File name:

OfficeSetup.exe

Full analysis: https://app.any.run/tasks/735f6ae1-d4ce-42f6-a1d7-decaa9f7e5d6
Verdict: Malicious activity
Analysis date: October 19, 2024, 09:26:33
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

B017D9F052427181F4844217A450FD44

SHA1:

9435F657CB19CF215415AF1DD7EA549A8B60DB78

SHA256:

0A196A7584FA1D1F85BBE9753FDDA47BE22113FC0D6A055E2BB1771BF1B0F48E

SSDEEP:

98304:6VpkJ/P8TKmq1+N42G+71kXkz4RdL3IfcsWwoT9d9QrOGYREikFCjVoxwi1mPwl0:I02y

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Scans artifacts that could help determine the target

      • OfficeSetup.exe (PID: 5100)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • OfficeSetup.exe (PID: 5100)
      • OfficeClickToRun.exe (PID: 1744)
      • OfficeClickToRun.exe (PID: 7720)
    • Starts a Microsoft application from unusual location

      • OfficeSetup.exe (PID: 5100)
      • OfficeSetup.exe (PID: 4584)
    • Reads security settings of Internet Explorer

      • OfficeSetup.exe (PID: 5100)
      • OfficeSetup.exe (PID: 4584)
    • Application launched itself

      • OfficeSetup.exe (PID: 5100)
    • Checks Windows Trust Settings

      • OfficeSetup.exe (PID: 5100)
      • OfficeSetup.exe (PID: 4584)
    • Executable content was dropped or overwritten

      • OfficeClickToRun.exe (PID: 1744)
      • OfficeClickToRun.exe (PID: 7720)
    • Searches for installed software

      • OfficeSetup.exe (PID: 4584)
    • The process drops C-runtime libraries

      • OfficeClickToRun.exe (PID: 1744)
  • INFO

    • Checks supported languages

      • OfficeSetup.exe (PID: 5100)
      • OfficeSetup.exe (PID: 4584)
      • OfficeClickToRun.exe (PID: 1744)
    • Process checks whether UAC notifications are on

      • OfficeSetup.exe (PID: 5100)
    • Reads the machine GUID from the registry

      • OfficeSetup.exe (PID: 5100)
      • OfficeSetup.exe (PID: 4584)
    • Checks proxy server information

      • OfficeSetup.exe (PID: 5100)
      • OfficeSetup.exe (PID: 4584)
      • OfficeClickToRun.exe (PID: 1744)
    • Reads the computer name

      • OfficeSetup.exe (PID: 5100)
      • OfficeClickToRun.exe (PID: 1744)
    • Reads Microsoft Office registry keys

      • OfficeSetup.exe (PID: 5100)
      • OfficeSetup.exe (PID: 4584)
      • OfficeClickToRun.exe (PID: 1744)
    • Process checks computer location settings

      • OfficeSetup.exe (PID: 5100)
      • OfficeSetup.exe (PID: 4584)
    • Reads Environment values

      • OfficeSetup.exe (PID: 5100)
    • Reads the software policy settings

      • OfficeSetup.exe (PID: 5100)
      • OfficeSetup.exe (PID: 4584)
    • The process uses the downloaded file

      • OfficeSetup.exe (PID: 4584)
    • Creates files or folders in the user directory

      • OfficeSetup.exe (PID: 4584)
    • Create files in a temporary directory

      • OfficeSetup.exe (PID: 4584)
    • Executes as Windows Service

      • OfficeClickToRun.exe (PID: 7720)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable (generic) (52.9)
.exe | Generic Win/DOS Executable (23.5)
.exe | DOS Executable Generic (23.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:09:24 19:36:57+00:00
ImageFileCharacteristics: Executable, 32-bit, Removable run from swap, Net run from swap
PEType: PE32
LinkerVersion: 14.38
CodeSize: 4568576
InitializedDataSize: 2994176
UninitializedDataSize: -
EntryPoint: 0x3e2b85
OSVersion: 5.2
ImageVersion: -
SubsystemVersion: 5.2
Subsystem: Windows GUI
FileVersionNumber: 16.0.18025.20104
ProductVersionNumber: 16.0.18025.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Windows, Latin1
CompanyName: Microsoft Corporation
FileDescription: Microsoft 365 and Office
FileVersion: 16.0.18025.20104
InternalName: Bootstrapper.exe
LegalTrademarks1: Microsoft® is a registered trademark of Microsoft Corporation.
LegalTrademarks2: Windows® is a registered trademark of Microsoft Corporation.
OriginalFileName: Bootstrapper.exe
ProductName: Microsoft Office
ProductVersion: 16.0.18025.20104
No data.
screenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
135
Monitored processes
6
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start officesetup.exe officesetup.exe officeclicktorun.exe Delivery Optimization User no specs officeclicktorun.exe officeclicktorun.exe

Process information

PID
CMD
Path
Indicators
Parent process
1744OfficeClickToRun.exe platform=x64 culture=en-us productstoadd=ProPlus2024Retail.16_en-us_x-none cdnbaseurl=http://officecdn.microsoft.com/pr/492350f6-3a01-4f97-b9c0-c7c6ddf67d60 baseurl=http://officecdn.microsoft.com/pr/492350f6-3a01-4f97-b9c0-c7c6ddf67d60 version=16.0.18025.20160 mediatype=CDN sourcetype=CDN ProPlus2024Retail.excludedapps=groove updatesenabled=False bitnessmigration=False deliverymechanism=492350f6-3a01-4f97-b9c0-c7c6ddf67d60 flt.useoutlookshareaddon=unknown flt.useofficehelperaddon=unknown flt.UseTeamsOnInstallConsumer=unknown flt.UseTeamsOnUpdateConsumer=unknown uninstallcentennial=True scenario=CLIENTUPDATEC:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
OfficeSetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Office Click-to-Run (SxS)
Exit code:
0
Version:
16.0.16026.20140
Modules
Images
c:\program files\common files\microsoft shared\clicktorun\officeclicktorun.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
4584"C:\Users\admin\AppData\Local\Temp\OfficeSetup.exe" ELEVATED sid=S-1-5-21-1693682860-607145093-2874071422-1001 C:\Users\admin\AppData\Local\Temp\OfficeSetup.exe
OfficeSetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft 365 and Office
Version:
16.0.18025.20104
Modules
Images
c:\windows\syswow64\slc.dll
c:\windows\syswow64\sppc.dll
c:\windows\syswow64\sxs.dll
c:\windows\syswow64\cryptnet.dll
c:\windows\syswow64\gpapi.dll
c:\windows\syswow64\cabinet.dll
c:\windows\syswow64\devrtl.dll
c:\windows\syswow64\msxml6.dll
c:\program files\microsoft office\root\vfs\programfilescommonx86\microsoft shared\office16\msoxmlmf.dll
c:\program files\microsoft office\root\vfs\programfilescommonx86\microsoft shared\office16\vcruntime140.dll
5100"C:\Users\admin\AppData\Local\Temp\OfficeSetup.exe" C:\Users\admin\AppData\Local\Temp\OfficeSetup.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft 365 and Office
Version:
16.0.18025.20104
Modules
Images
c:\users\admin\appdata\local\temp\officesetup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
7192C:\WINDOWS\system32\DllHost.exe /Processid:{338B40F9-9D68-4B53-A793-6B9AA0C5F63B}C:\Windows\System32\dllhost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
COM Surrogate
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\dllhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
7720"C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe" /serviceC:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Office Click-to-Run (SxS)
Version:
16.0.18025.20160
Modules
Images
c:\program files\common files\microsoft shared\clicktorun\officeclicktorun.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\gdi32.dll
7892OfficeClickToRun.exe platform=x64 culture=en-us productstoadd=ProPlus2024Retail.16_en-us_x-none cdnbaseurl.16=http://officecdn.microsoft.com/pr/492350f6-3a01-4f97-b9c0-c7c6ddf67d60 baseurl.16=http://officecdn.microsoft.com/pr/492350f6-3a01-4f97-b9c0-c7c6ddf67d60 version.16=16.0.18025.20160 mediatype.16=CDN sourcetype.16=CDN ProPlus2024Retail.excludedapps.16=groove updatesenabled.16=False bitnessmigration=False deliverymechanism=492350f6-3a01-4f97-b9c0-c7c6ddf67d60 flt.useoutlookshareaddon=unknown flt.useofficehelperaddon=unknown flt.UseTeamsOnInstallConsumer=unknown flt.UseTeamsOnUpdateConsumer=unknown uninstallcentennial=TrueC:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
OfficeSetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Office Click-to-Run (SxS)
Version:
16.0.18025.20160
Modules
Images
c:\program files\common files\microsoft shared\clicktorun\officeclicktorun.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
Total events
11 932
Read events
11 640
Write events
98
Delete events
194

Modification events

(PID) Process:(5100) OfficeSetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages
Operation:writeName:en-US
Value:
2
(PID) Process:(5100) OfficeSetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages
Operation:writeName:de-de
Value:
2
(PID) Process:(5100) OfficeSetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages
Operation:writeName:fr-fr
Value:
2
(PID) Process:(5100) OfficeSetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages
Operation:writeName:es-es
Value:
2
(PID) Process:(5100) OfficeSetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages
Operation:writeName:it-it
Value:
2
(PID) Process:(5100) OfficeSetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages
Operation:writeName:ja-jp
Value:
2
(PID) Process:(5100) OfficeSetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages
Operation:writeName:ko-kr
Value:
2
(PID) Process:(5100) OfficeSetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages
Operation:writeName:pt-br
Value:
2
(PID) Process:(5100) OfficeSetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages
Operation:writeName:ru-ru
Value:
2
(PID) Process:(5100) OfficeSetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages
Operation:writeName:tr-tr
Value:
2
Executable files
391
Suspicious files
18
Text files
43
Unknown types
1

Dropped files

PID
Process
Filename
Type
5100OfficeSetup.exeC:\Users\admin\AppData\Local\Microsoft\Office\OTele\officesetup.exe.db-shmbinary
MD5:FFB4D5C375F1D73989FED2398E0681B0
SHA256:F334DB3C8B2B4DFFCB09FA654D8807C1C89965E85654E228C255575C6DF91EDB
5100OfficeSetup.exeC:\Users\admin\AppData\Local\Microsoft\Office\OTele\officesetup.exe.db-walbinary
MD5:40E5D4497DA19D5923C948164AAFCF09
SHA256:EFE690B5BFF6461C6118ECD875144DE78CF84AB1692C8371381F7B51B11B4EA4
1744OfficeClickToRun.exeC:\Users\admin\AppData\Local\Temp\DESKTOP-JGLLJLD-20241019-0926a.logtext
MD5:2A1CCFAA7025E68FB85B9C3B710DEEC3
SHA256:433A2C0438AE033345FDDF7BED3CEE61843FA29A94D0B221407FC8907C89CA61
4584OfficeSetup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\A583E2A51BFBDC1E492A57B7C8325850binary
MD5:34EC7549D4023DBD7BC9B70A0D218328
SHA256:92C14E0D536136621B8592C48E2B0F7F347D51532E8E103052E89ABB943EB174
1744OfficeClickToRun.exeC:\Program Files\Common Files\microsoft shared\ClickToRun\Updates\EC02A501-36DA-445B-8F1B-A6E259C0C0C5OfficeC2R5E36E588-89BB-4514-9ADD-2434E6AF8B51\api-ms-win-core-localization-l1-2-0.dllexecutable
MD5:6B4F2CA3EFCEB2C21E93F92CDC150A9D
SHA256:B39A515B9E48FC6589703D45E14DCEA2273A02D7FA6F2E1D17985C0228D32564
4584OfficeSetup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\0B8A20E1F3F4D73D52A19929F922C892binary
MD5:8C07E9A695A1CD2C1DD31191AE4CD3F9
SHA256:741E17A41A942D4E0D2A1E8F30CC2CDBC63CCCD56910E5E55F45E049F6323F11
4584OfficeSetup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\36AC0BE60E1243344AE145F746D881FEbinary
MD5:84C5DD34FE954FD2C05155E413CBB8E3
SHA256:EAB4E57DAA611377F76D4A124F909AE9357C5237AC134576AB61712B33363F46
4584OfficeSetup.exeC:\Users\admin\AppData\Local\Temp\OfficeC2R50EF49E8-FDC5-4AB7-A9EF-5DA29172263EOfficeC2R1783985F-6BAF-4C3E-8E12-4C991CFBD855\v64.hashtext
MD5:C955AD47B7DE7F030929203CE9C40382
SHA256:D5E07C364D95B8CEF805A0E9A50626BAF6E8B1A01011AFEC563AA975E599DB5D
4584OfficeSetup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\0B8A20E1F3F4D73D52A19929F922C892binary
MD5:7B2D889AFA8558D921D5D96BBFFFF361
SHA256:05023211964BF3AB5D2FA17D05E0B0EA36978DE2D1B6CC194DDF32437D40871C
4584OfficeSetup.exeC:\Users\admin\AppData\Local\Temp\OfficeC2R50EF49E8-FDC5-4AB7-A9EF-5DA29172263EOfficeC2R1783985F-6BAF-4C3E-8E12-4C991CFBD855\VersionDescriptor.xmlxml
MD5:679BA08432795EA2EDA62B45291EE54E
SHA256:124E463926BBB23DC9D97B62C81279FD26AC86A7B41B0274B9392B432940B6BB
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
56
TCP/UDP connections
76
DNS requests
35
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5488
MoUsoCoreWorker.exe
GET
200
23.48.23.143:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
HEAD
200
23.48.23.67:80
http://f.c2r.ts.cdn.office.net/pr/492350f6-3a01-4f97-b9c0-c7c6ddf67d60/Office/Data/v64_16.0.16026.20146.cab
unknown
whitelisted
5488
MoUsoCoreWorker.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
4360
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
HEAD
200
23.48.23.67:80
http://f.c2r.ts.cdn.office.net/pr/492350f6-3a01-4f97-b9c0-c7c6ddf67d60/Office/Data/v64_16.0.18025.20160.cab
unknown
whitelisted
5100
OfficeSetup.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
1732
svchost.exe
HEAD
200
23.48.23.67:80
http://f.c2r.ts.cdn.office.net/pr/492350f6-3a01-4f97-b9c0-c7c6ddf67d60/Office/Data/v64_16.0.18025.20160.cab
unknown
whitelisted
HEAD
200
23.48.23.67:80
http://f.c2r.ts.cdn.office.net/pr/492350f6-3a01-4f97-b9c0-c7c6ddf67d60/Office/Data/v64_16.0.18025.20160.cab
unknown
whitelisted
1732
svchost.exe
GET
206
23.48.23.67:80
http://f.c2r.ts.cdn.office.net/pr/492350f6-3a01-4f97-b9c0-c7c6ddf67d60/Office/Data/v64_16.0.18025.20160.cab
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
6944
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5488
MoUsoCoreWorker.exe
23.48.23.143:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
5488
MoUsoCoreWorker.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
4020
svchost.exe
239.255.255.250:1900
whitelisted
52.109.32.97:443
officeclient.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
GB
whitelisted
4
System
192.168.100.255:138
whitelisted
52.113.194.132:443
ecs.office.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
whitelisted
crl.microsoft.com
  • 23.48.23.143
  • 23.48.23.156
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
google.com
  • 142.250.186.142
whitelisted
officeclient.microsoft.com
  • 52.109.32.97
whitelisted
ecs.office.com
  • 52.113.194.132
whitelisted
mrodevicemgr.officeapps.live.com
  • 52.109.77.37
whitelisted
f.c2r.ts.cdn.office.net
  • 23.48.23.67
  • 23.48.23.62
  • 23.48.23.37
whitelisted
mobile.events.data.microsoft.com
  • 40.79.189.58
  • 20.44.10.123
  • 13.69.116.109
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted

Threats

No threats detected
No debug info