File name:

hppsdr.exe

Full analysis: https://app.any.run/tasks/2ffec930-ed21-473a-90c4-5d80c676ec62
Verdict: Malicious activity
Analysis date: October 06, 2021, 13:22:29
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

E6FBF6061324545B6CA3D0AA12FCAD0B

SHA1:

EA3608A73883291B4144E6B0E887138BAF1CFC0C

SHA256:

5D6B3B97C6F5BEF101D749FB1EF435EB31FA7005CE232E557FF342154BB71E57

SSDEEP:

393216:Zkd1ebHkcg8vXNhnNS9vG1vYxnpwtn+HUm8KZeQ1UsNE:Gd1IHk6vjNYWvkNSsNE

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops executable file immediately after starts

      • NDP46-KB3045560-Web.exe (PID: 3652)
      • hppsdr.exe (PID: 2504)
    • Actions looks like stealing of personal data

      • NDP46-KB3045560-Web.exe (PID: 3652)
    • Application was dropped or rewritten from another process

      • NDP46-KB3045560-Web.exe (PID: 3652)
      • FILEEX~1.EXE (PID: 2344)
      • Setup.exe (PID: 1744)
      • SetupUtility.exe (PID: 3788)
      • SetupUtility.exe (PID: 644)
    • Loads dropped or rewritten executable

      • Setup.exe (PID: 1744)
  • SUSPICIOUS

    • Checks supported languages

      • hppsdr.exe (PID: 2504)
      • FILEEX~1.EXE (PID: 2344)
      • NDP46-KB3045560-Web.exe (PID: 3652)
      • Setup.exe (PID: 1744)
      • SetupUtility.exe (PID: 644)
      • SetupUtility.exe (PID: 3788)
    • Reads the computer name

      • hppsdr.exe (PID: 2504)
      • FILEEX~1.EXE (PID: 2344)
      • NDP46-KB3045560-Web.exe (PID: 3652)
      • Setup.exe (PID: 1744)
      • SetupUtility.exe (PID: 3788)
      • SetupUtility.exe (PID: 644)
    • Creates a directory in Program Files

      • hppsdr.exe (PID: 2504)
    • Drops a file with too old compile date

      • hppsdr.exe (PID: 2504)
    • Creates files in the program directory

      • hppsdr.exe (PID: 2504)
    • Drops a file that was compiled in debug mode

      • hppsdr.exe (PID: 2504)
      • NDP46-KB3045560-Web.exe (PID: 3652)
    • Executable content was dropped or overwritten

      • NDP46-KB3045560-Web.exe (PID: 3652)
      • hppsdr.exe (PID: 2504)
    • Creates files in the Windows directory

      • Setup.exe (PID: 1744)
    • Reads CPU info

      • Setup.exe (PID: 1744)
    • Reads Environment values

      • Setup.exe (PID: 1744)
  • INFO

    • Checks Windows Trust Settings

      • Setup.exe (PID: 1744)
    • Reads settings of System Certificates

      • Setup.exe (PID: 1744)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (64.6)
.dll | Win32 Dynamic Link Library (generic) (15.4)
.exe | Win32 Executable (generic) (10.5)
.exe | Generic Win/DOS Executable (4.6)
.exe | DOS Executable Generic (4.6)

EXIF

EXE

LegalCopyright: Copyright (c) 2019 HP Development Company, LP.
ProductVersion: 5.6.0.012
ProductName: HP PsDR
OriginalFileName: hpsoftpaqwrapper.exe
InternalName: hpsoftpaqwrapper
FileVersion: 0.2.56.9141
FileDescription: PsDR-5.6.0.012-HPPSdr
CompanyName: HP Inc.
CharacterSet: Unicode
LanguageCode: English (U.S.)
FileSubtype: -
ObjectFileType: Executable application
FileOS: Win32
FileFlags: (none)
FileFlagsMask: 0x003f
ProductVersionNumber: 0.2.0.0
FileVersionNumber: 0.2.56.9141
Subsystem: Windows GUI
SubsystemVersion: 6
ImageVersion: -
OSVersion: 6
EntryPoint: 0x190f6
UninitializedDataSize: -
InitializedDataSize: 126464
CodeSize: 186880
LinkerVersion: 14.16
PEType: PE32
TimeStamp: 2020:11:19 08:38:27+01:00
MachineType: Intel 386 or later, and compatibles

Summary

Architecture: IMAGE_FILE_MACHINE_I386
Subsystem: IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date: 19-Nov-2020 07:38:27
Detected languages:
  • English - United States
Debug artifacts:
  • D:\a\1\s\Release\hpsoftpaqwrapper.pdb
CompanyName: HP Inc.
FileDescription: PsDR-5.6.0.012-HPPSdr
FileVersion: 0.2.56.9141
InternalName: hpsoftpaqwrapper
OriginalFilename: hpsoftpaqwrapper.exe
ProductName: HP PsDR
ProductVersion: 5.6.0.012
LegalCopyright: Copyright (c) 2019 HP Development Company, LP.

DOS Header

Magic number: MZ
Bytes on last page of file: 0x0090
Pages in file: 0x0003
Relocations: 0x0000
Size of header: 0x0004
Min extra paragraphs: 0x0000
Max extra paragraphs: 0xFFFF
Initial SS value: 0x0000
Initial SP value: 0x00B8
Checksum: 0x0000
Initial IP value: 0x0000
Initial CS value: 0x0000
Overlay number: 0x0000
OEM identifier: 0x0000
OEM information: 0x0000
Address of NE header: 0x00000110

PE Headers

Signature: PE
Machine: IMAGE_FILE_MACHINE_I386
Number of sections: 5
Time date stamp: 19-Nov-2020 07:38:27
Pointer to Symbol Table: 0x00000000
Number of symbols: 0
Size of Optional Header: 0x00E0
Characteristics:
  • IMAGE_FILE_32BIT_MACHINE
  • IMAGE_FILE_EXECUTABLE_IMAGE

Sections

Name
Virtual Address
Virtual Size
Raw Size
Charateristics
Entropy
.text
0x00001000
0x0002D9DE
0x0002DA00
IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
6.5599
.rdata
0x0002F000
0x0000CAA2
0x0000CC00
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
5.03169
.data
0x0003C000
0x00002300
0x00001600
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
4.15838
.rsrc
0x0003F000
0x0000DE30
0x0000E000
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
7.52041
.reloc
0x0004D000
0x00002B88
0x00002C00
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
6.6058

Resources

Title
Entropy
Size
Codepage
Language
Type
1
5.12227
810
Latin 1 / Western European
English - United States
RT_MANIFEST
2
7.85069
1698
Latin 1 / Western European
English - United States
RT_ICON
3
7.89767
2869
Latin 1 / Western European
English - United States
RT_ICON
4
7.94506
4630
Latin 1 / Western European
English - United States
RT_ICON
5
7.97237
10113
Latin 1 / Western European
English - United States
RT_ICON
6
7.96456
19260
Latin 1 / Western European
English - United States
RT_ICON
13
3.22339
1014
Latin 1 / Western European
English - United States
RT_STRING
14
3.27585
1482
Latin 1 / Western European
English - United States
RT_STRING
102
2.47732
128
Latin 1 / Western European
English - United States
RT_DIALOG
115
2.70924
116
Latin 1 / Western European
English - United States
RT_DIALOG

Imports

ADVAPI32.dll
COMCTL32.dll
GDI32.dll
KERNEL32.dll
MPR.dll (delay-loaded)
OLEAUT32.dll
SHELL32.dll
USER32.dll
gdiplus.dll
ole32.dll
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
43
Monitored processes
7
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
drop and start start drop and start hppsdr.exe fileex~1.exe no specs ndp46-kb3045560-web.exe setup.exe setuputility.exe no specs setuputility.exe no specs hppsdr.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
644SetupUtility.exe /screbootC:\451cf73f2e6473c696f3d4e2db93\SetupUtility.exeSetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft .NET Framework 4.5 Setup
Exit code:
0
Version:
14.0.0081.0 built by: NETFXREL2
Modules
Images
c:\451cf73f2e6473c696f3d4e2db93\setuputility.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1744C:\451cf73f2e6473c696f3d4e2db93\\Setup.exe /x86 /x64 /webC:\451cf73f2e6473c696f3d4e2db93\Setup.exe
NDP46-KB3045560-Web.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Setup Installer
Exit code:
0
Version:
14.0.0081.0 built by: NETFXREL2
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\451cf73f2e6473c696f3d4e2db93\setup.exe
c:\451cf73f2e6473c696f3d4e2db93\setupengine.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
2344FileExtractor.exe C:\PROGRA~1\HP\DIAGNO~1\PSDR\SoftPaq\Binaries\FILEEX~1.EXEhppsdr.exe
User:
admin
Company:
HPDC LP
Integrity Level:
HIGH
Description:
HP Print and Scan Doctor 5.6.0
Exit code:
0
Version:
1.0.0.2
Modules
Images
c:\program files\hp\diagnostics\psdr\softpaq\binaries\fileextractor.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\psapi.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\msvcrt.dll
2504"C:\Users\admin\AppData\Local\Temp\hppsdr.exe" C:\Users\admin\AppData\Local\Temp\hppsdr.exe
Explorer.EXE
User:
admin
Company:
HP Inc.
Integrity Level:
HIGH
Description:
PsDR-5.6.0.012-HPPSdr
Exit code:
0
Version:
0.2.56.9141
Modules
Images
c:\users\admin\appdata\local\temp\hppsdr.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
3472"C:\Users\admin\AppData\Local\Temp\hppsdr.exe" C:\Users\admin\AppData\Local\Temp\hppsdr.exeExplorer.EXE
User:
admin
Company:
HP Inc.
Integrity Level:
MEDIUM
Description:
PsDR-5.6.0.012-HPPSdr
Exit code:
3221226540
Version:
0.2.56.9141
Modules
Images
c:\users\admin\appdata\local\temp\hppsdr.exe
c:\windows\system32\ntdll.dll
3652"C:\PROGRA~1\HP\DIAGNO~1\PSDR\SoftPaq\Binaries\NDP46-KB3045560-Web.exe" C:\PROGRA~1\HP\DIAGNO~1\PSDR\SoftPaq\Binaries\NDP46-KB3045560-Web.exe
FILEEX~1.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft .NET Framework 4.6 Setup
Exit code:
0
Version:
4.6.00081.00
Modules
Images
c:\program files\hp\diagnostics\psdr\softpaq\binaries\ndp46-kb3045560-web.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\gdi32.dll
3788SetupUtility.exe /aupauseC:\451cf73f2e6473c696f3d4e2db93\SetupUtility.exeSetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft .NET Framework 4.5 Setup
Exit code:
0
Version:
14.0.0081.0 built by: NETFXREL2
Modules
Images
c:\451cf73f2e6473c696f3d4e2db93\setuputility.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
5 868
Read events
5 843
Write events
25
Delete events
0

Modification events

(PID) Process:(2344) FILEEX~1.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2344) FILEEX~1.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(2344) FILEEX~1.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(2344) FILEEX~1.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(1744) Setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
D0060000AB1C8E4EB5BAD701
(PID) Process:(1744) Setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:SessionHash
Value:
23ACDF5F296C5AC86087F271362C773C83B564F6E369EC244D5078BA42718D9F
(PID) Process:(1744) Setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Sequence
Value:
1
(PID) Process:(1744) Setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:RegFiles0005
Value:
c:\windows\microsoft.net\assembly\gac_msil\presentationframework-systemdata\v4.0_4.0.0.0__b77a5c561934e089\presentationframework-systemdata.dll
(PID) Process:(1744) Setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:RegFilesHash
Value:
BE2F105FA6F3405CE61501D916CDB83FEC35376B79F248723A2711E0B4E1EDFD
(PID) Process:(1744) Setup.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\171\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
Executable files
127
Suspicious files
4
Text files
115
Unknown types
27

Dropped files

PID
Process
Filename
Type
2504hppsdr.exeC:\Program Files\HP\Diagnostics\PSDR\SoftPaq\Binaries\api-ms-win-core-debug-l1-1-0.dllexecutable
MD5:584766DF684B2AD2A3A5B05A5B457FAC
SHA256:B15964D49A2C5219E0923137AA9028611BE81FDBDCBB0D43BB3AAA23114E401F
2504hppsdr.exeC:\Program Files\HP\Diagnostics\PSDR\SoftPaq\Binaries\api-ms-win-core-file-l1-1-0.dllexecutable
MD5:779A8B14C22E463EA535CBCA9EA84D49
SHA256:FC0551DE11B310DFD8F3FC924F309D5E754B547FFC475CF6C3D007BB5366F148
2504hppsdr.exeC:\Program Files\HP\Diagnostics\PSDR\SoftPaq\Binaries\api-ms-win-core-datetime-l1-1-0.dllexecutable
MD5:3B3BD0AD4FEA16AB58FCAEAE4629879C
SHA256:DCB9CF7E31D6772434C683353A1514F10D87D39FEAA9B3EDF3FA983B2988294C
2504hppsdr.exeC:\Program Files\HP\Diagnostics\PSDR\SoftPaq\Binaries\api-ms-win-core-console-l1-1-0.dllexecutable
MD5:37DA7F6961082DD96A537235DD89B114
SHA256:6EE46C6B6727EB77BCBCDD54DC506680CA34AF7BC7CA433B77775DE90358844E
2504hppsdr.exeC:\Program Files\HP\Diagnostics\PSDR\SoftPaq\Binaries\api-ms-win-core-file-l1-2-0.dllexecutable
MD5:F6D1216E974FB76585FD350EBDC30648
SHA256:348B70E57AE0329AC40AC3D866B8E896B0B8FEF7E8809A09566F33AF55D33271
2504hppsdr.exeC:\Program Files\HP\Diagnostics\PSDR\SoftPaq\Binaries\api-ms-win-core-file-l2-1-0.dllexecutable
MD5:BFB08FB09E8D68673F2F0213C59E2B97
SHA256:6D5881719E9599BF10A4193C8E2DED2A38C10DE0BA8904F48C67F2DA6E84ED3E
2504hppsdr.exeC:\Program Files\HP\Diagnostics\PSDR\SoftPaq\Binaries\api-ms-win-core-errorhandling-l1-1-0.dllexecutable
MD5:906CB0C8ABA8342D552B0F37DDFD475F
SHA256:582E87ADE6DAC258844154B068C291FF8D8F6D7AB6EE029FCD3CF1391874C74B
2504hppsdr.exeC:\Program Files\HP\Diagnostics\PSDR\SoftPaq\Binaries\api-ms-win-core-interlocked-l1-1-0.dllexecutable
MD5:B8BB783DEE4EA95576882625C365E616
SHA256:21BD55B9D42A5FAA5FA3C5DD9FAD1665DF3C33557CC4F7A58248A88B69D372B8
2504hppsdr.exeC:\Program Files\HP\Diagnostics\PSDR\SoftPaq\Binaries\api-ms-win-core-handle-l1-1-0.dllexecutable
MD5:FC68978ABB44E572DFE637B7DD3D615F
SHA256:DF6BED7BCCCAF7298133DF99E497FA70DA761BE99C2A5B2742CFC835BF62D356
2504hppsdr.exeC:\Program Files\HP\Diagnostics\PSDR\SoftPaq\Binaries\api-ms-win-core-namedpipe-l1-1-0.dllexecutable
MD5:07954AF744363F9807355E4E9408DF45
SHA256:4B20AAF0E3B7566B797652F8D84B749AB23F7D1557DBA882C0590FE1BE98CED6
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
4
DNS requests
4
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
302
23.66.21.99:80
http://go.microsoft.com/fwlink/?LinkId=249117&clcid=0x409
NL
whitelisted
HEAD
302
23.66.21.99:80
http://go.microsoft.com/fwlink/?LinkId=249117&clcid=0x409
NL
whitelisted
HEAD
23.66.21.99:80
http://go.microsoft.com/fwlink/?LinkId=528231&clcid=0x409
NL
whitelisted
1744
Setup.exe
GET
200
88.221.144.41:80
http://crl.microsoft.com/pki/crl/products/microsoftrootcert.crl
IT
der
767 b
whitelisted
1744
Setup.exe
GET
200
88.221.144.41:80
http://crl.microsoft.com/pki/crl/products/MicrosoftTimeStampPCA.crl
IT
der
519 b
whitelisted
1744
Setup.exe
GET
200
209.197.3.8:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?435b30e9ef1810b9
US
compressed
4.70 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1744
Setup.exe
209.197.3.8:80
ctldl.windowsupdate.com
Highwinds Network Group, Inc.
US
whitelisted
1744
Setup.exe
88.221.144.41:80
crl.microsoft.com
Akamai International B.V.
IT
whitelisted
23.66.21.99:80
go.microsoft.com
Akamai Technologies, Inc.
NL
whitelisted
23.210.252.197:443
download.microsoft.com
Akamai International B.V.
NL
malicious

DNS requests

Domain
IP
Reputation
ctldl.windowsupdate.com
  • 209.197.3.8
whitelisted
crl.microsoft.com
  • 88.221.144.41
whitelisted
go.microsoft.com
  • 23.66.21.99
whitelisted
download.microsoft.com
  • 23.210.252.197
whitelisted

Threats

No threats detected
No debug info