File name:

Espanso-Win-Installer-x86_64.exe

Full analysis: https://app.any.run/tasks/a76aeb61-040b-49ac-b1a1-bccadd7739f1
Verdict: Malicious activity
Analysis date: July 07, 2024, 02:20:33
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

2FA97DD9B0983C93C080D71675AD5A71

SHA1:

8AC10413272F072EB867E8F64021464F198DA3EB

SHA256:

4930B0CEDFE36BD885596F0C283F21C9E6FDF60A49D17771B207C7E58E89F150

SSDEEP:

98304:m+cD4dnq17J/juh4YF1DDnAXTyX65Ef5Sf0THbD4N0FJIaXTAlF+K4YJMRiocu5A:JN0qzZUj

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • Espanso-Win-Installer-x86_64.exe (PID: 3188)
      • Espanso-Win-Installer-x86_64.tmp (PID: 2632)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • Espanso-Win-Installer-x86_64.tmp (PID: 2632)
      • Espanso-Win-Installer-x86_64.exe (PID: 3188)
    • Reads the Windows owner or organization settings

      • Espanso-Win-Installer-x86_64.tmp (PID: 2632)
    • Process drops legitimate windows executable

      • Espanso-Win-Installer-x86_64.tmp (PID: 2632)
    • The process drops C-runtime libraries

      • Espanso-Win-Installer-x86_64.tmp (PID: 2632)
  • INFO

    • Checks supported languages

      • Espanso-Win-Installer-x86_64.exe (PID: 3188)
      • Espanso-Win-Installer-x86_64.tmp (PID: 2632)
      • espansod.exe (PID: 740)
    • Reads the computer name

      • Espanso-Win-Installer-x86_64.tmp (PID: 2632)
      • espansod.exe (PID: 740)
    • Create files in a temporary directory

      • Espanso-Win-Installer-x86_64.tmp (PID: 2632)
      • Espanso-Win-Installer-x86_64.exe (PID: 3188)
    • Creates files or folders in the user directory

      • Espanso-Win-Installer-x86_64.tmp (PID: 2632)
      • espansod.exe (PID: 740)
    • Creates a software uninstall entry

      • Espanso-Win-Installer-x86_64.tmp (PID: 2632)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (67.7)
.exe | Win32 EXE PECompact compressed (generic) (25.6)
.exe | Win32 Executable (generic) (2.7)
.exe | Win16/32 Executable Delphi generic (1.2)
.exe | Generic Win/DOS Executable (1.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:02:15 14:54:16+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 741888
InitializedDataSize: 162304
UninitializedDataSize: -
EntryPoint: 0xb5eec
OSVersion: 6.1
ImageVersion: 6
SubsystemVersion: 6.1
Subsystem: Windows GUI
FileVersionNumber: 0.0.0.0
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: Federico Terzi
FileDescription: Espanso Setup
FileVersion:
LegalCopyright:
OriginalFileName:
ProductName: Espanso
ProductVersion: 2.2.1
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
128
Monitored processes
3
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start espanso-win-installer-x86_64.exe espanso-win-installer-x86_64.tmp espansod.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
740"C:\Users\admin\AppData\Local\Programs\Espanso\espansod.exe" launcherC:\Users\admin\AppData\Local\Programs\Espanso\espansod.exeEspanso-Win-Installer-x86_64.tmp
User:
admin
Integrity Level:
MEDIUM
Version:
0.1.0
Modules
Images
c:\users\admin\appdata\local\programs\espanso\espansod.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
2632"C:\Users\admin\AppData\Local\Temp\is-NG9GF.tmp\Espanso-Win-Installer-x86_64.tmp" /SL5="$702CC,5280117,905216,C:\Users\admin\Desktop\Espanso-Win-Installer-x86_64.exe" C:\Users\admin\AppData\Local\Temp\is-NG9GF.tmp\Espanso-Win-Installer-x86_64.tmp
Espanso-Win-Installer-x86_64.exe
User:
admin
Company:
Federico Terzi
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-ng9gf.tmp\espanso-win-installer-x86_64.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comdlg32.dll
3188"C:\Users\admin\Desktop\Espanso-Win-Installer-x86_64.exe" C:\Users\admin\Desktop\Espanso-Win-Installer-x86_64.exe
explorer.exe
User:
admin
Company:
Federico Terzi
Integrity Level:
MEDIUM
Description:
Espanso Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\desktop\espanso-win-installer-x86_64.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comctl32.dll
Total events
3 527
Read events
3 494
Write events
27
Delete events
6

Modification events

(PID) Process:(2632) Espanso-Win-Installer-x86_64.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
480A0000A3E8C44414D0DA01
(PID) Process:(2632) Espanso-Win-Installer-x86_64.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:SessionHash
Value:
38CA774188953BBDD675BD469518AB86C8B542420B4782B6A7A9367834E0277A
(PID) Process:(2632) Espanso-Win-Installer-x86_64.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:Sequence
Value:
1
(PID) Process:(2632) Espanso-Win-Installer-x86_64.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:RegFiles0000
Value:
C:\Users\admin\AppData\Local\Programs\Espanso\espansod.exe
(PID) Process:(2632) Espanso-Win-Installer-x86_64.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:RegFilesHash
Value:
C6ACD477AE5A15FA7BE62E79CD3B7C7A2ADEF720008EA959D3E55E7E81A63B0D
(PID) Process:(2632) Espanso-Win-Installer-x86_64.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{0E3D83CE-A644-4E0E-8487-657C7ECF6BF9}_is1
Operation:writeName:Inno Setup: Setup Version
Value:
6.2.2
(PID) Process:(2632) Espanso-Win-Installer-x86_64.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{0E3D83CE-A644-4E0E-8487-657C7ECF6BF9}_is1
Operation:writeName:Inno Setup: App Path
Value:
C:\Users\admin\AppData\Local\Programs\Espanso
(PID) Process:(2632) Espanso-Win-Installer-x86_64.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{0E3D83CE-A644-4E0E-8487-657C7ECF6BF9}_is1
Operation:writeName:InstallLocation
Value:
C:\Users\admin\AppData\Local\Programs\Espanso\
(PID) Process:(2632) Espanso-Win-Installer-x86_64.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{0E3D83CE-A644-4E0E-8487-657C7ECF6BF9}_is1
Operation:writeName:Inno Setup: Icon Group
Value:
(Default)
(PID) Process:(2632) Espanso-Win-Installer-x86_64.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{0E3D83CE-A644-4E0E-8487-657C7ECF6BF9}_is1
Operation:writeName:Inno Setup: User
Value:
admin
Executable files
24
Suspicious files
0
Text files
12
Unknown types
2

Dropped files

PID
Process
Filename
Type
3188Espanso-Win-Installer-x86_64.exeC:\Users\admin\AppData\Local\Temp\is-NG9GF.tmp\Espanso-Win-Installer-x86_64.tmpexecutable
MD5:7A5DE3C199D70C3E5BDFF0E6D0CA501B
SHA256:2471C49B2EC40758869E8719A99CBB87A584C360C37263D548899E644D2FBF11
2632Espanso-Win-Installer-x86_64.tmpC:\Users\admin\AppData\Local\Programs\Espanso\is-8Q0B0.tmpexecutable
MD5:C060BB176A671F068362DB2673A08C5E
SHA256:768E0829DECEA713AFB35A7DE07E276F051581C8FF2C17E1BAE9B07DD1445DD0
2632Espanso-Win-Installer-x86_64.tmpC:\Users\admin\AppData\Local\Programs\Espanso\is-10754.tmpexecutable
MD5:0D89995CC45C7EB40E5A7E287506C1E9
SHA256:E0A22A594E148FA55CEEF3E49969BFA77011A801267A0BD7805B681B593C9D0B
2632Espanso-Win-Installer-x86_64.tmpC:\Users\admin\AppData\Local\Programs\Espanso\concrt140.dllexecutable
MD5:B7FF8E74AB911B76F4FE2FBDC2C3CEA1
SHA256:D1A9B1A0EBE71E886B42A59FAA67D4BF7646C3F46E0153DD2519B0E77EBBCDC5
2632Espanso-Win-Installer-x86_64.tmpC:\Users\admin\AppData\Local\Programs\Espanso\espanso.cmdtext
MD5:488CA25E6BCF48BCCEC680754CB9C907
SHA256:1DD3111FA5518684125D1B43765E1BD1852D5C1A59F15DE9CA16F6833BD9A901
2632Espanso-Win-Installer-x86_64.tmpC:\Users\admin\AppData\Local\Programs\Espanso\is-NO0P0.tmpexecutable
MD5:B7FF8E74AB911B76F4FE2FBDC2C3CEA1
SHA256:D1A9B1A0EBE71E886B42A59FAA67D4BF7646C3F46E0153DD2519B0E77EBBCDC5
2632Espanso-Win-Installer-x86_64.tmpC:\Users\admin\AppData\Local\Programs\Espanso\is-604ML.tmpexecutable
MD5:94BC7A22EC7308F851CC58FD6DE90B2D
SHA256:5C12EAEF6DB18B168F712BFF9B55793E0EFFDDF15B89552E7F5CA4F8F1887B9B
2632Espanso-Win-Installer-x86_64.tmpC:\Users\admin\AppData\Local\Programs\Espanso\msvcp140.dllexecutable
MD5:0D89995CC45C7EB40E5A7E287506C1E9
SHA256:E0A22A594E148FA55CEEF3E49969BFA77011A801267A0BD7805B681B593C9D0B
2632Espanso-Win-Installer-x86_64.tmpC:\Users\admin\AppData\Local\Programs\Espanso\msvcp140_2.dllexecutable
MD5:94BC7A22EC7308F851CC58FD6DE90B2D
SHA256:5C12EAEF6DB18B168F712BFF9B55793E0EFFDDF15B89552E7F5CA4F8F1887B9B
2632Espanso-Win-Installer-x86_64.tmpC:\Users\admin\AppData\Local\Programs\Espanso\msvcp140_1.dllexecutable
MD5:C060BB176A671F068362DB2673A08C5E
SHA256:768E0829DECEA713AFB35A7DE07E276F051581C8FF2C17E1BAE9B07DD1445DD0
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
22
DNS requests
4
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3800
RUXIMICS.exe
GET
200
23.216.77.28:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
unknown
3692
MoUsoCoreWorker.exe
GET
200
23.216.77.28:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
unknown
3800
RUXIMICS.exe
GET
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
unknown
368
svchost.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
unknown
3692
MoUsoCoreWorker.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
unknown
POST
200
104.208.16.88:443
https://self.events.data.microsoft.com/OneCollector/1.0/
unknown
binary
9 b
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4032
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:138
whitelisted
368
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3800
RUXIMICS.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3692
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3800
RUXIMICS.exe
23.216.77.28:80
crl.microsoft.com
Akamai International B.V.
DE
unknown
3692
MoUsoCoreWorker.exe
23.216.77.28:80
crl.microsoft.com
Akamai International B.V.
DE
unknown
3800
RUXIMICS.exe
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
368
svchost.exe
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
3692
MoUsoCoreWorker.exe
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
crl.microsoft.com
  • 23.216.77.28
  • 23.216.77.6
whitelisted
www.microsoft.com
  • 23.35.229.160
whitelisted
settings-win.data.microsoft.com
  • 4.231.128.59
whitelisted
self.events.data.microsoft.com
  • 104.208.16.88
whitelisted

Threats

No threats detected
No debug info