File name:

Label Printer Driver-V1.0.10.exe

Full analysis: https://app.any.run/tasks/eba00f4f-9f45-45b4-a9eb-228df00f14d4
Verdict: Malicious activity
Analysis date: November 29, 2024, 12:52:04
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 5 sections
MD5:

AB57CF536ABFB134237E9CBF21B40DFB

SHA1:

0A30BC237FA0230F09628696495E241128074E17

SHA256:

371F5EC09039168595AB4FCEB07CA68BC439C492BA01EF23D63B30206256D1DF

SSDEEP:

98304:vxykG9F1B3rz1Ax8ft4FojxO7YXZhwIhEC6FrYheeSSpZplJqPNbPNLPNfJ2JJF+:qF5xlS9

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • Label Printer Driver-V1.0.10.exe (PID: 2256)
    • Reads the Internet Settings

      • Label Printer Driver-V1.0.10.exe (PID: 2256)
    • Process drops legitimate windows executable

      • Label Printer Driver-V1.0.10.exe (PID: 2256)
    • Uses RUNDLL32.EXE to load library

      • Label Printer Driver-V1.0.10.exe (PID: 2256)
    • Executable content was dropped or overwritten

      • Label Printer Driver-V1.0.10.exe (PID: 2256)
  • INFO

    • Checks supported languages

      • Label Printer Driver-V1.0.10.exe (PID: 2256)
    • The process uses the downloaded file

      • Label Printer Driver-V1.0.10.exe (PID: 2256)
    • Reads the computer name

      • Label Printer Driver-V1.0.10.exe (PID: 2256)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (76.4)
.exe | Win32 Executable (generic) (12.4)
.exe | Generic Win/DOS Executable (5.5)
.exe | DOS Executable Generic (5.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:07:24 06:36:00+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14.16
CodeSize: 806912
InitializedDataSize: 5697024
UninitializedDataSize: -
EntryPoint: 0x8703a
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
40
Monitored processes
5
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start label printer driver-v1.0.10.exe rundll32.exe no specs rundll32.exe no specs rundll32.exe no specs label printer driver-v1.0.10.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1932"C:\Users\admin\AppData\Local\Temp\Label Printer Driver-V1.0.10.exe" C:\Users\admin\AppData\Local\Temp\Label Printer Driver-V1.0.10.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\appdata\local\temp\label printer driver-v1.0.10.exe
c:\windows\system32\ntdll.dll
2052"C:\Windows\System32\rundll32.exe" printui.dll, PrintUIEntry /p /n"LABEL" C:\Windows\System32\rundll32.exeLabel Printer Driver-V1.0.10.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
2256"C:\Users\admin\AppData\Local\Temp\Label Printer Driver-V1.0.10.exe" C:\Users\admin\AppData\Local\Temp\Label Printer Driver-V1.0.10.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\label printer driver-v1.0.10.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\bthprops.cpl
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
2776"C:\Windows\System32\rundll32.exe" printui.dll, PrintUIEntry /k /n"LABEL" C:\Windows\System32\rundll32.exeLabel Printer Driver-V1.0.10.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
2824"C:\Windows\System32\rundll32.exe" printui.dll, PrintUIEntry /k /n"LABEL" C:\Windows\System32\rundll32.exeLabel Printer Driver-V1.0.10.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
Total events
930
Read events
917
Write events
12
Delete events
1

Modification events

(PID) Process:(2256) Label Printer Driver-V1.0.10.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\SessionDefaultDevices\S-1-5-5-0-67184
Operation:delete valueName:Device
Value:
(PID) Process:(2256) Label Printer Driver-V1.0.10.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows
Operation:writeName:Device
Value:
LABEL,winspool,Ne02:
(PID) Process:(2256) Label Printer Driver-V1.0.10.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows
Operation:writeName:UserSelectedDefault
Value:
1
(PID) Process:(2256) Label Printer Driver-V1.0.10.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2256) Label Printer Driver-V1.0.10.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(2256) Label Printer Driver-V1.0.10.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(2256) Label Printer Driver-V1.0.10.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(2052) rundll32.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached
Operation:writeName:{675F097E-4C4D-11D0-B6C1-0800091AA605} {000214E9-0000-0000-C000-000000000046} 0xFFFF
Value:
0100000000000000384C0F905D42DB01
(PID) Process:(2052) rundll32.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached
Operation:writeName:{F37C5810-4D3F-11D0-B4BF-00AA00BBB723} {000214E9-0000-0000-C000-000000000046} 0xFFFF
Value:
0100000000000000384C0F905D42DB01
Executable files
5
Suspicious files
1
Text files
3
Unknown types
0

Dropped files

PID
Process
Filename
Type
2256Label Printer Driver-V1.0.10.exeC:\Windows\System32\spool\drivers\w32x86\stdnames.gpdtext
MD5:CD0BA5F62202298A6367E0E34CF5A37E
SHA256:B5E8E0C7339EF73F4DD20E2570EE2C79F06CA983F74D175DBE90C0319C70CE3A
2256Label Printer Driver-V1.0.10.exeC:\Windows\System32\spool\drivers\w32x86\unidrvui.dllexecutable
MD5:520F265539616A67D7FE8584CB8B35C5
SHA256:0A82C0AAFA9BA95C574A3A19D36EBBE46C7089A3B90917391F3A8CE7F2CC0A05
2256Label Printer Driver-V1.0.10.exeC:\Windows\System32\spool\drivers\w32x86\unidrv.dllexecutable
MD5:A14143FAEAFB0355D7103F14E60DB01A
SHA256:2B54B64EA3277530E4B945EB0262BFC12E38620C840ABA141AC2B70E6D91DE8A
2256Label Printer Driver-V1.0.10.exeC:\Windows\System32\spool\drivers\w32x86\LABELUI.dllexecutable
MD5:48099E3C97368906B278B60DA9C5AC0C
SHA256:ED13A749F02097B17D2C13350104EDC24613FA0FB80C93254FFCCD73768EB1FC
2256Label Printer Driver-V1.0.10.exeC:\Windows\System32\spool\drivers\w32x86\LabelPrinter.gpdtext
MD5:AA4A7A42700573965A2CBD263DE8DD77
SHA256:ECB9399E5193F8A79B45EBE21167A4AD838C783099D6ACF9D50BBC0D4C2FB845
2256Label Printer Driver-V1.0.10.exeC:\Windows\System32\spool\drivers\w32x86\LabelPrinter.initext
MD5:D36310C944F0CDA27D1EC61025BDE7E6
SHA256:3F43CB2450B1ECDE86FEBF8194BAA833E0243BEAB4B3E300885036F4876FB3FA
2256Label Printer Driver-V1.0.10.exeC:\Windows\System32\spool\drivers\w32x86\LABELCORE.dllexecutable
MD5:0EFDCA877E44F3F977B277702292CDF6
SHA256:C2FAEBF15BCD20A9853280533A105B0E2E6281A41D962256B06D63259E322001
2256Label Printer Driver-V1.0.10.exeC:\Windows\System32\spool\drivers\w32x86\unires.dllexecutable
MD5:8A059028FC98D9943D89E7AE8AD10683
SHA256:8D3AEAD3672774AD834C2E6AD4AD1E7333247CB8197A9C8FEA914C8D27B3EA8B
2256Label Printer Driver-V1.0.10.exeC:\Windows\System32\spool\drivers\w32x86\unidrv.hlpbinary
MD5:5210636FD75A915860BB399EF01944A5
SHA256:CB93B418D93C59CCE9C06E1EBBE1300C3E990413A379AE04C00718213516A709
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
6
DNS requests
1
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
224.0.0.252:5355
whitelisted
1108
svchost.exe
224.0.0.252:5355
whitelisted
192.168.100.189:49163
unknown
192.168.100.189:49164
unknown

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.185.206
whitelisted

Threats

No threats detected
No debug info