| File name: | setuptr.exe |
| Full analysis: | https://app.any.run/tasks/590768d6-5a65-4aa1-8f4e-bbb56df33204 |
| Verdict: | Malicious activity |
| Analysis date: | February 17, 2024, 19:40:58 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 7AD79A39CFC3BD7B4050286C1F688CAB |
| SHA1: | FE7C84C61836462DA1DD83ACD7D7B3F193F71864 |
| SHA256: | 0894F82A3783827A2FC02B08988C11CC49CC7805A4B4A9078FF7EA756FBCC57E |
| SSDEEP: | 49152:RzoCtRtPtD5t47GMkJp+wJyxLK226CGYdKYdmF3pO4e0i7WU++HMApI0:xRBt4yNs5Y5y9L+Hv |
| .exe | | | Win32 Executable Borland Delphi 5 (78.6) |
|---|---|---|
| .exe | | | InstallShield setup (7.5) |
| .exe | | | Win32 EXE PECompact compressed (generic) (7.2) |
| .exe | | | Win32 Executable Delphi generic (2.4) |
| .scr | | | Windows screen saver (2.2) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 1992:06:19 22:22:17+00:00 |
| ImageFileCharacteristics: | Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi |
| PEType: | PE32 |
| LinkerVersion: | 2.25 |
| CodeSize: | 354816 |
| InitializedDataSize: | 1181696 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x57800 |
| OSVersion: | 1 |
| ImageVersion: | - |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 2.20.0.838 |
| ProductVersionNumber: | 2.20.0.838 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Windows, Latin1 |
| CompanyName: | Embetrix |
| FileDescription: | DialGuard Installer |
| FileVersion: | 2.20.0.838 |
| InternalName: | DialGuard installer |
| LegalCopyright: | © 2001-2002 Embetrix |
| LegalTrademarks: | - |
| OriginalFileName: | setup.exe |
| ProductName: | DialGuard |
| ProductVersion: | 1.0.0.0 |
| Comments: | www.dialguard.com |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 408 | "C:\Program Files\Common Files\microsoft shared\IME14\SHARED\IMEKLMG.EXE" /SetPreload /JPN /Log | C:\Program Files\Common Files\microsoft shared\IME14\SHARED\IMEKLMG.EXE | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Office IME 2010 Exit code: 1 Version: 14.0.4734.1000 Modules
| |||||||||||||||
| 564 | "C:\Program Files\Common Files\microsoft shared\IME14\SHARED\IMEKLMG.EXE" /SetPreload /KOR /Log | C:\Program Files\Common Files\microsoft shared\IME14\SHARED\IMEKLMG.EXE | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Office IME 2010 Exit code: 1 Version: 14.0.4734.1000 Modules
| |||||||||||||||
| 1384 | "C:\Users\admin\AppData\Local\Temp\setuptr.exe" | C:\Users\admin\AppData\Local\Temp\setuptr.exe | — | explorer.exe | |||||||||||
User: admin Company: Embetrix Integrity Level: MEDIUM Description: DialGuard Installer Exit code: 3221226540 Version: 2.20.0.838 Modules
| |||||||||||||||
| 1416 | "C:\Program Files\DialGuard\dg.exe" | C:\Program Files\DialGuard\dg.exe | explorer.exe | ||||||||||||
User: admin Company: Embetrix ApS Integrity Level: MEDIUM Description: DialGuard Exit code: 1 Version: 2.20.0.838 Modules
| |||||||||||||||
| 1460 | C:\Windows\system32\sipnotify.exe -LogonOrUnlock | C:\Windows\System32\sipnotify.exe | taskeng.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: sipnotify Exit code: 0 Version: 6.1.7602.20480 (win7sp1_ldr_escrow.191010-1716) Modules
| |||||||||||||||
| 1812 | C:\Windows\System32\ctfmon.exe | C:\Windows\System32\ctfmon.exe | — | taskeng.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: CTF Loader Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2340 | "C:\Program Files\Windows Media Player\wmpnscfg.exe" | C:\Program Files\Windows Media Player\wmpnscfg.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Network Sharing Service Configuration Application Exit code: 0 Version: 12.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2376 | "C:\Program Files\Windows Media Player\wmpnscfg.exe" | C:\Program Files\Windows Media Player\wmpnscfg.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Network Sharing Service Configuration Application Exit code: 0 Version: 12.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2540 | "C:\Program Files\Windows Media Player\wmpnscfg.exe" | C:\Program Files\Windows Media Player\wmpnscfg.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Network Sharing Service Configuration Application Exit code: 0 Version: 12.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2556 | SndVol.exe -f 45745297 15580 | C:\Windows\System32\SndVol.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Volume Mixer Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (3784) setuptr.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE |
| Operation: | write | Name: | EmbetrixTest |
Value: delete me | |||
| (PID) Process: | (3784) setuptr.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE |
| Operation: | delete value | Name: | EmbetrixTest |
Value: delete me | |||
| (PID) Process: | (3784) setuptr.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Telephony\Providers |
| Operation: | write | Name: | ProviderFileName0 |
Value: xunimdm.tsp | |||
| (PID) Process: | (3784) setuptr.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Telephony\Providers |
| Operation: | write | Name: | ProviderFileName1 |
Value: xkmddsp.tsp | |||
| (PID) Process: | (3784) setuptr.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run |
| Operation: | write | Name: | DialGuard |
Value: C:\Program Files\DialGuard\dg.exe | |||
| (PID) Process: | (1812) ctfmon.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run |
| Operation: | delete value | Name: | internat.exe |
Value: | |||
| (PID) Process: | (408) IMEKLMG.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\IMEJP\14.0 |
| Operation: | write | Name: | SetPreload |
Value: 1 | |||
| (PID) Process: | (564) IMEKLMG.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\IMEKR\14.0 |
| Operation: | write | Name: | SetPreload |
Value: 1 | |||
| (PID) Process: | (1460) sipnotify.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (1460) sipnotify.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Root\Certificates |
| Operation: | delete value | Name: | 9F6134C5FA75E4FDDE631B232BE961D6D4B97DB6 |
Value: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3784 | setuptr.exe | C:\Windows\system32\backup-unimdm.tsp | executable | |
MD5:377F0C1DDBFA6A43CB7E7568BC0ECED0 | SHA256:51C080068A3943B2950E16828EBBB181EF27BD007251916A556FA4B8FF64A826 | |||
| 3784 | setuptr.exe | C:\Program Files\DialGuard\dghelp6.chm | binary | |
MD5:DB9F84F52DB36A5F31BAB0FFDCB2482D | SHA256:07F7A35422FD672892D642DEC73ED4ED096A15C9E76B4FDE1A9E1A77EED7E8F8 | |||
| 3784 | setuptr.exe | C:\Program Files\DialGuard\dg.exe | executable | |
MD5:8239FA824932326CB2397CD5DB6B5E7B | SHA256:A7B8E55528350A2949124FCC9B61CDE1668874572E9996E3152C154DEDEEF2F7 | |||
| 3784 | setuptr.exe | C:\Windows\system32\dunimdm.tsp | executable | |
MD5:377F0C1DDBFA6A43CB7E7568BC0ECED0 | SHA256:51C080068A3943B2950E16828EBBB181EF27BD007251916A556FA4B8FF64A826 | |||
| 3784 | setuptr.exe | C:\Windows\system32\backup-kmddsp.tsp | executable | |
MD5:BF46D123C2FE430C618B2D2673A0E845 | SHA256:2FE7A2128ABA4AA665D7F75481D8583F83B2094EFC4FAFFA6217314B48E26D24 | |||
| 3784 | setuptr.exe | C:\Program Files\DialGuard\lang.dat | text | |
MD5:9035037C57CE8A11F41B6841F02F820A | SHA256:25E3244EB01542DD5F375B55C36C890CD0D706852ACC725E692EF7BB23CE9823 | |||
| 3784 | setuptr.exe | C:\Windows\system32\dkmddsp.tsp | executable | |
MD5:BF46D123C2FE430C618B2D2673A0E845 | SHA256:2FE7A2128ABA4AA665D7F75481D8583F83B2094EFC4FAFFA6217314B48E26D24 | |||
| 3784 | setuptr.exe | C:\Program Files\DialGuard\dghelp9.chm | chm | |
MD5:DBA0599968A597A62530FE6FFD8086C9 | SHA256:6717B4315402A77A9671B2FB0DEBF284936D4B5A9D24FA790581CABDDA17704A | |||
| 3784 | setuptr.exe | C:\Program Files\DialGuard\readme9.txt | text | |
MD5:8951772521F517E1E891601E3ED31026 | SHA256:903D4FFE9920A1C46F1280A44C5806297FBB41790397551322193A29D8BB6A04 | |||
| 3784 | setuptr.exe | C:\Program Files\DialGuard\readme6.txt | text | |
MD5:A66BF302EA89A5D42BE3AE30F38B8628 | SHA256:C7B944756F4CD3F6EB4B335C0A23927607D9B043DA8D69272471C1441C5DA545 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
1460 | sipnotify.exe | HEAD | 200 | 23.192.244.236:80 | http://query.prod.cms.rt.microsoft.com/cms/api/am/binary/RE2JgkA?v=133526725025930000 | unknown | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
1124 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
1460 | sipnotify.exe | 23.192.244.236:80 | query.prod.cms.rt.microsoft.com | AKAMAI-AS | US | unknown |
2220 | WerFault.exe | 104.208.16.93:443 | watson.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | unknown |
Domain | IP | Reputation |
|---|---|---|
query.prod.cms.rt.microsoft.com |
| whitelisted |
watson.microsoft.com |
| whitelisted |