File name:

DocklightSetup.exe

Full analysis: https://app.any.run/tasks/37935246-c70a-4082-8087-6a48f1aa51ad
Verdict: Malicious activity
Analysis date: March 25, 2024, 02:23:37
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

5F8A28180EA379276237BD297970E7BC

SHA1:

EB79CE44E870962C98BBBE34A7674CA4619D1B11

SHA256:

9499C46B108D1A09951D59F2BB6ADF54C3B7B0998E52B5FE9F52AAA68D2D24EF

SSDEEP:

98304:e+QqZ8fUbomm5uByoBEakK+YrgTR/3tssf3nccZpHL23It8KoNyKwhW/Fe3iWlvx:lMqysQKbvEJBi

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • DocklightSetup.exe (PID: 1692)
      • DocklightSetup.exe (PID: 2960)
      • DocklightSetup.tmp (PID: 2440)
    • Creates a writable file in the system directory

      • DocklightSetup.tmp (PID: 2440)
    • Registers / Runs the DLL via REGSVR32.EXE

      • DocklightSetup.tmp (PID: 2440)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • DocklightSetup.exe (PID: 2960)
      • DocklightSetup.tmp (PID: 2440)
      • DocklightSetup.exe (PID: 1692)
    • Reads the Windows owner or organization settings

      • DocklightSetup.tmp (PID: 2440)
    • Creates/Modifies COM task schedule object

      • regsvr32.exe (PID: 2432)
      • regsvr32.exe (PID: 1888)
      • regsvr32.exe (PID: 2832)
      • regsvr32.exe (PID: 3912)
      • regsvr32.exe (PID: 1900)
      • regsvr32.exe (PID: 1352)
      • regsvr32.exe (PID: 1808)
      • regsvr32.exe (PID: 2564)
      • regsvr32.exe (PID: 1576)
    • Non-standard symbols in registry

      • DocklightSetup.tmp (PID: 2440)
    • Process drops legitimate windows executable

      • DocklightSetup.tmp (PID: 2440)
  • INFO

    • Checks supported languages

      • DocklightSetup.exe (PID: 2960)
      • DocklightSetup.exe (PID: 1692)
      • DocklightSetup.tmp (PID: 2692)
      • DocklightSetup.tmp (PID: 2440)
      • Docklight.exe (PID: 1844)
      • DocklightCommServer_v2_4.exe (PID: 1368)
    • Reads the computer name

      • DocklightSetup.tmp (PID: 2692)
      • DocklightSetup.tmp (PID: 2440)
      • DocklightCommServer_v2_4.exe (PID: 1368)
      • Docklight.exe (PID: 1844)
    • Create files in a temporary directory

      • DocklightSetup.exe (PID: 2960)
      • DocklightSetup.exe (PID: 1692)
      • DocklightSetup.tmp (PID: 2440)
      • Docklight.exe (PID: 1844)
    • Creates files in the program directory

      • DocklightSetup.tmp (PID: 2440)
    • Reads mouse settings

      • Docklight.exe (PID: 1844)
      • regsvr32.exe (PID: 2432)
    • Reads the machine GUID from the registry

      • Docklight.exe (PID: 1844)
    • Reads Microsoft Office registry keys

      • Docklight.exe (PID: 1844)
    • Creates a software uninstall entry

      • DocklightSetup.tmp (PID: 2440)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (53.5)
.exe | InstallShield setup (21)
.exe | Win32 EXE PECompact compressed (generic) (20.2)
.exe | Win32 Executable (generic) (2.1)
.exe | Win16/32 Executable Delphi generic (1)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2021:06:03 08:09:11+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 741376
InitializedDataSize: 89088
UninitializedDataSize: -
EntryPoint: 0xb5eec
OSVersion: 6.1
ImageVersion: 6
SubsystemVersion: 6.1
Subsystem: Windows GUI
FileVersionNumber: 2.4.0.8
ProductVersionNumber: 2.4.0.8
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: Flachmann und Heggelbacher / Kickdrive
FileDescription: Docklight Setup
FileVersion: 2.4.0.8
LegalCopyright: Copyright 2002-2023 www.fuh-edv.de and www.kickdrive.de
OriginalFileName:
ProductName: Docklight
ProductVersion: 2.4.11
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
55
Monitored processes
15
Malicious processes
5
Suspicious processes
1

Behavior graph

Click at the process to see the details
start docklightsetup.exe docklightsetup.tmp no specs docklightsetup.exe docklightsetup.tmp regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs docklightcommserver_v2_4.exe no specs docklight.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1352"C:\Windows\system32\regsvr32.exe" /s "C:\Program Files\Common Files\FuH\Docklight\DocklightReceiveSeqList_v2_3.ocx"C:\Windows\System32\regsvr32.exeDocklightSetup.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1368"C:\Program Files\FuH\Docklight V2.4\DocklightCommServer_v2_4.exe" /REGSERVERC:\Program Files\FuH\Docklight V2.4\DocklightCommServer_v2_4.exeDocklightSetup.tmp
User:
admin
Company:
Flachmann und Heggelbacher GmbH & Co.KG / Kickdrive Software Solutions
Integrity Level:
HIGH
Description:
Docklight Communication Server
Exit code:
0
Version:
2.04.0004
Modules
Images
c:\program files\fuh\docklight v2.4\docklightcommserver_v2_4.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvbvm60.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
1576"C:\Windows\system32\regsvr32.exe" /s "C:\Windows\system32\MSWINSCK.OCX"C:\Windows\System32\regsvr32.exeDocklightSetup.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1692"C:\Users\admin\Desktop\DocklightSetup.exe" C:\Users\admin\Desktop\DocklightSetup.exe
explorer.exe
User:
admin
Company:
Flachmann und Heggelbacher / Kickdrive
Integrity Level:
MEDIUM
Description:
Docklight Setup
Exit code:
0
Version:
2.4.0.8
Modules
Images
c:\users\admin\desktop\docklightsetup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1808"C:\Windows\system32\regsvr32.exe" /s "C:\Program Files\Common Files\FuH\Docklight\DocklightEditSequence_v2_3.ocx"C:\Windows\System32\regsvr32.exeDocklightSetup.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1844"C:\Program Files\FuH\Docklight V2.4\Docklight.exe"C:\Program Files\FuH\Docklight V2.4\Docklight.exeDocklightSetup.tmp
User:
admin
Company:
Flachmann und Heggelbacher GmbH & Co.KG / Kickdrive Software Solutions
Integrity Level:
MEDIUM
Version:
2.04.0011
Modules
Images
c:\program files\fuh\docklight v2.4\docklight.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvbvm60.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
1888"C:\Windows\system32\regsvr32.exe" /s "C:\Windows\system32\MSSTDFMT.DLL"C:\Windows\System32\regsvr32.exeDocklightSetup.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1900"C:\Windows\system32\regsvr32.exe" /s "C:\Program Files\Common Files\FuH\Docklight\DocklightSendSeqList_v2_3.ocx"C:\Windows\System32\regsvr32.exeDocklightSetup.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2432"C:\Windows\system32\regsvr32.exe" /s "C:\Windows\system32\MSCOMCTL.OCX"C:\Windows\System32\regsvr32.exeDocklightSetup.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2440"C:\Users\admin\AppData\Local\Temp\is-7H5RE.tmp\DocklightSetup.tmp" /SL5="$140158,5620607,831488,C:\Users\admin\Desktop\DocklightSetup.exe" /SPAWNWND=$130180 /NOTIFYWND=$B017E C:\Users\admin\AppData\Local\Temp\is-7H5RE.tmp\DocklightSetup.tmp
DocklightSetup.exe
User:
admin
Company:
Flachmann und Heggelbacher / Kickdrive
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-7h5re.tmp\docklightsetup.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
Total events
4 091
Read events
3 732
Write events
209
Delete events
150

Modification events

(PID) Process:(2440) DocklightSetup.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
8809000018787C795B7EDA01
(PID) Process:(2440) DocklightSetup.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:SessionHash
Value:
3B7708F47D0EFDDFF49DA7ECEE5284C8C86FEAE56021ED5DC05DC8681F419223
(PID) Process:(2440) DocklightSetup.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Sequence
Value:
1
(PID) Process:(2440) DocklightSetup.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:RegFiles0000
Value:
C:\Windows\system32\MSSTDFMT.DLL
(PID) Process:(2440) DocklightSetup.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:RegFilesHash
Value:
FD219E706B7E4AFCB56143AE0666B636CBDA9795CEBCFCE5D9A6CDEB9FBBF810
(PID) Process:(2440) DocklightSetup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
Operation:writeName:C:\Windows\system32\MSSTDFMT.DLL
Value:
1
(PID) Process:(2440) DocklightSetup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
Operation:writeName:C:\Windows\system32\RICHTX32.OCX
Value:
1
(PID) Process:(2440) DocklightSetup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
Operation:writeName:C:\Windows\system32\MSFLXGRD.OCX
Value:
1
(PID) Process:(2440) DocklightSetup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
Operation:writeName:C:\Windows\system32\MSCOMCTL.OCX
Value:
2
(PID) Process:(2440) DocklightSetup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
Operation:writeName:C:\Windows\system32\COMDLG32.OCX
Value:
1
Executable files
31
Suspicious files
7
Text files
45
Unknown types
5

Dropped files

PID
Process
Filename
Type
2440DocklightSetup.tmpC:\Users\admin\AppData\Local\Temp\is-F1JQN.tmp\_isetup\_isdecmp.dllexecutable
MD5:C6AE924AD02500284F7E4EFA11FA7CFC
SHA256:31D04C1E4BFDFA34704C142FA98F80C0A3076E4B312D6ADA57C4BE9D9C7DCF26
2440DocklightSetup.tmpC:\Windows\System32\MSWINSCK.OCXexecutable
MD5:57325D394119DB3D3B3CF8A3BBFDA5CA
SHA256:B66E17E0D7BBFE4F6BE537C544083E844B5DD0EBC660910BFF17AD6CD5480971
2440DocklightSetup.tmpC:\Windows\System32\MSSTDFMT.DLLexecutable
MD5:B5A99B3B3ADCA9F5457955FE2D5321C9
SHA256:BEC5D1F842BCC50DBC932CC7B05835DC4D9C01D696FBC27EEF52ADF85B3267E1
2440DocklightSetup.tmpC:\Program Files\FuH\Docklight V2.4\is-81ME9.tmpexecutable
MD5:25779D9F808C047534D67AD5C489D0BF
SHA256:2D4960C165904A24123EB17369D0A94F192F35E3B168753ABC1CCA2D20390FDE
2440DocklightSetup.tmpC:\Windows\system32\is-8FRN0.tmpexecutable
MD5:9A4D0F97F0D84F877B388D4A12D90B6B
SHA256:2206E0F530032CB55E1FA00FDFB0C2D71D5B09B1F969089FB8F651FCD2489E6A
2440DocklightSetup.tmpC:\Windows\system32\is-L7JL0.tmpexecutable
MD5:14BB5CF93C7D69D019423C73C60AA856
SHA256:221B54AD16161B8CE71807B07559AB49F59DFFF4CDF695E808D90BF8BEAAFCF5
2440DocklightSetup.tmpC:\Program Files\FuH\Docklight V2.4\unins000.exeexecutable
MD5:25779D9F808C047534D67AD5C489D0BF
SHA256:2D4960C165904A24123EB17369D0A94F192F35E3B168753ABC1CCA2D20390FDE
2440DocklightSetup.tmpC:\Windows\System32\MSFLXGRD.OCXexecutable
MD5:20E06689D038E05795863694B5E1DCD7
SHA256:7827DBDBD340CEE846A61238002E5D438B859C06C80E540F29130CE654CC0918
2960DocklightSetup.exeC:\Users\admin\AppData\Local\Temp\is-7H5RE.tmp\DocklightSetup.tmpexecutable
MD5:25779D9F808C047534D67AD5C489D0BF
SHA256:2D4960C165904A24123EB17369D0A94F192F35E3B168753ABC1CCA2D20390FDE
2440DocklightSetup.tmpC:\Windows\System32\MSCOMCTL.OCXexecutable
MD5:273676426739B02A45A0FC9349500B65
SHA256:152121A5D1AC8F12002C18AFC294BB1EBCECC1D61DEEC6211DF586C11ACDE9B6
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
2
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
unknown
4
System
192.168.100.255:138
whitelisted

DNS requests

No data

Threats

No threats detected
No debug info