File name:

express scribe.exe

Full analysis: https://app.any.run/tasks/8922531c-73ea-4293-a019-eccb4e7b8d8e
Verdict: Malicious activity
Analysis date: June 28, 2024, 22:37:50
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

518CC34760C490383B9C7B773E04BD1E

SHA1:

4551C5835C3AB141B44FE317D474998038D8F464

SHA256:

7A80ABD72A27DBFC124B852544E61893C447E8B75C9663AB5BF200CDF271A0A7

SSDEEP:

49152:g1CVJsi7+Bl6iqdTf5pPqty0qsYpAtMr8/bj20iYWRGGtl+tkH98bBA1MWZO2ThU:g2qBYX9f5YtlYpuMsliYItstkH98bBAI

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • express scribe.exe (PID: 2752)
      • nchsetup.exe (PID: 3100)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • express scribe.exe (PID: 2752)
      • nchsetup.exe (PID: 3100)
    • Reads security settings of Internet Explorer

      • express scribe.exe (PID: 2752)
    • Reads the Internet Settings

      • express scribe.exe (PID: 2752)
      • nchsetup.exe (PID: 3100)
    • Searches for installed software

      • nchsetup.exe (PID: 3100)
    • Creates a software uninstall entry

      • nchsetup.exe (PID: 3100)
    • Starts itself from another location

      • nchsetup.exe (PID: 3100)
  • INFO

    • Create files in a temporary directory

      • express scribe.exe (PID: 2752)
      • scribe.exe (PID: 3572)
    • Checks supported languages

      • express scribe.exe (PID: 2752)
      • nchsetup.exe (PID: 3100)
      • msiexec.exe (PID: 3096)
      • scribe.exe (PID: 3580)
      • scribe.exe (PID: 3572)
    • Reads the computer name

      • express scribe.exe (PID: 2752)
      • nchsetup.exe (PID: 3100)
      • msiexec.exe (PID: 3096)
      • scribe.exe (PID: 3580)
      • scribe.exe (PID: 3572)
    • Creates files in the program directory

      • nchsetup.exe (PID: 3100)
    • Reads the machine GUID from the registry

      • msiexec.exe (PID: 3096)
      • scribe.exe (PID: 3572)
    • Creates files or folders in the user directory

      • scribe.exe (PID: 3572)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.dll | Win32 Dynamic Link Library (generic) (43.5)
.exe | Win32 Executable (generic) (29.8)
.exe | Generic Win/DOS Executable (13.2)
.exe | DOS Executable Generic (13.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2012:09:26 23:51:13+00:00
ImageFileCharacteristics: No relocs, Executable, 32-bit
PEType: PE32
LinkerVersion: 8
CodeSize: -
InitializedDataSize: 1039360
UninitializedDataSize: -
EntryPoint: 0x21d8
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 0.0.0.0
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x0017
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (Australian)
CharacterSet: Unicode
CompanyName: NCH Software
FileDescription: Express Scribe
FileVersion: 5.59+
ProductName: ExpressScribe
LegalCopyright: NCH Software
InternalName: Scribe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
50
Monitored processes
9
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start express scribe.exe nchsetup.exe msiexec.exe no specs msiexec.exe no specs msiexec.exe no specs scribe.exe no specs scribe.exe no specs wmpnscfg.exe no specs express scribe.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
400MsiExec.exe /X{86D4B82A-ABED-442A-BE86-96357B70F4FE} /passive /quietC:\Windows\System32\msiexec.exenchsetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Exit code:
1605
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1460MsiExec.exe /X{86D4B82A-ABED-442A-BE86-96357B70F4FE} /passive /quietC:\Windows\System32\msiexec.exenchsetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Exit code:
1605
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2752"C:\Users\admin\AppData\Local\Temp\express scribe.exe" C:\Users\admin\AppData\Local\Temp\express scribe.exe
explorer.exe
User:
admin
Company:
NCH Software
Integrity Level:
HIGH
Description:
Express Scribe
Exit code:
0
Version:
5.59+
Modules
Images
c:\users\admin\appdata\local\temp\express scribe.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
3096C:\Windows\system32\msiexec.exe /VC:\Windows\System32\msiexec.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3100"C:\Users\admin\AppData\Local\Temp\n1s\nchsetup.exe" -installer "C:\Users\admin\AppData\Local\Temp\express scribe.exe" -instdata "C:\Users\admin\AppData\Local\Temp\n1s\nchdata.dat"C:\Users\admin\AppData\Local\Temp\n1s\nchsetup.exe
express scribe.exe
User:
admin
Company:
NCH Software
Integrity Level:
HIGH
Description:
Express Scribe
Exit code:
0
Version:
5.59+
Modules
Images
c:\users\admin\appdata\local\temp\n1s\nchsetup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\gdi32.dll
3416"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
3532"C:\Users\admin\AppData\Local\Temp\express scribe.exe" C:\Users\admin\AppData\Local\Temp\express scribe.exeexplorer.exe
User:
admin
Company:
NCH Software
Integrity Level:
MEDIUM
Description:
Express Scribe
Exit code:
3221226540
Version:
5.59+
Modules
Images
c:\users\admin\appdata\local\temp\express scribe.exe
c:\windows\system32\ntdll.dll
3572"C:\Program Files\NCH Software\Scribe\scribe.exe"C:\Program Files\NCH Software\Scribe\scribe.exenchsetup.exe
User:
admin
Company:
NCH Software
Integrity Level:
MEDIUM
Description:
Express Scribe
Version:
5.59+
Modules
Images
c:\program files\nch software\scribe\scribe.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\gdi32.dll
3580"C:\Program Files\NCH Software\Scribe\scribe.exe" -installschedC:\Program Files\NCH Software\Scribe\scribe.exenchsetup.exe
User:
admin
Company:
NCH Software
Integrity Level:
MEDIUM
Description:
Express Scribe
Exit code:
0
Version:
5.59+
Modules
Images
c:\program files\nch software\scribe\scribe.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\gdi32.dll
Total events
7 465
Read events
7 332
Write events
129
Delete events
4

Modification events

(PID) Process:(2752) express scribe.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2752) express scribe.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(2752) express scribe.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(2752) express scribe.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(3100) nchsetup.exeKey:HKEY_CURRENT_USER\Software\NCH Software\Scribe\Settings
Operation:writeName:InstallerPath
Value:
C:\Program Files\NCH Software\Scribe
(PID) Process:(3100) nchsetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\NCH Software\Scribe\Settings
Operation:writeName:InstallerPath
Value:
C:\Program Files\NCH Software\Scribe
(PID) Process:(3100) nchsetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Scribe
Operation:writeName:DisplayName
Value:
Express Scribe
(PID) Process:(3100) nchsetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Scribe
Operation:writeName:Publisher
Value:
NCH Software
(PID) Process:(3100) nchsetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Scribe
Operation:writeName:UninstallString
Value:
"C:\Program Files\NCH Software\Scribe\scribe.exe" -uninstall
(PID) Process:(3100) nchsetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Scribe
Operation:writeName:DisplayIcon
Value:
C:\Program Files\NCH Software\Scribe\scribe.exe
Executable files
5
Suspicious files
29
Text files
44
Unknown types
0

Dropped files

PID
Process
Filename
Type
2752express scribe.exeC:\Users\admin\AppData\Local\Temp\n1s\nchdata.datexecutable
MD5:860723442C1E90B370B5EBAC3059EC54
SHA256:EF2CD165046CD0C425C5F4B617E848ADCC5789A0684632F5A4A4A28DF65DA510
3100nchsetup.exeC:\Program Files\NCH Software\Scribe\help\about.htmlhtml
MD5:C65A16078E449B2BFF3AD7C2BBD6C909
SHA256:41EE4952E517820248BCC34106CB5AD79C10A70DA65C513756971E8A5923DB59
3100nchsetup.exeC:\Program Files\NCH Software\Scribe\help\licences.htmlhtml
MD5:2A542DF213EB5B5AF2157E843502E7D1
SHA256:989AA3C902712773238644698BD3F39C5F5BFE0ABE26001EB233607A8D1C7669
3100nchsetup.exeC:\Program Files\NCH Software\Scribe\help\cd.htmlhtml
MD5:9E964A98C2630499A25C9FF4EC254925
SHA256:C8B2E07F8697234EF40AEDD6366BCD48870B6D01F11C15E094186BAD6D993C44
2752express scribe.exeC:\Users\admin\AppData\Local\Temp\n1s\nchsetup.cabcompressed
MD5:AF2EFF2318D5C0DCEB41219FE1A56F49
SHA256:085035462142AF2A38575091849C833DC905A241D6121FF39C5BB6798CFA2054
2752express scribe.exeC:\Users\admin\AppData\Local\Temp\n1s\nchsetup.exeexecutable
MD5:7D013EA1DEF556BF44463A5F70C7AA00
SHA256:82E5ECB1D456593895E5FB7849E015B74E3B67C47064319DB44775696B4A7F05
3100nchsetup.exeC:\Program Files\NCH Software\Scribe\scribe.exeexecutable
MD5:7D013EA1DEF556BF44463A5F70C7AA00
SHA256:82E5ECB1D456593895E5FB7849E015B74E3B67C47064319DB44775696B4A7F05
3100nchsetup.exeC:\Program Files\NCH Software\Scribe\hookappcommand.dllexecutable
MD5:C9D7F12D4B1567EF2B823A9F872B3C9D
SHA256:1F49E885F8C9293B76CC38AE7C7700C7FEDD8645BB3EC6D8B1E87FF6D068D9F2
3100nchsetup.exeC:\ProgramData\NCH Software\Scribe\Current\Welcome.wavbinary
MD5:B7F56245B177A188722A6EADFA44A078
SHA256:165D3B06642197CCF0366E966047EEB7D62CFAE38150105EF3E6A35336AD74B5
2752express scribe.exeC:\Users\admin\AppData\Local\Temp\n1s\nchdata.cabcompressed
MD5:4097DAF20E52E5129E5FDA7C492F56FF
SHA256:5C4AA945F5AF63846C91BAA552911BA97A3F883F7C15226DB755CA423DE5D12D
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
12
DNS requests
5
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1372
svchost.exe
GET
200
23.52.120.96:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
DE
binary
973 b
unknown
1372
svchost.exe
GET
304
23.53.40.83:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?33775f6043c93e33
DE
unknown
1372
svchost.exe
GET
200
23.48.23.156:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
DE
binary
1.01 Kb
unknown
1060
svchost.exe
GET
304
23.53.40.49:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?a9f83325acc8ca75
DE
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1372
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
2564
svchost.exe
239.255.255.250:3702
whitelisted
1060
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:137
whitelisted
1372
svchost.exe
23.53.40.83:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown
1372
svchost.exe
23.48.23.156:80
crl.microsoft.com
Akamai International B.V.
DE
unknown
1372
svchost.exe
23.52.120.96:80
www.microsoft.com
AKAMAI-AS
DE
unknown
1060
svchost.exe
23.53.40.49:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
whitelisted
ctldl.windowsupdate.com
  • 23.53.40.83
  • 23.53.40.35
  • 23.53.40.49
whitelisted
crl.microsoft.com
  • 23.48.23.156
  • 23.48.23.143
whitelisted
www.microsoft.com
  • 23.52.120.96
whitelisted

Threats

No threats detected
No debug info