URL:

https://app.prntscr.com/build/setup-lightshot.exe

Full analysis: https://app.any.run/tasks/ec01ba5d-0051-449d-860d-bcedf1ee42f4
Verdict: Malicious activity
Analysis date: January 29, 2019, 11:49:32
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

7282C26AB91508C93C0BD7EE32CBB27E

SHA1:

A625160E7C1078D1EE8A53D521333EBB8392DC7E

SHA256:

6504CA9FE8395FF6A11FFBFAE5D84900114B93EBA90BC20FC3201CED8507710B

SSDEEP:

3:N8aB7bJBWJ6Kv:2aB7ap

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • setup-lightshot[1].exe (PID: 3192)
      • setup-lightshot[1].exe (PID: 1428)
      • Lightshot.exe (PID: 3680)
      • Lightshot.exe (PID: 2228)
      • Updater.exe (PID: 2588)
      • Updater.exe (PID: 2292)
      • Updater.exe (PID: 3296)
      • Updater.exe (PID: 3160)
      • Updater.exe (PID: 3652)
      • updater.exe (PID: 3944)
      • updater.exe (PID: 2772)
      • updater.exe (PID: 3368)
      • updater.exe (PID: 2288)
    • Changes the autorun value in the registry

      • setup-lightshot[1].tmp (PID: 3992)
    • Loads dropped or rewritten executable

      • Lightshot.exe (PID: 2228)
    • Starts NET.EXE for service management

      • setupupdater.tmp (PID: 3476)
    • Loads the Task Scheduler DLL interface

      • Updater.exe (PID: 2588)
      • updater.exe (PID: 2772)
    • Changes settings of System certificates

      • Updater.exe (PID: 3296)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • setup-lightshot[1].exe (PID: 3192)
      • iexplore.exe (PID: 3256)
      • iexplore.exe (PID: 2964)
      • setup-lightshot[1].exe (PID: 1428)
      • setup-lightshot[1].tmp (PID: 3992)
      • setupupdater.exe (PID: 3560)
      • setupupdater.tmp (PID: 3476)
    • Reads Windows owner or organization settings

      • setup-lightshot[1].tmp (PID: 3992)
      • setupupdater.tmp (PID: 3476)
    • Uses TASKKILL.EXE to kill process

      • setup-lightshot[1].tmp (PID: 3992)
    • Reads the Windows organization settings

      • setup-lightshot[1].tmp (PID: 3992)
      • setupupdater.tmp (PID: 3476)
    • Creates files in the Windows directory

      • Updater.exe (PID: 2588)
      • updater.exe (PID: 2772)
    • Creates files in the program directory

      • Updater.exe (PID: 3296)
    • Creates files in the user directory

      • Updater.exe (PID: 3296)
      • Updater.exe (PID: 2292)
    • Adds / modifies Windows certificates

      • Updater.exe (PID: 3296)
    • Starts Internet Explorer

      • setup-lightshot[1].tmp (PID: 2512)
  • INFO

    • Changes internet zones settings

      • iexplore.exe (PID: 2964)
      • iexplore.exe (PID: 3936)
    • Reads Internet Cache Settings

      • iexplore.exe (PID: 3256)
      • iexplore.exe (PID: 2964)
      • iexplore.exe (PID: 3356)
    • Creates files in the user directory

      • iexplore.exe (PID: 3256)
      • FlashUtil32_26_0_0_131_ActiveX.exe (PID: 3636)
      • iexplore.exe (PID: 3356)
    • Application launched itself

      • iexplore.exe (PID: 2964)
      • iexplore.exe (PID: 3936)
    • Application was dropped or rewritten from another process

      • setup-lightshot[1].tmp (PID: 2512)
      • setup-lightshot[1].tmp (PID: 3992)
      • setupupdater.tmp (PID: 3476)
      • setupupdater.exe (PID: 3560)
    • Creates files in the program directory

      • setup-lightshot[1].tmp (PID: 3992)
      • setupupdater.tmp (PID: 3476)
    • Creates a software uninstall entry

      • setup-lightshot[1].tmp (PID: 3992)
    • Reads internet explorer settings

      • iexplore.exe (PID: 3356)
    • Reads settings of System Certificates

      • iexplore.exe (PID: 3936)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
63
Monitored processes
26
Malicious processes
6
Suspicious processes
5

Behavior graph

Click at the process to see the details
drop and start start drop and start drop and start drop and start drop and start drop and start drop and start drop and start iexplore.exe iexplore.exe setup-lightshot[1].exe setup-lightshot[1].tmp no specs setup-lightshot[1].exe setup-lightshot[1].tmp taskkill.exe no specs taskkill.exe no specs lightshot.exe no specs lightshot.exe no specs setupupdater.exe setupupdater.tmp net.exe no specs net1.exe no specs updater.exe no specs updater.exe no specs updater.exe updater.exe no specs updater.exe updater.exe no specs updater.exe no specs updater.exe no specs updater.exe iexplore.exe iexplore.exe flashutil32_26_0_0_131_activex.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1428"C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R9ZEWH8D\setup-lightshot[1].exe" /SPAWNWND=$3015E /NOTIFYWND=$401AA C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R9ZEWH8D\setup-lightshot[1].exe
setup-lightshot[1].tmp
User:
admin
Company:
Skillbrains
Integrity Level:
HIGH
Description:
lightshot Setup
Exit code:
0
Version:
5.4.0.35
Modules
Images
c:\users\admin\appdata\local\microsoft\windows\temporary internet files\content.ie5\r9zewh8d\setup-lightshot[1].exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2228"C:\Program Files\Skillbrains\lightshot\5.4.0.35\Lightshot.exe" C:\Program Files\Skillbrains\lightshot\5.4.0.35\Lightshot.exeLightshot.exe
User:
admin
Company:
Skillbrains
Integrity Level:
MEDIUM
Description:
Lightshot
Exit code:
0
Version:
5.4.0.1
Modules
Images
c:\program files\skillbrains\lightshot\5.4.0.35\lightshot.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2288"C:\Program Files\Skillbrains\Updater\1.8.0.0\updater.exe" -runmode=addproduct -info="C:\Program Files\Skillbrains\lightshot\info.xml"C:\Program Files\Skillbrains\Updater\1.8.0.0\updater.exe
updater.exe
User:
admin
Integrity Level:
HIGH
Description:
Updater Module
Exit code:
0
Version:
1.8.0.0
Modules
Images
c:\program files\skillbrains\updater\1.8.0.0\updater.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2292"C:\Program Files\Skillbrains\Updater\1.8.0.0\Updater.exe" -runmode=ping -url="http://updater.prntscr.com/getver/updater?ping=true"C:\Program Files\Skillbrains\Updater\1.8.0.0\Updater.exe
Updater.exe
User:
admin
Integrity Level:
HIGH
Description:
Updater Module
Exit code:
0
Version:
1.8.0.0
Modules
Images
c:\program files\skillbrains\updater\1.8.0.0\updater.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2468"C:\Windows\System32\taskkill.exe" /f /im lightshot.exeC:\Windows\System32\taskkill.exesetup-lightshot[1].tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Terminates Processes
Exit code:
128
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskkill.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
2512"C:\Users\admin\AppData\Local\Temp\is-IFAHI.tmp\setup-lightshot[1].tmp" /SL5="$401AA,2096383,486912,C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R9ZEWH8D\setup-lightshot[1].exe" C:\Users\admin\AppData\Local\Temp\is-IFAHI.tmp\setup-lightshot[1].tmpsetup-lightshot[1].exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-ifahi.tmp\setup-lightshot[1].tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2588"C:\Program Files\Skillbrains\Updater\1.8.0.0\Updater.exe" -runmode=addsystaskC:\Program Files\Skillbrains\Updater\1.8.0.0\Updater.exesetupupdater.tmp
User:
admin
Integrity Level:
HIGH
Description:
Updater Module
Exit code:
0
Version:
1.8.0.0
Modules
Images
c:\program files\skillbrains\updater\1.8.0.0\updater.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2772"C:\Program Files\Skillbrains\Updater\1.8.0.0\updater.exe" -runmode=addtaskC:\Program Files\Skillbrains\Updater\1.8.0.0\updater.exeupdater.exe
User:
admin
Integrity Level:
HIGH
Description:
Updater Module
Exit code:
0
Version:
1.8.0.0
Modules
Images
c:\program files\skillbrains\updater\1.8.0.0\updater.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
2964"C:\Program Files\Internet Explorer\iexplore.exe" -nohomeC:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
1
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\user32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
3052"C:\Windows\system32\net.exe" START SCHEDULEC:\Windows\system32\net.exesetupupdater.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Net Command
Exit code:
2
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\net.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\netutils.dll
c:\windows\system32\browcli.dll
Total events
2 724
Read events
2 416
Write events
291
Delete events
17

Modification events

(PID) Process:(2964) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(2964) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(2964) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
(PID) Process:(2964) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones
Operation:writeName:SecuritySafe
Value:
1
(PID) Process:(2964) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(2964) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
4600000069000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
(PID) Process:(2964) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Recovery\Active
Operation:writeName:{FD0EED85-23BB-11E9-BAD8-5254004A04AF}
Value:
0
(PID) Process:(2964) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Operation:writeName:Type
Value:
4
(PID) Process:(2964) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Operation:writeName:Count
Value:
3
(PID) Process:(2964) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Operation:writeName:Time
Value:
E307010002001D000B00310035004D03
Executable files
15
Suspicious files
4
Text files
120
Unknown types
7

Dropped files

PID
Process
Filename
Type
2964iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RB73MZ6Y\favicon[1].ico
MD5:
SHA256:
2964iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.ico
MD5:
SHA256:
2964iexplore.exeC:\Users\admin\AppData\Local\Temp\~DF7DCBBC4B99F87B1F.TMP
MD5:
SHA256:
2964iexplore.exeC:\Users\admin\AppData\Local\Temp\~DFBD9D1A6FFA6DCC88.TMP
MD5:
SHA256:
2964iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{FD0EED85-23BB-11E9-BAD8-5254004A04AF}.dat
MD5:
SHA256:
3992setup-lightshot[1].tmpC:\Program Files\Skillbrains\lightshot\is-UIKG4.tmp
MD5:
SHA256:
3992setup-lightshot[1].tmpC:\Users\admin\AppData\Local\Temp\is-G2R4G.tmp\is-352PH.tmp
MD5:
SHA256:
3992setup-lightshot[1].tmpC:\Users\admin\AppData\Local\Temp\is-G2R4G.tmp\is-P9VKR.tmp
MD5:
SHA256:
3992setup-lightshot[1].tmpC:\Users\admin\AppData\Local\Temp\is-G2R4G.tmp\is-A22QJ.tmp
MD5:
SHA256:
3992setup-lightshot[1].tmpC:\Users\admin\AppData\Local\Temp\is-G2R4G.tmp\is-BTP9L.tmp
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
10
TCP/UDP connections
25
DNS requests
8
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3356
iexplore.exe
GET
301
104.20.13.105:80
http://app.prntscr.com/thankyou_desktop.html
US
html
178 b
whitelisted
3992
setup-lightshot[1].tmp
GET
200
216.58.207.78:80
http://www.google-analytics.com/__utm.gif?&utmn=339657&utmwv=4.4sh&utmp=Lightshot/General%20Installation/default&utmac=UA-11927135-1&utmcc=__utma%3D1.1441444201.1.1.1.1
US
image
35 b
whitelisted
3992
setup-lightshot[1].tmp
GET
200
216.58.207.78:80
http://www.google-analytics.com/__utm.gif?&utmn=8475178&utmwv=4.4sh&utmp=Lightshot/Language/english&utmac=UA-11927135-1&utmcc=__utma%3D1.1441444201.1.1.1.1
US
image
35 b
whitelisted
2292
Updater.exe
GET
200
104.20.14.105:80
http://updater.prntscr.com/getver/updater?ping=true
US
xml
148 b
whitelisted
3936
iexplore.exe
GET
200
204.79.197.200:80
http://www.bing.com/favicon.ico
US
image
237 b
whitelisted
2292
Updater.exe
GET
200
216.58.207.78:80
http://www.google-analytics.com/__utm.gif?utmwv=4.4sh&utmac=UA-38715315-1&utmp=%2FUpdater%2Fusr%2FPing&utmcc=__utma%3D1.300931548762614.1548762614.1548762614.1548762615.2&utmn=300961548762615&utmsc=32-bit&utmsr=1280x720
US
image
35 b
whitelisted
2288
updater.exe
GET
200
216.58.207.78:80
http://www.google-analytics.com/__utm.gif?utmwv=4.4sh&utmac=UA-38715315-1&utmp=%2FUpdater%2Fusr%2FAddProduct%2Flightshot&utmcc=__utma%3D1.300931548762614.1548762614.1548762614.1548762615.3&utmn=300961548762615&utmsc=32-bit&utmsr=1280x720
US
image
35 b
whitelisted
3992
setup-lightshot[1].tmp
GET
200
216.58.207.78:80
http://www.google-analytics.com/__utm.gif?&utmn=685677&utmwv=4.4sh&utmp=Lightshot/Install%20version/5.4.0.35&utmac=UA-11927135-1&utmcc=__utma%3D1.1441444201.1.1.1.1
US
image
35 b
whitelisted
3296
Updater.exe
GET
200
216.58.207.78:80
http://www.google-analytics.com/__utm.gif?utmwv=4.4sh&utmac=UA-38715315-1&utmp=%2FUpdater%2Fusr%2FAddProduct%2Fupdater&utmcc=__utma%3D1.300931548762614.1548762614..1548762614.1&utmn=300931548762614&utmsc=32-bit&utmsr=1280x720
US
image
35 b
whitelisted
2964
iexplore.exe
GET
200
204.79.197.200:80
http://www.bing.com/favicon.ico
US
image
237 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2964
iexplore.exe
204.79.197.200:80
www.bing.com
Microsoft Corporation
US
whitelisted
3256
iexplore.exe
104.20.13.105:443
app.prntscr.com
Cloudflare Inc
US
shared
3296
Updater.exe
216.58.207.78:80
www.google-analytics.com
Google Inc.
US
whitelisted
3296
Updater.exe
77.88.21.119:443
mc.yandex.ru
YANDEX LLC
RU
whitelisted
2292
Updater.exe
104.20.14.105:80
app.prntscr.com
Cloudflare Inc
US
shared
2292
Updater.exe
216.58.207.78:80
www.google-analytics.com
Google Inc.
US
whitelisted
2292
Updater.exe
77.88.21.119:443
mc.yandex.ru
YANDEX LLC
RU
whitelisted
3992
setup-lightshot[1].tmp
216.58.207.78:80
www.google-analytics.com
Google Inc.
US
whitelisted
2288
updater.exe
216.58.207.78:80
www.google-analytics.com
Google Inc.
US
whitelisted
2288
updater.exe
77.88.21.119:443
mc.yandex.ru
YANDEX LLC
RU
whitelisted

DNS requests

Domain
IP
Reputation
www.bing.com
  • 204.79.197.200
  • 13.107.21.200
whitelisted
app.prntscr.com
  • 104.20.13.105
  • 104.20.14.105
whitelisted
www.google-analytics.com
  • 216.58.207.78
whitelisted
mc.yandex.ru
  • 77.88.21.119
  • 87.250.250.119
  • 87.250.251.119
  • 93.158.134.119
whitelisted
updater.prntscr.com
  • 104.20.14.105
  • 104.20.13.105
whitelisted
st.prntscr.com
  • 104.20.13.105
  • 104.20.14.105
whitelisted
widget.uservoice.com
  • 104.17.28.92
  • 104.17.29.92
  • 104.17.31.92
  • 104.17.30.92
  • 104.17.27.92
whitelisted

Threats

PID
Process
Class
Message
2292
Updater.exe
A Network Trojan was detected
MALWARE [PTsecurity] PowerShell.Downloader httpHeader
No debug info