File name:

3.9.6.6-21.exe

Full analysis: https://app.any.run/tasks/b2b3da86-7abf-461a-a51e-d9069127fb92
Verdict: Malicious activity
Analysis date: September 19, 2024, 10:29:16
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
MD5:

3A926B8794A5E83808BE2813CEAD81BD

SHA1:

D1384FF4CAAFD5FA1355F3C9DCAD09191065CBB1

SHA256:

140CABB2D8C2571DB8E7ABA8454E2878F6C89F10E8ABA752AFA90F89685CD0FE

SSDEEP:

98304:8QJpBD3mzMwo04EKklj0MEwuq9m8QwjrQb8051Gdp5D0cv9C9rjsanq/BAcd1+oj:P6ISUs

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • install64.exe (PID: 4180)
      • 3.9.6.6-21.exe (PID: 1612)
      • cmd.exe (PID: 6668)
    • Connects to FTP

      • spoolsv.exe (PID: 6344)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2021:09:25 21:57:46+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 27136
InitializedDataSize: 186880
UninitializedDataSize: 2048
EntryPoint: 0x352d
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
No data.
screenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
167
Monitored processes
34
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
start 3.9.6.6-21.exe net.exe no specs conhost.exe no specs net1.exe no specs sc.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs net.exe no specs net1.exe no specs sc.exe no specs net.exe no specs net1.exe no specs cmd.exe conhost.exe no specs icacls.exe no specs regedit.exe no specs net.exe no specs net1.exe no specs spoolsv.exe moncore.exe no specs net.exe no specs net1.exe no specs moncore.exe no specs spoolsv.exe cmd.exe no specs conhost.exe no specs install64.exe navcheck.exe werfault.exe sppextcomobj.exe no specs slui.exe slui.exe no specs 3.9.6.6-21.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
964\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1612"C:\Users\admin\AppData\Local\Temp\3.9.6.6-21.exe" C:\Users\admin\AppData\Local\Temp\3.9.6.6-21.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\3.9.6.6-21.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
1644C:\WINDOWS\system32\net1 start monsvrC:\Windows\System32\net1.exenet.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Net Command
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\net1.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\samcli.dll
c:\windows\system32\dsrole.dll
1700net stop monsvrC:\Windows\SysWOW64\net.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Net Command
Exit code:
2
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\net.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
2056C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
2212net start spoolerC:\Windows\System32\net.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Net Command
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\net.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\mpr.dll
c:\windows\system32\sechost.dll
c:\windows\system32\wkscli.dll
2608C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
3568\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exenet.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3904net stop spoolerC:\Windows\SysWOW64\net.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Net Command
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\net.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
4180C:\WINDOWS\system32\net1 stop MonSvrC:\Windows\SysWOW64\net1.exenet.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Net Command
Exit code:
2
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\net1.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\sechost.dll
Total events
6 834
Read events
6 654
Write events
177
Delete events
3

Modification events

(PID) Process:(6616) regedit.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Environments\Windows x64\Print Processors\MonPrint
Operation:writeName:Driver
Value:
MonPrint.dll
(PID) Process:(5996) spoolsv.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print
Operation:writeName:BeepEnabled
Value:
0
(PID) Process:(5996) spoolsv.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers
Operation:writeName:DefaultSpoolDirectory
Value:
C:\Windows\system32\spool\PRINTERS
(PID) Process:(5996) spoolsv.exeKey:HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Devices
Operation:writeName:OneNote (Desktop)
Value:
winspool,nul:
(PID) Process:(5996) spoolsv.exeKey:HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PrinterPorts
Operation:writeName:OneNote (Desktop)
Value:
winspool,nul:,15,45
(PID) Process:(5996) spoolsv.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Ports
Operation:writeName:Ne00:
Value:
(PID) Process:(5996) spoolsv.exeKey:HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Devices
Operation:writeName:Microsoft XPS Document Writer
Value:
winspool,Ne00:
(PID) Process:(5996) spoolsv.exeKey:HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PrinterPorts
Operation:writeName:Microsoft XPS Document Writer
Value:
winspool,Ne00:,15,45
(PID) Process:(5996) spoolsv.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Ports
Operation:writeName:Ne01:
Value:
(PID) Process:(5996) spoolsv.exeKey:HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Devices
Operation:writeName:Microsoft Print to PDF
Value:
winspool,Ne01:
Executable files
18
Suspicious files
6
Text files
16
Unknown types
0

Dropped files

PID
Process
Filename
Type
16123.9.6.6-21.exeC:\ProgramData\MonPrinter\Bin\installer.battext
MD5:05FD8238785B620EEE6A309046869101
SHA256:C0D0F62D5BFDA06C2728CD6D244B4FEC4FE7593840C19D36BDF6A585F89276A6
16123.9.6.6-21.exeC:\ProgramData\MonPrinter\cleanup.battext
MD5:9E8F8365FB1A5576ECA497DF86FDDE34
SHA256:D5B2AD24DDC5D5D39F8F7B8966D05F7991EB8C46A309FE58BF58C1F8F960B375
16123.9.6.6-21.exeC:\ProgramData\MonPrinter\Bin\MonFilter.conftext
MD5:60A9B3EC455C2BB31ED9E2DFA658154F
SHA256:9981353DED0A31DDAD015BAB3898B1BEB6D0083005B14B980046A460A18D3743
16123.9.6.6-21.exeC:\ProgramData\MonPrinter\Bin\Driver\amd64\MonPrint.dllexecutable
MD5:D7BE3F73CD633C029DA368EA0E4A2F2F
SHA256:0F6D29E3B2E4D03BDE22CA2A01B4585B63FA3E8FB8C29074A5D2066F8C518107
16123.9.6.6-21.exeC:\ProgramData\MonPrinter\Bin\Driver\install-driver.battext
MD5:BCA6C0BD0A1C2927B3FD4100421341A3
SHA256:ADB2D69081F910FF1218B8AF2D8881F2B681FB6B5AFD305BBFCB867F9BAA0A03
16123.9.6.6-21.exeC:\ProgramData\MonPrinter\Bin\Driver\amd64\MonCore.exeexecutable
MD5:B6959FCB9AF2DEE43FFF1FCFF22F1AAB
SHA256:F044ED10D4BEC1D242B0B8F67E68DE80756F6081CB8BBD0B54B28B21C2B01F66
6476cmd.exeC:\ProgramData\MonPrinter\cleanup.logtext
MD5:38D4D76BB8262ACB49AE372E4F43A0CD
SHA256:FC0983E904EAD2EE4C05915CC0178EAB1DCF081AFE868D78E9104F66CC910D67
16123.9.6.6-21.exeC:\ProgramData\MonPrinter\Bin\install64.exeexecutable
MD5:6536F8E38BEC8005760CB96429B3A06E
SHA256:CF28BF57EFCC6E45BD482E581EC2B63FFBD5B3FA693EDB8B70823D79905A02D9
16123.9.6.6-21.exeC:\ProgramData\MonPrinter\Bin\install.exeexecutable
MD5:ABDABAD135771A25EEA0512998FAA22F
SHA256:E19F6861D97BBEAF123AC808857A94BFD6025C56F9B68DC35BD94B8D06348DF6
16123.9.6.6-21.exeC:\ProgramData\MonPrinter\Bin\uninstall.battext
MD5:D91B808F2C2A47DD48BBA08E373F5C24
SHA256:7BC0CE28BA097CB4368BC9954F1EBBCA670D6DDF45E3568282E06A66FF999C5B
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
45
DNS requests
21
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5196
svchost.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6500
WerFault.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
3324
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
3324
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
5336
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
3812
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
5196
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3888
svchost.exe
239.255.255.250:1900
whitelisted
6392
RUXIMICS.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2120
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
20.42.65.90:443
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
2.23.209.182:443
Akamai International B.V.
GB
unknown
4
System
192.168.100.255:138
whitelisted
5196
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5196
svchost.exe
88.221.169.152:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 51.104.136.2
whitelisted
google.com
  • 142.250.185.174
whitelisted
www.microsoft.com
  • 88.221.169.152
  • 184.30.21.171
whitelisted
watson.events.data.microsoft.com
  • 52.182.143.212
whitelisted
login.live.com
  • 20.190.159.64
  • 20.190.159.71
  • 20.190.159.4
  • 20.190.159.0
  • 40.126.31.67
  • 40.126.31.71
  • 40.126.31.69
  • 20.190.159.75
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
go.microsoft.com
  • 23.35.238.131
whitelisted
browser.pipe.aria.microsoft.com
  • 20.42.73.30
  • 52.168.117.170
whitelisted
slscr.update.microsoft.com
  • 52.165.165.26
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 13.95.31.18
whitelisted

Threats

No threats detected
Process
Message
spoolsv.exe
Call EnumPrintProcessorDatatypes()
spoolsv.exe
winprint.dll load complete!
spoolsv.exe
OpenPrinterProcessor() address :1
spoolsv.exe
Monitor filter plugin load complete! ret: 0 error:87
spoolsv.exe
StartPrinterMonitor complete! ret: 0 error:87
spoolsv.exe
Call EnumPrintProcessorDatatypes()
spoolsv.exe
Monitor filter plugin load complete! ret: 0 error:87
spoolsv.exe
StartPrinterMonitor complete! ret: 0 error:87
spoolsv.exe
Call EnumPrintProcessorDatatypes()
spoolsv.exe
winprint.dll load complete!