File name:

TMACv6.0.7_Setup.exe

Full analysis: https://app.any.run/tasks/99bc0c00-397a-4823-a481-7fb0107fc33a
Verdict: Malicious activity
Analysis date: February 25, 2024, 03:27:32
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

A7C8CF1D50EBE630A7D0C47686A0ABBF

SHA1:

3229E8080975F4F5512D2382552F68C0389ACFF5

SHA256:

A453B3EA8D8133531FAD26B18701C694C324CC201E3069D07E99F0E100908C1A

SSDEEP:

98304:ARU3j4wtopcj2dqCYV1coZ4hv3tmF1b6CrjfW/sfH6s7zQcKDsVv/JLSF66b/:ARqt/CdqRc64hv3tmF1b6CffW/sfH6sm

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • rundll32.exe (PID: 3864)
      • TMACv6.0.7_Setup.exe (PID: 3460)
    • Registers / Runs the DLL via REGSVR32.EXE

      • TMACv6.0.7_Setup.exe (PID: 3460)
    • Creates a writable file in the system directory

      • TMACv6.0.7_Setup.exe (PID: 3460)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • TMACv6.0.7_Setup.exe (PID: 3460)
    • Process drops legitimate windows executable

      • TMACv6.0.7_Setup.exe (PID: 3460)
    • Creates/Modifies COM task schedule object

      • regsvr32.exe (PID: 120)
      • regsvr32.exe (PID: 3956)
    • Creates a software uninstall entry

      • TMACv6.0.7_Setup.exe (PID: 3460)
    • Reads the Internet Settings

      • TMAC.exe (PID: 2408)
      • TMAC.exe (PID: 1656)
    • Reads security settings of Internet Explorer

      • TMAC.exe (PID: 2408)
    • Application launched itself

      • TMAC.exe (PID: 2408)
    • Reads settings of System Certificates

      • TMAC.exe (PID: 1656)
    • Adds/modifies Windows certificates

      • TMAC.exe (PID: 1656)
  • INFO

    • Manual execution by a user

      • TMACv6.0.7_Setup.exe (PID: 3460)
      • TMACv6.0.7_Setup.exe (PID: 3716)
      • TMAC.exe (PID: 2408)
    • Checks supported languages

      • TMACv6.0.7_Setup.exe (PID: 3460)
      • TMAC.exe (PID: 2408)
      • TMAC.exe (PID: 1656)
    • Reads the machine GUID from the registry

      • TMACv6.0.7_Setup.exe (PID: 3460)
      • TMAC.exe (PID: 1656)
    • Reads Microsoft Office registry keys

      • TMACv6.0.7_Setup.exe (PID: 3460)
      • TMAC.exe (PID: 1656)
    • Create files in a temporary directory

      • TMACv6.0.7_Setup.exe (PID: 3460)
      • TMAC.exe (PID: 1656)
    • Reads mouse settings

      • TMACv6.0.7_Setup.exe (PID: 3460)
      • TMAC.exe (PID: 1656)
    • Reads the computer name

      • TMACv6.0.7_Setup.exe (PID: 3460)
      • TMAC.exe (PID: 2408)
      • TMAC.exe (PID: 1656)
    • Creates files in the program directory

      • TMACv6.0.7_Setup.exe (PID: 3460)
      • TMAC.exe (PID: 1656)
    • Checks proxy server information

      • TMAC.exe (PID: 1656)
    • Reads the time zone

      • TMAC.exe (PID: 1656)
    • Reads the software policy settings

      • TMAC.exe (PID: 1656)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.ax | DirectShow filter (37.9)
.exe | Win32 Executable Microsoft Visual Basic 6 (15.4)
.exe | InstallShield setup (8.1)
.exe | Win32 EXE PECompact compressed (generic) (7.8)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2012:01:01 19:37:01+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 167936
InitializedDataSize: 20480
UninitializedDataSize: -
EntryPoint: 0x21a8
OSVersion: 4
ImageVersion: 4.4
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 4.4.0.0
ProductVersionNumber: 4.4.0.0
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
Comments: Technitium Installer v4.4. Visit us at www.technitium.com
CompanyName: Technitium
FileDescription: Technitium Installer v4.4
ProductName: Technitium Installer v4.4
FileVersion: 4.04
ProductVersion: 4.04
InternalName: Installer
OriginalFileName: Installer.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
51
Monitored processes
8
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start rundll32.exe no specs tmacv6.0.7_setup.exe no specs tmacv6.0.7_setup.exe regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs tmac.exe no specs tmac.exe

Process information

PID
CMD
Path
Indicators
Parent process
120regsvr32 /s "C:\Windows\system32\COMDLG32.OCX"C:\Windows\System32\regsvr32.exeTMACv6.0.7_Setup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1656"C:\Program Files\Technitium\TMACv6.0\TMAC.exe" C:\Program Files\Technitium\TMACv6.0\TMAC.exe
TMAC.exe
User:
admin
Company:
Technitium
Integrity Level:
HIGH
Description:
Technitium MAC Address Changer
Exit code:
0
Version:
6.00.0007
Modules
Images
c:\program files\technitium\tmacv6.0\tmac.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvbvm60.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
2120regsvr32 /s "C:\Windows\system32\MSCHRT20.OCX"C:\Windows\System32\regsvr32.exeTMACv6.0.7_Setup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2408"C:\Program Files\Technitium\TMACv6.0\TMAC.exe" C:\Program Files\Technitium\TMACv6.0\TMAC.exeexplorer.exe
User:
admin
Company:
Technitium
Integrity Level:
MEDIUM
Description:
Technitium MAC Address Changer
Exit code:
0
Version:
6.00.0007
Modules
Images
c:\program files\technitium\tmacv6.0\tmac.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvbvm60.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
3460"C:\Users\admin\Desktop\TMACv6.0.7_Setup.exe" C:\Users\admin\Desktop\TMACv6.0.7_Setup.exe
explorer.exe
User:
admin
Company:
Technitium
Integrity Level:
HIGH
Description:
Technitium Installer v4.4
Exit code:
0
Version:
4.04
Modules
Images
c:\users\admin\desktop\tmacv6.0.7_setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvbvm60.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
3716"C:\Users\admin\Desktop\TMACv6.0.7_Setup.exe" C:\Users\admin\Desktop\TMACv6.0.7_Setup.exeexplorer.exe
User:
admin
Company:
Technitium
Integrity Level:
MEDIUM
Description:
Technitium Installer v4.4
Exit code:
3221226540
Version:
4.04
Modules
Images
c:\users\admin\desktop\tmacv6.0.7_setup.exe
c:\windows\system32\ntdll.dll
3864"C:\Windows\system32\rundll32.exe" C:\Windows\system32\shell32.dll,OpenAs_RunDLL "C:\Users\admin\AppData\Local\Temp\TMACv6.0.7_Setup.exe.ax"C:\Windows\System32\rundll32.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
3956regsvr32 /s "C:\Windows\system32\TABCTL32.OCX"C:\Windows\System32\regsvr32.exeTMACv6.0.7_Setup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
8 912
Read events
8 779
Write events
96
Delete events
37

Modification events

(PID) Process:(3460) TMACv6.0.7_Setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000000000000F01FEC\Usage
Operation:writeName:ProductNonBootFiles
Value:
(PID) Process:(120) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F9043C85-F6F2-101A-A3C9-08002B2F49FB}
Operation:delete keyName:(default)
Value:
(PID) Process:(120) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F9043C85-F6F2-101A-A3C9-08002B2F49FB}\InprocServer32
Operation:writeName:ThreadingModel
Value:
Apartment
(PID) Process:(120) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7629CFA2-3FE5-101B-A3C9-08002B2F49FB}
Operation:delete keyName:(default)
Value:
(PID) Process:(120) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7629CFA2-3FE5-101B-A3C9-08002B2F49FB}\InprocServer32
Operation:delete valueName:ThreadingModel
Value:
(PID) Process:(120) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7629CFA4-3FE5-101B-A3C9-08002B2F49FB}
Operation:delete keyName:(default)
Value:
(PID) Process:(120) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7629CFA4-3FE5-101B-A3C9-08002B2F49FB}\InprocServer32
Operation:delete valueName:ThreadingModel
Value:
(PID) Process:(120) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3C4F3BE5-47EB-101B-A3C9-08002B2F49FB}
Operation:delete keyName:(default)
Value:
(PID) Process:(120) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3C4F3BE5-47EB-101B-A3C9-08002B2F49FB}\InprocServer32
Operation:delete valueName:ThreadingModel
Value:
(PID) Process:(120) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3C4F3BE3-47EB-101B-A3C9-08002B2F49FB}
Operation:delete keyName:(default)
Value:
Executable files
5
Suspicious files
11
Text files
9
Unknown types
3

Dropped files

PID
Process
Filename
Type
3460TMACv6.0.7_Setup.exeC:\ProgramData\Microsoft\Windows\Start Menu\TMAC v6.lnk
MD5:
SHA256:
3460TMACv6.0.7_Setup.exeC:\Windows\system32\TABCTL32.OCXexecutable
MD5:DC925B6D77BA9ECB532E2F6750BE943B
SHA256:D10A197FD53E65DC910CA4AED86CB674C613FF14CE6436D1A445BB27A7A499E0
3460TMACv6.0.7_Setup.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Technitium MAC Address Changer v6\TMAC v6.lnkbinary
MD5:8CA82CEE223BC85B336FD67F5E20D779
SHA256:3ABF9B6AD2D8AB36D296E702625862A015664737E1710C965F8A71B98E0BC1B9
3460TMACv6.0.7_Setup.exeC:\Program Files\Technitium\TMACv6.0\Default.tpfbinary
MD5:B15B6771957A32AD93FFD0E044E4DCA7
SHA256:29106FA8E3C3D9370CED3D1C18F6D99A139710D6F77C8E61D468934DBD7EFEEB
3460TMACv6.0.7_Setup.exeC:\Program Files\Technitium\TMACv6.0\help.htmlhtml
MD5:8A707156B8AC8760E9DE9F2D62C2050E
SHA256:C37D369D1F1EE945DA67587B530D433B7FA0D16BA09A9EF13D468141A403C09D
3460TMACv6.0.7_Setup.exeC:\Windows\system32\MSCHRT20.OCXexecutable
MD5:38CE0C8FCD78D00FD717CE3A91214CBC
SHA256:DE49EB9F935416CC57A1B590CCA686E4A14E7B3CBBDE10B8FF7FB88642A215CE
3460TMACv6.0.7_Setup.exeC:\Program Files\Technitium\TMACv6.0\CLIHelp.txttext
MD5:780FFEB3F5DF428417F2D0A4EE03CCAF
SHA256:00D292FBE3A27290D2C6A80D7C40A44883BA84CA7309F74921ADF80FAFD51B00
3460TMACv6.0.7_Setup.exeC:\Program Files\Technitium\TMACv6.0\normal_logo_back.jpgimage
MD5:A1F052F23BEE756E5E972A427BB6D99C
SHA256:E1B2D122C76FCA89351097FB84BEEDFF99C69511F54E9000661E6BC1D6F7E019
3460TMACv6.0.7_Setup.exeC:\Program Files\Technitium\TMACv6.0\index.csstext
MD5:75E3113B6AE87E9C621BD4AA195735AC
SHA256:46D03EA49064A7F011F1CBB947D52F0B1DE6B69BD01DB8A57E9FB2778463FCA4
3460TMACv6.0.7_Setup.exeC:\Program Files\Technitium\TMACv6.0\EULA.txttext
MD5:A872B3D3D42216A0042E169BF13FE205
SHA256:586A7CF4B422290783C9F9BD93B1C89DCC1CCEA63A00C3C740DDE28ADC88AF82
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
3
TCP/UDP connections
8
DNS requests
3
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1656
TMAC.exe
GET
302
139.59.3.235:80
http://go.technitium.com/fwlink/?id=11
unknown
unknown
1656
TMAC.exe
GET
301
139.59.3.235:80
http://download.technitium.com/tmac/TMACAutomaticUpdate.bin
unknown
html
194 b
unknown
1656
TMAC.exe
GET
200
23.32.238.219:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?ee6b346b3dd915c4
unknown
compressed
65.2 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
1656
TMAC.exe
139.59.3.235:80
go.technitium.com
DIGITALOCEAN-ASN
IN
unknown
1656
TMAC.exe
139.59.3.235:443
go.technitium.com
DIGITALOCEAN-ASN
IN
unknown
1656
TMAC.exe
23.32.238.219:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown

DNS requests

Domain
IP
Reputation
go.technitium.com
  • 139.59.3.235
unknown
download.technitium.com
  • 139.59.3.235
unknown
ctldl.windowsupdate.com
  • 23.32.238.219
  • 23.32.238.201
whitelisted

Threats

No threats detected
No debug info