File name:

siinst.exe

Full analysis: https://app.any.run/tasks/96e7a64b-0177-4c22-a654-376d6d6bf08c
Verdict: Malicious activity
Analysis date: February 23, 2024, 21:31:07
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

18BC238BF7CA4F9DAD610604B857180A

SHA1:

C4A46C5883762368C24D3E944F409AAD54C3BF31

SHA256:

E7C2536EFB15B2137C4F4C07A94EBE37D396CEE2FFF0DFFE14BDBE4F8254E9DB

SSDEEP:

98304:6Yh+e+XdXD7IJkTi6PP4At/bgc50dPV5qnY:6Yke+NvIkz9/brOdPVcY

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • siinst.exe (PID: 3864)
      • siinst.exe (PID: 3948)
      • siinst.tmp (PID: 3464)
    • Changes the autorun value in the registry

      • siinst.tmp (PID: 3464)
    • Uses Task Scheduler to autorun other applications

      • siinst.tmp (PID: 3464)
    • Actions looks like stealing of personal data

      • softinfo.exe (PID: 956)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • siinst.exe (PID: 3948)
      • siinst.exe (PID: 3864)
      • siinst.tmp (PID: 3464)
    • Process drops legitimate windows executable

      • siinst.tmp (PID: 3464)
    • Reads the Windows owner or organization settings

      • siinst.tmp (PID: 3464)
    • The process drops C-runtime libraries

      • siinst.tmp (PID: 3464)
    • Changes Internet Explorer settings (feature browser emulation)

      • siinst.tmp (PID: 3464)
    • Reads the Internet Settings

      • softinfo.exe (PID: 3212)
      • softinfo.exe (PID: 956)
      • softinfo.exe (PID: 2592)
    • Searches for installed software

      • softinfo.exe (PID: 956)
    • Reads settings of System Certificates

      • softinfo.exe (PID: 956)
    • Reads Internet Explorer settings

      • softinfo.exe (PID: 956)
    • Reads security settings of Internet Explorer

      • softinfo.exe (PID: 956)
    • Reads Microsoft Outlook installation path

      • softinfo.exe (PID: 956)
    • Checks Windows Trust Settings

      • softinfo.exe (PID: 956)
  • INFO

    • Reads the computer name

      • siinst.tmp (PID: 2160)
      • siinst.tmp (PID: 3464)
      • softinfo.exe (PID: 3212)
      • softinfo.exe (PID: 956)
      • softinfo.exe (PID: 2592)
    • Checks supported languages

      • siinst.exe (PID: 3864)
      • siinst.tmp (PID: 2160)
      • siinst.exe (PID: 3948)
      • siinst.tmp (PID: 3464)
      • softinfo.exe (PID: 3212)
      • softinfo.exe (PID: 956)
      • softinfo.exe (PID: 2592)
    • Create files in a temporary directory

      • siinst.exe (PID: 3864)
      • siinst.exe (PID: 3948)
      • siinst.tmp (PID: 3464)
      • softinfo.exe (PID: 956)
    • Creates files or folders in the user directory

      • siinst.tmp (PID: 3464)
      • softinfo.exe (PID: 956)
    • Creates files in the program directory

      • siinst.tmp (PID: 3464)
      • softinfo.exe (PID: 956)
    • Creates a software uninstall entry

      • siinst.tmp (PID: 3464)
    • Reads CPU info

      • softinfo.exe (PID: 3212)
    • Checks proxy server information

      • softinfo.exe (PID: 3212)
      • softinfo.exe (PID: 956)
      • softinfo.exe (PID: 2592)
    • Reads the time zone

      • softinfo.exe (PID: 3212)
    • Reads the machine GUID from the registry

      • softinfo.exe (PID: 3212)
      • softinfo.exe (PID: 956)
    • Reads the software policy settings

      • softinfo.exe (PID: 956)
    • Manual execution by a user

      • softinfo.exe (PID: 2592)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable Delphi generic (45.2)
.dll | Win32 Dynamic Link Library (generic) (20.9)
.exe | Win32 Executable (generic) (14.3)
.exe | Win16/32 Executable Delphi generic (6.6)
.exe | Generic Win/DOS Executable (6.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2016:01:15 08:22:50+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 65024
InitializedDataSize: 53248
UninitializedDataSize: -
EntryPoint: 0x113bc
OSVersion: 5
ImageVersion: 6
SubsystemVersion: 5
Subsystem: Windows GUI
FileVersionNumber: 0.0.0.0
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: Informer Technologies, Inc.
FileDescription: Software Informer Setup
FileVersion:
LegalCopyright:
ProductName: Software Informer
ProductVersion:
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
50
Monitored processes
8
Malicious processes
5
Suspicious processes
1

Behavior graph

Click at the process to see the details
start siinst.exe siinst.tmp no specs siinst.exe siinst.tmp schtasks.exe no specs softinfo.exe no specs softinfo.exe softinfo.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
120"schtasks.exe" /create /sc onlogon /tn SoftwareInformerService /f /rl highest /tr "\"C:\Program Files\Software Informer\softinfo.exe\" -service"C:\Windows\System32\schtasks.exesiinst.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Manages scheduled tasks
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
956"C:\Program Files\Software Informer\softinfo.exe"C:\Program Files\Software Informer\softinfo.exe
siinst.tmp
User:
admin
Company:
Informer Technologies, Inc.
Integrity Level:
MEDIUM
Description:
Software Informer
Exit code:
0
Version:
1.5.1346.0
Modules
Images
c:\program files\software informer\softinfo.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2160"C:\Users\admin\AppData\Local\Temp\is-HU7IK.tmp\siinst.tmp" /SL5="$E0170,3521793,119296,C:\Users\admin\AppData\Local\Temp\siinst.exe" C:\Users\admin\AppData\Local\Temp\is-HU7IK.tmp\siinst.tmpsiinst.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-hu7ik.tmp\siinst.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2592"C:\Program Files\Software Informer\softinfo.exe" C:\Program Files\Software Informer\softinfo.exeexplorer.exe
User:
admin
Company:
Informer Technologies, Inc.
Integrity Level:
MEDIUM
Description:
Software Informer
Exit code:
0
Version:
1.5.1346.0
Modules
Images
c:\program files\software informer\softinfo.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3212"C:\Program Files\Software Informer\softinfo.exe" -serviceC:\Program Files\Software Informer\softinfo.exesiinst.tmp
User:
admin
Company:
Informer Technologies, Inc.
Integrity Level:
HIGH
Description:
Software Informer
Exit code:
0
Version:
1.5.1346.0
Modules
Images
c:\program files\software informer\softinfo.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3464"C:\Users\admin\AppData\Local\Temp\is-U4UO1.tmp\siinst.tmp" /SL5="$F0130,3521793,119296,C:\Users\admin\AppData\Local\Temp\siinst.exe" /SPAWNWND=$18013E /NOTIFYWND=$E0170 C:\Users\admin\AppData\Local\Temp\is-U4UO1.tmp\siinst.tmp
siinst.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-u4uo1.tmp\siinst.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
3864"C:\Users\admin\AppData\Local\Temp\siinst.exe" C:\Users\admin\AppData\Local\Temp\siinst.exe
explorer.exe
User:
admin
Company:
Informer Technologies, Inc.
Integrity Level:
MEDIUM
Description:
Software Informer Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\appdata\local\temp\siinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
3948"C:\Users\admin\AppData\Local\Temp\siinst.exe" /SPAWNWND=$18013E /NOTIFYWND=$E0170 C:\Users\admin\AppData\Local\Temp\siinst.exe
siinst.tmp
User:
admin
Company:
Informer Technologies, Inc.
Integrity Level:
HIGH
Description:
Software Informer Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\appdata\local\temp\siinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
Total events
16 726
Read events
16 640
Write events
77
Delete events
9

Modification events

(PID) Process:(3464) siinst.tmpKey:HKEY_CURRENT_USER\Software\Informer Technologies, Inc.\Software Informer
Operation:writeName:Path
Value:
C:\Program Files\Software Informer
(PID) Process:(3464) siinst.tmpKey:HKEY_CURRENT_USER\Software\Informer Technologies, Inc.\Software Informer\Settings
Operation:writeName:DisablePUL
Value:
0
(PID) Process:(3464) siinst.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
Operation:writeName:Software Informer
Value:
"C:\Program Files\Software Informer\softinfo.exe" -autorun
(PID) Process:(3464) siinst.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
Operation:delete valueName:fsm
Value:
(PID) Process:(3464) siinst.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\LocalDumps\softinfo.exe
Operation:writeName:DumpFolder
Value:
C:\Users\admin\AppData\Roaming\Software Informer\WerDumps
(PID) Process:(3464) siinst.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\LocalDumps\softinfo.exe
Operation:writeName:DumpCount
Value:
3
(PID) Process:(3464) siinst.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION
Operation:writeName:softinfo.exe
Value:
11000
(PID) Process:(3464) siinst.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION
Operation:writeName:softinfo.exe
Value:
11000
(PID) Process:(3464) siinst.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_GPU_RENDERING
Operation:writeName:softinfo.exe
Value:
0
(PID) Process:(3464) siinst.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_GPU_RENDERING
Operation:writeName:softinfo.exe
Value:
0
Executable files
28
Suspicious files
32
Text files
223
Unknown types
9

Dropped files

PID
Process
Filename
Type
3464siinst.tmpC:\Program Files\Software Informer\is-RB8I4.tmpexecutable
MD5:2A478D6E4134BBA048226B1C055F70B2
SHA256:9D11AB1BA6D95008CE302C1BA7AB6EBA6436760751F33A3E250E59CCD18486D2
3464siinst.tmpC:\Program Files\Software Informer\unins000.exeexecutable
MD5:2A478D6E4134BBA048226B1C055F70B2
SHA256:9D11AB1BA6D95008CE302C1BA7AB6EBA6436760751F33A3E250E59CCD18486D2
3464siinst.tmpC:\Users\admin\AppData\Local\Temp\is-QJFB6.tmp\InstallHelper.dllexecutable
MD5:A2B2EF9F5BBB9697A3EBB01F08EF837E
SHA256:FA896DBFB2DABF64D203067B007CC8BDF379CFDA6E4BD62B5EF3B008DB598254
3464siinst.tmpC:\Users\admin\AppData\Local\Temp\is-QJFB6.tmp\_isetup\_shfoldr.dllexecutable
MD5:92DC6EF532FBB4A5C3201469A5B5EB63
SHA256:9884E9D1B4F8A873CCBD81F8AD0AE257776D2348D027D811A56475E028360D87
3464siinst.tmpC:\Program Files\Software Informer\is-HQK09.tmpexecutable
MD5:1EE8D767059ED6A729AD941210D7A0CB
SHA256:3311E3BA5F6CCC3010FA925DB20D34651CACCA9F83BF15715047285515C4A9F7
3464siinst.tmpC:\Program Files\Software Informer\is-LMDIB.tmpexecutable
MD5:0D127254F49DC2E10876C08B8A4491F5
SHA256:8077F7C4F693AED7B48A458DDB5D03ED6883DBA7DB6F9BC4AAE03BB8C929C484
3464siinst.tmpC:\Program Files\Software Informer\core.dllexecutable
MD5:8AD0AE6B1737AB59E704A3377BB047E0
SHA256:37C987E7845824C4CB73734AB3864DBA439599C4A37DF6A637E30CE50971A40F
3464siinst.tmpC:\Program Files\Software Informer\winunivappfeatures.dllexecutable
MD5:1EE8D767059ED6A729AD941210D7A0CB
SHA256:3311E3BA5F6CCC3010FA925DB20D34651CACCA9F83BF15715047285515C4A9F7
3864siinst.exeC:\Users\admin\AppData\Local\Temp\is-HU7IK.tmp\siinst.tmpexecutable
MD5:2A478D6E4134BBA048226B1C055F70B2
SHA256:9D11AB1BA6D95008CE302C1BA7AB6EBA6436760751F33A3E250E59CCD18486D2
3948siinst.exeC:\Users\admin\AppData\Local\Temp\is-U4UO1.tmp\siinst.tmpexecutable
MD5:2A478D6E4134BBA048226B1C055F70B2
SHA256:9D11AB1BA6D95008CE302C1BA7AB6EBA6436760751F33A3E250E59CCD18486D2
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
13
TCP/UDP connections
52
DNS requests
16
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
956
softinfo.exe
GET
200
104.18.38.233:80
http://ocsp.comodoca.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRTtU9uFqgVGHhJwXZyWCNXmVR5ngQUoBEKIz6W8Qfs4q8p74Klf9AwpLQCEDlyRDr5IrdR19NsEN0xNZU%3D
unknown
binary
1.42 Kb
unknown
956
softinfo.exe
GET
304
92.123.27.139:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?35e9e893bb2db86c
unknown
unknown
956
softinfo.exe
GET
200
172.64.149.23:80
http://ocsp.usertrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTNMNJMNDqCqx8FcBWK16EHdimS6QQUU3m%2FWqorSs9UgOHYm8Cd8rIDZssCEH1bUSa0droR23QWC7xTDac%3D
unknown
binary
2.18 Kb
unknown
956
softinfo.exe
GET
200
172.64.149.23:80
http://ocsp.sectigo.com/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBRDC9IOTxN6GmyRjyTl2n4yTUczyAQUjYxexFStiuF36Zv5mwXhuAGNYeECEQDlubT3XUfB0sSasgxSuLVn
unknown
binary
472 b
unknown
1080
svchost.exe
GET
200
92.123.27.139:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?c503292d7802e201
unknown
compressed
65.2 Kb
unknown
1080
svchost.exe
GET
304
92.123.27.139:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?1b8fee253118cbef
unknown
compressed
65.2 Kb
unknown
956
softinfo.exe
GET
200
74.117.179.74:80
http://si5-s0.infcdn.net/img/win_v3/refresh_bg.png
unknown
image
4.52 Kb
unknown
956
softinfo.exe
GET
200
142.251.36.227:80
http://ocsp.pki.goog/gsr1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCEHe9DWzbNvka6iEPxPBY0w0%3D
unknown
binary
1.41 Kb
unknown
956
softinfo.exe
GET
200
172.64.149.23:80
http://ocsp.sectigo.com/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBRDC9IOTxN6GmyRjyTl2n4yTUczyAQUjYxexFStiuF36Zv5mwXhuAGNYeECEQDULZtoZwMKKCpIv95kbt0N
unknown
binary
472 b
unknown
956
softinfo.exe
GET
200
142.251.36.227:80
http://ocsp.pki.goog/gtsr1/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBQwkcLWD4LqGJ7bE7B1XZsEbmfwUAQU5K8rJnEaK0gnhS9SZizv8IkTcT4CDQIDvFNZazTHGPUBUGY%3D
unknown
binary
724 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
956
softinfo.exe
208.88.224.105:443
si.informer.com
WZCOM
US
unknown
956
softinfo.exe
92.123.27.139:80
ctldl.windowsupdate.com
AKAMAI-AS
AT
unknown
956
softinfo.exe
104.18.38.233:80
ocsp.comodoca.com
CLOUDFLARENET
shared
956
softinfo.exe
172.64.149.23:80
ocsp.usertrust.com
CLOUDFLARENET
US
unknown
1080
svchost.exe
92.123.27.139:80
ctldl.windowsupdate.com
AKAMAI-AS
AT
unknown
956
softinfo.exe
74.117.179.70:443
img.informer.com
WZCOM
US
unknown
956
softinfo.exe
216.239.36.178:443
www.google-analytics.com
GOOGLE
US
unknown

DNS requests

Domain
IP
Reputation
si.informer.com
  • 208.88.224.105
unknown
ctldl.windowsupdate.com
  • 92.123.27.139
whitelisted
ocsp.comodoca.com
  • 104.18.38.233
whitelisted
ocsp.usertrust.com
  • 172.64.149.23
whitelisted
ocsp.sectigo.com
  • 172.64.149.23
whitelisted
si5.informer.com
  • 208.88.224.105
unknown
img.informer.com
  • 74.117.179.70
whitelisted
ssl.google-analytics.com
  • 142.251.37.8
whitelisted
si5-s0.infcdn.net
  • 74.117.179.74
unknown
www.google-analytics.com
  • 216.239.36.178
whitelisted

Threats

No threats detected
No debug info