File name:

startup.exe

Full analysis: https://app.any.run/tasks/71781b58-9635-4c4c-bfe6-5ba70f005061
Verdict: Malicious activity
Analysis date: February 24, 2024, 15:23:19
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

4F67876EDB5D3F091C6A1B9E89F466F7

SHA1:

A84C066E757DEB867BC1B240C2A393E9AB2E7B9F

SHA256:

0E4E49CEB7333D79A87757B5727164D294719FA9A9C55E4DDA12603E7DEE1F90

SSDEEP:

98304:MQ7znSA1xYuq/a2MYzKLV5sWJ4AV/bPcDmjnIKAY3bQCes52H9tVpD8DX1grzIQY:oetTHgvctf

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • startup.exe (PID: 2160)
      • startup.exe (PID: 2208)
      • startup.exe (PID: 1864)
      • startup.exe (PID: 2336)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • startup.exe (PID: 2160)
      • startup.exe (PID: 2208)
      • startup.exe (PID: 1864)
    • Executable content was dropped or overwritten

      • startup.exe (PID: 2160)
      • startup.exe (PID: 2208)
      • startup.exe (PID: 1864)
      • startup.exe (PID: 2336)
    • Reads security settings of Internet Explorer

      • startup.exe (PID: 2160)
      • startup.exe (PID: 2208)
      • startup.exe (PID: 1864)
    • Reads the Internet Settings

      • startup.exe (PID: 2160)
      • startup.exe (PID: 2208)
      • startup.exe (PID: 1864)
    • Checks Windows Trust Settings

      • startup.exe (PID: 2160)
      • startup.exe (PID: 2208)
      • startup.exe (PID: 1864)
    • Reads settings of System Certificates

      • startup.exe (PID: 2160)
      • startup.exe (PID: 2208)
      • startup.exe (PID: 1864)
    • Application launched itself

      • startup.exe (PID: 2160)
      • startup.exe (PID: 2208)
    • Starts itself from another location

      • startup.exe (PID: 2336)
    • The process verifies whether the antivirus software is installed

      • startup.exe (PID: 1864)
    • Adds/modifies Windows certificates

      • startup.exe (PID: 1864)
  • INFO

    • Checks for the presence of KasperskyLab

      • startup.exe (PID: 2160)
      • startup.exe (PID: 2208)
      • startup.exe (PID: 1864)
    • Checks supported languages

      • startup.exe (PID: 2160)
      • startup.exe (PID: 2208)
      • startup.exe (PID: 2724)
      • startup.exe (PID: 1864)
      • startup.exe (PID: 2336)
    • Reads the computer name

      • startup.exe (PID: 2160)
      • startup.exe (PID: 2208)
      • startup.exe (PID: 1864)
      • startup.exe (PID: 2336)
    • Create files in a temporary directory

      • startup.exe (PID: 2160)
      • startup.exe (PID: 2208)
      • startup.exe (PID: 1864)
    • Process checks whether UAC notifications are on

      • startup.exe (PID: 2160)
      • startup.exe (PID: 2208)
      • startup.exe (PID: 1864)
    • Reads the machine GUID from the registry

      • startup.exe (PID: 2160)
      • startup.exe (PID: 2208)
      • startup.exe (PID: 1864)
    • Creates files in the program directory

      • startup.exe (PID: 2160)
      • startup.exe (PID: 2208)
      • startup.exe (PID: 1864)
    • Reads the software policy settings

      • startup.exe (PID: 2160)
      • startup.exe (PID: 2208)
      • startup.exe (PID: 1864)
    • Creates files or folders in the user directory

      • startup.exe (PID: 2160)
    • Checks proxy server information

      • startup.exe (PID: 2160)
      • startup.exe (PID: 2208)
      • startup.exe (PID: 1864)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (64.6)
.dll | Win32 Dynamic Link Library (generic) (15.4)
.exe | Win32 Executable (generic) (10.5)
.exe | Generic Win/DOS Executable (4.6)
.exe | DOS Executable Generic (4.6)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 1990:04:18 16:55:48+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14.29
CodeSize: 214016
InitializedDataSize: 3934208
UninitializedDataSize: -
EntryPoint: 0x25d0
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 21.13.5.506
ProductVersionNumber: 21.13.5.506
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Kaspersky
FileDescription: Kaspersky [21.13.5.506.0.26.0]
FileVersion: 21.13.5.506
LegalCopyright: © 2023 AO Kaspersky Lab
LegalTrademarks: Registered trademarks and service marks are the property of their respective owners
ProductName: Kaspersky
ProductVersion: 21.13.5.506
InternalName: Setup
OriginalFileName: Setup.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
46
Monitored processes
5
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
start startup.exe startup.exe startup.exe no specs startup.exe startup.exe

Process information

PID
CMD
Path
Indicators
Parent process
1864"C:\Windows\temp\51A847AC823DEE11EAA0219A68C677ED\startup.exe" /-elevated=;"C:\ProgramData\Kaspersky Lab Setup Files\KFA21.16.6.467.0.34.0\au_setup_B5EFBB26-D328-11EE-AE0A-12A9866C77DE\startup.exe"C:\Windows\Temp\51A847AC823DEE11EAA0219A68C677ED\startup.exe
startup.exe
User:
admin
Company:
Kaspersky
Integrity Level:
HIGH
Description:
Kaspersky [21.16.6.467.0.34.0]
Exit code:
0
Version:
21.16.6.467
Modules
Images
c:\windows\temp\51a847ac823dee11eaa0219a68c677ed\startup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\users\admin\appdata\local\temp\77b96aac823dee11eaa0219a68c677ed\setup.dll
c:\windows\system32\user32.dll
2160"C:\Users\admin\AppData\Local\Temp\startup.exe" C:\Users\admin\AppData\Local\Temp\startup.exe
explorer.exe
User:
admin
Company:
Kaspersky
Integrity Level:
MEDIUM
Description:
Kaspersky [21.13.5.506.0.26.0]
Exit code:
0
Version:
21.13.5.506
Modules
Images
c:\users\admin\appdata\local\temp\startup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\users\admin\appdata\local\temp\868a9dba823dee11eaa0219a68c677ed\setup.dll
c:\windows\system32\user32.dll
2208"C:\ProgramData\Kaspersky Lab Setup Files\KFA21.16.6.467.0.34.0\au_setup_B5EFBB26-D328-11EE-AE0A-12A9866C77DE\startup.exe" -auto_update_mode="C:\Users\admin\AppData\Local\Temp\startup.exe" /-self_remove -l=en -xpos=381 -ypos=101 -prevsetupver=21.13.5.506.0.26.0C:\ProgramData\Kaspersky Lab Setup Files\KFA21.16.6.467.0.34.0\au_setup_B5EFBB26-D328-11EE-AE0A-12A9866C77DE\startup.exe
startup.exe
User:
admin
Company:
Kaspersky
Integrity Level:
MEDIUM
Description:
Kaspersky [21.16.6.467.0.34.0]
Exit code:
0
Version:
21.16.6.467
Modules
Images
c:\programdata\kaspersky lab setup files\kfa21.16.6.467.0.34.0\au_setup_b5efbb26-d328-11ee-ae0a-12a9866c77de\startup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
2336"C:\ProgramData\Kaspersky Lab Setup Files\KFA21.16.6.467.0.34.0\au_setup_B5EFBB26-D328-11EE-AE0A-12A9866C77DE\startup.exe" /-elevated=;"C:\ProgramData\Kaspersky Lab Setup Files\KFA21.16.6.467.0.34.0\au_setup_B5EFBB26-D328-11EE-AE0A-12A9866C77DE\startup.exe"C:\ProgramData\Kaspersky Lab Setup Files\KFA21.16.6.467.0.34.0\au_setup_B5EFBB26-D328-11EE-AE0A-12A9866C77DE\startup.exe
startup.exe
User:
admin
Company:
Kaspersky
Integrity Level:
HIGH
Description:
Kaspersky [21.16.6.467.0.34.0]
Exit code:
0
Version:
21.16.6.467
Modules
Images
c:\programdata\kaspersky lab setup files\kfa21.16.6.467.0.34.0\au_setup_b5efbb26-d328-11ee-ae0a-12a9866c77de\startup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
2724"C:\Users\admin\AppData\Local\Temp\startup.exe" -cleanup="C:\Users\admin\AppData\Local\Temp\868A9DBA823DEE11EAA0219A68C677ED;2160"C:\Users\admin\AppData\Local\Temp\startup.exestartup.exe
User:
admin
Company:
Kaspersky
Integrity Level:
MEDIUM
Description:
Kaspersky [21.13.5.506.0.26.0]
Exit code:
0
Version:
21.13.5.506
Modules
Images
c:\users\admin\appdata\local\temp\startup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\msvcrt.dll
Total events
31 371
Read events
30 933
Write events
402
Delete events
36

Modification events

(PID) Process:(2160) startup.exeKey:HKEY_CURRENT_USER\Software\KasperskyLabSetup\Setup21.13.5.506.0.26.0\volatile
Operation:writeName:cp_storedResolvedType
Value:
-1
(PID) Process:(2160) startup.exeKey:HKEY_CURRENT_USER\Software\KasperskyLabSetup\Setup21.13.5.506.0.26.0\volatile
Operation:writeName:cp_storedResolvedProductTier
Value:
0
(PID) Process:(2160) startup.exeKey:HKEY_CURRENT_USER\Software\KasperskyLabSetup\Setup21.13.5.506.0.26.0\volatile
Operation:writeName:cp_storedResolvedStartupScenario
Value:
(PID) Process:(2160) startup.exeKey:HKEY_CURRENT_USER\Software\KasperskyLabSetup\Setup21.13.5.506.0.26.0\volatile
Operation:writeName:cp_storedResolvedType
Value:
4
(PID) Process:(2160) startup.exeKey:HKEY_CURRENT_USER\Software\KasperskyLabSetup\Setup21.13.5.506.0.26.0\volatile
Operation:writeName:cp_storedResolvedProductTier
Value:
230
(PID) Process:(2160) startup.exeKey:HKEY_CURRENT_USER\Software\KasperskyLabSetup\Setup21.13.5.506.0.26.0\volatile
Operation:writeName:cp_storedResolvedStartupScenario
Value:
Free
(PID) Process:(2160) startup.exeKey:HKEY_CURRENT_USER\Software\KasperskyLabSetup\Setup21.13.5.506.0.26.0\volatile
Operation:writeName:PreferredUI
Value:
0
(PID) Process:(2160) startup.exeKey:HKEY_CURRENT_USER\Software\KasperskyLabSetup\Setup21.13.5.506.0.26.0\volatile
Operation:writeName:PreferredUI
Value:
1
(PID) Process:(2160) startup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2160) startup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
Executable files
52
Suspicious files
35
Text files
132
Unknown types
8

Dropped files

PID
Process
Filename
Type
2160startup.exeC:\Users\admin\AppData\Local\Temp\ABD9A869-D328-11EE-AE0A-12A9866C77DE\GuiStrings_KFA.loctext
MD5:C9C0AD53C3306052E43635437E42957F
SHA256:592AE0DFC01DC6AFB25FB6DBB5201E86C71AAF1357CC84D2610BBBFD820612F1
2160startup.exeC:\Users\admin\AppData\Local\Temp\ABD9A869-D328-11EE-AE0A-12A9866C77DE\downloader_neutral.initext
MD5:BEBECE1F03CF6786F8907FDE1A33D430
SHA256:FADEC4AB98AD4455CB62BEC21D1AF1E039C9457B64F50272A7AE6C8A7E2D596F
2160startup.exeC:\Users\admin\AppData\Local\Temp\ABD9A869-D328-11EE-AE0A-12A9866C77DE\html\product.pngimage
MD5:DDE99DF5896D764DB2D26B5C4C485617
SHA256:EC8F4977DCE0076AA4A71385DDE57AE5C3F74A0427C8A6D020131FB33E173572
2160startup.exeC:\Users\admin\AppData\Local\Temp\ABD9A869-D328-11EE-AE0A-12A9866C77DE\GuiStrings.loctext
MD5:2812F2E0DE7BB161CD7EE46C0D6A68DC
SHA256:6E1F18B7DB3EF6CBEC961677AC60B6EE1E36EB4429DEB4727D1BAACFE0EF6466
2160startup.exeC:\Users\admin\AppData\Local\Temp\ABD9A869-D328-11EE-AE0A-12A9866C77DE\downloader_neutral_KFA.initext
MD5:2E10B2D4181D2F07D2DD305BD4285BD5
SHA256:CBB72CDC1E461226C7D0E49E7EF955F77DFEEF4F7FE12D0D8A8D0CF9658EDC78
2160startup.exeC:\Users\admin\AppData\Local\Temp\kl-setup-2024-02-24-15-23-34_KFA.21.13.5.506.logtext
MD5:2CA884D06C52973F7766CE20DB9C1437
SHA256:8053CEF34AB4B836A15E438E04E1C89EB7360F0815A5E52038B38501C0699E1B
2160startup.exeC:\Users\admin\AppData\Local\Temp\ABD9A869-D328-11EE-AE0A-12A9866C77DE\html\install_programm.pngimage
MD5:4C4FF2A5B22E51C9E362DE1F6DDBA31E
SHA256:41C6A3C5EB79E1B74E7E5D415DA6DB58C8E77382C7AD08CFFA34AFC6CE4CCD2A
2160startup.exeC:\Users\admin\AppData\Local\Temp\868A9DBA823DEE11EAA0219A68C677ED\sharpvectorconverterswpf.dllexecutable
MD5:1C8CD94BFA4C4728A098D3F0ABB32B01
SHA256:E36852AC836E9F8C458C93EB836011F140EB5B4DEBBB6DB5A95B3E63362CC5F8
2160startup.exeC:\Users\admin\AppData\Local\Temp\ABD9A869-D328-11EE-AE0A-12A9866C77DE\html\product.svgbinary
MD5:A41E5EFEED8C4C2D5F6CA9163BF044DE
SHA256:4A2260F0D29925BBCF1191D3327FF50F610A5958ECD41BC7DE15B3FBF9C759FC
2160startup.exeC:\Users\admin\AppData\Local\Temp\kl-setup-2024-02-24-15-23-34_KAV.21.13.5.506.logtext
MD5:2CA884D06C52973F7766CE20DB9C1437
SHA256:8053CEF34AB4B836A15E438E04E1C89EB7360F0815A5E52038B38501C0699E1B
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
3
TCP/UDP connections
43
DNS requests
8
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2160
startup.exe
GET
200
184.25.50.8:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?956c1609c0d25c3f
unknown
compressed
65.2 Kb
unknown
2160
startup.exe
GET
200
184.25.50.8:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?d4c03b16ab765dba
unknown
compressed
65.2 Kb
unknown
2160
startup.exe
GET
200
213.248.110.150:80
http://crl.kaspersky.com/aia/KasperskyLabPublicServicesRootCertificationAuthority.crt
unknown
binary
1.51 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
unknown
2160
startup.exe
213.248.110.148:443
dm.s.kaspersky-labs.com
Telia Company AB
FR
unknown
2160
startup.exe
82.202.184.193:443
ds.kaspersky.com
Kaspersky Lab Switzerland GmbH
CH
unknown
2160
startup.exe
213.248.110.150:80
crl.kaspersky.com
Telia Company AB
FR
unknown
2160
startup.exe
184.25.50.8:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown
2208
startup.exe
82.202.184.193:443
ds.kaspersky.com
Kaspersky Lab Switzerland GmbH
CH
unknown
2208
startup.exe
213.248.110.148:443
dm.s.kaspersky-labs.com
Telia Company AB
FR
unknown
1864
startup.exe
82.202.184.193:443
ds.kaspersky.com
Kaspersky Lab Switzerland GmbH
CH
unknown
1864
startup.exe
213.248.110.148:443
dm.s.kaspersky-labs.com
Telia Company AB
FR
unknown

DNS requests

Domain
IP
Reputation
ds.kaspersky.com
  • 82.202.184.193
unknown
dm.s.kaspersky-labs.com
  • 213.248.110.148
unknown
crl.kaspersky.com
  • 213.248.110.150
whitelisted
ctldl.windowsupdate.com
  • 184.25.50.8
whitelisted

Threats

No threats detected
Process
Message
startup.exe
startup.exe Information: 0 :
startup.exe
LocalizationEngine Trying to set LocalizationPropertiesManager.Culture to 'en'
startup.exe
startup.exe Information: 0 :
startup.exe
LocalizationEngine Buildloc 'en' => loc: en, region: , x:
startup.exe
startup.exe Information: 0 :
startup.exe
LocalizationEngine Neutral culture: en
startup.exe
startup.exe Information: 0 :
startup.exe
LocalizationEngine InstalledCultureName = en
startup.exe
startup.exe Information: 0 :
startup.exe
LocalizationEngine Culture = en CultureName = en FullCultureName = en