| File name: | Label Printer Driver-V1.0.10.exe |
| Full analysis: | https://app.any.run/tasks/eba00f4f-9f45-45b4-a9eb-228df00f14d4 |
| Verdict: | Malicious activity |
| Analysis date: | November 29, 2024, 12:52:04 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, 5 sections |
| MD5: | AB57CF536ABFB134237E9CBF21B40DFB |
| SHA1: | 0A30BC237FA0230F09628696495E241128074E17 |
| SHA256: | 371F5EC09039168595AB4FCEB07CA68BC439C492BA01EF23D63B30206256D1DF |
| SSDEEP: | 98304:vxykG9F1B3rz1Ax8ft4FojxO7YXZhwIhEC6FrYheeSSpZplJqPNbPNLPNfJ2JJF+:qF5xlS9 |
| .exe | | | Win64 Executable (generic) (76.4) |
|---|---|---|
| .exe | | | Win32 Executable (generic) (12.4) |
| .exe | | | Generic Win/DOS Executable (5.5) |
| .exe | | | DOS Executable Generic (5.5) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2024:07:24 06:36:00+00:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 14.16 |
| CodeSize: | 806912 |
| InitializedDataSize: | 5697024 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x8703a |
| OSVersion: | 5.1 |
| ImageVersion: | - |
| SubsystemVersion: | 5.1 |
| Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1932 | "C:\Users\admin\AppData\Local\Temp\Label Printer Driver-V1.0.10.exe" | C:\Users\admin\AppData\Local\Temp\Label Printer Driver-V1.0.10.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 3221226540 Modules
| |||||||||||||||
| 2052 | "C:\Windows\System32\rundll32.exe" printui.dll, PrintUIEntry /p /n"LABEL" | C:\Windows\System32\rundll32.exe | — | Label Printer Driver-V1.0.10.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows host process (Rundll32) Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2256 | "C:\Users\admin\AppData\Local\Temp\Label Printer Driver-V1.0.10.exe" | C:\Users\admin\AppData\Local\Temp\Label Printer Driver-V1.0.10.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 2776 | "C:\Windows\System32\rundll32.exe" printui.dll, PrintUIEntry /k /n"LABEL" | C:\Windows\System32\rundll32.exe | — | Label Printer Driver-V1.0.10.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows host process (Rundll32) Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2824 | "C:\Windows\System32\rundll32.exe" printui.dll, PrintUIEntry /k /n"LABEL" | C:\Windows\System32\rundll32.exe | — | Label Printer Driver-V1.0.10.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows host process (Rundll32) Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (2256) Label Printer Driver-V1.0.10.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\SessionDefaultDevices\S-1-5-5-0-67184 |
| Operation: | delete value | Name: | Device |
Value: | |||
| (PID) Process: | (2256) Label Printer Driver-V1.0.10.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows |
| Operation: | write | Name: | Device |
Value: LABEL,winspool,Ne02: | |||
| (PID) Process: | (2256) Label Printer Driver-V1.0.10.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows |
| Operation: | write | Name: | UserSelectedDefault |
Value: 1 | |||
| (PID) Process: | (2256) Label Printer Driver-V1.0.10.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (2256) Label Printer Driver-V1.0.10.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (2256) Label Printer Driver-V1.0.10.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (2256) Label Printer Driver-V1.0.10.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (2052) rundll32.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached |
| Operation: | write | Name: | {675F097E-4C4D-11D0-B6C1-0800091AA605} {000214E9-0000-0000-C000-000000000046} 0xFFFF |
Value: 0100000000000000384C0F905D42DB01 | |||
| (PID) Process: | (2052) rundll32.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached |
| Operation: | write | Name: | {F37C5810-4D3F-11D0-B4BF-00AA00BBB723} {000214E9-0000-0000-C000-000000000046} 0xFFFF |
Value: 0100000000000000384C0F905D42DB01 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2256 | Label Printer Driver-V1.0.10.exe | C:\Windows\System32\spool\drivers\w32x86\stdnames.gpd | text | |
MD5:CD0BA5F62202298A6367E0E34CF5A37E | SHA256:B5E8E0C7339EF73F4DD20E2570EE2C79F06CA983F74D175DBE90C0319C70CE3A | |||
| 2256 | Label Printer Driver-V1.0.10.exe | C:\Windows\System32\spool\drivers\w32x86\unidrvui.dll | executable | |
MD5:520F265539616A67D7FE8584CB8B35C5 | SHA256:0A82C0AAFA9BA95C574A3A19D36EBBE46C7089A3B90917391F3A8CE7F2CC0A05 | |||
| 2256 | Label Printer Driver-V1.0.10.exe | C:\Windows\System32\spool\drivers\w32x86\unidrv.dll | executable | |
MD5:A14143FAEAFB0355D7103F14E60DB01A | SHA256:2B54B64EA3277530E4B945EB0262BFC12E38620C840ABA141AC2B70E6D91DE8A | |||
| 2256 | Label Printer Driver-V1.0.10.exe | C:\Windows\System32\spool\drivers\w32x86\LABELUI.dll | executable | |
MD5:48099E3C97368906B278B60DA9C5AC0C | SHA256:ED13A749F02097B17D2C13350104EDC24613FA0FB80C93254FFCCD73768EB1FC | |||
| 2256 | Label Printer Driver-V1.0.10.exe | C:\Windows\System32\spool\drivers\w32x86\LabelPrinter.gpd | text | |
MD5:AA4A7A42700573965A2CBD263DE8DD77 | SHA256:ECB9399E5193F8A79B45EBE21167A4AD838C783099D6ACF9D50BBC0D4C2FB845 | |||
| 2256 | Label Printer Driver-V1.0.10.exe | C:\Windows\System32\spool\drivers\w32x86\LabelPrinter.ini | text | |
MD5:D36310C944F0CDA27D1EC61025BDE7E6 | SHA256:3F43CB2450B1ECDE86FEBF8194BAA833E0243BEAB4B3E300885036F4876FB3FA | |||
| 2256 | Label Printer Driver-V1.0.10.exe | C:\Windows\System32\spool\drivers\w32x86\LABELCORE.dll | executable | |
MD5:0EFDCA877E44F3F977B277702292CDF6 | SHA256:C2FAEBF15BCD20A9853280533A105B0E2E6281A41D962256B06D63259E322001 | |||
| 2256 | Label Printer Driver-V1.0.10.exe | C:\Windows\System32\spool\drivers\w32x86\unires.dll | executable | |
MD5:8A059028FC98D9943D89E7AE8AD10683 | SHA256:8D3AEAD3672774AD834C2E6AD4AD1E7333247CB8197A9C8FEA914C8D27B3EA8B | |||
| 2256 | Label Printer Driver-V1.0.10.exe | C:\Windows\System32\spool\drivers\w32x86\unidrv.hlp | binary | |
MD5:5210636FD75A915860BB399EF01944A5 | SHA256:CB93B418D93C59CCE9C06E1EBBE1300C3E990413A379AE04C00718213516A709 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
— | — | 224.0.0.252:5355 | — | — | — | whitelisted |
1108 | svchost.exe | 224.0.0.252:5355 | — | — | — | whitelisted |
— | — | 192.168.100.189:49163 | — | — | — | unknown |
— | — | 192.168.100.189:49164 | — | — | — | unknown |
Domain | IP | Reputation |
|---|---|---|
google.com |
| whitelisted |