File name:

MantraRDServiceIris_1.0.5.exe

Full analysis: https://app.any.run/tasks/5f6de6d5-e410-4a6f-b0e0-e6d3d311c811
Verdict: Malicious activity
Analysis date: May 04, 2024, 04:07:30
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

DAD7253B6028095D4A15ED4F29337ACE

SHA1:

147553167B31217F9A7F65A8D7081A5A4D7AF33E

SHA256:

B30405F9BF8F308DE9545DF3E4011A425F06051E557E73138FA35BB635943AFF

SSDEEP:

98304:m+QqZ8fZ9znDU3W3atJRnwCkiW3rZVBLOx8JByT3Ki1xKOulN00CELl5YQykQrRM:pAUKJCoCrmhd95g9gR5whZ+LF5ik

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • MantraRDServiceIris_1.0.5.exe (PID: 3972)
      • MantraRDServiceIris_1.0.5.exe (PID: 2104)
      • MantraRDServiceIris_1.0.5.tmp (PID: 2108)
    • Create files in the Startup directory

      • MantraRDServiceIris_1.0.5.tmp (PID: 2108)
    • Creates a writable file in the system directory

      • MantraRDIris.exe (PID: 1764)
      • wyUpdate.exe (PID: 1072)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • MantraRDServiceIris_1.0.5.exe (PID: 3972)
      • MantraRDServiceIris_1.0.5.exe (PID: 2104)
      • MantraRDServiceIris_1.0.5.tmp (PID: 2108)
    • Reads the Windows owner or organization settings

      • MantraRDServiceIris_1.0.5.tmp (PID: 2108)
    • The process drops C-runtime libraries

      • MantraRDServiceIris_1.0.5.tmp (PID: 2108)
    • Process drops legitimate windows executable

      • MantraRDServiceIris_1.0.5.tmp (PID: 2108)
    • Executing commands from a ".bat" file

      • MantraRDServiceIris_1.0.5.tmp (PID: 2108)
    • Starts CMD.EXE for commands execution

      • MantraRDServiceIris_1.0.5.tmp (PID: 2108)
    • Executes as Windows Service

      • MantraRDIris.exe (PID: 1764)
    • Reads security settings of Internet Explorer

      • InstallUtil.exe (PID: 1112)
      • MantraRDIris.exe (PID: 1764)
    • Reads the Internet Settings

      • InstallUtil.exe (PID: 1112)
      • MantraMIS100V2RDAutoConfigProxy.exe (PID: 1844)
    • Adds/modifies Windows certificates

      • MantraRDIris.exe (PID: 1764)
      • InstallUtil.exe (PID: 1112)
      • wyUpdate.exe (PID: 1072)
      • certutil.exe (PID: 2512)
    • Suspicious use of NETSH.EXE

      • MantraRDIris.exe (PID: 1764)
  • INFO

    • Checks supported languages

      • MantraRDServiceIris_1.0.5.tmp (PID: 3988)
      • MantraRDServiceIris_1.0.5.exe (PID: 3972)
      • MantraRDServiceIris_1.0.5.exe (PID: 2104)
      • MantraRDServiceIris_1.0.5.tmp (PID: 2108)
      • MantraAVDMUtilIris.exe (PID: 1876)
      • InstallUtil.exe (PID: 1112)
      • MantraRDIris.exe (PID: 1764)
      • MantraAVDMUtilIris.exe (PID: 1368)
      • MantraMIS100V2RDAutoConfigProxy.exe (PID: 1844)
      • wyUpdate.exe (PID: 1072)
      • ConfigMantraMIS100V2RDService.exe (PID: 2592)
      • wmpnscfg.exe (PID: 2396)
    • Reads the computer name

      • MantraRDServiceIris_1.0.5.tmp (PID: 3988)
      • MantraRDServiceIris_1.0.5.tmp (PID: 2108)
      • MantraAVDMUtilIris.exe (PID: 1876)
      • InstallUtil.exe (PID: 1112)
      • MantraRDIris.exe (PID: 1764)
      • MantraAVDMUtilIris.exe (PID: 1368)
      • MantraMIS100V2RDAutoConfigProxy.exe (PID: 1844)
      • wyUpdate.exe (PID: 1072)
      • wmpnscfg.exe (PID: 2396)
      • ConfigMantraMIS100V2RDService.exe (PID: 2592)
    • Create files in a temporary directory

      • MantraRDServiceIris_1.0.5.exe (PID: 3972)
      • MantraRDServiceIris_1.0.5.exe (PID: 2104)
    • Creates files in the program directory

      • MantraRDServiceIris_1.0.5.tmp (PID: 2108)
      • MantraRDIris.exe (PID: 1764)
      • InstallUtil.exe (PID: 1112)
      • certutil.exe (PID: 2512)
    • Creates a software uninstall entry

      • MantraRDServiceIris_1.0.5.tmp (PID: 2108)
    • Reads the machine GUID from the registry

      • MantraAVDMUtilIris.exe (PID: 1876)
      • InstallUtil.exe (PID: 1112)
      • MantraAVDMUtilIris.exe (PID: 1368)
      • MantraRDIris.exe (PID: 1764)
      • MantraMIS100V2RDAutoConfigProxy.exe (PID: 1844)
      • wyUpdate.exe (PID: 1072)
      • ConfigMantraMIS100V2RDService.exe (PID: 2592)
    • Reads Environment values

      • MantraMIS100V2RDAutoConfigProxy.exe (PID: 1844)
      • MantraRDIris.exe (PID: 1764)
      • wyUpdate.exe (PID: 1072)
    • Checks proxy server information

      • MantraRDIris.exe (PID: 1764)
    • Manual execution by a user

      • ConfigMantraMIS100V2RDService.exe (PID: 2592)
      • wmpnscfg.exe (PID: 2396)
    • Reads the software policy settings

      • certutil.exe (PID: 2512)
      • wyUpdate.exe (PID: 1072)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (67.7)
.exe | Win32 EXE PECompact compressed (generic) (25.6)
.exe | Win32 Executable (generic) (2.7)
.exe | Win16/32 Executable Delphi generic (1.2)
.exe | Generic Win/DOS Executable (1.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2021:06:03 08:09:11+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 741376
InitializedDataSize: 403456
UninitializedDataSize: -
EntryPoint: 0xb5eec
OSVersion: 6.1
ImageVersion: 6
SubsystemVersion: 6.1
Subsystem: Windows GUI
FileVersionNumber: 1.0.5.0
ProductVersionNumber: 1.0.5.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: Mantra Softech India Pvt Ltd
FileDescription: Mantra MIS100V2 Registered Device Service Production Setup
FileVersion: 1.0.5
LegalCopyright: Copyright © 2017 Mantra Softech India Pvt Ltd
OriginalFileName:
ProductName: Mantra MIS100V2 Registered Device Service Production
ProductVersion: 1.0.5
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
61
Monitored processes
18
Malicious processes
5
Suspicious processes
0

Behavior graph

Click at the process to see the details
start mantrardserviceiris_1.0.5.exe mantrardserviceiris_1.0.5.tmp no specs mantrardserviceiris_1.0.5.exe mantrardserviceiris_1.0.5.tmp mantraavdmutiliris.exe no specs cmd.exe no specs installutil.exe no specs mantrardiris.exe no specs mantraavdmutiliris.exe no specs mantramis100v2rdautoconfigproxy.exe no specs wyupdate.exe certutil.exe no specs configmantramis100v2rdservice.exe no specs netsh.exe no specs netsh.exe no specs netsh.exe no specs netsh.exe no specs wmpnscfg.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
328"C:\Windows\system32\cmd.exe" /C ""C:\Program Files\Mantra\RDService\MIS100V2\InstallRD.bat""C:\Windows\System32\cmd.exeMantraRDServiceIris_1.0.5.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1072"C:\Program Files\Mantra\RDService\MIS100V2\wyUpdate.exe" /autoupdateC:\Program Files\Mantra\RDService\MIS100V2\wyUpdate.exe
MantraRDIris.exe
User:
SYSTEM
Company:
wyDay
Integrity Level:
SYSTEM
Description:
wyUpdate
Exit code:
3
Version:
2.9.0.0
Modules
Images
c:\program files\mantra\rdservice\mis100v2\wyupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1112C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil "C:\Program Files\Mantra\RDService\MIS100V2\MantraRDIris.exe"C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
.NET Framework installation utility
Exit code:
0
Version:
4.8.3761.0 built by: NET48REL1
Modules
Images
c:\windows\microsoft.net\framework\v4.0.30319\installutil.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1368"C:\Program Files\Mantra\RDService\MIS100V2\MantraAVDMUtilIris.exe"C:\Program Files\Mantra\RDService\MIS100V2\MantraAVDMUtilIris.exeMantraRDIris.exe
User:
admin
Company:
MANTRA Softech India Pvt Ltd
Integrity Level:
MEDIUM
Description:
MantraAVDMUtilIris
Version:
1.0.0.0
Modules
Images
c:\program files\mantra\rdservice\mis100v2\mantraavdmutiliris.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1696"C:\Windows\system32\netsh.exe" http delete sslcert ipport=0.0.0.0:8005C:\Windows\System32\netsh.exeMantraRDIris.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Network Command Shell
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\netsh.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\credui.dll
c:\windows\system32\user32.dll
1764"C:\Program Files\Mantra\RDService\MIS100V2\MantraRDIris.exe"C:\Program Files\Mantra\RDService\MIS100V2\MantraRDIris.exeservices.exe
User:
SYSTEM
Company:
MANTRA Softech India Pvt Ltd
Integrity Level:
SYSTEM
Description:
MantraRDIris
Version:
1.0.0.0
Modules
Images
c:\program files\mantra\rdservice\mis100v2\mantrardiris.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1844"C:\Program Files\Mantra\RDService\MIS100V2\MantraMIS100V2RDAutoConfigProxy.exe"C:\Program Files\Mantra\RDService\MIS100V2\MantraMIS100V2RDAutoConfigProxy.exeMantraRDServiceIris_1.0.5.tmp
User:
admin
Company:
Microsoft
Integrity Level:
HIGH
Description:
MantraRDAutoConfigProxy
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\program files\mantra\rdservice\mis100v2\mantramis100v2rdautoconfigproxy.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1876"C:\Program Files\Mantra\RDService\MIS100V2\MantraAVDMUtilIris.exe"C:\Program Files\Mantra\RDService\MIS100V2\MantraAVDMUtilIris.exeMantraRDServiceIris_1.0.5.tmp
User:
admin
Company:
MANTRA Softech India Pvt Ltd
Integrity Level:
HIGH
Description:
MantraAVDMUtilIris
Exit code:
4294967295
Version:
1.0.0.0
Modules
Images
c:\program files\mantra\rdservice\mis100v2\mantraavdmutiliris.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1964"C:\Windows\system32\netsh.exe" http add sslcert ipport=0.0.0.0:11100 certhash=3CA04B0874EB980469A3DFC28EF222E5BD1F0499 appid={233bb249-37d9-42d0-9179-70d7c05cfbb0} clientcertnegotiation=enableC:\Windows\System32\netsh.exeMantraRDIris.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Network Command Shell
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\netsh.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\credui.dll
c:\windows\system32\user32.dll
2104"C:\Users\admin\AppData\Local\Temp\MantraRDServiceIris_1.0.5.exe" /SPAWNWND=$40130 /NOTIFYWND=$20138 C:\Users\admin\AppData\Local\Temp\MantraRDServiceIris_1.0.5.exe
MantraRDServiceIris_1.0.5.tmp
User:
admin
Company:
Mantra Softech India Pvt Ltd
Integrity Level:
HIGH
Description:
Mantra MIS100V2 Registered Device Service Production Setup
Exit code:
0
Version:
1.0.5
Modules
Images
c:\users\admin\appdata\local\temp\mantrardserviceiris_1.0.5.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
Total events
36 673
Read events
36 273
Write events
346
Delete events
54

Modification events

(PID) Process:(2108) MantraRDServiceIris_1.0.5.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
3C080000E2F6F69BD89DDA01
(PID) Process:(2108) MantraRDServiceIris_1.0.5.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:SessionHash
Value:
C1A7CECB7FF8CDC09C247801C053E30FB97FD8217FD66F3805C864036ED3C16A
(PID) Process:(2108) MantraRDServiceIris_1.0.5.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Sequence
Value:
1
(PID) Process:(2108) MantraRDServiceIris_1.0.5.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:RegFiles0000
Value:
C:\Program Files\Mantra\RDService\MIS100V2\AutomaticUpdater.dll
(PID) Process:(2108) MantraRDServiceIris_1.0.5.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:RegFilesHash
Value:
592DB2BC2FD2AB657FA2FA9E1D7D9C60BC5C1AD2265DE581543CF2D5287DBFD0
(PID) Process:(2108) MantraRDServiceIris_1.0.5.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Mantra\RDService\MIS100V2
Operation:writeName:Version
Value:
1050
(PID) Process:(2108) MantraRDServiceIris_1.0.5.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{06EE4D59-F3C7-486C-963F-EDAA420AA95C}_is1
Operation:writeName:Inno Setup: Setup Version
Value:
6.2.0
(PID) Process:(2108) MantraRDServiceIris_1.0.5.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{06EE4D59-F3C7-486C-963F-EDAA420AA95C}_is1
Operation:writeName:Inno Setup: App Path
Value:
C:\Program Files\Mantra\RDService\MIS100V2
(PID) Process:(2108) MantraRDServiceIris_1.0.5.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{06EE4D59-F3C7-486C-963F-EDAA420AA95C}_is1
Operation:writeName:InstallLocation
Value:
C:\Program Files\Mantra\RDService\MIS100V2\
(PID) Process:(2108) MantraRDServiceIris_1.0.5.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{06EE4D59-F3C7-486C-963F-EDAA420AA95C}_is1
Operation:writeName:Inno Setup: Icon Group
Value:
(Default)
Executable files
68
Suspicious files
26
Text files
15
Unknown types
3

Dropped files

PID
Process
Filename
Type
2108MantraRDServiceIris_1.0.5.tmpC:\Program Files\Mantra\RDService\MIS100V2\is-91BOG.tmp
MD5:
SHA256:
2108MantraRDServiceIris_1.0.5.tmpC:\Program Files\Mantra\RDService\MIS100V2\AutomaticUpdater.dll
MD5:
SHA256:
2108MantraRDServiceIris_1.0.5.tmpC:\Program Files\Mantra\RDService\MIS100V2\is-3SDN5.tmp
MD5:
SHA256:
2108MantraRDServiceIris_1.0.5.tmpC:\Program Files\Mantra\RDService\MIS100V2\client.wyc
MD5:
SHA256:
2108MantraRDServiceIris_1.0.5.tmpC:\Program Files\Mantra\RDService\MIS100V2\is-IDED3.tmp
MD5:
SHA256:
2108MantraRDServiceIris_1.0.5.tmpC:\Program Files\Mantra\RDService\MIS100V2\ConfigMantraMIS100V2RDService.exe
MD5:
SHA256:
2108MantraRDServiceIris_1.0.5.tmpC:\Program Files\Mantra\RDService\MIS100V2\is-1L8GC.tmp
MD5:
SHA256:
2108MantraRDServiceIris_1.0.5.tmpC:\Program Files\Mantra\RDService\MIS100V2\InstallRD.bat
MD5:
SHA256:
2108MantraRDServiceIris_1.0.5.tmpC:\Program Files\Mantra\RDService\MIS100V2\is-VH2K6.tmp
MD5:
SHA256:
2108MantraRDServiceIris_1.0.5.tmpC:\Program Files\Mantra\RDService\MIS100V2\iris_engine_v3.dll
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
5
DNS requests
2
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1072
wyUpdate.exe
GET
200
103.156.134.87:80
http://repository.emsign.com/certs/emSignSSLCAG1.crt
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
unknown
4
System
192.168.100.255:137
whitelisted
224.0.0.252:5355
unknown
1072
wyUpdate.exe
45.119.11.66:443
fw.aadhaardevice.com
Ishans Network
IN
unknown
1072
wyUpdate.exe
103.156.134.87:80
repository.emsign.com
eMudhra Limited
IN
unknown

DNS requests

Domain
IP
Reputation
fw.aadhaardevice.com
  • 45.119.11.66
unknown
repository.emsign.com
  • 103.156.134.87
unknown

Threats

No threats detected
No debug info