File name:

0503.exe

Full analysis: https://app.any.run/tasks/70b901ac-87ef-4089-a43c-bbc8ad3ff14c
Verdict: Malicious activity
Analysis date: May 03, 2024, 01:51:18
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
MD5:

FE54E986A6F7E89D07ECB70D4B023760

SHA1:

269A71838057F0C1AD5F961ECCD7FCB111A2709D

SHA256:

871A4927FF68D1F1C7466CFB8D37A55705207E6A2AB9EFC7DD895EECAC73D3B0

SSDEEP:

98304:EtC08sKQJWuXO91YosnKHOWIquzKd4Ia0NSTnvCKGalMeYVjSCREDnyySZx0mimV:aTES5pjp8LdCg049

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • markany_ImageSafer.exe (PID: 928)
      • 0503.exe (PID: 4080)
      • Inst_MaEPSBroker.exe (PID: 1764)
    • Creates a writable file in the system directory

      • markany_ImageSafer.exe (PID: 928)
      • 0503.exe (PID: 4080)
    • Actions looks like stealing of personal data

      • cmd.exe (PID: 660)
      • certutil.exe (PID: 1488)
    • Changes the autorun value in the registry

      • Inst_MaEPSBroker.exe (PID: 1764)
    • Registers / Runs the DLL via REGSVR32.EXE

      • 0503.exe (PID: 4080)
  • SUSPICIOUS

    • Malware-specific behavior (creating "System.dll" in Temp)

      • markany_ImageSafer.exe (PID: 928)
      • Inst_MaEPSBroker.exe (PID: 1764)
      • 0503.exe (PID: 4080)
    • Executable content was dropped or overwritten

      • 0503.exe (PID: 4080)
      • markany_ImageSafer.exe (PID: 928)
      • Inst_MaEPSBroker.exe (PID: 1764)
    • The process creates files with name similar to system file names

      • markany_ImageSafer.exe (PID: 928)
      • Inst_MaEPSBroker.exe (PID: 1764)
      • 0503.exe (PID: 4080)
    • Drops a system driver (possible attempt to evade defenses)

      • markany_ImageSafer.exe (PID: 928)
    • Executes as Windows Service

      • IMGSF50Svc.exe (PID: 1876)
    • Adds/modifies Windows certificates

      • BrokerCRIMGR.exe (PID: 1664)
    • Creates/Modifies COM task schedule object

      • Inst_MaEPSBroker.exe (PID: 1764)
      • regsvr32.exe (PID: 2556)
    • Process drops legitimate windows executable

      • Inst_MaEPSBroker.exe (PID: 1764)
    • Executing commands from a ".bat" file

      • Inst_MaEPSBroker.exe (PID: 1764)
    • Starts CMD.EXE for commands execution

      • Inst_MaEPSBroker.exe (PID: 1764)
    • Uses TASKKILL.EXE to kill Browsers

      • Inst_MaEPSBroker.exe (PID: 1764)
    • Creates a software uninstall entry

      • Inst_MaEPSBroker.exe (PID: 1764)
      • 0503.exe (PID: 4080)
    • Uses NETSH.EXE to delete a firewall rule or allowed programs

      • Inst_MaEPSBroker.exe (PID: 1764)
    • Uses NETSH.EXE to add a firewall rule or allowed programs

      • Inst_MaEPSBroker.exe (PID: 1764)
  • INFO

    • Reads the computer name

      • 0503.exe (PID: 4080)
      • markany_ImageSafer.exe (PID: 928)
      • IMGSF50Start_x86.exe (PID: 2180)
      • IMGSF50Svc.exe (PID: 820)
      • IMGSF50Svc.exe (PID: 112)
      • IMGSF50Svc.exe (PID: 1876)
      • certutil.exe (PID: 1488)
      • Inst_MaEPSBroker.exe (PID: 1764)
      • MaEPSBroker.exe (PID: 1548)
    • Checks supported languages

      • 0503.exe (PID: 4080)
      • markany_ImageSafer.exe (PID: 928)
      • IMGSF50Svc.exe (PID: 820)
      • Inst_MaEPSBroker.exe (PID: 1764)
      • IMGSF50Svc.exe (PID: 112)
      • IMGSF50Svc.exe (PID: 1876)
      • IMGSF50Start_x86.exe (PID: 2180)
      • BrokerCRIMGR.exe (PID: 1664)
      • certutil.exe (PID: 1488)
      • MaEPSBroker.exe (PID: 1548)
    • Create files in a temporary directory

      • 0503.exe (PID: 4080)
      • markany_ImageSafer.exe (PID: 928)
      • Inst_MaEPSBroker.exe (PID: 1764)
    • Creates files or folders in the user directory

      • certutil.exe (PID: 1488)
    • Creates files in the program directory

      • Inst_MaEPSBroker.exe (PID: 1764)
    • Reads the machine GUID from the registry

      • MaEPSBroker.exe (PID: 1548)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2018:12:15 22:24:41+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 25600
InitializedDataSize: 162816
UninitializedDataSize: 1024
EntryPoint: 0x320c
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 2.5.0.5
ProductVersionNumber: 2.5.0.5
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
Comments: MarkAny Inc. e-PageSafer v2.5 NoaXOZ
CompanyName: MarkAny Inc.
FileDescription: MarkAny Inc. e-PageSafer v2.5 NoaXOZ
FileVersion: 2.5.0.5
LegalCopyright: MarkAny Inc.
ProductName: MarkAny Inc. e-PageSafer v2.5 NoaXOZ
ProductVersion: 2.5.0.5
No data.
screenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
59
Monitored processes
17
Malicious processes
5
Suspicious processes
0

Behavior graph

Click at the process to see the details
start 0503.exe markany_imagesafer.exe imgsf50svc.exe no specs imgsf50svc.exe no specs imgsf50svc.exe no specs imgsf50start_x86.exe no specs inst_maepsbroker.exe cmd.exe certutil.exe brokercrimgr.exe no specs netsh.exe no specs netsh.exe no specs maepsbroker.exe no specs taskkill.exe no specs taskkill.exe no specs regsvr32.exe no specs 0503.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
112C:\Windows\IMGSF50Svc.exe -startC:\Windows\IMGSF50Svc.exemarkany_ImageSafer.exe
User:
admin
Company:
MarkAny
Integrity Level:
HIGH
Description:
Image SAFER 5.0 Session Managing Service for x86
Exit code:
0
Version:
5.0.21.1101
Modules
Images
c:\windows\imgsf50svc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
660C:\Windows\system32\cmd.exe /c ""C:\Program Files\MarkAny\EPSBroker\cert\MaImpCff.bat""C:\Windows\System32\cmd.exe
Inst_MaEPSBroker.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
768C:\Windows\system32\netsh advfirewall firewall delete rule name= "MaEPSBroker" program="C:\Program Files\MarkAny\EPSBroker\MaEPSBroker.exe"C:\Windows\System32\netsh.exeInst_MaEPSBroker.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Network Command Shell
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\netsh.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\credui.dll
c:\windows\system32\user32.dll
820C:\Windows\IMGSF50Svc.exe -installC:\Windows\IMGSF50Svc.exemarkany_ImageSafer.exe
User:
admin
Company:
MarkAny
Integrity Level:
HIGH
Description:
Image SAFER 5.0 Session Managing Service for x86
Exit code:
0
Version:
5.0.21.1101
Modules
Images
c:\windows\imgsf50svc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
928"C:\Users\admin\AppData\Local\Temp\markany_ImageSafer.exe" /qC:\Users\admin\AppData\Local\Temp\markany_ImageSafer.exe
0503.exe
User:
admin
Company:
MarkAny Inc.
Integrity Level:
HIGH
Description:
MarkAny ImageSAFER 5.0 Installer
Exit code:
0
Version:
5.0.21.1101
Modules
Images
c:\users\admin\appdata\local\temp\markany_imagesafer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
1488"C:\Program Files\MarkAny\EPSBroker\cert\certutil.exe" -A -n "C:\Program Files\MarkAny\EPSBroker\cert\maca.crt" -i "C:\Program Files\MarkAny\EPSBroker\cert\maca.crt" -t "TCu,TCu,TCu" -d "sql:."C:\Program Files\MarkAny\EPSBroker\cert\certutil.exe
cmd.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\program files\markany\epsbroker\cert\certutil.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\markany\epsbroker\cert\nssutil3.dll
c:\program files\markany\epsbroker\cert\libplc4.dll
c:\program files\markany\epsbroker\cert\libnspr4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
1548"C:\Program Files\MarkAny\EPSBroker\MaEPSBroker.exe"C:\Program Files\MarkAny\EPSBroker\MaEPSBroker.exeInst_MaEPSBroker.exe
User:
admin
Company:
MarkAny Inc.
Integrity Level:
HIGH
Description:
MaEPSBroker
Version:
2, 5, 0, 43
Modules
Images
c:\program files\markany\epsbroker\maepsbroker.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wininet.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
1664"C:\Program Files\MarkAny\EPSBroker\BrokerCRIMGR.exe"C:\Program Files\MarkAny\EPSBroker\BrokerCRIMGR.exeInst_MaEPSBroker.exe
User:
admin
Company:
Markany Inc
Integrity Level:
HIGH
Description:
Broker CRI MGR Module
Exit code:
0
Version:
1.0.0.4
Modules
Images
c:\program files\markany\epsbroker\brokercrimgr.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msimg32.dll
1764"C:\Users\admin\AppData\Local\Temp\Inst_MaEPSBroker.exe" /qC:\Users\admin\AppData\Local\Temp\Inst_MaEPSBroker.exe
0503.exe
User:
admin
Company:
MarkAny Inc.
Integrity Level:
HIGH
Description:
MarkAny Broker Moudle
Exit code:
0
Version:
2.5.0.43
Modules
Images
c:\users\admin\appdata\local\temp\inst_maepsbroker.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
1876C:\Windows\IMGSF50Svc.exeC:\Windows\IMGSF50Svc.exeservices.exe
User:
SYSTEM
Company:
MarkAny
Integrity Level:
SYSTEM
Description:
Image SAFER 5.0 Session Managing Service for x86
Version:
5.0.21.1101
Modules
Images
c:\windows\imgsf50svc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
Total events
9 249
Read events
9 056
Write events
192
Delete events
1

Modification events

(PID) Process:(928) markany_ImageSafer.exeKey:HKEY_CURRENT_USER\Software\MarkAny\ImageSAFERv5\CaptureMsg
Operation:writeName:Msg
Value:
본 화면은 보안정책에 의해 보호되었습니다.
(PID) Process:(928) markany_ImageSafer.exeKey:HKEY_CURRENT_USER\Software\MarkAny\ImageSAFERv5\CaptureMsg
Operation:writeName:MsgPosition
Value:
1
(PID) Process:(928) markany_ImageSafer.exeKey:HKEY_CURRENT_USER\Software\MarkAny\ImageSAFERv5\CaptureMsg
Operation:writeName:MsgSize
Value:
32
(PID) Process:(928) markany_ImageSafer.exeKey:HKEY_CURRENT_USER\Software\MarkAny\ImageSAFERv5\CaptureMsg
Operation:writeName:OnFlag
Value:
0
(PID) Process:(928) markany_ImageSafer.exeKey:HKEY_CURRENT_USER\Software\MarkAny\ImageSAFERv5\CaptureMsg
Operation:writeName:Msg_KR
Value:
정보 유출 방지를 위해 화면 캡처 기능을 사용할 수 없습니다.
(PID) Process:(928) markany_ImageSafer.exeKey:HKEY_CURRENT_USER\Software\MarkAny\ImageSAFERv5\CaptureMsg
Operation:writeName:Msg_US
Value:
Screencapture is prohibited to prevent information leak.
(PID) Process:(928) markany_ImageSafer.exeKey:HKEY_CURRENT_USER\Software\MarkAny\ImageSAFERv5\CaptureMsg
Operation:writeName:Msg_GB
Value:
Screencapture is prohibited to prevent information leaks.
(PID) Process:(928) markany_ImageSafer.exeKey:HKEY_CURRENT_USER\Software\MarkAny\ImageSAFERv5\CaptureMsg
Operation:writeName:Msg_CN
Value:
禁止抓屏以防止信息泄露。
(PID) Process:(928) markany_ImageSafer.exeKey:HKEY_CURRENT_USER\Software\MarkAny\ImageSAFERv5\CaptureMsg
Operation:writeName:Msg_HK
Value:
禁止螢幕擷取是為預防資料外洩。
(PID) Process:(928) markany_ImageSafer.exeKey:HKEY_CURRENT_USER\Software\MarkAny\ImageSAFERv5\CaptureMsg
Operation:writeName:Msg_PT
Value:
A captura de ecra e proibida para evitar fuga de informacao.
Executable files
57
Suspicious files
7
Text files
11
Unknown types
4

Dropped files

PID
Process
Filename
Type
928markany_ImageSafer.exeC:\Users\admin\AppData\Local\Temp\nsv452A.tmp\nsProcess.dllexecutable
MD5:05450FACE243B3A7472407B999B03A72
SHA256:95FE9D92512FF2318CC2520311EF9145B2CEE01209AB0E1B6E45C7CE1D4D0E89
928markany_ImageSafer.exeC:\Windows\system32\ImageSAFERMessage.exeexecutable
MD5:1C16B1EF674CEDD715D3A65D9581FA8C
SHA256:88DD644CD20BFA195E75F691FA95453CA6367A1977844CC019125AD6BC8F20AB
40800503.exeC:\Users\admin\AppData\Local\Temp\markany_ImageSafer.exeexecutable
MD5:B67266AFBFE12EB465F014C09B562798
SHA256:5D594159E5D235C5C84076E4D5FD0EBCB5C8D13FC613B840ADD27301A75C96DB
928markany_ImageSafer.exeC:\Windows\ImageSAFERSvc.exeexecutable
MD5:3B2955AAC1D9FA353E2FE678EF0E1BE4
SHA256:4574FBDB2CD737EEA7299DC98653ED4ACB07D710100FFD573C1B6E570A1AABB4
928markany_ImageSafer.exeC:\Windows\system32\ImageSAFERDrv.sysexecutable
MD5:EE382BD478EEC57D3F3CFE0968CA70A3
SHA256:44A0318ADA722350325BAD7B1E05921C177804CB771C1F71ED76F99DF13AFC1C
928markany_ImageSafer.exeC:\Users\admin\AppData\Local\Temp\nsv452A.tmp\System.dllexecutable
MD5:564BB0373067E1785CBA7E4C24AAB4BF
SHA256:7A9DDEE34562CD3703F1502B5C70E99CD5BBA15DE2B6845A3555033D7F6CB2A5
928markany_ImageSafer.exeC:\Windows\system32\IMGSF50MGR.dllexecutable
MD5:D586668509CB2E5EB8C02AC759F34103
SHA256:7D5331EA969EC7DF7DC2A9E262AD2F37791E3B1013037B0E3F6FF7C9E52B56C9
928markany_ImageSafer.exeC:\Windows\system32\ImageSAFERStart_X86.exeexecutable
MD5:5F76943EA54A6970E32F56659382DEFF
SHA256:3AAAE78043C07A763020EFE6B5D5B5EAA20822F2D6815202EA60D6602F1320DA
928markany_ImageSafer.exeC:\Windows\system32\ImageSAFERLang.xmlxml
MD5:F3E93CED4621ADE06E32391019E169D6
SHA256:C913B94DFA14883461738F01330484A85D4C637795CEF5BC9B06796B263FC579
928markany_ImageSafer.exeC:\Windows\system32\ImgsfProcPolicyForExe.xmlbinary
MD5:14CA2DFC723A7C24FED0ECD97568F3F5
SHA256:CD13EBB19F879A350E37EDBF6BBB7A1DAC5EE030088B9707462701E9004FF4F4
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
224.0.0.252:5355
unknown
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
unknown

DNS requests

No data

Threats

No threats detected
Process
Message
0503.exe
bRet1 == [0]
0503.exe
bRet3 == [0]
0503.exe
!bRet5 == [1]
0503.exe
bRet4 == [0]
0503.exe
bRet2 == [0]
0503.exe
pStr == []
0503.exe
pStr == []
0503.exe
pStr == []
Inst_MaEPSBroker.exe
C:\Windows\system32\netsh advfirewall firewall delete rule name= "MaEPSBroker" program="C:\Program Files\MarkAny\EPSBroker\MaEPSBroker.exe"
Inst_MaEPSBroker.exe
C:\Windows\system32\netsh advfirewall firewall add rule name="MaEPSBroker" dir=in action=allow program="C:\Program Files\MarkAny\EPSBroker\MaEPSBroker.exe" protocol=TCP enable=yes