File name:

sp84785.exe

Full analysis: https://app.any.run/tasks/f2d1e660-6fbd-4b38-b6b6-fa0b8c992205
Verdict: Malicious activity
Analysis date: May 26, 2024, 15:32:06
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

84419C556123EB7B7B7841A416BDFFE5

SHA1:

58AD3B81E78EDA002C0D12F34113A8661360FF3D

SHA256:

BBE398354F1BCCB781B7FDDBADBE19361B952F630D45F4FA5C951C590F70802E

SSDEEP:

98304:hgH3/RkG7vlZAqL1NhCoop2jJsHiZ5pEcDlCg9e2PS9yoNDkdZXVntBzdy3uU7xq:JEDMN/UQQWvVSOl

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • sp84785.exe (PID: 1120)
      • setup.exe (PID: 2116)
      • RTINSTALLER32.EXE (PID: 1824)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • sp84785.exe (PID: 1120)
      • setup.exe (PID: 2116)
      • RTINSTALLER32.EXE (PID: 1824)
    • Drops a system driver (possible attempt to evade defenses)

      • sp84785.exe (PID: 1120)
      • setup.exe (PID: 2116)
      • RTINSTALLER32.EXE (PID: 1824)
    • Searches for installed software

      • setup.exe (PID: 2116)
    • Reads the Windows owner or organization settings

      • setup.exe (PID: 2116)
    • Executes as Windows Service

      • VSSVC.exe (PID: 2024)
  • INFO

    • Checks supported languages

      • sp84785.exe (PID: 1120)
      • setup.exe (PID: 2116)
      • RTINSTALLER32.EXE (PID: 1836)
      • RTINSTALLER32.EXE (PID: 1824)
      • drvinst.exe (PID: 1548)
    • Create files in a temporary directory

      • sp84785.exe (PID: 1120)
      • setup.exe (PID: 2116)
      • RTINSTALLER32.EXE (PID: 1824)
    • Reads the computer name

      • setup.exe (PID: 2116)
      • RTINSTALLER32.EXE (PID: 1836)
      • RTINSTALLER32.EXE (PID: 1824)
      • drvinst.exe (PID: 1548)
    • Reads the machine GUID from the registry

      • setup.exe (PID: 2116)
      • RTINSTALLER32.EXE (PID: 1824)
      • drvinst.exe (PID: 1548)
    • Creates files in the program directory

      • setup.exe (PID: 2116)
      • RTINSTALLER32.EXE (PID: 1836)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | InstallShield setup (36.8)
.exe | Win32 Executable MS Visual C++ (generic) (26.6)
.exe | Win64 Executable (generic) (23.6)
.dll | Win32 Dynamic Link Library (generic) (5.6)
.exe | Win32 Executable (generic) (3.8)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2001:08:29 21:22:49+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 73728
InitializedDataSize: 212992
UninitializedDataSize: -
EntryPoint: 0x8927
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 4.0.100.1189
ProductVersionNumber: 4.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
Comments:
CompanyName: Hewlett-Packard Company
FileDescription: Realtek Ethernet Controller Drivers (DTO)
InternalName: stub32
OriginalFileName: stub32i.exe
FileVersion: 10.23.1003.2017
LegalCopyright:
ProductName: Realtek Ethernet Controller Drivers (DTO)
ProductVersion: 10.23.1003.2017
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
43
Monitored processes
7
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start sp84785.exe setup.exe vssvc.exe no specs rtinstaller32.exe no specs rtinstaller32.exe drvinst.exe no specs sp84785.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1120"C:\Users\admin\Desktop\sp84785.exe" C:\Users\admin\Desktop\sp84785.exe
explorer.exe
User:
admin
Company:
Hewlett-Packard Company
Integrity Level:
HIGH
Description:
Realtek Ethernet Controller Drivers (DTO)
Version:
10.23.1003.2017
Modules
Images
c:\users\admin\desktop\sp84785.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
1548DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{6963e3d6-aa29-779c-fe1d-257a5a0aa60a}\hp86win7.inf" "0" "69a62ba9f" "00000060" "WinSta0\Default" "000005C4" "208" "C:\Program Files\Realtek\NICDRV_8169\win7"C:\Windows\System32\drvinst.exesvchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1824"C:\Program Files\Realtek\NICDRV_8169\RTINSTALLER32.EXE" /I /NCFI /VISTA8169 /X86 /spn WOL_SETTING /spv WOL_PTN_AND_MAG /f WIN7\hp86win7.infC:\Program Files\Realtek\NICDRV_8169\RTINSTALLER32.EXE
setup.exe
User:
admin
Company:
Realtek Semiconductor Corp.
Integrity Level:
HIGH
Description:
RTInstaller
Version:
1.0.0.31
Modules
Images
c:\program files\realtek\nicdrv_8169\rtinstaller32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1836"C:\Program Files\Realtek\NICDRV_8169\RTINSTALLER32.EXE" /q /VISTA8169 /X86 /f WIN7\hp86win7.infC:\Program Files\Realtek\NICDRV_8169\RTINSTALLER32.EXEsetup.exe
User:
admin
Company:
Realtek Semiconductor Corp.
Integrity Level:
HIGH
Description:
RTInstaller
Exit code:
0
Version:
1.0.0.31
Modules
Images
c:\program files\realtek\nicdrv_8169\rtinstaller32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
2024C:\Windows\system32\vssvc.exeC:\Windows\System32\VSSVC.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Volume Shadow Copy Service
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\vssvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2116"c:\SWSetup\SP84785\Setup.exe"C:\SWSetup\SP84785\setup.exe
sp84785.exe
User:
admin
Company:
Realtek
Integrity Level:
HIGH
Description:
InstallScript Setup Launcher Unicode
Version:
1.00.0037
Modules
Images
c:\swsetup\sp84785\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3976"C:\Users\admin\Desktop\sp84785.exe" C:\Users\admin\Desktop\sp84785.exeexplorer.exe
User:
admin
Company:
Hewlett-Packard Company
Integrity Level:
MEDIUM
Description:
Realtek Ethernet Controller Drivers (DTO)
Exit code:
3221226540
Version:
10.23.1003.2017
Modules
Images
c:\users\admin\desktop\sp84785.exe
c:\windows\system32\ntdll.dll
Total events
3 146
Read events
2 966
Write events
177
Delete events
3

Modification events

(PID) Process:(2116) setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion
Operation:delete valueName:%IS_PREREQ%-Realtek Ethernet Controller Driver
Value:
(PID) Process:(2116) setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion
Operation:delete valueName:%IS_PREREQF%-Realtek Ethernet Controller Driver
Value:
(PID) Process:(2116) setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce
Operation:delete valueName: ISSetupPrerequisistes
Value:
(PID) Process:(2116) setup.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SystemRestore
Operation:writeName:SrCreateRp (Enter)
Value:
40000000000000004A19E0F981AFDA0144080000F0070000D5070000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(2116) setup.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
Operation:writeName:SppCreate (Enter)
Value:
40000000000000004A19E0F981AFDA0144080000F0070000D0070000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(2116) setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP
Operation:writeName:LastIndex
Value:
75
(PID) Process:(2116) setup.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
Operation:writeName:SppGatherWriterMetadata (Enter)
Value:
4000000000000000323982FA81AFDA0144080000F0070000D3070000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(2116) setup.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher
Operation:writeName:IDENTIFY (Enter)
Value:
40000000000000008C9B84FA81AFDA01440800002C060000E803000001000000000000000000000061F00D52ADD4D34083F1614356A8C88E0000000000000000
(PID) Process:(2024) VSSVC.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
Operation:writeName:IDENTIFY (Enter)
Value:
40000000000000004E8790FA81AFDA01E8070000A0040000E8030000010000000100000000000000000000000000000000000000000000000000000000000000
(PID) Process:(2024) VSSVC.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
Operation:writeName:IDENTIFY (Enter)
Value:
40000000000000004E8790FA81AFDA01E8070000FC020000E8030000010000000100000000000000000000000000000000000000000000000000000000000000
Executable files
46
Suspicious files
50
Text files
358
Unknown types
2

Dropped files

PID
Process
Filename
Type
1120sp84785.exeC:\Users\admin\AppData\Local\Temp\pft745B.tmp\pftw1.pkg
MD5:
SHA256:
1120sp84785.exeC:\Users\admin\AppData\Local\Temp\ext4077.tmptext
MD5:316E8CD1B167CCE083728F3A10E00CEC
SHA256:B299A623449E192C65A541C3563CF7A2A51079E3BBF0C3DA9F3DF757842C0FEC
1120sp84785.exeC:\Users\admin\AppData\Local\Temp\ext4079.tmpini
MD5:9EFCC61A0BAA38A6D7C67A05A97C7B87
SHA256:7CCB3A50CA08C66A220E4DA614CBABA1D05157359EDD174223C788B86D929EDF
1120sp84785.exeC:\Users\admin\AppData\Local\Temp\wel4076.tmptext
MD5:316E8CD1B167CCE083728F3A10E00CEC
SHA256:B299A623449E192C65A541C3563CF7A2A51079E3BBF0C3DA9F3DF757842C0FEC
1120sp84785.exeC:\Users\admin\AppData\Local\Temp\plf4078.tmptext
MD5:9EFCC61A0BAA38A6D7C67A05A97C7B87
SHA256:7CCB3A50CA08C66A220E4DA614CBABA1D05157359EDD174223C788B86D929EDF
1120sp84785.exeC:\SWSetup\SP84785\0x0405.initext
MD5:9FB56981DD06830B30CD9CADF54270D6
SHA256:9302A3E694DE8CC84947B41350A7F8AE0880E5D2F3FDBD67CD56444BF0BC3A43
1120sp84785.exeC:\SWSetup\SP84785\0x040a.initext
MD5:E872C54C58EEF055BC791D3EEAD093C3
SHA256:1739D42ED181F36AB4F524C01B57A4102C2F7510661D973A1077A4E88AC34B97
1120sp84785.exeC:\SWSetup\SP84785\0x040b.initext
MD5:48DD00B7D72FB37F937DB5714BF8A725
SHA256:AA0097E47CAA4933793155E45FC91EEF6B035DAAF22F9EA32EB509CC4811DD5C
1120sp84785.exeC:\SWSetup\SP84785\0x040c.initext
MD5:35989450C8121207917F04D1EBE4CA2A
SHA256:B14D9D7AFC505868407C425CB5A78C891BAA8A6AC8EB35CFB3D71C71F5BEE1FA
1120sp84785.exeC:\SWSetup\SP84785\0x040e.initext
MD5:A143F6D5AC3832B025C9D04855A790FD
SHA256:6A0F69C2918A51E38907A2501DA4169DA506D461031576A39F3D6D33C53F976C
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
3
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
unknown
224.0.0.252:5355
unknown

DNS requests

No data

Threats

No threats detected
No debug info