File name:

spywareguardsetup.exe

Full analysis: https://app.any.run/tasks/49058fe1-26cd-41d6-b59c-0cc948897300
Verdict: Malicious activity
Analysis date: February 24, 2024, 16:56:57
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
opendir
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, InnoSetup self-extracting archive
MD5:

14CE452049D0FC3F34B4B9CE56DCEE60

SHA1:

E2432FA050EDFA7F19B88C00F25C723F3940CFF2

SHA256:

173AA92938B5B1BFC6C888F8FF435BDAC068B7F295C93887D41515A99E01CE24

SSDEEP:

98304:4GQSPCl52tnMuDPY6sBVMBnFUg8NMZqiePQ+8ypkv8h6872cHd7wjWXmD4B8zbkY:po81bN

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • spywareguardsetup.exe (PID: 3708)
      • INSF741.tmp (PID: 3216)
    • Creates a writable file in the system directory

      • INSF741.tmp (PID: 3216)
    • Create files in the Startup directory

      • INSF741.tmp (PID: 3216)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • spywareguardsetup.exe (PID: 3708)
      • INSF741.tmp (PID: 3216)
    • Process drops legitimate windows executable

      • INSF741.tmp (PID: 3216)
    • Starts application with an unusual extension

      • spywareguardsetup.exe (PID: 3708)
    • Creates/Modifies COM task schedule object

      • INSF741.tmp (PID: 3216)
    • Creates a software uninstall entry

      • INSF741.tmp (PID: 3216)
    • Reads security settings of Internet Explorer

      • sgliveupdate.exe (PID: 2744)
      • sgliveupdate.exe (PID: 1824)
    • Reads the Internet Settings

      • sgliveupdate.exe (PID: 2744)
      • sgliveupdate.exe (PID: 1824)
  • INFO

    • Checks supported languages

      • spywareguardsetup.exe (PID: 3708)
      • INSF741.tmp (PID: 3216)
      • sgmain.exe (PID: 2624)
      • sgliveupdate.exe (PID: 2892)
      • sgliveupdate.exe (PID: 1824)
      • sgbhp.exe (PID: 2340)
      • sgliveupdate.exe (PID: 2744)
      • sgmain.exe (PID: 3404)
      • sgmain.exe (PID: 2576)
      • sgmain.exe (PID: 3984)
      • sgmain.exe (PID: 1624)
      • sgmain.exe (PID: 2668)
    • Reads the computer name

      • INSF741.tmp (PID: 3216)
      • sgbhp.exe (PID: 2340)
      • sgliveupdate.exe (PID: 2744)
      • sgliveupdate.exe (PID: 1824)
    • Create files in a temporary directory

      • spywareguardsetup.exe (PID: 3708)
      • INSF741.tmp (PID: 3216)
      • sgmain.exe (PID: 2624)
      • sgbhp.exe (PID: 2340)
      • sgliveupdate.exe (PID: 2892)
      • sgliveupdate.exe (PID: 2744)
      • sgliveupdate.exe (PID: 1824)
      • sgmain.exe (PID: 2576)
      • sgmain.exe (PID: 3984)
      • sgmain.exe (PID: 3404)
      • sgmain.exe (PID: 1624)
      • sgmain.exe (PID: 2668)
    • Creates files in the program directory

      • INSF741.tmp (PID: 3216)
      • sgbhp.exe (PID: 2340)
      • sgliveupdate.exe (PID: 1824)
      • sgliveupdate.exe (PID: 2744)
    • Creates files or folders in the user directory

      • INSF741.tmp (PID: 3216)
      • sgliveupdate.exe (PID: 1824)
      • sgliveupdate.exe (PID: 2744)
    • Reads the machine GUID from the registry

      • sgmain.exe (PID: 2624)
      • sgbhp.exe (PID: 2340)
      • sgliveupdate.exe (PID: 2892)
      • sgliveupdate.exe (PID: 2744)
      • sgliveupdate.exe (PID: 1824)
      • sgmain.exe (PID: 2576)
      • sgmain.exe (PID: 3984)
      • sgmain.exe (PID: 3404)
      • sgmain.exe (PID: 1624)
      • sgmain.exe (PID: 2668)
    • Reads Microsoft Office registry keys

      • sgmain.exe (PID: 2624)
      • sgmain.exe (PID: 3404)
      • sgmain.exe (PID: 2576)
      • sgmain.exe (PID: 1624)
      • sgmain.exe (PID: 2668)
      • sgmain.exe (PID: 3984)
    • Reads mouse settings

      • sgmain.exe (PID: 2624)
      • sgmain.exe (PID: 3404)
      • sgmain.exe (PID: 2576)
      • sgmain.exe (PID: 1624)
      • sgmain.exe (PID: 3984)
      • sgmain.exe (PID: 2668)
    • Manual execution by a user

      • sgliveupdate.exe (PID: 2892)
      • sgliveupdate.exe (PID: 4008)
      • sgliveupdate.exe (PID: 2208)
      • sgliveupdate.exe (PID: 1824)
      • sgliveupdate.exe (PID: 2744)
      • sgliveupdate.exe (PID: 240)
      • sgmain.exe (PID: 2576)
      • sgmain.exe (PID: 3984)
      • sgmain.exe (PID: 1624)
      • sgmain.exe (PID: 3404)
      • sgmain.exe (PID: 2668)
    • Checks proxy server information

      • sgliveupdate.exe (PID: 2744)
      • sgliveupdate.exe (PID: 1824)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (82.8)
.exe | Win32 Executable Delphi generic (10.7)
.exe | Win32 Executable (generic) (3.4)
.exe | Generic Win/DOS Executable (1.5)
.exe | DOS Executable Generic (1.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 1992:06:19 22:22:17+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 46592
InitializedDataSize: 16384
UninitializedDataSize: -
EntryPoint: 0xbed8
OSVersion: 1
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
64
Monitored processes
16
Malicious processes
2
Suspicious processes
2

Behavior graph

Click at the process to see the details
start spywareguardsetup.exe insf741.tmp sgmain.exe no specs sgbhp.exe no specs sgliveupdate.exe no specs sgliveupdate.exe sgliveupdate.exe no specs sgliveupdate.exe sgliveupdate.exe no specs sgliveupdate.exe sgmain.exe no specs sgmain.exe no specs sgmain.exe no specs sgmain.exe no specs sgmain.exe no specs spywareguardsetup.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
240"C:\Program Files\SpywareGuard\sgliveupdate.exe" C:\Program Files\SpywareGuard\sgliveupdate.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
SpywareGuard LiveUpdate
Exit code:
3221226540
Version:
2.02.0001
Modules
Images
c:\program files\spywareguard\sgliveupdate.exe
c:\windows\system32\ntdll.dll
1624"C:\Program Files\SpywareGuard\sgmain.exe" C:\Program Files\SpywareGuard\sgmain.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
SpywareGuard
Exit code:
0
Version:
2.02.0001
Modules
Images
c:\program files\spywareguard\sgmain.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvbvm60.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
1824"C:\Program Files\SpywareGuard\sgliveupdate.exe" C:\Program Files\SpywareGuard\sgliveupdate.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Description:
SpywareGuard LiveUpdate
Exit code:
0
Version:
2.02.0001
Modules
Images
c:\program files\spywareguard\sgliveupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvbvm60.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
2208"C:\Program Files\SpywareGuard\sgliveupdate.exe" C:\Program Files\SpywareGuard\sgliveupdate.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
SpywareGuard LiveUpdate
Exit code:
3221226540
Version:
2.02.0001
Modules
Images
c:\program files\spywareguard\sgliveupdate.exe
c:\windows\system32\ntdll.dll
2340"C:\Program Files\SpywareGuard\sgbhp.exe"C:\Program Files\SpywareGuard\sgbhp.exesgmain.exe
User:
admin
Integrity Level:
HIGH
Description:
SG Browser Hijacking Protection
Exit code:
0
Version:
2.02.0001
Modules
Images
c:\program files\spywareguard\sgbhp.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvbvm60.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
2472"C:\Users\admin\AppData\Local\Temp\spywareguardsetup.exe" C:\Users\admin\AppData\Local\Temp\spywareguardsetup.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\appdata\local\temp\spywareguardsetup.exe
c:\windows\system32\ntdll.dll
2576"C:\Program Files\SpywareGuard\sgmain.exe" C:\Program Files\SpywareGuard\sgmain.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
SpywareGuard
Exit code:
0
Version:
2.02.0001
Modules
Images
c:\program files\spywareguard\sgmain.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvbvm60.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
2624"C:\Program Files\SpywareGuard\sgmain.exe" C:\Program Files\SpywareGuard\sgmain.exeINSF741.tmp
User:
admin
Integrity Level:
HIGH
Description:
SpywareGuard
Exit code:
0
Version:
2.02.0001
Modules
Images
c:\program files\spywareguard\sgmain.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvbvm60.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
2668"C:\Program Files\SpywareGuard\sgmain.exe" C:\Program Files\SpywareGuard\sgmain.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
SpywareGuard
Exit code:
0
Version:
2.02.0001
Modules
Images
c:\program files\spywareguard\sgmain.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvbvm60.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
2744"C:\Program Files\SpywareGuard\sgliveupdate.exe" C:\Program Files\SpywareGuard\sgliveupdate.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Description:
SpywareGuard LiveUpdate
Exit code:
0
Version:
2.02.0001
Modules
Images
c:\program files\spywareguard\sgliveupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvbvm60.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
Total events
8 317
Read events
8 197
Write events
94
Delete events
26

Modification events

(PID) Process:(3216) INSF741.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
Operation:writeName:C:\Windows\system32\MSINET.OCX
Value:
1
(PID) Process:(3216) INSF741.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
Operation:writeName:C:\Windows\system32\RICHTX32.OCX
Value:
1
(PID) Process:(3216) INSF741.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
Operation:writeName:C:\Windows\system32\stdole2.tlb
Value:
2
(PID) Process:(3216) INSF741.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
Operation:writeName:C:\Windows\system32\msvbvm60.dll
Value:
2
(PID) Process:(3216) INSF741.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
Operation:writeName:C:\Windows\system32\oleaut32.dll
Value:
2
(PID) Process:(3216) INSF741.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
Operation:writeName:C:\Windows\system32\olepro32.dll
Value:
2
(PID) Process:(3216) INSF741.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
Operation:writeName:C:\Windows\system32\asycfilt.dll
Value:
2
(PID) Process:(3216) INSF741.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
Operation:writeName:C:\Windows\system32\comcat.dll
Value:
2
(PID) Process:(3216) INSF741.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
Operation:writeName:{81559C35-8464-49F7-BB0E-07A383BEF910}
Value:
(PID) Process:(3216) INSF741.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
Operation:writeName:{81559C35-8464-49F7-BB0E-07A383BEF910}
Value:
Executable files
25
Suspicious files
10
Text files
25
Unknown types
12

Dropped files

PID
Process
Filename
Type
3708spywareguardsetup.exeC:\Users\admin\AppData\Local\Temp\INSF741.tmpexecutable
MD5:99FA571A302C7E8ED49D149C1C700623
SHA256:D2E9C5966937BEADBA64D89D3CE31212C61A85118D9662ADB98FDEAC1AD6EB44
3216INSF741.tmpC:\Users\admin\AppData\Local\Temp\is-G425L.tmp\_isbunzp.dllexecutable
MD5:59A7E0FA5404DB5E9F1F18E2A2F69797
SHA256:5BCC823BA75C9BF6A8E01101EB5CEE690FD3DCB2D635432AD4E26BF76024954C
3216INSF741.tmpC:\Program Files\SpywareGuard\sgmain.exeexecutable
MD5:61C028ABA5E49573A6332F4A7C744E87
SHA256:69CCD902F1A62237F98DF5134483DA51DBB459EFDA94D6130790BA478A2AA467
3216INSF741.tmpC:\Program Files\SpywareGuard\is-K8AFN.tmptext
MD5:40EE7B133696D747B5806953E16134E6
SHA256:017142478E3AC208E027FCA7AEFD963577A564F8BFF46793A05F6340B796A31D
3216INSF741.tmpC:\Program Files\SpywareGuard\def2.dtbini
MD5:6B9EC873774E555612CAC3F29445515C
SHA256:75680E802CF43407BCE6D9E76FCF8947BE6279931B7433F793F320F451FB9BC3
3216INSF741.tmpC:\Program Files\SpywareGuard\is-7G64R.tmpini
MD5:6B9EC873774E555612CAC3F29445515C
SHA256:75680E802CF43407BCE6D9E76FCF8947BE6279931B7433F793F320F451FB9BC3
3216INSF741.tmpC:\Program Files\SpywareGuard\is-IMQDD.tmpini
MD5:19BC9BBA7A71C34C3A618FCF53BF9ECB
SHA256:56BC809CF27E088194BC0F41ACD339F29D65E5B5E5D0061BBABDEB75D2C48DF1
3216INSF741.tmpC:\Program Files\SpywareGuard\def1.dtbini
MD5:1513962462F96DB20758841581B3E30B
SHA256:F00AAFA57F6F3474EA2328FDF187BAE8895456DB5956B77E8F9BAAF12CD31024
3216INSF741.tmpC:\Program Files\SpywareGuard\dlbdata1.dtbini
MD5:19BC9BBA7A71C34C3A618FCF53BF9ECB
SHA256:56BC809CF27E088194BC0F41ACD339F29D65E5B5E5D0061BBABDEB75D2C48DF1
3216INSF741.tmpC:\Program Files\SpywareGuard\dlbdata2.dtbini
MD5:F3F70B68D9F96AE7617C72A10E915683
SHA256:11C1EB4E2D6984C652ADB643909EF97A4737949AFC54919F265296A8CA0FD610
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
12
TCP/UDP connections
8
DNS requests
2
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1824
sgliveupdate.exe
GET
301
67.225.152.77:80
http://www.javacoolsoftware.com/spywareguardversion.txt
unknown
html
257 b
unknown
1824
sgliveupdate.exe
GET
200
67.225.152.78:80
http://www.brightfort.com/spywareguardversion.txt
unknown
text
504 b
unknown
1824
sgliveupdate.exe
GET
301
67.225.152.77:80
http://www.javacoolsoftware.com/spywareguard/def1.dtb
unknown
html
255 b
unknown
1824
sgliveupdate.exe
GET
206
67.225.152.78:80
http://www.brightfort.com/spywareguard/def1.dtb
unknown
text
16.1 Kb
unknown
1824
sgliveupdate.exe
GET
301
67.225.152.77:80
http://www.javacoolsoftware.com/spywareguard/def2.dtb
unknown
html
255 b
unknown
1824
sgliveupdate.exe
GET
206
67.225.152.78:80
http://www.brightfort.com/spywareguard/def2.dtb
unknown
text
9.96 Kb
unknown
1824
sgliveupdate.exe
GET
301
67.225.152.77:80
http://www.javacoolsoftware.com/spywareguard/dlbdata1.dtb
unknown
html
259 b
unknown
1824
sgliveupdate.exe
GET
206
67.225.152.78:80
http://www.brightfort.com/spywareguard/dlbdata1.dtb
unknown
text
9.10 Kb
unknown
1824
sgliveupdate.exe
GET
301
67.225.152.77:80
http://www.javacoolsoftware.com/spywareguard/dlbdata2.dtb
unknown
html
259 b
unknown
1824
sgliveupdate.exe
GET
206
67.225.152.78:80
http://www.brightfort.com/spywareguard/dlbdata2.dtb
unknown
text
9.58 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
1824
sgliveupdate.exe
67.225.152.77:80
www.javacoolsoftware.com
LIQUIDWEB
US
unknown
1824
sgliveupdate.exe
67.225.152.78:80
www.brightfort.com
LIQUIDWEB
US
unknown
2744
sgliveupdate.exe
67.225.152.77:80
www.javacoolsoftware.com
LIQUIDWEB
US
unknown
2744
sgliveupdate.exe
67.225.152.78:80
www.brightfort.com
LIQUIDWEB
US
unknown

DNS requests

Domain
IP
Reputation
www.javacoolsoftware.com
  • 67.225.152.77
unknown
www.brightfort.com
  • 67.225.152.78
unknown

Threats

No threats detected
No debug info