File name:

POS Printer Driver V8.11.230113.3.exe

Full analysis: https://app.any.run/tasks/c71b6c6a-5bc0-496c-9359-80a12e10741e
Verdict: Malicious activity
Analysis date: October 18, 2023, 11:35:32
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

9A529046F6DD011FA4ACD55BBED760E9

SHA1:

935EB8770A2305E6007C2773D9E779C83361CB00

SHA256:

85C2C28AF7B0D4C881CA49E83B887816998C98255F4DF8B7A85E83DBD9826440

SSDEEP:

98304:Ut9nQL0skPOfNWG4Uq3U2EtQ5aScce/Unba+O+CB3jD9SxPKOgv5fiNyMPBnq3x1:9VS/RUAm

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • POS Printer Driver V8.11.230113.3.exe (PID: 664)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • POS Printer Driver V8.11.230113.3.exe (PID: 664)
  • INFO

    • Checks supported languages

      • POS Printer Driver V8.11.230113.3.exe (PID: 664)
      • wmpnscfg.exe (PID: 4064)
    • Reads the machine GUID from the registry

      • wmpnscfg.exe (PID: 4064)
    • Reads the computer name

      • wmpnscfg.exe (PID: 4064)
      • POS Printer Driver V8.11.230113.3.exe (PID: 664)
    • Creates files in the program directory

      • POS Printer Driver V8.11.230113.3.exe (PID: 664)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (17.3)
.dll | Win32 Dynamic Link Library (generic) (4.1)
.exe | Win32 Executable (generic) (2.8)
.exe | Generic Win/DOS Executable (1.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2022:12:13 03:05:28+01:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14.29
CodeSize: 1710080
InitializedDataSize: 2063872
UninitializedDataSize: -
EntryPoint: 0x16c20b
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 8.11.221.213
ProductVersionNumber: 8.11.0.60
FileFlagsMask: 0x003f
FileFlags: Pre-release, Patched, Private build, Special build
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Chinese (Simplified)
CharacterSet: Unicode
CompanyName: 2022 (C) Copyright
FileDescription: POS Printer Driver Setup
FileVersion: 8.11.221.213
InternalName: POSPrinterDriverSetup.exe
LegalCopyright: 2022 (C) Copyright
OriginalFileName: POSPrinterDriverSetup.exe
ProductName: POSPrinterDriverSetup
ProductVersion: 8.11.0.60
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
41
Monitored processes
3
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start pos printer driver v8.11.230113.3.exe pos printer driver v8.11.230113.3.exe no specs wmpnscfg.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
664"C:\Users\admin\AppData\Local\Temp\POS Printer Driver V8.11.230113.3.exe" C:\Users\admin\AppData\Local\Temp\POS Printer Driver V8.11.230113.3.exe
explorer.exe
User:
admin
Company:
2022 (C) Copyright
Integrity Level:
HIGH
Description:
POS Printer Driver Setup
Exit code:
0
Version:
8.11.221.213
Modules
Images
c:\users\admin\appdata\local\temp\pos printer driver v8.11.230113.3.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msimg32.dll
1536"C:\Users\admin\AppData\Local\Temp\POS Printer Driver V8.11.230113.3.exe" C:\Users\admin\AppData\Local\Temp\POS Printer Driver V8.11.230113.3.exeexplorer.exe
User:
admin
Company:
2022 (C) Copyright
Integrity Level:
MEDIUM
Description:
POS Printer Driver Setup
Exit code:
3221226540
Version:
8.11.221.213
Modules
Images
c:\users\admin\appdata\local\temp\pos printer driver v8.11.230113.3.exe
c:\windows\system32\ntdll.dll
4064"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\ole32.dll
Total events
183
Read events
180
Write events
0
Delete events
3

Modification events

(PID) Process:(4064) wmpnscfg.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{A678A1FB-CE2D-456E-97F0-333A9FB51765}\{C01382C4-86B3-429C-A0C7-C814DA5DE7AC}
Operation:delete keyName:(default)
Value:
(PID) Process:(4064) wmpnscfg.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{A678A1FB-CE2D-456E-97F0-333A9FB51765}
Operation:delete keyName:(default)
Value:
(PID) Process:(4064) wmpnscfg.exeKey:HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Health\{54443769-F5BA-4669-B57D-D431FC29AA68}
Operation:delete keyName:(default)
Value:
Executable files
33
Suspicious files
8
Text files
27
Unknown types
0

Dropped files

PID
Process
Filename
Type
664POS Printer Driver V8.11.230113.3.exeC:\Program Files (x86)\POS Printer Driver V8.11\Windows ARM64.zipcompressed
MD5:1B0BD62A5AF2D9D599A17368998A8037
SHA256:96CCA0529193B015493CF5A29A20755CFC708FA6D419EF17D3E060FAB9AC58BB
664POS Printer Driver V8.11.230113.3.exeC:\Program Files (x86)\POS Printer Driver V8.11\Windows ARM64\RES\P80.GPDtext
MD5:93A708D07D0EC267FF7275D9A3EC1771
SHA256:E6A3400D48253B30E5A9EB1C27BF18A4EA0E6143D34A8E60874B5D939FE8C88C
664POS Printer Driver V8.11.230113.3.exeC:\Program Files (x86)\POS Printer Driver V8.11\Windows ARM64\ReceiptDrv.dllexecutable
MD5:03A85A2E0314226452B9BE283759AFDD
SHA256:6087D7B3FCBBB7051F3693972BAEDA51459B9EC798462CABF1D3C8A2B5FDB70B
664POS Printer Driver V8.11.230113.3.exeC:\Program Files (x86)\POS Printer Driver V8.11\Windows ARM64\RES\P76.dllexecutable
MD5:31C466F9C7CF5A20574C21D1C637CFBC
SHA256:BAB46D640BF7A147EF90FFADCF1E106F9689DDB22CB0085332F51D57386DEFA6
664POS Printer Driver V8.11.230113.3.exeC:\Program Files (x86)\POS Printer Driver V8.11\Windows ARM64\RES\P76.GPDtext
MD5:1D4F68057F5DBDB9197EC28BFEA5FA7E
SHA256:453BEB779B5C2DAAF1A4789B89D339896AE859B4E00C793E3AF649837C3A0AD2
664POS Printer Driver V8.11.230113.3.exeC:\Program Files (x86)\POS Printer Driver V8.11\Windows ARM64\RES\P80.dllexecutable
MD5:F91FF5E7B6EE4FA915B16C6E138CDA52
SHA256:B32FBD1B9AC072D0759AC25B6CC1E3B93666DF08A55729DB0D134848C6963B3F
664POS Printer Driver V8.11.230113.3.exeC:\Program Files (x86)\POS Printer Driver V8.11\Windows ARM64\RES\P76C.GPDtext
MD5:DA090B0EBE8CEC77E50E56CAFE2F7D2D
SHA256:CE03D5157933D0E15730D8FA6CF1875B042C38E0C098FE8878164B693D20A11B
664POS Printer Driver V8.11.230113.3.exeC:\Program Files (x86)\POS Printer Driver V8.11\Windows ARM64\UNIDRVUI.DLLexecutable
MD5:F5137CC587A51288A73340C1046504B8
SHA256:708F10BE94938459F91A40E79D98A5665B8BF1395409A37E49B5DDA47329A51E
664POS Printer Driver V8.11.230113.3.exeC:\Program Files (x86)\POS Printer Driver V8.11\Windows ARM64\RES\P58.GPDtext
MD5:26BBDCDF2973320EF08C3696815B7813
SHA256:D8BB6ABE4760C3ACC40E409FC890CEF706781A3CED5A0A3D7C86B981B1873954
664POS Printer Driver V8.11.230113.3.exeC:\Program Files (x86)\POS Printer Driver V8.11\Windows ARM64\RES\P58C.GPDtext
MD5:31174C73B3E587B193273BBB78AE190E
SHA256:A36A6811103E833E9F5DC4A41A50BC9762C43F85E0235073DD402A3DF4A07FD4
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
3
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
2656
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:138
whitelisted

DNS requests

No data

Threats

No threats detected
No debug info