File name:

XP200i.exe

Full analysis: https://app.any.run/tasks/aa9badfe-ced6-4cc7-96b1-2a3afe477bcf
Verdict: Malicious activity
Analysis date: January 16, 2025, 17:54:55
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 4 sections
MD5:

ECAA9929D7B797D2080B8E677E8E8A7A

SHA1:

88100FBA469D7FD3D02776BC12973BF48C8E5EFF

SHA256:

32C157B7BF9DECE0798A98B44C2E177DE1B99EEB28155FBF88D8B9BB14841A12

SSDEEP:

98304:gwe/kikymhkXOSYIyDEYnf89PjtmOzSoTjMWK6bzXLpaRUe13jtwhAvEKKL4ZC62:NWi2KN2G8YPewA

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • XP200i.exe (PID: 2248)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • XP200i.exe (PID: 2248)
      • Setup.exe (PID: 532)
      • _INS5576._MP (PID: 3404)
    • Reads the Internet Settings

      • XP200i.exe (PID: 2248)
      • ScannerRegistration.exe (PID: 1424)
    • Reads security settings of Internet Explorer

      • XP200i.exe (PID: 2248)
      • ScannerRegistration.exe (PID: 1424)
    • Drops a system driver (possible attempt to evade defenses)

      • XP200i.exe (PID: 2248)
      • _INS5576._MP (PID: 3404)
    • Creates/Modifies COM task schedule object

      • GLJ83A5.tmp (PID: 1996)
      • GLJ83A5.tmp (PID: 1924)
      • GLJ83A5.tmp (PID: 3264)
      • GLJ83A5.tmp (PID: 3104)
      • GLJ83A5.tmp (PID: 1080)
      • GLJ83A5.tmp (PID: 120)
      • GLJ83A5.tmp (PID: 1176)
      • GLJ83A5.tmp (PID: 2616)
      • GLJ83A5.tmp (PID: 2648)
    • Starts application with an unusual extension

      • XP200i.exe (PID: 2248)
      • Setup.exe (PID: 532)
    • Uses REG/REGEDIT.EXE to modify registry

      • OneTouchMon.exe (PID: 1288)
    • Creates file in the systems drive root

      • _isdel.exe (PID: 1280)
    • Searches for installed software

      • _INS5576._MP (PID: 3404)
      • XP200i.exe (PID: 2248)
    • Process drops legitimate windows executable

      • _INS5576._MP (PID: 3404)
      • XP200i.exe (PID: 2248)
    • Creates a software uninstall entry

      • _INS5576._MP (PID: 3404)
      • XP200i.exe (PID: 2248)
    • The process drops C-runtime libraries

      • XP200i.exe (PID: 2248)
  • INFO

    • Create files in a temporary directory

      • XP200i.exe (PID: 2248)
      • OneTouchMon.exe (PID: 1288)
      • Setup.exe (PID: 532)
      • _INS5576._MP (PID: 3404)
    • Checks supported languages

      • XP200i.exe (PID: 2248)
      • GLJ83A5.tmp (PID: 1996)
      • STBXPCOM.exe (PID: 828)
      • VizPnP.exe (PID: 1780)
      • GLJ83A5.tmp (PID: 1924)
      • GLJ83A5.tmp (PID: 3264)
      • GLJ83A5.tmp (PID: 3104)
      • GLJ83A5.tmp (PID: 1080)
      • GLJ83A5.tmp (PID: 120)
      • GLJ83A5.tmp (PID: 1176)
      • GLJ83A5.tmp (PID: 2616)
      • GLJ83A5.tmp (PID: 2648)
      • ScannerRegistration.exe (PID: 1424)
      • OTConn.exe (PID: 3100)
      • OneTouchMon.exe (PID: 1288)
      • Setup.exe (PID: 532)
      • _INS5576._MP (PID: 3404)
      • _isdel.exe (PID: 1280)
    • Reads the computer name

      • XP200i.exe (PID: 2248)
      • GLJ83A5.tmp (PID: 1996)
      • GLJ83A5.tmp (PID: 1924)
      • GLJ83A5.tmp (PID: 3264)
      • OneTouchMon.exe (PID: 1288)
      • ScannerRegistration.exe (PID: 1424)
      • Setup.exe (PID: 532)
      • _INS5576._MP (PID: 3404)
      • _isdel.exe (PID: 1280)
    • Creates files in the program directory

      • XP200i.exe (PID: 2248)
    • The sample compiled with chinese language support

      • XP200i.exe (PID: 2248)
    • Reads the machine GUID from the registry

      • OneTouchMon.exe (PID: 1288)
      • ScannerRegistration.exe (PID: 1424)
    • Checks proxy server information

      • ScannerRegistration.exe (PID: 1424)
    • The sample compiled with english language support

      • Setup.exe (PID: 532)
      • _INS5576._MP (PID: 3404)
      • XP200i.exe (PID: 2248)
    • The process uses the downloaded file

      • XP200i.exe (PID: 2248)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Wise Installer executable (86.4)
.exe | Win32 Executable MS Visual C++ (generic) (5.7)
.exe | Win64 Executable (generic) (5)
.dll | Win32 Dynamic Link Library (generic) (1.2)
.exe | Win32 Executable (generic) (0.8)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2001:10:25 19:47:11+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit, Removable run from swap
PEType: PE32
LinkerVersion: 6
CodeSize: 8704
InitializedDataSize: 5632
UninitializedDataSize: -
EntryPoint: 0x21af
OSVersion: 4
ImageVersion: 4
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 0.0.0.0
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows 16-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
CompanyName: Visioneer
FileDescription: OneTouch Version 3.0
FileVersion: OneTouch 3.0
LegalCopyright: 1999 - 2003
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
57
Monitored processes
20
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start xp200i.exe stbxpcom.exe no specs vizpnp.exe no specs glj83a5.tmp no specs glj83a5.tmp no specs glj83a5.tmp no specs glj83a5.tmp no specs glj83a5.tmp no specs glj83a5.tmp no specs glj83a5.tmp no specs glj83a5.tmp no specs glj83a5.tmp no specs otconn.exe no specs onetouchmon.exe no specs scannerregistration.exe regedit.exe no specs setup.exe _ins5576._mp _isdel.exe no specs xp200i.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
120"C:\Users\admin\AppData\Local\Temp\GLJ83A5.tmp" C:\Program Files\Visioneer OneTouch\OneTouchImgConv.dllC:\Users\admin\AppData\Local\Temp\GLJ83A5.tmpXP200i.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\glj83a5.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
532"C:\Windows\twain_32\StrobeXp\Setup.exe" C:\Windows\twain_32\StrobeXp\Setup.exe
XP200i.exe
User:
admin
Company:
InstallShield Software Corporation
Integrity Level:
HIGH
Description:
32-bit Setup Launcher
Exit code:
0
Version:
5, 52, 164, 0
Modules
Images
c:\windows\twain_32\strobexp\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
828"C:\PROGRA~1\VISION~1\STBXPCOM.exe" /RegServerC:\Program Files\Visioneer OneTouch\STBXPCOM.exeXP200i.exe
User:
admin
Integrity Level:
HIGH
Description:
STBXPCOM Module
Exit code:
0
Version:
2, 4, 12, 13
Modules
Images
c:\program files\visioneer onetouch\stbxpcom.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\sti.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1080"C:\Users\admin\AppData\Local\Temp\GLJ83A5.tmp" C:\Program Files\Visioneer OneTouch\OneTouchHardware.dllC:\Users\admin\AppData\Local\Temp\GLJ83A5.tmpXP200i.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\glj83a5.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
1176"C:\Users\admin\AppData\Local\Temp\GLJ83A5.tmp" C:\Program Files\Visioneer OneTouch\stbxpdkw.dllC:\Users\admin\AppData\Local\Temp\GLJ83A5.tmpXP200i.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\glj83a5.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
1280C:\Windows\twain_32\StrobeXp\_ISDEL.EXEC:\Windows\twain_32\StrobeXp\_isdel.exeSetup.exe
User:
admin
Company:
InstallShield Software Corporation
Integrity Level:
HIGH
Description:
32-bit InstallShield Deleter.
Version:
5, 51, 138, 0
Modules
Images
c:\windows\twain_32\strobexp\_isdel.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\apphelp.dll
1288"C:\PROGRA~1\VISION~1\ONETOU~2.EXE" /CreateNewUserC:\Program Files\Visioneer OneTouch\OneTouchMon.exeXP200i.exe
User:
admin
Company:
Visioneer Inc
Integrity Level:
HIGH
Description:
OneTouch Module
Exit code:
0
Version:
3, 3, 8, 6
Modules
Images
c:\program files\visioneer onetouch\onetouchmon.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mfc42.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1424"C:\Users\admin\AppData\Local\Temp\SCANNE~1.EXE" /M/XP200/ /C/VISIONEER/C:\Users\admin\AppData\Local\Temp\ScannerRegistration.exe
XP200i.exe
User:
admin
Integrity Level:
HIGH
Description:
ScannerRegistration MFC Application
Exit code:
0
Version:
1, 0, 0, 1
Modules
Images
c:\users\admin\appdata\local\temp\scannerregistration.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wininet.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
1544C:\Windows\regedit.exe /s "C:\PROGRA~1\VISION~1\OneTouch.reg"C:\Windows\regedit.exeOneTouchMon.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Registry Editor
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\regedit.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1780"C:\PROGRA~1\VISION~1\VizPnP.exe" C:\Windows\Inf\onetouch.infC:\Program Files\Visioneer OneTouch\VizPnP.exeXP200i.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\program files\visioneer onetouch\vizpnp.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sspicli.dll
Total events
2 585
Read events
2 024
Write events
554
Delete events
7

Modification events

(PID) Process:(2248) XP200i.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Visioneer\Onetouch
Operation:writeName:Force DocDeposit
Value:
71565244
(PID) Process:(2248) XP200i.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Visioneer Strobe XP 200
Operation:writeName:DisplayName
Value:
Visioneer Strobe XP 200
(PID) Process:(2248) XP200i.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Visioneer Strobe XP 200
Operation:writeName:UninstallString
Value:
C:\PROGRA~1\VISION~1\UNWISE.EXE C:\PROGRA~1\VISION~1\INSTALL.LOG
(PID) Process:(2248) XP200i.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Visioneer\Onetouch
Operation:writeName:Hardware
Value:
Strobe XP 200
(PID) Process:(2248) XP200i.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Visioneer\Onetouch
Operation:writeName:InstallDir
Value:
C:\Program Files\Visioneer OneTouch
(PID) Process:(2248) XP200i.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2248) XP200i.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(2248) XP200i.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(2248) XP200i.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(828) STBXPCOM.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EFB4AF77-F452-4AAE-BE1C-AD8EDA2020B4}
Operation:writeName:AppID
Value:
{F54FC680-EC70-4BE6-B9A6-7D74A7C8CCF0}
Executable files
147
Suspicious files
21
Text files
17
Unknown types
0

Dropped files

PID
Process
Filename
Type
2248XP200i.exeC:\Users\admin\AppData\Local\Temp\GLF8F72.tmp
MD5:
SHA256:
2248XP200i.exeC:\Windows\Help\OneTouch.chm
MD5:
SHA256:
2248XP200i.exeC:\Windows\Help\Scanner Guide.pdf
MD5:
SHA256:
2248XP200i.exeC:\Program Files\Visioneer OneTouch\~GLH0009.TMP
MD5:
SHA256:
2248XP200i.exeC:\Program Files\Visioneer OneTouch\~GLH000a.TMP
MD5:
SHA256:
2248XP200i.exeC:\Program Files\Visioneer OneTouch\STBXPCOM.exe
MD5:
SHA256:
2248XP200i.exeC:\Program Files\Visioneer OneTouch\~GLH000b.TMP
MD5:
SHA256:
2248XP200i.exeC:\Program Files\Visioneer OneTouch\~GLH000c.TMP
MD5:
SHA256:
2248XP200i.exeC:\Program Files\Visioneer OneTouch\~GLH000d.TMP
MD5:
SHA256:
2248XP200i.exeC:\Users\admin\AppData\Local\Temp\~GLH0000.TMPexecutable
MD5:3B2E23D259394C701050486E642D14FA
SHA256:166D7156142F3EE09FA69EB617DD22E4FD248AA80A1AC08767DB6AD99A2705C1
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
3
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
224.0.0.252:5355
whitelisted
4
System
192.168.100.255:138
whitelisted
192.168.100.255:137
whitelisted
1424
ScannerRegistration.exe
71.140.176.206:80
jsma.visioneerdirect.com
ATT-INTERNET4
US
unknown

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.186.142
whitelisted
jsma.visioneerdirect.com
  • 71.140.176.206
unknown
dns.msftncsi.com
  • 131.107.255.255
whitelisted

Threats

No threats detected
No debug info