File name:

Scanalyzer 3.4.0.msi

Full analysis: https://app.any.run/tasks/7686624c-730b-4594-8401-13028076e9d3
Verdict: Malicious activity
Analysis date: February 27, 2024, 19:29:11
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-msi
File info: Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, MSI Installer, Create Time/Date: Mon Jun 21 07:00:00 1999, Name of Creating Application: Windows Installer, Security: 1, Code page: 1252, Template: Intel;1033, Number of Pages: 200, Revision Number: {0F42A29C-D7C6-4EC4-A52A-48DB0F705012}, Title: Scanalyzer, Author: Datalogic USA, Inc., Comments: Scanner and scale configuration and firmware update utility., Number of Words: 2, Last Saved Time/Date: Mon Sep 19 05:27:17 2022, Last Printed: Mon Sep 19 05:27:17 2022
MD5:

0D919F30D71599204A7741D349F918AF

SHA1:

3060464EF80DA4A7F01F4736591F3644511C1EBE

SHA256:

8D4CAFE58702A60398F7AE32913AC42C789873A35A08E95C117AF041BE27C5E2

SSDEEP:

98304:ziRM4gyslkXOSaQlRkXGcCf7Hb5BjtmZ+NeCVU86tFZ/dmnZ6Tu62YBouUTcLoNj:84+x

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • msiexec.exe (PID: 3656)
  • SUSPICIOUS

    • Executes as Windows Service

      • VSSVC.exe (PID: 3948)
    • Reads the Internet Settings

      • Scanalyzer.exe (PID: 2832)
      • Scanalyzer.exe (PID: 2060)
      • Scanalyzer.exe (PID: 568)
    • Process drops legitimate windows executable

      • msiexec.exe (PID: 3656)
  • INFO

    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 3656)
    • Checks proxy server information

      • Scanalyzer.exe (PID: 2832)
      • Scanalyzer.exe (PID: 2060)
      • Scanalyzer.exe (PID: 568)
    • Reads the computer name

      • Scanalyzer.exe (PID: 2060)
      • Scanalyzer.exe (PID: 2832)
      • dw20.exe (PID: 2320)
      • Scanalyzer.exe (PID: 568)
    • Manual execution by a user

      • Scanalyzer.exe (PID: 2060)
      • Scanalyzer.exe (PID: 568)
      • Scanalyzer.exe (PID: 2832)
    • Checks supported languages

      • Scanalyzer.exe (PID: 2060)
      • dw20.exe (PID: 2320)
      • Scanalyzer.exe (PID: 568)
      • Scanalyzer.exe (PID: 2832)
    • Creates files or folders in the user directory

      • Scanalyzer.exe (PID: 2832)
      • Scanalyzer.exe (PID: 2060)
      • dw20.exe (PID: 2320)
      • Scanalyzer.exe (PID: 568)
    • Reads the machine GUID from the registry

      • Scanalyzer.exe (PID: 2832)
      • Scanalyzer.exe (PID: 2060)
      • dw20.exe (PID: 2320)
      • Scanalyzer.exe (PID: 568)
    • Reads Environment values

      • Scanalyzer.exe (PID: 2832)
      • Scanalyzer.exe (PID: 2060)
      • Scanalyzer.exe (PID: 568)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.msi | Microsoft Windows Installer (81.9)
.mst | Windows SDK Setup Transform Script (9.2)
.msp | Windows Installer Patch (7.6)
.msi | Microsoft Installer (100)

EXIF

FlashPix

CreateDate: 1999:06:21 07:00:00
Software: Windows Installer
Security: Password protected
CodePage: Windows Latin 1 (Western European)
Template: Intel;1033
Pages: 200
RevisionNumber: {0F42A29C-D7C6-4EC4-A52A-48DB0F705012}
Title: Scanalyzer
Subject: -
Author: Datalogic USA, Inc.
Keywords: -
Comments: Scanner and scale configuration and firmware update utility.
Words: 2
ModifyDate: 2022:09:19 05:27:17
LastPrinted: 2022:09:19 05:27:17
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
45
Monitored processes
6
Malicious processes
0
Suspicious processes
4

Behavior graph

Click at the process to see the details
start msiexec.exe vssvc.exe no specs scanalyzer.exe scanalyzer.exe dw20.exe no specs scanalyzer.exe

Process information

PID
CMD
Path
Indicators
Parent process
568"C:\Program Files\Datalogic\Scanalyzer\Scanalyzer.exe" C:\Program Files\Datalogic\Scanalyzer\Scanalyzer.exe
explorer.exe
User:
admin
Company:
Datalogic USA, Inc.
Integrity Level:
MEDIUM
Description:
Scanalyzer
Exit code:
0
Version:
3.4.0
Modules
Images
c:\program files\datalogic\scanalyzer\scanalyzer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2060"C:\Program Files\Datalogic\Scanalyzer\Scanalyzer.exe" C:\Program Files\Datalogic\Scanalyzer\Scanalyzer.exe
explorer.exe
User:
admin
Company:
Datalogic USA, Inc.
Integrity Level:
MEDIUM
Description:
Scanalyzer
Exit code:
3762507597
Version:
3.4.0
Modules
Images
c:\program files\datalogic\scanalyzer\scanalyzer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2320dw20.exe -x -s 1144C:\Windows\Microsoft.NET\Framework\v2.0.50727\dw20.exeScanalyzer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft .NET Error Reporting Shim
Exit code:
0
Version:
2.0.50727.5483 (Win7SP1GDR.050727-5400)
Modules
Images
c:\windows\microsoft.net\framework\v2.0.50727\dw20.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc\msvcr80.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
2832"C:\Program Files\Datalogic\Scanalyzer\Scanalyzer.exe" C:\Program Files\Datalogic\Scanalyzer\Scanalyzer.exe
explorer.exe
User:
admin
Company:
Datalogic USA, Inc.
Integrity Level:
MEDIUM
Description:
Scanalyzer
Exit code:
0
Version:
3.4.0
Modules
Images
c:\program files\datalogic\scanalyzer\scanalyzer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3656"C:\Windows\System32\msiexec.exe" /i "C:\Users\admin\Desktop\Scanalyzer 3.4.0.msi"C:\Windows\System32\msiexec.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3948C:\Windows\system32\vssvc.exeC:\Windows\System32\VSSVC.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Volume Shadow Copy Service
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\vssvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
5 464
Read events
5 303
Write events
149
Delete events
12

Modification events

(PID) Process:(3948) VSSVC.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
Operation:writeName:IDENTIFY (Enter)
Value:
4000000000000000549E874BB369DA016C0F0000D4050000E8030000010000000100000000000000000000000000000000000000000000000000000000000000
(PID) Process:(3948) VSSVC.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\ASR Writer
Operation:writeName:IDENTIFY (Enter)
Value:
4000000000000000549E874BB369DA016C0F0000880D0000E8030000010000000100000000000000000000000000000000000000000000000000000000000000
(PID) Process:(3948) VSSVC.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
Operation:writeName:IDENTIFY (Enter)
Value:
4000000000000000549E874BB369DA016C0F000078000000E8030000010000000100000000000000000000000000000000000000000000000000000000000000
(PID) Process:(3948) VSSVC.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
Operation:writeName:IDENTIFY (Enter)
Value:
4000000000000000549E874BB369DA016C0F000060030000E8030000010000000100000000000000000000000000000000000000000000000000000000000000
(PID) Process:(3948) VSSVC.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
Operation:writeName:IDENTIFY (Leave)
Value:
4000000000000000AE008A4BB369DA016C0F0000D4050000E8030000000000000100000000000000000000000000000000000000000000000000000000000000
(PID) Process:(3948) VSSVC.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
Operation:writeName:IDENTIFY (Leave)
Value:
400000000000000008638C4BB369DA016C0F000078000000E8030000000000000100000000000000000000000000000000000000000000000000000000000000
(PID) Process:(3948) VSSVC.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
Operation:writeName:IDENTIFY (Leave)
Value:
400000000000000008638C4BB369DA016C0F000060030000E8030000000000000100000000000000000000000000000000000000000000000000000000000000
(PID) Process:(3948) VSSVC.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\ASR Writer
Operation:writeName:IDENTIFY (Leave)
Value:
4000000000000000BC27914BB369DA016C0F0000880D0000E8030000000000000100000000000000000000000000000000000000000000000000000000000000
(PID) Process:(3948) VSSVC.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
Operation:writeName:PROVIDER_BEGINPREPARE (Enter)
Value:
4000000000000000A26A3D4EB369DA016C0F0000880D0000010400000100000000000000000000007F4C148246AC38498AC1FC7D5DF218530000000000000000
(PID) Process:(3948) VSSVC.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
Operation:writeName:PROVIDER_BEGINPREPARE (Leave)
Value:
4000000000000000FCCC3F4EB369DA016C0F0000880D0000010400000000000000000000000000007F4C148246AC38498AC1FC7D5DF218530000000000000000
Executable files
2
Suspicious files
1
Text files
3
Unknown types
1

Dropped files

PID
Process
Filename
Type
2320dw20.exeC:\Users\admin\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_scanalyzer.exe_264badde8a3d59b5b640b3f34e75296f569bda29_0908ace5\Report.wer
MD5:
SHA256:
2060Scanalyzer.exeC:\USERS\ADMIN\APPDATA\ROAMING\LOGS\LOG9.LOGtext
MD5:E208E0AF018797BEC592C316FDAA4715
SHA256:92A6893A03D1859A0A5EBB6B32841B61385895AD3D35FF7481E5078708CE784B
3656msiexec.exeC:\Users\admin\AppData\Local\Temp\MSI9CF.tmpexecutable
MD5:B77A2A2768B9CC78A71BBFFB9812B978
SHA256:F74C97B1A53541B059D3BFAFE41A79005CE5065F8210D7DE9F1B600DC4E28AA0
3656msiexec.exeC:\Users\admin\AppData\Local\Temp\MSIA5C.tmpexecutable
MD5:B77A2A2768B9CC78A71BBFFB9812B978
SHA256:F74C97B1A53541B059D3BFAFE41A79005CE5065F8210D7DE9F1B600DC4E28AA0
2060Scanalyzer.exeC:\Users\admin\AppData\Roaming\Logs\Scanalyzer Event Report.zipcompressed
MD5:BBD199DB70874EDA827B6BAD5FBBF70D
SHA256:6A7F0EA7AEE11F8F1213F100147D66E1AD00463A9005C7A35C4CB4DD6BACE9D0
568Scanalyzer.exeC:\Users\admin\AppData\Roaming\MCF.CEZbinary
MD5:14537B634DBA6954425B6A60A3CB1703
SHA256:581F581149392BE9702573D529D059592C2B903691412588EBE724ABA47C5252
568Scanalyzer.exeC:\USERS\ADMIN\APPDATA\ROAMING\LOGS\LOG2.LOGtext
MD5:EAE55A8105591C653D99C2AFCF7F2C7F
SHA256:D4103452F1AE3E8260D17C2AC91BD1B16C86B2EA83E962CB5468B033CF600FDA
2060Scanalyzer.exeC:\USERS\ADMIN\APPDATA\ROAMING\LOGS\LOG1.LOGtext
MD5:24713214E048A79826B064A37DB40210
SHA256:65A7B8DE2A67B44ED945436175DBD6DBBE403EE8FF4E118571378FB0A551DE9B
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
5
DNS requests
1
Threats
3

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2832
Scanalyzer.exe
GET
200
207.109.248.140:80
http://go.datalogic.com/get/scanalyzer/Scanalyzer_DATABASE_VERSION.txt
unknown
text
16 b
unknown
2060
Scanalyzer.exe
GET
200
207.109.248.140:80
http://go.datalogic.com/get/scanalyzer/Scanalyzer_VERSION.txt
unknown
text
16 b
unknown
568
Scanalyzer.exe
GET
200
207.109.248.140:80
http://go.datalogic.com/get/scanalyzer/Scanalyzer_DATABASE_VERSION.txt
unknown
text
16 b
unknown
2832
Scanalyzer.exe
GET
200
207.109.248.140:80
http://go.datalogic.com/get/scanalyzer/Scanalyzer_VERSION.txt
unknown
text
16 b
unknown
2060
Scanalyzer.exe
GET
200
207.109.248.140:80
http://go.datalogic.com/get/scanalyzer/Scanalyzer_DATABASE_VERSION.txt
unknown
text
16 b
unknown
2832
Scanalyzer.exe
GET
207.109.248.140:80
http://go.datalogic.com/get/scanalyzer/Scanalyzer_MCF.cez
unknown
unknown
568
Scanalyzer.exe
GET
200
207.109.248.140:80
http://go.datalogic.com/get/scanalyzer/Scanalyzer_VERSION.txt
unknown
text
16 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
unknown
2832
Scanalyzer.exe
207.109.248.140:80
go.datalogic.com
CENTURYLINK-US-LEGACY-QWEST
US
unknown
2060
Scanalyzer.exe
207.109.248.140:80
go.datalogic.com
CENTURYLINK-US-LEGACY-QWEST
US
unknown
568
Scanalyzer.exe
207.109.248.140:80
go.datalogic.com
CENTURYLINK-US-LEGACY-QWEST
US
unknown

DNS requests

Domain
IP
Reputation
go.datalogic.com
  • 207.109.248.140
unknown

Threats

Found threats are available for the paid subscriptions
3 ETPRO signatures available at the full report
No debug info