File name:

TMACv6.0.7_Setup.exe

Full analysis: https://app.any.run/tasks/99bc0c00-397a-4823-a481-7fb0107fc33a
Verdict: Malicious activity
Analysis date: February 25, 2024, 03:27:32
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

A7C8CF1D50EBE630A7D0C47686A0ABBF

SHA1:

3229E8080975F4F5512D2382552F68C0389ACFF5

SHA256:

A453B3EA8D8133531FAD26B18701C694C324CC201E3069D07E99F0E100908C1A

SSDEEP:

98304:ARU3j4wtopcj2dqCYV1coZ4hv3tmF1b6CrjfW/sfH6s7zQcKDsVv/JLSF66b/:ARqt/CdqRc64hv3tmF1b6CffW/sfH6sm

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • rundll32.exe (PID: 3864)
      • TMACv6.0.7_Setup.exe (PID: 3460)
    • Registers / Runs the DLL via REGSVR32.EXE

      • TMACv6.0.7_Setup.exe (PID: 3460)
    • Creates a writable file in the system directory

      • TMACv6.0.7_Setup.exe (PID: 3460)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • TMACv6.0.7_Setup.exe (PID: 3460)
    • Process drops legitimate windows executable

      • TMACv6.0.7_Setup.exe (PID: 3460)
    • Creates/Modifies COM task schedule object

      • regsvr32.exe (PID: 120)
      • regsvr32.exe (PID: 3956)
    • Creates a software uninstall entry

      • TMACv6.0.7_Setup.exe (PID: 3460)
    • Reads security settings of Internet Explorer

      • TMAC.exe (PID: 2408)
    • Adds/modifies Windows certificates

      • TMAC.exe (PID: 1656)
    • Reads the Internet Settings

      • TMAC.exe (PID: 1656)
      • TMAC.exe (PID: 2408)
    • Reads settings of System Certificates

      • TMAC.exe (PID: 1656)
    • Application launched itself

      • TMAC.exe (PID: 2408)
  • INFO

    • Reads the machine GUID from the registry

      • TMACv6.0.7_Setup.exe (PID: 3460)
      • TMAC.exe (PID: 1656)
    • Manual execution by a user

      • TMACv6.0.7_Setup.exe (PID: 3460)
      • TMACv6.0.7_Setup.exe (PID: 3716)
      • TMAC.exe (PID: 2408)
    • Checks supported languages

      • TMACv6.0.7_Setup.exe (PID: 3460)
      • TMAC.exe (PID: 2408)
      • TMAC.exe (PID: 1656)
    • Reads Microsoft Office registry keys

      • TMACv6.0.7_Setup.exe (PID: 3460)
      • TMAC.exe (PID: 1656)
    • Create files in a temporary directory

      • TMACv6.0.7_Setup.exe (PID: 3460)
      • TMAC.exe (PID: 1656)
    • Reads mouse settings

      • TMACv6.0.7_Setup.exe (PID: 3460)
      • TMAC.exe (PID: 1656)
    • Reads the computer name

      • TMACv6.0.7_Setup.exe (PID: 3460)
      • TMAC.exe (PID: 2408)
      • TMAC.exe (PID: 1656)
    • Creates files in the program directory

      • TMACv6.0.7_Setup.exe (PID: 3460)
      • TMAC.exe (PID: 1656)
    • Checks proxy server information

      • TMAC.exe (PID: 1656)
    • Reads the time zone

      • TMAC.exe (PID: 1656)
    • Reads the software policy settings

      • TMAC.exe (PID: 1656)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.ax | DirectShow filter (37.9)
.exe | Win32 Executable Microsoft Visual Basic 6 (15.4)
.exe | InstallShield setup (8.1)
.exe | Win32 EXE PECompact compressed (generic) (7.8)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2012:01:01 19:37:01+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 167936
InitializedDataSize: 20480
UninitializedDataSize: -
EntryPoint: 0x21a8
OSVersion: 4
ImageVersion: 4.4
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 4.4.0.0
ProductVersionNumber: 4.4.0.0
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
Comments: Technitium Installer v4.4. Visit us at www.technitium.com
CompanyName: Technitium
FileDescription: Technitium Installer v4.4
ProductName: Technitium Installer v4.4
FileVersion: 4.04
ProductVersion: 4.04
InternalName: Installer
OriginalFileName: Installer.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
51
Monitored processes
8
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start rundll32.exe no specs tmacv6.0.7_setup.exe no specs tmacv6.0.7_setup.exe regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs tmac.exe no specs tmac.exe

Process information

PID
CMD
Path
Indicators
Parent process
120regsvr32 /s "C:\Windows\system32\COMDLG32.OCX"C:\Windows\System32\regsvr32.exeTMACv6.0.7_Setup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1656"C:\Program Files\Technitium\TMACv6.0\TMAC.exe" C:\Program Files\Technitium\TMACv6.0\TMAC.exe
TMAC.exe
User:
admin
Company:
Technitium
Integrity Level:
HIGH
Description:
Technitium MAC Address Changer
Exit code:
0
Version:
6.00.0007
Modules
Images
c:\program files\technitium\tmacv6.0\tmac.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvbvm60.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
2120regsvr32 /s "C:\Windows\system32\MSCHRT20.OCX"C:\Windows\System32\regsvr32.exeTMACv6.0.7_Setup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2408"C:\Program Files\Technitium\TMACv6.0\TMAC.exe" C:\Program Files\Technitium\TMACv6.0\TMAC.exeexplorer.exe
User:
admin
Company:
Technitium
Integrity Level:
MEDIUM
Description:
Technitium MAC Address Changer
Exit code:
0
Version:
6.00.0007
Modules
Images
c:\program files\technitium\tmacv6.0\tmac.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvbvm60.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
3460"C:\Users\admin\Desktop\TMACv6.0.7_Setup.exe" C:\Users\admin\Desktop\TMACv6.0.7_Setup.exe
explorer.exe
User:
admin
Company:
Technitium
Integrity Level:
HIGH
Description:
Technitium Installer v4.4
Exit code:
0
Version:
4.04
Modules
Images
c:\users\admin\desktop\tmacv6.0.7_setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvbvm60.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
3716"C:\Users\admin\Desktop\TMACv6.0.7_Setup.exe" C:\Users\admin\Desktop\TMACv6.0.7_Setup.exeexplorer.exe
User:
admin
Company:
Technitium
Integrity Level:
MEDIUM
Description:
Technitium Installer v4.4
Exit code:
3221226540
Version:
4.04
Modules
Images
c:\users\admin\desktop\tmacv6.0.7_setup.exe
c:\windows\system32\ntdll.dll
3864"C:\Windows\system32\rundll32.exe" C:\Windows\system32\shell32.dll,OpenAs_RunDLL "C:\Users\admin\AppData\Local\Temp\TMACv6.0.7_Setup.exe.ax"C:\Windows\System32\rundll32.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
3956regsvr32 /s "C:\Windows\system32\TABCTL32.OCX"C:\Windows\System32\regsvr32.exeTMACv6.0.7_Setup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
8 912
Read events
8 779
Write events
96
Delete events
37

Modification events

(PID) Process:(3460) TMACv6.0.7_Setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000000000000F01FEC\Usage
Operation:writeName:ProductNonBootFiles
Value:
(PID) Process:(120) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F9043C85-F6F2-101A-A3C9-08002B2F49FB}
Operation:delete keyName:(default)
Value:
(PID) Process:(120) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F9043C85-F6F2-101A-A3C9-08002B2F49FB}\InprocServer32
Operation:writeName:ThreadingModel
Value:
Apartment
(PID) Process:(120) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7629CFA2-3FE5-101B-A3C9-08002B2F49FB}
Operation:delete keyName:(default)
Value:
(PID) Process:(120) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7629CFA2-3FE5-101B-A3C9-08002B2F49FB}\InprocServer32
Operation:delete valueName:ThreadingModel
Value:
(PID) Process:(120) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7629CFA4-3FE5-101B-A3C9-08002B2F49FB}
Operation:delete keyName:(default)
Value:
(PID) Process:(120) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7629CFA4-3FE5-101B-A3C9-08002B2F49FB}\InprocServer32
Operation:delete valueName:ThreadingModel
Value:
(PID) Process:(120) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3C4F3BE5-47EB-101B-A3C9-08002B2F49FB}
Operation:delete keyName:(default)
Value:
(PID) Process:(120) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3C4F3BE5-47EB-101B-A3C9-08002B2F49FB}\InprocServer32
Operation:delete valueName:ThreadingModel
Value:
(PID) Process:(120) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3C4F3BE3-47EB-101B-A3C9-08002B2F49FB}
Operation:delete keyName:(default)
Value:
Executable files
5
Suspicious files
11
Text files
9
Unknown types
3

Dropped files

PID
Process
Filename
Type
3460TMACv6.0.7_Setup.exeC:\ProgramData\Microsoft\Windows\Start Menu\TMAC v6.lnk
MD5:
SHA256:
3460TMACv6.0.7_Setup.exeC:\Program Files\Technitium\TMACv6.0\Installer.exeexecutable
MD5:1A56AF5A19362FF83B99EDA81F5DFDF9
SHA256:72367E11DBF5E3AD9FA1CC4B2FBD3D8E3E5A26D5683CFC7B06B7D1AC33AA4011
3460TMACv6.0.7_Setup.exeC:\Program Files\Technitium\TMACv6.0\EULA.txttext
MD5:A872B3D3D42216A0042E169BF13FE205
SHA256:586A7CF4B422290783C9F9BD93B1C89DCC1CCEA63A00C3C740DDE28ADC88AF82
3460TMACv6.0.7_Setup.exeC:\Windows\system32\TABCTL32.OCXexecutable
MD5:DC925B6D77BA9ECB532E2F6750BE943B
SHA256:D10A197FD53E65DC910CA4AED86CB674C613FF14CE6436D1A445BB27A7A499E0
3460TMACv6.0.7_Setup.exeC:\Program Files\Technitium\TMACv6.0\CLIHelp.txttext
MD5:780FFEB3F5DF428417F2D0A4EE03CCAF
SHA256:00D292FBE3A27290D2C6A80D7C40A44883BA84CA7309F74921ADF80FAFD51B00
3460TMACv6.0.7_Setup.exeC:\Program Files\Technitium\TMACv6.0\Default.tpfbinary
MD5:B15B6771957A32AD93FFD0E044E4DCA7
SHA256:29106FA8E3C3D9370CED3D1C18F6D99A139710D6F77C8E61D468934DBD7EFEEB
3460TMACv6.0.7_Setup.exeC:\Program Files\Technitium\TMACv6.0\help.htmlhtml
MD5:8A707156B8AC8760E9DE9F2D62C2050E
SHA256:C37D369D1F1EE945DA67587B530D433B7FA0D16BA09A9EF13D468141A403C09D
3460TMACv6.0.7_Setup.exeC:\Windows\system32\MSCHRT20.OCXexecutable
MD5:38CE0C8FCD78D00FD717CE3A91214CBC
SHA256:DE49EB9F935416CC57A1B590CCA686E4A14E7B3CBBDE10B8FF7FB88642A215CE
3460TMACv6.0.7_Setup.exeC:\Program Files\Technitium\TMACv6.0\oui.dbatm
MD5:DF01B5D254A5975AB617CF11D1C31FE1
SHA256:EB13AFF91A8EE50DFDF7B2CBF10E0E975F6D6111298737AB051539A4B9156944
3460TMACv6.0.7_Setup.exeC:\Program Files\Technitium\TMACv6.0\Read Me.txttext
MD5:8379466260AAF7E3219C442B24B2213D
SHA256:F998879070E7C17E484C4A4913252BF3494350EFFC626E7F5BF06220E2EF7D97
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
3
TCP/UDP connections
8
DNS requests
3
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1656
TMAC.exe
GET
302
139.59.3.235:80
http://go.technitium.com/fwlink/?id=11
unknown
unknown
1656
TMAC.exe
GET
200
23.32.238.219:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?ee6b346b3dd915c4
unknown
compressed
65.2 Kb
unknown
1656
TMAC.exe
GET
301
139.59.3.235:80
http://download.technitium.com/tmac/TMACAutomaticUpdate.bin
unknown
html
194 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
1656
TMAC.exe
139.59.3.235:80
go.technitium.com
DIGITALOCEAN-ASN
IN
unknown
1656
TMAC.exe
139.59.3.235:443
go.technitium.com
DIGITALOCEAN-ASN
IN
unknown
1656
TMAC.exe
23.32.238.219:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown

DNS requests

Domain
IP
Reputation
go.technitium.com
  • 139.59.3.235
unknown
download.technitium.com
  • 139.59.3.235
unknown
ctldl.windowsupdate.com
  • 23.32.238.219
  • 23.32.238.201
whitelisted

Threats

No threats detected
No debug info