B35E850D64

SSDEEP:

196608:FlkvsbARsOK0eRQSaM49jnJyFj4TjAHEV5ViXD9rq5cFFjqIIqLUuKkFm:FpARsO/eRhD8nG4EG5c2IIqznFm

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • freeocr541 (1).exe (PID: 3972)
      • freeocr541 (1).tmp (PID: 2104)
      • freeocr541 (1).exe (PID: 1020)
    • Creates a writable file in the system directory

      • freeocr541 (1).tmp (PID: 2104)
    • Registers / Runs the DLL via REGSVR32.EXE

      • freeocr541 (1).tmp (PID: 2104)
  • SUSPICIOUS

    • Reads the Windows owner or organization settings

      • freeocr541 (1).tmp (PID: 2104)
    • Executable content was dropped or overwritten

      • freeocr541 (1).tmp (PID: 2104)
      • freeocr541 (1).exe (PID: 1020)
      • freeocr541 (1).exe (PID: 3972)
    • Creates/Modifies COM task schedule object

      • regsvr32.exe (PID: 1064)
    • Process drops legitimate windows executable

      • freeocr541 (1).tmp (PID: 2104)
    • Reads the Internet Settings

      • FreeOCR.exe (PID: 2024)
  • INFO

    • Create files in a temporary directory

      • freeocr541 (1).exe (PID: 3972)
      • freeocr541 (1).tmp (PID: 2104)
      • freeocr541 (1).exe (PID: 1020)
      • FreeOCR.exe (PID: 2024)
    • Reads the computer name

      • freeocr541 (1).tmp (PID: 2104)
      • freeocr541 (1).tmp (PID: 3988)
      • FreeOCR.exe (PID: 2024)
      • wmpnscfg.exe (PID: 524)
    • Creates files in the program directory

      • freeocr541 (1).tmp (PID: 2104)
    • Checks supported languages

      • FreeOCR.exe (PID: 2024)
      • freeocr541 (1).tmp (PID: 3988)
      • freeocr541 (1).exe (PID: 1020)
      • freeocr541 (1).exe (PID: 3972)
      • freeocr541 (1).tmp (PID: 2104)
      • wmpnscfg.exe (PID: 524)
    • Creates a software uninstall entry

      • freeocr541 (1).tmp (PID: 2104)
    • Reads the machine GUID from the registry

      • FreeOCR.exe (PID: 2024)
    • Reads Environment values

      • FreeOCR.exe (PID: 2024)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 524)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (77.7)
.exe | Win32 Executable Delphi generic (10)
.dll | Win32 Dynamic Link Library (generic) (4.6)
.exe | Win32 Executable (generic) (3.1)
.exe | Win16/32 Executable Delphi generic (1.4)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 1992:06:19 22:22:17+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 37888
InitializedDataSize: 17920
UninitializedDataSize: -
EntryPoint: 0x9c40
OSVersion: 1
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 0.0.0.0
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: FreeOCR Setup
FileVersion:
LegalCopyright:
ProductName: FreeOCR
ProductVersion:
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
43
Monitored processes
7
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
start freeocr541 (1).exe freeocr541 (1).tmp no specs freeocr541 (1).exe freeocr541 (1).tmp regsvr32.exe no specs freeocr.exe wmpnscfg.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
524"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1020"C:\Users\admin\AppData\Local\Temp\freeocr541 (1).exe" /SPAWNWND=$20134 /NOTIFYWND=$20138 C:\Users\admin\AppData\Local\Temp\freeocr541 (1).exe
freeocr541 (1).tmp
User:
admin
Company:
Integrity Level:
HIGH
Description:
FreeOCR Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\appdata\local\temp\freeocr541 (1).exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
1064"C:\Windows\system32\regsvr32.exe" /s "C:\Windows\system32\ImageEnXLibrary.ocx"C:\Windows\System32\regsvr32.exefreeocr541 (1).tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2024"C:\FreeOCR\FreeOCR.exe"C:\FreeOCR\FreeOCR.exe
freeocr541 (1).tmp
User:
admin
Integrity Level:
HIGH
Description:
FreeOCR
Version:
1.1.0.8
Modules
Images
c:\freeocr\freeocr.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2104"C:\Users\admin\AppData\Local\Temp\is-PF1FG.tmp\freeocr541 (1).tmp" /SL5="$30130,11027424,54272,C:\Users\admin\AppData\Local\Temp\freeocr541 (1).exe" /SPAWNWND=$20134 /NOTIFYWND=$20138 C:\Users\admin\AppData\Local\Temp\is-PF1FG.tmp\freeocr541 (1).tmp
freeocr541 (1).exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.52.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-pf1fg.tmp\freeocr541 (1).tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
3972"C:\Users\admin\AppData\Local\Temp\freeocr541 (1).exe" C:\Users\admin\AppData\Local\Temp\freeocr541 (1).exe
explorer.exe
User:
admin
Company:
Integrity Level:
MEDIUM
Description:
FreeOCR Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\appdata\local\temp\freeocr541 (1).exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
3988"C:\Users\admin\AppData\Local\Temp\is-CIBS3.tmp\freeocr541 (1).tmp" /SL5="$20138,11027424,54272,C:\Users\admin\AppData\Local\Temp\freeocr541 (1).exe" C:\Users\admin\AppData\Local\Temp\is-CIBS3.tmp\freeocr541 (1).tmpfreeocr541 (1).exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.52.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-cibs3.tmp\freeocr541 (1).tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
Total events
10 779
Read events
10 633
Write events
130
Delete events
16

Modification events

(PID) Process:(2104) freeocr541 (1).tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
38080000B022A241209DDA01
(PID) Process:(2104) freeocr541 (1).tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:SessionHash
Value:
042B79EF4AD7F6009ED8F76701A3F94D9DC94C1106E59270F8D59DF55C2F90A1
(PID) Process:(2104) freeocr541 (1).tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Sequence
Value:
1
(PID) Process:(2104) freeocr541 (1).tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:RegFiles0000
Value:
C:\FreeOCR\AxInterop.DYNAMICWEBTWAINCTRLLib.dll
(PID) Process:(2104) freeocr541 (1).tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:RegFilesHash
Value:
77A5622157226D0A3D7D9AF3F880DDF0FFA4AE451697646AF2C5773B580E9815
(PID) Process:(1064) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8750375A-8460-4A02-BE5F-B87541277B36}\TypeLib
Operation:writeName:Version
Value:
1.2328
(PID) Process:(1064) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7FC1EC9C-4977-46EB-9F98-1CCFB10419C3}\TypeLib
Operation:writeName:Version
Value:
1.2328
(PID) Process:(1064) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{4BC41543-7C64-4CE7-8A63-9E973EF03478}\TypeLib
Operation:writeName:Version
Value:
1.2328
(PID) Process:(1064) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{563EE62D-AED0-4B5C-950F-8DDF345438B2}\TypeLib
Operation:writeName:Version
Value:
1.2328
(PID) Process:(1064) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71AB87D4-8FD5-47A6-82D8-92D3750CCA2F}\InprocServer32
Operation:writeName:ThreadingModel
Value:
Apartment
Executable files
27
Suspicious files
11
Text files
17
Unknown types
21

Dropped files

PID
Process
Filename
Type
2104freeocr541 (1).tmpC:\Users\admin\AppData\Local\Temp\is-M3PMM.tmp\_isetup\_shfoldr.dllexecutable
MD5:92DC6EF532FBB4A5C3201469A5B5EB63
SHA256:9884E9D1B4F8A873CCBD81F8AD0AE257776D2348D027D811A56475E028360D87
2104freeocr541 (1).tmpC:\FreeOCR\unins000.exeexecutable
MD5:40A991184A3972FA9AC939F8829E4E10
SHA256:74564D866F8B1299249352E60925D0ACAB5671DD5F756B247FC52C4D6CFA886D
3972freeocr541 (1).exeC:\Users\admin\AppData\Local\Temp\is-CIBS3.tmp\freeocr541 (1).tmpexecutable
MD5:C49B0148CB58B886F60CB32EB5E81439
SHA256:FC13F965789A342DBA0784492C2E2797AB92BDEAA6532E125B04BE81675C0810
2104freeocr541 (1).tmpC:\FreeOCR\is-GSFHV.tmpexecutable
MD5:2C32ABB062C0796718E68465548E6C14
SHA256:5AC746D2B941323D72F10D0B2FA9B653928CBD1B6998C8BBE6DC57EA5098CC8C
2104freeocr541 (1).tmpC:\FreeOCR\is-OS753.tmpexecutable
MD5:D29C86441DF0D674441060214F1D1DF9
SHA256:CEA1F34BFFBCBA5400DE04B41512C49091D453224EF944E71852FA5C9D6E6387
2104freeocr541 (1).tmpC:\FreeOCR\DynamicWebTwainCtrl.dllexecutable
MD5:D29C86441DF0D674441060214F1D1DF9
SHA256:CEA1F34BFFBCBA5400DE04B41512C49091D453224EF944E71852FA5C9D6E6387
2104freeocr541 (1).tmpC:\FreeOCR\is-Q0UHE.tmpexecutable
MD5:80644C8916CC802A76DEFC16B8B42B6A
SHA256:E7A12351368766EB52B0EB8D27970C1B9280AFB3D98350C349C34760DBDEEBB4
2104freeocr541 (1).tmpC:\FreeOCR\FreeOCR.exeexecutable
MD5:80644C8916CC802A76DEFC16B8B42B6A
SHA256:E7A12351368766EB52B0EB8D27970C1B9280AFB3D98350C349C34760DBDEEBB4
2104freeocr541 (1).tmpC:\FreeOCR\FreeOCR.exe.configxml
MD5:D60E2986D633C4E223FCDE7A3DDBAEBD
SHA256:4FE9573C67980262910797DB4206D27699807632515C1A308355A494A85231F2
2104freeocr541 (1).tmpC:\FreeOCR\is-A02ND.tmpxml
MD5:D60E2986D633C4E223FCDE7A3DDBAEBD
SHA256:4FE9573C67980262910797DB4206D27699807632515C1A308355A494A85231F2
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
5
DNS requests
1
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2024
FreeOCR.exe
GET
200
52.217.228.21:80
http://www.paperfile.net/version.html
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
unknown
2024
FreeOCR.exe
52.217.228.21:80
www.paperfile.net
AMAZON-02
US
unknown

DNS requests

Domain
IP
Reputation
www.paperfile.net
  • 52.217.228.21
  • 52.217.11.107
  • 52.217.191.21
  • 54.231.139.221
  • 16.182.97.149
  • 52.217.64.75
  • 52.217.46.43
  • 52.217.226.61
unknown

Threats

No threats detected
No debug info