File name:

mypr-win-3_3_0-ea11_2.exe

Full analysis: https://app.any.run/tasks/3c6df926-e59c-42bc-b0ca-9de912e433a3
Verdict: Malicious activity
Analysis date: March 19, 2022, 19:14:12
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

5E490B9D8C2C3BFA273E4708F1AA609D

SHA1:

A150B3608DCB744F6BEA5F22388466AC79584138

SHA256:

3C66677DC1085932F685638CE3CBCC15D53370067A89DD9090D28A011F3271FF

SSDEEP:

98304:OiM1Ua7ewhUp+2L5fBfVRS6c+broB88B9zbzJnTu0BIs595H2LEfJkbppXpH/bn:ZQX6p+2NBfVaUUB9fzxTtljH2QfJEjXJ

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Actions looks like stealing of personal data

      • mypr-win-3_3_0-ea11_2.exe (PID: 3780)
    • Drops executable file immediately after starts

      • mypr-win-3_3_0-ea11_2.exe (PID: 3780)
      • Setup.exe (PID: 2676)
    • Application was dropped or rewritten from another process

      • Setup.exe (PID: 2676)
    • Loads dropped or rewritten executable

      • Setup.exe (PID: 2676)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • mypr-win-3_3_0-ea11_2.exe (PID: 3780)
      • Setup.exe (PID: 2676)
    • Checks supported languages

      • mypr-win-3_3_0-ea11_2.exe (PID: 3780)
      • Setup.exe (PID: 2676)
    • Drops a file that was compiled in debug mode

      • Setup.exe (PID: 2676)
    • Reads the computer name

      • Setup.exe (PID: 2676)
    • Creates a directory in Program Files

      • Setup.exe (PID: 2676)
    • Creates a software uninstall entry

      • Setup.exe (PID: 2676)
    • Creates files in the program directory

      • Setup.exe (PID: 2676)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (32.1)
.exe | Win64 Executable (generic) (28.5)
.exe | Winzip Win32 self-extracting archive (generic) (23.7)
.dll | Win32 Dynamic Link Library (generic) (6.7)
.exe | Win32 Executable (generic) (4.6)

EXIF

EXE

Subsystem: Windows GUI
SubsystemVersion: 4
ImageVersion: -
OSVersion: 4
EntryPoint: 0xaf1e
UninitializedDataSize: -
InitializedDataSize: 65536
CodeSize: 77824
LinkerVersion: 8
PEType: PE32
TimeStamp: 2009:11:02 21:24:15+01:00
MachineType: Intel 386 or later, and compatibles

Summary

Architecture: IMAGE_FILE_MACHINE_I386
Subsystem: IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date: 02-Nov-2009 20:24:15
Detected languages:
  • English - United States

DOS Header

Magic number: MZ
Bytes on last page of file: 0x0090
Pages in file: 0x0003
Relocations: 0x0000
Size of header: 0x0004
Min extra paragraphs: 0x0000
Max extra paragraphs: 0xFFFF
Initial SS value: 0x0000
Initial SP value: 0x00B8
Checksum: 0x0000
Initial IP value: 0x0000
Initial CS value: 0x0000
Overlay number: 0x0000
OEM identifier: 0x0000
OEM information: 0x0000
Address of NE header: 0x000000F0

PE Headers

Signature: PE
Machine: IMAGE_FILE_MACHINE_I386
Number of sections: 5
Time date stamp: 02-Nov-2009 20:24:15
Pointer to Symbol Table: 0x00000000
Number of symbols: 0
Size of Optional Header: 0x00E0
Characteristics:
  • IMAGE_FILE_32BIT_MACHINE
  • IMAGE_FILE_EXECUTABLE_IMAGE
  • IMAGE_FILE_RELOCS_STRIPPED

Sections

Name
Virtual Address
Virtual Size
Raw Size
Charateristics
Entropy
.text
0x00001000
0x00012775
0x00013000
IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
6.50172
.rdata
0x00014000
0x00003822
0x00004000
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
4.98675
.data
0x00018000
0x0000E6E4
0x00002000
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
1.97167
.rsrc
0x00027000
0x00009B6C
0x0000A000
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
5.56412
_winzip_
0x00031000
0x00568000
0x00568000
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
7.99967

Resources

Title
Entropy
Size
Codepage
Language
Type
1
5.04402
1503
Latin 1 / Western European
English - United States
RT_MANIFEST
2
4.03621
744
Latin 1 / Western European
English - United States
RT_ICON
3
3.14459
296
Latin 1 / Western European
English - United States
RT_ICON
4
5.56342
3752
Latin 1 / Western European
English - United States
RT_ICON
5
5.99214
2216
Latin 1 / Western European
English - United States
RT_ICON
6
3.69605
1384
Latin 1 / Western European
English - United States
RT_ICON
7
5.83382
9640
Latin 1 / Western European
English - United States
RT_ICON
8
6.01045
4264
Latin 1 / Western European
English - United States
RT_ICON
9
4.68735
1128
Latin 1 / Western European
English - United States
RT_ICON
63
3.18826
764
Latin 1 / Western European
English - United States
RT_STRING

Imports

COMCTL32.dll
GDI32.dll
KERNEL32.dll
SHELL32.dll
USER32.dll
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
40
Monitored processes
3
Malicious processes
1
Suspicious processes
1

Behavior graph

Click at the process to see the details
drop and start start mypr-win-3_3_0-ea11_2.exe setup.exe mypr-win-3_3_0-ea11_2.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2404"C:\Users\admin\AppData\Local\Temp\mypr-win-3_3_0-ea11_2.exe" C:\Users\admin\AppData\Local\Temp\mypr-win-3_3_0-ea11_2.exeExplorer.EXE
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\appdata\local\temp\mypr-win-3_3_0-ea11_2.exe
c:\windows\system32\ntdll.dll
2676".\mypr-win-3_3_0-ea11_2\Setup.exe"C:\Users\admin\AppData\Local\Temp\WZSE0.TMP\mypr-win-3_3_0-ea11_2\Setup.exe
mypr-win-3_3_0-ea11_2.exe
User:
admin
Company:
CANON INC.
Integrity Level:
HIGH
Description:
SETUP
Exit code:
0
Version:
4.1.0.0
Modules
Images
c:\users\admin\appdata\local\temp\wzse0.tmp\mypr-win-3_3_0-ea11_2\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\wininet.dll
c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
c:\windows\system32\user32.dll
3780"C:\Users\admin\AppData\Local\Temp\mypr-win-3_3_0-ea11_2.exe" C:\Users\admin\AppData\Local\Temp\mypr-win-3_3_0-ea11_2.exe
Explorer.EXE
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\mypr-win-3_3_0-ea11_2.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
Total events
400
Read events
371
Write events
29
Delete events
0

Modification events

(PID) Process:(2676) Setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Canon\MyPrinter
Operation:writeName:AppPath
Value:
C:\Program Files\Canon\MyPrinter\BJMyPrt.exe
(PID) Process:(2676) Setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Canon\MyPrinter
Operation:writeName:DiagPath
Value:
C:\Program Files\Canon\MyPrinter\BJMyDgn.exe
(PID) Process:(2676) Setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Canon\MyPrinter
Operation:writeName:SMFlag
Value:
/SM
(PID) Process:(2676) Setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Canon\MyPrinter
Operation:writeName:DSFlag
Value:
/DS
(PID) Process:(2676) Setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Canon\MyPrinter\Canon Utilities\My Printer\LegacySupport
Operation:writeName:(default)
Value:
(PID) Process:(2676) Setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Canon\MyPrinter\Canon Utilities\My Printer\NewCmdSupport
Operation:writeName:(default)
Value:
(PID) Process:(2676) Setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\BJMYPRT.EXE
Operation:writeName:(default)
Value:
C:\Program Files\Canon\MyPrinter\BJMyPrt.exe
(PID) Process:(2676) Setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\BJMYPRT.EXE
Operation:writeName:Path
Value:
C:\Program Files\Canon\MyPrinter
(PID) Process:(2676) Setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\BJMYDGN.EXE
Operation:writeName:(default)
Value:
C:\Program Files\Canon\MyPrinter\BJMyDgn.exe
(PID) Process:(2676) Setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\BJMYDGN.EXE
Operation:writeName:Path
Value:
C:\Program Files\Canon\MyPrinter
Executable files
83
Suspicious files
6
Text files
163
Unknown types
2

Dropped files

PID
Process
Filename
Type
3780mypr-win-3_3_0-ea11_2.exeC:\Users\admin\AppData\Local\Temp\WZSE0.TMP\mypr-win-3_3_0-ea11_2\res\EULA\EC_German.txttext
MD5:88A6F3B3DF08971D1172C89ED79C575B
SHA256:9140DF0AD5AE06D41DD45B23741768565DA81D55450B45717D0A77898E17C4FF
3780mypr-win-3_3_0-ea11_2.exeC:\Users\admin\AppData\Local\Temp\WZSE0.TMP\mypr-win-3_3_0-ea11_2\Data1.cabcompressed
MD5:1DFA7A2349DC8889E9BDD40AD89D3A22
SHA256:A65CED5942D67ED212EC8666ED29A56A2B1DE2FBDBCCD90C528D5528B5570DAD
3780mypr-win-3_3_0-ea11_2.exeC:\Users\admin\AppData\Local\Temp\WZSE0.TMP\mypr-win-3_3_0-ea11_2\CHECKSUMtext
MD5:8856285A7CB7DDC22B3245EFA1176B4A
SHA256:69161E031E0765FDBE7B0884D922F40DEDC664A6AEA14854C899A52330990530
3780mypr-win-3_3_0-ea11_2.exeC:\Users\admin\AppData\Local\Temp\WZSE0.TMP\mypr-win-3_3_0-ea11_2\res\EULA\EC_Russian.txttext
MD5:DD0B346465CD52E448CA39A079CA74F6
SHA256:3F02EB0377350471711A8832FB76A44B64FAEF620FB82ED4925D597656092F5F
3780mypr-win-3_3_0-ea11_2.exeC:\Users\admin\AppData\Local\Temp\WZSE0.TMP\mypr-win-3_3_0-ea11_2\res\EULA\AS_English.txttext
MD5:175E363C9074201AD380C302C2C6B707
SHA256:7B94AC7F01B7F516AA2783BEA1B3A368D5B7877CA28880F198C25C849A82BEF4
3780mypr-win-3_3_0-ea11_2.exeC:\Users\admin\AppData\Local\Temp\WZSE0.TMP\mypr-win-3_3_0-ea11_2\res\EULA\AS_SimplifiedChinese.txttext
MD5:D37BA89462E00BEAAB89994ACB5FE15F
SHA256:7EE7FA415405AC508AAEFAAB2C78C7EB49B8E5E15AF3A9C789B58B47CF0A5428
3780mypr-win-3_3_0-ea11_2.exeC:\Users\admin\AppData\Local\Temp\WZSE0.TMP\mypr-win-3_3_0-ea11_2\res\EULA\EC_Dutch.txttext
MD5:06999089DD5202ED5277416751661998
SHA256:18AB933B8302A9D49F1FC39D900CC81C1499D5432E3192908FF61F75F6ECA562
3780mypr-win-3_3_0-ea11_2.exeC:\Users\admin\AppData\Local\Temp\WZSE0.TMP\mypr-win-3_3_0-ea11_2\res\EULA\EC_French.txttext
MD5:EC6830F6F5270052CF7A2B1EBB010E60
SHA256:EE6DFD5ACA8C7ACB5038A3D3B042500FCD70B62B17E1BD376B848C7F99110CF9
3780mypr-win-3_3_0-ea11_2.exeC:\Users\admin\AppData\Local\Temp\WZSE0.TMP\mypr-win-3_3_0-ea11_2\res\EULA\EC_Italian.txttext
MD5:7B6C7FC799766B98A64D6170B1602B0A
SHA256:113F25E075BD7C61D47EE2C3BE16BB3A4D5A64D4EF1F7927EAC0719957C79476
3780mypr-win-3_3_0-ea11_2.exeC:\Users\admin\AppData\Local\Temp\WZSE0.TMP\mypr-win-3_3_0-ea11_2\res\EULA\EC_Polish.txttext
MD5:91A6FFFC3ACEE706C3EE465613B06E7C
SHA256:DB160115EDBC480E24992D2890950001C24F456C4DBCBB4F69D67E3280C1C198
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info