File name:

Espanso-Win-Installer-x86_64.exe

Full analysis: https://app.any.run/tasks/a76aeb61-040b-49ac-b1a1-bccadd7739f1
Verdict: Malicious activity
Analysis date: July 07, 2024, 02:20:33
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

2FA97DD9B0983C93C080D71675AD5A71

SHA1:

8AC10413272F072EB867E8F64021464F198DA3EB

SHA256:

4930B0CEDFE36BD885596F0C283F21C9E6FDF60A49D17771B207C7E58E89F150

SSDEEP:

98304:m+cD4dnq17J/juh4YF1DDnAXTyX65Ef5Sf0THbD4N0FJIaXTAlF+K4YJMRiocu5A:JN0qzZUj

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • Espanso-Win-Installer-x86_64.exe (PID: 3188)
      • Espanso-Win-Installer-x86_64.tmp (PID: 2632)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • Espanso-Win-Installer-x86_64.exe (PID: 3188)
      • Espanso-Win-Installer-x86_64.tmp (PID: 2632)
    • Reads the Windows owner or organization settings

      • Espanso-Win-Installer-x86_64.tmp (PID: 2632)
    • Process drops legitimate windows executable

      • Espanso-Win-Installer-x86_64.tmp (PID: 2632)
    • The process drops C-runtime libraries

      • Espanso-Win-Installer-x86_64.tmp (PID: 2632)
  • INFO

    • Checks supported languages

      • Espanso-Win-Installer-x86_64.exe (PID: 3188)
      • Espanso-Win-Installer-x86_64.tmp (PID: 2632)
      • espansod.exe (PID: 740)
    • Reads the computer name

      • Espanso-Win-Installer-x86_64.tmp (PID: 2632)
      • espansod.exe (PID: 740)
    • Create files in a temporary directory

      • Espanso-Win-Installer-x86_64.exe (PID: 3188)
      • Espanso-Win-Installer-x86_64.tmp (PID: 2632)
    • Creates files or folders in the user directory

      • Espanso-Win-Installer-x86_64.tmp (PID: 2632)
      • espansod.exe (PID: 740)
    • Creates a software uninstall entry

      • Espanso-Win-Installer-x86_64.tmp (PID: 2632)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (67.7)
.exe | Win32 EXE PECompact compressed (generic) (25.6)
.exe | Win32 Executable (generic) (2.7)
.exe | Win16/32 Executable Delphi generic (1.2)
.exe | Generic Win/DOS Executable (1.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:02:15 14:54:16+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 741888
InitializedDataSize: 162304
UninitializedDataSize: -
EntryPoint: 0xb5eec
OSVersion: 6.1
ImageVersion: 6
SubsystemVersion: 6.1
Subsystem: Windows GUI
FileVersionNumber: 0.0.0.0
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: Federico Terzi
FileDescription: Espanso Setup
FileVersion:
LegalCopyright:
OriginalFileName:
ProductName: Espanso
ProductVersion: 2.2.1
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
128
Monitored processes
3
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start espanso-win-installer-x86_64.exe espanso-win-installer-x86_64.tmp espansod.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
740"C:\Users\admin\AppData\Local\Programs\Espanso\espansod.exe" launcherC:\Users\admin\AppData\Local\Programs\Espanso\espansod.exeEspanso-Win-Installer-x86_64.tmp
User:
admin
Integrity Level:
MEDIUM
Version:
0.1.0
Modules
Images
c:\users\admin\appdata\local\programs\espanso\espansod.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
2632"C:\Users\admin\AppData\Local\Temp\is-NG9GF.tmp\Espanso-Win-Installer-x86_64.tmp" /SL5="$702CC,5280117,905216,C:\Users\admin\Desktop\Espanso-Win-Installer-x86_64.exe" C:\Users\admin\AppData\Local\Temp\is-NG9GF.tmp\Espanso-Win-Installer-x86_64.tmp
Espanso-Win-Installer-x86_64.exe
User:
admin
Company:
Federico Terzi
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-ng9gf.tmp\espanso-win-installer-x86_64.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comdlg32.dll
3188"C:\Users\admin\Desktop\Espanso-Win-Installer-x86_64.exe" C:\Users\admin\Desktop\Espanso-Win-Installer-x86_64.exe
explorer.exe
User:
admin
Company:
Federico Terzi
Integrity Level:
MEDIUM
Description:
Espanso Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\desktop\espanso-win-installer-x86_64.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comctl32.dll
Total events
3 527
Read events
3 494
Write events
27
Delete events
6

Modification events

(PID) Process:(2632) Espanso-Win-Installer-x86_64.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
480A0000A3E8C44414D0DA01
(PID) Process:(2632) Espanso-Win-Installer-x86_64.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:SessionHash
Value:
38CA774188953BBDD675BD469518AB86C8B542420B4782B6A7A9367834E0277A
(PID) Process:(2632) Espanso-Win-Installer-x86_64.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:Sequence
Value:
1
(PID) Process:(2632) Espanso-Win-Installer-x86_64.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:RegFiles0000
Value:
C:\Users\admin\AppData\Local\Programs\Espanso\espansod.exe
(PID) Process:(2632) Espanso-Win-Installer-x86_64.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:RegFilesHash
Value:
C6ACD477AE5A15FA7BE62E79CD3B7C7A2ADEF720008EA959D3E55E7E81A63B0D
(PID) Process:(2632) Espanso-Win-Installer-x86_64.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{0E3D83CE-A644-4E0E-8487-657C7ECF6BF9}_is1
Operation:writeName:Inno Setup: Setup Version
Value:
6.2.2
(PID) Process:(2632) Espanso-Win-Installer-x86_64.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{0E3D83CE-A644-4E0E-8487-657C7ECF6BF9}_is1
Operation:writeName:Inno Setup: App Path
Value:
C:\Users\admin\AppData\Local\Programs\Espanso
(PID) Process:(2632) Espanso-Win-Installer-x86_64.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{0E3D83CE-A644-4E0E-8487-657C7ECF6BF9}_is1
Operation:writeName:InstallLocation
Value:
C:\Users\admin\AppData\Local\Programs\Espanso\
(PID) Process:(2632) Espanso-Win-Installer-x86_64.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{0E3D83CE-A644-4E0E-8487-657C7ECF6BF9}_is1
Operation:writeName:Inno Setup: Icon Group
Value:
(Default)
(PID) Process:(2632) Espanso-Win-Installer-x86_64.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{0E3D83CE-A644-4E0E-8487-657C7ECF6BF9}_is1
Operation:writeName:Inno Setup: User
Value:
admin
Executable files
24
Suspicious files
0
Text files
12
Unknown types
2

Dropped files

PID
Process
Filename
Type
2632Espanso-Win-Installer-x86_64.tmpC:\Users\admin\AppData\Local\Temp\is-4FK0J.tmp\_isetup\_setup64.tmpexecutable
MD5:E4211D6D009757C078A9FAC7FF4F03D4
SHA256:388A796580234EFC95F3B1C70AD4CB44BFDDC7BA0F9203BF4902B9929B136F95
2632Espanso-Win-Installer-x86_64.tmpC:\Users\admin\AppData\Local\Programs\Espanso\is-6P9GI.tmpexecutable
MD5:367B94DBDFD71D5698E1ED0C3A83D868
SHA256:6EA2918FBDD98BE274E1C7CF940A35BCE95B1EB348C3B89B88066933C5C8DD05
2632Espanso-Win-Installer-x86_64.tmpC:\Users\admin\AppData\Local\Programs\Espanso\espansod.exeexecutable
MD5:367B94DBDFD71D5698E1ED0C3A83D868
SHA256:6EA2918FBDD98BE274E1C7CF940A35BCE95B1EB348C3B89B88066933C5C8DD05
2632Espanso-Win-Installer-x86_64.tmpC:\Users\admin\AppData\Local\Programs\Espanso\is-EHB56.tmpimage
MD5:34C403BC01132CD3E220D4EEF941A64D
SHA256:C38B68792057E1D30005AEEF57049E90E3A986314B0D22EA68E2208347C3DF6E
2632Espanso-Win-Installer-x86_64.tmpC:\Users\admin\AppData\Local\Programs\Espanso\is-NO0P0.tmpexecutable
MD5:B7FF8E74AB911B76F4FE2FBDC2C3CEA1
SHA256:D1A9B1A0EBE71E886B42A59FAA67D4BF7646C3F46E0153DD2519B0E77EBBCDC5
2632Espanso-Win-Installer-x86_64.tmpC:\Users\admin\AppData\Local\Programs\Espanso\is-UNLUK.tmptext
MD5:488CA25E6BCF48BCCEC680754CB9C907
SHA256:1DD3111FA5518684125D1B43765E1BD1852D5C1A59F15DE9CA16F6833BD9A901
2632Espanso-Win-Installer-x86_64.tmpC:\Users\admin\AppData\Local\Programs\Espanso\unins000.exeexecutable
MD5:D57214BDB73B49A837C7B59DE656E60A
SHA256:AE227043EAE53C09BB8999301BAB3798707F682D7CA18A16DE7CA30F2768C83D
2632Espanso-Win-Installer-x86_64.tmpC:\Users\admin\AppData\Local\Programs\Espanso\is-O5FBS.tmpexecutable
MD5:D57214BDB73B49A837C7B59DE656E60A
SHA256:AE227043EAE53C09BB8999301BAB3798707F682D7CA18A16DE7CA30F2768C83D
3188Espanso-Win-Installer-x86_64.exeC:\Users\admin\AppData\Local\Temp\is-NG9GF.tmp\Espanso-Win-Installer-x86_64.tmpexecutable
MD5:7A5DE3C199D70C3E5BDFF0E6D0CA501B
SHA256:2471C49B2EC40758869E8719A99CBB87A584C360C37263D548899E644D2FBF11
2632Espanso-Win-Installer-x86_64.tmpC:\Users\admin\AppData\Local\Programs\Espanso\concrt140.dllexecutable
MD5:B7FF8E74AB911B76F4FE2FBDC2C3CEA1
SHA256:D1A9B1A0EBE71E886B42A59FAA67D4BF7646C3F46E0153DD2519B0E77EBBCDC5
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
22
DNS requests
4
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3800
RUXIMICS.exe
GET
200
23.216.77.28:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
unknown
3692
MoUsoCoreWorker.exe
GET
200
23.216.77.28:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
unknown
3800
RUXIMICS.exe
GET
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
unknown
368
svchost.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
unknown
3692
MoUsoCoreWorker.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
unknown
POST
200
104.208.16.88:443
https://self.events.data.microsoft.com/OneCollector/1.0/
unknown
binary
9 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4032
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:138
whitelisted
368
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3800
RUXIMICS.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3692
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3800
RUXIMICS.exe
23.216.77.28:80
crl.microsoft.com
Akamai International B.V.
DE
unknown
3692
MoUsoCoreWorker.exe
23.216.77.28:80
crl.microsoft.com
Akamai International B.V.
DE
unknown
3800
RUXIMICS.exe
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
368
svchost.exe
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
3692
MoUsoCoreWorker.exe
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
crl.microsoft.com
  • 23.216.77.28
  • 23.216.77.6
whitelisted
www.microsoft.com
  • 23.35.229.160
whitelisted
settings-win.data.microsoft.com
  • 4.231.128.59
whitelisted
self.events.data.microsoft.com
  • 104.208.16.88
whitelisted

Threats

No threats detected
No debug info