File name:

sp84785.exe

Full analysis: https://app.any.run/tasks/f2d1e660-6fbd-4b38-b6b6-fa0b8c992205
Verdict: Malicious activity
Analysis date: May 26, 2024, 15:32:06
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

84419C556123EB7B7B7841A416BDFFE5

SHA1:

58AD3B81E78EDA002C0D12F34113A8661360FF3D

SHA256:

BBE398354F1BCCB781B7FDDBADBE19361B952F630D45F4FA5C951C590F70802E

SSDEEP:

98304:hgH3/RkG7vlZAqL1NhCoop2jJsHiZ5pEcDlCg9e2PS9yoNDkdZXVntBzdy3uU7xq:JEDMN/UQQWvVSOl

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • sp84785.exe (PID: 1120)
      • setup.exe (PID: 2116)
      • RTINSTALLER32.EXE (PID: 1824)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • sp84785.exe (PID: 1120)
      • setup.exe (PID: 2116)
      • RTINSTALLER32.EXE (PID: 1824)
    • Drops a system driver (possible attempt to evade defenses)

      • sp84785.exe (PID: 1120)
      • setup.exe (PID: 2116)
      • RTINSTALLER32.EXE (PID: 1824)
    • Searches for installed software

      • setup.exe (PID: 2116)
    • Reads the Windows owner or organization settings

      • setup.exe (PID: 2116)
    • Executes as Windows Service

      • VSSVC.exe (PID: 2024)
  • INFO

    • Checks supported languages

      • sp84785.exe (PID: 1120)
      • setup.exe (PID: 2116)
      • RTINSTALLER32.EXE (PID: 1836)
      • RTINSTALLER32.EXE (PID: 1824)
      • drvinst.exe (PID: 1548)
    • Reads the computer name

      • setup.exe (PID: 2116)
      • RTINSTALLER32.EXE (PID: 1836)
      • RTINSTALLER32.EXE (PID: 1824)
      • drvinst.exe (PID: 1548)
    • Reads the machine GUID from the registry

      • setup.exe (PID: 2116)
      • RTINSTALLER32.EXE (PID: 1824)
      • drvinst.exe (PID: 1548)
    • Create files in a temporary directory

      • sp84785.exe (PID: 1120)
      • setup.exe (PID: 2116)
      • RTINSTALLER32.EXE (PID: 1824)
    • Creates files in the program directory

      • setup.exe (PID: 2116)
      • RTINSTALLER32.EXE (PID: 1836)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | InstallShield setup (36.8)
.exe | Win32 Executable MS Visual C++ (generic) (26.6)
.exe | Win64 Executable (generic) (23.6)
.dll | Win32 Dynamic Link Library (generic) (5.6)
.exe | Win32 Executable (generic) (3.8)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2001:08:29 21:22:49+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 73728
InitializedDataSize: 212992
UninitializedDataSize: -
EntryPoint: 0x8927
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 4.0.100.1189
ProductVersionNumber: 4.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
Comments:
CompanyName: Hewlett-Packard Company
FileDescription: Realtek Ethernet Controller Drivers (DTO)
InternalName: stub32
OriginalFileName: stub32i.exe
FileVersion: 10.23.1003.2017
LegalCopyright:
ProductName: Realtek Ethernet Controller Drivers (DTO)
ProductVersion: 10.23.1003.2017
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
43
Monitored processes
7
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start sp84785.exe setup.exe vssvc.exe no specs rtinstaller32.exe no specs rtinstaller32.exe drvinst.exe no specs sp84785.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1120"C:\Users\admin\Desktop\sp84785.exe" C:\Users\admin\Desktop\sp84785.exe
explorer.exe
User:
admin
Company:
Hewlett-Packard Company
Integrity Level:
HIGH
Description:
Realtek Ethernet Controller Drivers (DTO)
Version:
10.23.1003.2017
Modules
Images
c:\users\admin\desktop\sp84785.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
1548DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{6963e3d6-aa29-779c-fe1d-257a5a0aa60a}\hp86win7.inf" "0" "69a62ba9f" "00000060" "WinSta0\Default" "000005C4" "208" "C:\Program Files\Realtek\NICDRV_8169\win7"C:\Windows\System32\drvinst.exesvchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1824"C:\Program Files\Realtek\NICDRV_8169\RTINSTALLER32.EXE" /I /NCFI /VISTA8169 /X86 /spn WOL_SETTING /spv WOL_PTN_AND_MAG /f WIN7\hp86win7.infC:\Program Files\Realtek\NICDRV_8169\RTINSTALLER32.EXE
setup.exe
User:
admin
Company:
Realtek Semiconductor Corp.
Integrity Level:
HIGH
Description:
RTInstaller
Version:
1.0.0.31
Modules
Images
c:\program files\realtek\nicdrv_8169\rtinstaller32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1836"C:\Program Files\Realtek\NICDRV_8169\RTINSTALLER32.EXE" /q /VISTA8169 /X86 /f WIN7\hp86win7.infC:\Program Files\Realtek\NICDRV_8169\RTINSTALLER32.EXEsetup.exe
User:
admin
Company:
Realtek Semiconductor Corp.
Integrity Level:
HIGH
Description:
RTInstaller
Exit code:
0
Version:
1.0.0.31
Modules
Images
c:\program files\realtek\nicdrv_8169\rtinstaller32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
2024C:\Windows\system32\vssvc.exeC:\Windows\System32\VSSVC.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Volume Shadow Copy Service
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\vssvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2116"c:\SWSetup\SP84785\Setup.exe"C:\SWSetup\SP84785\setup.exe
sp84785.exe
User:
admin
Company:
Realtek
Integrity Level:
HIGH
Description:
InstallScript Setup Launcher Unicode
Version:
1.00.0037
Modules
Images
c:\swsetup\sp84785\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3976"C:\Users\admin\Desktop\sp84785.exe" C:\Users\admin\Desktop\sp84785.exeexplorer.exe
User:
admin
Company:
Hewlett-Packard Company
Integrity Level:
MEDIUM
Description:
Realtek Ethernet Controller Drivers (DTO)
Exit code:
3221226540
Version:
10.23.1003.2017
Modules
Images
c:\users\admin\desktop\sp84785.exe
c:\windows\system32\ntdll.dll
Total events
3 146
Read events
2 966
Write events
177
Delete events
3

Modification events

(PID) Process:(2116) setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion
Operation:delete valueName:%IS_PREREQ%-Realtek Ethernet Controller Driver
Value:
(PID) Process:(2116) setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion
Operation:delete valueName:%IS_PREREQF%-Realtek Ethernet Controller Driver
Value:
(PID) Process:(2116) setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce
Operation:delete valueName: ISSetupPrerequisistes
Value:
(PID) Process:(2116) setup.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SystemRestore
Operation:writeName:SrCreateRp (Enter)
Value:
40000000000000004A19E0F981AFDA0144080000F0070000D5070000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(2116) setup.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
Operation:writeName:SppCreate (Enter)
Value:
40000000000000004A19E0F981AFDA0144080000F0070000D0070000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(2116) setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP
Operation:writeName:LastIndex
Value:
75
(PID) Process:(2116) setup.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
Operation:writeName:SppGatherWriterMetadata (Enter)
Value:
4000000000000000323982FA81AFDA0144080000F0070000D3070000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(2116) setup.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher
Operation:writeName:IDENTIFY (Enter)
Value:
40000000000000008C9B84FA81AFDA01440800002C060000E803000001000000000000000000000061F00D52ADD4D34083F1614356A8C88E0000000000000000
(PID) Process:(2024) VSSVC.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
Operation:writeName:IDENTIFY (Enter)
Value:
40000000000000004E8790FA81AFDA01E8070000A0040000E8030000010000000100000000000000000000000000000000000000000000000000000000000000
(PID) Process:(2024) VSSVC.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
Operation:writeName:IDENTIFY (Enter)
Value:
40000000000000004E8790FA81AFDA01E8070000FC020000E8030000010000000100000000000000000000000000000000000000000000000000000000000000
Executable files
46
Suspicious files
50
Text files
358
Unknown types
2

Dropped files

PID
Process
Filename
Type
1120sp84785.exeC:\Users\admin\AppData\Local\Temp\pft745B.tmp\pftw1.pkg
MD5:
SHA256:
1120sp84785.exeC:\SWSetup\SP84785\0x0404.initext
MD5:EC1F8F71FA21C49BC96A17C81AD51598
SHA256:60F176F3014342F48468FF7EA67280FA3A671C4721EBEFE7B4EE789FF65C87DF
1120sp84785.exeC:\Users\admin\AppData\Local\Temp\ext4077.tmptext
MD5:316E8CD1B167CCE083728F3A10E00CEC
SHA256:B299A623449E192C65A541C3563CF7A2A51079E3BBF0C3DA9F3DF757842C0FEC
1120sp84785.exeC:\SWSetup\SP84785\0x0407.initext
MD5:9A62DA6C523506355C1BF1B30DB73EDD
SHA256:8B5D7BC395D0D6980299702D0573C6019FEFEA92EB98701D1894A5623B2691A0
1120sp84785.exeC:\SWSetup\SP84785\0x0403.initext
MD5:04B3D8BE6E6F17F13A3BE3F24E3AC1B0
SHA256:BAD754F1F64BC40D1AA6D037179C4DEDB41E9237D3B5E05BFFF4F92ECF623E02
1120sp84785.exeC:\SWSetup\SP84785\0x0405.initext
MD5:9FB56981DD06830B30CD9CADF54270D6
SHA256:9302A3E694DE8CC84947B41350A7F8AE0880E5D2F3FDBD67CD56444BF0BC3A43
1120sp84785.exeC:\SWSetup\SP84785\0x0406.initext
MD5:7C6AD5705B8C076697C1CA0EB6229F6F
SHA256:FAD1187DF234B8B2B27C3F866B218036E377469871E0816FA6CC38C391D5AD93
1120sp84785.exeC:\SWSetup\SP84785\0x040b.initext
MD5:48DD00B7D72FB37F937DB5714BF8A725
SHA256:AA0097E47CAA4933793155E45FC91EEF6B035DAAF22F9EA32EB509CC4811DD5C
1120sp84785.exeC:\SWSetup\SP84785\0x040a.initext
MD5:E872C54C58EEF055BC791D3EEAD093C3
SHA256:1739D42ED181F36AB4F524C01B57A4102C2F7510661D973A1077A4E88AC34B97
1120sp84785.exeC:\Users\admin\AppData\Local\Temp\wel4076.tmptext
MD5:316E8CD1B167CCE083728F3A10E00CEC
SHA256:B299A623449E192C65A541C3563CF7A2A51079E3BBF0C3DA9F3DF757842C0FEC
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
3
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
unknown
224.0.0.252:5355
unknown

DNS requests

No data

Threats

No threats detected
No debug info