File name:

Install Restore Point Creator.exe

Full analysis: https://app.any.run/tasks/2b522f4d-6fc1-42a8-8996-1fef4c01c12e
Verdict: Malicious activity
Analysis date: March 09, 2024, 17:45:27
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

27214A9689A7B4A56761544312299570

SHA1:

3229A1873B44BA11E7467984A4B01385CCA3714F

SHA256:

4EE2BFCCFFD22E1B03E84827DD2CB956E46F02E2C8B294AB645C9191100A74E7

SSDEEP:

24576:2URscN64sYqLzeQd7Q0np5F8vdJbG91AhBr7ab0rGKSMB/kbeCrBa0MNX5/62QBm:2UHN64sYqLzeA7Q0np5F8vdJbG91AhBP

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • Install Restore Point Creator.exe (PID: 3700)
      • Install Restore Point Creator.exe (PID: 2840)
      • Install Restore Point Creator.tmp (PID: 3944)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • Install Restore Point Creator.exe (PID: 3700)
      • Install Restore Point Creator.exe (PID: 2840)
      • Install Restore Point Creator.tmp (PID: 3944)
    • Reads the Windows owner or organization settings

      • Install Restore Point Creator.tmp (PID: 3944)
    • Reads the Internet Settings

      • Install Restore Point Creator.tmp (PID: 3944)
      • Restore Point Creator.exe (PID: 2892)
      • Restore Point Creator.exe (PID: 3684)
      • Restore Point Creator.exe (PID: 2376)
      • Restore Point Creator.exe (PID: 1592)
      • sipnotify.exe (PID: 1840)
    • Reads security settings of Internet Explorer

      • Install Restore Point Creator.tmp (PID: 3944)
      • Restore Point Creator.exe (PID: 2892)
      • Restore Point Creator.exe (PID: 3684)
      • Restore Point Creator.exe (PID: 2376)
      • Restore Point Creator.exe (PID: 1592)
    • Uses TASKKILL.EXE to kill process

      • Install Restore Point Creator.tmp (PID: 3944)
    • Non-standard symbols in registry

      • Install Restore Point Creator.tmp (PID: 3944)
    • Application launched itself

      • Restore Point Creator.exe (PID: 2892)
    • Reads the date of Windows installation

      • Restore Point Creator.exe (PID: 3684)
      • Restore Point Creator.exe (PID: 1592)
    • Executes as Windows Service

      • VSSVC.exe (PID: 2100)
    • Reads settings of System Certificates

      • Restore Point Creator.exe (PID: 3684)
      • sipnotify.exe (PID: 1840)
    • Searches for installed software

      • dllhost.exe (PID: 568)
    • The process executes via Task Scheduler

      • Restore Point Creator.exe (PID: 1592)
      • sipnotify.exe (PID: 1840)
      • ctfmon.exe (PID: 1704)
    • The system shut down or reboot

      • Restore Point Creator.exe (PID: 1592)
  • INFO

    • Checks supported languages

      • Install Restore Point Creator.tmp (PID: 2160)
      • Install Restore Point Creator.exe (PID: 2840)
      • Install Restore Point Creator.exe (PID: 3700)
      • Install Restore Point Creator.tmp (PID: 3944)
      • Restore Point Creator.exe (PID: 2892)
      • Restore Point Creator.exe (PID: 3684)
      • Restore Point Creator.exe (PID: 2376)
      • Restore Point Creator.exe (PID: 1592)
      • IMEKLMG.EXE (PID: 1564)
      • IMEKLMG.EXE (PID: 1968)
    • Reads the computer name

      • Install Restore Point Creator.tmp (PID: 2160)
      • Install Restore Point Creator.tmp (PID: 3944)
      • Restore Point Creator.exe (PID: 2892)
      • Restore Point Creator.exe (PID: 3684)
      • Restore Point Creator.exe (PID: 2376)
      • Restore Point Creator.exe (PID: 1592)
      • IMEKLMG.EXE (PID: 1564)
      • IMEKLMG.EXE (PID: 1968)
    • Create files in a temporary directory

      • Install Restore Point Creator.exe (PID: 2840)
      • Install Restore Point Creator.exe (PID: 3700)
    • Creates files in the program directory

      • Install Restore Point Creator.tmp (PID: 3944)
      • Restore Point Creator.exe (PID: 3684)
      • Restore Point Creator.exe (PID: 1592)
    • Creates a software uninstall entry

      • Install Restore Point Creator.tmp (PID: 3944)
    • Manual execution by a user

      • Restore Point Creator.exe (PID: 2892)
      • Restore Point Creator.exe (PID: 2376)
      • IMEKLMG.EXE (PID: 1968)
      • IMEKLMG.EXE (PID: 1564)
    • Reads the machine GUID from the registry

      • Restore Point Creator.exe (PID: 2892)
      • Restore Point Creator.exe (PID: 3684)
      • Restore Point Creator.exe (PID: 1592)
      • Restore Point Creator.exe (PID: 2376)
    • Creates files or folders in the user directory

      • Restore Point Creator.exe (PID: 2892)
      • Restore Point Creator.exe (PID: 3684)
      • Restore Point Creator.exe (PID: 2376)
      • Restore Point Creator.exe (PID: 1592)
    • Reads Environment values

      • Restore Point Creator.exe (PID: 3684)
    • Reads the software policy settings

      • Restore Point Creator.exe (PID: 3684)
      • sipnotify.exe (PID: 1840)
    • Process checks whether UAC notifications are on

      • IMEKLMG.EXE (PID: 1564)
      • IMEKLMG.EXE (PID: 1968)
    • Reads security settings of Internet Explorer

      • sipnotify.exe (PID: 1840)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (77.7)
.exe | Win32 Executable Delphi generic (10)
.dll | Win32 Dynamic Link Library (generic) (4.6)
.exe | Win32 Executable (generic) (3.1)
.exe | Win16/32 Executable Delphi generic (1.4)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 1992:06:19 22:22:17+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 41984
InitializedDataSize: 17920
UninitializedDataSize: -
EntryPoint: 0xaad0
OSVersion: 1
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 0.0.0.0
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: Restore Point Creator Setup
FileVersion:
LegalCopyright:
ProductName: Restore Point Creator
ProductVersion: 7.1
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
107
Monitored processes
20
Malicious processes
7
Suspicious processes
2

Behavior graph

Click at the process to see the details
start install restore point creator.exe install restore point creator.tmp no specs install restore point creator.exe install restore point creator.tmp taskkill.exe no specs restore point creator.exe no specs restore point creator.exe vssvc.exe no specs SPPSurrogate no specs SPPSurrogate no specs restore point creator.exe no specs restore point creator.exe no specs SPPSurrogate no specs vssadmin.exe no specs SPPSurrogate no specs shutdown.exe no specs ctfmon.exe no specs sipnotify.exe imeklmg.exe no specs imeklmg.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
532"C:\Windows\system32\vssadmin.exe" Resize ShadowStorage /For=C: /On=C: /MaxSize=20%C:\Windows\System32\vssadmin.exeRestore Point Creator.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Command Line Interface for Microsoft® Volume Shadow Copy Service
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\vssadmin.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\atl.dll
c:\windows\system32\user32.dll
568C:\Windows\system32\DllHost.exe /Processid:{F32D97DF-E3E5-4CB9-9E3E-0EB5B4E49801}C:\Windows\System32\dllhost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
COM Surrogate
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\dllhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1492"C:\Windows\System32\taskkill.exe" /f /im "Restore Point Creator.exe"C:\Windows\System32\taskkill.exeInstall Restore Point Creator.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Terminates Processes
Exit code:
128
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
1564"C:\Program Files\Common Files\microsoft shared\IME14\SHARED\IMEKLMG.EXE" /SetPreload /KOR /LogC:\Program Files\Common Files\microsoft shared\IME14\SHARED\IMEKLMG.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Office IME 2010
Exit code:
1
Version:
14.0.4734.1000
Modules
Images
c:\program files\common files\microsoft shared\ime14\shared\imeklmg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\userenv.dll
1592"C:\Program Files\Restore Point Creator\Restore Point Creator.exe" C:\Program Files\Restore Point Creator\Restore Point Creator.exetaskeng.exe
User:
admin
Integrity Level:
HIGH
Description:
Restore Point Creator
Exit code:
1073807364
Version:
7.1.2.0
Modules
Images
c:\program files\restore point creator\restore point creator.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1604C:\Windows\system32\DllHost.exe /Processid:{F32D97DF-E3E5-4CB9-9E3E-0EB5B4E49801}C:\Windows\System32\dllhost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
COM Surrogate
Exit code:
1073807364
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\dllhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1704C:\Windows\System32\ctfmon.exe C:\Windows\System32\ctfmon.exetaskeng.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
CTF Loader
Exit code:
1073807364
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ctfmon.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msctfmonitor.dll
c:\windows\system32\msctf.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
1840C:\Windows\system32\sipnotify.exe -LogonOrUnlockC:\Windows\System32\sipnotify.exe
taskeng.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
sipnotify
Exit code:
0
Version:
6.1.7602.20480 (win7sp1_ldr_escrow.191010-1716)
Modules
Images
c:\windows\system32\sipnotify.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1968"C:\Program Files\Common Files\microsoft shared\IME14\SHARED\IMEKLMG.EXE" /SetPreload /JPN /LogC:\Program Files\Common Files\microsoft shared\IME14\SHARED\IMEKLMG.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Office IME 2010
Exit code:
1
Version:
14.0.4734.1000
Modules
Images
c:\program files\common files\microsoft shared\ime14\shared\imeklmg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\userenv.dll
2100C:\Windows\system32\vssvc.exeC:\Windows\System32\VSSVC.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Volume Shadow Copy Service
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\vssvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
71 037
Read events
70 619
Write events
404
Delete events
14

Modification events

(PID) Process:(3944) Install Restore Point Creator.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
680F0000D07B60984972DA01
(PID) Process:(3944) Install Restore Point Creator.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:SessionHash
Value:
8A490DE10E6FB9838E95C32FA46433001842C25BE31392887316DFAEEBB12890
(PID) Process:(3944) Install Restore Point Creator.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Sequence
Value:
1
(PID) Process:(3944) Install Restore Point Creator.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3944) Install Restore Point Creator.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(3944) Install Restore Point Creator.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(3944) Install Restore Point Creator.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(3944) Install Restore Point Creator.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:RegFiles0000
Value:
C:\Program Files\Restore Point Creator\Restore Point Creator.exe
(PID) Process:(3944) Install Restore Point Creator.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:RegFilesHash
Value:
DF258B1E6D19937681C4AC8F16616BAFC61B6E893D06FBD430C11031C6B8604C
(PID) Process:(3944) Install Restore Point Creator.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Restore Point Creator
Operation:writeName:Exported Old Logs
Value:
True
Executable files
6
Suspicious files
11
Text files
71
Unknown types
2

Dropped files

PID
Process
Filename
Type
3944Install Restore Point Creator.tmpC:\Program Files\Restore Point Creator\is-8IH7S.tmpexecutable
MD5:74A266ACB8FBED04F5E1F0F2BB1FCB44
SHA256:A64DD88BA5227B16BCE8246AF8EB793D08C39E6000690E7F5E352F32242E4BBC
3700Install Restore Point Creator.exeC:\Users\admin\AppData\Local\Temp\is-JHTLK.tmp\Install Restore Point Creator.tmpexecutable
MD5:1AFBD25DB5C9A90FE05309F7C4FBCF09
SHA256:3BB0EE5569FE5453C6B3FA25AA517B925D4F8D1F7BA3475E58FA09C46290658C
3944Install Restore Point Creator.tmpC:\Program Files\Restore Point Creator\unins000.exeexecutable
MD5:4DDEE1D4B40F8DA61A82507C7A6F03B7
SHA256:24B923F397F2C5EE6A157CE10C187DB9969970DE746A374A966BFD889EC72A8D
3944Install Restore Point Creator.tmpC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Restore Point Creator\Restore Point Creator.lnklnk
MD5:8063EC856C43945892AB15644DC36CB0
SHA256:FA155C4C1CA29CEF0046F3A343E2F13EE445E4E062A6A01B7DC6066A52C13880
3944Install Restore Point Creator.tmpC:\Program Files\Restore Point Creator\is-SK8Q9.tmpexecutable
MD5:4DDEE1D4B40F8DA61A82507C7A6F03B7
SHA256:24B923F397F2C5EE6A157CE10C187DB9969970DE746A374A966BFD889EC72A8D
3944Install Restore Point Creator.tmpC:\Program Files\Restore Point Creator\Restore Point Creator.exeexecutable
MD5:74A266ACB8FBED04F5E1F0F2BB1FCB44
SHA256:A64DD88BA5227B16BCE8246AF8EB793D08C39E6000690E7F5E352F32242E4BBC
3944Install Restore Point Creator.tmpC:\Program Files\Restore Point Creator\is-SJ461.tmptext
MD5:B3636FCD78D0F760AE141FEEE71F2224
SHA256:6A5BF0C3A8B5FE566705BBD129F897657ED8D6394460E85856AE22405E3CACFF
3944Install Restore Point Creator.tmpC:\Program Files\Restore Point Creator\License.txttext
MD5:B3636FCD78D0F760AE141FEEE71F2224
SHA256:6A5BF0C3A8B5FE566705BBD129F897657ED8D6394460E85856AE22405E3CACFF
568dllhost.exeC:\System Volume Information\SPP\metadata-2
MD5:
SHA256:
3944Install Restore Point Creator.tmpC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Restore Point Creator\Restore Point Creator (Force UAC Prompt).lnklnk
MD5:5F2DB53C3D041BD0589451EB2075F285
SHA256:18A0B318CA1AA675B30F1789CBB116905E419F3B14793090A0A4842E96152214
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
9
DNS requests
2
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1840
sipnotify.exe
HEAD
200
88.221.61.151:80
http://query.prod.cms.rt.microsoft.com/cms/api/am/binary/RE2JgkA?v=133544800185000000
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
3684
Restore Point Creator.exe
172.67.154.125:443
www.toms-world.org
CLOUDFLARENET
US
unknown
1120
svchost.exe
224.0.0.252:5355
unknown
1840
sipnotify.exe
88.221.61.151:80
query.prod.cms.rt.microsoft.com
AKAMAI-AS
DE
unknown

DNS requests

Domain
IP
Reputation
www.toms-world.org
  • 172.67.154.125
  • 104.21.49.249
unknown
query.prod.cms.rt.microsoft.com
  • 88.221.61.151
whitelisted

Threats

No threats detected
No debug info