File name:

ResetEpsonL3152EN.exe

Full analysis: https://app.any.run/tasks/4568a289-8aa4-4db3-ad1d-a34c417a4e6f
Verdict: Malicious activity
Analysis date: March 14, 2024, 12:38:30
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

888BBBB4761D24C2937137B104BEAEDC

SHA1:

AE16B4807EAEBD58D54B65DD515F3C8A071BD872

SHA256:

B7513B8A25CD4C84AA54518616C518AA4B68E4A8610185BF1565D2AAFC60EB64

SSDEEP:

98304:LbUOrfK+9NJd4ph9zMTXpRoKekhMVud2ZW3FoHyG2nDgHazHSSY7ILT8YHLnUTYy:AzhWxY

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • ResetEpsonL3152EN.exe (PID: 2472)
      • ResetEpsonL3152EN.exe (PID: 3464)
      • ResetEpsonL3152EN.tmp (PID: 3932)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • ResetEpsonL3152EN.exe (PID: 2472)
      • ResetEpsonL3152EN.exe (PID: 3464)
      • ResetEpsonL3152EN.tmp (PID: 3932)
    • Reads the Windows owner or organization settings

      • ResetEpsonL3152EN.tmp (PID: 3932)
    • Non-standard symbols in registry

      • ResetEpsonL3152EN.tmp (PID: 3932)
  • INFO

    • Create files in a temporary directory

      • ResetEpsonL3152EN.exe (PID: 3464)
      • ResetEpsonL3152EN.exe (PID: 2472)
    • Reads the computer name

      • ResetEpsonL3152EN.tmp (PID: 3932)
      • ResetEpsonL3152EN.tmp (PID: 3700)
      • Reset Epson L3152-EN.exe (PID: 3212)
    • Checks supported languages

      • ResetEpsonL3152EN.tmp (PID: 3700)
      • ResetEpsonL3152EN.exe (PID: 2472)
      • ResetEpsonL3152EN.exe (PID: 3464)
      • ResetEpsonL3152EN.tmp (PID: 3932)
      • Reset Epson L3152-EN.exe (PID: 3212)
    • Creates files in the program directory

      • ResetEpsonL3152EN.tmp (PID: 3932)
    • Creates a software uninstall entry

      • ResetEpsonL3152EN.tmp (PID: 3932)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (67.7)
.exe | Win32 EXE PECompact compressed (generic) (25.6)
.exe | Win32 Executable (generic) (2.7)
.exe | Win16/32 Executable Delphi generic (1.2)
.exe | Generic Win/DOS Executable (1.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2019:10:12 11:15:57+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 682496
InitializedDataSize: 87552
UninitializedDataSize: -
EntryPoint: 0xa7ed0
OSVersion: 6
ImageVersion: 6
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 0.0.0.0
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: RESETEPSONAP
FileDescription: Reset Epson L3152 EN Setup
FileVersion:
LegalCopyright:
OriginalFileName:
ProductName: Reset Epson L3152 EN
ProductVersion: 2.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
43
Monitored processes
5
Malicious processes
3
Suspicious processes
1

Behavior graph

Click at the process to see the details
start resetepsonl3152en.exe resetepsonl3152en.tmp no specs resetepsonl3152en.exe resetepsonl3152en.tmp reset epson l3152-en.exe

Process information

PID
CMD
Path
Indicators
Parent process
2472"C:\Users\admin\Desktop\ResetEpsonL3152EN.exe" C:\Users\admin\Desktop\ResetEpsonL3152EN.exe
explorer.exe
User:
admin
Company:
RESETEPSONAP
Integrity Level:
MEDIUM
Description:
Reset Epson L3152 EN Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\desktop\resetepsonl3152en.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3212"C:\Program Files\Reset Epson L3152 EN\Reset Epson L3152-EN.exe"C:\Program Files\Reset Epson L3152 EN\Reset Epson L3152-EN.exe
ResetEpsonL3152EN.tmp
User:
admin
Integrity Level:
MEDIUM
Description:
Adjustment program for EPSON Inkjet Printer / Scanner
Exit code:
0
Version:
1, 0, 0, 0
Modules
Images
c:\program files\reset epson l3152 en\reset epson l3152-en.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
3464"C:\Users\admin\Desktop\ResetEpsonL3152EN.exe" /SPAWNWND=$18013E /NOTIFYWND=$E0170 C:\Users\admin\Desktop\ResetEpsonL3152EN.exe
ResetEpsonL3152EN.tmp
User:
admin
Company:
RESETEPSONAP
Integrity Level:
HIGH
Description:
Reset Epson L3152 EN Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\desktop\resetepsonl3152en.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3700"C:\Users\admin\AppData\Local\Temp\is-LL5IP.tmp\ResetEpsonL3152EN.tmp" /SL5="$E0170,4267224,771072,C:\Users\admin\Desktop\ResetEpsonL3152EN.exe" C:\Users\admin\AppData\Local\Temp\is-LL5IP.tmp\ResetEpsonL3152EN.tmpResetEpsonL3152EN.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-ll5ip.tmp\resetepsonl3152en.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3932"C:\Users\admin\AppData\Local\Temp\is-0I95C.tmp\ResetEpsonL3152EN.tmp" /SL5="$1801B0,4267224,771072,C:\Users\admin\Desktop\ResetEpsonL3152EN.exe" /SPAWNWND=$18013E /NOTIFYWND=$E0170 C:\Users\admin\AppData\Local\Temp\is-0I95C.tmp\ResetEpsonL3152EN.tmp
ResetEpsonL3152EN.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-0i95c.tmp\resetepsonl3152en.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
Total events
1 770
Read events
1 734
Write events
29
Delete events
7

Modification events

(PID) Process:(3932) ResetEpsonL3152EN.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
5C0F0000F277D18D0C76DA01
(PID) Process:(3932) ResetEpsonL3152EN.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:SessionHash
Value:
90E8E4BB6F0486AC8DF96F7B14D069C31745F04DF723FF3C45778694E087EB7D
(PID) Process:(3932) ResetEpsonL3152EN.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Sequence
Value:
1
(PID) Process:(3932) ResetEpsonL3152EN.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:RegFiles0000
Value:
C:\Program Files\Reset Epson L3152 EN\Reset Epson L3152-EN.exe
(PID) Process:(3932) ResetEpsonL3152EN.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:RegFilesHash
Value:
377F34A6523CE58D993A0FCD738B98650840533C109C6473D884B303D79A4C56
(PID) Process:(3932) ResetEpsonL3152EN.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{504A416F-74F3-44B8-8400-58577DB3F80A}_is1
Operation:writeName:Inno Setup: Setup Version
Value:
6.0.3 (u)
(PID) Process:(3932) ResetEpsonL3152EN.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{504A416F-74F3-44B8-8400-58577DB3F80A}_is1
Operation:writeName:Inno Setup: App Path
Value:
C:\Program Files\Reset Epson L3152 EN
(PID) Process:(3932) ResetEpsonL3152EN.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{504A416F-74F3-44B8-8400-58577DB3F80A}_is1
Operation:writeName:InstallLocation
Value:
C:\Program Files\Reset Epson L3152 EN\
(PID) Process:(3932) ResetEpsonL3152EN.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{504A416F-74F3-44B8-8400-58577DB3F80A}_is1
Operation:writeName:Inno Setup: Icon Group
Value:
(Default)
(PID) Process:(3932) ResetEpsonL3152EN.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{504A416F-74F3-44B8-8400-58577DB3F80A}_is1
Operation:writeName:Inno Setup: User
Value:
admin
Executable files
10
Suspicious files
2
Text files
2
Unknown types
0

Dropped files

PID
Process
Filename
Type
3932ResetEpsonL3152EN.tmpC:\Program Files\Reset Epson L3152 EN\unins000.exeexecutable
MD5:EE4BFA12DFA215810BBECB58808A2218
SHA256:54CACD1D64048179F29C1BBACAE554A08B79E17FB0B9E7621BE40CA6046B1DF9
3464ResetEpsonL3152EN.exeC:\Users\admin\AppData\Local\Temp\is-0I95C.tmp\ResetEpsonL3152EN.tmpexecutable
MD5:E777329ACDFC5104D414191112BFAC35
SHA256:3B0C7CB85DF6EE44C95FBC1EE76635535CDD5A63DF730BDE4301E581F13B25C4
3932ResetEpsonL3152EN.tmpC:\Program Files\Reset Epson L3152 EN\is-R6HF1.tmpexecutable
MD5:EE4BFA12DFA215810BBECB58808A2218
SHA256:54CACD1D64048179F29C1BBACAE554A08B79E17FB0B9E7621BE40CA6046B1DF9
3932ResetEpsonL3152EN.tmpC:\Program Files\Reset Epson L3152 EN\is-FC63H.tmpexecutable
MD5:7BC6071301F011EDFE115026A5E3A20D
SHA256:F2277C9F1F477A6BD06B4645BD818E241CE8352395B4D67BAB87583AAEBD36FD
3932ResetEpsonL3152EN.tmpC:\Program Files\Reset Epson L3152 EN\is-GI46A.tmpexecutable
MD5:0CF43737C5D063A82B788D56206B43C5
SHA256:8E731F4D1DDDB9A46031F3D863425C62BFD16DD755925D42FA6D5F707B27F6D6
3932ResetEpsonL3152EN.tmpC:\Program Files\Reset Epson L3152 EN\Reset Epson L3152-EN.exeexecutable
MD5:451F0E23C3D58E9CCBA9280CD1FC31FF
SHA256:F0E1110CCC013617361A8031D19E80F4895E68A19E47D20FD2FD37C51EA50143
3932ResetEpsonL3152EN.tmpC:\Program Files\Reset Epson L3152 EN\Logo.icoimage
MD5:DE2089B8AA259F2A3652EF169777A99D
SHA256:26F3F37CEED827BA62173FB6E96E8FF1DC63809EFBB57040828513F8FFD2A88A
3932ResetEpsonL3152EN.tmpC:\Program Files\Reset Epson L3152 EN\apdadrv.dllexecutable
MD5:7BC6071301F011EDFE115026A5E3A20D
SHA256:F2277C9F1F477A6BD06B4645BD818E241CE8352395B4D67BAB87583AAEBD36FD
3932ResetEpsonL3152EN.tmpC:\Program Files\Reset Epson L3152 EN\is-K031T.tmpexecutable
MD5:451F0E23C3D58E9CCBA9280CD1FC31FF
SHA256:F0E1110CCC013617361A8031D19E80F4895E68A19E47D20FD2FD37C51EA50143
2472ResetEpsonL3152EN.exeC:\Users\admin\AppData\Local\Temp\is-LL5IP.tmp\ResetEpsonL3152EN.tmpexecutable
MD5:E777329ACDFC5104D414191112BFAC35
SHA256:3B0C7CB85DF6EE44C95FBC1EE76635535CDD5A63DF730BDE4301E581F13B25C4
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
6
DNS requests
3
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3212
Reset Epson L3152-EN.exe
POST
200
64.22.104.168:80
http://ls014012.softwareprotection.info/index.php/remote
unknown
xml
588 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
3212
Reset Epson L3152-EN.exe
64.22.104.168:80
ls014012.softwareprotection.info
NTHL
US
unknown

DNS requests

Domain
IP
Reputation
ls014012.softwareprotection.info
  • 64.22.104.168
unknown
dns.msftncsi.com
  • 131.107.255.255
shared

Threats

No threats detected
No debug info