File name:

lsDaisySetup.exe

Full analysis: https://app.any.run/tasks/4f307188-4957-466f-8f58-d2ca02d3fd48
Verdict: Malicious activity
Analysis date: December 14, 2023, 15:34:16
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

D762134CAA8E493B4D564BC20A0FBF1C

SHA1:

235034D165106B4FF59792E9665B63AE81FBDEED

SHA256:

5E5E674E51EF1366576C7358D73B0B721823BB4767806427C46E5233619FC114

SSDEEP:

98304:vLs7IrweemAgwRcjzn+9FxDdm5NtoKoQqRAUXFyc+JgulK253/0wHCdfGoTB+wk9:PH7kkvP

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Creates a writable file in the system directory

      • lsDaisySetup.exe (PID: 1352)
    • Drops the executable file immediately after the start

      • lsDaisySetup.exe (PID: 1352)
    • Create files in the Startup directory

      • lsDaisySetup.exe (PID: 1352)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • lsDaisySetup.exe (PID: 1352)
    • Creates/Modifies COM task schedule object

      • lsDaisySetup.exe (PID: 1352)
  • INFO

    • Create files in a temporary directory

      • lsDaisySetup.exe (PID: 1352)
    • Reads the computer name

      • lsDaisySetup.exe (PID: 1352)
    • Checks supported languages

      • lsDaisySetup.exe (PID: 1352)
    • Creates files in the program directory

      • lsDaisySetup.exe (PID: 1352)
    • Creates files or folders in the user directory

      • lsDaisySetup.exe (PID: 1352)
    • Reads mouse settings

      • lsDaisySetup.exe (PID: 1352)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | InstallShield setup (49.2)
.exe | Win32 Executable Delphi generic (16.2)
.scr | Windows screen saver (14.9)
.dll | Win32 Dynamic Link Library (generic) (7.5)
.exe | Win32 Executable (generic) (5.1)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 1992:06:20 00:22:17+02:00
ImageFileCharacteristics: Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 93696
InitializedDataSize: 20480
UninitializedDataSize: -
EntryPoint: 0x17d98
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 0.0.0.0
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
Comments: -
CompanyName: Linia Soft
FileDescription: Daisy фискальный принтер v1.0 Installation
FileVersion: v1.0
LegalCopyright: Linia Soft
No data.
screenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
41
Monitored processes
2
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start lsdaisysetup.exe lsdaisysetup.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1352"C:\Users\admin\AppData\Local\Temp\lsDaisySetup.exe" C:\Users\admin\AppData\Local\Temp\lsDaisySetup.exe
explorer.exe
User:
admin
Company:
Linia Soft
Integrity Level:
HIGH
Description:
Daisy фискальный принтер v1.0 Installation
Exit code:
0
Version:
v1.0
Modules
Images
c:\users\admin\appdata\local\temp\lsdaisysetup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1864"C:\Users\admin\AppData\Local\Temp\lsDaisySetup.exe" C:\Users\admin\AppData\Local\Temp\lsDaisySetup.exeexplorer.exe
User:
admin
Company:
Linia Soft
Integrity Level:
MEDIUM
Description:
Daisy фискальный принтер v1.0 Installation
Exit code:
3221226540
Version:
v1.0
Modules
Images
c:\users\admin\appdata\local\temp\lsdaisysetup.exe
c:\windows\system32\ntdll.dll
Total events
468
Read events
374
Write events
37
Delete events
57

Modification events

(PID) Process:(1352) lsDaisySetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{996BF5E0-8044-4650-ADEB-0B013914E99C}\InprocServer32
Operation:writeName:ThreadingModel
Value:
Apartment
(PID) Process:(1352) lsDaisySetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BDD1F04B-858B-11D1-B16A-00C0F0283628}\InprocServer32
Operation:writeName:ThreadingModel
Value:
Apartment
(PID) Process:(1352) lsDaisySetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9181DC5F-E07D-418A-ACA6-8EEA1ECB8E9E}\InprocServer32
Operation:writeName:ThreadingModel
Value:
Apartment
(PID) Process:(1352) lsDaisySetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C74190B6-8589-11D1-B16A-00C0F0283628}\InprocServer32
Operation:writeName:ThreadingModel
Value:
Apartment
(PID) Process:(1352) lsDaisySetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{24B224E0-9545-4A2F-ABD5-86AA8A849385}\InprocServer32
Operation:writeName:ThreadingModel
Value:
Apartment
(PID) Process:(1352) lsDaisySetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1EFB6596-857C-11D1-B16A-00C0F0283628}\InprocServer32
Operation:writeName:ThreadingModel
Value:
Apartment
(PID) Process:(1352) lsDaisySetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7DC6F291-BF55-4E50-B619-EF672D9DCC58}\InprocServer32
Operation:writeName:ThreadingModel
Value:
Apartment
(PID) Process:(1352) lsDaisySetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{66833FE6-8583-11D1-B16A-00C0F0283628}\InprocServer32
Operation:writeName:ThreadingModel
Value:
Apartment
(PID) Process:(1352) lsDaisySetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F91CAF91-225B-43A7-BB9E-472F991FC402}\InprocServer32
Operation:writeName:ThreadingModel
Value:
Apartment
(PID) Process:(1352) lsDaisySetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2C247F23-8591-11D1-B16A-00C0F0283628}\InprocServer32
Operation:writeName:ThreadingModel
Value:
Apartment
Executable files
5
Suspicious files
3
Text files
4
Unknown types
0

Dropped files

PID
Process
Filename
Type
1352lsDaisySetup.exeC:\Program Files\Linia Soft\Daisy ôèñêàëüíûé ïðèíòåð\settings.initext
MD5:A690EBCF024A732545FEDB3FE5FB5FE5
SHA256:70EFF41E8A0325AE185796794CF30306443FBE2CA40D0546DA86AFBFBED26BAD
1352lsDaisySetup.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Daisy ôèñêàëüíûé ïðèíòåð.lnkbinary
MD5:520F8CE53A6077104E65E91878A60947
SHA256:CE3898C6AAD58CC5E19C506F35D832E49E29572FF6C7F2852AF74623A0E265F2
1352lsDaisySetup.exeC:\Users\admin\AppData\Local\Temp\$inst\2.tmpcompressed
MD5:B4E383CE701AFAAC579022ADAD1BF18F
SHA256:1C30230E4203BE31317B8A77618BAA30275101C0F87A6B3D15FD8C797B5D54C6
1352lsDaisySetup.exeC:\Users\admin\AppData\Local\Temp\$inst\7.tmpimage
MD5:420AEE57B5E083D256D28E45EF887ADB
SHA256:1EFB1A8831F68B443A3E3A06599E914162DC1A9B1B8F9EBC8020B40B72BBFB80
1352lsDaisySetup.exeC:\Windows\system32\mscomm32.ocxexecutable
MD5:2C6119DA3993F410E74B15112F840CB0
SHA256:51A1D6812E445C26C71465E2709E6D1AD587F8513002D662CD160F424F48B37C
1352lsDaisySetup.exeC:\Users\admin\AppData\Local\Temp\$inst\temp_0.tmpcompressed
MD5:1AF041622B5AF848F8C3DAE007EB8C80
SHA256:DBCE1D662D58C982C74884E64FA37F3F17164C5268FE05869CE350808AD59F35
1352lsDaisySetup.exeC:\Users\admin\AppData\Local\Temp\$inst\4.tmpimage
MD5:19BB91C74FDC4A9D3DDAAF373A3BCD5F
SHA256:F2D44F4ED276B933A0AA7790E0EA2AF1AA3FBABD487DCF367AAFB6F5F05F8141
1352lsDaisySetup.exeC:\Program Files\Linia Soft\Daisy ôèñêàëüíûé ïðèíòåð\lsDaisyPrn.exeexecutable
MD5:2056F22B8D1CF939A07A551E456BBACA
SHA256:81768AFEFFB304CCCFF03DD9CDC3442BE898321B278E3E7ED4171B6BC305A446
1352lsDaisySetup.exeC:\Users\admin\AppData\Local\Temp\$inst\5.tmpimage
MD5:FAEEE688DF74D4FFC14EA4DAB1D23418
SHA256:D44F3E9D49F05F11254A453EB50E326A0C4A02A96C120FC170CA5CC71D30DA04
1352lsDaisySetup.exeC:\Program Files\Linia Soft\Daisy ôèñêàëüíûé ïðèíòåð\Uninstall.exeexecutable
MD5:7E430FCE0E5B8912BEAE832960EDCA0A
SHA256:75408D1188E444AF9BAE21B8508A7725BA16E0DC72911385D8E3E3945C646C1C
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
2588
svchost.exe
239.255.255.250:1900
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown

DNS requests

No data

Threats

No threats detected
No debug info