File name:

scantailor-advanced-2019.8.16-win64.exe

Full analysis: https://app.any.run/tasks/96d1734a-eec1-4d8b-b6b0-164c9f7a2d29
Verdict: Malicious activity
Analysis date: May 25, 2025, 04:01:34
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive, 5 sections
MD5:

A9B442CC792F31C9C03831EC3CD103F8

SHA1:

DBF4F246D585214B7670CAA721761B780C1BF828

SHA256:

AC81EDC53AF6090144D3255EE2D8775613CC5BD780FD499091C4394DFE33D36C

SSDEEP:

98304:rbjvFqJVYoGgd2TcUsYTJCxrrP3U0eijlq8GWiTb/tCfscT4mIW/JqPQcTt3wbaO:arVusZTuYTPnLmWT1JXPbFOS

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • scantailor-advanced-2019.8.16-win64.exe (PID: 7428)
    • There is functionality for taking screenshot (YARA)

      • scantailor-advanced-2019.8.16-win64.exe (PID: 7428)
    • Creates a software uninstall entry

      • scantailor-advanced-2019.8.16-win64.exe (PID: 7428)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • scantailor-advanced-2019.8.16-win64.exe (PID: 7428)
    • The process creates files with name similar to system file names

      • scantailor-advanced-2019.8.16-win64.exe (PID: 7428)
  • INFO

    • Create files in a temporary directory

      • scantailor-advanced-2019.8.16-win64.exe (PID: 7428)
    • Reads the computer name

      • scantailor-advanced-2019.8.16-win64.exe (PID: 7428)
      • scantailor.exe (PID: 7948)
    • Checks supported languages

      • scantailor-advanced-2019.8.16-win64.exe (PID: 7428)
      • scantailor.exe (PID: 7948)
    • The sample compiled with english language support

      • scantailor-advanced-2019.8.16-win64.exe (PID: 7428)
    • Creates files in the program directory

      • scantailor-advanced-2019.8.16-win64.exe (PID: 7428)
    • Manual execution by a user

      • scantailor.exe (PID: 7948)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2018:12:15 22:24:22+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 24576
InitializedDataSize: 118784
UninitializedDataSize: 1024
EntryPoint: 0x31d6
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
137
Monitored processes
3
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start scantailor-advanced-2019.8.16-win64.exe scantailor.exe no specs scantailor-advanced-2019.8.16-win64.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
7372"C:\Users\admin\AppData\Local\Temp\scantailor-advanced-2019.8.16-win64.exe" C:\Users\admin\AppData\Local\Temp\scantailor-advanced-2019.8.16-win64.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\appdata\local\temp\scantailor-advanced-2019.8.16-win64.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
7428"C:\Users\admin\AppData\Local\Temp\scantailor-advanced-2019.8.16-win64.exe" C:\Users\admin\AppData\Local\Temp\scantailor-advanced-2019.8.16-win64.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\scantailor-advanced-2019.8.16-win64.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
7948"C:\Program Files\ScanTailor Advanced\scantailor.exe" C:\Program Files\ScanTailor Advanced\scantailor.exeexplorer.exe
User:
admin
Company:
4lex4 <4lex49@zoho.com>
Integrity Level:
MEDIUM
Description:
ScanTailor Advanced
Version:
2019.8.16.0
Modules
Images
c:\program files\scantailor advanced\scantailor.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\program files\scantailor advanced\libgcc_s_seh-1.dll
c:\program files\scantailor advanced\libjpeg.dll
c:\program files\scantailor advanced\libpng.dll
c:\program files\scantailor advanced\libstdc++-6.dll
Total events
290
Read events
281
Write events
9
Delete events
0

Modification events

(PID) Process:(7428) scantailor-advanced-2019.8.16-win64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ScanTailor Advanced
Operation:writeName:DisplayName
Value:
ScanTailor Advanced 2019.8.16
(PID) Process:(7428) scantailor-advanced-2019.8.16-win64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ScanTailor Advanced
Operation:writeName:DisplayVersion
Value:
2019.8.16
(PID) Process:(7428) scantailor-advanced-2019.8.16-win64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ScanTailor Advanced
Operation:writeName:DisplayIcon
Value:
C:\Program Files\ScanTailor Advanced\scantailor.exe
(PID) Process:(7428) scantailor-advanced-2019.8.16-win64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\4lex4 <4lex49@zoho.com>\ScanTailor Advanced
Operation:writeName:Start Menu Folder
Value:
ScanTailor Advanced
(PID) Process:(7428) scantailor-advanced-2019.8.16-win64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ScanTailor Advanced
Operation:writeName:Publisher
Value:
4lex4 <4lex49@zoho.com>
(PID) Process:(7428) scantailor-advanced-2019.8.16-win64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ScanTailor Advanced
Operation:writeName:UninstallString
Value:
C:\Program Files\ScanTailor Advanced\Uninstall.exe
(PID) Process:(7428) scantailor-advanced-2019.8.16-win64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ScanTailor Advanced
Operation:writeName:NoRepair
Value:
1
(PID) Process:(7428) scantailor-advanced-2019.8.16-win64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ScanTailor Advanced
Operation:writeName:NoModify
Value:
1
(PID) Process:(7428) scantailor-advanced-2019.8.16-win64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ScanTailor Advanced
Operation:writeName:StartMenu
Value:
ScanTailor Advanced
Executable files
26
Suspicious files
4
Text files
2
Unknown types
1

Dropped files

PID
Process
Filename
Type
7428scantailor-advanced-2019.8.16-win64.exeC:\Users\admin\AppData\Local\Temp\nsoB48D.tmp\UserInfo.dllexecutable
MD5:7836F464AE0102452E94A363B491B759
SHA256:11ADF8916947B5A20A071B494FA034CF62769DCC6293A1340B29A5BB29AC8E87
7428scantailor-advanced-2019.8.16-win64.exeC:\Users\admin\AppData\Local\Temp\nsoB48D.tmp\InstallOptions.dllexecutable
MD5:5D195F1AC9869C208F6C02A5BDE6F9C1
SHA256:78012F560BB917218435F4B3EF2E3491BAB15647E11CCB90BC117731181134C4
7428scantailor-advanced-2019.8.16-win64.exeC:\Users\admin\AppData\Local\Temp\nsoB48D.tmp\modern-header.bmpimage
MD5:940C56737BF9BB69CE7A31C623D4E87A
SHA256:766A893FE962AEFD27C574CB05F25CF895D3FC70A00DB5A6FA73D573F571AEFC
7428scantailor-advanced-2019.8.16-win64.exeC:\Users\admin\AppData\Local\Temp\nsoB48D.tmp\ioSpecial.initext
MD5:E2D5070BC28DB1AC745613689FF86067
SHA256:D95AED234F932A1C48A2B1B0D98C60CA31F962310C03158E2884AB4DDD3EA1E0
7428scantailor-advanced-2019.8.16-win64.exeC:\Program Files\ScanTailor Advanced\Qt5Network.dllexecutable
MD5:0BF6223EEA8E09B91B24B8A48526E491
SHA256:1C06054BC48626A517BC6B03D9415EBF5A6FF6D7124890AFEAC9F79BFF6D8AA5
7428scantailor-advanced-2019.8.16-win64.exeC:\Program Files\ScanTailor Advanced\Qt5Xml.dllexecutable
MD5:537D37C05C489BA866A63F549698B88D
SHA256:287DF7B50708DBF2D5A1AACD3BC4E0022DED10E87F73B7EEF48F39F399D9DE70
7428scantailor-advanced-2019.8.16-win64.exeC:\Program Files\ScanTailor Advanced\Qt5Widgets.dllexecutable
MD5:D038657BDAFCB3AAF5AD650A42789DFA
SHA256:CAB1CBFA96EBB7BCC14C7345BD6C389EC306141789E0504E22746FEAFD5E23AF
7428scantailor-advanced-2019.8.16-win64.exeC:\Program Files\ScanTailor Advanced\libgcc_s_seh-1.dllexecutable
MD5:534B365361004828059600F05B34006D
SHA256:438AE82FFD621A2413199155574CC85681F8986F05420B1485AA4BE936C3BC0B
7428scantailor-advanced-2019.8.16-win64.exeC:\Program Files\ScanTailor Advanced\libtiff.dllexecutable
MD5:91755D74264DF056CEF82E4C30011AB6
SHA256:1BC3E10BF50E61046F6BF531E07157C30438FA45BCA46BE393B0300ADA174D8A
7428scantailor-advanced-2019.8.16-win64.exeC:\Program Files\ScanTailor Advanced\libpng.dllexecutable
MD5:A62EC0EE535438EB24D67F4FB14989F7
SHA256:4E5DF172F64CFEE1F8FA04D9E61D0BE63CAE9DFAEC4599D225A9D30E1A530C02
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
3
TCP/UDP connections
17
DNS requests
10
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5796
svchost.exe
GET
200
23.216.77.6:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
6544
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
5796
svchost.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1020
RUXIMICS.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
5496
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5796
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
6544
svchost.exe
40.126.31.131:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6544
svchost.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
3216
svchost.exe
172.211.123.248:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
5796
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5796
svchost.exe
23.216.77.6:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 40.127.240.158
  • 51.124.78.146
whitelisted
google.com
  • 142.250.185.142
whitelisted
login.live.com
  • 40.126.31.131
  • 20.190.159.2
  • 20.190.159.75
  • 20.190.159.4
  • 40.126.31.69
  • 40.126.31.67
  • 20.190.159.64
  • 20.190.159.68
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
client.wns.windows.com
  • 172.211.123.248
whitelisted
crl.microsoft.com
  • 23.216.77.6
  • 23.216.77.28
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted

Threats

No threats detected
No debug info