File name:

Setup Meter Tap 3 v1.0.4.exe

Full analysis: https://app.any.run/tasks/97869678-f68e-41a7-a22b-462f4789934b
Verdict: Malicious activity
Analysis date: November 26, 2023, 20:40:05
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

093F6DD4A7566D82E57F61690C4A4583

SHA1:

A38A3173C3E6AB21A26ECC51D8197C67BDFF4385

SHA256:

17659242F4CF4364BE7263B9B8799FF2A3C0A693E7AD148ED3E458890F67B7ED

SSDEEP:

24576:bBWGqK3aJsofTrnjtg5hEbZ+/pewTM/+Z7U:8BK0u8Mpe/K7U

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • Setup Meter Tap 3 v1.0.4.exe (PID: 2480)
      • Setup Meter Tap 3 v1.0.4.exe (PID: 3072)
      • Setup Meter Tap 3 v1.0.4.tmp (PID: 1448)
  • SUSPICIOUS

    • Reads the Windows owner or organization settings

      • Setup Meter Tap 3 v1.0.4.tmp (PID: 1448)
  • INFO

    • Checks supported languages

      • Setup Meter Tap 3 v1.0.4.exe (PID: 3072)
      • Setup Meter Tap 3 v1.0.4.exe (PID: 2480)
      • Setup Meter Tap 3 v1.0.4.tmp (PID: 3104)
      • Setup Meter Tap 3 v1.0.4.tmp (PID: 1448)
    • Creates files in the program directory

      • Setup Meter Tap 3 v1.0.4.tmp (PID: 1448)
    • Reads the computer name

      • Setup Meter Tap 3 v1.0.4.tmp (PID: 3104)
      • Setup Meter Tap 3 v1.0.4.tmp (PID: 1448)
    • Create files in a temporary directory

      • Setup Meter Tap 3 v1.0.4.exe (PID: 2480)
      • Setup Meter Tap 3 v1.0.4.exe (PID: 3072)
      • Setup Meter Tap 3 v1.0.4.tmp (PID: 1448)
    • Manual execution by a user

      • WINWORD.EXE (PID: 3200)
      • WINWORD.EXE (PID: 1728)
      • WINWORD.EXE (PID: 2840)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable Delphi generic (45.2)
.dll | Win32 Dynamic Link Library (generic) (20.9)
.exe | Win32 Executable (generic) (14.3)
.exe | Win16/32 Executable Delphi generic (6.6)
.exe | Generic Win/DOS Executable (6.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2016:04:06 16:39:04+02:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 66560
InitializedDataSize: 53760
UninitializedDataSize: -
EntryPoint: 0x117dc
OSVersion: 5
ImageVersion: 6
SubsystemVersion: 5
Subsystem: Windows GUI
FileVersionNumber: 1.0.4.0
ProductVersionNumber: 1.0.4.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: iZotope
FileDescription: Meter Tap 3 Setup
FileVersion: 1.0.4
LegalCopyright: iZotope
ProductName: Meter Tap 3
ProductVersion: 1.0.4
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
49
Monitored processes
7
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
start setup meter tap 3 v1.0.4.exe no specs setup meter tap 3 v1.0.4.tmp no specs setup meter tap 3 v1.0.4.exe setup meter tap 3 v1.0.4.tmp no specs winword.exe no specs winword.exe no specs winword.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1448"C:\Users\admin\AppData\Local\Temp\is-IFBVR.tmp\Setup Meter Tap 3 v1.0.4.tmp" /SL5="$80158,493066,121344,C:\Users\admin\AppData\Local\Temp\Setup Meter Tap 3 v1.0.4.exe" /SPAWNWND=$9016A /NOTIFYWND=$8019C C:\Users\admin\AppData\Local\Temp\is-IFBVR.tmp\Setup Meter Tap 3 v1.0.4.tmpSetup Meter Tap 3 v1.0.4.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
3221225547
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-ifbvr.tmp\setup meter tap 3 v1.0.4.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1728"C:\Program Files\Microsoft Office\Office14\WINWORD.EXE" /n "C:\Users\admin\Desktop\areadecember.rtf"C:\Program Files\Microsoft Office\Office14\WINWORD.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Word
Exit code:
0
Version:
14.0.6024.1000
Modules
Images
c:\program files\microsoft office\office14\winword.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc\comctl32.dll
2480"C:\Users\admin\AppData\Local\Temp\Setup Meter Tap 3 v1.0.4.exe" C:\Users\admin\AppData\Local\Temp\Setup Meter Tap 3 v1.0.4.exeexplorer.exe
User:
admin
Company:
iZotope
Integrity Level:
MEDIUM
Description:
Meter Tap 3 Setup
Exit code:
0
Version:
1.0.4
Modules
Images
c:\users\admin\appdata\local\temp\setup meter tap 3 v1.0.4.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2840"C:\Program Files\Microsoft Office\Office14\WINWORD.EXE" /n "C:\Users\admin\Desktop\globaleg.rtf"C:\Program Files\Microsoft Office\Office14\WINWORD.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Word
Exit code:
0
Version:
14.0.6024.1000
Modules
Images
c:\program files\microsoft office\office14\winword.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc\comctl32.dll
3072"C:\Users\admin\AppData\Local\Temp\Setup Meter Tap 3 v1.0.4.exe" /SPAWNWND=$9016A /NOTIFYWND=$8019C C:\Users\admin\AppData\Local\Temp\Setup Meter Tap 3 v1.0.4.exe
Setup Meter Tap 3 v1.0.4.tmp
User:
admin
Company:
iZotope
Integrity Level:
HIGH
Description:
Meter Tap 3 Setup
Exit code:
0
Version:
1.0.4
Modules
Images
c:\users\admin\appdata\local\temp\setup meter tap 3 v1.0.4.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
3104"C:\Users\admin\AppData\Local\Temp\is-ESN4V.tmp\Setup Meter Tap 3 v1.0.4.tmp" /SL5="$8019C,493066,121344,C:\Users\admin\AppData\Local\Temp\Setup Meter Tap 3 v1.0.4.exe" C:\Users\admin\AppData\Local\Temp\is-ESN4V.tmp\Setup Meter Tap 3 v1.0.4.tmpSetup Meter Tap 3 v1.0.4.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-esn4v.tmp\setup meter tap 3 v1.0.4.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
3200"C:\Program Files\Microsoft Office\Office14\WINWORD.EXE" /n "C:\Users\admin\Desktop\screenmost.rtf"C:\Program Files\Microsoft Office\Office14\WINWORD.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Word
Exit code:
0
Version:
14.0.6024.1000
Modules
Images
c:\program files\microsoft office\office14\winword.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc\comctl32.dll
Total events
8 900
Read events
8 063
Write events
387
Delete events
450

Modification events

(PID) Process:(2840) WINWORD.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1033
Value:
On
(PID) Process:(2840) WINWORD.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1041
Value:
On
(PID) Process:(2840) WINWORD.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1046
Value:
On
(PID) Process:(2840) WINWORD.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1036
Value:
On
(PID) Process:(2840) WINWORD.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1031
Value:
On
(PID) Process:(2840) WINWORD.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1040
Value:
On
(PID) Process:(2840) WINWORD.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1049
Value:
On
(PID) Process:(2840) WINWORD.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:3082
Value:
On
(PID) Process:(2840) WINWORD.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1042
Value:
On
(PID) Process:(2840) WINWORD.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1055
Value:
On
Executable files
12
Suspicious files
21
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
2840WINWORD.EXEC:\Users\admin\AppData\Local\Temp\CVR64AD.tmp.cvr
MD5:
SHA256:
1728WINWORD.EXEC:\Users\admin\AppData\Local\Temp\CVRD21C.tmp.cvr
MD5:
SHA256:
3200WINWORD.EXEC:\Users\admin\AppData\Local\Temp\CVRE789.tmp.cvr
MD5:
SHA256:
2840WINWORD.EXEC:\Users\admin\Desktop\~$obaleg.rtfbinary
MD5:76D66ED004B53EB5BC1E007EA149433D
SHA256:DAB845757789E75DD33CEA05F95F7F4EC34EB66163C2D429E7DF8266377AE505
1448Setup Meter Tap 3 v1.0.4.tmpC:\Users\admin\AppData\Local\Temp\is-CR8JS.tmp\R2RINNO.dllexecutable
MD5:0F8BBAB51C5F70093B7ED7DD825D68E8
SHA256:7FC4FA7F5CEA34DF0A6733527081886CFB1C49B369DF2DB454DE87CC4E70BDB5
3072Setup Meter Tap 3 v1.0.4.exeC:\Users\admin\AppData\Local\Temp\is-IFBVR.tmp\Setup Meter Tap 3 v1.0.4.tmpexecutable
MD5:90FC739C83CD19766ACB562C66A7D0E2
SHA256:821BD11693BF4B4B2B9F3C196036E1F4902ABD95FB26873EA6C43E123B8C9431
2840WINWORD.EXEC:\Users\admin\AppData\Roaming\Microsoft\Office\Recent\globaleg.rtf.LNKbinary
MD5:930CB81DA43A4AE846F252D8822AC6B1
SHA256:53E313EA3FB2061AB43E80BD2BB18A6EE84A3958C767D7C1DBEACD915AD9E641
2840WINWORD.EXEC:\Users\admin\AppData\Roaming\Microsoft\Templates\~$Normal.dotmbinary
MD5:9763C631F4C2F0AF9D5F400699747E51
SHA256:4AB15D9D4CBBF5137B44111E747F4526FDD77E8BE46CCCF98DE8A8940FFB6C61
1728WINWORD.EXEC:\Users\admin\AppData\Roaming\Microsoft\Office\Recent\areadecember.rtf.LNKbinary
MD5:EF9BAF52BA845B94C3221BEA2805A874
SHA256:D9C37DF5778B7CE06DF13E581F13EA9CAAF37FB566DA7B02420260FDD82B0E42
1728WINWORD.EXEC:\Users\admin\AppData\Roaming\Microsoft\Templates\~$Normal.dotmbinary
MD5:0DD10268C1227B7F07642F6812144245
SHA256:EA2674735D55402787964F0201468D3DA81E72B14D2F7482E2DFBE489D194BC1
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
2588
svchost.exe
239.255.255.250:1900
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown

DNS requests

No data

Threats

No threats detected
No debug info