URL:

https://www.bookletcreator.com/

Full analysis: https://app.any.run/tasks/edf654b7-b91c-4d91-a174-d99c05ae6e35
Verdict: Malicious activity
Analysis date: December 01, 2023, 19:04:37
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

45FAE0B9CA6387781EE7A74F1AC4432E

SHA1:

E5687BA6453A0A20672040423C21F448995E1F11

SHA256:

66765C4DFD94B9FFD5D059D080F235A58C325A275132298D1B6C339FFC58D4E1

SSDEEP:

3:N8DSLqVJZ2Z3:2OLqVq

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • msiexec.exe (PID: 3428)
      • BookletCreator.exe (PID: 3236)
  • SUSPICIOUS

    • Executes as Windows Service

      • VSSVC.exe (PID: 3252)
    • Reads the Internet Settings

      • msiexec.exe (PID: 3316)
      • BookletCreator.exe (PID: 3236)
      • BookletCreator.exe (PID: 3868)
    • The process drops C-runtime libraries

      • BookletCreator.exe (PID: 3236)
    • Process drops legitimate windows executable

      • BookletCreator.exe (PID: 3236)
    • Reads settings of System Certificates

      • BookletCreator.exe (PID: 3868)
      • BookletCreator.exe (PID: 3236)
  • INFO

    • Manual execution by a user

      • wmpnscfg.exe (PID: 2184)
      • wmpnscfg.exe (PID: 240)
      • explorer.exe (PID: 2344)
      • BookletCreator.exe (PID: 3868)
    • Reads the computer name

      • wmpnscfg.exe (PID: 240)
      • wmpnscfg.exe (PID: 2184)
      • msiexec.exe (PID: 3428)
      • msiexec.exe (PID: 3316)
      • msiexec.exe (PID: 3132)
      • BookletCreator.exe (PID: 3236)
      • BookletCreator.exe (PID: 3868)
    • Checks supported languages

      • wmpnscfg.exe (PID: 2184)
      • wmpnscfg.exe (PID: 240)
      • msiexec.exe (PID: 3428)
      • msiexec.exe (PID: 3316)
      • msiexec.exe (PID: 3132)
      • BookletCreator.exe (PID: 3236)
      • BookletCreator.exe (PID: 3868)
    • Application launched itself

      • iexplore.exe (PID: 2644)
      • msiexec.exe (PID: 3428)
    • The process uses the downloaded file

      • iexplore.exe (PID: 2644)
    • Reads the machine GUID from the registry

      • msiexec.exe (PID: 3316)
      • msiexec.exe (PID: 3428)
      • msiexec.exe (PID: 3132)
      • BookletCreator.exe (PID: 3868)
      • BookletCreator.exe (PID: 3236)
    • Drops the executable file immediately after the start

      • msiexec.exe (PID: 3108)
    • Create files in a temporary directory

      • msiexec.exe (PID: 3428)
      • BookletCreator.exe (PID: 3236)
      • BookletCreator.exe (PID: 3868)
    • Creates files in the program directory

      • BookletCreator.exe (PID: 3236)
    • Process checks computer location settings

      • BookletCreator.exe (PID: 3236)
      • BookletCreator.exe (PID: 3868)
    • Creates files or folders in the user directory

      • BookletCreator.exe (PID: 3236)
      • BookletCreator.exe (PID: 3868)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
62
Monitored processes
12
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe wmpnscfg.exe no specs wmpnscfg.exe no specs msiexec.exe no specs msiexec.exe no specs msiexec.exe no specs vssvc.exe no specs msiexec.exe no specs bookletcreator.exe explorer.exe no specs bookletcreator.exe

Process information

PID
CMD
Path
Indicators
Parent process
240"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2080"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2644 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
2184"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2344"C:\Windows\explorer.exe" C:\Windows\explorer.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2644"C:\Program Files\Internet Explorer\iexplore.exe" "https://www.bookletcreator.com/"C:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
1
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
3108"C:\Windows\System32\msiexec.exe" /i "C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6Z2BCOUL\BookletCreatorSetup-2.0.1.msi" C:\Windows\System32\msiexec.exeiexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3132C:\Windows\system32\MsiExec.exe -Embedding 81D06D22F85100F3DE7E7DDCFC7186DCC:\Windows\System32\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3236"C:\Program Files\BookletCreator 2\BookletCreator.exe" C:\Program Files\BookletCreator 2\BookletCreator.exe
msiexec.exe
User:
admin
Company:
BookletCreator
Integrity Level:
MEDIUM
Description:
BookletCreator
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\program files\bookletcreator 2\bookletcreator.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
3252C:\Windows\system32\vssvc.exeC:\Windows\System32\VSSVC.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Volume Shadow Copy Service
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\vssvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3316C:\Windows\system32\MsiExec.exe -Embedding A485A831033C4DAD4EA0155F464D5E24 CC:\Windows\System32\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
30 423
Read events
30 284
Write events
124
Delete events
15

Modification events

(PID) Process:(2644) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPDaysSinceLastAutoMigration
Value:
0
(PID) Process:(2644) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchHighDateTime
Value:
30847387
(PID) Process:(2644) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
30847437
(PID) Process:(2644) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(2644) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(2644) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(2644) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(2644) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
460000005A010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(2644) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2644) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
Executable files
13
Suspicious files
55
Text files
31
Unknown types
0

Dropped files

PID
Process
Filename
Type
2080iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\57C8EDB95DF3F0AD4EE2DC2B8CFD4157compressed
MD5:1BFE591A4FE3D91B03CDF26EAACD8F89
SHA256:9CF94355051BF0F4A45724CA20D1CC02F76371B963AB7D1E38BD8997737B13D8
2080iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:09535C92C7B888F924C600D3BC1DA539
SHA256:D51F2F904DD11E3612455157B732FFCD16C35D7A4A1912404BF1721D4FFE706F
2080iexplore.exeC:\Users\admin\AppData\Local\Temp\Low\Cab69EB.tmpcompressed
MD5:AC05D27423A85ADC1622C714F2CB6184
SHA256:C6456E12E5E53287A547AF4103E0397CB9697E466CF75844312DC296D43D144D
2080iexplore.exeC:\Users\admin\AppData\Local\Temp\Low\Cab69E9.tmpcompressed
MD5:AC05D27423A85ADC1622C714F2CB6184
SHA256:C6456E12E5E53287A547AF4103E0397CB9697E466CF75844312DC296D43D144D
2080iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506compressed
MD5:AC05D27423A85ADC1622C714F2CB6184
SHA256:C6456E12E5E53287A547AF4103E0397CB9697E466CF75844312DC296D43D144D
2080iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\buttons-min[1].csstext
MD5:32D32F7A4BBBE17787FF2DB271FC0A65
SHA256:E1522A228F3FE88563F8CE7628B00172C47FBCD07F3E50254A5E84C2701CE74D
2080iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\5A98C5D3C3F5C63F06DB9E54F9718045binary
MD5:CEB19459D37DE1BA0EBB2D05FB369C8F
SHA256:06292F86416787B59A2683707243CAC1983021BF83F7CCB2810C74AE5BC11B9F
2080iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\5A98C5D3C3F5C63F06DB9E54F9718045binary
MD5:4FE7A43E1FE7B31092FC15C26DD22143
SHA256:838BB25ABDBDD280BEF7374B3FF5BD8F8317462B16479970BC49C6943F88BC5D
2080iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5IWPIAR9\screenshot-win[1].pngimage
MD5:87C69944945A95ADA39F2F6412498E92
SHA256:AC6F74D3A29E6CD122C0FE306765C3B6B1C0A0776F9729F987F1C74EA7B06D4A
2080iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5IWPIAR9\screenshot-mac[1].pngimage
MD5:1B77E4FEA5CFF2D32A8B64456D8E2C79
SHA256:1C467922CCB9951EE9A517E24BA4C107BF4B92C96A30F31D0D0609D5EE0BB860
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
11
TCP/UDP connections
30
DNS requests
17
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2080
iexplore.exe
GET
200
184.24.77.174:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?1d7b6ba33f16a438
unknown
compressed
4.66 Kb
unknown
2080
iexplore.exe
GET
200
184.24.77.174:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?64a1a5dfd935ecb5
unknown
compressed
4.66 Kb
unknown
2080
iexplore.exe
GET
200
184.24.77.174:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?53b29833e1287ce6
unknown
compressed
65.2 Kb
unknown
2080
iexplore.exe
GET
200
184.24.77.174:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?797d15c14aeccb02
unknown
compressed
65.2 Kb
unknown
2080
iexplore.exe
GET
200
88.221.110.49:80
http://r3.o.lencr.org/MFMwUTBPME0wSzAJBgUrDgMCGgUABBRI2smg%2ByvTLU%2Fw3mjS9We3NfmzxAQUFC6zF7dYVsuuUAlA5h%2BvnYsUwsYCEgODiZ%2Bd56xu1MxZZTgD%2Bf2R2A%3D%3D
unknown
binary
503 b
unknown
2080
iexplore.exe
GET
200
23.60.200.134:80
http://x1.c.lencr.org/
unknown
binary
717 b
unknown
2644
iexplore.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAzlnDD9eoNTLi0BRrMy%2BWU%3D
unknown
binary
314 b
unknown
2644
iexplore.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAqvpsXKY8RRQeo74ffHUxc%3D
unknown
binary
471 b
unknown
2644
iexplore.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
binary
471 b
unknown
2644
iexplore.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
binary
471 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2080
iexplore.exe
206.189.188.129:443
www.bookletcreator.com
DIGITALOCEAN-ASN
US
unknown
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
2588
svchost.exe
239.255.255.250:1900
whitelisted
2080
iexplore.exe
184.24.77.174:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown
1080
svchost.exe
224.0.0.252:5355
unknown
2080
iexplore.exe
23.60.200.134:80
x1.c.lencr.org
AKAMAI-AS
DE
unknown
2080
iexplore.exe
169.150.247.38:443
plausible.io
GB
unknown
2080
iexplore.exe
88.221.110.49:80
r3.o.lencr.org
Akamai International B.V.
DE
unknown
2644
iexplore.exe
206.189.188.129:443
www.bookletcreator.com
DIGITALOCEAN-ASN
US
unknown

DNS requests

Domain
IP
Reputation
www.bookletcreator.com
  • 206.189.188.129
unknown
ctldl.windowsupdate.com
  • 184.24.77.174
  • 184.24.77.199
  • 184.24.77.207
  • 184.24.77.191
  • 184.24.77.176
  • 184.24.77.209
  • 184.24.77.205
whitelisted
x1.c.lencr.org
  • 23.60.200.134
whitelisted
plausible.io
  • 169.150.247.38
whitelisted
r3.o.lencr.org
  • 88.221.110.49
  • 2.16.100.112
shared
api.bing.com
  • 13.107.5.80
whitelisted
www.bing.com
  • 104.126.37.177
  • 104.126.37.128
  • 104.126.37.186
  • 104.126.37.179
  • 104.126.37.123
  • 104.126.37.163
  • 104.126.37.184
  • 104.126.37.178
  • 104.126.37.168
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
iecvlist.microsoft.com
  • 152.199.19.161
whitelisted
r20swj13mr.microsoft.com
  • 152.199.19.161
whitelisted

Threats

No threats detected
No debug info