File name:

DECLAN_Install_3203.EXE

Full analysis: https://app.any.run/tasks/9099e084-5dc2-4184-ad4c-67c8a3f5c039
Verdict: Malicious activity
Analysis date: January 07, 2022, 20:56:58
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
installer
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

BDDA2337A5BD132B0BEAF5DC4C8D8CB7

SHA1:

FFD5A042A520A1F7E707F8D4FD30A7ADB9078F8D

SHA256:

1F8DE9CD9F75B44F0AECA99A1B8E3A1048B244664A52ED8BC1D6D1D551E8FE86

SSDEEP:

196608:zF0wOvQYdClqUy8hKZLLbmpzCcX2OShfyvb4CUfkdiJ:zF0woQYBj8U5IRXCNAbpUfP

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops executable file immediately after starts

      • DECLAN_Install_3203.EXE (PID: 2396)
    • Loads dropped or rewritten executable

      • ibguard.exe (PID: 576)
      • GLJD1E0.tmp (PID: 1284)
      • ibserver.exe (PID: 1308)
      • AppDeclan.exe (PID: 3936)
      • ibguard.exe (PID: 1468)
      • svchost.exe (PID: 2460)
      • werfault.exe (PID: 2572)
      • ibserver.exe (PID: 2604)
      • DECLAN_Install_3203.EXE (PID: 2396)
    • Application was dropped or rewritten from another process

      • ibserver.exe (PID: 1308)
      • ibguard.exe (PID: 576)
      • ibguard.exe (PID: 1468)
      • ibserver.exe (PID: 2604)
      • AppDeclan.exe (PID: 3936)
      • GLJD1E0.tmp (PID: 1284)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • DECLAN_Install_3203.EXE (PID: 2396)
    • Checks supported languages

      • DECLAN_Install_3203.EXE (PID: 2396)
      • ibguard.exe (PID: 576)
      • ibserver.exe (PID: 1308)
      • AppDeclan.exe (PID: 3936)
      • ibguard.exe (PID: 1468)
      • ibserver.exe (PID: 2604)
      • GLJD1E0.tmp (PID: 1284)
    • Reads the computer name

      • DECLAN_Install_3203.EXE (PID: 2396)
      • ibguard.exe (PID: 576)
      • ibserver.exe (PID: 1308)
      • AppDeclan.exe (PID: 3936)
      • ibguard.exe (PID: 1468)
      • ibserver.exe (PID: 2604)
    • Creates a software uninstall entry

      • DECLAN_Install_3203.EXE (PID: 2396)
    • Creates files in the Windows directory

      • DECLAN_Install_3203.EXE (PID: 2396)
    • Creates a directory in Program Files

      • DECLAN_Install_3203.EXE (PID: 2396)
    • Drops a file with too old compile date

      • DECLAN_Install_3203.EXE (PID: 2396)
    • Drops a file with a compile date too recent

      • DECLAN_Install_3203.EXE (PID: 2396)
    • Creates files in the program directory

      • DECLAN_Install_3203.EXE (PID: 2396)
      • ibguard.exe (PID: 576)
      • ibserver.exe (PID: 2604)
    • Removes files from Windows directory

      • DECLAN_Install_3203.EXE (PID: 2396)
    • Drops a file that was compiled in debug mode

      • DECLAN_Install_3203.EXE (PID: 2396)
    • Reads default file associations for system extensions

      • DECLAN_Install_3203.EXE (PID: 2396)
    • Creates or modifies windows services

      • DECLAN_Install_3203.EXE (PID: 2396)
    • Creates/Modifies COM task schedule object

      • GLJD1E0.tmp (PID: 1284)
    • Executed as Windows Service

      • ibserver.exe (PID: 1308)
      • ibguard.exe (PID: 576)
    • Creates files in the driver directory

      • DECLAN_Install_3203.EXE (PID: 2396)
    • Starts application with an unusual extension

      • DECLAN_Install_3203.EXE (PID: 2396)
  • INFO

    • Manual execution by user

      • AppDeclan.exe (PID: 3936)
    • Checks supported languages

      • svchost.exe (PID: 2460)
      • werfault.exe (PID: 2572)
    • Reads the computer name

      • svchost.exe (PID: 2460)
      • werfault.exe (PID: 2572)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Wise Installer executable (96.9)
.dll | Win32 Dynamic Link Library (generic) (1.3)
.exe | Win32 Executable (generic) (0.9)
.exe | Generic Win/DOS Executable (0.4)
.exe | DOS Executable Generic (0.4)

EXIF

EXE

LegalCopyright: SEFAZ-RJ
FileVersion: 3.2.0.3
FileDescription: DECLAN-IPM
CompanyName: SEFAZ-RJ
CharacterSet: Windows, Latin1
LanguageCode: English (U.S.)
FileSubtype: -
ObjectFileType: Executable application
FileOS: Windows 16-bit
FileFlags: (none)
FileFlagsMask: 0x003f
ProductVersionNumber: 3.2.0.3
FileVersionNumber: 3.2.0.3
Subsystem: Windows GUI
SubsystemVersion: 4
ImageVersion: 4
OSVersion: 4
EntryPoint: 0x21af
UninitializedDataSize: -
InitializedDataSize: 5632
CodeSize: 8704
LinkerVersion: 6
PEType: PE32
TimeStamp: 2000:04:25 16:37:12+02:00
MachineType: Intel 386 or later, and compatibles
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
46
Monitored processes
10
Malicious processes
7
Suspicious processes
0

Behavior graph

Click at the process to see the details
drop and start start declan_install_3203.exe gljd1e0.tmp no specs ibguard.exe no specs ibserver.exe no specs appdeclan.exe no specs ibguard.exe no specs ibserver.exe no specs svchost.exe no specs werfault.exe no specs declan_install_3203.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
576C:\PROGRA~1\Borland\INTERB~1\Bin\ibguard.exe -sC:\PROGRA~1\Borland\INTERB~1\Bin\ibguard.exeservices.exe
User:
SYSTEM
Company:
Inprise Corporation
Integrity Level:
SYSTEM
Description:
InterBase Server
Exit code:
0
Version:
WI-O6.0.1.6
Modules
Images
c:\program files\borland\interbase\bin\ibguard.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gds32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
1284"C:\Users\admin\AppData\Local\Temp\GLJD1E0.tmp" C:\Windows\System32\midas.dllC:\Users\admin\AppData\Local\Temp\GLJD1E0.tmpDECLAN_Install_3203.EXE
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\gljd1e0.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
1308C:\PROGRA~1\Borland\INTERB~1\Bin\ibserver.exe -s -gC:\PROGRA~1\Borland\INTERB~1\Bin\ibserver.exeservices.exe
User:
SYSTEM
Company:
Inprise Corporation
Integrity Level:
SYSTEM
Description:
InterBase Server
Exit code:
0
Version:
WI-O6.0.1.6
Modules
Images
c:\program files\borland\interbase\bin\ibserver.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc\comctl32.dll
c:\windows\system32\gdi32.dll
1468"C:\Program Files\Borland\Interbase\Bin\ibguard.exe" -aC:\Program Files\Borland\Interbase\Bin\ibguard.exeAppDeclan.exe
User:
admin
Company:
Inprise Corporation
Integrity Level:
MEDIUM
Description:
InterBase Server
Exit code:
0
Version:
WI-O6.0.1.6
Modules
Images
c:\program files\borland\interbase\bin\ibguard.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\gds32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
2396"C:\Users\admin\AppData\Local\Temp\DECLAN_Install_3203.EXE" C:\Users\admin\AppData\Local\Temp\DECLAN_Install_3203.EXE
Explorer.EXE
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\declan_install_3203.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2460C:\Windows\System32\svchost.exe -k WerSvcGroupC:\Windows\System32\svchost.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Host Process for Windows Services
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\wersvc.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\version.dll
2572werfault.exe /h /shared Global\9c59f402fc7148f28945a98c19686871C:\Windows\system32\werfault.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Problem Reporting
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2604"C:\Program Files\Borland\Interbase\bin\ibserver.exe" -a -nC:\Program Files\Borland\Interbase\bin\ibserver.exeibguard.exe
User:
admin
Company:
Inprise Corporation
Integrity Level:
MEDIUM
Description:
InterBase Server
Exit code:
0
Version:
WI-O6.0.1.6
Modules
Images
c:\program files\borland\interbase\bin\ibserver.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc\comctl32.dll
c:\windows\system32\gdi32.dll
3836"C:\Users\admin\AppData\Local\Temp\DECLAN_Install_3203.EXE" C:\Users\admin\AppData\Local\Temp\DECLAN_Install_3203.EXEExplorer.EXE
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\appdata\local\temp\declan_install_3203.exe
c:\windows\system32\ntdll.dll
3936"C:\Program Files\SEFAZ-RJ\DECLAN-IPM\AppDeclan.exe" C:\Program Files\SEFAZ-RJ\DECLAN-IPM\AppDeclan.exeExplorer.EXE
User:
admin
Company:
SEFAZ-RJ
Integrity Level:
MEDIUM
Description:
Declara��o Anual para Apura��o dos �ndices de Participa��o dos Munic�pios no Produto da Arrecada��o do ICMS
Exit code:
0
Version:
3.2.0.3
Modules
Images
c:\program files\sefaz-rj\declan-ipm\appdeclan.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
Total events
1 018
Read events
953
Write events
65
Delete events
0

Modification events

(PID) Process:(2396) DECLAN_Install_3203.EXEKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DECLAN-IPM
Operation:writeName:DisplayName
Value:
DECLAN-IPM
(PID) Process:(2396) DECLAN_Install_3203.EXEKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DECLAN-IPM
Operation:writeName:UninstallString
Value:
C:\PROGRA~1\SEFAZ-RJ\DECLAN~1\UNWISE.EXE C:\PROGRA~1\SEFAZ-RJ\DECLAN~1\INSTALL.LOG
(PID) Process:(2396) DECLAN_Install_3203.EXEKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
Operation:writeName:C:\Windows\System32\midas.dll
Value:
1
(PID) Process:(2396) DECLAN_Install_3203.EXEKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
Operation:writeName:C:\Program Files\Borland\Interbase\Bin\ibguard.exe
Value:
1
(PID) Process:(2396) DECLAN_Install_3203.EXEKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
Operation:writeName:C:\Program Files\Borland\Interbase\Bin\ibserver.exe
Value:
1
(PID) Process:(2396) DECLAN_Install_3203.EXEKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
Operation:writeName:C:\Program Files\Borland\Interbase\intl\gdsintl.dll
Value:
1
(PID) Process:(2396) DECLAN_Install_3203.EXEKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
Operation:writeName:C:\Program Files\Borland\Interbase\udf\ib_udf.dll
Value:
1
(PID) Process:(2396) DECLAN_Install_3203.EXEKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
Operation:writeName:C:\Program Files\Borland\Interbase\Bin\ib_util.dll
Value:
1
(PID) Process:(2396) DECLAN_Install_3203.EXEKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
Operation:writeName:C:\Windows\System32\ibmgr.cpl
Value:
1
(PID) Process:(2396) DECLAN_Install_3203.EXEKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
Operation:writeName:C:\Windows\System32\gds32.dll
Value:
1
Executable files
54
Suspicious files
4
Text files
22
Unknown types
27

Dropped files

PID
Process
Filename
Type
2396DECLAN_Install_3203.EXEC:\Users\admin\AppData\Local\Temp\~GLH0000.TMPexecutable
MD5:B9B41E50D612E00BF3A49A6405B89D74
SHA256:50E7A30E1825FAB93B94B698C2C6D2CC1787B094C6CEE53EEED5C497F77443C9
2396DECLAN_Install_3203.EXEC:\Users\admin\AppData\Local\Temp\GLJD1E0.tmpexecutable
MD5:6F608D264503796BEBD7CD66B687BE92
SHA256:49833D2820AFB1D7409DFBD916480F2CDF5787D2E2D94166725BEB9064922D5D
2396DECLAN_Install_3203.EXEC:\Users\admin\AppData\Local\Temp\~GLH0001.TMPtext
MD5:8D94B1C31C934E7076B8E0DDE6D41F50
SHA256:F4D62655E8F85A3CDE05E58686C7D744190A00BAF91936E91E5D6288B37C652E
2396DECLAN_Install_3203.EXEC:\Users\admin\AppData\Local\Temp\GLCD1DF.tmpexecutable
MD5:FBD929BFC7B4A9E4FA4506655BAB4C4A
SHA256:ADF8DEA5D36B58CF621E2BB0C4549F94E0919308DD7CC1215D942417C45E54A4
2396DECLAN_Install_3203.EXEC:\Windows\System32\ctl3d32.dll
MD5:
SHA256:
2396DECLAN_Install_3203.EXEC:\Program Files\SEFAZ-RJ\DECLAN-IPM\~GLH0003.TMPexecutable
MD5:883CB754C8F4790DD85BE35B7ABE1C1B
SHA256:7101777BE4E0166F1E47C2ECF68DF4B0E7E4CAC3E358BA61CB8FEC0074BBD440
2396DECLAN_Install_3203.EXEC:\Users\admin\AppData\Local\Temp\GLFDDAA.tmpexecutable
MD5:B9B41E50D612E00BF3A49A6405B89D74
SHA256:50E7A30E1825FAB93B94B698C2C6D2CC1787B094C6CEE53EEED5C497F77443C9
2396DECLAN_Install_3203.EXEC:\Program Files\SEFAZ-RJ\DECLAN-IPM\~GLH0002.TMPexecutable
MD5:3A938ED2427DF10E571041069E6980CB
SHA256:4751A3547F3B482BB4A2440D4E91E3DCBA9B4B0F5B1BB50416A32FB47AE75C5E
2396DECLAN_Install_3203.EXEC:\PROGRA~1\SEFAZ-RJ\DECLAN~1\temp.000executable
MD5:883CB754C8F4790DD85BE35B7ABE1C1B
SHA256:7101777BE4E0166F1E47C2ECF68DF4B0E7E4CAC3E358BA61CB8FEC0074BBD440
2396DECLAN_Install_3203.EXEC:\Program Files\SEFAZ-RJ\DECLAN-IPM\Dados\Dbdeclan.gdbfdb
MD5:E71428EE397B51A3975C752ED4B0A3E6
SHA256:937102B5189AB8A2143972EB02BA59F0124B90744B914C225C283D27A9ACD658
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info