File name:

software_reporter_tool.exe

Full analysis: https://app.any.run/tasks/8cc5f10f-c32e-4ee7-819d-56776741fdb6
Verdict: Malicious activity
Analysis date: February 09, 2024, 20:44:11
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

8F3C648FCA3811066AB418208B078691

SHA1:

4776A0FBD1D9D0ECE20EDBB0661D1C2A10D77630

SHA256:

E0788548E3C42A936B8695A6637C2D079EF4203311C87CB62E2784FF16A2AB24

SSDEEP:

98304:Pk9zmSg8M+TdRr+oiH6jMxHk8iq3MHJNU6EVHiv5kSlDOVpZOhl+OKBuRUVOFFBT:sX

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • software_reporter_tool.exe (PID: 1384)
      • software_reporter_tool.exe (PID: 3952)
  • SUSPICIOUS

    • Application launched itself

      • software_reporter_tool.exe (PID: 1384)
      • software_reporter_tool.exe (PID: 3256)
      • software_reporter_tool.exe (PID: 2152)
    • Executable content was dropped or overwritten

      • software_reporter_tool.exe (PID: 3952)
    • Searches for installed software

      • software_reporter_tool.exe (PID: 3952)
      • software_reporter_tool.exe (PID: 2192)
    • Read startup parameters

      • software_reporter_tool.exe (PID: 3952)
      • software_reporter_tool.exe (PID: 2192)
    • Reads the Internet Settings

      • software_reporter_tool.exe (PID: 3952)
      • software_reporter_tool.exe (PID: 2192)
  • INFO

    • Checks supported languages

      • software_reporter_tool.exe (PID: 3672)
      • software_reporter_tool.exe (PID: 1384)
      • software_reporter_tool.exe (PID: 3952)
      • software_reporter_tool.exe (PID: 3708)
      • software_reporter_tool.exe (PID: 3256)
      • software_reporter_tool.exe (PID: 3352)
      • software_reporter_tool.exe (PID: 2192)
      • software_reporter_tool.exe (PID: 2416)
      • software_reporter_tool.exe (PID: 1656)
      • software_reporter_tool.exe (PID: 2152)
      • software_reporter_tool.exe (PID: 2596)
      • software_reporter_tool.exe (PID: 3072)
    • Reads the computer name

      • software_reporter_tool.exe (PID: 3952)
      • software_reporter_tool.exe (PID: 1384)
      • software_reporter_tool.exe (PID: 3708)
      • software_reporter_tool.exe (PID: 2192)
      • software_reporter_tool.exe (PID: 3256)
      • software_reporter_tool.exe (PID: 2596)
      • software_reporter_tool.exe (PID: 2152)
      • software_reporter_tool.exe (PID: 2416)
      • software_reporter_tool.exe (PID: 3072)
    • Manual execution by a user

      • software_reporter_tool.exe (PID: 3256)
      • software_reporter_tool.exe (PID: 2152)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic Win/DOS Executable (50)
.exe | DOS Executable Generic (49.9)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2019:07:22 05:00:00+00:00
ImageFileCharacteristics: Executable, Large address aware, 32-bit
PEType: PE32
LinkerVersion: 14
CodeSize: 1754112
InitializedDataSize: 11241984
UninitializedDataSize: -
EntryPoint: 0x183f00
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 44.211.200.0
ProductVersionNumber: 44.211.200.0
FileFlagsMask: 0x0017
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Google
FileDescription: Software Reporter Tool
FileVersion: 44.211.200
InternalName: software_reporter_tool_exe
LegalCopyright: Copyright 2015 Google Inc. All Rights Reserved.
OriginalFileName: software_reporter_tool.exe
ProductName: Software Reporter Tool
ProductVersion: 44.211.200
CompanyShortName: Google
ProductShortName: Software Reporter Tool
OfficialBuild: 1
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
48
Monitored processes
12
Malicious processes
3
Suspicious processes
1

Behavior graph

Click at the process to see the details
start software_reporter_tool.exe no specs software_reporter_tool.exe no specs software_reporter_tool.exe software_reporter_tool.exe no specs software_reporter_tool.exe no specs software_reporter_tool.exe no specs software_reporter_tool.exe no specs software_reporter_tool.exe no specs software_reporter_tool.exe no specs software_reporter_tool.exe no specs software_reporter_tool.exe no specs software_reporter_tool.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1384"C:\Users\admin\Desktop\software_reporter_tool.exe" C:\Users\admin\Desktop\software_reporter_tool.exeexplorer.exe
User:
admin
Company:
Google
Integrity Level:
MEDIUM
Description:
Software Reporter Tool
Exit code:
0
Version:
44.211.200
Modules
Images
c:\users\admin\desktop\software_reporter_tool.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
1656c:\users\admin\desktop\software_reporter_tool.exe --crash-handler "--database=c:\users\admin\appdata\local\Google\Software Reporter Tool" --url=https://clients2.google.com/cr/report --annotation=plat=Win32 --annotation=prod=ChromeFoil --annotation=ver=44.211.200 --initial-client-data=0xfc,0x104,0x108,0x100,0x10c,0xef9e28,0xef9e38,0xef9e44C:\Users\admin\Desktop\software_reporter_tool.exesoftware_reporter_tool.exe
User:
admin
Company:
Google
Integrity Level:
MEDIUM
Description:
Software Reporter Tool
Exit code:
0
Version:
44.211.200
Modules
Images
c:\users\admin\desktop\software_reporter_tool.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
2152"C:\Users\admin\Desktop\software_reporter_tool.exe" C:\Users\admin\Desktop\software_reporter_tool.exeexplorer.exe
User:
admin
Company:
Google
Integrity Level:
MEDIUM
Description:
Software Reporter Tool
Exit code:
0
Version:
44.211.200
Modules
Images
c:\users\admin\desktop\software_reporter_tool.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
2192"c:\users\admin\desktop\software_reporter_tool.exe" --use-crash-handler-with-id="\\.\pipe\crashpad_3256_WOPUJGTHUXZZLOFH" --sandboxed-process-id=2 --init-done-notifier=420 --sandbox-mojo-pipe-token=12346253584596772913 --mojo-platform-channel-handle=356 --engine=2C:\Users\admin\Desktop\software_reporter_tool.exesoftware_reporter_tool.exe
User:
admin
Company:
Google
Integrity Level:
MEDIUM
Description:
Software Reporter Tool
Exit code:
0
Version:
44.211.200
Modules
Images
c:\users\admin\desktop\software_reporter_tool.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
2416"c:\users\admin\desktop\software_reporter_tool.exe" --use-crash-handler-with-id="\\.\pipe\crashpad_3256_WOPUJGTHUXZZLOFH" --sandboxed-process-id=3 --init-done-notifier=644 --sandbox-mojo-pipe-token=9521308708977934084 --mojo-platform-channel-handle=636C:\Users\admin\Desktop\software_reporter_tool.exesoftware_reporter_tool.exe
User:
admin
Company:
Google
Integrity Level:
MEDIUM
Description:
Software Reporter Tool
Exit code:
0
Version:
44.211.200
Modules
Images
c:\users\admin\desktop\software_reporter_tool.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
2596"c:\users\admin\desktop\software_reporter_tool.exe" --use-crash-handler-with-id="\\.\pipe\crashpad_2152_DPERDHVRWFEKJRBK" --sandboxed-process-id=2 --init-done-notifier=404 --sandbox-mojo-pipe-token=12679791480163594906 --mojo-platform-channel-handle=332 --engine=2C:\Users\admin\Desktop\software_reporter_tool.exesoftware_reporter_tool.exe
User:
admin
Company:
Google
Integrity Level:
MEDIUM
Description:
Software Reporter Tool
Exit code:
0
Version:
44.211.200
Modules
Images
c:\users\admin\desktop\software_reporter_tool.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
3072"c:\users\admin\desktop\software_reporter_tool.exe" --use-crash-handler-with-id="\\.\pipe\crashpad_2152_DPERDHVRWFEKJRBK" --sandboxed-process-id=3 --init-done-notifier=640 --sandbox-mojo-pipe-token=10382954342129728946 --mojo-platform-channel-handle=632C:\Users\admin\Desktop\software_reporter_tool.exesoftware_reporter_tool.exe
User:
admin
Company:
Google
Integrity Level:
MEDIUM
Description:
Software Reporter Tool
Exit code:
0
Version:
44.211.200
Modules
Images
c:\users\admin\desktop\software_reporter_tool.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
3256"C:\Users\admin\Desktop\software_reporter_tool.exe" C:\Users\admin\Desktop\software_reporter_tool.exeexplorer.exe
User:
admin
Company:
Google
Integrity Level:
MEDIUM
Description:
Software Reporter Tool
Exit code:
0
Version:
44.211.200
Modules
Images
c:\users\admin\desktop\software_reporter_tool.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
3352c:\users\admin\desktop\software_reporter_tool.exe --crash-handler "--database=c:\users\admin\appdata\local\Google\Software Reporter Tool" --url=https://clients2.google.com/cr/report --annotation=plat=Win32 --annotation=prod=ChromeFoil --annotation=ver=44.211.200 --initial-client-data=0xfc,0x104,0x108,0x100,0x10c,0xef9e28,0xef9e38,0xef9e44C:\Users\admin\Desktop\software_reporter_tool.exesoftware_reporter_tool.exe
User:
admin
Company:
Google
Integrity Level:
MEDIUM
Description:
Software Reporter Tool
Exit code:
0
Version:
44.211.200
Modules
Images
c:\users\admin\desktop\software_reporter_tool.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
3672c:\users\admin\desktop\software_reporter_tool.exe --crash-handler "--database=c:\users\admin\appdata\local\Google\Software Reporter Tool" --url=https://clients2.google.com/cr/report --annotation=plat=Win32 --annotation=prod=ChromeFoil --annotation=ver=44.211.200 --initial-client-data=0xfc,0x104,0x108,0x100,0x10c,0xef9e28,0xef9e38,0xef9e44C:\Users\admin\Desktop\software_reporter_tool.exesoftware_reporter_tool.exe
User:
admin
Company:
Google
Integrity Level:
MEDIUM
Description:
Software Reporter Tool
Exit code:
0
Version:
44.211.200
Modules
Images
c:\users\admin\desktop\software_reporter_tool.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
Total events
21 813
Read events
21 798
Write events
9
Delete events
6

Modification events

(PID) Process:(1384) software_reporter_tool.exeKey:HKEY_CURRENT_USER\Software\Google\Software Removal Tool\ScanTimes
Operation:delete keyName:(default)
Value:
(PID) Process:(1384) software_reporter_tool.exeKey:HKEY_CURRENT_USER\Software\Google\Software Removal Tool
Operation:delete valueName:ExitCode
Value:
(PID) Process:(1384) software_reporter_tool.exeKey:HKEY_CURRENT_USER\Software\Google\Software Removal Tool
Operation:writeName:StartTime
Value:
89BCB3468F6F2F00
(PID) Process:(1384) software_reporter_tool.exeKey:HKEY_CURRENT_USER\Software\Google\Software Removal Tool
Operation:writeName:EngineErrorCode
Value:
65536
(PID) Process:(1384) software_reporter_tool.exeKey:HKEY_CURRENT_USER\Software\Google\Software Removal Tool
Operation:writeName:EngineErrorCode
Value:
589824
(PID) Process:(3256) software_reporter_tool.exeKey:HKEY_CURRENT_USER\Software\Google\Software Removal Tool\ScanTimes
Operation:delete keyName:(default)
Value:
(PID) Process:(3256) software_reporter_tool.exeKey:HKEY_CURRENT_USER\Software\Google\Software Removal Tool
Operation:delete valueName:ExitCode
Value:
(PID) Process:(3256) software_reporter_tool.exeKey:HKEY_CURRENT_USER\Software\Google\Software Removal Tool
Operation:writeName:StartTime
Value:
92419C488F6F2F00
(PID) Process:(3256) software_reporter_tool.exeKey:HKEY_CURRENT_USER\Software\Google\Software Removal Tool
Operation:writeName:EngineErrorCode
Value:
65536
(PID) Process:(3256) software_reporter_tool.exeKey:HKEY_CURRENT_USER\Software\Google\Software Removal Tool
Operation:writeName:EngineErrorCode
Value:
589824
Executable files
7
Suspicious files
0
Text files
3
Unknown types
1

Dropped files

PID
Process
Filename
Type
3952software_reporter_tool.exeC:\users\admin\desktop\em003_32.dllexecutable
MD5:A72D7396A9B0F68E464DAA4AE39A3155
SHA256:1B3F34B71226824324888682682807A9C877D780D896588C39F6C4C2109A478D
3952software_reporter_tool.exeC:\users\admin\desktop\em002_32.dllexecutable
MD5:C5F99F64621F8783CE891DAF1A78113B
SHA256:4576672F872A0BBBCEC8C1C441156F0CEB57BBF165C3CB25FC9D1734D25F8CCD
3952software_reporter_tool.exeC:\users\admin\desktop\em001_32.dllexecutable
MD5:E9C10B913C4365C5E14DFBFA5F1B128F
SHA256:D89D40ABA74EF9818F3C440BE36FD8C13DA4B9E09272DA3A1ED59A98F20E3C1D
3952software_reporter_tool.exeC:\users\admin\desktop\em005_32.dllexecutable
MD5:B9842D223D8B8E192D0C1778AFE5476E
SHA256:A2C4B09DFA925676D37B7E2F33341821A5151D727ED7BECD441D65F3F5B735D2
1384software_reporter_tool.exeC:\users\admin\appdata\local\Google\Software Reporter Tool\settings.datbinary
MD5:B94703502CAB5AC56931643149E6FB81
SHA256:B0AE3F8E9904CCDF4E887A2BD65156B9A844739C75F2D6F1F592D7878A5FDA00
3952software_reporter_tool.exeC:\users\admin\desktop\em004_32.dllexecutable
MD5:1E476D42CFE1D63055D7A53E9026477E
SHA256:7A8C1450C7B81AD37882EF08A6B1D9407DA012D2BED7485A5AD0920E90D87D24
3256software_reporter_tool.exeC:\Users\admin\AppData\Local\Google\Software Reporter Tool\software_reporter_tool.logtext
MD5:0C77FB52794C8289473973A8D3A8C8C5
SHA256:ECE2BC6E89CBE30B6F8ECB27691D7B0BF9DDFE2C74C293EB60686347AFAB12CF
3952software_reporter_tool.exeC:\users\admin\desktop\edls_32.dllexecutable
MD5:5A6A6029614AC855D5A7D2A4A595DEA1
SHA256:1DDAE5721437F3CFA3B7DF754227F9D6388F3EB5F63000FDC16793E25229972D
3708software_reporter_tool.exeC:\Users\admin\AppData\Local\Google\Software Reporter Tool\software_reporter_tool-sandbox.logtext
MD5:0B68FE214811FEFDECF29796BDC6FF60
SHA256:64D9B3CED69169796BE507BFC65D404AA09C508C4542555854C4E9FC2A5D36A9
3952software_reporter_tool.exeC:\users\admin\desktop\em000_32.dllexecutable
MD5:2AD7364C59F37DB236AB149ACE05FD10
SHA256:C282F94F71CE00483B5D57C7A0EA5A44E70272DC2C8F4ABF3C5B1C8D9C860608
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown

DNS requests

No data

Threats

No threats detected
No debug info