File name:

TaxSpoolerInst-2-7-0-21.exe

Full analysis: https://app.any.run/tasks/d3797b57-a96a-400d-9543-f1107deb500c
Verdict: Malicious activity
Analysis date: April 10, 2025, 12:48:43
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, InstallShield self-extracting archive, 4 sections
MD5:

6DB87DD5CD51CAD37E879436E3CBA54E

SHA1:

EA203707356F1A7C5914B913354808B11C3BB9A6

SHA256:

B10A810A35E4693CE507B0CB6BB0401E7EF9A0668DCBF52CBC62E776A198BC9D

SSDEEP:

98304:Ye23J202hV+1Lrnl/daXwalOpwK6DqMxaUaCaKwR+NKW//GfubQYBcaVXru0K7pD:O9Bl+2UgF2eOXK4pmtnEG

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Create files in the Startup directory

      • IKernel.exe (PID: 7912)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • TaxSpoolerInst-2-7-0-21.exe (PID: 7760)
      • Setup.exe (PID: 7820)
      • IKernel.exe (PID: 7912)
    • Reads security settings of Internet Explorer

      • IKernel.exe (PID: 7840)
      • IKernel.exe (PID: 7968)
    • Application launched itself

      • IKernel.exe (PID: 7912)
    • There is functionality for taking screenshot (YARA)

      • TaxSpoolerInst-2-7-0-21.exe (PID: 7760)
      • Setup.exe (PID: 7820)
      • IKernel.exe (PID: 7912)
    • Executes as Windows Service

      • VSSVC.exe (PID: 7296)
    • Creates a software uninstall entry

      • IKernel.exe (PID: 7912)
    • Process drops SQLite DLL files

      • IKernel.exe (PID: 7912)
    • Creates/Modifies COM task schedule object

      • IKernel.exe (PID: 7912)
    • Searches for installed software

      • dllhost.exe (PID: 6620)
  • INFO

    • Create files in a temporary directory

      • TaxSpoolerInst-2-7-0-21.exe (PID: 7760)
      • Setup.exe (PID: 7820)
      • IKernel.exe (PID: 7912)
    • Checks supported languages

      • TaxSpoolerInst-2-7-0-21.exe (PID: 7760)
      • Setup.exe (PID: 7820)
      • IKernel.exe (PID: 7840)
      • IKernel.exe (PID: 7912)
      • IKernel.exe (PID: 7968)
      • TaxService.exe (PID: 7368)
    • Reads the computer name

      • TaxSpoolerInst-2-7-0-21.exe (PID: 7760)
      • Setup.exe (PID: 7820)
      • IKernel.exe (PID: 7840)
      • IKernel.exe (PID: 7912)
      • IKernel.exe (PID: 7968)
    • The sample compiled with english language support

      • TaxSpoolerInst-2-7-0-21.exe (PID: 7760)
      • Setup.exe (PID: 7820)
      • IKernel.exe (PID: 7912)
    • Creates files in the program directory

      • Setup.exe (PID: 7820)
      • IKernel.exe (PID: 7912)
    • Checks proxy server information

      • IKernel.exe (PID: 7840)
      • IKernel.exe (PID: 7968)
    • Manages system restore points

      • SrTasks.exe (PID: 5800)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | InstallShield setup (36.8)
.exe | Win32 Executable MS Visual C++ (generic) (26.6)
.exe | Win64 Executable (generic) (23.6)
.dll | Win32 Dynamic Link Library (generic) (5.6)
.exe | Win32 Executable (generic) (3.8)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2001:09:05 17:02:57+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 73728
InitializedDataSize: 212992
UninitializedDataSize: -
EntryPoint: 0x8947
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 4.0.100.1190
ProductVersionNumber: 4.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
Comments:
CompanyName: INCA Hellas Ltd.
FileDescription:
InternalName: stub32
OriginalFileName: stub32i.exe
FileVersion: 1.00.000
LegalCopyright: INCA Hellas Ltd.
ProductName: TaxSpoolerInst
ProductVersion: 1.00.000
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
135
Monitored processes
12
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start taxspoolerinst-2-7-0-21.exe setup.exe ikernel.exe no specs ikernel.exe ikernel.exe no specs SPPSurrogate no specs vssvc.exe no specs srtasks.exe no specs conhost.exe no specs taxservice.exe no specs slui.exe no specs taxspoolerinst-2-7-0-21.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
5064\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeSrTasks.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
5800C:\WINDOWS\system32\srtasks.exe ExecuteScopeRestorePoint /WaitForRestorePoint:11C:\Windows\System32\SrTasks.exedllhost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft® Windows System Protection background tasks.
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\srtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
6620C:\WINDOWS\system32\DllHost.exe /Processid:{F32D97DF-E3E5-4CB9-9E3E-0EB5B4E49801}C:\Windows\System32\dllhost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
COM Surrogate
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\dllhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\msvcrt.dll
7296C:\WINDOWS\system32\vssvc.exeC:\Windows\System32\VSSVC.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Volume Shadow Copy Service
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\vssvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
7368"C:\Program Files (x86)\INCA Hellas\TaxSpooler\TaxService.exe" /INSTALLC:\Program Files (x86)\INCA Hellas\TaxSpooler\TaxService.exeIKernel.exe
User:
admin
Company:
Metafuture Ltd
Integrity Level:
HIGH
Description:
TaxSpooler Service
Version:
2.7.0.21
Modules
Images
c:\program files (x86)\inca hellas\taxspooler\taxservice.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acgenral.dll
7512C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
7664"C:\Users\admin\AppData\Local\Temp\TaxSpoolerInst-2-7-0-21.exe" C:\Users\admin\AppData\Local\Temp\TaxSpoolerInst-2-7-0-21.exeexplorer.exe
User:
admin
Company:
INCA Hellas Ltd.
Integrity Level:
MEDIUM
Description:
Exit code:
3221226540
Version:
1.00.000
Modules
Images
c:\users\admin\appdata\local\temp\taxspoolerinst-2-7-0-21.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
7760"C:\Users\admin\AppData\Local\Temp\TaxSpoolerInst-2-7-0-21.exe" C:\Users\admin\AppData\Local\Temp\TaxSpoolerInst-2-7-0-21.exe
explorer.exe
User:
admin
Company:
INCA Hellas Ltd.
Integrity Level:
HIGH
Description:
Version:
1.00.000
Modules
Images
c:\users\admin\appdata\local\temp\taxspoolerinst-2-7-0-21.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acgenral.dll
7820"C:\Users\admin\AppData\Local\Temp\pftC373.tmp\Disk1\Setup.exe"C:\Users\admin\AppData\Local\Temp\pftC373.tmp\Disk1\Setup.exe
TaxSpoolerInst-2-7-0-21.exe
User:
admin
Company:
InstallShield Software Corporation
Integrity Level:
HIGH
Description:
InstallShield (R) Setup Launcher
Version:
6, 31, 100, 1190
Modules
Images
c:\users\admin\appdata\local\temp\pftc373.tmp\disk1\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acspecfc.dll
7840"C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe" -RegServerC:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exeSetup.exe
User:
admin
Company:
InstallShield Software Corporation
Integrity Level:
HIGH
Description:
InstallShield (R) Setup Engine
Exit code:
0
Version:
6, 31, 100, 1221
Modules
Images
c:\program files (x86)\common files\installshield\engine\6\intel 32\ikernel.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acspecfc.dll
Total events
3 160
Read events
2 777
Write events
365
Delete events
18

Modification events

(PID) Process:(7840) IKernel.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{AA7E2068-CB55-11D2-8094-00104B1F9838}\TypeLib
Operation:writeName:Version
Value:
1.0
(PID) Process:(7840) IKernel.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{AA7E2068-CB55-11D2-8094-00104B1F9838}\TypeLib
Operation:writeName:Version
Value:
1.0
(PID) Process:(7840) IKernel.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{AA7E2066-CB55-11D2-8094-00104B1F9838}\TypeLib
Operation:writeName:Version
Value:
1.0
(PID) Process:(7840) IKernel.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{AA7E2066-CB55-11D2-8094-00104B1F9838}\TypeLib
Operation:writeName:Version
Value:
1.0
(PID) Process:(7840) IKernel.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{CC096170-E2CB-11D2-80C8-00104B1F6CEA}\TypeLib
Operation:writeName:Version
Value:
1.0
(PID) Process:(7840) IKernel.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{CC096170-E2CB-11D2-80C8-00104B1F6CEA}\TypeLib
Operation:writeName:Version
Value:
1.0
(PID) Process:(7840) IKernel.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{8C3C1B11-E59D-11D2-B40B-00A024B9DDDD}\TypeLib
Operation:writeName:Version
Value:
1.0
(PID) Process:(7840) IKernel.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8C3C1B11-E59D-11D2-B40B-00A024B9DDDD}\TypeLib
Operation:writeName:Version
Value:
1.0
(PID) Process:(7840) IKernel.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{8C3C1B13-E59D-11D2-B40B-00A024B9DDDD}\TypeLib
Operation:writeName:Version
Value:
1.0
(PID) Process:(7840) IKernel.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8C3C1B13-E59D-11D2-B40B-00A024B9DDDD}\TypeLib
Operation:writeName:Version
Value:
1.0
Executable files
115
Suspicious files
141
Text files
142
Unknown types
1

Dropped files

PID
Process
Filename
Type
7760TaxSpoolerInst-2-7-0-21.exeC:\Users\admin\AppData\Local\Temp\pftC373.tmp\pftw1.pkg
MD5:
SHA256:
7760TaxSpoolerInst-2-7-0-21.exeC:\Users\admin\AppData\Local\Temp\pftC373.tmp\Disk1\data2.cab
MD5:
SHA256:
7760TaxSpoolerInst-2-7-0-21.exeC:\Users\admin\AppData\Local\Temp\pftC373.tmp\Disk1\data1.hdrcompressed
MD5:42F87E10A20C5F16EC5CCC838DB492A8
SHA256:44E0CA4735019206CA80B7BFDE5F326150BCA048F83B5EE14731FB880A8C9354
7760TaxSpoolerInst-2-7-0-21.exeC:\Users\admin\AppData\Local\Temp\extC2E5.tmptext
MD5:9EFCC61A0BAA38A6D7C67A05A97C7B87
SHA256:7CCB3A50CA08C66A220E4DA614CBABA1D05157359EDD174223C788B86D929EDF
7760TaxSpoolerInst-2-7-0-21.exeC:\Users\admin\AppData\Local\Temp\pftC373.tmp\Disk1\data1.cabcompressed
MD5:2E4DC02E0EA354F7093D1B2D985A49D9
SHA256:6EFC473D17F09460DD136FA890B2C81F78F236C490B94947B862C318E87D1C0A
7760TaxSpoolerInst-2-7-0-21.exeC:\Users\admin\AppData\Local\Temp\plfC2E4.tmpini
MD5:9EFCC61A0BAA38A6D7C67A05A97C7B87
SHA256:7CCB3A50CA08C66A220E4DA614CBABA1D05157359EDD174223C788B86D929EDF
7760TaxSpoolerInst-2-7-0-21.exeC:\Users\admin\AppData\Local\Temp\pftC373.tmp\Disk1\ikernel.ex_binary
MD5:93B63F516482715A784BBEC3A0BF5F3A
SHA256:FBF95719B956B548B947436E29FEB18BB884E01F75AE31B05C030EBD76605249
7820Setup.exeC:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\temp.000executable
MD5:B3FD01873BD5FD163AB465779271C58F
SHA256:985EB55ECB750DA812876B8569D5F1999A30A24BCC54F9BAB4D3FC44DFEDB931
7912IKernel.exeC:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\ctor.dllexecutable
MD5:003A6C011AAC993BCDE8C860988CE49B
SHA256:590BE865DDF8C8D0431D8F92AA3948CC3C1685FD0649D607776B81CD1E267D0A
7760TaxSpoolerInst-2-7-0-21.exeC:\Users\admin\AppData\Local\Temp\pftC373.tmp\Disk1\layout.binbinary
MD5:2430BD57207EE8725D55EDBAE9A044CA
SHA256:F5949D5569E366E0915B539E0530E38912A7214D45D458FE71067B7FFE227C1D
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
3
TCP/UDP connections
23
DNS requests
11
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
23.53.40.178:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
8188
SIHClient.exe
GET
200
2.23.181.156:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
8188
SIHClient.exe
GET
200
2.23.181.156:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
23.53.40.178:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
3216
svchost.exe
172.211.123.250:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
8188
SIHClient.exe
20.12.23.50:443
slscr.update.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
8188
SIHClient.exe
2.23.181.156:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
8188
SIHClient.exe
40.69.42.241:443
fe3cr.delivery.mp.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4040
svchost.exe
95.100.186.9:443
go.microsoft.com
AKAMAI-AS
FR
whitelisted
7408
slui.exe
20.83.72.98:443
activation-v2.sls.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
whitelisted
crl.microsoft.com
  • 23.53.40.178
  • 23.53.40.176
whitelisted
google.com
  • 172.217.23.110
whitelisted
client.wns.windows.com
  • 172.211.123.250
whitelisted
slscr.update.microsoft.com
  • 20.12.23.50
whitelisted
www.microsoft.com
  • 2.23.181.156
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 40.69.42.241
whitelisted
go.microsoft.com
  • 95.100.186.9
whitelisted
activation-v2.sls.microsoft.com
  • 20.83.72.98
whitelisted

Threats

No threats detected
No debug info