File name:

scantailor-advanced-2019.8.16-win64.exe

Full analysis: https://app.any.run/tasks/96d1734a-eec1-4d8b-b6b0-164c9f7a2d29
Verdict: Malicious activity
Analysis date: May 25, 2025, 04:01:34
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive, 5 sections
MD5:

A9B442CC792F31C9C03831EC3CD103F8

SHA1:

DBF4F246D585214B7670CAA721761B780C1BF828

SHA256:

AC81EDC53AF6090144D3255EE2D8775613CC5BD780FD499091C4394DFE33D36C

SSDEEP:

98304:rbjvFqJVYoGgd2TcUsYTJCxrrP3U0eijlq8GWiTb/tCfscT4mIW/JqPQcTt3wbaO:arVusZTuYTPnLmWT1JXPbFOS

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • There is functionality for taking screenshot (YARA)

      • scantailor-advanced-2019.8.16-win64.exe (PID: 7428)
    • Executable content was dropped or overwritten

      • scantailor-advanced-2019.8.16-win64.exe (PID: 7428)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • scantailor-advanced-2019.8.16-win64.exe (PID: 7428)
    • The process creates files with name similar to system file names

      • scantailor-advanced-2019.8.16-win64.exe (PID: 7428)
    • Creates a software uninstall entry

      • scantailor-advanced-2019.8.16-win64.exe (PID: 7428)
  • INFO

    • Reads the computer name

      • scantailor-advanced-2019.8.16-win64.exe (PID: 7428)
      • scantailor.exe (PID: 7948)
    • Checks supported languages

      • scantailor-advanced-2019.8.16-win64.exe (PID: 7428)
      • scantailor.exe (PID: 7948)
    • Creates files in the program directory

      • scantailor-advanced-2019.8.16-win64.exe (PID: 7428)
    • The sample compiled with english language support

      • scantailor-advanced-2019.8.16-win64.exe (PID: 7428)
    • Create files in a temporary directory

      • scantailor-advanced-2019.8.16-win64.exe (PID: 7428)
    • Manual execution by a user

      • scantailor.exe (PID: 7948)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2018:12:15 22:24:22+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 24576
InitializedDataSize: 118784
UninitializedDataSize: 1024
EntryPoint: 0x31d6
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
137
Monitored processes
3
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start scantailor-advanced-2019.8.16-win64.exe scantailor.exe no specs scantailor-advanced-2019.8.16-win64.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
7372"C:\Users\admin\AppData\Local\Temp\scantailor-advanced-2019.8.16-win64.exe" C:\Users\admin\AppData\Local\Temp\scantailor-advanced-2019.8.16-win64.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\appdata\local\temp\scantailor-advanced-2019.8.16-win64.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
7428"C:\Users\admin\AppData\Local\Temp\scantailor-advanced-2019.8.16-win64.exe" C:\Users\admin\AppData\Local\Temp\scantailor-advanced-2019.8.16-win64.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\scantailor-advanced-2019.8.16-win64.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
7948"C:\Program Files\ScanTailor Advanced\scantailor.exe" C:\Program Files\ScanTailor Advanced\scantailor.exeexplorer.exe
User:
admin
Company:
4lex4 <4lex49@zoho.com>
Integrity Level:
MEDIUM
Description:
ScanTailor Advanced
Version:
2019.8.16.0
Modules
Images
c:\program files\scantailor advanced\scantailor.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\program files\scantailor advanced\libgcc_s_seh-1.dll
c:\program files\scantailor advanced\libjpeg.dll
c:\program files\scantailor advanced\libpng.dll
c:\program files\scantailor advanced\libstdc++-6.dll
Total events
290
Read events
281
Write events
9
Delete events
0

Modification events

(PID) Process:(7428) scantailor-advanced-2019.8.16-win64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ScanTailor Advanced
Operation:writeName:DisplayName
Value:
ScanTailor Advanced 2019.8.16
(PID) Process:(7428) scantailor-advanced-2019.8.16-win64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ScanTailor Advanced
Operation:writeName:DisplayVersion
Value:
2019.8.16
(PID) Process:(7428) scantailor-advanced-2019.8.16-win64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ScanTailor Advanced
Operation:writeName:DisplayIcon
Value:
C:\Program Files\ScanTailor Advanced\scantailor.exe
(PID) Process:(7428) scantailor-advanced-2019.8.16-win64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\4lex4 <4lex49@zoho.com>\ScanTailor Advanced
Operation:writeName:Start Menu Folder
Value:
ScanTailor Advanced
(PID) Process:(7428) scantailor-advanced-2019.8.16-win64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ScanTailor Advanced
Operation:writeName:Publisher
Value:
4lex4 <4lex49@zoho.com>
(PID) Process:(7428) scantailor-advanced-2019.8.16-win64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ScanTailor Advanced
Operation:writeName:UninstallString
Value:
C:\Program Files\ScanTailor Advanced\Uninstall.exe
(PID) Process:(7428) scantailor-advanced-2019.8.16-win64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ScanTailor Advanced
Operation:writeName:NoRepair
Value:
1
(PID) Process:(7428) scantailor-advanced-2019.8.16-win64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ScanTailor Advanced
Operation:writeName:NoModify
Value:
1
(PID) Process:(7428) scantailor-advanced-2019.8.16-win64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ScanTailor Advanced
Operation:writeName:StartMenu
Value:
ScanTailor Advanced
Executable files
26
Suspicious files
4
Text files
2
Unknown types
1

Dropped files

PID
Process
Filename
Type
7428scantailor-advanced-2019.8.16-win64.exeC:\Program Files\ScanTailor Advanced\Qt5Widgets.dllexecutable
MD5:D038657BDAFCB3AAF5AD650A42789DFA
SHA256:CAB1CBFA96EBB7BCC14C7345BD6C389EC306141789E0504E22746FEAFD5E23AF
7428scantailor-advanced-2019.8.16-win64.exeC:\Users\admin\AppData\Local\Temp\nsoB48D.tmp\InstallOptions.dllexecutable
MD5:5D195F1AC9869C208F6C02A5BDE6F9C1
SHA256:78012F560BB917218435F4B3EF2E3491BAB15647E11CCB90BC117731181134C4
7428scantailor-advanced-2019.8.16-win64.exeC:\Users\admin\AppData\Local\Temp\nsoB48D.tmp\modern-wizard.bmpimage
MD5:CBE40FD2B1EC96DAEDC65DA172D90022
SHA256:3AD2DC318056D0A2024AF1804EA741146CFC18CC404649A44610CBF8B2056CF2
7428scantailor-advanced-2019.8.16-win64.exeC:\Program Files\ScanTailor Advanced\Qt5Xml.dllexecutable
MD5:537D37C05C489BA866A63F549698B88D
SHA256:287DF7B50708DBF2D5A1AACD3BC4E0022DED10E87F73B7EEF48F39F399D9DE70
7428scantailor-advanced-2019.8.16-win64.exeC:\Users\admin\AppData\Local\Temp\nsoB48D.tmp\UserInfo.dllexecutable
MD5:7836F464AE0102452E94A363B491B759
SHA256:11ADF8916947B5A20A071B494FA034CF62769DCC6293A1340B29A5BB29AC8E87
7428scantailor-advanced-2019.8.16-win64.exeC:\Users\admin\AppData\Local\Temp\nsoB48D.tmp\ioSpecial.initext
MD5:E2D5070BC28DB1AC745613689FF86067
SHA256:D95AED234F932A1C48A2B1B0D98C60CA31F962310C03158E2884AB4DDD3EA1E0
7428scantailor-advanced-2019.8.16-win64.exeC:\Program Files\ScanTailor Advanced\Qt5Network.dllexecutable
MD5:0BF6223EEA8E09B91B24B8A48526E491
SHA256:1C06054BC48626A517BC6B03D9415EBF5A6FF6D7124890AFEAC9F79BFF6D8AA5
7428scantailor-advanced-2019.8.16-win64.exeC:\Users\admin\AppData\Local\Temp\nsoB48D.tmp\StartMenu.dllexecutable
MD5:C365C5FF6418EFAE5FE288BD0419FA5C
SHA256:88CEBBF8BAD719D06709E9E29C39D1ABE3325AE26F8D65C101E50DF3AFDD9057
7428scantailor-advanced-2019.8.16-win64.exeC:\Program Files\ScanTailor Advanced\Qt5Core.dllexecutable
MD5:3B4AED0B8F98DECA65BD15BE4E74B188
SHA256:F2BBCEB611C9861FE10EC2D426C1A9F66DBF6B4A9A6DC846A7555AB899FB131F
7428scantailor-advanced-2019.8.16-win64.exeC:\Program Files\ScanTailor Advanced\Qt5OpenGL.dllexecutable
MD5:CCC8FE4301B35D24ED03A883A5B4720E
SHA256:9ADF83C972CFD5026F522431DB682C5E95E5A891D12639B688FC2015C7502495
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
3
TCP/UDP connections
17
DNS requests
10
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5796
svchost.exe
GET
200
23.216.77.6:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5796
svchost.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6544
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1020
RUXIMICS.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
5496
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5796
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
6544
svchost.exe
40.126.31.131:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6544
svchost.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
3216
svchost.exe
172.211.123.248:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
5796
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5796
svchost.exe
23.216.77.6:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 40.127.240.158
  • 51.124.78.146
whitelisted
google.com
  • 142.250.185.142
whitelisted
login.live.com
  • 40.126.31.131
  • 20.190.159.2
  • 20.190.159.75
  • 20.190.159.4
  • 40.126.31.69
  • 40.126.31.67
  • 20.190.159.64
  • 20.190.159.68
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
client.wns.windows.com
  • 172.211.123.248
whitelisted
crl.microsoft.com
  • 23.216.77.6
  • 23.216.77.28
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted

Threats

No threats detected
No debug info