File name:

TGsetup.exe

Full analysis: https://app.any.run/tasks/f06121ef-d3b6-4c27-aa90-7df000ae03c5
Verdict: Malicious activity
Analysis date: May 17, 2024, 01:50:05
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
qrcode
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

74FE7139456E360F55804055D11A318A

SHA1:

FA3A5BC8F36F1A403A9F2163EF54B33D3B9598FF

SHA256:

060A0D59B662EEFEDCCFB1C1E18A1B81AFA9D5173D59E0B83308C4FAC0240BFF

SSDEEP:

98304:BI1+hjWzeElA9rONfa0ChzcfAvqygk3NQXlR0artDoC2Tb3Qvid4eFk3f0UIauDK:r8iVCUu5CK2VXgR

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • TGsetup.exe (PID: 3964)
      • TGsetup.exe (PID: 1020)
      • TGsetup.tmp (PID: 2104)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • TGsetup.exe (PID: 3964)
      • TGsetup.exe (PID: 1020)
      • TGsetup.tmp (PID: 2104)
    • Process drops legitimate windows executable

      • TGsetup.tmp (PID: 2104)
    • Reads the Windows owner or organization settings

      • TGsetup.tmp (PID: 2104)
  • INFO

    • Checks supported languages

      • TGsetup.exe (PID: 3964)
      • TGsetup.tmp (PID: 3980)
      • TGsetup.exe (PID: 1020)
      • TGsetup.tmp (PID: 2104)
    • Reads the computer name

      • TGsetup.tmp (PID: 3980)
      • TGsetup.tmp (PID: 2104)
    • Create files in a temporary directory

      • TGsetup.exe (PID: 3964)
      • TGsetup.exe (PID: 1020)
      • TGsetup.tmp (PID: 2104)
    • Creates files in the program directory

      • TGsetup.tmp (PID: 2104)
    • Creates a software uninstall entry

      • TGsetup.tmp (PID: 2104)
    • Manual execution by a user

      • TGServer.exe (PID: 1680)
      • TGServer.exe (PID: 1628)
      • TGServer.exe (PID: 1236)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (71.1)
.exe | Win32 Executable Delphi generic (9.1)
.scr | Windows screen saver (8.4)
.dll | Win32 Dynamic Link Library (generic) (4.2)
.exe | Win32 Executable (generic) (2.9)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 1992:06:19 22:22:17+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 40448
InitializedDataSize: 17920
UninitializedDataSize: -
EntryPoint: 0xa5f8
OSVersion: 1
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 0.0.0.0
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: Odd Sheep Ltd.
FileDescription: TrinusVR Setup
FileVersion:
LegalCopyright:
ProductName: TrinusVR
ProductVersion: 2.0.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
45
Monitored processes
7
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
start tgsetup.exe tgsetup.tmp no specs tgsetup.exe tgsetup.tmp tgserver.exe no specs tgserver.exe no specs tgserver.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1020"C:\Users\admin\AppData\Local\Temp\TGsetup.exe" /SPAWNWND=$20134 /NOTIFYWND=$20138 C:\Users\admin\AppData\Local\Temp\TGsetup.exe
TGsetup.tmp
User:
admin
Company:
Odd Sheep Ltd.
Integrity Level:
HIGH
Description:
TrinusVR Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\appdata\local\temp\tgsetup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
1236"C:\Program Files\TrinusVR\TGServer.exe" C:\Program Files\TrinusVR\TGServer.exeexplorer.exe
User:
admin
Company:
Odd Sheep Ltd
Integrity Level:
MEDIUM
Description:
Trinus VR
Exit code:
3221226540
Version:
1.0.0.0
Modules
Images
c:\program files\trinusvr\tgserver.exe
c:\windows\system32\ntdll.dll
1628"C:\Program Files\TrinusVR\TGServer.exe" C:\Program Files\TrinusVR\TGServer.exeexplorer.exe
User:
admin
Company:
Odd Sheep Ltd
Integrity Level:
MEDIUM
Description:
Trinus VR
Exit code:
3221226540
Version:
1.0.0.0
Modules
Images
c:\program files\trinusvr\tgserver.exe
c:\windows\system32\ntdll.dll
1680"C:\Program Files\TrinusVR\TGServer.exe" C:\Program Files\TrinusVR\TGServer.exeexplorer.exe
User:
admin
Company:
Odd Sheep Ltd
Integrity Level:
MEDIUM
Description:
Trinus VR
Exit code:
3221226540
Version:
1.0.0.0
Modules
Images
c:\program files\trinusvr\tgserver.exe
c:\windows\system32\ntdll.dll
2104"C:\Users\admin\AppData\Local\Temp\is-86TH2.tmp\TGsetup.tmp" /SL5="$40130,11824489,56832,C:\Users\admin\AppData\Local\Temp\TGsetup.exe" /SPAWNWND=$20134 /NOTIFYWND=$20138 C:\Users\admin\AppData\Local\Temp\is-86TH2.tmp\TGsetup.tmp
TGsetup.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.52.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-86th2.tmp\tgsetup.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
3964"C:\Users\admin\AppData\Local\Temp\TGsetup.exe" C:\Users\admin\AppData\Local\Temp\TGsetup.exe
explorer.exe
User:
admin
Company:
Odd Sheep Ltd.
Integrity Level:
MEDIUM
Description:
TrinusVR Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\appdata\local\temp\tgsetup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
3980"C:\Users\admin\AppData\Local\Temp\is-UH7EE.tmp\TGsetup.tmp" /SL5="$20138,11824489,56832,C:\Users\admin\AppData\Local\Temp\TGsetup.exe" C:\Users\admin\AppData\Local\Temp\is-UH7EE.tmp\TGsetup.tmpTGsetup.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.52.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-uh7ee.tmp\tgsetup.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
Total events
3 558
Read events
3 525
Write events
27
Delete events
6

Modification events

(PID) Process:(2104) TGsetup.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
38080000741A6991FCA7DA01
(PID) Process:(2104) TGsetup.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:SessionHash
Value:
C69308C991625795D82660AA059B4411CF704B3A43D0698AC189550C1C267A11
(PID) Process:(2104) TGsetup.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Sequence
Value:
1
(PID) Process:(2104) TGsetup.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:RegFiles0000
Value:
C:\Program Files\TrinusVR\TGServer.exe
(PID) Process:(2104) TGsetup.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:RegFilesHash
Value:
4A5682357064EA7C4946B26804808CD06837EB9C558C1713F7950B39F8F81783
(PID) Process:(2104) TGsetup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A66AD08F-FC5B-4583-9A7D-4636F5637B2C}_is1
Operation:writeName:Inno Setup: Setup Version
Value:
5.5.5 (a)
(PID) Process:(2104) TGsetup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A66AD08F-FC5B-4583-9A7D-4636F5637B2C}_is1
Operation:writeName:Inno Setup: App Path
Value:
C:\Program Files\TrinusVR
(PID) Process:(2104) TGsetup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A66AD08F-FC5B-4583-9A7D-4636F5637B2C}_is1
Operation:writeName:InstallLocation
Value:
C:\Program Files\TrinusVR\
(PID) Process:(2104) TGsetup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A66AD08F-FC5B-4583-9A7D-4636F5637B2C}_is1
Operation:writeName:Inno Setup: Icon Group
Value:
TrinusVR
(PID) Process:(2104) TGsetup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A66AD08F-FC5B-4583-9A7D-4636F5637B2C}_is1
Operation:writeName:Inno Setup: User
Value:
admin
Executable files
27
Suspicious files
7
Text files
11
Unknown types
0

Dropped files

PID
Process
Filename
Type
2104TGsetup.tmpC:\Program Files\TrinusVR\is-M44K4.tmp
MD5:
SHA256:
2104TGsetup.tmpC:\Program Files\TrinusVR\shapePositionTrackerInstructions.pdf
MD5:
SHA256:
2104TGsetup.tmpC:\Program Files\TrinusVR\is-FILLC.tmp
MD5:
SHA256:
2104TGsetup.tmpC:\Program Files\TrinusVR\is-GI839.tmp
MD5:
SHA256:
2104TGsetup.tmpC:\Program Files\TrinusVR\SharpDX.DirectInput.dll
MD5:
SHA256:
2104TGsetup.tmpC:\Program Files\TrinusVR\is-MCTL9.tmp
MD5:
SHA256:
2104TGsetup.tmpC:\Program Files\TrinusVR\is-G5F0J.tmp
MD5:
SHA256:
2104TGsetup.tmpC:\Program Files\TrinusVR\is-0UNMV.tmpexecutable
MD5:418D681E06AB54C176313319A33D8DE3
SHA256:9631E75CEED4B50ECD781B9A0670F174EA12A6BB81A55F498725A992672B0BCD
2104TGsetup.tmpC:\Program Files\TrinusVR\SharpDX.DXGI.dll
MD5:
SHA256:
2104TGsetup.tmpC:\Program Files\TrinusVR\is-PHT1G.tmp
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
3
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
unknown
224.0.0.252:5355
unknown

DNS requests

No data

Threats

No threats detected
No debug info