| File name: | startup.exe |
| Full analysis: | https://app.any.run/tasks/71781b58-9635-4c4c-bfe6-5ba70f005061 |
| Verdict: | Malicious activity |
| Analysis date: | February 24, 2024, 15:23:19 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 4F67876EDB5D3F091C6A1B9E89F466F7 |
| SHA1: | A84C066E757DEB867BC1B240C2A393E9AB2E7B9F |
| SHA256: | 0E4E49CEB7333D79A87757B5727164D294719FA9A9C55E4DDA12603E7DEE1F90 |
| SSDEEP: | 98304:MQ7znSA1xYuq/a2MYzKLV5sWJ4AV/bPcDmjnIKAY3bQCes52H9tVpD8DX1grzIQY:oetTHgvctf |
| .exe | | | Win64 Executable (generic) (64.6) |
|---|---|---|
| .dll | | | Win32 Dynamic Link Library (generic) (15.4) |
| .exe | | | Win32 Executable (generic) (10.5) |
| .exe | | | Generic Win/DOS Executable (4.6) |
| .exe | | | DOS Executable Generic (4.6) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 1990:04:18 16:55:48+00:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 14.29 |
| CodeSize: | 214016 |
| InitializedDataSize: | 3934208 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x25d0 |
| OSVersion: | 6 |
| ImageVersion: | - |
| SubsystemVersion: | 6 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 21.13.5.506 |
| ProductVersionNumber: | 21.13.5.506 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Windows NT 32-bit |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| CompanyName: | Kaspersky |
| FileDescription: | Kaspersky [21.13.5.506.0.26.0] |
| FileVersion: | 21.13.5.506 |
| LegalCopyright: | © 2023 AO Kaspersky Lab |
| LegalTrademarks: | Registered trademarks and service marks are the property of their respective owners |
| ProductName: | Kaspersky |
| ProductVersion: | 21.13.5.506 |
| InternalName: | Setup |
| OriginalFileName: | Setup.exe |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1864 | "C:\Windows\temp\51A847AC823DEE11EAA0219A68C677ED\startup.exe" /-elevated=;"C:\ProgramData\Kaspersky Lab Setup Files\KFA21.16.6.467.0.34.0\au_setup_B5EFBB26-D328-11EE-AE0A-12A9866C77DE\startup.exe" | C:\Windows\Temp\51A847AC823DEE11EAA0219A68C677ED\startup.exe | startup.exe | ||||||||||||
User: admin Company: Kaspersky Integrity Level: HIGH Description: Kaspersky [21.16.6.467.0.34.0] Exit code: 0 Version: 21.16.6.467 Modules
| |||||||||||||||
| 2160 | "C:\Users\admin\AppData\Local\Temp\startup.exe" | C:\Users\admin\AppData\Local\Temp\startup.exe | explorer.exe | ||||||||||||
User: admin Company: Kaspersky Integrity Level: MEDIUM Description: Kaspersky [21.13.5.506.0.26.0] Exit code: 0 Version: 21.13.5.506 Modules
| |||||||||||||||
| 2208 | "C:\ProgramData\Kaspersky Lab Setup Files\KFA21.16.6.467.0.34.0\au_setup_B5EFBB26-D328-11EE-AE0A-12A9866C77DE\startup.exe" -auto_update_mode="C:\Users\admin\AppData\Local\Temp\startup.exe" /-self_remove -l=en -xpos=381 -ypos=101 -prevsetupver=21.13.5.506.0.26.0 | C:\ProgramData\Kaspersky Lab Setup Files\KFA21.16.6.467.0.34.0\au_setup_B5EFBB26-D328-11EE-AE0A-12A9866C77DE\startup.exe | startup.exe | ||||||||||||
User: admin Company: Kaspersky Integrity Level: MEDIUM Description: Kaspersky [21.16.6.467.0.34.0] Exit code: 0 Version: 21.16.6.467 Modules
| |||||||||||||||
| 2336 | "C:\ProgramData\Kaspersky Lab Setup Files\KFA21.16.6.467.0.34.0\au_setup_B5EFBB26-D328-11EE-AE0A-12A9866C77DE\startup.exe" /-elevated=;"C:\ProgramData\Kaspersky Lab Setup Files\KFA21.16.6.467.0.34.0\au_setup_B5EFBB26-D328-11EE-AE0A-12A9866C77DE\startup.exe" | C:\ProgramData\Kaspersky Lab Setup Files\KFA21.16.6.467.0.34.0\au_setup_B5EFBB26-D328-11EE-AE0A-12A9866C77DE\startup.exe | startup.exe | ||||||||||||
User: admin Company: Kaspersky Integrity Level: HIGH Description: Kaspersky [21.16.6.467.0.34.0] Exit code: 0 Version: 21.16.6.467 Modules
| |||||||||||||||
| 2724 | "C:\Users\admin\AppData\Local\Temp\startup.exe" -cleanup="C:\Users\admin\AppData\Local\Temp\868A9DBA823DEE11EAA0219A68C677ED;2160" | C:\Users\admin\AppData\Local\Temp\startup.exe | — | startup.exe | |||||||||||
User: admin Company: Kaspersky Integrity Level: MEDIUM Description: Kaspersky [21.13.5.506.0.26.0] Exit code: 0 Version: 21.13.5.506 Modules
| |||||||||||||||
| (PID) Process: | (2160) startup.exe | Key: | HKEY_CURRENT_USER\Software\KasperskyLabSetup\Setup21.13.5.506.0.26.0\volatile |
| Operation: | write | Name: | cp_storedResolvedType |
Value: -1 | |||
| (PID) Process: | (2160) startup.exe | Key: | HKEY_CURRENT_USER\Software\KasperskyLabSetup\Setup21.13.5.506.0.26.0\volatile |
| Operation: | write | Name: | cp_storedResolvedProductTier |
Value: 0 | |||
| (PID) Process: | (2160) startup.exe | Key: | HKEY_CURRENT_USER\Software\KasperskyLabSetup\Setup21.13.5.506.0.26.0\volatile |
| Operation: | write | Name: | cp_storedResolvedStartupScenario |
Value: | |||
| (PID) Process: | (2160) startup.exe | Key: | HKEY_CURRENT_USER\Software\KasperskyLabSetup\Setup21.13.5.506.0.26.0\volatile |
| Operation: | write | Name: | cp_storedResolvedType |
Value: 4 | |||
| (PID) Process: | (2160) startup.exe | Key: | HKEY_CURRENT_USER\Software\KasperskyLabSetup\Setup21.13.5.506.0.26.0\volatile |
| Operation: | write | Name: | cp_storedResolvedProductTier |
Value: 230 | |||
| (PID) Process: | (2160) startup.exe | Key: | HKEY_CURRENT_USER\Software\KasperskyLabSetup\Setup21.13.5.506.0.26.0\volatile |
| Operation: | write | Name: | cp_storedResolvedStartupScenario |
Value: Free | |||
| (PID) Process: | (2160) startup.exe | Key: | HKEY_CURRENT_USER\Software\KasperskyLabSetup\Setup21.13.5.506.0.26.0\volatile |
| Operation: | write | Name: | PreferredUI |
Value: 0 | |||
| (PID) Process: | (2160) startup.exe | Key: | HKEY_CURRENT_USER\Software\KasperskyLabSetup\Setup21.13.5.506.0.26.0\volatile |
| Operation: | write | Name: | PreferredUI |
Value: 1 | |||
| (PID) Process: | (2160) startup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (2160) startup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2160 | startup.exe | C:\Users\admin\AppData\Local\Temp\ABD9A869-D328-11EE-AE0A-12A9866C77DE\GuiStrings_KFA.loc | text | |
MD5:C9C0AD53C3306052E43635437E42957F | SHA256:592AE0DFC01DC6AFB25FB6DBB5201E86C71AAF1357CC84D2610BBBFD820612F1 | |||
| 2160 | startup.exe | C:\Users\admin\AppData\Local\Temp\ABD9A869-D328-11EE-AE0A-12A9866C77DE\downloader_neutral.ini | text | |
MD5:BEBECE1F03CF6786F8907FDE1A33D430 | SHA256:FADEC4AB98AD4455CB62BEC21D1AF1E039C9457B64F50272A7AE6C8A7E2D596F | |||
| 2160 | startup.exe | C:\Users\admin\AppData\Local\Temp\ABD9A869-D328-11EE-AE0A-12A9866C77DE\html\product.png | image | |
MD5:DDE99DF5896D764DB2D26B5C4C485617 | SHA256:EC8F4977DCE0076AA4A71385DDE57AE5C3F74A0427C8A6D020131FB33E173572 | |||
| 2160 | startup.exe | C:\Users\admin\AppData\Local\Temp\ABD9A869-D328-11EE-AE0A-12A9866C77DE\GuiStrings.loc | text | |
MD5:2812F2E0DE7BB161CD7EE46C0D6A68DC | SHA256:6E1F18B7DB3EF6CBEC961677AC60B6EE1E36EB4429DEB4727D1BAACFE0EF6466 | |||
| 2160 | startup.exe | C:\Users\admin\AppData\Local\Temp\ABD9A869-D328-11EE-AE0A-12A9866C77DE\downloader_neutral_KFA.ini | text | |
MD5:2E10B2D4181D2F07D2DD305BD4285BD5 | SHA256:CBB72CDC1E461226C7D0E49E7EF955F77DFEEF4F7FE12D0D8A8D0CF9658EDC78 | |||
| 2160 | startup.exe | C:\Users\admin\AppData\Local\Temp\kl-setup-2024-02-24-15-23-34_KFA.21.13.5.506.log | text | |
MD5:2CA884D06C52973F7766CE20DB9C1437 | SHA256:8053CEF34AB4B836A15E438E04E1C89EB7360F0815A5E52038B38501C0699E1B | |||
| 2160 | startup.exe | C:\Users\admin\AppData\Local\Temp\ABD9A869-D328-11EE-AE0A-12A9866C77DE\html\install_programm.png | image | |
MD5:4C4FF2A5B22E51C9E362DE1F6DDBA31E | SHA256:41C6A3C5EB79E1B74E7E5D415DA6DB58C8E77382C7AD08CFFA34AFC6CE4CCD2A | |||
| 2160 | startup.exe | C:\Users\admin\AppData\Local\Temp\868A9DBA823DEE11EAA0219A68C677ED\sharpvectorconverterswpf.dll | executable | |
MD5:1C8CD94BFA4C4728A098D3F0ABB32B01 | SHA256:E36852AC836E9F8C458C93EB836011F140EB5B4DEBBB6DB5A95B3E63362CC5F8 | |||
| 2160 | startup.exe | C:\Users\admin\AppData\Local\Temp\ABD9A869-D328-11EE-AE0A-12A9866C77DE\html\product.svg | binary | |
MD5:A41E5EFEED8C4C2D5F6CA9163BF044DE | SHA256:4A2260F0D29925BBCF1191D3327FF50F610A5958ECD41BC7DE15B3FBF9C759FC | |||
| 2160 | startup.exe | C:\Users\admin\AppData\Local\Temp\kl-setup-2024-02-24-15-23-34_KAV.21.13.5.506.log | text | |
MD5:2CA884D06C52973F7766CE20DB9C1437 | SHA256:8053CEF34AB4B836A15E438E04E1C89EB7360F0815A5E52038B38501C0699E1B | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2160 | startup.exe | GET | 200 | 184.25.50.8:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?956c1609c0d25c3f | unknown | compressed | 65.2 Kb | unknown |
2160 | startup.exe | GET | 200 | 184.25.50.8:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?d4c03b16ab765dba | unknown | compressed | 65.2 Kb | unknown |
2160 | startup.exe | GET | 200 | 213.248.110.150:80 | http://crl.kaspersky.com/aia/KasperskyLabPublicServicesRootCertificationAuthority.crt | unknown | binary | 1.51 Kb | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | unknown |
2160 | startup.exe | 213.248.110.148:443 | dm.s.kaspersky-labs.com | Telia Company AB | FR | unknown |
2160 | startup.exe | 82.202.184.193:443 | ds.kaspersky.com | Kaspersky Lab Switzerland GmbH | CH | unknown |
2160 | startup.exe | 213.248.110.150:80 | crl.kaspersky.com | Telia Company AB | FR | unknown |
2160 | startup.exe | 184.25.50.8:80 | ctldl.windowsupdate.com | Akamai International B.V. | DE | unknown |
2208 | startup.exe | 82.202.184.193:443 | ds.kaspersky.com | Kaspersky Lab Switzerland GmbH | CH | unknown |
2208 | startup.exe | 213.248.110.148:443 | dm.s.kaspersky-labs.com | Telia Company AB | FR | unknown |
1864 | startup.exe | 82.202.184.193:443 | ds.kaspersky.com | Kaspersky Lab Switzerland GmbH | CH | unknown |
1864 | startup.exe | 213.248.110.148:443 | dm.s.kaspersky-labs.com | Telia Company AB | FR | unknown |
Domain | IP | Reputation |
|---|---|---|
ds.kaspersky.com |
| unknown |
dm.s.kaspersky-labs.com |
| unknown |
crl.kaspersky.com |
| whitelisted |
ctldl.windowsupdate.com |
| whitelisted |
Process | Message |
|---|---|
startup.exe | startup.exe Information: 0 : |
startup.exe | LocalizationEngine Trying to set LocalizationPropertiesManager.Culture to 'en'
|
startup.exe | startup.exe Information: 0 : |
startup.exe | LocalizationEngine Buildloc 'en' => loc: en, region: , x:
|
startup.exe | startup.exe Information: 0 : |
startup.exe | LocalizationEngine Neutral culture: en
|
startup.exe | startup.exe Information: 0 : |
startup.exe | LocalizationEngine InstalledCultureName = en
|
startup.exe | startup.exe Information: 0 : |
startup.exe | LocalizationEngine Culture = en
CultureName = en
FullCultureName = en
|