File name:

CLodop_Setup_for_Win32NT (1).exe

Full analysis: https://app.any.run/tasks/8f305750-d902-4f15-981f-a83abc51918e
Verdict: Malicious activity
Threats:

Metamorfo is a trojan malware family that has been active since 2018. It remains a top threat, focusing on stealing victims’ financial information, including banking credentials and other data. The malware is known for targeting users in Brazil.

Analysis date: October 25, 2023, 13:08:29
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
metamorfo
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

EAC342A26A394ECDCF95E668121F6526

SHA1:

C5EE45D5CD506DC330DDE8DE3779DC83BF286400

SHA256:

81B89CC0B3659C6E250B5ECF6B86D3E8CCBA14CDA64E51E7B8DC1747113EF4EF

SSDEEP:

98304:+xUNtgBzrIWreDvt4vPprIpk6pjcnguWlV3eaEL/l2Yh+hOoBo0l2sAgX/gZmhEA:4E2jnkyk6K7C21Bbv

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • CLodop_Setup_for_Win32NT (1).exe (PID: 2328)
      • is-8SFLL.tmp (PID: 2440)
      • CLodopPrint32.exe (PID: 1736)
    • Loads dropped or rewritten executable

      • is-8SFLL.tmp (PID: 2440)
      • CLodopPrint32.exe (PID: 1736)
    • Application was dropped or rewritten from another process

      • CLodopPrint32.exe (PID: 1736)
      • CLodopService32.exe (PID: 2628)
      • CLodopPrint32_backup.exe (PID: 3420)
      • CLodopPrint32_backup.exe (PID: 2568)
      • CLodopService32.exe (PID: 1556)
    • METAMORFO has been detected (YARA)

      • CLodopPrint32.exe (PID: 1736)
      • CLodopPrint32_backup.exe (PID: 2568)
      • CLodopService32.exe (PID: 1556)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • is-8SFLL.tmp (PID: 2440)
    • Reads the Windows owner or organization settings

      • is-8SFLL.tmp (PID: 2440)
    • The process drops C-runtime libraries

      • is-8SFLL.tmp (PID: 2440)
    • Reads the Internet Settings

      • CLodopPrint32.exe (PID: 1736)
    • Starts itself from another location

      • CLodopPrint32.exe (PID: 1736)
    • Executes as Windows Service

      • CLodopService32.exe (PID: 1556)
  • INFO

    • Checks supported languages

      • is-8SFLL.tmp (PID: 2440)
      • CLodop_Setup_for_Win32NT (1).exe (PID: 2328)
      • CLodopPrint32.exe (PID: 1736)
      • CLodopService32.exe (PID: 2628)
      • CLodopService32.exe (PID: 1556)
      • CLodopPrint32_backup.exe (PID: 2568)
    • Create files in a temporary directory

      • CLodop_Setup_for_Win32NT (1).exe (PID: 2328)
      • is-8SFLL.tmp (PID: 2440)
      • CLodopPrint32.exe (PID: 1736)
    • Reads the computer name

      • is-8SFLL.tmp (PID: 2440)
      • CLodopPrint32.exe (PID: 1736)
      • CLodopService32.exe (PID: 2628)
      • CLodopService32.exe (PID: 1556)
      • CLodopPrint32_backup.exe (PID: 2568)
    • Application was dropped or rewritten from another process

      • is-8SFLL.tmp (PID: 2440)
    • Creates files in the program directory

      • is-8SFLL.tmp (PID: 2440)
      • CLodopPrint32.exe (PID: 1736)
    • Reads the machine GUID from the registry

      • CLodopPrint32.exe (PID: 1736)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (77.7)
.exe | Win32 Executable Delphi generic (10)
.dll | Win32 Dynamic Link Library (generic) (4.6)
.exe | Win32 Executable (generic) (3.1)
.exe | Win16/32 Executable Delphi generic (1.4)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 1992:06:20 00:22:17+02:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 36864
InitializedDataSize: 15872
UninitializedDataSize: -
EntryPoint: 0x97f8
OSVersion: 1
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 6.5.7.7
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Chinese (Simplified)
CharacterSet: ASCII
Comments: 此安装程序由 Inno Setup 构建。
CompanyName: MTSoftware(CN)
FileDescription: C-Lodop(32-bit) Setup
FileVersion: 6.5.7.7
LegalCopyright:
No data.
screenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
48
Monitored processes
8
Malicious processes
6
Suspicious processes
1

Behavior graph

Click at the process to see the details
drop and start start drop and start drop and start drop and start clodop_setup_for_win32nt (1).exe is-8sfll.tmp no specs #METAMORFO clodopprint32.exe no specs clodopservice32.exe no specs #METAMORFO clodopservice32.exe no specs clodopprint32_backup.exe no specs #METAMORFO clodopprint32_backup.exe no specs clodop_setup_for_win32nt (1).exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1556"C:\Program Files\MountTaiSoftware\CLodop32\CLodopService32.exe"C:\Program Files\MountTaiSoftware\CLodop32\CLodopService32.exe
services.exe
User:
SYSTEM
Company:
(中国)梦泰尔软件 MTSoftware(CN)
Integrity Level:
SYSTEM
Description:
C-Lodop 云打印“免登录”启动服务
Exit code:
0
Version:
6.5.7.1
Modules
Images
c:\program files\mounttaisoftware\clodop32\clodopservice32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1736"C:\Program Files\MountTaiSoftware\CLodop32\CLodopPrint32.exe" setup_noautoC:\Program Files\MountTaiSoftware\CLodop32\CLodopPrint32.exe
is-8SFLL.tmp
User:
admin
Company:
(中国)梦泰尔软件 MTSoftware(CN)
Integrity Level:
HIGH
Description:
Web打印服务C-Lodop
Exit code:
0
Version:
6.5.7.7
Modules
Images
c:\program files\mounttaisoftware\clodop32\clodopprint32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\user32.dll
2328"C:\Users\admin\AppData\Local\Temp\CLodop_Setup_for_Win32NT (1).exe" C:\Users\admin\AppData\Local\Temp\CLodop_Setup_for_Win32NT (1).exe
explorer.exe
User:
admin
Company:
MTSoftware(CN)
Integrity Level:
HIGH
Description:
C-Lodop(32-bit) Setup
Exit code:
0
Version:
6.5.7.7
Modules
Images
c:\users\admin\appdata\local\temp\clodop_setup_for_win32nt (1).exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
2440"C:\Users\admin\AppData\Local\Temp\is-9AKG9.tmp\is-8SFLL.tmp" /SL4 $1001CA "C:\Users\admin\AppData\Local\Temp\CLodop_Setup_for_Win32NT (1).exe" 4701871 51200 C:\Users\admin\AppData\Local\Temp\is-9AKG9.tmp\is-8SFLL.tmpCLodop_Setup_for_Win32NT (1).exe
User:
admin
Integrity Level:
HIGH
Description:
安装/卸载
Exit code:
0
Version:
51.46.0.0
Modules
Images
c:\windows\system32\ntdll.dll
c:\users\admin\appdata\local\temp\is-9akg9.tmp\is-8sfll.tmp
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
2568"C:\Program Files\MountTaiSoftware\CLodop32\CLodopPrint32_backup.exe" C:\Program Files\MountTaiSoftware\CLodop32\CLodopPrint32_backup.exe
CLodopPrint32.exe
User:
admin
Company:
(中国)梦泰尔软件 MTSoftware(CN)
Integrity Level:
HIGH
Description:
Web打印服务C-Lodop
Exit code:
0
Version:
6.5.7.7
Modules
Images
c:\program files\mounttaisoftware\clodop32\clodopprint32_backup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\lpk.dll
c:\windows\system32\user32.dll
2628"C:\Program Files\MountTaiSoftware\CLodop32\CLodopService32.exe" -INSTALL -SILENTC:\Program Files\MountTaiSoftware\CLodop32\CLodopService32.exeCLodopPrint32.exe
User:
admin
Company:
(中国)梦泰尔软件 MTSoftware(CN)
Integrity Level:
HIGH
Description:
C-Lodop 云打印“免登录”启动服务
Exit code:
0
Version:
6.5.7.1
Modules
Images
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\ntdll.dll
c:\program files\mounttaisoftware\clodop32\clodopservice32.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\rpcrt4.dll
3420"C:\Program Files\MountTaiSoftware\CLodop32\CLodopPrint32_backup.exe" C:\Program Files\MountTaiSoftware\CLodop32\CLodopPrint32_backup.exeCLodopPrint32.exe
User:
admin
Company:
(中国)梦泰尔软件 MTSoftware(CN)
Integrity Level:
HIGH
Description:
Web打印服务C-Lodop
Exit code:
0
Version:
6.5.7.7
Modules
Images
c:\windows\system32\ntdll.dll
c:\program files\mounttaisoftware\clodop32\clodopprint32_backup.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
3820"C:\Users\admin\AppData\Local\Temp\CLodop_Setup_for_Win32NT (1).exe" C:\Users\admin\AppData\Local\Temp\CLodop_Setup_for_Win32NT (1).exeexplorer.exe
User:
admin
Company:
MTSoftware(CN)
Integrity Level:
MEDIUM
Description:
C-Lodop(32-bit) Setup
Exit code:
3221226540
Version:
6.5.7.7
Modules
Images
c:\users\admin\appdata\local\temp\clodop_setup_for_win32nt (1).exe
c:\windows\system32\ntdll.dll
Total events
1 543
Read events
1 530
Write events
13
Delete events
0

Modification events

(PID) Process:(1736) CLodopPrint32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLodop.protocol
Operation:writeName:URL Protocol
Value:
(PID) Process:(1736) CLodopPrint32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLodop.protocol\Application
Operation:writeName:ApplicationName
Value:
Web打印服务C-Lodop
(PID) Process:(1736) CLodopPrint32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLodop.protocol\Application
Operation:writeName:ApplicationCompany
Value:
MTSoftware
(PID) Process:(1736) CLodopPrint32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLodop.protocol\Application
Operation:writeName:ApplicationDescription
Value:
Web打印服务C-Lodop
(PID) Process:(1736) CLodopPrint32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLodop.protocol\Application
Operation:writeName:ApplicationIcon
Value:
C:\Program Files\MountTaiSoftware\CLodop32\CLodopPrint32.exe,0
(PID) Process:(1736) CLodopPrint32.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(1736) CLodopPrint32.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(1736) CLodopPrint32.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(1736) CLodopPrint32.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
Executable files
19
Suspicious files
7
Text files
133
Unknown types
0

Dropped files

PID
Process
Filename
Type
2440is-8SFLL.tmpC:\Users\admin\AppData\Local\Temp\is-JI52T.tmp\_isetup\_shfoldr.dllexecutable
MD5:92DC6EF532FBB4A5C3201469A5B5EB63
SHA256:9884E9D1B4F8A873CCBD81F8AD0AE257776D2348D027D811A56475E028360D87
2440is-8SFLL.tmpC:\Program Files\MountTaiSoftware\CLodop32\SSL\is-JKUQ0.tmp
MD5:
SHA256:
2440is-8SFLL.tmpC:\Program Files\MountTaiSoftware\CLodop32\SSL\localhost_c_bak.pem
MD5:
SHA256:
2440is-8SFLL.tmpC:\Program Files\MountTaiSoftware\CLodop32\SSL\is-9S9DN.tmp
MD5:
SHA256:
2440is-8SFLL.tmpC:\Program Files\MountTaiSoftware\CLodop32\SSL\localhost_c_bak.key
MD5:
SHA256:
2440is-8SFLL.tmpC:\Users\admin\AppData\Local\Temp\is-JI52T.tmp\_isetup\_RegDLL.tmpexecutable
MD5:C594B792B9C556EA62A30DE541D2FB03
SHA256:5DCC1E0A197922907BCA2C4369F778BD07EE4B1BBBDF633E987A028A314D548E
2440is-8SFLL.tmpC:\Program Files\MountTaiSoftware\CLodop32\is-M1TDV.tmpexecutable
MD5:7A6D009BB8F758C5DCE0830CC3FFD25B
SHA256:A5E18AA27305328549D9606BA47417285527758F61EC9DB494473CC8B1AC0BF7
2440is-8SFLL.tmpC:\Program Files\MountTaiSoftware\CLodop32\unins000.exeexecutable
MD5:7A6D009BB8F758C5DCE0830CC3FFD25B
SHA256:A5E18AA27305328549D9606BA47417285527758F61EC9DB494473CC8B1AC0BF7
2328CLodop_Setup_for_Win32NT (1).exeC:\Users\admin\AppData\Local\Temp\is-9AKG9.tmp\is-8SFLL.tmpexecutable
MD5:79551E7F460CE4A92B6C9C0F0B714108
SHA256:06AE7ABCEC424F92569CD67E55E27C7E91F84F6108F91876CD3F135262341BEF
2440is-8SFLL.tmpC:\Users\admin\AppData\Local\Temp\is-JI52T.tmp\TaskDll.dllexecutable
MD5:3A57389802E43A5BC4F13E99742C218E
SHA256:25CD485DD2A9E692637A6860ED3F75F810D8883781D169EE4954170FB800DCA6
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
3
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
2656
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:138
whitelisted

DNS requests

No data

Threats

No threats detected
No debug info