| File name: | anytoiso_setup.exe |
| Full analysis: | https://app.any.run/tasks/1a506788-57c0-4bff-9cc6-55523c7fea02 |
| Verdict: | Malicious activity |
| Analysis date: | February 18, 2024, 12:58:46 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 490128AD8C2FE36A4B3430860E61FE30 |
| SHA1: | 14BD1AA15559AC295D37BA47AA4D612E256FE85B |
| SHA256: | 10C72764F6D4D5B571A45CF42034CBB6EAF7C2921BEC1F8B52C3540D596C3987 |
| SSDEEP: | 98304:5yUY9byZ6CCmn8QxKM8QXtiHZO35EHmlxS+HADCWqWg0TUSftPAGlXIPceW74T/L:5kHmTSf1xd/0MBrD+laJcZ |
| .exe | | | Win64 Executable (generic) (76.4) |
|---|---|---|
| .exe | | | Win32 Executable (generic) (12.4) |
| .exe | | | Generic Win/DOS Executable (5.5) |
| .exe | | | DOS Executable Generic (5.5) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2021:04:23 07:52:46+00:00 |
| ImageFileCharacteristics: | Executable, Large address aware, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 14.28 |
| CodeSize: | 1559040 |
| InitializedDataSize: | 648704 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x1260c8 |
| OSVersion: | 6 |
| ImageVersion: | - |
| SubsystemVersion: | 6 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.0.0.0 |
| ProductVersionNumber: | 1.0.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | Debug |
| FileOS: | Win32 |
| ObjectFileType: | Dynamic link library |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| CompanyName: | anytoiso_setup |
| FileDescription: | anytoiso_setup Installer |
| FileVersion: | 1.0.0 |
| InternalName: | anytoiso_setup |
| LegalCopyright: | Copyright (C) 2023 anytoiso_setup |
| OriginalFileName: | anytoiso_setup.exe |
| ProductName: | anytoiso_setup |
| ProductVersion: | 1.0.0 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1484 | "C:\Windows\system32\regsvr32.exe" /s "C:\Program Files\AnyToISO\anyshellext_x86.dll" | C:\Windows\System32\regsvr32.exe | — | anytoiso_setup.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft(C) Register Server Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2804 | "C:\Users\admin\AppData\Local\Temp\is-I7AIQ.tmp\anytoiso_setup.tmp" /SL5="$F0170,10319616,857088,C:\Program Files\anytoiso_setup\anytoiso_setup\anytoiso_setup.exe" | C:\Users\admin\AppData\Local\Temp\is-I7AIQ.tmp\anytoiso_setup.tmp | — | anytoiso_setup.exe | |||||||||||
User: admin Company: CrystalIDEA Software Integrity Level: MEDIUM Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 Modules
| |||||||||||||||
| 2840 | "C:\Windows\system32\msiexec.exe" /i "C:\Users\admin\AppData\Roaming\anytoiso_setup\anytoiso_setup 1.0.0\install\C9ABEC1\anytoiso_setup.msi" AI_SETUPEXEPATH=C:\Users\admin\AppData\Local\Temp\anytoiso_setup.exe SETUPEXEDIR=C:\Users\admin\AppData\Local\Temp\ EXE_CMD_LINE="/exenoupdates /forcecleanup /wintime 1708259568 " | C:\Windows\System32\msiexec.exe | — | anytoiso_setup.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2904 | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -ENC UwB0AGEAcgB0AC0AUwBsAGUAZQBwACAALQBzACAAMQAwADsAIABSAGUAbQBvAHYAZQAtAEkAdABlAG0AIAAtAFAAYQB0AGgAIAAiAEMAOgBcAFUAcwBlAHIAcwBcAGEAZABtAGkAbgBcAEEAcABwAEQAYQB0AGEAXABMAG8AYwBhAGwAXABXAGkAbgBkAG8AdwBzAEEAYwB0AGkAdgBlAFMAZQByAHYAaQBjAGUAcwBcAFAAYQB0AGMAaAAuAGUAeABlACIAIAAtAEYAbwByAGMAZQA= | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | — | Patch.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Exit code: 0 Version: 10.0.14409.1005 (rs1_srvoob.161208-1155) Modules
| |||||||||||||||
| 3224 | "C:\Users\admin\AppData\Local\Temp\is-18P2J.tmp\anytoiso_setup.tmp" /SL5="$1E01BC,10319616,857088,C:\Program Files\anytoiso_setup\anytoiso_setup\anytoiso_setup.exe" /SPAWNWND=$170158 /NOTIFYWND=$F0170 | C:\Users\admin\AppData\Local\Temp\is-18P2J.tmp\anytoiso_setup.tmp | anytoiso_setup.exe | ||||||||||||
User: admin Company: CrystalIDEA Software Integrity Level: HIGH Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 Modules
| |||||||||||||||
| 3444 | "C:\Users\admin\AppData\Local\Temp\is-BQF6I.tmp\unzip.exe" -o "C:\Users\admin\AppData\Local\Temp\is-BQF6I.tmp\qt_redist_x86.zip" -d "C:\Program Files\AnyToISO" | C:\Users\admin\AppData\Local\Temp\is-BQF6I.tmp\unzip.exe | anytoiso_setup.tmp | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 3800 | "C:\Program Files\anytoiso_setup\anytoiso_setup\anytoiso_setup.exe" /SPAWNWND=$170158 /NOTIFYWND=$F0170 | C:\Program Files\anytoiso_setup\anytoiso_setup\anytoiso_setup.exe | anytoiso_setup.tmp | ||||||||||||
User: admin Company: CrystalIDEA Software Integrity Level: HIGH Description: AnyToISO Setup Exit code: 0 Version: AnyToISO Modules
| |||||||||||||||
| 3916 | "C:\Users\admin\AppData\Local\Temp\anytoiso_setup.exe" | C:\Users\admin\AppData\Local\Temp\anytoiso_setup.exe | explorer.exe | ||||||||||||
User: admin Company: anytoiso_setup Integrity Level: MEDIUM Description: anytoiso_setup Installer Exit code: 0 Version: 1.0.0 Modules
| |||||||||||||||
| 3932 | C:\Windows\system32\vssvc.exe | C:\Windows\System32\VSSVC.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft® Volume Shadow Copy Service Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (3932) VSSVC.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\ASR Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 4000000000000000CA4EFB3D6A62DA015C0F0000E80C0000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3932) VSSVC.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 4000000000000000CA4EFB3D6A62DA015C0F00001C090000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3932) VSSVC.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 4000000000000000CA4EFB3D6A62DA015C0F000078000000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3932) VSSVC.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 4000000000000000CA4EFB3D6A62DA015C0F0000600F0000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3932) VSSVC.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer |
| Operation: | write | Name: | IDENTIFY (Leave) |
Value: 4000000000000000CA4EFB3D6A62DA015C0F00001C090000E8030000000000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3932) VSSVC.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer |
| Operation: | write | Name: | IDENTIFY (Leave) |
Value: 400000000000000024B1FD3D6A62DA015C0F000078000000E8030000000000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3932) VSSVC.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\ASR Writer |
| Operation: | write | Name: | IDENTIFY (Leave) |
Value: 400000000000000024B1FD3D6A62DA015C0F0000E80C0000E8030000000000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3932) VSSVC.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer |
| Operation: | write | Name: | IDENTIFY (Leave) |
Value: 400000000000000024B1FD3D6A62DA015C0F0000600F0000E8030000000000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3932) VSSVC.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5} |
| Operation: | write | Name: | PROVIDER_BEGINPREPARE (Enter) |
Value: 40000000000000009416683F6A62DA015C0F0000600F0000010400000100000000000000000000003333CDF2BB21A9479FBE1C8488110A950000000000000000 | |||
| (PID) Process: | (3932) VSSVC.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5} |
| Operation: | write | Name: | PROVIDER_BEGINPREPARE (Leave) |
Value: 40000000000000009416683F6A62DA015C0F0000600F0000010400000000000000000000000000003333CDF2BB21A9479FBE1C8488110A950000000000000000 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3916 | anytoiso_setup.exe | C:\Users\admin\AppData\Roaming\anytoiso_setup\anytoiso_setup 1.0.0\install\holder0.aiph | — | |
MD5:— | SHA256:— | |||
| 3916 | anytoiso_setup.exe | C:\Users\admin\AppData\Roaming\anytoiso_setup\anytoiso_setup 1.0.0\install\C9ABEC1\anytoiso_setup.msi | executable | |
MD5:3E25368D5BD27E6F2E69ACE42D554794 | SHA256:6271FDB76F4E3115F65A335CE9C3F34CEB51CFC5974E38C82213E6CFA8B7F85F | |||
| 3916 | anytoiso_setup.exe | C:\Users\admin\AppData\Roaming\anytoiso_setup\anytoiso_setup 1.0.0\install\C9ABEC1\anytoiso_setup.exe | executable | |
MD5:ADA8E39EFBE48CEC5FA440576EFDC834 | SHA256:EA2A607714343AA54DF3501FB2E42A6BDD5E5629F18348F99A90937061A00DED | |||
| 3916 | anytoiso_setup.exe | C:\Users\admin\AppData\Roaming\anytoiso_setup\anytoiso_setup 1.0.0\install\C9ABEC1\LocalAppDataFolder\WindowsActiveServices\Patch.exe | executable | |
MD5:2AFBB4562F46E981BEAE497935002D3C | SHA256:7B949EC5F73DFF9E83D9C5E8995E025940F1ED6D3B07C27923D9321CA9A42EAD | |||
| 3916 | anytoiso_setup.exe | C:\Users\admin\AppData\Roaming\anytoiso_setup\anytoiso_setup 1.0.0\install\decoder.dll | executable | |
MD5:2CA6D4ED5DD15FB7934C87E857F5EBFC | SHA256:39412AACDCDDC4B2B3CFEB126456EDB125CE8CADB131CA5C23C031DB4431C5FC | |||
| 3916 | anytoiso_setup.exe | C:\Users\admin\AppData\Local\Temp\MSIFB48.tmp | executable | |
MD5:0981D5C068A9C33F4E8110F81FFBB92E | SHA256:B3F5E10FB1B7352A6DBBCBB10ED605A8FDA24F3F9C31F954835BD5A41EB6EA68 | |||
| 3800 | anytoiso_setup.exe | C:\Users\admin\AppData\Local\Temp\is-18P2J.tmp\anytoiso_setup.tmp | executable | |
MD5:D7907C5D4C9B358AA951A8881FF56AD2 | SHA256:8497ACC7371F8532D8A6BDA75E12B24C2BB4520E95D7E71C8DA14193A64A9BC9 | |||
| 3224 | anytoiso_setup.tmp | C:\Program Files\AnyToISO\is-TCE1M.tmp | executable | |
MD5:D7907C5D4C9B358AA951A8881FF56AD2 | SHA256:8497ACC7371F8532D8A6BDA75E12B24C2BB4520E95D7E71C8DA14193A64A9BC9 | |||
| 3224 | anytoiso_setup.tmp | C:\Program Files\AnyToISO\unins000.exe | executable | |
MD5:D7907C5D4C9B358AA951A8881FF56AD2 | SHA256:8497ACC7371F8532D8A6BDA75E12B24C2BB4520E95D7E71C8DA14193A64A9BC9 | |||
| 3224 | anytoiso_setup.tmp | C:\Users\admin\AppData\Local\Temp\is-BQF6I.tmp\is-I7KLI.tmp | executable | |
MD5:0CA0F8EFAEBE3636976165528D633560 | SHA256:39DD69F54B934C34E84FE19747A5D3AD118B54D19158CDF641CA6F8B8D40FAE3 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |