| File name: | Setup1.exe |
| Full analysis: | https://app.any.run/tasks/11c9393c-5ef3-4c71-af11-1c5714a3d644 |
| Verdict: | Malicious activity |
| Threats: | DarkGate is a loader, which possesses extensive functionality, ranging from keylogging to crypto mining. Written in Delphi, this malware is known for the use of AutoIT scripts in its infection process. Thanks to this malicious software’s versatile architecture, it is widely used by established threat actors. |
| Analysis date: | August 12, 2024, 13:39:16 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 176ABCDF359BD0F1FBB11741C88876FC |
| SHA1: | BD5B19FCA023300EF18FFE3F08179D9CB45A0C9E |
| SHA256: | 01FDCC1B190A64A5DD5D0B8EFF108A9481E200FA315FAD2D5BD902EFDB9E392B |
| SSDEEP: | 49152:b+zj1C/cMAHTTXFSmQ9jj6zCioX9RiZcXTWpufIM6wxFelLVc55:b+zjIkMAHTTd0HioX3i6XTWpgI5wxkmz |
| .exe | | | Win32 Executable MS Visual C++ (generic) (42.2) |
|---|---|---|
| .exe | | | Win64 Executable (generic) (37.3) |
| .dll | | | Win32 Dynamic Link Library (generic) (8.8) |
| .exe | | | Win32 Executable (generic) (6) |
| .exe | | | Generic Win/DOS Executable (2.7) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2010:03:16 00:57:30+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 8 |
| CodeSize: | 53248 |
| InitializedDataSize: | 65536 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x32f7 |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.0.0.4 |
| ProductVersionNumber: | 1.0.0.4 |
| FileFlagsMask: | 0x0017 |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| CompanyName: | Brother Industries, Ltd. |
| FileDescription: | Small Setup |
| FileVersion: | 1, 0, 0, 4 |
| InternalName: | SSetup |
| LegalCopyright: | Copyright (C) 2010 |
| OriginalFileName: | SSetup.exe |
| ProductName: | SSetup |
| ProductVersion: | 1, 0, 0, 4 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 32 | "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /svc | C:\Program Files (x86)\Google\Update\GoogleUpdate.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Google LLC Integrity Level: SYSTEM Description: Google Installer Exit code: 0 Version: 1.3.36.51 Modules
| |||||||||||||||
| 188 | C:\WINDOWS\System32\msdtc.exe | C:\Windows\System32\msdtc.exe | services.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft Distributed Transaction Coordinator Service Version: 2001.12.10941.16384 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2872 | C:\WINDOWS\PSEXESVC.exe | C:\Windows\PSEXESVC.exe | services.exe | ||||||||||||
User: SYSTEM Company: Sysinternals Integrity Level: SYSTEM Description: PsExec Service Version: 2.34 Modules
| |||||||||||||||
| 3356 | "C:\Program Files (x86)\Google\Update\1.3.36.372\GoogleCrashHandler64.exe" | C:\Program Files (x86)\Google\Update\1.3.36.372\GoogleCrashHandler64.exe | — | GoogleUpdate.exe | |||||||||||
User: SYSTEM Company: Google LLC Integrity Level: SYSTEM Description: Google Crash Handler Exit code: 0 Version: 1.3.36.371 Modules
| |||||||||||||||
| 4644 | "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /ua /installsource core | C:\Program Files (x86)\Google\Update\GoogleUpdate.exe | — | GoogleUpdate.exe | |||||||||||
User: SYSTEM Company: Google LLC Integrity Level: SYSTEM Description: Google Installer Version: 1.3.36.51 Modules
| |||||||||||||||
| 5388 | "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /c | C:\Program Files (x86)\Google\Update\GoogleUpdate.exe | GoogleUpdate.exe | ||||||||||||
User: SYSTEM Company: Google LLC Integrity Level: SYSTEM Description: Google Installer Version: 1.3.36.51 Modules
| |||||||||||||||
| 5552 | "C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe" | C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe | services.exe | ||||||||||||
User: SYSTEM Company: Mozilla Foundation Integrity Level: SYSTEM Exit code: 0 Version: 123.0 Modules
| |||||||||||||||
| 5924 | C:\WINDOWS\system32\TieringEngineService.exe | C:\Windows\System32\TieringEngineService.exe | services.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Storage Tiers Management Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6052 | "C:\Program Files (x86)\Microsoft\Edge\Application\122.0.2365.59\elevation_service.exe" | C:\Program Files (x86)\Microsoft\Edge\Application\122.0.2365.59\elevation_service.exe | services.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft Edge Version: 122.0.2365.59 Modules
| |||||||||||||||
| 6160 | "C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /svc | C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe | services.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft Edge Update Version: 1.3.147.37 Modules
| |||||||||||||||
| (PID) Process: | (6464) armsvc.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Adobe\Adobe ARM\1.0\ARM |
| Operation: | write | Name: | iLastSvcSuccess |
Value: 944640 | |||
| (PID) Process: | (6652) MicrosoftEdgeUpdate.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate\UsageStats\Daily\Integers |
| Operation: | write | Name: | omaha_version |
Value: 1100B90003000100 | |||
| (PID) Process: | (6652) MicrosoftEdgeUpdate.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate\UsageStats\Daily\Booleans |
| Operation: | write | Name: | is_system_install |
Value: 01000000 | |||
| (PID) Process: | (6652) MicrosoftEdgeUpdate.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate\UsageStats\Daily\Counts |
| Operation: | write | Name: | goopdate_main |
Value: 1500000000000000 | |||
| (PID) Process: | (6652) MicrosoftEdgeUpdate.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate\UsageStats\Daily\Counts |
| Operation: | write | Name: | goopdate_constructor |
Value: 1500000000000000 | |||
| (PID) Process: | (6652) MicrosoftEdgeUpdate.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate\UsageStats\Daily\Integers |
| Operation: | write | Name: | windows_major_version |
Value: 0A00000000000000 | |||
| (PID) Process: | (6812) MicrosoftEdgeUpdate.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate\ClientState\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062} |
| Operation: | write | Name: | InstallTime |
Value: | |||
| (PID) Process: | (6812) MicrosoftEdgeUpdate.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate\ClientState\{F3017226-FE2A-4295-8BDF-00C3A9A7E4C5} |
| Operation: | write | Name: | InstallTime |
Value: | |||
| (PID) Process: | (6860) MicrosoftEdgeUpdate.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{9E8F1B36-249F-4FC3-9994-974AFAA07B26}\InprocServer32 |
| Operation: | write | Name: | ThreadingModel |
Value: Both | |||
| (PID) Process: | (6860) MicrosoftEdgeUpdate.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{A2F5CB38-265F-4A02-9D1E-F25B664968AB}\InprocServer32 |
| Operation: | write | Name: | ThreadingModel |
Value: Both | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6428 | Setup1.exe | C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe | executable | |
MD5:94B612904E7D391D5105238C3981078C | SHA256:33B33D55C14E5FAFA959A1E6DB99E2C6872D596A8969383DF261944FE7BDC153 | |||
| 6428 | Setup1.exe | C:\Windows\System32\alg.exe | executable | |
MD5:558D5345CD0F9BFBE77ADD24E2721B1A | SHA256:F16BC053107B319FBD337BF76F8084053A29BB3A47C78F9FA272447CBA31BFB2 | |||
| 6492 | FlashPlayerUpdateService.exe | C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\26b799fa89ba8c8f.bin | binary | |
MD5:42C1F97E42DF09B99F04FD310141C430 | SHA256:7EB9935F43C4C68F700A9EA58407F101D25C67F4C9C2C47320CEEF3D18B17CEA | |||
| 6652 | MicrosoftEdgeUpdate.exe | C:\ProgramData\Microsoft\EdgeUpdate\Log\MicrosoftEdgeUpdate.log | text | |
MD5:1E8D3037AC72A2F4762A056B2CBC7470 | SHA256:820D8CB9287DFA57601745818966693642F40C2932319232A7D44FFA267BA6CB | |||
| 6428 | Setup1.exe | C:\Program Files\Google\Chrome\Application\122.0.6261.70\elevation_service.exe | executable | |
MD5:99B87AF16D68407FB14E8952A8208268 | SHA256:38759404E5A771320C7C1338B78148A3BD61C3373BCB64DB75789D826D130E2E | |||
| 7120 | GameInputSvc.exe | C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\36AC0BE60E1243344AE145F746D881FE | binary | |
MD5:6B306039D9EF8DCBF2F488269E6DECA1 | SHA256:BCECF6601855462FFA023224B12001CDD317E1DBF738BA3DC28D8BCC944B9E14 | |||
| 6428 | Setup1.exe | C:\Windows\System32\GameInputSvc.exe | executable | |
MD5:A59E55D256372660140906FCF6048650 | SHA256:18C2529E928E2D88938FDC10C33EE33BD34D5075E7C43EA66BF61DC15CB69C52 | |||
| 6428 | Setup1.exe | C:\Program Files (x86)\Google\Update\GoogleUpdate.exe | executable | |
MD5:AEFF9CE563A3CB2A016448F06AA78549 | SHA256:373A7CB1EB86509C3BC3AF55021739881C1EF35ACF13A583B49666EDF8593251 | |||
| 6428 | Setup1.exe | C:\Windows\System32\AppVClient.exe | executable | |
MD5:7A3B0796991041EDCA76FFF63CE45BA9 | SHA256:C1A87C88DAF59681679B95CDD8D398668500B7AEA2B2EE5D7EB600E7EA23A05A | |||
| 5552 | maintenanceservice.exe | C:\Program Files (x86)\Mozilla Maintenance Service\logs\maintenanceservice.log | text | |
MD5:D769FD1F74620ECE40F6770DA9B7DAFB | SHA256:3C4397BFA2A1DF02E09789A400920C405850BB5A548C34B99A475C5BC11A9D8A | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
6528 | alg.exe | POST | 200 | 54.244.188.177:80 | http://pywolwnvd.biz/aqyyxaerrxhep | unknown | — | — | unknown |
6428 | Setup1.exe | POST | 200 | 54.244.188.177:80 | http://cvgrf.biz/xgvdmb | unknown | — | — | unknown |
6428 | Setup1.exe | POST | 200 | 18.141.10.107:80 | http://ssbzmoy.biz/lfxniekyihsglwau | unknown | — | — | unknown |
6528 | alg.exe | POST | 200 | 18.141.10.107:80 | http://ssbzmoy.biz/wvq | unknown | — | — | unknown |
6428 | Setup1.exe | POST | — | 172.234.222.143:80 | http://przvgke.biz/lqppfmuu | unknown | — | — | unknown |
6864 | svchost.exe | GET | 206 | 199.232.210.172:80 | http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/01a02d0e-9d8d-47a3-8c36-9bf38dabe21a?P1=1724074770&P2=404&P3=2&P4=FpZAp6Hf%2b1sfJGnn3wlDHl1KoLcw5U11H7clkSfPC4Vc6gFFx2J0fE3nz%2fh2aVxEAtIdMYi%2fYXeYYZqw30hjXg%3d%3d | unknown | — | — | whitelisted |
6528 | alg.exe | POST | 200 | 54.244.188.177:80 | http://cvgrf.biz/ahamk | unknown | — | — | unknown |
6864 | svchost.exe | GET | 206 | 199.232.210.172:80 | http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/01a02d0e-9d8d-47a3-8c36-9bf38dabe21a?P1=1724074770&P2=404&P3=2&P4=FpZAp6Hf%2b1sfJGnn3wlDHl1KoLcw5U11H7clkSfPC4Vc6gFFx2J0fE3nz%2fh2aVxEAtIdMYi%2fYXeYYZqw30hjXg%3d%3d | unknown | — | — | whitelisted |
6528 | alg.exe | POST | 200 | 44.221.84.105:80 | http://npukfztj.biz/bwbxn | unknown | — | — | unknown |
6864 | svchost.exe | GET | 206 | 199.232.210.172:80 | http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/01a02d0e-9d8d-47a3-8c36-9bf38dabe21a?P1=1724074770&P2=404&P3=2&P4=FpZAp6Hf%2b1sfJGnn3wlDHl1KoLcw5U11H7clkSfPC4Vc6gFFx2J0fE3nz%2fh2aVxEAtIdMYi%2fYXeYYZqw30hjXg%3d%3d | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
3376 | RUXIMICS.exe | 20.73.194.208:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
2120 | MoUsoCoreWorker.exe | 20.73.194.208:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
3888 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
4936 | svchost.exe | 20.73.194.208:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
6428 | Setup1.exe | 54.244.188.177:80 | pywolwnvd.biz | AMAZON-02 | US | unknown |
— | — | 54.244.188.177:80 | pywolwnvd.biz | AMAZON-02 | US | unknown |
6428 | Setup1.exe | 18.141.10.107:80 | ssbzmoy.biz | AMAZON-02 | SG | unknown |
— | — | 18.141.10.107:80 | ssbzmoy.biz | AMAZON-02 | SG | unknown |
6380 | GoogleUpdate.exe | 142.250.186.46:443 | clients2.google.com | GOOGLE | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
google.com |
| whitelisted |
pywolwnvd.biz |
| unknown |
ssbzmoy.biz |
| unknown |
clients2.google.com |
| whitelisted |
cvgrf.biz |
| malicious |
npukfztj.biz |
| unknown |
config.edge.skype.com |
| whitelisted |
msedge.api.cdp.microsoft.com |
| whitelisted |
przvgke.biz |
| unknown |
geo.prod.do.dsp.mp.microsoft.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
6428 | Setup1.exe | A Network Trojan was detected | ET MALWARE Possible Compromised Host AnubisNetworks Sinkhole Cookie Value Snkz |
6428 | Setup1.exe | A Network Trojan was detected | ET MALWARE Possible Compromised Host AnubisNetworks Sinkhole Cookie Value btst |
6428 | Setup1.exe | A Network Trojan was detected | ET MALWARE Possible Compromised Host AnubisNetworks Sinkhole Cookie Value Snkz |
6428 | Setup1.exe | A Network Trojan was detected | ET MALWARE Possible Compromised Host AnubisNetworks Sinkhole Cookie Value btst |
6428 | Setup1.exe | A Network Trojan was detected | ET MALWARE Possible Compromised Host AnubisNetworks Sinkhole Cookie Value Snkz |
6428 | Setup1.exe | A Network Trojan was detected | ET MALWARE Possible Compromised Host AnubisNetworks Sinkhole Cookie Value btst |
— | — | A Network Trojan was detected | ET MALWARE DNS Query to DarkGate/Expiro Related Domain (knjghuig .biz) |
— | — | Potential Corporate Privacy Violation | ET POLICY PE EXE or DLL Windows file download HTTP |
— | — | Misc activity | ET INFO EXE - Served Attached HTTP |