| File name: | ACRS Setup.exe |
| Full analysis: | https://app.any.run/tasks/1c0d66b7-9c37-4126-b631-377f6b8a1377 |
| Verdict: | Malicious activity |
| Analysis date: | July 18, 2025, 08:53:33 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows, 3 sections |
| MD5: | C8AA3490150F11107D14947834113BD9 |
| SHA1: | 40817B923277463034086FE5D5435C6A9BB27ED5 |
| SHA256: | EE597BF2A2724DFECDA87D094141B67489FBC825AA23BAA3FD53DABA47BF9EC4 |
| SSDEEP: | 98304:fWW4q150YHkZs1iLlSc2+kL31SE4/hqIwCFZ74Vc8D1iXRhzyz0jp3BStT3YPFNC:I+sgBwJeDOe4v |
| .exe | | | Generic CIL Executable (.NET, Mono, etc.) (63.1) |
|---|---|---|
| .exe | | | Win64 Executable (generic) (23.8) |
| .dll | | | Win32 Dynamic Link Library (generic) (5.6) |
| .exe | | | Win32 Executable (generic) (3.8) |
| .exe | | | Generic Win/DOS Executable (1.7) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2016:12:15 15:17:16+00:00 |
| ImageFileCharacteristics: | Executable, Large address aware |
| PEType: | PE32 |
| LinkerVersion: | 48 |
| CodeSize: | 11542016 |
| InitializedDataSize: | 19968 |
| UninitializedDataSize: | - |
| EntryPoint: | 0xb03db6 |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 6 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 3.4.5.7 |
| ProductVersionNumber: | 3.4.5.7 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| Comments: | - |
| CompanyName: | - |
| FileDescription: | PatchTool |
| FileVersion: | 3.4.5.7 |
| InternalName: | ACRS Setup.exe |
| LegalCopyright: | Copyright © 2013 |
| LegalTrademarks: | - |
| OriginalFileName: | ACRS Setup.exe |
| ProductName: | PatchTool |
| ProductVersion: | 3.4.5.7 |
| AssemblyVersion: | 3.4.5.7 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1352 | "C:\Windows\System32\sc.exe" description "ACRS Server" "3.4.5.7" | C:\Windows\SysWOW64\sc.exe | — | ACRS Setup.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Service Control Manager Configuration Tool Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1508 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | sc.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1944 | "C:\Windows\System32\sc.exe" create "ACRS Server" binPath= "C:\Program Files (x86)\ACS\ACRS Server\ACRS.Server.exe" start= auto displayName= "ACRS Server" | C:\Windows\SysWOW64\sc.exe | — | ACRS Setup.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Service Control Manager Configuration Tool Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2232 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | sc.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2348 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | sc.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 3504 | "C:\Users\admin\Desktop\ACRS Setup.exe" | C:\Users\admin\Desktop\ACRS Setup.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: PatchTool Version: 3.4.5.7 Modules
| |||||||||||||||
| 4752 | "C:\Users\admin\Desktop\ACRS Setup.exe" | C:\Users\admin\Desktop\ACRS Setup.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: PatchTool Exit code: 3221226540 Version: 3.4.5.7 Modules
| |||||||||||||||
| 4836 | "C:\Windows\System32\sc.exe" description "ACRS Update Service" "3.4.5.7" | C:\Windows\SysWOW64\sc.exe | — | ACRS Setup.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Service Control Manager Configuration Tool Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 5432 | "C:\Program Files (x86)\ACS\ACRS Server\ACRS.CfgTool.exe" /server | C:\Program Files (x86)\ACS\ACRS Server\ACRS.CfgTool.exe | — | ACRS Setup.exe | |||||||||||
User: admin Company: ACS Integrity Level: HIGH Description: ACRS Configuration Tool Version: 3.4.5.7 Modules
| |||||||||||||||
| 5504 | "C:\Windows\System32\sc.exe" create "ACRS Update Service" binPath= "C:\Program Files (x86)\ACS\ACRS Server\ACRS.UpdateSrv.exe" start= auto displayName= "ACRS Update Service" | C:\Windows\SysWOW64\sc.exe | — | ACRS Setup.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Service Control Manager Configuration Tool Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| (PID) Process: | (3504) ACRS Setup.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fusion |
| Operation: | write | Name: | DownloadCacheSize3 |
Value: 564 | |||
| (PID) Process: | (3504) ACRS Setup.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fusion |
| Operation: | write | Name: | DownloadCacheSize3 |
Value: 640 | |||
| (PID) Process: | (3504) ACRS Setup.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fusion |
| Operation: | write | Name: | DownloadCacheLocation |
Value: C:\Users\admin\AppData\Local\assembly\dl3\59M7BZ18.4ON\9KBKO0ZH.OAW | |||
| (PID) Process: | (3504) ACRS Setup.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fusion |
| Operation: | write | Name: | DownloadCacheSize3 |
Value: 356 | |||
| (PID) Process: | (3504) ACRS Setup.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fusion |
| Operation: | write | Name: | DownloadCacheSize3 |
Value: 492 | |||
| (PID) Process: | (3504) ACRS Setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ACRS Server |
| Operation: | write | Name: | DisplayName |
Value: ACRS Server | |||
| (PID) Process: | (3504) ACRS Setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ACRS Server |
| Operation: | write | Name: | InstallLocation |
Value: C:\Program Files (x86)\ACS\ACRS Server\ | |||
| (PID) Process: | (3504) ACRS Setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ACRS Server |
| Operation: | write | Name: | UninstallString |
Value: "C:\ProgramData\ACRS\Installations\ACRS Server\ACRS Setup.exe" /product=server /action=uninstall /silent=0 | |||
| (PID) Process: | (3504) ACRS Setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ACRS Server |
| Operation: | write | Name: | DisplayIcon |
Value: C:\Program Files (x86)\ACS\ACRS Server\server_48.ico | |||
| (PID) Process: | (3504) ACRS Setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ACRS Server |
| Operation: | write | Name: | Publisher |
Value: Xerox Services | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3504 | ACRS Setup.exe | C:\ProgramData\ACRS\Patches\ACRS.AppLoader.exe | executable | |
MD5:F2846CB36A9DE3FF3679E307B99002A7 | SHA256:E00264FD09C2A4FB5E666FD203B46273A7839D57E3BA98E4F262D8BEB4E5CCE6 | |||
| 3504 | ACRS Setup.exe | C:\ProgramData\ACRS\Patches\ACRS.UpdateSrv.exe | executable | |
MD5:B2AA720A8C6E8A5FFC15FB5183BF993A | SHA256:C347BCCA0129A2C6EC279FCE4245A0B4F0EEFB70EC449E27C0401831B1873A27 | |||
| 3504 | ACRS Setup.exe | C:\ProgramData\ACRS\Patches\ACRS.CfgTool.exe | executable | |
MD5:A10FA785C8362403980401C39A127E93 | SHA256:A440CB8477A6849058DF48AFC1F72AC8807F8785C8008E77FDAEE7FF39948CBE | |||
| 3504 | ACRS Setup.exe | C:\ProgramData\ACRS\Patches\ACRS.Manager.exe.config | xml | |
MD5:F174BD89A6BEFEF79C467F1D8F0D2711 | SHA256:504D43E5CEEE03A9964D0355FB09BBE54256DFF0CE6D15B1DDBBD1C41105129D | |||
| 3504 | ACRS Setup.exe | C:\ProgramData\ACRS\Patches\ACRS.Manager.exe | executable | |
MD5:8645FF35D432B69CC4E3738F1C16D4CF | SHA256:E709406917C9238021B0BB806BF19188AC38AC899E82758BF31302A5BA666818 | |||
| 3504 | ACRS Setup.exe | C:\ProgramData\ACRS\Patches\ACRS.Server.exe | executable | |
MD5:821A017A782EA59285AAA25A41E6D04D | SHA256:2D978F33CFE76D0D0C3152D278A8782BC75B482ECB70A943197D24BAA16A77C7 | |||
| 3504 | ACRS Setup.exe | C:\ProgramData\ACRS\Patches\ACRS.Runner.dll | executable | |
MD5:0309D1135262649CEEF4A1720ED89AF1 | SHA256:477741C36BC0B6B063EF6891D0913E12DDC5D892BDC3674197C6E5FDB1ECDE55 | |||
| 3504 | ACRS Setup.exe | C:\ProgramData\ACRS\Patches\ACRS.Toolbar.exe | executable | |
MD5:1ED57960B94023D9BDFACDA647493E55 | SHA256:7CCC42896DDAEF6258E5BCC17FC80888C6442A9AC8739D821E21CA09A877180A | |||
| 3504 | ACRS Setup.exe | C:\ProgramData\ACRS\Patches\ACRS.ToolbarSrv.exe | executable | |
MD5:3F858DDA03396C17EA6E5C13D77AC19F | SHA256:99C8C79F043140E6595CAB6295B8497A89B38EE3AE3997E5D36D47BD35EEFCC9 | |||
| 3504 | ACRS Setup.exe | C:\ProgramData\ACRS\Patches\ACRS.UpdateActions.dll | executable | |
MD5:AFAB980B6C1CEA32B7BCAD024460A08B | SHA256:18C2B600F621F654A78E928E1B00AE4E9C272D049E7D9914C6F2FD69D1C10F3F | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
1268 | svchost.exe | GET | 200 | 2.16.241.14:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
1268 | svchost.exe | GET | 200 | 72.246.169.155:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
3584 | SIHClient.exe | GET | 200 | 95.101.149.131:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
1380 | svchost.exe | GET | 200 | 184.30.131.245:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
3584 | SIHClient.exe | GET | 200 | 95.101.149.131:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
1268 | svchost.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
5944 | MoUsoCoreWorker.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
188 | RUXIMICS.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1268 | svchost.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
1268 | svchost.exe | 2.16.241.14:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
1268 | svchost.exe | 72.246.169.155:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
5944 | MoUsoCoreWorker.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
1380 | svchost.exe | 20.190.159.2:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
login.live.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |
fe3cr.delivery.mp.microsoft.com |
| whitelisted |
self.events.data.microsoft.com |
| whitelisted |
Process | Message |
|---|---|
ACRS Setup.exe | Creating System Tmp Directory: C:\ProgramData\ACRS\Tmp\
|
ACRS Setup.exe | Creating User Data Directory: C:\Users\admin\AppData\Local\ACRS\
|
ACRS Setup.exe | Creating System Log Directory: C:\ProgramData\ACRS\Log\
|
ACRS Setup.exe | Creating Local Repository Directory: C:\Users\admin\AppData\Local\ACRS\Downloads\
|
ACRS Setup.exe | Creating Patch Backup Directory: C:\ProgramData\ACRS\Backups\
|
ACRS Setup.exe | Creating User Log Directory: C:\Users\admin\AppData\Local\ACRS\Log\
|
ACRS Setup.exe | Creating User Tmp Directory: C:\Users\admin\AppData\Local\ACRS\Tmp\
|