File name:

PSDCodec-Setup.exe

Full analysis: https://app.any.run/tasks/aae00645-0514-4fa0-a49e-a6f87e477570
Verdict: Malicious activity
Analysis date: November 23, 2023, 16:59:54
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

95BCAB1334E82B7E8CC8ADF91F69FF46

SHA1:

8A4060954768EE10855FB8BDB4A7F61FC20A0CB6

SHA256:

9BFE7142B2BE9D2CAE2DD2ABF9E9315D96CA3DC92DD7348D5B0B672DBD8B719D

SSDEEP:

49152:gYQvr5tMmrpOprgmoyy0mY+olABsAV+Vsd2umMxdnykY3MIrboA7xhIabvrKemrT:av4m9uDJycAB2Vs2umMxdyBpkyvIabvs

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • PSDCodec-Setup.exe (PID: 3128)
      • PSDCodec-Setup.exe (PID: 3500)
      • PSDCodec-Setup.tmp (PID: 3420)
      • msiexec.exe (PID: 3380)
    • Reads the value of a key from the registry (SCRIPT)

      • msiexec.exe (PID: 3536)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • PSDCodec-Setup.tmp (PID: 3420)
    • Reads the Windows owner or organization settings

      • PSDCodec-Setup.tmp (PID: 3420)
      • msiexec.exe (PID: 3380)
    • Executes as Windows Service

      • VSSVC.exe (PID: 3680)
    • Checks Windows Trust Settings

      • msiexec.exe (PID: 3380)
    • Creates FileSystem object to access computer's file system (SCRIPT)

      • msiexec.exe (PID: 3536)
  • INFO

    • Checks supported languages

      • PSDCodec-Setup.tmp (PID: 3432)
      • PSDCodec-Setup.exe (PID: 3128)
      • PSDCodec-Setup.exe (PID: 3500)
      • PSDCodec-Setup.tmp (PID: 3420)
      • msiexec.exe (PID: 3380)
      • msiexec.exe (PID: 3536)
      • MSIAA02.tmp (PID: 3588)
    • Reads the computer name

      • PSDCodec-Setup.tmp (PID: 3432)
      • PSDCodec-Setup.tmp (PID: 3420)
      • msiexec.exe (PID: 3380)
      • msiexec.exe (PID: 3536)
    • Create files in a temporary directory

      • PSDCodec-Setup.exe (PID: 3500)
      • PSDCodec-Setup.exe (PID: 3128)
      • PSDCodec-Setup.tmp (PID: 3420)
      • msiexec.exe (PID: 3380)
    • Creates files in the program directory

      • PSDCodec-Setup.tmp (PID: 3420)
    • Reads the machine GUID from the registry

      • msiexec.exe (PID: 3380)
      • msiexec.exe (PID: 3536)
    • Application launched itself

      • msiexec.exe (PID: 3380)
    • Reads Environment values

      • msiexec.exe (PID: 3536)
    • Starts application with an unusual extension

      • msiexec.exe (PID: 3380)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable Delphi generic (45.2)
.dll | Win32 Dynamic Link Library (generic) (20.9)
.exe | Win32 Executable (generic) (14.3)
.exe | Win16/32 Executable Delphi generic (6.6)
.exe | Generic Win/DOS Executable (6.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2014:07:09 09:58:13+02:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 65024
InitializedDataSize: 53248
UninitializedDataSize: -
EntryPoint: 0x113bc
OSVersion: 5
ImageVersion: 6
SubsystemVersion: 5
Subsystem: Windows GUI
FileVersionNumber: 1.7.0.0
ProductVersionNumber: 1.7.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: Ardfry Imaging, LLC
FileDescription: Ardfry PSD CODEC Setup
FileVersion: 1.7.0.0
LegalCopyright: Copyright © 2009-2017 Ardfry Imaging, LLC
ProductName: Ardfry PSD CODEC
ProductVersion: 1.7.0.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
48
Monitored processes
9
Malicious processes
5
Suspicious processes
1

Behavior graph

Click at the process to see the details
start psdcodec-setup.exe no specs psdcodec-setup.tmp no specs psdcodec-setup.exe psdcodec-setup.tmp no specs msiexec.exe no specs msiexec.exe no specs vssvc.exe no specs msiexec.exe no specs msiaa02.tmp no specs

Process information

PID
CMD
Path
Indicators
Parent process
3128"C:\Users\admin\AppData\Local\Temp\PSDCodec-Setup.exe" C:\Users\admin\AppData\Local\Temp\PSDCodec-Setup.exeexplorer.exe
User:
admin
Company:
Ardfry Imaging, LLC
Integrity Level:
MEDIUM
Description:
Ardfry PSD CODEC Setup
Exit code:
0
Version:
1.7.0.0
Modules
Images
c:\users\admin\appdata\local\temp\psdcodec-setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
3380C:\Windows\system32\msiexec.exe /VC:\Windows\System32\msiexec.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3420"C:\Users\admin\AppData\Local\Temp\is-9LSDQ.tmp\PSDCodec-Setup.tmp" /SL5="$70186,1188173,119296,C:\Users\admin\AppData\Local\Temp\PSDCodec-Setup.exe" /SPAWNWND=$501F6 /NOTIFYWND=$60134 C:\Users\admin\AppData\Local\Temp\is-9LSDQ.tmp\PSDCodec-Setup.tmpPSDCodec-Setup.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-9lsdq.tmp\psdcodec-setup.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
3432"C:\Users\admin\AppData\Local\Temp\is-IHFK9.tmp\PSDCodec-Setup.tmp" /SL5="$60134,1188173,119296,C:\Users\admin\AppData\Local\Temp\PSDCodec-Setup.exe" C:\Users\admin\AppData\Local\Temp\is-IHFK9.tmp\PSDCodec-Setup.tmpPSDCodec-Setup.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-ihfk9.tmp\psdcodec-setup.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
3500"C:\Users\admin\AppData\Local\Temp\PSDCodec-Setup.exe" /SPAWNWND=$501F6 /NOTIFYWND=$60134 C:\Users\admin\AppData\Local\Temp\PSDCodec-Setup.exe
PSDCodec-Setup.tmp
User:
admin
Company:
Ardfry Imaging, LLC
Integrity Level:
HIGH
Description:
Ardfry PSD CODEC Setup
Exit code:
0
Version:
1.7.0.0
Modules
Images
c:\users\admin\appdata\local\temp\psdcodec-setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
3536C:\Windows\system32\MsiExec.exe -Embedding DF9FE9DC7DC10FA47718F833C2ADA3F4 E Global\MSI0000C:\Windows\System32\msiexec.exemsiexec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3584"msiexec.exe" /qb! REBOOT=ReallySuppress /i "C:\Users\admin\AppData\Local\Temp\is-26TBH.tmp\ArdfryPSDCodec.msi" NOUNINSTALLSHORTCUT=1 ARPSYSTEMCOMPONENT=1C:\Windows\System32\msiexec.exePSDCodec-Setup.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Exit code:
3010
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3588"C:\Windows\Installer\MSIAA02.tmp"C:\Windows\Installer\MSIAA02.tmpmsiexec.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\windows\installer\msiaa02.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
3680C:\Windows\system32\vssvc.exeC:\Windows\System32\VSSVC.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Volume Shadow Copy Service
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\vssvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
6 553
Read events
6 505
Write events
32
Delete events
16

Modification events

(PID) Process:(3380) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SystemRestore
Operation:writeName:SrCreateRp (Enter)
Value:
4000000000000000F2B487BA16B0D901C80700002C0A0000D5070000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(3380) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
Operation:writeName:SppCreate (Enter)
Value:
4000000000000000F2B487BA16B0D901C80700002C0A0000D0070000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(3380) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP
Operation:writeName:LastIndex
Value:
72
(PID) Process:(3380) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
Operation:writeName:SppGatherWriterMetadata (Enter)
Value:
40000000000000008C62D6BA16B0D901C80700002C0A0000D3070000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(3380) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
Operation:writeName:SppGatherWriterMetadata (Leave)
Value:
400000000000000064514ABC16B0D901C80700002C0A0000D3070000010000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(3380) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
Operation:writeName:SppAddInterestingComponents (Enter)
Value:
400000000000000064514ABC16B0D901C80700002C0A0000D4070000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(3380) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
Operation:writeName:SppAddInterestingComponents (Leave)
Value:
400000000000000034645DBC16B0D901C80700002C0A0000D4070000010000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(3380) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
Operation:writeName:SppCreate (Leave)
Value:
4000000000000000781D5ABD16B0D901C80700002C0A0000D0070000010000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(3380) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SystemRestore
Operation:writeName:SrCreateRp (Leave)
Value:
4000000000000000781D5ABD16B0D901C80700002C0A0000D5070000010000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(3380) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore
Operation:writeName:FirstRun
Value:
0
Executable files
14
Suspicious files
14
Text files
2
Unknown types
0

Dropped files

PID
Process
Filename
Type
3380msiexec.exeC:\System Volume Information\SPP\metadata-2
MD5:
SHA256:
3500PSDCodec-Setup.exeC:\Users\admin\AppData\Local\Temp\is-9LSDQ.tmp\PSDCodec-Setup.tmpexecutable
MD5:3E6319E538E00B26EACFC555CEDE9232
SHA256:4FFC9FA2A8E61EF95030A2FDE7C74FF71A24BFC5E1F1229BA2647A0D00766AC6
3420PSDCodec-Setup.tmpC:\Program Files\ArdfryImaging\PSD Codec\unins000.datbinary
MD5:AD82F6AF09D07794819F56C8B6B3A4C8
SHA256:506A8F7D48E2C4827FDE879BBA4EB13FAC1DFCABF4964AE83F82A64F6106F5DF
3420PSDCodec-Setup.tmpC:\Users\admin\AppData\Local\Temp\is-26TBH.tmp\_isetup\_shfoldr.dllexecutable
MD5:92DC6EF532FBB4A5C3201469A5B5EB63
SHA256:9884E9D1B4F8A873CCBD81F8AD0AE257776D2348D027D811A56475E028360D87
3420PSDCodec-Setup.tmpC:\Viewers\ArdfryPSDDOPlugin.dllexecutable
MD5:1EFB7D5BE609CEB08AAF0CB47E3270F9
SHA256:58EE61E93B10FAE254BC83CC9AA2E2166F4B71BCB621638533DDB05E7DF2FC06
3420PSDCodec-Setup.tmpC:\Users\admin\AppData\Local\Temp\is-26TBH.tmp\ArdfryPSDCodec.msiexecutable
MD5:F1425965190B8408963130DB241B596F
SHA256:ACA8C60F362B471F7F1149AA68C89EFD5CDA5F425232B246611E213E83011567
3420PSDCodec-Setup.tmpC:\ProgramData\Microsoft\Windows\Start Menu\Programs\PSD Codec by Ardfry Imaging\Uninstall Ardfry PSD Codec.lnkbinary
MD5:18CEE58FE532BDA566835767C96E3F20
SHA256:2A1F1D9E6A7A836912A7ED825E6A0CD2E90F72F1D81EA25CD4181612E29A84D4
3420PSDCodec-Setup.tmpC:\Program Files\ArdfryImaging\PSD Codec\unins000.msgbinary
MD5:5F38274FC51EC35B61E925153E26EF1C
SHA256:946195C199C2F798ED0AB3DC8AE4511BE30AD70E5FB994D677BEEE0AE249DEC8
3420PSDCodec-Setup.tmpC:\Users\admin\AppData\Local\Temp\is-26TBH.tmp\is-O0SPG.tmpexecutable
MD5:F1425965190B8408963130DB241B596F
SHA256:ACA8C60F362B471F7F1149AA68C89EFD5CDA5F425232B246611E213E83011567
3380msiexec.exeC:\Windows\Installer\16a33a.msiexecutable
MD5:F1425965190B8408963130DB241B596F
SHA256:ACA8C60F362B471F7F1149AA68C89EFD5CDA5F425232B246611E213E83011567
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
unknown
2588
svchost.exe
239.255.255.250:1900
unknown
4
System
192.168.100.255:138
unknown
1080
svchost.exe
224.0.0.252:5355
unknown

DNS requests

No data

Threats

No threats detected
No debug info