File name:

mypr-win-3_3_0-ea11_2.exe

Full analysis: https://app.any.run/tasks/3c6df926-e59c-42bc-b0ca-9de912e433a3
Verdict: Malicious activity
Analysis date: March 19, 2022, 19:14:12
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

5E490B9D8C2C3BFA273E4708F1AA609D

SHA1:

A150B3608DCB744F6BEA5F22388466AC79584138

SHA256:

3C66677DC1085932F685638CE3CBCC15D53370067A89DD9090D28A011F3271FF

SSDEEP:

98304:OiM1Ua7ewhUp+2L5fBfVRS6c+broB88B9zbzJnTu0BIs595H2LEfJkbppXpH/bn:ZQX6p+2NBfVaUUB9fzxTtljH2QfJEjXJ

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Setup.exe (PID: 2676)
    • Loads dropped or rewritten executable

      • Setup.exe (PID: 2676)
    • Drops executable file immediately after starts

      • mypr-win-3_3_0-ea11_2.exe (PID: 3780)
      • Setup.exe (PID: 2676)
    • Actions looks like stealing of personal data

      • mypr-win-3_3_0-ea11_2.exe (PID: 3780)
  • SUSPICIOUS

    • Checks supported languages

      • mypr-win-3_3_0-ea11_2.exe (PID: 3780)
      • Setup.exe (PID: 2676)
    • Drops a file that was compiled in debug mode

      • Setup.exe (PID: 2676)
    • Executable content was dropped or overwritten

      • mypr-win-3_3_0-ea11_2.exe (PID: 3780)
      • Setup.exe (PID: 2676)
    • Reads the computer name

      • Setup.exe (PID: 2676)
    • Creates a directory in Program Files

      • Setup.exe (PID: 2676)
    • Creates a software uninstall entry

      • Setup.exe (PID: 2676)
    • Creates files in the program directory

      • Setup.exe (PID: 2676)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (32.1)
.exe | Win64 Executable (generic) (28.5)
.exe | Winzip Win32 self-extracting archive (generic) (23.7)
.dll | Win32 Dynamic Link Library (generic) (6.7)
.exe | Win32 Executable (generic) (4.6)

EXIF

EXE

Subsystem: Windows GUI
SubsystemVersion: 4
ImageVersion: -
OSVersion: 4
EntryPoint: 0xaf1e
UninitializedDataSize: -
InitializedDataSize: 65536
CodeSize: 77824
LinkerVersion: 8
PEType: PE32
TimeStamp: 2009:11:02 21:24:15+01:00
MachineType: Intel 386 or later, and compatibles

Summary

Architecture: IMAGE_FILE_MACHINE_I386
Subsystem: IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date: 02-Nov-2009 20:24:15
Detected languages:
  • English - United States

DOS Header

Magic number: MZ
Bytes on last page of file: 0x0090
Pages in file: 0x0003
Relocations: 0x0000
Size of header: 0x0004
Min extra paragraphs: 0x0000
Max extra paragraphs: 0xFFFF
Initial SS value: 0x0000
Initial SP value: 0x00B8
Checksum: 0x0000
Initial IP value: 0x0000
Initial CS value: 0x0000
Overlay number: 0x0000
OEM identifier: 0x0000
OEM information: 0x0000
Address of NE header: 0x000000F0

PE Headers

Signature: PE
Machine: IMAGE_FILE_MACHINE_I386
Number of sections: 5
Time date stamp: 02-Nov-2009 20:24:15
Pointer to Symbol Table: 0x00000000
Number of symbols: 0
Size of Optional Header: 0x00E0
Characteristics:
  • IMAGE_FILE_32BIT_MACHINE
  • IMAGE_FILE_EXECUTABLE_IMAGE
  • IMAGE_FILE_RELOCS_STRIPPED

Sections

Name
Virtual Address
Virtual Size
Raw Size
Charateristics
Entropy
.text
0x00001000
0x00012775
0x00013000
IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
6.50172
.rdata
0x00014000
0x00003822
0x00004000
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
4.98675
.data
0x00018000
0x0000E6E4
0x00002000
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
1.97167
.rsrc
0x00027000
0x00009B6C
0x0000A000
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
5.56412
_winzip_
0x00031000
0x00568000
0x00568000
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
7.99967

Resources

Title
Entropy
Size
Codepage
Language
Type
1
5.04402
1503
Latin 1 / Western European
English - United States
RT_MANIFEST
2
4.03621
744
Latin 1 / Western European
English - United States
RT_ICON
3
3.14459
296
Latin 1 / Western European
English - United States
RT_ICON
4
5.56342
3752
Latin 1 / Western European
English - United States
RT_ICON
5
5.99214
2216
Latin 1 / Western European
English - United States
RT_ICON
6
3.69605
1384
Latin 1 / Western European
English - United States
RT_ICON
7
5.83382
9640
Latin 1 / Western European
English - United States
RT_ICON
8
6.01045
4264
Latin 1 / Western European
English - United States
RT_ICON
9
4.68735
1128
Latin 1 / Western European
English - United States
RT_ICON
63
3.18826
764
Latin 1 / Western European
English - United States
RT_STRING

Imports

COMCTL32.dll
GDI32.dll
KERNEL32.dll
SHELL32.dll
USER32.dll
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
40
Monitored processes
3
Malicious processes
1
Suspicious processes
1

Behavior graph

Click at the process to see the details
drop and start start mypr-win-3_3_0-ea11_2.exe setup.exe mypr-win-3_3_0-ea11_2.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2404"C:\Users\admin\AppData\Local\Temp\mypr-win-3_3_0-ea11_2.exe" C:\Users\admin\AppData\Local\Temp\mypr-win-3_3_0-ea11_2.exeExplorer.EXE
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\appdata\local\temp\mypr-win-3_3_0-ea11_2.exe
c:\windows\system32\ntdll.dll
2676".\mypr-win-3_3_0-ea11_2\Setup.exe"C:\Users\admin\AppData\Local\Temp\WZSE0.TMP\mypr-win-3_3_0-ea11_2\Setup.exe
mypr-win-3_3_0-ea11_2.exe
User:
admin
Company:
CANON INC.
Integrity Level:
HIGH
Description:
SETUP
Exit code:
0
Version:
4.1.0.0
Modules
Images
c:\users\admin\appdata\local\temp\wzse0.tmp\mypr-win-3_3_0-ea11_2\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\wininet.dll
c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
c:\windows\system32\user32.dll
3780"C:\Users\admin\AppData\Local\Temp\mypr-win-3_3_0-ea11_2.exe" C:\Users\admin\AppData\Local\Temp\mypr-win-3_3_0-ea11_2.exe
Explorer.EXE
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\mypr-win-3_3_0-ea11_2.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
Total events
400
Read events
371
Write events
29
Delete events
0

Modification events

(PID) Process:(2676) Setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Canon\MyPrinter
Operation:writeName:AppPath
Value:
C:\Program Files\Canon\MyPrinter\BJMyPrt.exe
(PID) Process:(2676) Setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Canon\MyPrinter
Operation:writeName:DiagPath
Value:
C:\Program Files\Canon\MyPrinter\BJMyDgn.exe
(PID) Process:(2676) Setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Canon\MyPrinter
Operation:writeName:SMFlag
Value:
/SM
(PID) Process:(2676) Setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Canon\MyPrinter
Operation:writeName:DSFlag
Value:
/DS
(PID) Process:(2676) Setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Canon\MyPrinter\Canon Utilities\My Printer\LegacySupport
Operation:writeName:(default)
Value:
(PID) Process:(2676) Setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Canon\MyPrinter\Canon Utilities\My Printer\NewCmdSupport
Operation:writeName:(default)
Value:
(PID) Process:(2676) Setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\BJMYPRT.EXE
Operation:writeName:(default)
Value:
C:\Program Files\Canon\MyPrinter\BJMyPrt.exe
(PID) Process:(2676) Setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\BJMYPRT.EXE
Operation:writeName:Path
Value:
C:\Program Files\Canon\MyPrinter
(PID) Process:(2676) Setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\BJMYDGN.EXE
Operation:writeName:(default)
Value:
C:\Program Files\Canon\MyPrinter\BJMyDgn.exe
(PID) Process:(2676) Setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\BJMYDGN.EXE
Operation:writeName:Path
Value:
C:\Program Files\Canon\MyPrinter
Executable files
83
Suspicious files
6
Text files
163
Unknown types
2

Dropped files

PID
Process
Filename
Type
3780mypr-win-3_3_0-ea11_2.exeC:\Users\admin\AppData\Local\Temp\WZSE0.TMP\mypr-win-3_3_0-ea11_2\CHECKSUMtext
MD5:8856285A7CB7DDC22B3245EFA1176B4A
SHA256:69161E031E0765FDBE7B0884D922F40DEDC664A6AEA14854C899A52330990530
3780mypr-win-3_3_0-ea11_2.exeC:\Users\admin\AppData\Local\Temp\WZSE0.TMP\mypr-win-3_3_0-ea11_2\MUI.dllexecutable
MD5:8AE6266B99B24698D84A86E8BDCD9CB2
SHA256:4086331FF53C34B9FF6E4CB14D3932FD7FFB42296DB6CB0F1EE96A4441903A5A
3780mypr-win-3_3_0-ea11_2.exeC:\Users\admin\AppData\Local\Temp\WZSE0.TMP\mypr-win-3_3_0-ea11_2\res\EULA\AS_English.txttext
MD5:175E363C9074201AD380C302C2C6B707
SHA256:7B94AC7F01B7F516AA2783BEA1B3A368D5B7877CA28880F198C25C849A82BEF4
3780mypr-win-3_3_0-ea11_2.exeC:\Users\admin\AppData\Local\Temp\WZSE0.TMP\mypr-win-3_3_0-ea11_2\Data3.cabcompressed
MD5:5698B04F2D87CE74DA02785556E94D33
SHA256:C6253FEACE394D02BCCC30F1666D2336A6A9BE64EEB466338BED4F49989EA58A
3780mypr-win-3_3_0-ea11_2.exeC:\Users\admin\AppData\Local\Temp\WZSE0.TMP\mypr-win-3_3_0-ea11_2\Data2.cabcompressed
MD5:F37D5C37228254AE3CE3DD0C84E6E500
SHA256:4629EEA1DC643ABD85E884043C7544EF83EBDAD335988EDC4D6213E55539E45B
3780mypr-win-3_3_0-ea11_2.exeC:\Users\admin\AppData\Local\Temp\WZSE0.TMP\mypr-win-3_3_0-ea11_2\res\EULA\EC_French.txttext
MD5:EC6830F6F5270052CF7A2B1EBB010E60
SHA256:EE6DFD5ACA8C7ACB5038A3D3B042500FCD70B62B17E1BD376B848C7F99110CF9
3780mypr-win-3_3_0-ea11_2.exeC:\Users\admin\AppData\Local\Temp\WZSE0.TMP\mypr-win-3_3_0-ea11_2\res\EULA\EC_Czech.txttext
MD5:99BF4E03D5C5B65179F444B36F01FBEE
SHA256:BD662F50E2736C7B5A931A33167AC65E35F833EC0432884E9CFEA0C589E6B3C2
3780mypr-win-3_3_0-ea11_2.exeC:\Users\admin\AppData\Local\Temp\WZSE0.TMP\mypr-win-3_3_0-ea11_2\res\EULA\EC_German.txttext
MD5:88A6F3B3DF08971D1172C89ED79C575B
SHA256:9140DF0AD5AE06D41DD45B23741768565DA81D55450B45717D0A77898E17C4FF
3780mypr-win-3_3_0-ea11_2.exeC:\Users\admin\AppData\Local\Temp\WZSE0.TMP\mypr-win-3_3_0-ea11_2\res\EULA\EC_Polish.txttext
MD5:91A6FFFC3ACEE706C3EE465613B06E7C
SHA256:DB160115EDBC480E24992D2890950001C24F456C4DBCBB4F69D67E3280C1C198
3780mypr-win-3_3_0-ea11_2.exeC:\Users\admin\AppData\Local\Temp\WZSE0.TMP\mypr-win-3_3_0-ea11_2\res\EULA\EC_Russian.txttext
MD5:DD0B346465CD52E448CA39A079CA74F6
SHA256:3F02EB0377350471711A8832FB76A44B64FAEF620FB82ED4925D597656092F5F
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info