File name:

mp68-win-mg2500-1_02-ejs.exe

Full analysis: https://app.any.run/tasks/3f29c37f-6ef5-487d-98bb-98d03c976ef9
Verdict: Malicious activity
Analysis date: January 03, 2024, 05:50:20
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

06ED0386EA9C5D4306975C19BBA400EF

SHA1:

279530349CAECAFCFDE6B7D37044AB77B2B34046

SHA256:

21162CD8CD04D719D7FC8177334F7A0D9D9B78E75C1F385857251901DF0D0D5E

SSDEEP:

98304:t/l/oxQBgHKayykkDPFPh2+XkT4dQVxY3QhS/G+kEn+Uo48B2idSF9tYVa/qdhJG:+iWxHtNoqimrStfXciHIkYbb

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Creates a writable file in the system directory

      • drvinst.exe (PID: 1264)
      • drvinst.exe (PID: 696)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • SETUP.exe (PID: 2024)
    • Checks Windows Trust Settings

      • SETUP.exe (PID: 2024)
      • drvinst.exe (PID: 1264)
      • drvinst.exe (PID: 696)
    • Reads settings of System Certificates

      • SETUP.exe (PID: 2024)
    • Creates files in the driver directory

      • drvinst.exe (PID: 1264)
      • drvinst.exe (PID: 696)
    • Uses RUNDLL32.EXE to load library

      • SETUP.exe (PID: 2024)
  • INFO

    • Checks supported languages

      • mp68-win-mg2500-1_02-ejs.exe (PID: 2268)
      • SETUP.exe (PID: 2024)
      • SETUP.exe (PID: 668)
      • DELDRV.exe (PID: 1588)
      • drvinst.exe (PID: 1264)
      • drvinst.exe (PID: 696)
    • Drops the executable file immediately after the start

      • mp68-win-mg2500-1_02-ejs.exe (PID: 2268)
      • SETUP.exe (PID: 668)
      • drvinst.exe (PID: 696)
      • drvinst.exe (PID: 1264)
      • SETUP.exe (PID: 2024)
    • Reads product name

      • SETUP.exe (PID: 2024)
      • DELDRV.exe (PID: 1588)
    • Create files in a temporary directory

      • mp68-win-mg2500-1_02-ejs.exe (PID: 2268)
      • SETUP.exe (PID: 2024)
      • DELDRV.exe (PID: 1588)
    • Reads the computer name

      • SETUP.exe (PID: 2024)
      • SETUP.exe (PID: 668)
      • DELDRV.exe (PID: 1588)
      • drvinst.exe (PID: 1264)
      • drvinst.exe (PID: 696)
    • Reads Environment values

      • SETUP.exe (PID: 2024)
      • DELDRV.exe (PID: 1588)
    • Reads the machine GUID from the registry

      • SETUP.exe (PID: 2024)
      • drvinst.exe (PID: 1264)
      • drvinst.exe (PID: 696)
    • Creates files in the program directory

      • SETUP.exe (PID: 668)
      • SETUP.exe (PID: 2024)
      • PrintIsolationHost.exe (PID: 1796)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (32.1)
.exe | Win64 Executable (generic) (28.5)
.exe | Winzip Win32 self-extracting archive (generic) (23.7)
.dll | Win32 Dynamic Link Library (generic) (6.7)
.exe | Win32 Executable (generic) (4.6)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2009:11:02 21:24:29+01:00
ImageFileCharacteristics: No relocs, Executable, 32-bit
PEType: PE32
LinkerVersion: 8
CodeSize: 147456
InitializedDataSize: 81920
UninitializedDataSize: -
EntryPoint: 0x1479f
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
44
Monitored processes
9
Malicious processes
5
Suspicious processes
0

Behavior graph

Click at the process to see the details
start mp68-win-mg2500-1_02-ejs.exe setup.exe no specs setup.exe no specs deldrv.exe no specs drvinst.exe no specs drvinst.exe no specs rundll32.exe no specs printisolationhost.exe no specs mp68-win-mg2500-1_02-ejs.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
668C:\Users\admin\AppData\Local\Temp\WZSE0.TMP\mp68-win-mg2500-1_02-ejs\SCNUTIL\ScanUtility\setup.exe -NOUI -NOEULA -CHECKAPP -LANG:0x0009C:\Users\admin\AppData\Local\Temp\WZSE0.TMP\mp68-win-mg2500-1_02-ejs\SCNUTIL\ScanUtility\SETUP.exeSETUP.exe
User:
admin
Company:
CANON INC.
Integrity Level:
HIGH
Description:
Canon IJ Scan Utility Installer
Exit code:
0
Version:
2.2.0.3
Modules
Images
c:\users\admin\appdata\local\temp\wzse0.tmp\mp68-win-mg2500-1_02-ejs\scnutil\scanutility\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
696DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{33fdf15b-ad38-1c59-f7bf-7265bec6ce34}\MG2500SC.INF" "0" "695cf6973" "000005D4" "WinSta0\Default" "000005D8" "208" "C:\Program Files\CanonBJ\IJPrinter\Canon MG2500 series"C:\Windows\System32\drvinst.exesvchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1264DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{1f6e8600-05a1-7eff-3516-60793e5d606e}\MG2500P3.inf" "0" "637e9ece3" "00000558" "WinSta0\Default" "000005D4" "208" "C:\Program Files\CanonBJ\IJPrinter\Canon MG2500 series"C:\Windows\System32\drvinst.exesvchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1588"DELDRV.exe" /U:{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG2500_series /L0x0009 /QR:Canon_MG2500_series /F:SOFTWARE,PRINT,SCAN -SW:SHORTCUT -SW:WIFIHELPER -DR:"" -DR:"INBOX PRINT" -DR:"INBOX FAX" -DR:"INBOX SCAN"C:\Users\admin\AppData\Local\Temp\WZSE0.TMP\mp68-win-mg2500-1_02-ejs\DrvSetup\DELDRV.exeSETUP.exe
User:
admin
Company:
CANON INC.
Integrity Level:
HIGH
Description:
Canon IJ Driver Uninstaller
Exit code:
0
Version:
2.4
Modules
Images
c:\users\admin\appdata\local\temp\wzse0.tmp\mp68-win-mg2500-1_02-ejs\drvsetup\deldrv.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1796C:\Windows\system32\PrintIsolationHost.exe -EmbeddingC:\Windows\System32\PrintIsolationHost.exesvchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
PrintIsolationHost
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\printisolationhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1808rundll32 PRINTUI.DLL,PrintUIEntry /ia /q /m "Canon MG2500 series Printer" /f "C:\Windows\INF\oem2.inf"C:\Windows\System32\rundll32.exeSETUP.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
2024.\mp68-win-mg2500-1_02-ejs\DrvSetup\SETUP.exeC:\Users\admin\AppData\Local\Temp\WZSE0.TMP\mp68-win-mg2500-1_02-ejs\DrvSetup\SETUP.exemp68-win-mg2500-1_02-ejs.exe
User:
admin
Company:
CANON INC.
Integrity Level:
HIGH
Description:
Canon IJ Driver Installer
Exit code:
0
Version:
2.4
Modules
Images
c:\users\admin\appdata\local\temp\wzse0.tmp\mp68-win-mg2500-1_02-ejs\drvsetup\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
2044"C:\Users\admin\AppData\Local\Temp\mp68-win-mg2500-1_02-ejs.exe" C:\Users\admin\AppData\Local\Temp\mp68-win-mg2500-1_02-ejs.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\appdata\local\temp\mp68-win-mg2500-1_02-ejs.exe
c:\windows\system32\ntdll.dll
2268"C:\Users\admin\AppData\Local\Temp\mp68-win-mg2500-1_02-ejs.exe" C:\Users\admin\AppData\Local\Temp\mp68-win-mg2500-1_02-ejs.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\mp68-win-mg2500-1_02-ejs.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
Total events
11 488
Read events
11 440
Write events
46
Delete events
2

Modification events

(PID) Process:(2024) SETUP.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2024) SETUP.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Canon\cnmbj\PrinterDriverInstaller\Canon MG2500 series Printer
Operation:writeName:SendInfoAgree
Value:
1
(PID) Process:(2024) SETUP.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Canon\cnmbj\ScannerDriverInstaller\Canon MG2500 series
Operation:writeName:SendInfoAgree
Value:
1
(PID) Process:(1264) drvinst.exeKey:HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\182\52C64B7E
Operation:delete keyName:(default)
Value:
(PID) Process:(1264) drvinst.exeKey:HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\182
Operation:delete keyName:(default)
Value:
(PID) Process:(1264) drvinst.exeKey:HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\183\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(696) drvinst.exeKey:HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\183\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2024) SETUP.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Canon\cnmbj\PrinterDriverInstaller\Canon MG2500 series Printer
Operation:writeName:ForceDefaultPrinter
Value:
1
Executable files
316
Suspicious files
122
Text files
65
Unknown types
47

Dropped files

PID
Process
Filename
Type
2268mp68-win-mg2500-1_02-ejs.exeC:\Users\admin\AppData\Local\Temp\WZSE0.TMP\mp68-win-mg2500-1_02-ejs\Driver\MG2500SC.INFbinary
MD5:166D64FC17E33FFEB393A6FCFDF81B4E
SHA256:2A0D34C5DDA00E4BD32712469DB14AF629508FCDFC76EA734D7DDF65527ADEA8
2268mp68-win-mg2500-1_02-ejs.exeC:\Users\admin\AppData\Local\Temp\WZSE0.TMP\mp68-win-mg2500-1_02-ejs\Driver\MG2500P6.inftxt
MD5:633B766672AFCBBA16C3FCD8A473E891
SHA256:8D5F9DF1B31A247342A034B5A46D9CA7021D1C0D09445A84599C2D2393877E68
2268mp68-win-mg2500-1_02-ejs.exeC:\Users\admin\AppData\Local\Temp\WZSE0.TMP\mp68-win-mg2500-1_02-ejs\Driver\PrnCm.cabcompressed
MD5:B8A2A0AC93D23F39B4A289AF9C6CA921
SHA256:52F147EB7F3CF6A8D757E346F9932122E9D1451BC103EA302DD25DB694577B1C
2268mp68-win-mg2500-1_02-ejs.exeC:\Users\admin\AppData\Local\Temp\WZSE0.TMP\mp68-win-mg2500-1_02-ejs\Driver\MG2500P3.catbinary
MD5:9A024F82B0395B5A28A2264DECA49EDA
SHA256:FDA6E7D781B241DA3DDF471303414F38D812012277AD67935539457CF0CDC4E7
2268mp68-win-mg2500-1_02-ejs.exeC:\Users\admin\AppData\Local\Temp\WZSE0.TMP\mp68-win-mg2500-1_02-ejs\Driver\MG2500P3.inftxt
MD5:B861722215BDD6B9E01816CAC9BC9D41
SHA256:8205608F611B5B8B43C6D7311F2D580E5931A0F8AB2B9FD62640B16B61043761
2268mp68-win-mg2500-1_02-ejs.exeC:\Users\admin\AppData\Local\Temp\WZSE0.TMP\mp68-win-mg2500-1_02-ejs\Driver\mg2500sb.catcat
MD5:C45B1A3473FBB94C23ED7260228B6819
SHA256:510AF5850994C01F6458F3DC2A7E03E7FE2604B74CB70182AC06B253980D2E77
2268mp68-win-mg2500-1_02-ejs.exeC:\Users\admin\AppData\Local\Temp\WZSE0.TMP\mp68-win-mg2500-1_02-ejs\DrvSetup\RES\DLL\IJINSTES.dllexecutable
MD5:481B15011CF80332D1D6D9D539273B6C
SHA256:34571DF01E3EED553F5C04EEB17186C0CDC138766E4651C75F768E6372633440
2268mp68-win-mg2500-1_02-ejs.exeC:\Users\admin\AppData\Local\Temp\WZSE0.TMP\mp68-win-mg2500-1_02-ejs\DrvSetup\CHECKSUMtext
MD5:991ED103ED3ED73479107A746CEE6656
SHA256:10C07B1068F799A24D0D71A477D13A7358053C8569AA62633F4E7521E1C6F261
2268mp68-win-mg2500-1_02-ejs.exeC:\Users\admin\AppData\Local\Temp\WZSE0.TMP\mp68-win-mg2500-1_02-ejs\DrvSetup\DELDRV.dllexecutable
MD5:5FFD6DD00F7B09875DC74F2B5F73B4C3
SHA256:B7F4F2291C68B27687C4A83804F5E25524BF3803E59F1367AF8EEC082D46EF21
2268mp68-win-mg2500-1_02-ejs.exeC:\Users\admin\AppData\Local\Temp\WZSE0.TMP\mp68-win-mg2500-1_02-ejs\DrvSetup\DELDRV64.exeexecutable
MD5:86BDD5330EE0CD4DD46A32289352A0F1
SHA256:A9A2028D3745E60F416FC3534B7B1588C954A0773010836309A4002AF6EF78CB
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown

DNS requests

No data

Threats

No threats detected
No debug info