File name:

rp505enu.exe

Full analysis: https://app.any.run/tasks/2567c96c-b65f-4bff-90e4-0966629cc3a6
Verdict: Malicious activity
Analysis date: February 08, 2025, 14:16:20
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, InstallShield self-extracting archive, 5 sections
MD5:

2700A631F3B171F58C054A59E4486286

SHA1:

0B08E16C5F47EC08E3A6A56A86132AF40CD9A69B

SHA256:

5DBD36C7D933B4B709319CA6434143612CF03A7D56CAA7DC23EBC6901E8027BD

SSDEEP:

98304:pCois7lzI8IanypO+VWvnYLmfkE2oM33JMs8j7WE4vTr2l3P0p+33zWndLL2b0uy:WamqKenewifDSwBrtccPuu

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Registers / Runs the DLL via REGSVR32.EXE

      • _INS5576._MP (PID: 6480)
  • SUSPICIOUS

    • Creates file in the systems drive root

      • _ISDel.exe (PID: 6500)
    • Starts application with an unusual extension

      • Setup.exe (PID: 6448)
    • Executable content was dropped or overwritten

      • rp505enu.exe (PID: 6396)
      • Setup.exe (PID: 6448)
      • _INS5576._MP (PID: 6480)
    • Process drops legitimate windows executable

      • rp505enu.exe (PID: 6396)
      • _INS5576._MP (PID: 6480)
    • Creates a software uninstall entry

      • _INS5576._MP (PID: 6480)
    • There is functionality for taking screenshot (YARA)

      • rp505enu.exe (PID: 6396)
      • Setup.exe (PID: 6448)
    • Creates/Modifies COM task schedule object

      • _INS5576._MP (PID: 6480)
      • regsvr32.exe (PID: 7104)
    • Reads security settings of Internet Explorer

      • AcroRd32.exe (PID: 236)
  • INFO

    • The sample compiled with english language support

      • rp505enu.exe (PID: 6396)
      • Setup.exe (PID: 6448)
      • _INS5576._MP (PID: 6480)
    • Reads the computer name

      • rp505enu.exe (PID: 6396)
      • Setup.exe (PID: 6448)
      • _INS5576._MP (PID: 6480)
      • AcroRd32.exe (PID: 236)
    • Checks supported languages

      • rp505enu.exe (PID: 6396)
      • _INS5576._MP (PID: 6480)
      • Setup.exe (PID: 6448)
      • AcroRd32.exe (PID: 236)
      • _ISDel.exe (PID: 6500)
    • Create files in a temporary directory

      • Setup.exe (PID: 6448)
      • rp505enu.exe (PID: 6396)
      • _INS5576._MP (PID: 6480)
    • Creates files in the program directory

      • _INS5576._MP (PID: 6480)
    • Checks proxy server information

      • AcroRd32.exe (PID: 236)
    • Creates files or folders in the user directory

      • _INS5576._MP (PID: 6480)
      • AcroRd32.exe (PID: 236)
    • Manual execution by a user

      • AcroRd32.exe (PID: 236)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ 4.x (53)
.exe | InstallShield setup (16.9)
.exe | Win32 Executable MS Visual C++ (generic) (12.2)
.exe | Win64 Executable (generic) (10.8)
.dll | Win32 Dynamic Link Library (generic) (2.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 1998:03:26 14:31:20+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 5
CodeSize: 69120
InitializedDataSize: 75776
UninitializedDataSize: -
EntryPoint: 0xc110
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 2.1.5.0
ProductVersionNumber: 2.1.5.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: InstallShield Software Corporation
FileDescription: PackageForTheWeb Stub
FileVersion: 2.02.001
InternalName: STUB.EXE
LegalCopyright: Copyright © 1996 InstallShield Software Corporation
OriginalFileName: STUB32.EXE
ProductName: PackageForTheWeb Stub
ProductVersion: 2.02.001
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
133
Monitored processes
8
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start rp505enu.exe setup.exe _ins5576._mp _isdel.exe no specs regsvr32.exe no specs acrord32.exe no specs pcaui.exe no specs rp505enu.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
236"C:\Program Files (x86)\Adobe\Acrobat 5.0\Reader\AcroRd32.exe" C:\Program Files (x86)\Adobe\Acrobat 5.0\Reader\AcroRd32.exeexplorer.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
MEDIUM
Description:
Acrobat Reader 5.0
Exit code:
0
Version:
5.0.5.2001092400
Modules
Images
c:\program files (x86)\adobe\acrobat 5.0\reader\acrord32.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\sechost.dll
5988"C:\WINDOWS\system32\pcaui.exe" -g {11111111-1111-1111-1111-111111111111} -x {2fadd937-8962-4118-9f0a-af12b10f0714} -a "Adobe Acrobat 5" -v "Adobe" -s "This app can't run because it causes security or performance issues on Windows. A new version may be available. Check with your software provider for an updated version that runs on this version of Windows." -n 1 -f 0 -k 0 -e "C:\Program Files (x86)\Adobe\Acrobat 5.0\Reader\AcroRd32.exe"C:\Windows\System32\pcaui.exeAcroRd32.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Program Compatibility Assistant User Interface
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\pcaui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
6228"C:\Users\admin\AppData\Local\Temp\rp505enu.exe" C:\Users\admin\AppData\Local\Temp\rp505enu.exeexplorer.exe
User:
admin
Company:
InstallShield Software Corporation
Integrity Level:
MEDIUM
Description:
PackageForTheWeb Stub
Exit code:
3221226540
Version:
2.02.001
Modules
Images
c:\users\admin\appdata\local\temp\rp505enu.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
6396"C:\Users\admin\AppData\Local\Temp\rp505enu.exe" C:\Users\admin\AppData\Local\Temp\rp505enu.exe
explorer.exe
User:
admin
Company:
InstallShield Software Corporation
Integrity Level:
HIGH
Description:
PackageForTheWeb Stub
Exit code:
0
Version:
2.02.001
Modules
Images
c:\users\admin\appdata\local\temp\rp505enu.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acgenral.dll
6448"C:\Users\admin\AppData\Local\Temp\pft68FE~tmp\Setup.exe" /SMSC:\Users\admin\AppData\Local\Temp\pft68FE~tmp\Setup.exe
rp505enu.exe
User:
admin
Company:
InstallShield Software Corporation
Integrity Level:
HIGH
Description:
32-bit Setup Launcher
Exit code:
0
Version:
5, 52, 164, 0
Modules
Images
c:\users\admin\appdata\local\temp\pft68fe~tmp\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acspecfc.dll
6480C:\Users\admin\AppData\Local\Temp\_ISTMP1.DIR\_INS5576._MPC:\Users\admin\AppData\Local\Temp\_ISTMP1.DIR\_INS5576._MP
Setup.exe
User:
admin
Company:
InstallShield Software Corporation
Integrity Level:
HIGH
Description:
InstallShield Engine
Exit code:
0
Version:
5, 53, 168, 0
Modules
Images
c:\users\admin\appdata\local\temp\_istmp1.dir\_ins5576._mp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acspecfc.dll
6500C:\Users\admin\AppData\Local\Temp\pft68FE~tmp\_ISDEL.EXEC:\Users\admin\AppData\Local\Temp\pft68FE~tmp\_ISDel.exeSetup.exe
User:
admin
Company:
InstallShield Software Corporation
Integrity Level:
HIGH
Description:
32-bit InstallShield Deleter.
Exit code:
0
Version:
5, 51, 138, 0
Modules
Images
c:\users\admin\appdata\local\temp\pft68fe~tmp\_isdel.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acspecfc.dll
7104C:\WINDOWS\system32\RegSvr32.exe /s "C:\Program Files (x86)\Adobe\Acrobat 5.0\Reader\ActiveX\pdf.ocx"C:\Windows\SysWOW64\regsvr32.exe_INS5576._MP
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
Total events
1 590
Read events
1 116
Write events
341
Delete events
133

Modification events

(PID) Process:(6480) _INS5576._MPKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\AcroRd32.exe
Operation:writeName:Path
Value:
C:\Program Files (x86)\Adobe\Acrobat 5.0\Reader
(PID) Process:(6480) _INS5576._MPKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Adobe Acrobat 5.0
Operation:writeName:DisplayName
Value:
Adobe Acrobat 5.0
(PID) Process:(6480) _INS5576._MPKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Adobe Acrobat 5.0
Operation:writeName:UninstallString
Value:
C:\WINDOWS\IsUninst.exe -f"C:\Program Files (x86)\Common Files\Adobe\Acrobat 5.0\NT\Uninst.isu"
(PID) Process:(6480) _INS5576._MPKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Component Categories\{7DD95802-9882-11CF-9FA9-00AA006C42C4
Operation:writeName:409
Value:
Controls safely initializable from persistent data
(PID) Process:(6480) _INS5576._MPKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Adobe Acrobat 5.0
Operation:writeName:UninstallString
Value:
C:\WINDOWS\ISUNINST.EXE -f"C:\Program Files (x86)\Common Files\Adobe\Acrobat 5.0\NT\Uninst.isu" -c"C:\Program Files (x86)\Common Files\Adobe\Acrobat 5.0\NT\Uninst.dll"
(PID) Process:(6480) _INS5576._MPKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Adobe Acrobat 5.0
Operation:writeName:UninstallPath
Value:
C:\WINDOWS\ISUNINST.EXE -f"C:\Program Files (x86)\Common Files\Adobe\Acrobat 5.0\NT\Uninst.isu" -c"C:\Program Files (x86)\Common Files\Adobe\Acrobat 5.0\NT\Uninst.dll"
(PID) Process:(6480) _INS5576._MPKey:HKEY_CURRENT_USER\SOFTWARE\InterTrust\DocBox
Operation:writeName:__MinimumVersion
Value:
1.16
(PID) Process:(6480) _INS5576._MPKey:HKEY_CURRENT_USER\SOFTWARE\InterTrust\DocBox
Operation:writeName:ContentFolder
Value:
C:\Users\admin\Documents\My eBooks
(PID) Process:(6480) _INS5576._MPKey:HKEY_CURRENT_USER\SOFTWARE\InterTrust\DocBox
Operation:writeName:ContentLockingChoice
Value:
0
(PID) Process:(6480) _INS5576._MPKey:HKEY_CURRENT_USER\SOFTWARE\InterTrust\DocBox
Operation:writeName:ReceiptFolder
Value:
C:\Users\admin\AppData\Roaming\InterTrust\ReceiptRepository
Executable files
81
Suspicious files
136
Text files
69
Unknown types
0

Dropped files

PID
Process
Filename
Type
6396rp505enu.exeC:\Users\admin\AppData\Local\Temp\pft68FE~tmp\pftw1.pkg
MD5:
SHA256:
6396rp505enu.exeC:\Users\admin\AppData\Local\Temp\pft68FE~tmp\Abcpy.inibinary
MD5:9EC7E0AAC1B0D2068BCCCACC2AC38988
SHA256:A39624BB8B63F2225ECFA69D1A1D812F309091992BD6788CB7EC47C2EC7F5914
6396rp505enu.exeC:\Users\admin\AppData\Local\Temp\pft68FE~tmp\data1.hdrcompressed
MD5:4C72D37DBD7775A314B09FDE75882E41
SHA256:73A426A571CF376CA4C2F3FBC14D8E6B5E08C06CB5D3F7D92C85946A54BC1180
6396rp505enu.exeC:\Users\admin\AppData\Local\Temp\pft68FE~tmp\data1.cabcompressed
MD5:71AF230907090AE68287B861B8A694BC
SHA256:BA74335C7AA56E4DE7D8A162677C572A2B24F8936A80A00E3F7F12DFEBA32714
6396rp505enu.exeC:\Users\admin\AppData\Local\Temp\pft68FE~tmp\DATA.TAGtext
MD5:AC8B33C0C4BF3DC58794842E49AB9C00
SHA256:38B5E9734FFDF1FDCBD9B0BD57E20B19596FFD19AC877C981448D2D0912DCB1A
6396rp505enu.exeC:\Users\admin\AppData\Local\Temp\pft68FE~tmp\Help\ENU\Reader.pdfpdf
MD5:7C1E26BC1B70F710A87B7CE9F7F19570
SHA256:5B3297DD6FA74969C28A5D17DEB37D4BA4A90C92FB0853A530F0440D8DB30308
6396rp505enu.exeC:\Users\admin\AppData\Local\Temp\pft68FE~tmp\Help\ENU\DocBox.pdfpdf
MD5:B1AA261D84C99AE9638B35B614B1A808
SHA256:D93FE87FC70C041187791948AF43C1FBBD1E5C954759A511B7DE156B20BCCE15
6396rp505enu.exeC:\Users\admin\AppData\Local\Temp\pft68FE~tmp\Help\ENU\MiniReader.pdfpdf
MD5:D4991B09EF1DA6EDBE5E8980E79AC2E9
SHA256:A2E4F329A28E0C02952A778888D361EF98ED227E9DE6DD83BC810C3BD7C71BC9
6396rp505enu.exeC:\Users\admin\AppData\Local\Temp\pft68FE~tmp\lang.dattext
MD5:70627BD56FE92A5C97027CBBD88BACD0
SHA256:B67A09F3FE25B08025810BBB20B8FAE05672D0A723F2DBED84F04224A89E6344
6396rp505enu.exeC:\Users\admin\AppData\Local\Temp\pft68FE~tmp\os.dattext
MD5:478F65A0B922B6BA0A6CE99E1D15C336
SHA256:BE2292517342DE82D50CEFBACB185E36558FCDFBF686692E7DF08A80331F9BEE
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
24
DNS requests
12
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1944
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
1944
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
1176
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6828
backgroundTaskHost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
51.124.78.146:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1684
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1176
svchost.exe
20.190.160.17:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1176
svchost.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
1076
svchost.exe
23.35.238.131:443
go.microsoft.com
AKAMAI-AS
DE
whitelisted
4
System
192.168.100.255:137
whitelisted
1944
SIHClient.exe
4.245.163.56:443
slscr.update.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
1944
SIHClient.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
1944
SIHClient.exe
52.165.164.15:443
fe3cr.delivery.mp.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
whitelisted
login.live.com
  • 20.190.160.17
  • 20.190.160.66
  • 40.126.32.76
  • 20.190.160.22
  • 20.190.160.64
  • 40.126.32.134
  • 20.190.160.2
  • 40.126.32.72
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
go.microsoft.com
  • 23.35.238.131
whitelisted
slscr.update.microsoft.com
  • 4.245.163.56
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 52.165.164.15
whitelisted
arc.msn.com
  • 20.223.36.55
whitelisted
fd.api.iris.microsoft.com
  • 20.223.35.26
whitelisted

Threats

No threats detected
No debug info