Proprietary · · 219 days

Procolored printer downloads served malware

Procolored printer software links led to infected Mega-hosted downloads for months. G DATA found XRed backdoor files and the SnipVex clipbanker/file infector.

The Procolored case began with a hardware review. A reviewer plugged in vendor-supplied software media for a V11 Pro DTO UV printer and saw antivirus alerts. Procolored initially described the detections as false positives.

G DATA then checked Procolored's public software downloads. The vendor site linked six product download folders hosted on Mega, with files last updated around October 2024. Antivirus scanning found 39 infected files across the public download set.

The malware mix was messy, which matters. PrintExp.exe carried XRed, a Delphi backdoor with keylogging, screenshots, file operations, downloads, command shell access, and a bundled clean program resource. Other files carried SnipVex, a .NET clipbanker and prepending file infector that monitored drives for .exe files and replaced cryptocurrency addresses in the clipboard.

G DATA favored poor hygiene over a targeted implant: old malware, inactive C2, and file-infection spread through software preparation or distribution systems. Procolored removed the downloads around 2025-05-08, investigated, and later provided clean replacement packages for verification.

Notes

  • G Data identified two families in the downloads, the Delphi backdoor Win32.Backdoor.XRedRAT.A and a .NET file infector it nicknamed SnipVex, detected as MSIL.Trojan-Stealer.CoinStealer.H. It counted 39 infected files across the packages, of which 20 carried distinct hashes.
  • The archive hash recorded on f13-pro, v11-pro, and vf13-pro is the same file. G Data lists PrintExp_X64_V5.7.6.5.77.2024.06.25.Single.zip as shared across those three models, so one set of bytes was served for all of them.
  • The command-and-control server had been offline since February 2024, before the downloads were pulled, so infected hosts could not reach it during much of the exposure window. Procolored initially dismissed the detections as false positives.

Appendix · Affected releases

v11 Pro DTO procolored website download
  • G DATA reported six Procolored product download folders on Mega; shared malware hashes remain at the attack level because not every hash is mapped to a product folder. Hackster's review is the primary first-hand account of the vendor-supplied USB media finding.
F8 procolored website download
F13 Pro procolored website download
V6 procolored website download
V11 Pro procolored website download
VF13 Pro procolored website download

Indicators

  • file_sha256PrintExp.exe 531d08606455898408672d88513b8a1ac284fdf1fe011019770801b7b46d5434
  • file_sha256SnipVex 39df537aaefb0aa31019d053a61fabf93ba5f8f3934ad0d543cde6db1e8b35d1
  • file_sha256.NWReceive.exe b14c855ad7600ac9fda2c46b290acac1342d0e08dc1a95901504d8c5aa206606
  • file_sha256.PrintExp.exe 4de65f542bc2a144d0e220e93f367c08bf008045fcc1fddbc4e54af62e7da847
  • file_sha256._cache_NWReceive.exe 332deb26f74b6e6633214fe3ca7e95e4c6861d6eac0f9a792c3f2154adea73c7
  • file_sha256._cache_PrintExp.exe 0f8bf833d6673dcba58347b9bde618969b948268d42fbb17d48f68cbc925109e
  • file_sha256NWReceive.exe bfb9d8af2c57f055c1e35effb1f42410238981bc16cee96f045aca50ff495550
  • file_sha256epson-l800_drv_x64.exe 81de4cedda6109eacc9a3903a30e3a11622668ce6af533f94beadad052f591fb
  • file_sha256L800_x86_672HomeExportAsia_MP.exe 6d86f66c81c2c3e1a524fd8a8598e76d939bdf3cd8f7411036f7d5ca15afe622
  • file_sha256DEVICEOP.EXE 7f9657992c3c6169f629a8a12885eb5468482eba23e5f310d37ef0458ae8f87a
  • file_sha256SETUP.EXE 455374fe0f6f4123ecc9282189c67d261c877beba79ea77eb561dfb7a689a546
  • file_sha256Setup.exe (MEP folder) 995c9822c1803851301b060c4dbfe369e423d694e18fe526e0468150d8a79231
  • file_sha256._cache_ variant (V6) 7ae9e8b68f77bf0970feb2fcf80d830cbfaef49dd02828fd0086d4a64b713a64
  • file_sha256._cache_ variant (V6) 790bb3e769ef33f824015c5c814a29bde7f852c66f76647486d5c5fa3daafc1c
  • file_sha256._cache_ variant (V6) 4a4164fb3867e39506f316e2bc038ebaceacc51453e2e98ed132880b3dfe84b6
  • file_sha256._cache_ variant (V6) 1f44d8ab5cbb8e9a5673c8148367b9b0dd34cb947bb4c8297c03c5febfc8f8ab
  • file_sha256._cache_ variant (V6) 2114fe34d510894985ed6dd1d737414fcc7ec023a0980469fc6db580698b8ecc
  • file_sha256._cache_ variant (V6) eade6f6e514c5c8f079e160538683b30e59e0396f99d7ec38da02ebefac7a104
  • hashsha256:531d08606455898408672d88513b8a1ac284fdf1fe011019770801b7b46d5434
  • hashsha256:39df537aaefb0aa31019d053a61fabf93ba5f8f3934ad0d543cde6db1e8b35d1
  • hashsha256:b14c855ad7600ac9fda2c46b290acac1342d0e08dc1a95901504d8c5aa206606
  • hashsha256:81de4cedda6109eacc9a3903a30e3a11622668ce6af533f94beadad052f591fb

References

  1. The Maker's Toolbox: Procolored V11 Pro DTO UV Printer Reviewhackster.io
  2. Printer company provided infected software downloads for half a yearblog.gdatasoftware.com
  3. Printer maker Procolored offered malware-laced drivers for monthsbleepingcomputer.com
  4. Viruses included in product I'm reviewingreddit.com
  5. This Printer Company Served You Malware for Monthshowtogeek.com
  6. This printer company served you malware for months and dismissed it as false positivesneowin.net

Source record: proprietary/procolor/meta.yaml