File name:

IDEASLicenseServer.exe

Full analysis: https://app.any.run/tasks/0dc42a3f-6922-438d-8005-87b2d2f2c916
Verdict: Malicious activity
Analysis date: May 24, 2024, 03:46:40
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

4A8498FD8EEF9CC75916C8CA316EB85E

SHA1:

3A73582D280132180594E13D575682B5EB13411A

SHA256:

3E310794C8C78646005A8E6551C5AF29F00880F3EB213B84A0D05B6C5C87E7B0

SSDEEP:

98304:n9t0taQE75U5Tf+S+PDR4lNgTS0Bsx3BhE4tcMcErxpXh/rQ3YGhgdY+QkVd3xNZ:tQicfRiXXjObmue6n

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • IDEASLicenseServer.exe (PID: 1200)
      • IDEASLicenseServer.exe (PID: 2108)
      • msiexec.exe (PID: 1432)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • IDEASLicenseServer.exe (PID: 1200)
      • IDEASLicenseServer.exe (PID: 2108)
    • Starts itself from another location

      • IDEASLicenseServer.exe (PID: 1200)
  • INFO

    • Reads the computer name

      • IDEASLicenseServer.exe (PID: 1200)
      • IDEASLicenseServer.exe (PID: 2108)
      • msiexec.exe (PID: 2040)
      • msiexec.exe (PID: 1432)
    • Checks supported languages

      • IDEASLicenseServer.exe (PID: 1200)
      • IDEASLicenseServer.exe (PID: 2108)
      • msiexec.exe (PID: 2040)
      • msiexec.exe (PID: 1432)
    • Create files in a temporary directory

      • IDEASLicenseServer.exe (PID: 1200)
      • IDEASLicenseServer.exe (PID: 2108)
      • msiexec.exe (PID: 1136)
      • msiexec.exe (PID: 1432)
    • Reads the machine GUID from the registry

      • IDEASLicenseServer.exe (PID: 2108)
      • msiexec.exe (PID: 2040)
      • msiexec.exe (PID: 1432)
    • Creates files or folders in the user directory

      • IDEASLicenseServer.exe (PID: 2108)
    • Application launched itself

      • msiexec.exe (PID: 2040)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 1136)
      • msiexec.exe (PID: 1432)
    • Drops the executable file immediately after the start

      • msiexec.exe (PID: 1136)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (64.6)
.dll | Win32 Dynamic Link Library (generic) (15.4)
.exe | Win32 Executable (generic) (10.5)
.exe | Generic Win/DOS Executable (4.6)
.exe | DOS Executable Generic (4.6)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2021:06:20 19:44:34+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 11
CodeSize: 622080
InitializedDataSize: 684544
UninitializedDataSize: -
EntryPoint: 0x59e5a
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 4.0.0.0
ProductVersionNumber: 4.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Dynamic link library
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: ANDRIT~1|Andritz Inc
FileDescription: Setup Launcher Unicode
FileVersion: 4.0.0
InternalName: Setup
LegalCopyright: Copyright (c) 2020 Flexera. All Rights Reserved.
OriginalFileName: IDEASLicenseServer.exe
ProductName: IDEAS License Server
ProductVersion: 4.0.0
InternalBuildNumber: 202227
ISInternalVersion: 26.0.720
ISInternalDescription: Setup Launcher Unicode
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
40
Monitored processes
6
Malicious processes
3
Suspicious processes
1

Behavior graph

Click at the process to see the details
start ideaslicenseserver.exe ideaslicenseserver.exe msiexec.exe msiexec.exe no specs msiexec.exe ideaslicenseserver.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1136"C:\Windows\system32\MSIEXEC.EXE" /i "C:\Users\admin\AppData\Local\Downloaded Installations\{CF74258C-4D16-493A-A034-89A22BD48822}\IDEASLicenseServer.msi" SETUPEXEDIR="C:\Users\admin\Downloads" SETUPEXENAME="IDEASLicenseServer.exe"C:\Windows\System32\msiexec.exe
IDEASLicenseServer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1200"C:\Users\admin\Downloads\IDEASLicenseServer.exe" C:\Users\admin\Downloads\IDEASLicenseServer.exe
explorer.exe
User:
admin
Company:
ANDRIT~1|Andritz Inc
Integrity Level:
HIGH
Description:
Setup Launcher Unicode
Version:
4.0.0
Modules
Images
c:\users\admin\downloads\ideaslicenseserver.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1432C:\Windows\system32\MsiExec.exe -Embedding D90EFCD01C3305A712C9590357AA565E CC:\Windows\System32\msiexec.exe
msiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2040C:\Windows\system32\msiexec.exe /VC:\Windows\System32\msiexec.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2108C:\Users\admin\AppData\Local\Temp\{5E2923AC-6C12-4484-9E7F-79DD390A54DB}\IDEASLicenseServer.exe /q"C:\Users\admin\Downloads\IDEASLicenseServer.exe" /tempdisk1folder"C:\Users\admin\AppData\Local\Temp\{5E2923AC-6C12-4484-9E7F-79DD390A54DB}" /IS_tempC:\Users\admin\AppData\Local\Temp\{5E2923AC-6C12-4484-9E7F-79DD390A54DB}\IDEASLicenseServer.exe
IDEASLicenseServer.exe
User:
admin
Company:
ANDRIT~1|Andritz Inc
Integrity Level:
HIGH
Description:
Setup Launcher Unicode
Version:
4.0.0
Modules
Images
c:\users\admin\appdata\local\temp\{5e2923ac-6c12-4484-9e7f-79dd390a54db}\ideaslicenseserver.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
4000"C:\Users\admin\Downloads\IDEASLicenseServer.exe" C:\Users\admin\Downloads\IDEASLicenseServer.exeexplorer.exe
User:
admin
Company:
ANDRIT~1|Andritz Inc
Integrity Level:
MEDIUM
Description:
Setup Launcher Unicode
Exit code:
3221226540
Version:
4.0.0
Modules
Images
c:\users\admin\downloads\ideaslicenseserver.exe
c:\windows\system32\ntdll.dll
Total events
1 860
Read events
1 857
Write events
0
Delete events
3

Modification events

(PID) Process:(2108) IDEASLicenseServer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion
Operation:delete valueName:%IS_PREREQ%-IDEAS License Server
Value:
(PID) Process:(2108) IDEASLicenseServer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion
Operation:delete valueName:%IS_PREREQF%-IDEAS License Server
Value:
(PID) Process:(2108) IDEASLicenseServer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce
Operation:delete valueName: ISSetupPrerequisistes
Value:
Executable files
18
Suspicious files
1
Text files
25
Unknown types
0

Dropped files

PID
Process
Filename
Type
2108IDEASLicenseServer.exeC:\Users\admin\AppData\Local\Temp\{5E2923AC-6C12-4484-9E7F-79DD390A54DB}\IDEASLicenseServer.msi
MD5:
SHA256:
2108IDEASLicenseServer.exeC:\Users\admin\AppData\Local\Downloaded Installations\{CF74258C-4D16-493A-A034-89A22BD48822}\IDEASLicenseServer.msi
MD5:
SHA256:
1200IDEASLicenseServer.exeC:\Users\admin\AppData\Local\Temp\~426B.tmptext
MD5:5640F02340111FD23ABCB9F7DA8D7CF2
SHA256:C557227A401A1AF1F193A6EF35D1393D3A708CEE0C6B359BD84723400F5A42A0
2108IDEASLicenseServer.exeC:\Users\admin\AppData\Local\Temp\{5E2923AC-6C12-4484-9E7F-79DD390A54DB}\Microsoft Visual C++ 2015 Redistributable Package (x64).prqxml
MD5:4D4D8846B9479A96777A117289F32210
SHA256:2DC37CDE843105E84367D6D89F1E5009E2850FCBDA460782E3375F3AF93A232E
1200IDEASLicenseServer.exeC:\Users\admin\AppData\Local\Temp\{5E2923AC-6C12-4484-9E7F-79DD390A54DB}\_ISMSIDEL.INItext
MD5:FC05D8D0EF532280BE194BF420E210FA
SHA256:B0A0D94D53878632FCB405FC623C33669480FB2916FEDD72ABDCA1BB7C9AB740
1200IDEASLicenseServer.exeC:\Users\admin\AppData\Local\Temp\~427C.tmptext
MD5:5640F02340111FD23ABCB9F7DA8D7CF2
SHA256:C557227A401A1AF1F193A6EF35D1393D3A708CEE0C6B359BD84723400F5A42A0
2108IDEASLicenseServer.exeC:\Users\admin\AppData\Local\Temp\{5E2923AC-6C12-4484-9E7F-79DD390A54DB}\Setup.INItext
MD5:5640F02340111FD23ABCB9F7DA8D7CF2
SHA256:C557227A401A1AF1F193A6EF35D1393D3A708CEE0C6B359BD84723400F5A42A0
1200IDEASLicenseServer.exeC:\Users\admin\AppData\Local\Temp\~427B.tmptext
MD5:5640F02340111FD23ABCB9F7DA8D7CF2
SHA256:C557227A401A1AF1F193A6EF35D1393D3A708CEE0C6B359BD84723400F5A42A0
2108IDEASLicenseServer.exeC:\Users\admin\AppData\Local\Temp\~42D8.tmptext
MD5:5640F02340111FD23ABCB9F7DA8D7CF2
SHA256:C557227A401A1AF1F193A6EF35D1393D3A708CEE0C6B359BD84723400F5A42A0
2108IDEASLicenseServer.exeC:\Users\admin\AppData\Local\Temp\{5E2923AC-6C12-4484-9E7F-79DD390A54DB}\0x0409.initext
MD5:A108F0030A2CDA00405281014F897241
SHA256:8B76DF0FFC9A226B532B60936765B852B89780C6E475C152F7C320E085E43948
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
unknown

DNS requests

No data

Threats

No threats detected
No debug info