File name:

Enscape 3D.exe

Full analysis: https://app.any.run/tasks/1be8bb66-3c06-460f-aa51-e79f8b695981
Verdict: Malicious activity
Analysis date: December 10, 2023, 03:11:28
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

E97CBB2FE30FDA3D3FD8192E1776BAFD

SHA1:

3690CD799F9D9283DF536D42F0157E6758083713

SHA256:

F408A2A38F75CACF706B8BAD27BA51DDFD6BAF4C22514B32BCBC377E466F8D2D

SSDEEP:

98304:vH0ZWWjztLaZ90vZysVahHy0MJR3ttrl9QC57l9zmFcZ+aDr3yChzqe68THFkfCC:NI2n6J4KfmSjW

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • msiexec.exe (PID: 2220)
      • Enscape 3D.exe (PID: 1344)
    • Bypass execution policy to execute commands

      • powershell.exe (PID: 2728)
    • Changes powershell execution policy (Bypass)

      • msiexec.exe (PID: 3108)
  • SUSPICIOUS

    • Reads settings of System Certificates

      • Enscape 3D.exe (PID: 1344)
    • Reads the Internet Settings

      • Enscape 3D.exe (PID: 1344)
    • Checks Windows Trust Settings

      • Enscape 3D.exe (PID: 1344)
      • msiexec.exe (PID: 2220)
    • Reads security settings of Internet Explorer

      • Enscape 3D.exe (PID: 1344)
    • Reads the Windows owner or organization settings

      • Enscape 3D.exe (PID: 1344)
    • The process bypasses the loading of PowerShell profile settings

      • msiexec.exe (PID: 3108)
    • Starts POWERSHELL.EXE for commands execution

      • msiexec.exe (PID: 3108)
    • The process hide an interactive prompt from the user

      • msiexec.exe (PID: 3108)
    • The process executes Powershell scripts

      • msiexec.exe (PID: 3108)
    • Powershell version downgrade attack

      • powershell.exe (PID: 2728)
  • INFO

    • Create files in a temporary directory

      • Enscape 3D.exe (PID: 1344)
      • msiexec.exe (PID: 2220)
      • msiexec.exe (PID: 3108)
    • Creates files or folders in the user directory

      • Enscape 3D.exe (PID: 1344)
      • msiexec.exe (PID: 2220)
    • Reads the computer name

      • Enscape 3D.exe (PID: 1344)
      • msiexec.exe (PID: 2220)
      • msiexec.exe (PID: 2860)
      • wmpnscfg.exe (PID: 3140)
      • msiexec.exe (PID: 3108)
    • Reads the machine GUID from the registry

      • Enscape 3D.exe (PID: 1344)
      • msiexec.exe (PID: 2220)
      • msiexec.exe (PID: 2860)
      • msiexec.exe (PID: 3108)
    • Checks supported languages

      • Enscape 3D.exe (PID: 1344)
      • msiexec.exe (PID: 2220)
      • msiexec.exe (PID: 2860)
      • msiexec.exe (PID: 3108)
      • wmpnscfg.exe (PID: 3140)
      • minstall.exe (PID: 3116)
    • Reads Environment values

      • Enscape 3D.exe (PID: 1344)
      • msiexec.exe (PID: 3108)
    • Application launched itself

      • msiexec.exe (PID: 2220)
    • Reads security settings of Internet Explorer

      • msiexec.exe (PID: 2996)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 3140)
      • explorer.exe (PID: 2492)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (18)
.exe | Win32 Executable (generic) (2.9)
.exe | Generic Win/DOS Executable (1.3)
.exe | DOS Executable Generic (1.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:09:07 14:39:10+02:00
ImageFileCharacteristics: Executable, Large address aware, 32-bit
PEType: PE32
LinkerVersion: 14.37
CodeSize: 2595840
InitializedDataSize: 1076224
UninitializedDataSize: -
EntryPoint: 0x1ef409
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 10.0.8413.0
ProductVersionNumber: 10.0.8413.0
FileFlagsMask: 0x003f
FileFlags: Debug
FileOS: Win32
ObjectFileType: Dynamic link library
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
FileVersion: 10.0.8413
ProductVersion: 10.0.8413
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
50
Monitored processes
10
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
start enscape 3d.exe msiexec.exe no specs msiexec.exe no specs wmpnscfg.exe no specs msiexec.exe no specs msiexec.exe no specs powershell.exe no specs minstall.exe no specs explorer.exe no specs enscape 3d.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1344"C:\Users\admin\AppData\Local\Temp\Enscape 3D.exe" C:\Users\admin\AppData\Local\Temp\Enscape 3D.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Version:
10.0.8413
Modules
Images
c:\users\admin\appdata\local\temp\enscape 3d.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
1996"C:\Users\admin\AppData\Local\Temp\Enscape 3D.exe" C:\Users\admin\AppData\Local\Temp\Enscape 3D.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Version:
10.0.8413
Modules
Images
c:\users\admin\appdata\local\temp\enscape 3d.exe
c:\windows\system32\ntdll.dll
2220C:\Windows\system32\msiexec.exe /VC:\Windows\System32\msiexec.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2492"C:\Windows\explorer.exe" C:\Windows\explorer.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2728 -NoProfile -Noninteractive -ExecutionPolicy Bypass -File "C:\Users\admin\AppData\Local\Temp\pssB2D.ps1" -propFile "C:\Users\admin\AppData\Local\Temp\msiB1B.txt" -scriptFile "C:\Users\admin\AppData\Local\Temp\scrB1C.ps1" -scriptArgsFile "C:\Users\admin\AppData\Local\Temp\scrB2C.txt" -propSep " :<->: " -lineSep " <<:>> " -testPrefix "_testValue."C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows PowerShell
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\atl.dll
c:\windows\system32\user32.dll
2860C:\Windows\system32\MsiExec.exe -Embedding 9F53F403C11C5E47D083D7891B420E91 CC:\Windows\System32\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2996"C:\Windows\system32\msiexec.exe" /i C:\Users\admin\AppData\Roaming\install\F9094B6\database.msi AI_SETUPEXEPATH="C:\Users\admin\AppData\Local\Temp\Enscape 3D.exe" SETUPEXEDIR=C:\Users\admin\AppData\Local\Temp\ EXE_CMD_LINE="/exenoupdates /forcecleanup /wintime 1702175735 " AI_EUIMSI="" AI_FOUND_PREREQS=".NET Framework 4.6.1 (web installer)"C:\Windows\System32\msiexec.exeEnscape 3D.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3108C:\Windows\system32\MsiExec.exe -Embedding AABA33175F717627E95DC7CFDC561C4CC:\Windows\System32\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3116"C:\Users\admin\AppData\Roaming\Microsoft\Windows\Templates\minstall.exe"C:\Users\admin\AppData\Roaming\Microsoft\Windows\Templates\minstall.exemsiexec.exe
User:
admin
Integrity Level:
HIGH
Exit code:
1551066484
Modules
Images
c:\users\admin\appdata\roaming\microsoft\windows\templates\minstall.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
3140"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
Total events
13 615
Read events
13 515
Write events
89
Delete events
11

Modification events

(PID) Process:(1344) Enscape 3D.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\17F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2996) msiexec.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\17F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2220) msiexec.exeKey:HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000_CLASSES\Local Settings\MuiCache\17F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2220) msiexec.exeKey:HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000_CLASSES\Local Settings\MuiCache\17F\52C64B7E
Operation:delete keyName:(default)
Value:
(PID) Process:(2220) msiexec.exeKey:HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000_CLASSES\Local Settings\MuiCache\17F
Operation:delete keyName:(default)
Value:
(PID) Process:(2220) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
Operation:delete valueName:C:\Config.Msi\210784.rbs
Value:
31075094
(PID) Process:(2220) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
Operation:delete keyName:(default)
Value:
(PID) Process:(2220) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback
Operation:delete keyName:(default)
Value:
(PID) Process:(2728) powershell.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\17F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2220) msiexec.exeKey:HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:Sequence
Value:
1
Executable files
14
Suspicious files
15
Text files
40
Unknown types
0

Dropped files

PID
Process
Filename
Type
1344Enscape 3D.exeC:\Users\admin\AppData\Roaming\install\F9094B6\database.msi
MD5:
SHA256:
1344Enscape 3D.exeC:\Users\admin\AppData\Local\Temp\Cab3B8.tmpcompressed
MD5:AC05D27423A85ADC1622C714F2CB6184
SHA256:C6456E12E5E53287A547AF4103E0397CB9697E466CF75844312DC296D43D144D
1344Enscape 3D.exeC:\Users\admin\AppData\Local\Temp\MSI5AF.tmpexecutable
MD5:89F70B588A48793450DD603B6CD4096F
SHA256:066C52ED8EBF63A33AB8290B7C58D0C13F79C14FAA8BF12B1B41F643D3EBE281
1344Enscape 3D.exeC:\Users\admin\AppData\Local\Temp\Tar3B9.tmpcat
MD5:9C0C641C06238516F27941AA1166D427
SHA256:4276AF3669A141A59388BC56A87F6614D9A9BDDDF560636C264219A7EB11256F
1344Enscape 3D.exeC:\Users\admin\AppData\Local\Temp\AI_EXTUI_BIN_1344\backgroundimage
MD5:9E23DA7C3CD3FB8113E698A12A3D3047
SHA256:B671008E5D4A15409051D7B3D2AA40F7C028E1DAB5876C2882976793ABB9356C
1344Enscape 3D.exeC:\Users\admin\AppData\Local\Temp\AI_EXTUI_BIN_1344\aboutbtndarkimage
MD5:B51B54B77E9CBFDB1063F7487C1C07EC
SHA256:9D7243C688264329A8CB9E22DA00B651E0A9407741D722E03DD67CC8B3EE1335
1344Enscape 3D.exeC:\Users\admin\AppData\Local\Temp\MSI5CF.tmpexecutable
MD5:58C6476771F68F57661D0F6533CB70EF
SHA256:7EB240EF6E75DE05B2A199BC55FDC8D13F467D5B4E58457011653312FFFCC65F
1344Enscape 3D.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506binary
MD5:01DF1B4EAE833825F2F5348996645479
SHA256:2DBC8175F96AE7648E2FA44D2E2CF2B915192EA3EE500E111F912A1697C76B32
1344Enscape 3D.exeC:\Users\admin\AppData\Local\Temp\AI_EXTUI_BIN_1344\buttonimgsdarkimage
MD5:D2CEE1442309FE99E978F0316395D970
SHA256:75FEA1443A0AF73756270C1840ED88B22301530AE5B9418A6BD1F45B62F8F1CD
1344Enscape 3D.exeC:\Users\admin\AppData\Local\Temp\AI_EXTUI_BIN_1344\applogodark.pngimage
MD5:730BFCD42DA287C882FDE2C73B34CF64
SHA256:0BFA4489CED383533C486FEAFAF0DBA59A3DBBA7772B78A91788FF09E9AED8EB
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
6
DNS requests
1
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1344
Enscape 3D.exe
GET
200
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?a4790458f2158537
unknown
compressed
65.2 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1080
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
2588
svchost.exe
239.255.255.250:1900
whitelisted
1344
Enscape 3D.exe
93.184.221.240:80
ctldl.windowsupdate.com
EDGECAST
GB
whitelisted

DNS requests

Domain
IP
Reputation
ctldl.windowsupdate.com
  • 93.184.221.240
whitelisted

Threats

No threats detected
Process
Message
Enscape 3D.exe
DBGHELP: SymSrv load failure: symsrv.dll
Enscape 3D.exe
DBGHELP: Symbol Search Path: .
Enscape 3D.exe
DBGHELP: Symbol Search Path: C:\Users\admin\AppData\Local\Temp
Enscape 3D.exe
DBGHELP: C:\Users\admin\AppData\Local\Temp\symbols\exe\ExternalUi.pdb - file not found
Enscape 3D.exe
DBGHELP: C:\Users\admin\AppData\Local\Temp\ExternalUi.pdb - file not found
Enscape 3D.exe
DBGHELP: C:\Users\admin\AppData\Local\Temp\symbols\exe\ExternalUi.pdb - file not found
Enscape 3D.exe
DBGHELP: C:\Users\admin\AppData\Local\Temp\exe\ExternalUi.pdb - file not found
Enscape 3D.exe
DBGHELP: Symbol Search Path: C:\Users\admin\AppData\Local\Temp
Enscape 3D.exe
DBGHELP: Symbol Search Path: .
Enscape 3D.exe
DBGHELP: C:\ReleaseAI\win\Release\stubs\x86\ExternalUi.pdb - file not found