| File name: | Scanalyzer 3.4.0.msi |
| Full analysis: | https://app.any.run/tasks/7686624c-730b-4594-8401-13028076e9d3 |
| Verdict: | Malicious activity |
| Analysis date: | February 27, 2024, 19:29:11 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-msi |
| File info: | Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, MSI Installer, Create Time/Date: Mon Jun 21 07:00:00 1999, Name of Creating Application: Windows Installer, Security: 1, Code page: 1252, Template: Intel;1033, Number of Pages: 200, Revision Number: {0F42A29C-D7C6-4EC4-A52A-48DB0F705012}, Title: Scanalyzer, Author: Datalogic USA, Inc., Comments: Scanner and scale configuration and firmware update utility., Number of Words: 2, Last Saved Time/Date: Mon Sep 19 05:27:17 2022, Last Printed: Mon Sep 19 05:27:17 2022 |
| MD5: | 0D919F30D71599204A7741D349F918AF |
| SHA1: | 3060464EF80DA4A7F01F4736591F3644511C1EBE |
| SHA256: | 8D4CAFE58702A60398F7AE32913AC42C789873A35A08E95C117AF041BE27C5E2 |
| SSDEEP: | 98304:ziRM4gyslkXOSaQlRkXGcCf7Hb5BjtmZ+NeCVU86tFZ/dmnZ6Tu62YBouUTcLoNj:84+x |
| .msi | | | Microsoft Windows Installer (81.9) |
|---|---|---|
| .mst | | | Windows SDK Setup Transform Script (9.2) |
| .msp | | | Windows Installer Patch (7.6) |
| .msi | | | Microsoft Installer (100) |
| CreateDate: | 1999:06:21 07:00:00 |
|---|---|
| Software: | Windows Installer |
| Security: | Password protected |
| CodePage: | Windows Latin 1 (Western European) |
| Template: | Intel;1033 |
| Pages: | 200 |
| RevisionNumber: | {0F42A29C-D7C6-4EC4-A52A-48DB0F705012} |
| Title: | Scanalyzer |
| Subject: | - |
| Author: | Datalogic USA, Inc. |
| Keywords: | - |
| Comments: | Scanner and scale configuration and firmware update utility. |
| Words: | 2 |
| ModifyDate: | 2022:09:19 05:27:17 |
| LastPrinted: | 2022:09:19 05:27:17 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 568 | "C:\Program Files\Datalogic\Scanalyzer\Scanalyzer.exe" | C:\Program Files\Datalogic\Scanalyzer\Scanalyzer.exe | explorer.exe | ||||||||||||
User: admin Company: Datalogic USA, Inc. Integrity Level: MEDIUM Description: Scanalyzer Exit code: 0 Version: 3.4.0 Modules
| |||||||||||||||
| 2060 | "C:\Program Files\Datalogic\Scanalyzer\Scanalyzer.exe" | C:\Program Files\Datalogic\Scanalyzer\Scanalyzer.exe | explorer.exe | ||||||||||||
User: admin Company: Datalogic USA, Inc. Integrity Level: MEDIUM Description: Scanalyzer Exit code: 3762507597 Version: 3.4.0 Modules
| |||||||||||||||
| 2320 | dw20.exe -x -s 1144 | C:\Windows\Microsoft.NET\Framework\v2.0.50727\dw20.exe | — | Scanalyzer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft .NET Error Reporting Shim Exit code: 0 Version: 2.0.50727.5483 (Win7SP1GDR.050727-5400) Modules
| |||||||||||||||
| 2832 | "C:\Program Files\Datalogic\Scanalyzer\Scanalyzer.exe" | C:\Program Files\Datalogic\Scanalyzer\Scanalyzer.exe | explorer.exe | ||||||||||||
User: admin Company: Datalogic USA, Inc. Integrity Level: MEDIUM Description: Scanalyzer Exit code: 0 Version: 3.4.0 Modules
| |||||||||||||||
| 3656 | "C:\Windows\System32\msiexec.exe" /i "C:\Users\admin\Desktop\Scanalyzer 3.4.0.msi" | C:\Windows\System32\msiexec.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3948 | C:\Windows\system32\vssvc.exe | C:\Windows\System32\VSSVC.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft® Volume Shadow Copy Service Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (3948) VSSVC.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 4000000000000000549E874BB369DA016C0F0000D4050000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3948) VSSVC.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\ASR Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 4000000000000000549E874BB369DA016C0F0000880D0000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3948) VSSVC.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 4000000000000000549E874BB369DA016C0F000078000000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3948) VSSVC.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 4000000000000000549E874BB369DA016C0F000060030000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3948) VSSVC.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer |
| Operation: | write | Name: | IDENTIFY (Leave) |
Value: 4000000000000000AE008A4BB369DA016C0F0000D4050000E8030000000000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3948) VSSVC.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer |
| Operation: | write | Name: | IDENTIFY (Leave) |
Value: 400000000000000008638C4BB369DA016C0F000078000000E8030000000000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3948) VSSVC.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer |
| Operation: | write | Name: | IDENTIFY (Leave) |
Value: 400000000000000008638C4BB369DA016C0F000060030000E8030000000000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3948) VSSVC.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\ASR Writer |
| Operation: | write | Name: | IDENTIFY (Leave) |
Value: 4000000000000000BC27914BB369DA016C0F0000880D0000E8030000000000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3948) VSSVC.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5} |
| Operation: | write | Name: | PROVIDER_BEGINPREPARE (Enter) |
Value: 4000000000000000A26A3D4EB369DA016C0F0000880D0000010400000100000000000000000000007F4C148246AC38498AC1FC7D5DF218530000000000000000 | |||
| (PID) Process: | (3948) VSSVC.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5} |
| Operation: | write | Name: | PROVIDER_BEGINPREPARE (Leave) |
Value: 4000000000000000FCCC3F4EB369DA016C0F0000880D0000010400000000000000000000000000007F4C148246AC38498AC1FC7D5DF218530000000000000000 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2320 | dw20.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_scanalyzer.exe_264badde8a3d59b5b640b3f34e75296f569bda29_0908ace5\Report.wer | — | |
MD5:— | SHA256:— | |||
| 2060 | Scanalyzer.exe | C:\USERS\ADMIN\APPDATA\ROAMING\LOGS\LOG9.LOG | text | |
MD5:E208E0AF018797BEC592C316FDAA4715 | SHA256:92A6893A03D1859A0A5EBB6B32841B61385895AD3D35FF7481E5078708CE784B | |||
| 3656 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\MSI9CF.tmp | executable | |
MD5:B77A2A2768B9CC78A71BBFFB9812B978 | SHA256:F74C97B1A53541B059D3BFAFE41A79005CE5065F8210D7DE9F1B600DC4E28AA0 | |||
| 3656 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\MSIA5C.tmp | executable | |
MD5:B77A2A2768B9CC78A71BBFFB9812B978 | SHA256:F74C97B1A53541B059D3BFAFE41A79005CE5065F8210D7DE9F1B600DC4E28AA0 | |||
| 2060 | Scanalyzer.exe | C:\Users\admin\AppData\Roaming\Logs\Scanalyzer Event Report.zip | compressed | |
MD5:BBD199DB70874EDA827B6BAD5FBBF70D | SHA256:6A7F0EA7AEE11F8F1213F100147D66E1AD00463A9005C7A35C4CB4DD6BACE9D0 | |||
| 568 | Scanalyzer.exe | C:\Users\admin\AppData\Roaming\MCF.CEZ | binary | |
MD5:14537B634DBA6954425B6A60A3CB1703 | SHA256:581F581149392BE9702573D529D059592C2B903691412588EBE724ABA47C5252 | |||
| 568 | Scanalyzer.exe | C:\USERS\ADMIN\APPDATA\ROAMING\LOGS\LOG2.LOG | text | |
MD5:EAE55A8105591C653D99C2AFCF7F2C7F | SHA256:D4103452F1AE3E8260D17C2AC91BD1B16C86B2EA83E962CB5468B033CF600FDA | |||
| 2060 | Scanalyzer.exe | C:\USERS\ADMIN\APPDATA\ROAMING\LOGS\LOG1.LOG | text | |
MD5:24713214E048A79826B064A37DB40210 | SHA256:65A7B8DE2A67B44ED945436175DBD6DBBE403EE8FF4E118571378FB0A551DE9B | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2832 | Scanalyzer.exe | GET | 200 | 207.109.248.140:80 | http://go.datalogic.com/get/scanalyzer/Scanalyzer_DATABASE_VERSION.txt | unknown | text | 16 b | unknown |
2060 | Scanalyzer.exe | GET | 200 | 207.109.248.140:80 | http://go.datalogic.com/get/scanalyzer/Scanalyzer_VERSION.txt | unknown | text | 16 b | unknown |
568 | Scanalyzer.exe | GET | 200 | 207.109.248.140:80 | http://go.datalogic.com/get/scanalyzer/Scanalyzer_DATABASE_VERSION.txt | unknown | text | 16 b | unknown |
2832 | Scanalyzer.exe | GET | 200 | 207.109.248.140:80 | http://go.datalogic.com/get/scanalyzer/Scanalyzer_VERSION.txt | unknown | text | 16 b | unknown |
2060 | Scanalyzer.exe | GET | 200 | 207.109.248.140:80 | http://go.datalogic.com/get/scanalyzer/Scanalyzer_DATABASE_VERSION.txt | unknown | text | 16 b | unknown |
2832 | Scanalyzer.exe | GET | — | 207.109.248.140:80 | http://go.datalogic.com/get/scanalyzer/Scanalyzer_MCF.cez | unknown | — | — | unknown |
568 | Scanalyzer.exe | GET | 200 | 207.109.248.140:80 | http://go.datalogic.com/get/scanalyzer/Scanalyzer_VERSION.txt | unknown | text | 16 b | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | unknown |
2832 | Scanalyzer.exe | 207.109.248.140:80 | go.datalogic.com | CENTURYLINK-US-LEGACY-QWEST | US | unknown |
2060 | Scanalyzer.exe | 207.109.248.140:80 | go.datalogic.com | CENTURYLINK-US-LEGACY-QWEST | US | unknown |
568 | Scanalyzer.exe | 207.109.248.140:80 | go.datalogic.com | CENTURYLINK-US-LEGACY-QWEST | US | unknown |
Domain | IP | Reputation |
|---|---|---|
go.datalogic.com |
| unknown |