File name:

PrintWiz.exe

Full analysis: https://app.any.run/tasks/2b06ebd9-1ba7-4f57-af1f-13f1bab3d2b7
Verdict: Malicious activity
Threats:

Trojans are a group of malicious programs distinguished by their ability to masquerade as benign software. Depending on their type, trojans possess a variety of capabilities, ranging from maintaining full remote control over the victim’s machine to stealing data and files, as well as dropping other malware. At the same time, the main functionality of each trojan family can differ significantly depending on its type. The most common trojan infection chain starts with a phishing email.

Analysis date: December 21, 2023, 18:22:39
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
tinba
trojan
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

9B32FA9DE6F8939AB5A9809587E3CB24

SHA1:

1C14827E32F3E9C0B3A2E916C9E98066CFB7997A

SHA256:

0EE662DB7AC463B7869C983F911E3ADFB224A04961F7AF5673825153919E283B

SSDEEP:

6144:2qFLvoNTvox4BT/f5AuRZMOfOQr1KSckoLrPvd+EgcPxG1tkBs1LV8SZWpMG8SD:2qANLox6yQPcwbZ/wMnSD

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • TINBA has been detected (SURICATA)

      • explorer.exe (PID: 1164)
    • Runs injected code in another process

      • winver.exe (PID: 2080)
    • Connects to the CnC server

      • explorer.exe (PID: 1164)
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    • Drops the executable file immediately after the start

      • PrintWiz.exe (PID: 1692)
      • explorer.exe (PID: 1164)
    • Checks supported languages

      • PrintWiz.exe (PID: 1692)
    • Reads the computer name

      • PrintWiz.exe (PID: 1692)
    • Reads the machine GUID from the registry

      • PrintWiz.exe (PID: 1692)
    • Creates files or folders in the user directory

      • explorer.exe (PID: 1164)
    • Application was injected by another process

      • explorer.exe (PID: 1164)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2014:06:12 04:27:16+02:00
ImageFileCharacteristics: No relocs, Executable, No symbols, Aggressive working-set trim, Large address aware, [6], 32-bit, Net run from swap, Uniprocessor only
PEType: PE32
LinkerVersion: 10
CodeSize: 135168
InitializedDataSize: 93696
UninitializedDataSize: -
EntryPoint: 0x4040
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 4.0.2.28
ProductVersionNumber: 4.0.2.28
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Boris Eyrich Software
FileDescription: Print Provider Wizard
FileVersion: 4.0.2.28
InternalName: Print Provider Wizard
LegalCopyright: © 2002-2014 Boris Eyrich Software
OriginalFileName: PrintWiz.exe
ProductName: Print Provider Wizard
ProductVersion: 4.0.2.28
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
35
Monitored processes
3
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start inject printwiz.exe no specs winver.exe no specs #TINBA explorer.exe

Process information

PID
CMD
Path
Indicators
Parent process
1164C:\Windows\Explorer.EXEC:\Windows\explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1692"C:\Users\admin\Desktop\PrintWiz.exe" C:\Users\admin\Desktop\PrintWiz.exeexplorer.exe
User:
admin
Company:
Boris Eyrich Software
Integrity Level:
MEDIUM
Description:
Print Provider Wizard
Exit code:
0
Version:
4.0.2.28
Modules
Images
c:\users\admin\desktop\printwiz.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2080winverC:\Windows\System32\winver.exePrintWiz.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Version Reporter Applet
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\winver.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
Total events
895
Read events
894
Write events
1
Delete events
0

Modification events

(PID) Process:(1164) explorer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Action Center\Checks\{C8E6F269-B90A-4053-A3BE-499AFCEC98C4}.check.0
Operation:writeName:CheckSetting
Value:
01000000D08C9DDF0115D1118C7A00C04FC297EB01000000DBDD10622BD67741A42163F361389C4700000000020000000000106600000001000020000000714C0B985B0540658F4A2080B484A48FEA0193B4945278E76DEADC9EF300F178000000000E80000000020000200000002B477AD6A48910EDA2BF44A8E4FAAFB7E2EDF3EE6F87B8965B303D8016BD90EA30000000CB02147CAA96DADF9F5A3BD08AC8A954F632048A3EC443FAA534C64E43A96953CAB4A202A2BC0443ADBC5B693897DBB44000000078BCD17E1DCD91E99A86D38616C049FA8C5E2A7C07BB269B76B0709DC8A01ABF25866BF6638D5C4422D1151CE173748901F5A2433E1BD07914E254B07BB130FD
Executable files
1
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
1164explorer.exeC:\Users\admin\AppData\Roaming\A5D80028\bin.exeexecutable
MD5:BBE4E137E005211D5E8B2683A709690A
SHA256:248DFD579E0336416679F4A3D59B8FD9E733A9BB25FE34830082073D42C006A2
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
9
DNS requests
8
Threats
4

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1164
explorer.exe
POST
216.218.185.162:80
http://fovcpylsiqvv.com/el0hjkd76ghs65dhj0it/
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
1164
explorer.exe
216.218.185.162:80
elitiorecfreetoo.cc
HURRICANE
US
unknown
1164
explorer.exe
162.249.66.138:80
ljjskttqximu.ru
COMCAST-7922
US
unknown

DNS requests

Domain
IP
Reputation
elitiorecfreetoo.cc
  • 216.218.185.162
unknown
ljjskttqximu.com
unknown
ljjskttqximu.net
unknown
ljjskttqximu.in
  • 216.218.185.162
unknown
dns.msftncsi.com
  • 131.107.255.255
shared
ljjskttqximu.ru
  • 162.249.66.138
unknown
fovcpylsiqvv.com
  • 216.218.185.162
unknown

Threats

PID
Process
Class
Message
1080
svchost.exe
Potentially Bad Traffic
ET DNS Query for .cc TLD
1164
explorer.exe
Malware Command and Control Activity Detected
ET MALWARE Tinba Checkin
1164
explorer.exe
Malware Command and Control Activity Detected
ET MALWARE [PTsecurity] Tinba Checkin 4
1164
explorer.exe
Malware Command and Control Activity Detected
ET MALWARE Tinba Checkin 2
No debug info