| File name: | TaxSpoolerInst-2-7-0-21.exe |
| Full analysis: | https://app.any.run/tasks/d3797b57-a96a-400d-9543-f1107deb500c |
| Verdict: | Malicious activity |
| Analysis date: | April 10, 2025, 12:48:43 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, InstallShield self-extracting archive, 4 sections |
| MD5: | 6DB87DD5CD51CAD37E879436E3CBA54E |
| SHA1: | EA203707356F1A7C5914B913354808B11C3BB9A6 |
| SHA256: | B10A810A35E4693CE507B0CB6BB0401E7EF9A0668DCBF52CBC62E776A198BC9D |
| SSDEEP: | 98304:Ye23J202hV+1Lrnl/daXwalOpwK6DqMxaUaCaKwR+NKW//GfubQYBcaVXru0K7pD:O9Bl+2UgF2eOXK4pmtnEG |
| .exe | | | InstallShield setup (36.8) |
|---|---|---|
| .exe | | | Win32 Executable MS Visual C++ (generic) (26.6) |
| .exe | | | Win64 Executable (generic) (23.6) |
| .dll | | | Win32 Dynamic Link Library (generic) (5.6) |
| .exe | | | Win32 Executable (generic) (3.8) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2001:09:05 17:02:57+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 73728 |
| InitializedDataSize: | 212992 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x8947 |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 4.0.100.1190 |
| ProductVersionNumber: | 4.0.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Windows NT 32-bit |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| Comments: | |
| CompanyName: | INCA Hellas Ltd. |
| FileDescription: | |
| InternalName: | stub32 |
| OriginalFileName: | stub32i.exe |
| FileVersion: | 1.00.000 |
| LegalCopyright: | INCA Hellas Ltd. |
| ProductName: | TaxSpoolerInst |
| ProductVersion: | 1.00.000 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 5064 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | SrTasks.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Console Window Host Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 5800 | C:\WINDOWS\system32\srtasks.exe ExecuteScopeRestorePoint /WaitForRestorePoint:11 | C:\Windows\System32\SrTasks.exe | — | dllhost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft® Windows System Protection background tasks. Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6620 | C:\WINDOWS\system32\DllHost.exe /Processid:{F32D97DF-E3E5-4CB9-9E3E-0EB5B4E49801} | C:\Windows\System32\dllhost.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: COM Surrogate Exit code: 0 Version: 10.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 7296 | C:\WINDOWS\system32\vssvc.exe | C:\Windows\System32\VSSVC.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft® Volume Shadow Copy Service Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 7368 | "C:\Program Files (x86)\INCA Hellas\TaxSpooler\TaxService.exe" /INSTALL | C:\Program Files (x86)\INCA Hellas\TaxSpooler\TaxService.exe | — | IKernel.exe | |||||||||||
User: admin Company: Metafuture Ltd Integrity Level: HIGH Description: TaxSpooler Service Version: 2.7.0.21 Modules
| |||||||||||||||
| 7512 | C:\WINDOWS\System32\slui.exe -Embedding | C:\Windows\System32\slui.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Activation Client Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 7664 | "C:\Users\admin\AppData\Local\Temp\TaxSpoolerInst-2-7-0-21.exe" | C:\Users\admin\AppData\Local\Temp\TaxSpoolerInst-2-7-0-21.exe | — | explorer.exe | |||||||||||
User: admin Company: INCA Hellas Ltd. Integrity Level: MEDIUM Description: Exit code: 3221226540 Version: 1.00.000 Modules
| |||||||||||||||
| 7760 | "C:\Users\admin\AppData\Local\Temp\TaxSpoolerInst-2-7-0-21.exe" | C:\Users\admin\AppData\Local\Temp\TaxSpoolerInst-2-7-0-21.exe | explorer.exe | ||||||||||||
User: admin Company: INCA Hellas Ltd. Integrity Level: HIGH Description: Version: 1.00.000 Modules
| |||||||||||||||
| 7820 | "C:\Users\admin\AppData\Local\Temp\pftC373.tmp\Disk1\Setup.exe" | C:\Users\admin\AppData\Local\Temp\pftC373.tmp\Disk1\Setup.exe | TaxSpoolerInst-2-7-0-21.exe | ||||||||||||
User: admin Company: InstallShield Software Corporation Integrity Level: HIGH Description: InstallShield (R) Setup Launcher Version: 6, 31, 100, 1190 Modules
| |||||||||||||||
| 7840 | "C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe" -RegServer | C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe | — | Setup.exe | |||||||||||
User: admin Company: InstallShield Software Corporation Integrity Level: HIGH Description: InstallShield (R) Setup Engine Exit code: 0 Version: 6, 31, 100, 1221 Modules
| |||||||||||||||
| (PID) Process: | (7840) IKernel.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{AA7E2068-CB55-11D2-8094-00104B1F9838}\TypeLib |
| Operation: | write | Name: | Version |
Value: 1.0 | |||
| (PID) Process: | (7840) IKernel.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{AA7E2068-CB55-11D2-8094-00104B1F9838}\TypeLib |
| Operation: | write | Name: | Version |
Value: 1.0 | |||
| (PID) Process: | (7840) IKernel.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{AA7E2066-CB55-11D2-8094-00104B1F9838}\TypeLib |
| Operation: | write | Name: | Version |
Value: 1.0 | |||
| (PID) Process: | (7840) IKernel.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{AA7E2066-CB55-11D2-8094-00104B1F9838}\TypeLib |
| Operation: | write | Name: | Version |
Value: 1.0 | |||
| (PID) Process: | (7840) IKernel.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{CC096170-E2CB-11D2-80C8-00104B1F6CEA}\TypeLib |
| Operation: | write | Name: | Version |
Value: 1.0 | |||
| (PID) Process: | (7840) IKernel.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{CC096170-E2CB-11D2-80C8-00104B1F6CEA}\TypeLib |
| Operation: | write | Name: | Version |
Value: 1.0 | |||
| (PID) Process: | (7840) IKernel.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{8C3C1B11-E59D-11D2-B40B-00A024B9DDDD}\TypeLib |
| Operation: | write | Name: | Version |
Value: 1.0 | |||
| (PID) Process: | (7840) IKernel.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8C3C1B11-E59D-11D2-B40B-00A024B9DDDD}\TypeLib |
| Operation: | write | Name: | Version |
Value: 1.0 | |||
| (PID) Process: | (7840) IKernel.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{8C3C1B13-E59D-11D2-B40B-00A024B9DDDD}\TypeLib |
| Operation: | write | Name: | Version |
Value: 1.0 | |||
| (PID) Process: | (7840) IKernel.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8C3C1B13-E59D-11D2-B40B-00A024B9DDDD}\TypeLib |
| Operation: | write | Name: | Version |
Value: 1.0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 7760 | TaxSpoolerInst-2-7-0-21.exe | C:\Users\admin\AppData\Local\Temp\pftC373.tmp\pftw1.pkg | — | |
MD5:— | SHA256:— | |||
| 7760 | TaxSpoolerInst-2-7-0-21.exe | C:\Users\admin\AppData\Local\Temp\pftC373.tmp\Disk1\data2.cab | — | |
MD5:— | SHA256:— | |||
| 7760 | TaxSpoolerInst-2-7-0-21.exe | C:\Users\admin\AppData\Local\Temp\pftC373.tmp\Disk1\data1.hdr | compressed | |
MD5:42F87E10A20C5F16EC5CCC838DB492A8 | SHA256:44E0CA4735019206CA80B7BFDE5F326150BCA048F83B5EE14731FB880A8C9354 | |||
| 7760 | TaxSpoolerInst-2-7-0-21.exe | C:\Users\admin\AppData\Local\Temp\extC2E5.tmp | text | |
MD5:9EFCC61A0BAA38A6D7C67A05A97C7B87 | SHA256:7CCB3A50CA08C66A220E4DA614CBABA1D05157359EDD174223C788B86D929EDF | |||
| 7760 | TaxSpoolerInst-2-7-0-21.exe | C:\Users\admin\AppData\Local\Temp\pftC373.tmp\Disk1\data1.cab | compressed | |
MD5:2E4DC02E0EA354F7093D1B2D985A49D9 | SHA256:6EFC473D17F09460DD136FA890B2C81F78F236C490B94947B862C318E87D1C0A | |||
| 7760 | TaxSpoolerInst-2-7-0-21.exe | C:\Users\admin\AppData\Local\Temp\plfC2E4.tmp | ini | |
MD5:9EFCC61A0BAA38A6D7C67A05A97C7B87 | SHA256:7CCB3A50CA08C66A220E4DA614CBABA1D05157359EDD174223C788B86D929EDF | |||
| 7760 | TaxSpoolerInst-2-7-0-21.exe | C:\Users\admin\AppData\Local\Temp\pftC373.tmp\Disk1\ikernel.ex_ | binary | |
MD5:93B63F516482715A784BBEC3A0BF5F3A | SHA256:FBF95719B956B548B947436E29FEB18BB884E01F75AE31B05C030EBD76605249 | |||
| 7820 | Setup.exe | C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\temp.000 | executable | |
MD5:B3FD01873BD5FD163AB465779271C58F | SHA256:985EB55ECB750DA812876B8569D5F1999A30A24BCC54F9BAB4D3FC44DFEDB931 | |||
| 7912 | IKernel.exe | C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\ctor.dll | executable | |
MD5:003A6C011AAC993BCDE8C860988CE49B | SHA256:590BE865DDF8C8D0431D8F92AA3948CC3C1685FD0649D607776B81CD1E267D0A | |||
| 7760 | TaxSpoolerInst-2-7-0-21.exe | C:\Users\admin\AppData\Local\Temp\pftC373.tmp\Disk1\layout.bin | binary | |
MD5:2430BD57207EE8725D55EDBAE9A044CA | SHA256:F5949D5569E366E0915B539E0530E38912A7214D45D458FE71067B7FFE227C1D | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | GET | 200 | 23.53.40.178:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
8188 | SIHClient.exe | GET | 200 | 2.23.181.156:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
8188 | SIHClient.exe | GET | 200 | 2.23.181.156:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
— | — | 23.53.40.178:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
3216 | svchost.exe | 172.211.123.250:443 | client.wns.windows.com | MICROSOFT-CORP-MSN-AS-BLOCK | FR | whitelisted |
8188 | SIHClient.exe | 20.12.23.50:443 | slscr.update.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
8188 | SIHClient.exe | 2.23.181.156:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
8188 | SIHClient.exe | 40.69.42.241:443 | fe3cr.delivery.mp.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4040 | svchost.exe | 95.100.186.9:443 | go.microsoft.com | AKAMAI-AS | FR | whitelisted |
7408 | slui.exe | 20.83.72.98:443 | activation-v2.sls.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
fe3cr.delivery.mp.microsoft.com |
| whitelisted |
go.microsoft.com |
| whitelisted |
activation-v2.sls.microsoft.com |
| whitelisted |