URL:

https://download.advanced-ip-scanner.com/download/files/Advanced_IP_Scanner_2.5.4594.1.exe

Full analysis: https://app.any.run/tasks/151efab6-b4e0-4014-b09a-39cb5456fbfe
Verdict: Malicious activity
Analysis date: March 24, 2025, 11:51:14
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
advancedipscanner
tool
delphi
inno
installer
scan
Indicators:
MD5:

183148B5D0D44271E91F44EFF74BE795

SHA1:

BEB9EC325D32C421848204F67498CD7EFA5F8A90

SHA256:

39C33444941E3E54F9A70280B8A7F080595AA7641AA3308B5FB64EE8CDF916DD

SSDEEP:

3:N8SElfGA5IWHuyNLfFL1XC7m0dA:2SKfXWWlSI

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • Advanced_IP_Scanner_2.5.4594.1.exe (PID: 2352)
      • advanced_ip_scanner.exe (PID: 3184)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • Advanced_IP_Scanner_2.5.4594.1.exe (PID: 2352)
      • Advanced_IP_Scanner_2.5.4594.1.tmp (PID: 3856)
    • Reads the Windows owner or organization settings

      • Advanced_IP_Scanner_2.5.4594.1.tmp (PID: 3856)
      • msiexec.exe (PID: 3044)
    • Process drops legitimate windows executable

      • Advanced_IP_Scanner_2.5.4594.1.tmp (PID: 3856)
      • msiexec.exe (PID: 3044)
    • Detection of a Network Scan

      • advanced_ip_scanner.exe (PID: 3184)
    • Reads settings of System Certificates

      • advanced_ip_scanner.exe (PID: 3184)
    • Connects to unusual port

      • advanced_ip_scanner.exe (PID: 3184)
    • Connects to FTP

      • advanced_ip_scanner.exe (PID: 3184)
    • Uses pipe srvsvc via SMB (transferring data)

      • advanced_ip_scanner.exe (PID: 3184)
    • The process drops C-runtime libraries

      • msiexec.exe (PID: 3044)
  • INFO

    • Modifies the phishing filter of IE

      • iexplore.exe (PID: 2480)
    • Application launched itself

      • iexplore.exe (PID: 2480)
      • msiexec.exe (PID: 3044)
    • Executable content was dropped or overwritten

      • iexplore.exe (PID: 1744)
      • iexplore.exe (PID: 2480)
      • msiexec.exe (PID: 3044)
    • Checks supported languages

      • Advanced_IP_Scanner_2.5.4594.1.exe (PID: 2352)
      • Advanced_IP_Scanner_2.5.4594.1.tmp (PID: 3856)
      • msiexec.exe (PID: 3044)
      • msiexec.exe (PID: 3688)
      • msiexec.exe (PID: 3020)
      • advanced_ip_scanner.exe (PID: 3184)
    • Create files in a temporary directory

      • Advanced_IP_Scanner_2.5.4594.1.exe (PID: 2352)
      • Advanced_IP_Scanner_2.5.4594.1.tmp (PID: 3856)
      • msiexec.exe (PID: 3044)
    • The sample compiled with english language support

      • Advanced_IP_Scanner_2.5.4594.1.tmp (PID: 3856)
      • msiexec.exe (PID: 3044)
    • ADVANCEDIPSCANNER mutex has been found

      • Advanced_IP_Scanner_2.5.4594.1.tmp (PID: 3856)
    • Reads the computer name

      • Advanced_IP_Scanner_2.5.4594.1.tmp (PID: 3856)
      • msiexec.exe (PID: 3044)
      • msiexec.exe (PID: 3020)
    • Reads the machine GUID from the registry

      • Advanced_IP_Scanner_2.5.4594.1.tmp (PID: 3856)
      • msiexec.exe (PID: 3044)
      • msiexec.exe (PID: 3688)
      • msiexec.exe (PID: 3020)
      • advanced_ip_scanner.exe (PID: 3184)
    • Reads the software policy settings

      • msiexec.exe (PID: 3044)
    • Detects InnoSetup installer (YARA)

      • Advanced_IP_Scanner_2.5.4594.1.exe (PID: 2352)
      • Advanced_IP_Scanner_2.5.4594.1.tmp (PID: 3856)
    • Compiled with Borland Delphi (YARA)

      • Advanced_IP_Scanner_2.5.4594.1.exe (PID: 2352)
      • Advanced_IP_Scanner_2.5.4594.1.tmp (PID: 3856)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 3044)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
43
Monitored processes
9
Malicious processes
4
Suspicious processes
1

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe advanced_ip_scanner_2.5.4594.1.exe advanced_ip_scanner_2.5.4594.1.tmp msiexec.exe msiexec.exe no specs msiexec.exe no specs advanced_ip_scanner.exe svchost.exe

Process information

PID
CMD
Path
Indicators
Parent process
1080C:\Windows\system32\svchost.exe -k NetworkServiceC:\Windows\System32\svchost.exe
services.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Host Process for Windows Services
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1744"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2480 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
2352"C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\Advanced_IP_Scanner_2.5.4594.1.exe" C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\Advanced_IP_Scanner_2.5.4594.1.exe
iexplore.exe
User:
admin
Company:
Famatech Corp.
Integrity Level:
MEDIUM
Description:
Advanced IP Scanner Setup
Exit code:
0
Version:
2.5.4594.1
Modules
Images
c:\users\admin\appdata\local\microsoft\windows\temporary internet files\content.ie5\b6qgx7lp\advanced_ip_scanner_2.5.4594.1.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2480"C:\Program Files\Internet Explorer\iexplore.exe" "https://download.advanced-ip-scanner.com/download/files/Advanced_IP_Scanner_2.5.4594.1.exe"C:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
3020C:\Windows\system32\MsiExec.exe -Embedding 24F3FC51DB33DD99B6DAC95591F8A7DF E Global\MSI0000C:\Windows\System32\msiexec.exemsiexec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3044C:\Windows\system32\msiexec.exe /VC:\Windows\System32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3184"C:\Program Files\Advanced IP Scanner\advanced_ip_scanner.exe"C:\Program Files\Advanced IP Scanner\advanced_ip_scanner.exe
Advanced_IP_Scanner_2.5.4594.1.tmp
User:
admin
Company:
Famatech Corp.
Integrity Level:
MEDIUM
Description:
Advanced IP Scanner
Version:
2.5.4594.1
Modules
Images
c:\program files\advanced ip scanner\advanced_ip_scanner.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3688C:\Windows\system32\MsiExec.exe -Embedding 439617A4E9B218863C7132F13124C02EC:\Windows\System32\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3856"C:\Users\admin\AppData\Local\Temp\is-MLEPU.tmp\Advanced_IP_Scanner_2.5.4594.1.tmp" /SL5="$4014E,20439558,139776,C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\Advanced_IP_Scanner_2.5.4594.1.exe" C:\Users\admin\AppData\Local\Temp\is-MLEPU.tmp\Advanced_IP_Scanner_2.5.4594.1.tmp
Advanced_IP_Scanner_2.5.4594.1.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-mlepu.tmp\advanced_ip_scanner_2.5.4594.1.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
Total events
26 452
Read events
26 033
Write events
385
Delete events
34

Modification events

(PID) Process:(2480) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPDaysSinceLastAutoMigration
Value:
1
(PID) Process:(2480) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchLowDateTime
Value:
238339360
(PID) Process:(2480) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchHighDateTime
Value:
31169715
(PID) Process:(2480) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateLowDateTime
Value:
538813110
(PID) Process:(2480) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
31169715
(PID) Process:(2480) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(2480) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(2480) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(2480) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(2480) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
Executable files
65
Suspicious files
63
Text files
41
Unknown types
0

Dropped files

PID
Process
Filename
Type
1080svchost.exeC:\Windows\ServiceProfiles\NetworkService\AppData\Local\Temp\Tar23B3.tmpbinary
MD5:91A1B89AA7A488DBB204DBB4767F1F21
SHA256:F6BE95C88C20EF82EE8A6878E16F9ECD77300BC1905EB826592A0DD41AD1C0F8
1080svchost.exeC:\Windows\ServiceProfiles\NetworkService\AppData\Local\Temp\Cab23B2.tmpcompressed
MD5:77B20B5CD41BC6BB475CCA3F91AE6E3C
SHA256:5511A9B9F9144ED7BDE4CCB074733B7C564D918D2A8B10D391AFC6BE5B3B1509
3856Advanced_IP_Scanner_2.5.4594.1.tmpC:\Users\admin\AppData\Local\Temp\is-O1NPR.tmp\is-AT223.tmp
MD5:
SHA256:
3856Advanced_IP_Scanner_2.5.4594.1.tmpC:\Users\admin\AppData\Local\Temp\is-O1NPR.tmp\ip_scan_en_us_Release_2.5.4594.1.msi
MD5:
SHA256:
3044msiexec.exeC:\Windows\Installer\18ab7d.msi
MD5:
SHA256:
1080svchost.exeC:\Windows\ServiceProfiles\NetworkService\AppData\Local\Temp\Cab23A0.tmpcompressed
MD5:77B20B5CD41BC6BB475CCA3F91AE6E3C
SHA256:5511A9B9F9144ED7BDE4CCB074733B7C564D918D2A8B10D391AFC6BE5B3B1509
1080svchost.exeC:\Windows\ServiceProfiles\NetworkService\AppData\Local\Temp\Tar23A1.tmpbinary
MD5:91A1B89AA7A488DBB204DBB4767F1F21
SHA256:F6BE95C88C20EF82EE8A6878E16F9ECD77300BC1905EB826592A0DD41AD1C0F8
1744iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\57C8EDB95DF3F0AD4EE2DC2B8CFD4157compressed
MD5:77B20B5CD41BC6BB475CCA3F91AE6E3C
SHA256:5511A9B9F9144ED7BDE4CCB074733B7C564D918D2A8B10D391AFC6BE5B3B1509
2480iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\Advanced_IP_Scanner_2.5.4594.1.exeexecutable
MD5:5537C708EDB9A2C21F88E34E8A0F1744
SHA256:26D5748FFE6BD95E3FEE6CE184D388A1A681006DC23A0F08D53C083C593C193B
2480iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\{4B73B859-08A6-11F0-B32B-12A9866C77DE}.datbinary
MD5:3BC3EA69838B2EDB3D747DF70032B771
SHA256:C5AB397C15A8DDAE44B7C204DCAF04892101091E5408431EAF9F5B2B5D5DCA18
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
35
DNS requests
12
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1744
iexplore.exe
GET
200
104.76.201.34:80
http://x1.c.lencr.org/
unknown
whitelisted
1744
iexplore.exe
GET
200
146.75.122.172:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?9585ecb6ce86c775
unknown
whitelisted
1744
iexplore.exe
GET
200
146.75.122.172:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?2c1c1224967e261d
unknown
whitelisted
2480
iexplore.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
3184
advanced_ip_scanner.exe
GET
200
188.40.30.100:80
http://www.advanced-ip-scanner.com/checkupdate.php?lng=en&ver=2-5-4594-1&beta=n&type=upd&rmode=i&product=aips
unknown
malicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
whitelisted
1744
iexplore.exe
213.133.104.63:443
download.advanced-ip-scanner.com
Hetzner Online GmbH
DE
malicious
4
System
192.168.100.255:138
whitelisted
1744
iexplore.exe
146.75.122.172:80
ctldl.windowsupdate.com
FASTLY
US
whitelisted
1744
iexplore.exe
104.76.201.34:80
x1.c.lencr.org
AKAMAI-AS
DE
whitelisted
2480
iexplore.exe
52.239.160.33:443
iecvlist.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
2480
iexplore.exe
184.30.131.245:80
ocsp.digicert.com
AKAMAI-AS
US
whitelisted
3184
advanced_ip_scanner.exe
188.40.30.100:80
www.advanced-ip-scanner.com
Hetzner Online GmbH
DE
shared
3184
advanced_ip_scanner.exe
192.168.100.2:4899
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.186.46
whitelisted
download.advanced-ip-scanner.com
  • 213.133.104.63
malicious
ctldl.windowsupdate.com
  • 146.75.122.172
whitelisted
x1.c.lencr.org
  • 104.76.201.34
whitelisted
r20swj13mr.microsoft.com
whitelisted
iecvlist.microsoft.com
  • 52.239.160.33
whitelisted
ocsp.digicert.com
  • 184.30.131.245
whitelisted
www.advanced-ip-scanner.com
  • 188.40.30.100
shared
2.100.168.192.in-addr.arpa
whitelisted
1.100.168.192.in-addr.arpa
unknown

Threats

PID
Process
Class
Message
3184
advanced_ip_scanner.exe
Misc activity
INFO [ANY.RUN] USER_AGENTS Suspicious User-Agent (Mozilla/5.0)
3184
advanced_ip_scanner.exe
Detection of a Network Scan
ET ADWARE_PUP IP Scanner Tool Update Request (GET)
No debug info