File name:

MBSetup

Full analysis: https://app.any.run/tasks/bf8fda96-c33e-4862-a77d-54cc1149fb6b
Verdict: Malicious activity
Analysis date: May 12, 2025, 16:36:54
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 5 sections
MD5:

43DC0BEE6E91D28D0E2D2A40664DC5EE

SHA1:

206F2B1B32692E684145A9AAC41317EA71FD1220

SHA256:

09F8B72EBED762DD7C8CEE790E339BE81ADA29DB13DD9F46FEAFD1428C40DA98

SSDEEP:

98304:ZdwSrm2PRD40cWI22IT1PD222222272TSRTP4WG5N0aFvGSSRkrlcfABLqI141X1:xX6

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Searches for installed software

      • MBSetup.exe (PID: 7240)
      • MBAMInstallerService.exe (PID: 7788)
    • Reads the BIOS version

      • MBSetup.exe (PID: 7240)
    • The process verifies whether the antivirus software is installed

      • MBSetup.exe (PID: 7240)
      • MBAMInstallerService.exe (PID: 7788)
    • Creates files in the driver directory

      • MBSetup.exe (PID: 7240)
    • Executable content was dropped or overwritten

      • MBSetup.exe (PID: 7240)
      • MBAMInstallerService.exe (PID: 7788)
    • Drops 7-zip archiver for unpacking

      • MBAMInstallerService.exe (PID: 7788)
    • The process creates files with name similar to system file names

      • MBAMInstallerService.exe (PID: 7788)
    • Executes as Windows Service

      • MBAMInstallerService.exe (PID: 7788)
    • Drops a system driver (possible attempt to evade defenses)

      • MBAMInstallerService.exe (PID: 7788)
    • Process drops legitimate windows executable

      • MBAMInstallerService.exe (PID: 7788)
  • INFO

    • The sample compiled with english language support

      • MBSetup.exe (PID: 7240)
      • MBAMInstallerService.exe (PID: 7788)
    • Create files in a temporary directory

      • MBSetup.exe (PID: 7240)
    • Reads the machine GUID from the registry

      • MBSetup.exe (PID: 7240)
    • Reads the computer name

      • MBSetup.exe (PID: 7240)
      • MBAMInstallerService.exe (PID: 7788)
    • Checks supported languages

      • MBSetup.exe (PID: 7240)
      • MBAMInstallerService.exe (PID: 7788)
    • Reads the software policy settings

      • MBSetup.exe (PID: 7240)
      • MBAMInstallerService.exe (PID: 7788)
    • Checks proxy server information

      • MBSetup.exe (PID: 7240)
    • Creates files in the program directory

      • MBSetup.exe (PID: 7240)
      • MBAMInstallerService.exe (PID: 7788)
    • The sample compiled with spanish language support

      • MBAMInstallerService.exe (PID: 7788)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (76.4)
.exe | Win32 Executable (generic) (12.4)
.exe | Generic Win/DOS Executable (5.5)
.exe | DOS Executable Generic (5.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2025:05:02 00:24:44+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14.38
CodeSize: 799744
InitializedDataSize: 1980416
UninitializedDataSize: -
EntryPoint: 0x90685
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 5.3.1.129
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Dynamic link library
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Malwarebytes
FileDescription: Malwarebytes Setup
FileVersion: 5.3.1.129
LegalCopyright: Copyright (C) 2017 - 2024 Malwarebytes, Inc. All rights reserved.
InternalName: MBSetup.exe
OriginalFileName: MBSetup.exe
ProductName: Malwarebytes
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
133
Monitored processes
3
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start mbsetup.exe mbaminstallerservice.exe mbsetup.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
976"C:\Users\admin\AppData\Local\Temp\MBSetup.exe" C:\Users\admin\AppData\Local\Temp\MBSetup.exeexplorer.exe
User:
admin
Company:
Malwarebytes
Integrity Level:
MEDIUM
Description:
Malwarebytes Setup
Exit code:
3221226540
Version:
5.3.1.129
Modules
Images
c:\users\admin\appdata\local\temp\mbsetup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
7240"C:\Users\admin\AppData\Local\Temp\MBSetup.exe" C:\Users\admin\AppData\Local\Temp\MBSetup.exe
explorer.exe
User:
admin
Company:
Malwarebytes
Integrity Level:
HIGH
Description:
Malwarebytes Setup
Version:
5.3.1.129
Modules
Images
c:\users\admin\appdata\local\temp\mbsetup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\crypt32.dll
7788"C:\Program Files\Malwarebytes\Anti-Malware\MBAMInstallerService.exe"C:\Program Files\Malwarebytes\Anti-Malware\MBAMInstallerService.exe
services.exe
User:
SYSTEM
Company:
Malwarebytes
Integrity Level:
SYSTEM
Description:
Malwarebytes Installer Service
Version:
5.1.0.189
Modules
Images
c:\program files\malwarebytes\anti-malware\mbaminstallerservice.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\authz.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\cryptbase.dll
Total events
4 391
Read events
4 319
Write events
71
Delete events
1

Modification events

(PID) Process:(7240) MBSetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Malwarebytes
Operation:writeName:id
Value:
032c26248eff4fa988cb7e1c6f052477
(PID) Process:(7240) MBSetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Malwarebytes
Operation:writeName:id
Value:
032c26248eff4fa988cb7e1c6f052477
(PID) Process:(7240) MBSetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\mbamtestkey
Operation:delete keyName:(default)
Value:
(PID) Process:(7240) MBSetup.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MBAMInstallerService\Parameters
Operation:writeName:UserName
Value:
admin
(PID) Process:(7240) MBSetup.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MBAMInstallerService\Parameters
Operation:writeName:ProductCode
Value:
MBAM-C
(PID) Process:(7240) MBSetup.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MBAMInstallerService\Parameters
Operation:writeName:ProductBuild
Value:
consumer
(PID) Process:(7240) MBSetup.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MBAMInstallerService\Parameters
Operation:writeName:ProgramDirectory
Value:
C:\Program Files\Malwarebytes\Anti-Malware
(PID) Process:(7240) MBSetup.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MBAMInstallerService\Parameters
Operation:writeName:LocalAppDataDir
Value:
C:\Users\admin\AppData\Local
(PID) Process:(7240) MBSetup.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MBAMInstallerService\Parameters
Operation:writeName:Channel
Value:
release
(PID) Process:(7240) MBSetup.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MBAMInstallerService\Parameters
Operation:writeName:Installer
Value:
C:\Users\admin\AppData\Local\Temp\MBSetup.exe
Executable files
121
Suspicious files
31
Text files
12
Unknown types
0

Dropped files

PID
Process
Filename
Type
7788MBAMInstallerService.exeC:\Windows\Temp\MBInstallTemp602a30732f4f11f08efe92c31c8432e2\ctlrpkg.7z
MD5:
SHA256:
7788MBAMInstallerService.exeC:\Windows\Temp\MBInstallTemp602a30732f4f11f08efe92c31c8432e2\dbclspkg.7z
MD5:
SHA256:
7788MBAMInstallerService.exeC:\Windows\Temp\MBInstallTemp602a30732f4f11f08efe92c31c8432e2\dotnetpkg.7z
MD5:
SHA256:
7240MBSetup.exeC:\Windows\SysWOW64\drivers\mbamtestfile.dattext
MD5:9F06243ABCB89C70E0C331C61D871FA7
SHA256:837CCB607E312B170FAC7383D7CCFD61FA5072793F19A25E75FBACB56539B86B
7240MBSetup.exeC:\Program Files (x86)\mbamtestfile.dattext
MD5:9F06243ABCB89C70E0C331C61D871FA7
SHA256:837CCB607E312B170FAC7383D7CCFD61FA5072793F19A25E75FBACB56539B86B
7788MBAMInstallerService.exeC:\Windows\Temp\MBInstallTemp602a30732f4f11f08efe92c31c8432e2\servicepkg.7zcompressed
MD5:37FD745A68FDA4A02F4A2C1AC3DF266A
SHA256:4FD0583A37B6905B50E0B5D13EACFB866849350922EEFAB627225E4BA8AF2F85
7788MBAMInstallerService.exeC:\Windows\Temp\MBInstallTemp602a30732f4f11f08efe92c31c8432e2\7z.dllexecutable
MD5:3430E2544637CEBF8BA1F509ED5A27B1
SHA256:BB01C6FBB29590D6D144A9038C2A7736D6925A6DBD31889538AF033E03E4F5FA
7788MBAMInstallerService.exeC:\Windows\Temp\MBInstallTemp602a30732f4f11f08efe92c31c8432e2\servicepkg\mbamelam.catbinary
MD5:BD4CEAE54AF081D6B1DD91FF584C5D61
SHA256:C3C4967B05CD00C31CAFC39B57000EC2E82CCF2CA295C72365F5CF6E5D191034
7240MBSetup.exeC:\Program Files\Malwarebytes\Anti-Malware\MBAMInstallerService.exeexecutable
MD5:CEA3222BD01165E983F7079C4DD88B11
SHA256:4D3204DD695B8A7E32A4E123B79D3470088CCAA3BDDAA187C2661445CA852344
7788MBAMInstallerService.exeC:\Windows\Temp\MBInstallTemp602a30732f4f11f08efe92c31c8432e2\servicepkg\mbamelam.infbinary
MD5:5D8C05CC4F9B4304D57EA10B87F2DCF0
SHA256:E26C2D3347E5F077DA92713C9DF3CD3EAE438FB7E29810BD5C3AFE567D2D3125
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
30
DNS requests
19
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
2.19.11.120:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
6544
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
40.127.240.158:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
2.19.11.120:80
crl.microsoft.com
Elisa Oyj
NL
whitelisted
2.23.246.101:80
www.microsoft.com
Ooredoo Q.S.C.
QA
whitelisted
2104
svchost.exe
40.127.240.158:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
4
System
192.168.100.255:138
whitelisted
2112
svchost.exe
40.127.240.158:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
7240
MBSetup.exe
54.200.40.13:443
api2.amplitude.com
AMAZON-02
US
whitelisted
3216
svchost.exe
172.211.123.248:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
6544
svchost.exe
20.190.159.130:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
crl.microsoft.com
  • 2.19.11.120
  • 2.19.11.111
whitelisted
www.microsoft.com
  • 2.23.246.101
  • 184.30.21.171
whitelisted
google.com
  • 142.250.185.174
whitelisted
api2.amplitude.com
  • 54.200.40.13
  • 35.161.220.29
  • 35.165.73.62
  • 44.231.7.217
  • 54.200.66.185
  • 54.245.224.95
  • 52.33.133.54
  • 54.187.71.8
whitelisted
client.wns.windows.com
  • 172.211.123.248
whitelisted
login.live.com
  • 20.190.159.130
  • 20.190.159.71
  • 20.190.159.129
  • 40.126.31.73
  • 20.190.159.64
  • 20.190.159.4
  • 20.190.159.23
  • 20.190.159.75
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
settings-win.data.microsoft.com
  • 51.124.78.146
whitelisted
ark.mwbsys.com
  • 52.204.45.27
  • 18.205.34.246
  • 34.235.51.28
whitelisted
cdn.mwbsys.com
  • 13.225.239.74
  • 13.225.239.118
  • 13.225.239.104
  • 13.225.239.85
whitelisted

Threats

No threats detected
No debug info