File name:

DashlaneInst.exe

Full analysis: https://app.any.run/tasks/8d209694-1424-4288-9a17-7387ebc1a131
Verdict: Malicious activity
Analysis date: December 06, 2022, 06:21:03
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
MD5:

3BE372C290A12BD343C25E94ABDC89AC

SHA1:

E8840F3703DA7E737BC15C950ED768F2B1BD50E1

SHA256:

4F71407A42B514140D5FCE3F122C428484ADCD20CF1A45A8C8D28380C5120426

SSDEEP:

12288:STwwc/MsA2k+l3BNYXwDN9ytoXY6vCCzCE2UPDGiA6brQxzM/PFP79BeI0:aw/MB+3YXuidACyCKDGEozM/PFz9wI

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • DashlaneInst.exe (PID: 3444)
      • DashlaneInst.exe (PID: 1880)
    • Drops the executable file immediately after the start

      • DashlaneInst.exe (PID: 3444)
      • DashlaneInst.exe (PID: 1880)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • DashlaneInst.exe (PID: 3444)
      • DashlaneInst.exe (PID: 1880)
    • Application launched itself

      • DashlaneInst.exe (PID: 1880)
  • INFO

    • Drops a file that was compiled in debug mode

      • DashlaneInst.exe (PID: 3444)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

Summary

Architecture: IMAGE_FILE_MACHINE_I386
Subsystem: IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date: 2019-Jan-24 14:28:37
Detected languages:
  • English - United States
Comments :
CompanyName: Dashlane Inc.
FileDescription: Dashlane
FileVersion: 6.2105.0.43225
LegalCopyright: Copyright 2009-2021 Dashlane Inc.
LegalTradmarks: Dashlane is a tradmark of Dashlane Inc.
ProductName: Dashlane

DOS Header

e_magic: MZ
e_cblp: 144
e_cp: 3
e_crlc: 0
e_cparhdr: 4
e_minalloc: 0
e_maxalloc: 65535
e_ss: 0
e_sp: 184
e_csum: 0
e_ip: 0
e_cs: 0
e_ovno: 0
e_oemid: 0
e_oeminfo: 0
e_lfanew: 224

PE Headers

Signature: PE
Machine: IMAGE_FILE_MACHINE_I386
NumberofSections: 5
TimeDateStamp: 2019-Jan-24 14:28:37
PointerToSymbolTable: 0
NumberOfSymbols: 0
SizeOfOptionalHeader: 224
Characteristics:
  • IMAGE_FILE_32BIT_MACHINE
  • IMAGE_FILE_EXECUTABLE_IMAGE
  • IMAGE_FILE_RELOCS_STRIPPED

Sections

Name
Virtual Address
Virtual Size
Raw Size
Charateristics
Entropy
.text
4096
26288
26624
IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
6.35989
.rdata
32768
5544
5632
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
5.34624
.data
40960
107736
512
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
1.61575
.ndata
151552
786432
0
IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
.rsrc
937984
126088
126464
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
4.24235

Resources

Title
Entropy
Size
Codepage
Language
Type
1
2.60233
67624
UNKNOWN
English - United States
RT_ICON
2
3.09318
16936
UNKNOWN
English - United States
RT_ICON
3
7.61812
13137
UNKNOWN
English - United States
RT_ICON
4
3.21852
9640
UNKNOWN
English - United States
RT_ICON
5
7.86823
6375
UNKNOWN
English - United States
RT_ICON
6
3.26551
4264
UNKNOWN
English - United States
RT_ICON
7
4.44343
1128
UNKNOWN
English - United States
RT_ICON
103
2.79933
104
UNKNOWN
English - United States
RT_GROUP_ICON
105
2.73893
514
UNKNOWN
English - United States
RT_DIALOG
106
2.91148
248
UNKNOWN
English - United States
RT_DIALOG

Imports

ADVAPI32.dll
COMCTL32.dll
GDI32.dll
KERNEL32.dll
SHELL32.dll
USER32.dll
ole32.dll
No data.
screenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
39
Monitored processes
2
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start dashlaneinst.exe dashlaneinst.exe

Process information

PID
CMD
Path
Indicators
Parent process
1880"C:\Users\admin\Desktop\DashlaneInst.exe" C:\Users\admin\Desktop\DashlaneInst.exe
Explorer.EXE
User:
admin
Company:
Dashlane Inc.
Integrity Level:
MEDIUM
Description:
Dashlane
Exit code:
1223
Version:
6.2105.0.43225
Modules
Images
c:\users\admin\desktop\dashlaneinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\lpk.dll
c:\windows\system32\shell32.dll
3444"C:\Users\admin\Desktop\DashlaneInst.exe" /UAC:50150 /NCRC C:\Users\admin\Desktop\DashlaneInst.exe
DashlaneInst.exe
User:
admin
Company:
Dashlane Inc.
Integrity Level:
HIGH
Description:
Dashlane
Version:
6.2105.0.43225
Modules
Images
c:\users\admin\desktop\dashlaneinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
Total events
4 866
Read events
4 824
Write events
42
Delete events
0

Modification events

(PID) Process:(1880) DashlaneInst.exeKey:HKEY_CURRENT_USER\Software\Dashlane\InstallInformation
Operation:writeName:partnerid
Value:
(PID) Process:(1880) DashlaneInst.exeKey:HKEY_CURRENT_USER\Software\Dashlane\InstallInformation
Operation:writeName:campaignid
Value:
NO_CAMPAIGN
(PID) Process:(1880) DashlaneInst.exeKey:HKEY_CURRENT_USER\Software\Dashlane\InstallInformation
Operation:writeName:createDesktopShortcut
Value:
true
(PID) Process:(3444) DashlaneInst.exeKey:HKEY_CURRENT_USER\Software\Dashlane\InstallInformation
Operation:writeName:partnerid
Value:
(PID) Process:(3444) DashlaneInst.exeKey:HKEY_CURRENT_USER\Software\Dashlane\InstallInformation
Operation:writeName:AnonymousInstallerId2
Value:
808239285514477688830040442
(PID) Process:(3444) DashlaneInst.exeKey:HKEY_CURRENT_USER\Software\Dashlane\InstallInformation
Operation:writeName:partnername
Value:
NO_TYPE
(PID) Process:(3444) DashlaneInst.exeKey:HKEY_CURRENT_USER\Software\Dashlane\InstallInformation
Operation:writeName:InstallerPath
Value:
C:\Users\admin\Desktop\DashlaneInst.exe
(PID) Process:(3444) DashlaneInst.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(3444) DashlaneInst.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(3444) DashlaneInst.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
Executable files
15
Suspicious files
0
Text files
3
Unknown types
0

Dropped files

PID
Process
Filename
Type
3444DashlaneInst.exeC:\Users\admin\AppData\Local\Temp\nsrCC.tmp
MD5:
SHA256:
1880DashlaneInst.exeC:\Users\admin\AppData\Local\Temp\nsqFCD5.tmp
MD5:
SHA256:
1880DashlaneInst.exeC:\Users\admin\AppData\Local\Temp\nsgFD82.tmp\nsRandom_1.dllexecutable
MD5:AB467B8DFAA660A0F0E5B26E28AF5735
SHA256:DB267D9920395B4BADC48DE04DF99DFD21D579480D103CAE0F48E6578197FF73
1880DashlaneInst.exeC:\Users\admin\AppData\Local\Temp\nsgFD82.tmp\UAC.dllexecutable
MD5:4814167AA1C7EC892E84907094646FAA
SHA256:32DD7269ABF5A0E5DB888E307D9DF313E87CEF4F1B597965A9D8E00934658822
1880DashlaneInst.exeC:\Users\admin\AppData\Local\Temp\nsgFD82.tmp\UserInfo_1.dllexecutable
MD5:D1E37112390E6BCCA8362788D61BECF5
SHA256:77B40D42606D48F817B901F1E5ABEA114B4288B344B8C193BF3E3C52E469A926
1880DashlaneInst.exeC:\Users\admin\AppData\Local\Temp\dashlaneInstallLog.txttext
MD5:FE59C75C7E63C8D78BEE683CDA5BE180
SHA256:59305098F4582EA05490AB9C40AEB45CBDF4A59F6CA177C6FFC31FD75DEE8CBD
3444DashlaneInst.exeC:\Users\admin\AppData\Local\Temp\nsn199.tmp\UAC.dllexecutable
MD5:4814167AA1C7EC892E84907094646FAA
SHA256:32DD7269ABF5A0E5DB888E307D9DF313E87CEF4F1B597965A9D8E00934658822
1880DashlaneInst.exeC:\Users\admin\AppData\Local\Temp\nsgFD82.tmp\System.dllexecutable
MD5:5BC871689EAB0C9726D71DD0E5921D9B
SHA256:0BCCF2D9FCAE0F2746E52DB6D3DA99C1AB21CBE81FD8D115157D31AFABA4601E
3444DashlaneInst.exeC:\Users\admin\AppData\Local\Temp\nsn199.tmp\inetc_17-05-09_1.dllexecutable
MD5:51843D1334D3D9E751622541BBC76131
SHA256:AF1BC66BCF117B5BA88ED3BE3676928EB527C98C50156405DDEBE73DB1F26E82
3444DashlaneInst.exeC:\Users\admin\AppData\Local\Temp\nsn199.tmp\System_2.dllexecutable
MD5:2AE993A2FFEC0C137EB51C8832691BCB
SHA256:681382F3134DE5C6272A49DD13651C8C201B89C247B471191496E7335702FA59
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
22
DNS requests
3
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3444
DashlaneInst.exe
GET
404
209.197.3.8:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?aa0362af8bc978ad
US
xml
341 b
whitelisted
1092
svchost.exe
GET
404
209.197.3.8:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?b8dc0bf9f55bb2e9
US
xml
341 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3444
DashlaneInst.exe
34.255.201.174:443
logs.dashlane.com
AMAZON-02
IE
unknown
3444
DashlaneInst.exe
104.18.27.218:443
ws1.dashlane.com
CLOUDFLARENET
shared
1092
svchost.exe
209.197.3.8:80
ctldl.windowsupdate.com
STACKPATH-CDN
US
suspicious
3444
DashlaneInst.exe
209.197.3.8:80
ctldl.windowsupdate.com
STACKPATH-CDN
US
suspicious

DNS requests

Domain
IP
Reputation
logs.dashlane.com
  • 34.255.201.174
  • 52.209.55.14
  • 54.171.25.177
whitelisted
ctldl.windowsupdate.com
  • 209.197.3.8
whitelisted
ws1.dashlane.com
  • 104.18.27.218
  • 104.18.26.218
unknown

Threats

No threats detected
No debug info