| File name: | software_reporter_tool.exe |
| Full analysis: | https://app.any.run/tasks/8cc5f10f-c32e-4ee7-819d-56776741fdb6 |
| Verdict: | Malicious activity |
| Analysis date: | February 09, 2024, 20:44:11 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 8F3C648FCA3811066AB418208B078691 |
| SHA1: | 4776A0FBD1D9D0ECE20EDBB0661D1C2A10D77630 |
| SHA256: | E0788548E3C42A936B8695A6637C2D079EF4203311C87CB62E2784FF16A2AB24 |
| SSDEEP: | 98304:Pk9zmSg8M+TdRr+oiH6jMxHk8iq3MHJNU6EVHiv5kSlDOVpZOhl+OKBuRUVOFFBT:sX |
| .exe | | | Generic Win/DOS Executable (50) |
|---|---|---|
| .exe | | | DOS Executable Generic (49.9) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2019:07:22 05:00:00+00:00 |
| ImageFileCharacteristics: | Executable, Large address aware, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 14 |
| CodeSize: | 1754112 |
| InitializedDataSize: | 11241984 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x183f00 |
| OSVersion: | 5.1 |
| ImageVersion: | - |
| SubsystemVersion: | 5.1 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 44.211.200.0 |
| ProductVersionNumber: | 44.211.200.0 |
| FileFlagsMask: | 0x0017 |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| CompanyName: | |
| FileDescription: | Software Reporter Tool |
| FileVersion: | 44.211.200 |
| InternalName: | software_reporter_tool_exe |
| LegalCopyright: | Copyright 2015 Google Inc. All Rights Reserved. |
| OriginalFileName: | software_reporter_tool.exe |
| ProductName: | Software Reporter Tool |
| ProductVersion: | 44.211.200 |
| CompanyShortName: | |
| ProductShortName: | Software Reporter Tool |
| OfficialBuild: | 1 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1384 | "C:\Users\admin\Desktop\software_reporter_tool.exe" | C:\Users\admin\Desktop\software_reporter_tool.exe | — | explorer.exe | |||||||||||
User: admin Company: Google Integrity Level: MEDIUM Description: Software Reporter Tool Exit code: 0 Version: 44.211.200 Modules
| |||||||||||||||
| 1656 | c:\users\admin\desktop\software_reporter_tool.exe --crash-handler "--database=c:\users\admin\appdata\local\Google\Software Reporter Tool" --url=https://clients2.google.com/cr/report --annotation=plat=Win32 --annotation=prod=ChromeFoil --annotation=ver=44.211.200 --initial-client-data=0xfc,0x104,0x108,0x100,0x10c,0xef9e28,0xef9e38,0xef9e44 | C:\Users\admin\Desktop\software_reporter_tool.exe | — | software_reporter_tool.exe | |||||||||||
User: admin Company: Google Integrity Level: MEDIUM Description: Software Reporter Tool Exit code: 0 Version: 44.211.200 Modules
| |||||||||||||||
| 2152 | "C:\Users\admin\Desktop\software_reporter_tool.exe" | C:\Users\admin\Desktop\software_reporter_tool.exe | — | explorer.exe | |||||||||||
User: admin Company: Google Integrity Level: MEDIUM Description: Software Reporter Tool Exit code: 0 Version: 44.211.200 Modules
| |||||||||||||||
| 2192 | "c:\users\admin\desktop\software_reporter_tool.exe" --use-crash-handler-with-id="\\.\pipe\crashpad_3256_WOPUJGTHUXZZLOFH" --sandboxed-process-id=2 --init-done-notifier=420 --sandbox-mojo-pipe-token=12346253584596772913 --mojo-platform-channel-handle=356 --engine=2 | C:\Users\admin\Desktop\software_reporter_tool.exe | — | software_reporter_tool.exe | |||||||||||
User: admin Company: Google Integrity Level: MEDIUM Description: Software Reporter Tool Exit code: 0 Version: 44.211.200 Modules
| |||||||||||||||
| 2416 | "c:\users\admin\desktop\software_reporter_tool.exe" --use-crash-handler-with-id="\\.\pipe\crashpad_3256_WOPUJGTHUXZZLOFH" --sandboxed-process-id=3 --init-done-notifier=644 --sandbox-mojo-pipe-token=9521308708977934084 --mojo-platform-channel-handle=636 | C:\Users\admin\Desktop\software_reporter_tool.exe | — | software_reporter_tool.exe | |||||||||||
User: admin Company: Google Integrity Level: MEDIUM Description: Software Reporter Tool Exit code: 0 Version: 44.211.200 Modules
| |||||||||||||||
| 2596 | "c:\users\admin\desktop\software_reporter_tool.exe" --use-crash-handler-with-id="\\.\pipe\crashpad_2152_DPERDHVRWFEKJRBK" --sandboxed-process-id=2 --init-done-notifier=404 --sandbox-mojo-pipe-token=12679791480163594906 --mojo-platform-channel-handle=332 --engine=2 | C:\Users\admin\Desktop\software_reporter_tool.exe | — | software_reporter_tool.exe | |||||||||||
User: admin Company: Google Integrity Level: MEDIUM Description: Software Reporter Tool Exit code: 0 Version: 44.211.200 Modules
| |||||||||||||||
| 3072 | "c:\users\admin\desktop\software_reporter_tool.exe" --use-crash-handler-with-id="\\.\pipe\crashpad_2152_DPERDHVRWFEKJRBK" --sandboxed-process-id=3 --init-done-notifier=640 --sandbox-mojo-pipe-token=10382954342129728946 --mojo-platform-channel-handle=632 | C:\Users\admin\Desktop\software_reporter_tool.exe | — | software_reporter_tool.exe | |||||||||||
User: admin Company: Google Integrity Level: MEDIUM Description: Software Reporter Tool Exit code: 0 Version: 44.211.200 Modules
| |||||||||||||||
| 3256 | "C:\Users\admin\Desktop\software_reporter_tool.exe" | C:\Users\admin\Desktop\software_reporter_tool.exe | — | explorer.exe | |||||||||||
User: admin Company: Google Integrity Level: MEDIUM Description: Software Reporter Tool Exit code: 0 Version: 44.211.200 Modules
| |||||||||||||||
| 3352 | c:\users\admin\desktop\software_reporter_tool.exe --crash-handler "--database=c:\users\admin\appdata\local\Google\Software Reporter Tool" --url=https://clients2.google.com/cr/report --annotation=plat=Win32 --annotation=prod=ChromeFoil --annotation=ver=44.211.200 --initial-client-data=0xfc,0x104,0x108,0x100,0x10c,0xef9e28,0xef9e38,0xef9e44 | C:\Users\admin\Desktop\software_reporter_tool.exe | — | software_reporter_tool.exe | |||||||||||
User: admin Company: Google Integrity Level: MEDIUM Description: Software Reporter Tool Exit code: 0 Version: 44.211.200 Modules
| |||||||||||||||
| 3672 | c:\users\admin\desktop\software_reporter_tool.exe --crash-handler "--database=c:\users\admin\appdata\local\Google\Software Reporter Tool" --url=https://clients2.google.com/cr/report --annotation=plat=Win32 --annotation=prod=ChromeFoil --annotation=ver=44.211.200 --initial-client-data=0xfc,0x104,0x108,0x100,0x10c,0xef9e28,0xef9e38,0xef9e44 | C:\Users\admin\Desktop\software_reporter_tool.exe | — | software_reporter_tool.exe | |||||||||||
User: admin Company: Google Integrity Level: MEDIUM Description: Software Reporter Tool Exit code: 0 Version: 44.211.200 Modules
| |||||||||||||||
| (PID) Process: | (1384) software_reporter_tool.exe | Key: | HKEY_CURRENT_USER\Software\Google\Software Removal Tool\ScanTimes |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (1384) software_reporter_tool.exe | Key: | HKEY_CURRENT_USER\Software\Google\Software Removal Tool |
| Operation: | delete value | Name: | ExitCode |
Value: | |||
| (PID) Process: | (1384) software_reporter_tool.exe | Key: | HKEY_CURRENT_USER\Software\Google\Software Removal Tool |
| Operation: | write | Name: | StartTime |
Value: 89BCB3468F6F2F00 | |||
| (PID) Process: | (1384) software_reporter_tool.exe | Key: | HKEY_CURRENT_USER\Software\Google\Software Removal Tool |
| Operation: | write | Name: | EngineErrorCode |
Value: 65536 | |||
| (PID) Process: | (1384) software_reporter_tool.exe | Key: | HKEY_CURRENT_USER\Software\Google\Software Removal Tool |
| Operation: | write | Name: | EngineErrorCode |
Value: 589824 | |||
| (PID) Process: | (3256) software_reporter_tool.exe | Key: | HKEY_CURRENT_USER\Software\Google\Software Removal Tool\ScanTimes |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (3256) software_reporter_tool.exe | Key: | HKEY_CURRENT_USER\Software\Google\Software Removal Tool |
| Operation: | delete value | Name: | ExitCode |
Value: | |||
| (PID) Process: | (3256) software_reporter_tool.exe | Key: | HKEY_CURRENT_USER\Software\Google\Software Removal Tool |
| Operation: | write | Name: | StartTime |
Value: 92419C488F6F2F00 | |||
| (PID) Process: | (3256) software_reporter_tool.exe | Key: | HKEY_CURRENT_USER\Software\Google\Software Removal Tool |
| Operation: | write | Name: | EngineErrorCode |
Value: 65536 | |||
| (PID) Process: | (3256) software_reporter_tool.exe | Key: | HKEY_CURRENT_USER\Software\Google\Software Removal Tool |
| Operation: | write | Name: | EngineErrorCode |
Value: 589824 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3952 | software_reporter_tool.exe | C:\users\admin\desktop\em003_32.dll | executable | |
MD5:A72D7396A9B0F68E464DAA4AE39A3155 | SHA256:1B3F34B71226824324888682682807A9C877D780D896588C39F6C4C2109A478D | |||
| 3952 | software_reporter_tool.exe | C:\users\admin\desktop\em002_32.dll | executable | |
MD5:C5F99F64621F8783CE891DAF1A78113B | SHA256:4576672F872A0BBBCEC8C1C441156F0CEB57BBF165C3CB25FC9D1734D25F8CCD | |||
| 3952 | software_reporter_tool.exe | C:\users\admin\desktop\em001_32.dll | executable | |
MD5:E9C10B913C4365C5E14DFBFA5F1B128F | SHA256:D89D40ABA74EF9818F3C440BE36FD8C13DA4B9E09272DA3A1ED59A98F20E3C1D | |||
| 3952 | software_reporter_tool.exe | C:\users\admin\desktop\em005_32.dll | executable | |
MD5:B9842D223D8B8E192D0C1778AFE5476E | SHA256:A2C4B09DFA925676D37B7E2F33341821A5151D727ED7BECD441D65F3F5B735D2 | |||
| 1384 | software_reporter_tool.exe | C:\users\admin\appdata\local\Google\Software Reporter Tool\settings.dat | binary | |
MD5:B94703502CAB5AC56931643149E6FB81 | SHA256:B0AE3F8E9904CCDF4E887A2BD65156B9A844739C75F2D6F1F592D7878A5FDA00 | |||
| 3952 | software_reporter_tool.exe | C:\users\admin\desktop\em004_32.dll | executable | |
MD5:1E476D42CFE1D63055D7A53E9026477E | SHA256:7A8C1450C7B81AD37882EF08A6B1D9407DA012D2BED7485A5AD0920E90D87D24 | |||
| 3256 | software_reporter_tool.exe | C:\Users\admin\AppData\Local\Google\Software Reporter Tool\software_reporter_tool.log | text | |
MD5:0C77FB52794C8289473973A8D3A8C8C5 | SHA256:ECE2BC6E89CBE30B6F8ECB27691D7B0BF9DDFE2C74C293EB60686347AFAB12CF | |||
| 3952 | software_reporter_tool.exe | C:\users\admin\desktop\edls_32.dll | executable | |
MD5:5A6A6029614AC855D5A7D2A4A595DEA1 | SHA256:1DDAE5721437F3CFA3B7DF754227F9D6388F3EB5F63000FDC16793E25229972D | |||
| 3708 | software_reporter_tool.exe | C:\Users\admin\AppData\Local\Google\Software Reporter Tool\software_reporter_tool-sandbox.log | text | |
MD5:0B68FE214811FEFDECF29796BDC6FF60 | SHA256:64D9B3CED69169796BE507BFC65D404AA09C508C4542555854C4E9FC2A5D36A9 | |||
| 3952 | software_reporter_tool.exe | C:\users\admin\desktop\em000_32.dll | executable | |
MD5:2AD7364C59F37DB236AB149ACE05FD10 | SHA256:C282F94F71CE00483B5D57C7A0EA5A44E70272DC2C8F4ABF3C5B1C8D9C860608 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |