File name:

Stub.exe

Full analysis: https://app.any.run/tasks/bce28860-00e4-4988-9523-7c3499415b38
Verdict: Malicious activity
Analysis date: August 29, 2024, 16:43:25
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
netreactor
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

3695B9EDF0BD656886234FC8B27381A1

SHA1:

524941AFA72BB3B6B3A1A8CF559AEA76DC3D2ED1

SHA256:

FC54A3CA1E2F6F983B918B037808D3FDF6753B7114922896C9864342ECB24794

SSDEEP:

98304:wQpA0weYarruWcxkkPt/6D7FQLnVkUyTIa5vFpzjIoIsI70Vdg6gFB0oxnnGC561:VeFK

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Drops the executable file immediately after the start

      • Stub.exe (PID: 3784)
    • Executable content was dropped or overwritten

      • Stub.exe (PID: 3784)
    • Process drops legitimate windows executable

      • Stub.exe (PID: 3784)
    • Reads security settings of Internet Explorer

      • UnifiedStub-installer.exe (PID: 4444)
  • INFO

    • Create files in a temporary directory

      • Stub.exe (PID: 3784)
    • Checks supported languages

      • Stub.exe (PID: 3784)
      • UnifiedStub-installer.exe (PID: 4444)
    • Reads the computer name

      • UnifiedStub-installer.exe (PID: 4444)
    • Reads the machine GUID from the registry

      • UnifiedStub-installer.exe (PID: 4444)
    • Checks proxy server information

      • UnifiedStub-installer.exe (PID: 4444)
    • Reads Environment values

      • UnifiedStub-installer.exe (PID: 4444)
    • Disables trace logs

      • UnifiedStub-installer.exe (PID: 4444)
    • Reads the software policy settings

      • UnifiedStub-installer.exe (PID: 4444)
    • .NET Reactor protector has been detected

      • UnifiedStub-installer.exe (PID: 4444)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (76.4)
.exe | Win32 Executable (generic) (12.4)
.exe | Generic Win/DOS Executable (5.5)
.exe | DOS Executable Generic (5.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:06:20 08:00:00+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Large address aware, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 106496
InitializedDataSize: 492032
UninitializedDataSize: -
EntryPoint: 0x19b6c
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 6.0.6.0
ProductVersionNumber: 6.0.6.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: ReasonLabs
FileDescription: ReasonLabs-setup-wizard.exe
FileVersion: 6.0.6
InternalName: 7zS.sfx
LegalCopyright: Copyright (C) 2024 Reason Software Company Inc.
OriginalFileName: 7zS.sfx.exe
ProductName: ReasonLabs Setup Wizard
ProductVersion: 6.0.6
No data.
screenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
127
Monitored processes
5
Malicious processes
0
Suspicious processes
1

Behavior graph

Click at the process to see the details
start stub.exe THREAT unifiedstub-installer.exe sppextcomobj.exe no specs slui.exe no specs stub.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2024C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
2136"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exeSppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
3784"C:\Users\admin\AppData\Local\Temp\Stub.exe" C:\Users\admin\AppData\Local\Temp\Stub.exe
explorer.exe
User:
admin
Company:
ReasonLabs
Integrity Level:
HIGH
Description:
ReasonLabs-setup-wizard.exe
Version:
6.0.6
Modules
Images
c:\users\admin\appdata\local\temp\stub.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\oleaut32.dll
4444.\UnifiedStub-installer.exeC:\Users\admin\AppData\Local\Temp\7zS8CE212D2\UnifiedStub-installer.exe
Stub.exe
User:
admin
Company:
Reason Software Company Inc.
Integrity Level:
HIGH
Description:
UnifiedStub
Version:
6.0.6
Modules
Images
c:\users\admin\appdata\local\temp\7zs8ce212d2\unifiedstub-installer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
6176"C:\Users\admin\AppData\Local\Temp\Stub.exe" C:\Users\admin\AppData\Local\Temp\Stub.exeexplorer.exe
User:
admin
Company:
ReasonLabs
Integrity Level:
MEDIUM
Description:
ReasonLabs-setup-wizard.exe
Exit code:
3221226540
Version:
6.0.6
Modules
Images
c:\users\admin\appdata\local\temp\stub.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
Total events
1 990
Read events
1 976
Write events
14
Delete events
0

Modification events

(PID) Process:(4444) UnifiedStub-installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\UnifiedStub-installer_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(4444) UnifiedStub-installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\UnifiedStub-installer_RASAPI32
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(4444) UnifiedStub-installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\UnifiedStub-installer_RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(4444) UnifiedStub-installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\UnifiedStub-installer_RASAPI32
Operation:writeName:FileTracingMask
Value:
(PID) Process:(4444) UnifiedStub-installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\UnifiedStub-installer_RASAPI32
Operation:writeName:ConsoleTracingMask
Value:
(PID) Process:(4444) UnifiedStub-installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\UnifiedStub-installer_RASAPI32
Operation:writeName:MaxFileSize
Value:
1048576
(PID) Process:(4444) UnifiedStub-installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\UnifiedStub-installer_RASAPI32
Operation:writeName:FileDirectory
Value:
%windir%\tracing
(PID) Process:(4444) UnifiedStub-installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\UnifiedStub-installer_RASMANCS
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(4444) UnifiedStub-installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\UnifiedStub-installer_RASMANCS
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(4444) UnifiedStub-installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\UnifiedStub-installer_RASMANCS
Operation:writeName:EnableConsoleTracing
Value:
0
Executable files
56
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
3784Stub.exeC:\Users\admin\AppData\Local\Temp\7zS8CE212D2\fr\Microsoft.Win32.TaskScheduler.resources.dllexecutable
MD5:3B4621370ADDCF4306669C9E7E45C865
SHA256:E3EE50E08124A7603BE7D996DCF596EB0D3F9C603768E86E003F7B942D7097F3
3784Stub.exeC:\Users\admin\AppData\Local\Temp\7zS8CE212D2\hi-IN\UnifiedStub.resources.dllexecutable
MD5:B80F580A19DD9EB1AE0D100E904AA355
SHA256:FD09CE82263B7AD24FBEECE917A58BC572017C02B692445C7BE1DA9A5E384474
3784Stub.exeC:\Users\admin\AppData\Local\Temp\7zS8CE212D2\fi-FI\UnifiedStub.resources.dllexecutable
MD5:156BBCB21840D19FB90DDAB9210293AE
SHA256:F4EA93584B3B9EE0132AD808B09A68076BA3C7067812FDED553BB3CC353FBC35
3784Stub.exeC:\Users\admin\AppData\Local\Temp\7zS8CE212D2\hr-HR\UnifiedStub.resources.dllexecutable
MD5:4FFCEB071591908E3F18B29C6BF4860B
SHA256:FA262361EF43DFC3FECB69C769EFAF693C044B07664D22AD2360F5DF341E8F8B
3784Stub.exeC:\Users\admin\AppData\Local\Temp\7zS8CE212D2\el-GR\UnifiedStub.resources.dllexecutable
MD5:41153F9DF6CD4962556F6C29C44F6005
SHA256:D5C842BBA00EE1B8670C5C29546F433E19787A1A64EB9383D918039557ED5751
3784Stub.exeC:\Users\admin\AppData\Local\Temp\7zS8CE212D2\id-ID\UnifiedStub.resources.dllexecutable
MD5:7B8886C28F10833E92E310561CB2B9AC
SHA256:80964508FFE5492F2A5FC2DB1BEBF045CA51B1337138327323B1756498C91A65
3784Stub.exeC:\Users\admin\AppData\Local\Temp\7zS8CE212D2\es\Microsoft.Win32.TaskScheduler.resources.dllexecutable
MD5:15DB634B70D6D9D6CD41BAAE3F02EB14
SHA256:E893C6907DA8D68C03B1A10E68B554AD5A8C0533F15912106F32E925F2BEABF0
3784Stub.exeC:\Users\admin\AppData\Local\Temp\7zS8CE212D2\es-ES\UnifiedStub.resources.dllexecutable
MD5:247A59BD0062DC0E43621CBD016CCDCC
SHA256:48980B044DDDF81D79C468527B59A5364ADDB216F35014BD83CE5771AF4AF8EE
3784Stub.exeC:\Users\admin\AppData\Local\Temp\7zS8CE212D2\ko-KR\UnifiedStub.resources.dllexecutable
MD5:8DB8FB00D4221C08C3683DD70DC3658B
SHA256:3A2FFB6A465D8B09BDD54F94BCE9EF68045F1C9BF969C10B63D1BD8FB3FD670E
3784Stub.exeC:\Users\admin\AppData\Local\Temp\7zS8CE212D2\de\Microsoft.Win32.TaskScheduler.resources.dllexecutable
MD5:F83D720B236576C7D1F9F55D3BB988F9
SHA256:6909A1C134D0285FBA2422A40EA0E65C1F0CA3C3EF2B94A1166015AF2A87780F
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
3
TCP/UDP connections
25
DNS requests
13
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3660
SIHClient.exe
GET
200
23.218.209.163:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
3660
SIHClient.exe
GET
200
23.218.209.163:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
2720
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
2400
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2120
MoUsoCoreWorker.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3260
svchost.exe
40.113.103.199:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4444
UnifiedStub-installer.exe
23.20.124.162:443
track.analytics-data.io
AMAZON-AES
US
malicious
2720
svchost.exe
40.126.31.73:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2720
svchost.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
2400
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2120
MoUsoCoreWorker.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
  • 20.73.194.208
whitelisted
google.com
  • 142.250.184.206
whitelisted
client.wns.windows.com
  • 40.113.103.199
whitelisted
track.analytics-data.io
  • 23.20.124.162
  • 54.90.250.141
  • 52.200.141.143
malicious
login.live.com
  • 40.126.31.73
  • 20.190.159.75
  • 20.190.159.23
  • 20.190.159.68
  • 20.190.159.0
  • 40.126.31.69
  • 20.190.159.71
  • 40.126.31.71
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
slscr.update.microsoft.com
  • 20.114.59.183
whitelisted
www.microsoft.com
  • 23.218.209.163
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 13.95.31.18
whitelisted

Threats

No threats detected
No debug info