File name:

setuptr.exe

Full analysis: https://app.any.run/tasks/590768d6-5a65-4aa1-8f4e-bbb56df33204
Verdict: Malicious activity
Analysis date: February 17, 2024, 19:40:58
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

7AD79A39CFC3BD7B4050286C1F688CAB

SHA1:

FE7C84C61836462DA1DD83ACD7D7B3F193F71864

SHA256:

0894F82A3783827A2FC02B08988C11CC49CC7805A4B4A9078FF7EA756FBCC57E

SSDEEP:

49152:RzoCtRtPtD5t47GMkJp+wJyxLK226CGYdKYdmF3pO4e0i7WU++HMApI0:xRBt4yNs5Y5y9L+Hv

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • setuptr.exe (PID: 3784)
    • Changes the autorun value in the registry

      • setuptr.exe (PID: 3784)
    • Creates a writable file in the system directory

      • setuptr.exe (PID: 3784)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • setuptr.exe (PID: 3784)
    • Process drops legitimate windows executable

      • setuptr.exe (PID: 3784)
    • The process executes via Task Scheduler

      • sipnotify.exe (PID: 1460)
      • ctfmon.exe (PID: 1812)
    • Reads the Internet Settings

      • sipnotify.exe (PID: 1460)
    • Reads settings of System Certificates

      • sipnotify.exe (PID: 1460)
  • INFO

    • Checks supported languages

      • setuptr.exe (PID: 3784)
      • IMEKLMG.EXE (PID: 408)
      • dg.exe (PID: 1416)
      • wmpnscfg.exe (PID: 2340)
      • wmpnscfg.exe (PID: 2376)
      • wmpnscfg.exe (PID: 2540)
      • IMEKLMG.EXE (PID: 564)
    • Reads the computer name

      • setuptr.exe (PID: 3784)
      • dg.exe (PID: 1416)
      • wmpnscfg.exe (PID: 2340)
      • wmpnscfg.exe (PID: 2376)
      • wmpnscfg.exe (PID: 2540)
      • IMEKLMG.EXE (PID: 408)
      • IMEKLMG.EXE (PID: 564)
    • Creates files in the program directory

      • setuptr.exe (PID: 3784)
    • Manual execution by a user

      • IMEKLMG.EXE (PID: 408)
      • IMEKLMG.EXE (PID: 564)
      • dg.exe (PID: 1416)
      • wmpnscfg.exe (PID: 2340)
      • wmpnscfg.exe (PID: 2376)
      • wmpnscfg.exe (PID: 2540)
      • SndVol.exe (PID: 2556)
      • explorer.exe (PID: 2584)
    • Creates files or folders in the user directory

      • dg.exe (PID: 1416)
    • Reads the software policy settings

      • sipnotify.exe (PID: 1460)
    • Reads security settings of Internet Explorer

      • sipnotify.exe (PID: 1460)
    • Process checks whether UAC notifications are on

      • IMEKLMG.EXE (PID: 564)
      • IMEKLMG.EXE (PID: 408)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable Borland Delphi 5 (78.6)
.exe | InstallShield setup (7.5)
.exe | Win32 EXE PECompact compressed (generic) (7.2)
.exe | Win32 Executable Delphi generic (2.4)
.scr | Windows screen saver (2.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 1992:06:19 22:22:17+00:00
ImageFileCharacteristics: Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 354816
InitializedDataSize: 1181696
UninitializedDataSize: -
EntryPoint: 0x57800
OSVersion: 1
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 2.20.0.838
ProductVersionNumber: 2.20.0.838
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
CompanyName: Embetrix
FileDescription: DialGuard Installer
FileVersion: 2.20.0.838
InternalName: DialGuard installer
LegalCopyright: © 2001-2002 Embetrix
LegalTrademarks: -
OriginalFileName: setup.exe
ProductName: DialGuard
ProductVersion: 1.0.0.0
Comments: www.dialguard.com
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
94
Monitored processes
12
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start setuptr.exe sipnotify.exe ctfmon.exe no specs imeklmg.exe no specs imeklmg.exe no specs dg.exe wmpnscfg.exe no specs wmpnscfg.exe no specs wmpnscfg.exe no specs sndvol.exe no specs explorer.exe no specs setuptr.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
408"C:\Program Files\Common Files\microsoft shared\IME14\SHARED\IMEKLMG.EXE" /SetPreload /JPN /LogC:\Program Files\Common Files\microsoft shared\IME14\SHARED\IMEKLMG.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Office IME 2010
Exit code:
1
Version:
14.0.4734.1000
Modules
Images
c:\program files\common files\microsoft shared\ime14\shared\imeklmg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\userenv.dll
564"C:\Program Files\Common Files\microsoft shared\IME14\SHARED\IMEKLMG.EXE" /SetPreload /KOR /LogC:\Program Files\Common Files\microsoft shared\IME14\SHARED\IMEKLMG.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Office IME 2010
Exit code:
1
Version:
14.0.4734.1000
Modules
Images
c:\program files\common files\microsoft shared\ime14\shared\imeklmg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\userenv.dll
1384"C:\Users\admin\AppData\Local\Temp\setuptr.exe" C:\Users\admin\AppData\Local\Temp\setuptr.exeexplorer.exe
User:
admin
Company:
Embetrix
Integrity Level:
MEDIUM
Description:
DialGuard Installer
Exit code:
3221226540
Version:
2.20.0.838
Modules
Images
c:\users\admin\appdata\local\temp\setuptr.exe
c:\windows\system32\ntdll.dll
1416"C:\Program Files\DialGuard\dg.exe" C:\Program Files\DialGuard\dg.exe
explorer.exe
User:
admin
Company:
Embetrix ApS
Integrity Level:
MEDIUM
Description:
DialGuard
Exit code:
1
Version:
2.20.0.838
Modules
Images
c:\program files\dialguard\dg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
1460C:\Windows\system32\sipnotify.exe -LogonOrUnlockC:\Windows\System32\sipnotify.exe
taskeng.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
sipnotify
Exit code:
0
Version:
6.1.7602.20480 (win7sp1_ldr_escrow.191010-1716)
Modules
Images
c:\windows\system32\sipnotify.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1812C:\Windows\System32\ctfmon.exe C:\Windows\System32\ctfmon.exetaskeng.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
CTF Loader
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ctfmon.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msctfmonitor.dll
c:\windows\system32\msctf.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
2340"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2376"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2540"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2556SndVol.exe -f 45745297 15580C:\Windows\System32\SndVol.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Volume Mixer
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\sndvol.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
Total events
5 135
Read events
5 095
Write events
26
Delete events
14

Modification events

(PID) Process:(3784) setuptr.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE
Operation:writeName:EmbetrixTest
Value:
delete me
(PID) Process:(3784) setuptr.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE
Operation:delete valueName:EmbetrixTest
Value:
delete me
(PID) Process:(3784) setuptr.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Telephony\Providers
Operation:writeName:ProviderFileName0
Value:
xunimdm.tsp
(PID) Process:(3784) setuptr.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Telephony\Providers
Operation:writeName:ProviderFileName1
Value:
xkmddsp.tsp
(PID) Process:(3784) setuptr.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Operation:writeName:DialGuard
Value:
C:\Program Files\DialGuard\dg.exe
(PID) Process:(1812) ctfmon.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
Operation:delete valueName:internat.exe
Value:
(PID) Process:(408) IMEKLMG.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\IMEJP\14.0
Operation:writeName:SetPreload
Value:
1
(PID) Process:(564) IMEKLMG.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\IMEKR\14.0
Operation:writeName:SetPreload
Value:
1
(PID) Process:(1460) sipnotify.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1460) sipnotify.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Root\Certificates
Operation:delete valueName:9F6134C5FA75E4FDDE631B232BE961D6D4B97DB6
Value:
Executable files
6
Suspicious files
6
Text files
8
Unknown types
2

Dropped files

PID
Process
Filename
Type
3784setuptr.exeC:\Windows\system32\backup-unimdm.tspexecutable
MD5:377F0C1DDBFA6A43CB7E7568BC0ECED0
SHA256:51C080068A3943B2950E16828EBBB181EF27BD007251916A556FA4B8FF64A826
3784setuptr.exeC:\Program Files\DialGuard\dghelp6.chmbinary
MD5:DB9F84F52DB36A5F31BAB0FFDCB2482D
SHA256:07F7A35422FD672892D642DEC73ED4ED096A15C9E76B4FDE1A9E1A77EED7E8F8
3784setuptr.exeC:\Program Files\DialGuard\dg.exeexecutable
MD5:8239FA824932326CB2397CD5DB6B5E7B
SHA256:A7B8E55528350A2949124FCC9B61CDE1668874572E9996E3152C154DEDEEF2F7
3784setuptr.exeC:\Windows\system32\dunimdm.tspexecutable
MD5:377F0C1DDBFA6A43CB7E7568BC0ECED0
SHA256:51C080068A3943B2950E16828EBBB181EF27BD007251916A556FA4B8FF64A826
3784setuptr.exeC:\Windows\system32\backup-kmddsp.tspexecutable
MD5:BF46D123C2FE430C618B2D2673A0E845
SHA256:2FE7A2128ABA4AA665D7F75481D8583F83B2094EFC4FAFFA6217314B48E26D24
3784setuptr.exeC:\Program Files\DialGuard\lang.dattext
MD5:9035037C57CE8A11F41B6841F02F820A
SHA256:25E3244EB01542DD5F375B55C36C890CD0D706852ACC725E692EF7BB23CE9823
3784setuptr.exeC:\Windows\system32\dkmddsp.tspexecutable
MD5:BF46D123C2FE430C618B2D2673A0E845
SHA256:2FE7A2128ABA4AA665D7F75481D8583F83B2094EFC4FAFFA6217314B48E26D24
3784setuptr.exeC:\Program Files\DialGuard\dghelp9.chmchm
MD5:DBA0599968A597A62530FE6FFD8086C9
SHA256:6717B4315402A77A9671B2FB0DEBF284936D4B5A9D24FA790581CABDDA17704A
3784setuptr.exeC:\Program Files\DialGuard\readme9.txttext
MD5:8951772521F517E1E891601E3ED31026
SHA256:903D4FFE9920A1C46F1280A44C5806297FBB41790397551322193A29D8BB6A04
3784setuptr.exeC:\Program Files\DialGuard\readme6.txttext
MD5:A66BF302EA89A5D42BE3AE30F38B8628
SHA256:C7B944756F4CD3F6EB4B335C0A23927607D9B043DA8D69272471C1441C5DA545
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
10
DNS requests
2
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1460
sipnotify.exe
HEAD
200
23.192.244.236:80
http://query.prod.cms.rt.microsoft.com/cms/api/am/binary/RE2JgkA?v=133526725025930000
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
1124
svchost.exe
224.0.0.252:5355
unknown
1460
sipnotify.exe
23.192.244.236:80
query.prod.cms.rt.microsoft.com
AKAMAI-AS
US
unknown
2220
WerFault.exe
104.208.16.93:443
watson.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown

DNS requests

Domain
IP
Reputation
query.prod.cms.rt.microsoft.com
  • 23.192.244.236
whitelisted
watson.microsoft.com
  • 104.208.16.93
whitelisted

Threats

No threats detected
No debug info