File name:

Stub.exe

Full analysis: https://app.any.run/tasks/bce28860-00e4-4988-9523-7c3499415b38
Verdict: Malicious activity
Analysis date: August 29, 2024, 16:43:25
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
netreactor
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

3695B9EDF0BD656886234FC8B27381A1

SHA1:

524941AFA72BB3B6B3A1A8CF559AEA76DC3D2ED1

SHA256:

FC54A3CA1E2F6F983B918B037808D3FDF6753B7114922896C9864342ECB24794

SSDEEP:

98304:wQpA0weYarruWcxkkPt/6D7FQLnVkUyTIa5vFpzjIoIsI70Vdg6gFB0oxnnGC561:VeFK

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • Stub.exe (PID: 3784)
    • Drops the executable file immediately after the start

      • Stub.exe (PID: 3784)
    • Executable content was dropped or overwritten

      • Stub.exe (PID: 3784)
    • Reads security settings of Internet Explorer

      • UnifiedStub-installer.exe (PID: 4444)
  • INFO

    • Create files in a temporary directory

      • Stub.exe (PID: 3784)
    • Reads the machine GUID from the registry

      • UnifiedStub-installer.exe (PID: 4444)
    • Checks supported languages

      • Stub.exe (PID: 3784)
      • UnifiedStub-installer.exe (PID: 4444)
    • Reads the computer name

      • UnifiedStub-installer.exe (PID: 4444)
    • Reads Environment values

      • UnifiedStub-installer.exe (PID: 4444)
    • Disables trace logs

      • UnifiedStub-installer.exe (PID: 4444)
    • Checks proxy server information

      • UnifiedStub-installer.exe (PID: 4444)
    • Reads the software policy settings

      • UnifiedStub-installer.exe (PID: 4444)
    • .NET Reactor protector has been detected

      • UnifiedStub-installer.exe (PID: 4444)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (76.4)
.exe | Win32 Executable (generic) (12.4)
.exe | Generic Win/DOS Executable (5.5)
.exe | DOS Executable Generic (5.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:06:20 08:00:00+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Large address aware, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 106496
InitializedDataSize: 492032
UninitializedDataSize: -
EntryPoint: 0x19b6c
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 6.0.6.0
ProductVersionNumber: 6.0.6.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: ReasonLabs
FileDescription: ReasonLabs-setup-wizard.exe
FileVersion: 6.0.6
InternalName: 7zS.sfx
LegalCopyright: Copyright (C) 2024 Reason Software Company Inc.
OriginalFileName: 7zS.sfx.exe
ProductName: ReasonLabs Setup Wizard
ProductVersion: 6.0.6
No data.
screenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
127
Monitored processes
5
Malicious processes
0
Suspicious processes
1

Behavior graph

Click at the process to see the details
start stub.exe THREAT unifiedstub-installer.exe sppextcomobj.exe no specs slui.exe no specs stub.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2024C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
2136"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exeSppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
3784"C:\Users\admin\AppData\Local\Temp\Stub.exe" C:\Users\admin\AppData\Local\Temp\Stub.exe
explorer.exe
User:
admin
Company:
ReasonLabs
Integrity Level:
HIGH
Description:
ReasonLabs-setup-wizard.exe
Version:
6.0.6
Modules
Images
c:\users\admin\appdata\local\temp\stub.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\oleaut32.dll
4444.\UnifiedStub-installer.exeC:\Users\admin\AppData\Local\Temp\7zS8CE212D2\UnifiedStub-installer.exe
Stub.exe
User:
admin
Company:
Reason Software Company Inc.
Integrity Level:
HIGH
Description:
UnifiedStub
Version:
6.0.6
Modules
Images
c:\users\admin\appdata\local\temp\7zs8ce212d2\unifiedstub-installer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
6176"C:\Users\admin\AppData\Local\Temp\Stub.exe" C:\Users\admin\AppData\Local\Temp\Stub.exeexplorer.exe
User:
admin
Company:
ReasonLabs
Integrity Level:
MEDIUM
Description:
ReasonLabs-setup-wizard.exe
Exit code:
3221226540
Version:
6.0.6
Modules
Images
c:\users\admin\appdata\local\temp\stub.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
Total events
1 990
Read events
1 976
Write events
14
Delete events
0

Modification events

(PID) Process:(4444) UnifiedStub-installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\UnifiedStub-installer_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(4444) UnifiedStub-installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\UnifiedStub-installer_RASAPI32
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(4444) UnifiedStub-installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\UnifiedStub-installer_RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(4444) UnifiedStub-installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\UnifiedStub-installer_RASAPI32
Operation:writeName:FileTracingMask
Value:
(PID) Process:(4444) UnifiedStub-installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\UnifiedStub-installer_RASAPI32
Operation:writeName:ConsoleTracingMask
Value:
(PID) Process:(4444) UnifiedStub-installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\UnifiedStub-installer_RASAPI32
Operation:writeName:MaxFileSize
Value:
1048576
(PID) Process:(4444) UnifiedStub-installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\UnifiedStub-installer_RASAPI32
Operation:writeName:FileDirectory
Value:
%windir%\tracing
(PID) Process:(4444) UnifiedStub-installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\UnifiedStub-installer_RASMANCS
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(4444) UnifiedStub-installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\UnifiedStub-installer_RASMANCS
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(4444) UnifiedStub-installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\UnifiedStub-installer_RASMANCS
Operation:writeName:EnableConsoleTracing
Value:
0
Executable files
56
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
3784Stub.exeC:\Users\admin\AppData\Local\Temp\7zS8CE212D2\ARM64\Reason.ArchiveUtility-ARM64.dllexecutable
MD5:084B3EBB27DA692C90CCC83A765E8B2E
SHA256:DBB2C00B06B818D5DA88954EDDD9C7B8911A748B1E8C853B9DA7FAAACDBE536D
3784Stub.exeC:\Users\admin\AppData\Local\Temp\7zS8CE212D2\de\Microsoft.Win32.TaskScheduler.resources.dllexecutable
MD5:F83D720B236576C7D1F9F55D3BB988F9
SHA256:6909A1C134D0285FBA2422A40EA0E65C1F0CA3C3EF2B94A1166015AF2A87780F
3784Stub.exeC:\Users\admin\AppData\Local\Temp\7zS8CE212D2\el-GR\UnifiedStub.resources.dllexecutable
MD5:41153F9DF6CD4962556F6C29C44F6005
SHA256:D5C842BBA00EE1B8670C5C29546F433E19787A1A64EB9383D918039557ED5751
3784Stub.exeC:\Users\admin\AppData\Local\Temp\7zS8CE212D2\da-DK\UnifiedStub.resources.dllexecutable
MD5:C7D53FBA41BBD98B09ADC6370530187D
SHA256:0973897156246245DAFC537D4023FD899E29F65F9AFCCC0049F41BC08138F5F5
3784Stub.exeC:\Users\admin\AppData\Local\Temp\7zS8CE212D2\fr\Microsoft.Win32.TaskScheduler.resources.dllexecutable
MD5:3B4621370ADDCF4306669C9E7E45C865
SHA256:E3EE50E08124A7603BE7D996DCF596EB0D3F9C603768E86E003F7B942D7097F3
3784Stub.exeC:\Users\admin\AppData\Local\Temp\7zS8CE212D2\de-DE\UnifiedStub.resources.dllexecutable
MD5:2157C628AB1269DBEBF9DB38F9F5DC9A
SHA256:6B6EB8B9BA257C7AD0A708D3C90737DA456003F4313580D91EA9F6F054E96A15
3784Stub.exeC:\Users\admin\AppData\Local\Temp\7zS8CE212D2\fi-FI\UnifiedStub.resources.dllexecutable
MD5:156BBCB21840D19FB90DDAB9210293AE
SHA256:F4EA93584B3B9EE0132AD808B09A68076BA3C7067812FDED553BB3CC353FBC35
3784Stub.exeC:\Users\admin\AppData\Local\Temp\7zS8CE212D2\cs-CZ\UnifiedStub.resources.dllexecutable
MD5:F230C03FC14C59760D29F3364A43581F
SHA256:7DFB9CD2FA7AB935F6DCFABEB2F65CD1E3CB30BF0A4E0B8F6CC878F05147FDBC
3784Stub.exeC:\Users\admin\AppData\Local\Temp\7zS8CE212D2\ja-JP\UnifiedStub.resources.dllexecutable
MD5:1383AD9188B59F954393713319DF301A
SHA256:17FFBD582826AA3171D654827FF92D0C79218AF48414AA0ABE72E4AA3FEF17E3
3784Stub.exeC:\Users\admin\AppData\Local\Temp\7zS8CE212D2\it\Microsoft.Win32.TaskScheduler.resources.dllexecutable
MD5:1C331DA4BCE2809E16913C02E385576E
SHA256:1D0493E38D8B3FCC7EFA4916FEA1EEA69EE6449BF435E1869C1BC3F54D4090C5
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
3
TCP/UDP connections
25
DNS requests
13
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2720
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
3660
SIHClient.exe
GET
200
23.218.209.163:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
3660
SIHClient.exe
GET
200
23.218.209.163:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
2400
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2120
MoUsoCoreWorker.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3260
svchost.exe
40.113.103.199:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4444
UnifiedStub-installer.exe
23.20.124.162:443
track.analytics-data.io
AMAZON-AES
US
malicious
2720
svchost.exe
40.126.31.73:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2720
svchost.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
2400
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2120
MoUsoCoreWorker.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
  • 20.73.194.208
whitelisted
google.com
  • 142.250.184.206
whitelisted
client.wns.windows.com
  • 40.113.103.199
whitelisted
track.analytics-data.io
  • 23.20.124.162
  • 54.90.250.141
  • 52.200.141.143
malicious
login.live.com
  • 40.126.31.73
  • 20.190.159.75
  • 20.190.159.23
  • 20.190.159.68
  • 20.190.159.0
  • 40.126.31.69
  • 20.190.159.71
  • 40.126.31.71
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
slscr.update.microsoft.com
  • 20.114.59.183
whitelisted
www.microsoft.com
  • 23.218.209.163
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 13.95.31.18
whitelisted

Threats

No threats detected
No debug info