File name:

rawprint.exe

Full analysis: https://app.any.run/tasks/9e2ed995-587b-486a-8207-02bad5036be6
Verdict: Malicious activity
Analysis date: September 19, 2023, 09:38:45
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

6CD9362A90A208161182572B2120A191

SHA1:

CEF583E6F6C38E91E78FA9E958155A24878FC5F6

SHA256:

8066C5BB3E45DE320A4FAC47F32607A8982B5D92B2D51AAEFD9796304347EFE5

SSDEEP:

768:4VR+gnkR9zwkYj3eERwv5sjYweuYHSNBjdJwiJiNi5iI7p4d:Y+GUzFOveuNHjdJwSOCx4

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Loads DLL from Mozilla Firefox

      • default-browser-agent.exe (PID: 3080)
    • The process executes via Task Scheduler

      • default-browser-agent.exe (PID: 3080)
    • Reads the Internet Settings

      • default-browser-agent.exe (PID: 3080)
    • Reads security settings of Internet Explorer

      • default-browser-agent.exe (PID: 3080)
    • Checks Windows Trust Settings

      • default-browser-agent.exe (PID: 3080)
    • Reads settings of System Certificates

      • default-browser-agent.exe (PID: 3080)
  • INFO

    • Checks supported languages

      • rawprint.exe (PID: 3488)
      • default-browser-agent.exe (PID: 3080)
    • Reads the computer name

      • rawprint.exe (PID: 3488)
      • default-browser-agent.exe (PID: 3080)
    • Checks proxy server information

      • default-browser-agent.exe (PID: 3080)
    • Reads the machine GUID from the registry

      • default-browser-agent.exe (PID: 3080)
    • Create files in a temporary directory

      • default-browser-agent.exe (PID: 3080)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable (generic) (52.9)
.exe | Generic Win/DOS Executable (23.5)
.exe | DOS Executable Generic (23.5)

EXIF

EXE

SpecialBuild: -
ProductVersion: 1, 0, 0, 1
ProductName: RawPrint Application
PrivateBuild: -
OriginalFileName: RawPrint.EXE
LegalTrademarks: -
LegalCopyright: Copyright (C) 2003
InternalName: RawPrint
FileVersion: 1, 0, 0, 1
FileDescription: RawPrint MFC Application
CompanyName: -
Comments: -
CharacterSet: Unicode
LanguageCode: English (U.S.)
FileSubtype: -
ObjectFileType: Executable application
FileOS: Win32
FileFlags: (none)
FileFlagsMask: 0x003f
ProductVersionNumber: 1.0.0.1
FileVersionNumber: 1.0.0.1
Subsystem: Windows GUI
SubsystemVersion: 4
ImageVersion: -
OSVersion: 4
EntryPoint: 0x523e
UninitializedDataSize: -
InitializedDataSize: 36864
CodeSize: 20480
LinkerVersion: 6
PEType: PE32
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
TimeStamp: 2003:11:23 11:46:29+00:00
MachineType: Intel 386 or later, and compatibles
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
36
Monitored processes
2
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start rawprint.exe no specs default-browser-agent.exe

Process information

PID
CMD
Path
Indicators
Parent process
3080"C:\Program Files\Mozilla Firefox\default-browser-agent.exe" do-task "308046B0AF4A39CB"C:\Program Files\Mozilla Firefox\default-browser-agent.exe
taskeng.exe
User:
admin
Company:
Mozilla Foundation
Integrity Level:
MEDIUM
Description:
Firefox Default Browser Agent
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\default-browser-agent.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msasn1.dll
3488"C:\Users\admin\AppData\Local\Temp\rawprint.exe" C:\Users\admin\AppData\Local\Temp\rawprint.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
RawPrint MFC Application
Exit code:
0
Version:
1, 0, 0, 1
Modules
Images
c:\windows\system32\ntdll.dll
c:\users\admin\appdata\local\temp\rawprint.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mfc42.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
Total events
5 731
Read events
5 709
Write events
22
Delete events
0

Modification events

(PID) Process:(3080) default-browser-agent.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(3080) default-browser-agent.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
460000004F010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(3080) default-browser-agent.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3080) default-browser-agent.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(3080) default-browser-agent.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(3080) default-browser-agent.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(3080) default-browser-agent.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\178\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
Executable files
0
Suspicious files
6
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
3080default-browser-agent.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506compressed
MD5:F3441B8572AAE8801C04F3060B550443
SHA256:6720349E7D82EE0A8E73920D3C2B7CB2912D9FCF2EDB6FD98F2F12820158B0BF
3080default-browser-agent.exeC:\Users\admin\AppData\Local\Temp\TarD7E9.tmpcat
MD5:9441737383D21192400ECA82FDA910EC
SHA256:BC3A6E84E41FAEB57E7C21AA3B60C2A64777107009727C5B7C0ED8FE658909E5
3080default-browser-agent.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:E581EE7DD66A810FF5A2AF7B4C6992C9
SHA256:9F791CAB158533A24C44F603DB2D87FA24EEB48379AF2D84EFDD3EA37664EC58
3080default-browser-agent.exeC:\Users\admin\AppData\Local\Temp\CabD7E8.tmpcompressed
MD5:F3441B8572AAE8801C04F3060B550443
SHA256:6720349E7D82EE0A8E73920D3C2B7CB2912D9FCF2EDB6FD98F2F12820158B0BF
3080default-browser-agent.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\57C8EDB95DF3F0AD4EE2DC2B8CFD4157compressed
MD5:24BE8A92460B5B7A555B1DA559296958
SHA256:77A3CFE6B7EB676AF438D5DE88C7EFCB6ABCC494E0B65DA90201969E6D79B2A3
3080default-browser-agent.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506binary
MD5:9E8F28DC0BB0D571007A71493714B723
SHA256:2388A0089F986C0B7BC35A1BE0E9C1874722CE83DDC78A67B3CF4B04AF8E9F5A
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
8
DNS requests
5
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3080
default-browser-agent.exe
GET
200
178.79.242.0:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?ba16fb409fc394b5
unknown
compressed
61.6 Kb
unknown
3080
default-browser-agent.exe
GET
200
178.79.242.0:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?4f51719d24f966ec
unknown
compressed
4.66 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
3284
svchost.exe
239.255.255.250:1900
whitelisted
1088
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
whitelisted
3080
default-browser-agent.exe
34.149.100.209:443
firefox.settings.services.mozilla.com
GOOGLE
US
unknown
3080
default-browser-agent.exe
178.79.242.0:80
ctldl.windowsupdate.com
LLNW
DE
whitelisted
3080
default-browser-agent.exe
23.212.210.158:80
x1.c.lencr.org
AKAMAI-AS
AU
unknown
3080
default-browser-agent.exe
184.24.77.74:80
r3.o.lencr.org
Akamai International B.V.
DE
unknown

DNS requests

Domain
IP
Reputation
firefox.settings.services.mozilla.com
  • 34.149.100.209
whitelisted
ctldl.windowsupdate.com
  • 178.79.242.0
  • 95.140.236.0
whitelisted
x1.c.lencr.org
  • 23.212.210.158
whitelisted
r3.o.lencr.org
  • 184.24.77.74
  • 184.24.77.54
  • 184.24.77.83
  • 184.24.77.78
  • 184.24.77.48
  • 184.24.77.53
  • 184.24.77.75
  • 184.24.77.46
  • 184.24.77.47
shared
dns.msftncsi.com
  • 131.107.255.255
shared

Threats

No threats detected
No debug info