File name:

ACRS Setup.exe

Full analysis: https://app.any.run/tasks/1c0d66b7-9c37-4126-b631-377f6b8a1377
Verdict: Malicious activity
Analysis date: July 18, 2025, 08:53:33
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows, 3 sections
MD5:

C8AA3490150F11107D14947834113BD9

SHA1:

40817B923277463034086FE5D5435C6A9BB27ED5

SHA256:

EE597BF2A2724DFECDA87D094141B67489FBC825AA23BAA3FD53DABA47BF9EC4

SSDEEP:

98304:fWW4q150YHkZs1iLlSc2+kL31SE4/hqIwCFZ74Vc8D1iXRhzyz0jp3BStT3YPFNC:I+sgBwJeDOe4v

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • ACRS Setup.exe (PID: 3504)
    • Executable content was dropped or overwritten

      • ACRS Setup.exe (PID: 3504)
    • Creates a software uninstall entry

      • ACRS Setup.exe (PID: 3504)
    • Searches for installed software

      • ACRS Setup.exe (PID: 3504)
    • Reads security settings of Internet Explorer

      • ACRS Setup.exe (PID: 3504)
    • Adds/modifies Windows certificates

      • ACRS Setup.exe (PID: 3504)
    • Creates a new Windows service

      • sc.exe (PID: 1944)
      • sc.exe (PID: 5504)
    • Windows service management via SC.EXE

      • sc.exe (PID: 1352)
      • sc.exe (PID: 4836)
    • The process creates files with name similar to system file names

      • ACRS Setup.exe (PID: 3504)
  • INFO

    • Checks supported languages

      • ACRS Setup.exe (PID: 3504)
      • ACRS.CfgTool.exe (PID: 5432)
    • Creates files in the program directory

      • ACRS Setup.exe (PID: 3504)
      • ACRS.CfgTool.exe (PID: 5432)
    • Reads the computer name

      • ACRS Setup.exe (PID: 3504)
      • ACRS.CfgTool.exe (PID: 5432)
    • The sample compiled with english language support

      • ACRS Setup.exe (PID: 3504)
    • Creates files or folders in the user directory

      • ACRS Setup.exe (PID: 3504)
    • Reads the machine GUID from the registry

      • ACRS Setup.exe (PID: 3504)
      • ACRS.CfgTool.exe (PID: 5432)
    • Process checks computer location settings

      • ACRS Setup.exe (PID: 3504)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic CIL Executable (.NET, Mono, etc.) (63.1)
.exe | Win64 Executable (generic) (23.8)
.dll | Win32 Dynamic Link Library (generic) (5.6)
.exe | Win32 Executable (generic) (3.8)
.exe | Generic Win/DOS Executable (1.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2016:12:15 15:17:16+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32
LinkerVersion: 48
CodeSize: 11542016
InitializedDataSize: 19968
UninitializedDataSize: -
EntryPoint: 0xb03db6
OSVersion: 4
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 3.4.5.7
ProductVersionNumber: 3.4.5.7
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: -
CompanyName: -
FileDescription: PatchTool
FileVersion: 3.4.5.7
InternalName: ACRS Setup.exe
LegalCopyright: Copyright © 2013
LegalTrademarks: -
OriginalFileName: ACRS Setup.exe
ProductName: PatchTool
ProductVersion: 3.4.5.7
AssemblyVersion: 3.4.5.7
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
148
Monitored processes
12
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start acrs setup.exe sc.exe no specs conhost.exe no specs sc.exe no specs conhost.exe no specs sc.exe no specs conhost.exe no specs sc.exe no specs conhost.exe no specs acrs.cfgtool.exe no specs slui.exe no specs acrs setup.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1352"C:\Windows\System32\sc.exe" description "ACRS Server" "3.4.5.7"C:\Windows\SysWOW64\sc.exeACRS Setup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Service Control Manager Configuration Tool
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\sc.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
1508\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exesc.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1944"C:\Windows\System32\sc.exe" create "ACRS Server" binPath= "C:\Program Files (x86)\ACS\ACRS Server\ACRS.Server.exe" start= auto displayName= "ACRS Server"C:\Windows\SysWOW64\sc.exeACRS Setup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Service Control Manager Configuration Tool
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\sc.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
2232\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exesc.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2348\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exesc.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3504"C:\Users\admin\Desktop\ACRS Setup.exe" C:\Users\admin\Desktop\ACRS Setup.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Description:
PatchTool
Version:
3.4.5.7
Modules
Images
c:\users\admin\desktop\acrs setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
4752"C:\Users\admin\Desktop\ACRS Setup.exe" C:\Users\admin\Desktop\ACRS Setup.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
PatchTool
Exit code:
3221226540
Version:
3.4.5.7
Modules
Images
c:\users\admin\desktop\acrs setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
4836"C:\Windows\System32\sc.exe" description "ACRS Update Service" "3.4.5.7"C:\Windows\SysWOW64\sc.exeACRS Setup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Service Control Manager Configuration Tool
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\sc.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
5432"C:\Program Files (x86)\ACS\ACRS Server\ACRS.CfgTool.exe" /serverC:\Program Files (x86)\ACS\ACRS Server\ACRS.CfgTool.exeACRS Setup.exe
User:
admin
Company:
ACS
Integrity Level:
HIGH
Description:
ACRS Configuration Tool
Version:
3.4.5.7
Modules
Images
c:\program files (x86)\acs\acrs server\acrs.cfgtool.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
5504"C:\Windows\System32\sc.exe" create "ACRS Update Service" binPath= "C:\Program Files (x86)\ACS\ACRS Server\ACRS.UpdateSrv.exe" start= auto displayName= "ACRS Update Service"C:\Windows\SysWOW64\sc.exeACRS Setup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Service Control Manager Configuration Tool
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\sc.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
Total events
1 612
Read events
1 584
Write events
25
Delete events
3

Modification events

(PID) Process:(3504) ACRS Setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fusion
Operation:writeName:DownloadCacheSize3
Value:
564
(PID) Process:(3504) ACRS Setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fusion
Operation:writeName:DownloadCacheSize3
Value:
640
(PID) Process:(3504) ACRS Setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fusion
Operation:writeName:DownloadCacheLocation
Value:
C:\Users\admin\AppData\Local\assembly\dl3\59M7BZ18.4ON\9KBKO0ZH.OAW
(PID) Process:(3504) ACRS Setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fusion
Operation:writeName:DownloadCacheSize3
Value:
356
(PID) Process:(3504) ACRS Setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fusion
Operation:writeName:DownloadCacheSize3
Value:
492
(PID) Process:(3504) ACRS Setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ACRS Server
Operation:writeName:DisplayName
Value:
ACRS Server
(PID) Process:(3504) ACRS Setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ACRS Server
Operation:writeName:InstallLocation
Value:
C:\Program Files (x86)\ACS\ACRS Server\
(PID) Process:(3504) ACRS Setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ACRS Server
Operation:writeName:UninstallString
Value:
"C:\ProgramData\ACRS\Installations\ACRS Server\ACRS Setup.exe" /product=server /action=uninstall /silent=0
(PID) Process:(3504) ACRS Setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ACRS Server
Operation:writeName:DisplayIcon
Value:
C:\Program Files (x86)\ACS\ACRS Server\server_48.ico
(PID) Process:(3504) ACRS Setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ACRS Server
Operation:writeName:Publisher
Value:
Xerox Services
Executable files
91
Suspicious files
6
Text files
17
Unknown types
5

Dropped files

PID
Process
Filename
Type
3504ACRS Setup.exeC:\ProgramData\ACRS\Patches\ACRS.AppLoader.exeexecutable
MD5:F2846CB36A9DE3FF3679E307B99002A7
SHA256:E00264FD09C2A4FB5E666FD203B46273A7839D57E3BA98E4F262D8BEB4E5CCE6
3504ACRS Setup.exeC:\ProgramData\ACRS\Patches\ACRS.UpdateSrv.exeexecutable
MD5:B2AA720A8C6E8A5FFC15FB5183BF993A
SHA256:C347BCCA0129A2C6EC279FCE4245A0B4F0EEFB70EC449E27C0401831B1873A27
3504ACRS Setup.exeC:\ProgramData\ACRS\Patches\ACRS.CfgTool.exeexecutable
MD5:A10FA785C8362403980401C39A127E93
SHA256:A440CB8477A6849058DF48AFC1F72AC8807F8785C8008E77FDAEE7FF39948CBE
3504ACRS Setup.exeC:\ProgramData\ACRS\Patches\ACRS.Manager.exe.configxml
MD5:F174BD89A6BEFEF79C467F1D8F0D2711
SHA256:504D43E5CEEE03A9964D0355FB09BBE54256DFF0CE6D15B1DDBBD1C41105129D
3504ACRS Setup.exeC:\ProgramData\ACRS\Patches\ACRS.Manager.exeexecutable
MD5:8645FF35D432B69CC4E3738F1C16D4CF
SHA256:E709406917C9238021B0BB806BF19188AC38AC899E82758BF31302A5BA666818
3504ACRS Setup.exeC:\ProgramData\ACRS\Patches\ACRS.Server.exeexecutable
MD5:821A017A782EA59285AAA25A41E6D04D
SHA256:2D978F33CFE76D0D0C3152D278A8782BC75B482ECB70A943197D24BAA16A77C7
3504ACRS Setup.exeC:\ProgramData\ACRS\Patches\ACRS.Runner.dllexecutable
MD5:0309D1135262649CEEF4A1720ED89AF1
SHA256:477741C36BC0B6B063EF6891D0913E12DDC5D892BDC3674197C6E5FDB1ECDE55
3504ACRS Setup.exeC:\ProgramData\ACRS\Patches\ACRS.Toolbar.exeexecutable
MD5:1ED57960B94023D9BDFACDA647493E55
SHA256:7CCC42896DDAEF6258E5BCC17FC80888C6442A9AC8739D821E21CA09A877180A
3504ACRS Setup.exeC:\ProgramData\ACRS\Patches\ACRS.ToolbarSrv.exeexecutable
MD5:3F858DDA03396C17EA6E5C13D77AC19F
SHA256:99C8C79F043140E6595CAB6295B8497A89B38EE3AE3997E5D36D47BD35EEFCC9
3504ACRS Setup.exeC:\ProgramData\ACRS\Patches\ACRS.UpdateActions.dllexecutable
MD5:AFAB980B6C1CEA32B7BCAD024460A08B
SHA256:18C2B600F621F654A78E928E1B00AE4E9C272D049E7D9914C6F2FD69D1C10F3F
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
23
DNS requests
16
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1268
svchost.exe
GET
200
2.16.241.14:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
1268
svchost.exe
GET
200
72.246.169.155:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
3584
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
1380
svchost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
3584
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1268
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:137
whitelisted
5944
MoUsoCoreWorker.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
188
RUXIMICS.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
1268
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1268
svchost.exe
2.16.241.14:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
1268
svchost.exe
72.246.169.155:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
5944
MoUsoCoreWorker.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1380
svchost.exe
20.190.159.2:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
  • 4.231.128.59
  • 51.104.136.2
whitelisted
google.com
  • 142.250.186.110
whitelisted
crl.microsoft.com
  • 2.16.241.14
  • 2.16.241.12
whitelisted
www.microsoft.com
  • 72.246.169.155
  • 95.101.149.131
whitelisted
login.live.com
  • 20.190.159.2
  • 20.190.159.23
  • 40.126.31.73
  • 40.126.31.0
  • 40.126.31.1
  • 40.126.31.2
  • 20.190.159.129
  • 40.126.31.130
whitelisted
ocsp.digicert.com
  • 184.30.131.245
whitelisted
client.wns.windows.com
  • 172.211.123.249
whitelisted
slscr.update.microsoft.com
  • 52.149.20.212
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 13.85.23.206
whitelisted
self.events.data.microsoft.com
  • 104.208.16.95
whitelisted

Threats

No threats detected
Process
Message
ACRS Setup.exe
Creating System Tmp Directory: C:\ProgramData\ACRS\Tmp\
ACRS Setup.exe
Creating User Data Directory: C:\Users\admin\AppData\Local\ACRS\
ACRS Setup.exe
Creating System Log Directory: C:\ProgramData\ACRS\Log\
ACRS Setup.exe
Creating Local Repository Directory: C:\Users\admin\AppData\Local\ACRS\Downloads\
ACRS Setup.exe
Creating Patch Backup Directory: C:\ProgramData\ACRS\Backups\
ACRS Setup.exe
Creating User Log Directory: C:\Users\admin\AppData\Local\ACRS\Log\
ACRS Setup.exe
Creating User Tmp Directory: C:\Users\admin\AppData\Local\ACRS\Tmp\