File name:

ACRS Setup.exe

Full analysis: https://app.any.run/tasks/1c0d66b7-9c37-4126-b631-377f6b8a1377
Verdict: Malicious activity
Analysis date: July 18, 2025, 08:53:33
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows, 3 sections
MD5:

C8AA3490150F11107D14947834113BD9

SHA1:

40817B923277463034086FE5D5435C6A9BB27ED5

SHA256:

EE597BF2A2724DFECDA87D094141B67489FBC825AA23BAA3FD53DABA47BF9EC4

SSDEEP:

98304:fWW4q150YHkZs1iLlSc2+kL31SE4/hqIwCFZ74Vc8D1iXRhzyz0jp3BStT3YPFNC:I+sgBwJeDOe4v

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • ACRS Setup.exe (PID: 3504)
    • The process creates files with name similar to system file names

      • ACRS Setup.exe (PID: 3504)
    • Searches for installed software

      • ACRS Setup.exe (PID: 3504)
    • Adds/modifies Windows certificates

      • ACRS Setup.exe (PID: 3504)
    • Creates a software uninstall entry

      • ACRS Setup.exe (PID: 3504)
    • Executable content was dropped or overwritten

      • ACRS Setup.exe (PID: 3504)
    • Creates a new Windows service

      • sc.exe (PID: 1944)
      • sc.exe (PID: 5504)
    • Reads security settings of Internet Explorer

      • ACRS Setup.exe (PID: 3504)
    • Windows service management via SC.EXE

      • sc.exe (PID: 1352)
      • sc.exe (PID: 4836)
  • INFO

    • Reads the computer name

      • ACRS Setup.exe (PID: 3504)
      • ACRS.CfgTool.exe (PID: 5432)
    • Creates files in the program directory

      • ACRS Setup.exe (PID: 3504)
      • ACRS.CfgTool.exe (PID: 5432)
    • Checks supported languages

      • ACRS Setup.exe (PID: 3504)
      • ACRS.CfgTool.exe (PID: 5432)
    • The sample compiled with english language support

      • ACRS Setup.exe (PID: 3504)
    • Reads the machine GUID from the registry

      • ACRS Setup.exe (PID: 3504)
      • ACRS.CfgTool.exe (PID: 5432)
    • Creates files or folders in the user directory

      • ACRS Setup.exe (PID: 3504)
    • Process checks computer location settings

      • ACRS Setup.exe (PID: 3504)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic CIL Executable (.NET, Mono, etc.) (63.1)
.exe | Win64 Executable (generic) (23.8)
.dll | Win32 Dynamic Link Library (generic) (5.6)
.exe | Win32 Executable (generic) (3.8)
.exe | Generic Win/DOS Executable (1.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2016:12:15 15:17:16+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32
LinkerVersion: 48
CodeSize: 11542016
InitializedDataSize: 19968
UninitializedDataSize: -
EntryPoint: 0xb03db6
OSVersion: 4
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 3.4.5.7
ProductVersionNumber: 3.4.5.7
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: -
CompanyName: -
FileDescription: PatchTool
FileVersion: 3.4.5.7
InternalName: ACRS Setup.exe
LegalCopyright: Copyright © 2013
LegalTrademarks: -
OriginalFileName: ACRS Setup.exe
ProductName: PatchTool
ProductVersion: 3.4.5.7
AssemblyVersion: 3.4.5.7
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
148
Monitored processes
12
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start acrs setup.exe sc.exe no specs conhost.exe no specs sc.exe no specs conhost.exe no specs sc.exe no specs conhost.exe no specs sc.exe no specs conhost.exe no specs acrs.cfgtool.exe no specs slui.exe no specs acrs setup.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1352"C:\Windows\System32\sc.exe" description "ACRS Server" "3.4.5.7"C:\Windows\SysWOW64\sc.exeACRS Setup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Service Control Manager Configuration Tool
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\sc.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
1508\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exesc.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1944"C:\Windows\System32\sc.exe" create "ACRS Server" binPath= "C:\Program Files (x86)\ACS\ACRS Server\ACRS.Server.exe" start= auto displayName= "ACRS Server"C:\Windows\SysWOW64\sc.exeACRS Setup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Service Control Manager Configuration Tool
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\sc.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
2232\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exesc.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2348\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exesc.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3504"C:\Users\admin\Desktop\ACRS Setup.exe" C:\Users\admin\Desktop\ACRS Setup.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Description:
PatchTool
Version:
3.4.5.7
Modules
Images
c:\users\admin\desktop\acrs setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
4752"C:\Users\admin\Desktop\ACRS Setup.exe" C:\Users\admin\Desktop\ACRS Setup.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
PatchTool
Exit code:
3221226540
Version:
3.4.5.7
Modules
Images
c:\users\admin\desktop\acrs setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
4836"C:\Windows\System32\sc.exe" description "ACRS Update Service" "3.4.5.7"C:\Windows\SysWOW64\sc.exeACRS Setup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Service Control Manager Configuration Tool
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\sc.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
5432"C:\Program Files (x86)\ACS\ACRS Server\ACRS.CfgTool.exe" /serverC:\Program Files (x86)\ACS\ACRS Server\ACRS.CfgTool.exeACRS Setup.exe
User:
admin
Company:
ACS
Integrity Level:
HIGH
Description:
ACRS Configuration Tool
Version:
3.4.5.7
Modules
Images
c:\program files (x86)\acs\acrs server\acrs.cfgtool.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
5504"C:\Windows\System32\sc.exe" create "ACRS Update Service" binPath= "C:\Program Files (x86)\ACS\ACRS Server\ACRS.UpdateSrv.exe" start= auto displayName= "ACRS Update Service"C:\Windows\SysWOW64\sc.exeACRS Setup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Service Control Manager Configuration Tool
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\sc.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
Total events
1 612
Read events
1 584
Write events
25
Delete events
3

Modification events

(PID) Process:(3504) ACRS Setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fusion
Operation:writeName:DownloadCacheSize3
Value:
564
(PID) Process:(3504) ACRS Setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fusion
Operation:writeName:DownloadCacheSize3
Value:
640
(PID) Process:(3504) ACRS Setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fusion
Operation:writeName:DownloadCacheLocation
Value:
C:\Users\admin\AppData\Local\assembly\dl3\59M7BZ18.4ON\9KBKO0ZH.OAW
(PID) Process:(3504) ACRS Setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fusion
Operation:writeName:DownloadCacheSize3
Value:
356
(PID) Process:(3504) ACRS Setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fusion
Operation:writeName:DownloadCacheSize3
Value:
492
(PID) Process:(3504) ACRS Setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ACRS Server
Operation:writeName:DisplayName
Value:
ACRS Server
(PID) Process:(3504) ACRS Setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ACRS Server
Operation:writeName:InstallLocation
Value:
C:\Program Files (x86)\ACS\ACRS Server\
(PID) Process:(3504) ACRS Setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ACRS Server
Operation:writeName:UninstallString
Value:
"C:\ProgramData\ACRS\Installations\ACRS Server\ACRS Setup.exe" /product=server /action=uninstall /silent=0
(PID) Process:(3504) ACRS Setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ACRS Server
Operation:writeName:DisplayIcon
Value:
C:\Program Files (x86)\ACS\ACRS Server\server_48.ico
(PID) Process:(3504) ACRS Setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ACRS Server
Operation:writeName:Publisher
Value:
Xerox Services
Executable files
91
Suspicious files
6
Text files
17
Unknown types
5

Dropped files

PID
Process
Filename
Type
3504ACRS Setup.exeC:\ProgramData\ACRS\Patches\ACRS.ClientConfig.exeexecutable
MD5:C831D4E18DB107DD83A597C008012A4B
SHA256:50092472E626621EA2518FBFD0CB71C836B81A4E0B6B0DFE749EE489A6D0F7AC
3504ACRS Setup.exeC:\ProgramData\ACRS\Patches\ACRS.AppLoader.exeexecutable
MD5:F2846CB36A9DE3FF3679E307B99002A7
SHA256:E00264FD09C2A4FB5E666FD203B46273A7839D57E3BA98E4F262D8BEB4E5CCE6
3504ACRS Setup.exeC:\ProgramData\ACRS\Patches\ACRS.Cmd.exeexecutable
MD5:8734BF2451F6F593904C22138F926D3A
SHA256:CEAA393C3F9876EAA502B86D178F98895EDC597FF5F2391809CDA910019021C8
3504ACRS Setup.exeC:\ProgramData\ACRS\Patches\ACRS.Server.exeexecutable
MD5:821A017A782EA59285AAA25A41E6D04D
SHA256:2D978F33CFE76D0D0C3152D278A8782BC75B482ECB70A943197D24BAA16A77C7
3504ACRS Setup.exeC:\ProgramData\ACRS\Patches\ACRS.CfgTool.exeexecutable
MD5:A10FA785C8362403980401C39A127E93
SHA256:A440CB8477A6849058DF48AFC1F72AC8807F8785C8008E77FDAEE7FF39948CBE
3504ACRS Setup.exeC:\ProgramData\ACRS\Patches\ACRS.Manager.exe.configxml
MD5:F174BD89A6BEFEF79C467F1D8F0D2711
SHA256:504D43E5CEEE03A9964D0355FB09BBE54256DFF0CE6D15B1DDBBD1C41105129D
3504ACRS Setup.exeC:\ProgramData\ACRS\Patches\ACRS.Manager.exeexecutable
MD5:8645FF35D432B69CC4E3738F1C16D4CF
SHA256:E709406917C9238021B0BB806BF19188AC38AC899E82758BF31302A5BA666818
3504ACRS Setup.exeC:\ProgramData\ACRS\Patches\ACRS.Runner.dllexecutable
MD5:0309D1135262649CEEF4A1720ED89AF1
SHA256:477741C36BC0B6B063EF6891D0913E12DDC5D892BDC3674197C6E5FDB1ECDE55
3504ACRS Setup.exeC:\ProgramData\ACRS\Patches\ACRS.Common.dllexecutable
MD5:AF0E0DAD3B343FF7567FC3A7B9323EBD
SHA256:97D7FCDD25C7DEFEB6A98E8E3D0334072A339220A54B05ACFBD4EAC0D5EF831A
3504ACRS Setup.exeC:\ProgramData\ACRS\Patches\ACRS.Watcher.exeexecutable
MD5:D61A231340E6C597D703A72EB3AB2436
SHA256:40F70688267E9791AE14950450B03E632F0A0C221CC280B29E599B16848FD9AE
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
23
DNS requests
16
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1268
svchost.exe
GET
200
2.16.241.14:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
1268
svchost.exe
GET
200
72.246.169.155:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
1380
svchost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
3584
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
3584
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1268
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:137
whitelisted
5944
MoUsoCoreWorker.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
188
RUXIMICS.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
1268
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1268
svchost.exe
2.16.241.14:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
1268
svchost.exe
72.246.169.155:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
5944
MoUsoCoreWorker.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1380
svchost.exe
20.190.159.2:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
  • 4.231.128.59
  • 51.104.136.2
whitelisted
google.com
  • 142.250.186.110
whitelisted
crl.microsoft.com
  • 2.16.241.14
  • 2.16.241.12
whitelisted
www.microsoft.com
  • 72.246.169.155
  • 95.101.149.131
whitelisted
login.live.com
  • 20.190.159.2
  • 20.190.159.23
  • 40.126.31.73
  • 40.126.31.0
  • 40.126.31.1
  • 40.126.31.2
  • 20.190.159.129
  • 40.126.31.130
whitelisted
ocsp.digicert.com
  • 184.30.131.245
whitelisted
client.wns.windows.com
  • 172.211.123.249
whitelisted
slscr.update.microsoft.com
  • 52.149.20.212
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 13.85.23.206
whitelisted
self.events.data.microsoft.com
  • 104.208.16.95
whitelisted

Threats

No threats detected
Process
Message
ACRS Setup.exe
Creating System Tmp Directory: C:\ProgramData\ACRS\Tmp\
ACRS Setup.exe
Creating User Data Directory: C:\Users\admin\AppData\Local\ACRS\
ACRS Setup.exe
Creating System Log Directory: C:\ProgramData\ACRS\Log\
ACRS Setup.exe
Creating Local Repository Directory: C:\Users\admin\AppData\Local\ACRS\Downloads\
ACRS Setup.exe
Creating Patch Backup Directory: C:\ProgramData\ACRS\Backups\
ACRS Setup.exe
Creating User Log Directory: C:\Users\admin\AppData\Local\ACRS\Log\
ACRS Setup.exe
Creating User Tmp Directory: C:\Users\admin\AppData\Local\ACRS\Tmp\