File name:

MBSetup.exe

Full analysis: https://app.any.run/tasks/90ed6014-253a-42ba-8086-53a992bbe0ab
Verdict: Malicious activity
Analysis date: June 21, 2025, 18:36:28
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 5 sections
MD5:

43DC0BEE6E91D28D0E2D2A40664DC5EE

SHA1:

206F2B1B32692E684145A9AAC41317EA71FD1220

SHA256:

09F8B72EBED762DD7C8CEE790E339BE81ADA29DB13DD9F46FEAFD1428C40DA98

SSDEEP:

98304:ZdwSrm2PRD40cWI22IT1PD222222272TSRTP4WG5N0aFvGSSRkrlcfABLqI141X1:xX6

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads the BIOS version

      • MBSetup.exe (PID: 5168)
    • Searches for installed software

      • MBSetup.exe (PID: 5168)
      • MBAMInstallerService.exe (PID: 3620)
    • Creates files in the driver directory

      • MBSetup.exe (PID: 5168)
    • Executable content was dropped or overwritten

      • MBSetup.exe (PID: 5168)
      • MBAMInstallerService.exe (PID: 3620)
    • Executes as Windows Service

      • MBAMInstallerService.exe (PID: 3620)
    • The process verifies whether the antivirus software is installed

      • MBSetup.exe (PID: 5168)
      • MBAMInstallerService.exe (PID: 3620)
    • Drops 7-zip archiver for unpacking

      • MBAMInstallerService.exe (PID: 3620)
    • The process creates files with name similar to system file names

      • MBAMInstallerService.exe (PID: 3620)
    • Process drops legitimate windows executable

      • MBAMInstallerService.exe (PID: 3620)
    • Drops a system driver (possible attempt to evade defenses)

      • MBAMInstallerService.exe (PID: 3620)
  • INFO

    • Checks supported languages

      • MBSetup.exe (PID: 5168)
      • MBAMInstallerService.exe (PID: 3620)
    • Create files in a temporary directory

      • MBSetup.exe (PID: 5168)
    • The sample compiled with english language support

      • MBSetup.exe (PID: 5168)
      • MBAMInstallerService.exe (PID: 3620)
    • Creates files in the program directory

      • MBSetup.exe (PID: 5168)
      • MBAMInstallerService.exe (PID: 3620)
    • Reads the computer name

      • MBSetup.exe (PID: 5168)
      • MBAMInstallerService.exe (PID: 3620)
    • Reads the machine GUID from the registry

      • MBSetup.exe (PID: 5168)
    • Reads the software policy settings

      • MBSetup.exe (PID: 5168)
      • MBAMInstallerService.exe (PID: 3620)
    • Checks proxy server information

      • MBSetup.exe (PID: 5168)
    • The sample compiled with spanish language support

      • MBAMInstallerService.exe (PID: 3620)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (76.4)
.exe | Win32 Executable (generic) (12.4)
.exe | Generic Win/DOS Executable (5.5)
.exe | DOS Executable Generic (5.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2025:05:02 00:24:44+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14.38
CodeSize: 799744
InitializedDataSize: 1980416
UninitializedDataSize: -
EntryPoint: 0x90685
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 5.3.1.129
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Dynamic link library
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Malwarebytes
FileDescription: Malwarebytes Setup
FileVersion: 5.3.1.129
LegalCopyright: Copyright (C) 2017 - 2024 Malwarebytes, Inc. All rights reserved.
InternalName: MBSetup.exe
OriginalFileName: MBSetup.exe
ProductName: Malwarebytes
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
139
Monitored processes
4
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start mbsetup.exe mbaminstallerservice.exe slui.exe no specs mbsetup.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
3620"C:\Program Files\Malwarebytes\Anti-Malware\MBAMInstallerService.exe"C:\Program Files\Malwarebytes\Anti-Malware\MBAMInstallerService.exe
services.exe
User:
SYSTEM
Company:
Malwarebytes
Integrity Level:
SYSTEM
Description:
Malwarebytes Installer Service
Version:
5.1.0.210
Modules
Images
c:\program files\malwarebytes\anti-malware\mbaminstallerservice.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\authz.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\cryptbase.dll
4120C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
5168"C:\Users\admin\AppData\Local\Temp\MBSetup.exe" C:\Users\admin\AppData\Local\Temp\MBSetup.exe
explorer.exe
User:
admin
Company:
Malwarebytes
Integrity Level:
HIGH
Description:
Malwarebytes Setup
Version:
5.3.1.129
Modules
Images
c:\users\admin\appdata\local\temp\mbsetup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\crypt32.dll
5300"C:\Users\admin\AppData\Local\Temp\MBSetup.exe" C:\Users\admin\AppData\Local\Temp\MBSetup.exeexplorer.exe
User:
admin
Company:
Malwarebytes
Integrity Level:
MEDIUM
Description:
Malwarebytes Setup
Exit code:
3221226540
Version:
5.3.1.129
Modules
Images
c:\users\admin\appdata\local\temp\mbsetup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
Total events
4 492
Read events
4 417
Write events
74
Delete events
1

Modification events

(PID) Process:(5168) MBSetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Malwarebytes
Operation:writeName:id
Value:
c872d9353191408988b94ddb8f787402
(PID) Process:(5168) MBSetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Malwarebytes
Operation:writeName:id
Value:
c872d9353191408988b94ddb8f787402
(PID) Process:(5168) MBSetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\mbamtestkey
Operation:delete keyName:(default)
Value:
(PID) Process:(5168) MBSetup.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MBAMInstallerService\Parameters
Operation:writeName:UserName
Value:
admin
(PID) Process:(5168) MBSetup.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MBAMInstallerService\Parameters
Operation:writeName:ProductCode
Value:
MBAM-C
(PID) Process:(5168) MBSetup.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MBAMInstallerService\Parameters
Operation:writeName:ProductBuild
Value:
consumer
(PID) Process:(5168) MBSetup.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MBAMInstallerService\Parameters
Operation:writeName:ProgramDirectory
Value:
C:\Program Files\Malwarebytes\Anti-Malware
(PID) Process:(5168) MBSetup.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MBAMInstallerService\Parameters
Operation:writeName:LocalAppDataDir
Value:
C:\Users\admin\AppData\Local
(PID) Process:(5168) MBSetup.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MBAMInstallerService\Parameters
Operation:writeName:Channel
Value:
release
(PID) Process:(5168) MBSetup.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MBAMInstallerService\Parameters
Operation:writeName:Installer
Value:
C:\Users\admin\AppData\Local\Temp\MBSetup.exe
Executable files
318
Suspicious files
31
Text files
12
Unknown types
0

Dropped files

PID
Process
Filename
Type
3620MBAMInstallerService.exeC:\Windows\Temp\MBInstallTempb8c0e8054ece11f0a8194ce923cbaee5\ctlrpkg.7z
MD5:
SHA256:
3620MBAMInstallerService.exeC:\Windows\Temp\MBInstallTempb8c0e8054ece11f0a8194ce923cbaee5\dbclspkg.7z
MD5:
SHA256:
3620MBAMInstallerService.exeC:\Windows\Temp\MBInstallTempb8c0e8054ece11f0a8194ce923cbaee5\dotnetpkg.7z
MD5:
SHA256:
3620MBAMInstallerService.exeC:\Windows\Temp\MBInstallTempb8c0e8054ece11f0a8194ce923cbaee5\ctlrpkg\Assistant.deps.jsonbinary
MD5:26D5540F2674A1E33722EAF225EF7591
SHA256:064A06E32F5A36F010A26737DEDEFD24CDBE5112FD08757B78449C3548447954
5168MBSetup.exeC:\ProgramData\mbamtestfile.dattext
MD5:9F06243ABCB89C70E0C331C61D871FA7
SHA256:837CCB607E312B170FAC7383D7CCFD61FA5072793F19A25E75FBACB56539B86B
5168MBSetup.exeC:\Windows\SysWOW64\drivers\mbamtestfile.dattext
MD5:9F06243ABCB89C70E0C331C61D871FA7
SHA256:837CCB607E312B170FAC7383D7CCFD61FA5072793F19A25E75FBACB56539B86B
3620MBAMInstallerService.exeC:\Windows\Temp\MBInstallTempb8c0e8054ece11f0a8194ce923cbaee5\servicepkg.7zcompressed
MD5:6F605A7E0FE5A4115271F4024141881F
SHA256:6ED9E1D563EF152137D1AB9F9E6371127A3F135FDCEA2F7F6462D718C2CA3D29
3620MBAMInstallerService.exeC:\Windows\Temp\MBInstallTempb8c0e8054ece11f0a8194ce923cbaee5\ctlrpkg\Malwarebytes_Assistant.deps.jsonbinary
MD5:0C0163F65B5457C15ABE97834ECA99D7
SHA256:426998F682589E0700286C17D7FDC33125CE6B4334DD2DFDC505A4F3CC3C33A0
3620MBAMInstallerService.exeC:\Windows\Temp\MBInstallTempb8c0e8054ece11f0a8194ce923cbaee5\servicepkg\srvversion.dattext
MD5:35BC43D96E8BE3AF32020DD6B7CC3A68
SHA256:614BAE3C6BE7BB988DF1EE255A3A54D3BF5DBB786E1093C08594FD19B03D1FCD
3620MBAMInstallerService.exeC:\Windows\Temp\MBInstallTempb8c0e8054ece11f0a8194ce923cbaee5\7z.dllexecutable
MD5:3430E2544637CEBF8BA1F509ED5A27B1
SHA256:BB01C6FBB29590D6D144A9038C2A7736D6925A6DBD31889538AF033E03E4F5FA
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
35
DNS requests
22
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4168
svchost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
1268
svchost.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6948
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
1268
svchost.exe
GET
200
23.55.104.172:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
6948
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
5944
MoUsoCoreWorker.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1268
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2324
RUXIMICS.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
192.168.100.255:138
whitelisted
5168
MBSetup.exe
50.112.46.114:443
api2.amplitude.com
AMAZON-02
US
whitelisted
2336
svchost.exe
172.211.123.250:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
4168
svchost.exe
40.126.32.76:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4168
svchost.exe
2.23.77.188:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
1268
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 51.124.78.146
whitelisted
google.com
  • 142.250.186.78
whitelisted
api2.amplitude.com
  • 50.112.46.114
  • 35.166.46.215
  • 100.21.115.98
  • 35.83.151.156
  • 54.190.221.59
  • 54.201.145.164
  • 52.36.62.207
  • 35.167.49.124
whitelisted
client.wns.windows.com
  • 172.211.123.250
whitelisted
login.live.com
  • 40.126.32.76
  • 20.190.160.67
  • 20.190.160.128
  • 20.190.160.66
  • 40.126.32.133
  • 20.190.160.65
  • 40.126.32.74
  • 40.126.32.68
whitelisted
ocsp.digicert.com
  • 2.23.77.188
whitelisted
crl.microsoft.com
  • 23.55.104.172
  • 23.55.104.190
whitelisted
www.microsoft.com
  • 95.101.149.131
whitelisted
nexusrules.officeapps.live.com
  • 52.111.236.21
whitelisted
ark.mwbsys.com
  • 54.237.82.196
  • 54.146.252.215
  • 34.234.155.242
whitelisted

Threats

No threats detected
No debug info