File name:

SignCut Productivity Pro v1.07 (WinALL) PATCH.exe

Full analysis: https://app.any.run/tasks/d2520d2c-79b2-4603-8f64-14e687932ccf
Verdict: Malicious activity
Analysis date: December 04, 2024, 07:39:27
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 4 sections
MD5:

4D918D526F6EB78BB561A5D5C4CBE30F

SHA1:

0163267EEAB462C4AA71A91320F124608B176FE0

SHA256:

D84DCEF86FC9BAD8510BF430CDEE0638D9155840491AD2B6774C84BB57200CE7

SSDEEP:

6144:/+rhBVhDY2VJtwtutTtIt4yokLHZ1eU1Pn7LbZ:/+rhBVhE2VJtwtutTtItrLHZ1eU1v73Z

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • SignCut Productivity Pro v1.07 (WinALL) PATCH.exe (PID: 5588)
      • SignCut Productivity Pro v1.07 (WinALL).exe (PID: 7072)
    • Creates a software uninstall entry

      • SignCut Productivity Pro v1.07 (WinALL).exe (PID: 7072)
    • Process drops legitimate windows executable

      • SignCut Productivity Pro v1.07 (WinALL).exe (PID: 7072)
    • The process drops C-runtime libraries

      • SignCut Productivity Pro v1.07 (WinALL).exe (PID: 7072)
    • Process drops python dynamic module

      • SignCut Productivity Pro v1.07 (WinALL).exe (PID: 7072)
  • INFO

    • Checks supported languages

      • SignCut Productivity Pro v1.07 (WinALL) PATCH.exe (PID: 5588)
      • SignCut Productivity Pro v1.07 (WinALL).exe (PID: 7072)
    • Reads the computer name

      • SignCut Productivity Pro v1.07 (WinALL) PATCH.exe (PID: 5588)
      • SignCut Productivity Pro v1.07 (WinALL).exe (PID: 7072)
    • Create files in a temporary directory

      • SignCut Productivity Pro v1.07 (WinALL) PATCH.exe (PID: 5588)
    • Manual execution by a user

      • SignCut Productivity Pro v1.07 (WinALL).exe (PID: 7072)
      • SignCut Productivity Pro v1.07 (WinALL).exe (PID: 7012)
    • Creates files in the program directory

      • SignCut Productivity Pro v1.07 (WinALL).exe (PID: 7072)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2011:11:21 23:31:35+00:00
ImageFileCharacteristics: No relocs, Executable, 32-bit
PEType: PE32
LinkerVersion: 10
CodeSize: 38912
InitializedDataSize: 549888
UninitializedDataSize: -
EntryPoint: 0x20c0
OSVersion: 5
ImageVersion: -
SubsystemVersion: 5
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
130
Monitored processes
3
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start signcut productivity pro v1.07 (winall) patch.exe signcut productivity pro v1.07 (winall).exe no specs signcut productivity pro v1.07 (winall).exe

Process information

PID
CMD
Path
Indicators
Parent process
5588"C:\Users\admin\AppData\Local\Temp\SignCut Productivity Pro v1.07 (WinALL) PATCH.exe" C:\Users\admin\AppData\Local\Temp\SignCut Productivity Pro v1.07 (WinALL) PATCH.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\signcut productivity pro v1.07 (winall) patch.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
7012"C:\Users\admin\Desktop\SignCut Productivity Pro v1.07 (WinALL).exe" C:\Users\admin\Desktop\SignCut Productivity Pro v1.07 (WinALL).exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\desktop\signcut productivity pro v1.07 (winall).exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
7072"C:\Users\admin\Desktop\SignCut Productivity Pro v1.07 (WinALL).exe" C:\Users\admin\Desktop\SignCut Productivity Pro v1.07 (WinALL).exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Modules
Images
c:\users\admin\desktop\signcut productivity pro v1.07 (winall).exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
Total events
314
Read events
308
Write events
6
Delete events
0

Modification events

(PID) Process:(7072) SignCut Productivity Pro v1.07 (WinALL).exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Whisqu Graphic AB\SignCut
Operation:writeName:SCDestination
Value:
C:\Program Files (x86)\SignCut
(PID) Process:(7072) SignCut Productivity Pro v1.07 (WinALL).exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Whisqu Graphic AB\SignCut
Operation:writeName:Destination
Value:
C:\Program Files (x86)\SignCut
(PID) Process:(7072) SignCut Productivity Pro v1.07 (WinALL).exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\SignCut
Operation:writeName:DisplayName
Value:
SignCut (remove only)
(PID) Process:(7072) SignCut Productivity Pro v1.07 (WinALL).exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\SignCut
Operation:writeName:UninstallString
Value:
"C:\Program Files (x86)\SignCut\uninst.exe"
(PID) Process:(7072) SignCut Productivity Pro v1.07 (WinALL).exeKey:HKEY_CURRENT_USER\SOFTWARE\Whisqu Graphic AB\SignCut
Operation:writeName:ExportPath
Value:
C:\Users\admin\AppData\Roaming\SignCut\Import
(PID) Process:(7072) SignCut Productivity Pro v1.07 (WinALL).exeKey:HKEY_CURRENT_USER\SOFTWARE\Whisqu Graphic AB\SignCut
Operation:writeName:Destination
Value:
C:\Program Files (x86)\SignCut
Executable files
55
Suspicious files
202
Text files
601
Unknown types
3

Dropped files

PID
Process
Filename
Type
7072SignCut Productivity Pro v1.07 (WinALL).exeC:\Program Files (x86)\SignCut\GDIPLUS.DLLexecutable
MD5:B4666C664808F7BC51124B7CC6CE4A70
SHA256:73913148CDE634A0976F16501D344231006B279F959F3377CA3B625002EB8647
5588SignCut Productivity Pro v1.07 (WinALL) PATCH.exeC:\Users\admin\AppData\Local\Temp\dup2patcher.exeexecutable
MD5:4D918D526F6EB78BB561A5D5C4CBE30F
SHA256:D84DCEF86FC9BAD8510BF430CDEE0638D9155840491AD2B6774C84BB57200CE7
7072SignCut Productivity Pro v1.07 (WinALL).exeC:\Program Files (x86)\SignCut\Microsoft.VC90.CRT.manifestxml
MD5:6BB5D2AAD0AE1B4A82E7DDF7CF58802A
SHA256:9E0220511D4EBDB014CC17ECB8319D57E3B0FEA09681A80D8084AA8647196582
5588SignCut Productivity Pro v1.07 (WinALL) PATCH.exeC:\Users\admin\AppData\Local\Temp\bassmod.dllexecutable
MD5:780D14604D49E3C634200C523DEF8351
SHA256:844EB66A10B848D3A71A8C63C35F0A01550A46D2FF8503E2CA8947978B03B4D2
7072SignCut Productivity Pro v1.07 (WinALL).exeC:\Program Files (x86)\SignCut\EULA.TXTtext
MD5:A263BC10EC740611D104E686811261BB
SHA256:40353174A5132B96FFFCC0A8D0152B4BC31DEA4592CBBBDA87E34E6C2DEC5FAB
7072SignCut Productivity Pro v1.07 (WinALL).exeC:\Program Files (x86)\SignCut\LiveUpdate.exeexecutable
MD5:65036C2449A52C8C16038D2A2D56D790
SHA256:DAABF7F64C7EB45F87B26CC3AB8D64166B28C4DF27BD800FE1C977D75EB48BAD
7072SignCut Productivity Pro v1.07 (WinALL).exeC:\Program Files (x86)\SignCut\CreationUsbDll.dllexecutable
MD5:4864BC978E1A9EEED47BA94D65C914B5
SHA256:D5E9C3B158250FFC599702566422E82817559373B018DFE669E47A9BD670CC8B
7072SignCut Productivity Pro v1.07 (WinALL).exeC:\Program Files (x86)\SignCut\GITKUSBP.DLLexecutable
MD5:3FEFB76506BDD9EFA0C9A2A2FAB7BAE3
SHA256:BF62BC71577D323736E92A42ABC985C05D88E0FD20BB7D3C9ABA6B9BABE9FE4A
7072SignCut Productivity Pro v1.07 (WinALL).exeC:\Program Files (x86)\SignCut\SignCut.exeexecutable
MD5:6F1EB5523BB6640F6002A8C0892149CC
SHA256:9896531E7315EAB05758020006F0B2CCBE2845DD1EDB68E8CACBE40F8ED5641A
7072SignCut Productivity Pro v1.07 (WinALL).exeC:\Program Files (x86)\SignCut\VUFun.dllexecutable
MD5:6C06DFB4674CC815105D2CA2E5928DA7
SHA256:320F11047D38B143905E53C3C31A6E781820D2013009471C4E0F02D38C149229
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
9
TCP/UDP connections
32
DNS requests
16
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
23.216.77.6:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
4712
MoUsoCoreWorker.exe
GET
200
23.216.77.6:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
23.52.120.96:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
4712
MoUsoCoreWorker.exe
GET
200
23.52.120.96:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
1176
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
7096
SIHClient.exe
GET
200
23.52.120.96:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
7096
SIHClient.exe
GET
200
23.52.120.96:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
6688
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4712
MoUsoCoreWorker.exe
23.216.77.6:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
23.216.77.6:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
5064
SearchApp.exe
2.16.110.138:443
www.bing.com
Akamai International B.V.
DE
whitelisted
4712
MoUsoCoreWorker.exe
23.52.120.96:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
23.52.120.96:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
4
System
192.168.100.255:138
whitelisted
5004
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 4.231.128.59
whitelisted
crl.microsoft.com
  • 23.216.77.6
  • 23.216.77.28
whitelisted
www.bing.com
  • 2.16.110.138
  • 2.16.110.195
  • 2.16.110.121
  • 2.16.110.146
  • 2.16.110.130
  • 2.16.110.123
  • 2.16.110.145
  • 2.16.110.152
  • 2.16.110.131
whitelisted
www.microsoft.com
  • 23.52.120.96
whitelisted
google.com
  • 216.58.206.78
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
login.live.com
  • 40.126.32.140
  • 40.126.32.134
  • 20.190.160.14
  • 40.126.32.68
  • 20.190.160.17
  • 40.126.32.74
  • 20.190.160.22
  • 40.126.32.72
whitelisted
go.microsoft.com
  • 23.213.166.81
whitelisted
slscr.update.microsoft.com
  • 4.245.163.56
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 13.85.23.206
whitelisted

Threats

No threats detected
No debug info