File name:

POS58Setup_20190329.exe

Full analysis: https://app.any.run/tasks/c1683204-96f6-4bee-aeea-206b985d7afb
Verdict: Malicious activity
Analysis date: February 21, 2025, 06:42:00
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 6 sections
MD5:

3BDC1244343BAEACFE7E1A444AB25B6A

SHA1:

EE7CDF1D5891508AB1AFCA0D649A198E53B2E1AA

SHA256:

733BE8C11F0147DE746188C9DA715F640A74013B00B814C2EFD1D609EFC60663

SSDEEP:

98304:Znm6CKCbIkVFpAVUAEd66ldznZndWG0Yq03euk6dpBVUTw343PdzcnM9ESkCbIkd:IzSz75xXP

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • POS58Setup_20190329.exe (PID: 3172)
      • DriverSetup.exe (PID: 6372)
    • Reads security settings of Internet Explorer

      • POS58Setup_20190329.exe (PID: 3172)
    • There is functionality for taking screenshot (YARA)

      • POS58Setup_20190329.exe (PID: 3172)
    • Process drops legitimate windows executable

      • POS58Setup_20190329.exe (PID: 3172)
      • DriverSetup.exe (PID: 6372)
  • INFO

    • Reads the computer name

      • POS58Setup_20190329.exe (PID: 3172)
      • DriverSetup.exe (PID: 6372)
    • Checks supported languages

      • POS58Setup_20190329.exe (PID: 3172)
      • DriverSetup.exe (PID: 6372)
    • Create files in a temporary directory

      • POS58Setup_20190329.exe (PID: 3172)
    • The sample compiled with arabic language support

      • POS58Setup_20190329.exe (PID: 3172)
      • DriverSetup.exe (PID: 6372)
    • The sample compiled with chinese language support

      • POS58Setup_20190329.exe (PID: 3172)
    • Process checks computer location settings

      • POS58Setup_20190329.exe (PID: 3172)
    • The sample compiled with english language support

      • DriverSetup.exe (PID: 6372)
      • POS58Setup_20190329.exe (PID: 3172)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (64.6)
.dll | Win32 Dynamic Link Library (generic) (15.4)
.exe | Win32 Executable (generic) (10.5)
.exe | Generic Win/DOS Executable (4.6)
.exe | DOS Executable Generic (4.6)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2017:08:11 13:54:06+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14
CodeSize: 188928
InitializedDataSize: 69632
UninitializedDataSize: -
EntryPoint: 0x1cec9
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
130
Monitored processes
3
Malicious processes
1
Suspicious processes
1

Behavior graph

Click at the process to see the details
start pos58setup_20190329.exe driversetup.exe no specs driversetup.exe

Process information

PID
CMD
Path
Indicators
Parent process
3172"C:\Users\admin\Desktop\POS58Setup_20190329.exe" C:\Users\admin\Desktop\POS58Setup_20190329.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\pos58setup_20190329.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\version.dll
6260"C:\Users\admin\AppData\Local\Temp\RarSFX0\DriverSetup.exe" C:\Users\admin\AppData\Local\Temp\RarSFX0\DriverSetup.exePOS58Setup_20190329.exe
User:
admin
Company:
KAICONG ELECTRONIC
Integrity Level:
MEDIUM
Description:
Printer Driver Setup
Exit code:
3221226540
Version:
1.0.0.1
Modules
Images
c:\users\admin\appdata\local\temp\rarsfx0\driversetup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
6372"C:\Users\admin\AppData\Local\Temp\RarSFX0\DriverSetup.exe" C:\Users\admin\AppData\Local\Temp\RarSFX0\DriverSetup.exe
POS58Setup_20190329.exe
User:
admin
Company:
KAICONG ELECTRONIC
Integrity Level:
HIGH
Description:
Printer Driver Setup
Exit code:
0
Version:
1.0.0.1
Modules
Images
c:\users\admin\appdata\local\temp\rarsfx0\driversetup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
Total events
590
Read events
590
Write events
0
Delete events
0

Modification events

No data
Executable files
36
Suspicious files
6
Text files
24
Unknown types
0

Dropped files

PID
Process
Filename
Type
3172POS58Setup_20190329.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\SETUP\CHN\POS58UNICHN.DLLexecutable
MD5:B72ED1A3CC2E42D274E076C5E7A52381
SHA256:6EFAE8A47C542717E7CF5927261CA5F8EC3F2E33694A3444B7B79EAECE228AEB
3172POS58Setup_20190329.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\SETUP\CHN\POS58CHN.INItext
MD5:AD0622BED8E56A81C0DC9E3E79A343BB
SHA256:F0FD080B64E1AC91E1E495ADF5C69FD11C3CF09FF6D4C5BE93312472DD5EBE1F
3172POS58Setup_20190329.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\SETUP\CHN\STDNAMES.GPDtext
MD5:F8912EED4BE5B47A634EB31A896BE032
SHA256:290109933E9E2A0649AEC035E010022808C6656AE1B0C7E113BC8B14FB5268DD
3172POS58Setup_20190329.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\SETUP\CHN\POS58CHN.GPDtext
MD5:4A1772964C4AE414AAE950244DF06956
SHA256:0F7AF49D220D4E746590D0A626EA5F0F4AAEA707502A73747DE95DCCC5023203
3172POS58Setup_20190329.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\SETUP\CHN\POS58RCCHN.DLLexecutable
MD5:3EEA89E35DE06A82F733CF0E9E64C2BC
SHA256:9C2D71EB172A533D744917C050A09D5831E2E9B54316ECB517799BD9CCC28C8A
3172POS58Setup_20190329.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\SETUP\ENG\POS58ENG.GPDtext
MD5:0CF92A450C416AFCD1624EC8D6168B8C
SHA256:34C7BBAAEF42075A304071FEA11DFD2CF3D41A7F109AAA7F3C48C42D0AD93AE9
3172POS58Setup_20190329.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\SETUP\CHN\UNIRES.DLLexecutable
MD5:E0DB0370CCF78EAE634F613AF028E4CD
SHA256:C1578C547259FC922892BDDA2FEF0BFC307B6745F422643E899C9C0329E06632
3172POS58Setup_20190329.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\SETUP\ENG\STDNAMES.GPDtext
MD5:F8912EED4BE5B47A634EB31A896BE032
SHA256:290109933E9E2A0649AEC035E010022808C6656AE1B0C7E113BC8B14FB5268DD
3172POS58Setup_20190329.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\SETUP\ENG\POS58RCENG.DLLexecutable
MD5:0D74D66621EDAE4507FDAA9DE06DAB67
SHA256:2408C032BB83AA0C99B00EC6932621F3A3A74D4E6CFA21D1F8A6C235A55123CA
3172POS58Setup_20190329.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\SETUP\ENG\srclient.dllexecutable
MD5:8DD6DE91537619888A4D72C213074B0C
SHA256:5A16E6AC1CA2CB5318FA6FDA0E0F114DF0651C1A67FA15E8AE2F283AF1058174
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
9
TCP/UDP connections
33
DNS requests
15
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
23.48.23.156:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
GET
200
23.48.23.156:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
1176
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6364
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
6364
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
6672
backgroundTaskHost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
104.126.37.131:443
www.bing.com
Akamai International B.V.
DE
whitelisted
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
23.48.23.156:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
1176
svchost.exe
20.190.159.23:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1176
svchost.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
5880
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1076
svchost.exe
23.35.238.131:443
go.microsoft.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
whitelisted
www.bing.com
  • 104.126.37.131
  • 104.126.37.171
  • 104.126.37.146
  • 104.126.37.136
  • 104.126.37.144
  • 104.126.37.185
  • 104.126.37.179
  • 104.126.37.139
  • 104.126.37.123
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
crl.microsoft.com
  • 23.48.23.156
  • 23.48.23.143
whitelisted
google.com
  • 142.250.186.78
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
login.live.com
  • 20.190.159.23
  • 20.190.159.2
  • 20.190.159.128
  • 20.190.159.64
  • 20.190.159.73
  • 40.126.31.2
  • 20.190.159.68
  • 20.190.159.71
whitelisted
go.microsoft.com
  • 23.35.238.131
whitelisted
slscr.update.microsoft.com
  • 52.149.20.212
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 20.3.187.198
whitelisted

Threats

No threats detected
Process
Message
DriverSetup.exe
PrinterSetup - Copy POS58UIENG.DLL From C:\Users\admin\AppData\Local\Temp\RarSFX0\SETUP64\ENG To C:\WINDOWS\system32\spool\DRIVERS\x64 Result 0x00010000
DriverSetup.exe
PrinterSetup - Copy POS58ENG.GPD From C:\Users\admin\AppData\Local\Temp\RarSFX0\SETUP64\ENG To C:\WINDOWS\system32\spool\DRIVERS\x64 Result 0x00000000
DriverSetup.exe
PrinterSetup - Copy POS58ENG.INI From C:\Users\admin\AppData\Local\Temp\RarSFX0\SETUP64\ENG To C:\WINDOWS\system32\spool\DRIVERS\x64 Result 0x00000000
DriverSetup.exe
PrinterSetup - Copy POS58UNIENG.DLL From C:\Users\admin\AppData\Local\Temp\RarSFX0\SETUP64\ENG To C:\WINDOWS\system32\spool\DRIVERS\x64 Result 0x00000000
DriverSetup.exe
PrinterSetup - Copy POS58RCENG.DLL From C:\Users\admin\AppData\Local\Temp\RarSFX0\SETUP64\ENG To C:\WINDOWS\system32\spool\DRIVERS\x64 Result 0x00000000
DriverSetup.exe
PrinterSetup - Copy UNIDRV.DLL From C:\Users\admin\AppData\Local\Temp\RarSFX0\SETUP64\ENG To C:\WINDOWS\system32\spool\DRIVERS\x64 Result 0x00000000
DriverSetup.exe
PrinterSetup - Copy UNIDRV.HLP From C:\Users\admin\AppData\Local\Temp\RarSFX0\SETUP64\ENG To C:\WINDOWS\system32\spool\DRIVERS\x64 Result 0x00000000
DriverSetup.exe
PrinterSetup - Copy UNIDRVUI.DLL From C:\Users\admin\AppData\Local\Temp\RarSFX0\SETUP64\ENG To C:\WINDOWS\system32\spool\DRIVERS\x64 Result 0x00000000
DriverSetup.exe
PrinterSetup - Copy STDNAMES.GPD From C:\Users\admin\AppData\Local\Temp\RarSFX0\SETUP64\ENG To C:\WINDOWS\system32\spool\DRIVERS\x64 Result 0x00000000
DriverSetup.exe
PrinterSetup - Copy UNIRES.DLL From C:\Users\admin\AppData\Local\Temp\RarSFX0\SETUP64\ENG To C:\WINDOWS\system32\spool\DRIVERS\x64 Result 0x00000000