File name:

Setup Meter Tap 3 v1.0.4.exe

Full analysis: https://app.any.run/tasks/97869678-f68e-41a7-a22b-462f4789934b
Verdict: Malicious activity
Analysis date: November 26, 2023, 20:40:05
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

093F6DD4A7566D82E57F61690C4A4583

SHA1:

A38A3173C3E6AB21A26ECC51D8197C67BDFF4385

SHA256:

17659242F4CF4364BE7263B9B8799FF2A3C0A693E7AD148ED3E458890F67B7ED

SSDEEP:

24576:bBWGqK3aJsofTrnjtg5hEbZ+/pewTM/+Z7U:8BK0u8Mpe/K7U

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • Setup Meter Tap 3 v1.0.4.exe (PID: 2480)
      • Setup Meter Tap 3 v1.0.4.exe (PID: 3072)
      • Setup Meter Tap 3 v1.0.4.tmp (PID: 1448)
  • SUSPICIOUS

    • Reads the Windows owner or organization settings

      • Setup Meter Tap 3 v1.0.4.tmp (PID: 1448)
  • INFO

    • Checks supported languages

      • Setup Meter Tap 3 v1.0.4.exe (PID: 2480)
      • Setup Meter Tap 3 v1.0.4.tmp (PID: 3104)
      • Setup Meter Tap 3 v1.0.4.exe (PID: 3072)
      • Setup Meter Tap 3 v1.0.4.tmp (PID: 1448)
    • Reads the computer name

      • Setup Meter Tap 3 v1.0.4.tmp (PID: 3104)
      • Setup Meter Tap 3 v1.0.4.tmp (PID: 1448)
    • Create files in a temporary directory

      • Setup Meter Tap 3 v1.0.4.exe (PID: 2480)
      • Setup Meter Tap 3 v1.0.4.exe (PID: 3072)
      • Setup Meter Tap 3 v1.0.4.tmp (PID: 1448)
    • Manual execution by a user

      • WINWORD.EXE (PID: 2840)
      • WINWORD.EXE (PID: 1728)
      • WINWORD.EXE (PID: 3200)
    • Creates files in the program directory

      • Setup Meter Tap 3 v1.0.4.tmp (PID: 1448)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable Delphi generic (45.2)
.dll | Win32 Dynamic Link Library (generic) (20.9)
.exe | Win32 Executable (generic) (14.3)
.exe | Win16/32 Executable Delphi generic (6.6)
.exe | Generic Win/DOS Executable (6.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2016:04:06 16:39:04+02:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 66560
InitializedDataSize: 53760
UninitializedDataSize: -
EntryPoint: 0x117dc
OSVersion: 5
ImageVersion: 6
SubsystemVersion: 5
Subsystem: Windows GUI
FileVersionNumber: 1.0.4.0
ProductVersionNumber: 1.0.4.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: iZotope
FileDescription: Meter Tap 3 Setup
FileVersion: 1.0.4
LegalCopyright: iZotope
ProductName: Meter Tap 3
ProductVersion: 1.0.4
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
49
Monitored processes
7
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
start setup meter tap 3 v1.0.4.exe no specs setup meter tap 3 v1.0.4.tmp no specs setup meter tap 3 v1.0.4.exe setup meter tap 3 v1.0.4.tmp no specs winword.exe no specs winword.exe no specs winword.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1448"C:\Users\admin\AppData\Local\Temp\is-IFBVR.tmp\Setup Meter Tap 3 v1.0.4.tmp" /SL5="$80158,493066,121344,C:\Users\admin\AppData\Local\Temp\Setup Meter Tap 3 v1.0.4.exe" /SPAWNWND=$9016A /NOTIFYWND=$8019C C:\Users\admin\AppData\Local\Temp\is-IFBVR.tmp\Setup Meter Tap 3 v1.0.4.tmpSetup Meter Tap 3 v1.0.4.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
3221225547
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-ifbvr.tmp\setup meter tap 3 v1.0.4.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1728"C:\Program Files\Microsoft Office\Office14\WINWORD.EXE" /n "C:\Users\admin\Desktop\areadecember.rtf"C:\Program Files\Microsoft Office\Office14\WINWORD.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Word
Exit code:
0
Version:
14.0.6024.1000
Modules
Images
c:\program files\microsoft office\office14\winword.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc\comctl32.dll
2480"C:\Users\admin\AppData\Local\Temp\Setup Meter Tap 3 v1.0.4.exe" C:\Users\admin\AppData\Local\Temp\Setup Meter Tap 3 v1.0.4.exeexplorer.exe
User:
admin
Company:
iZotope
Integrity Level:
MEDIUM
Description:
Meter Tap 3 Setup
Exit code:
0
Version:
1.0.4
Modules
Images
c:\users\admin\appdata\local\temp\setup meter tap 3 v1.0.4.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2840"C:\Program Files\Microsoft Office\Office14\WINWORD.EXE" /n "C:\Users\admin\Desktop\globaleg.rtf"C:\Program Files\Microsoft Office\Office14\WINWORD.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Word
Exit code:
0
Version:
14.0.6024.1000
Modules
Images
c:\program files\microsoft office\office14\winword.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc\comctl32.dll
3072"C:\Users\admin\AppData\Local\Temp\Setup Meter Tap 3 v1.0.4.exe" /SPAWNWND=$9016A /NOTIFYWND=$8019C C:\Users\admin\AppData\Local\Temp\Setup Meter Tap 3 v1.0.4.exe
Setup Meter Tap 3 v1.0.4.tmp
User:
admin
Company:
iZotope
Integrity Level:
HIGH
Description:
Meter Tap 3 Setup
Exit code:
0
Version:
1.0.4
Modules
Images
c:\users\admin\appdata\local\temp\setup meter tap 3 v1.0.4.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
3104"C:\Users\admin\AppData\Local\Temp\is-ESN4V.tmp\Setup Meter Tap 3 v1.0.4.tmp" /SL5="$8019C,493066,121344,C:\Users\admin\AppData\Local\Temp\Setup Meter Tap 3 v1.0.4.exe" C:\Users\admin\AppData\Local\Temp\is-ESN4V.tmp\Setup Meter Tap 3 v1.0.4.tmpSetup Meter Tap 3 v1.0.4.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-esn4v.tmp\setup meter tap 3 v1.0.4.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
3200"C:\Program Files\Microsoft Office\Office14\WINWORD.EXE" /n "C:\Users\admin\Desktop\screenmost.rtf"C:\Program Files\Microsoft Office\Office14\WINWORD.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Word
Exit code:
0
Version:
14.0.6024.1000
Modules
Images
c:\program files\microsoft office\office14\winword.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc\comctl32.dll
Total events
8 900
Read events
8 063
Write events
387
Delete events
450

Modification events

(PID) Process:(2840) WINWORD.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1033
Value:
On
(PID) Process:(2840) WINWORD.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1041
Value:
On
(PID) Process:(2840) WINWORD.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1046
Value:
On
(PID) Process:(2840) WINWORD.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1036
Value:
On
(PID) Process:(2840) WINWORD.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1031
Value:
On
(PID) Process:(2840) WINWORD.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1040
Value:
On
(PID) Process:(2840) WINWORD.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1049
Value:
On
(PID) Process:(2840) WINWORD.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:3082
Value:
On
(PID) Process:(2840) WINWORD.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1042
Value:
On
(PID) Process:(2840) WINWORD.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1055
Value:
On
Executable files
12
Suspicious files
21
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
2840WINWORD.EXEC:\Users\admin\AppData\Local\Temp\CVR64AD.tmp.cvr
MD5:
SHA256:
1728WINWORD.EXEC:\Users\admin\AppData\Local\Temp\CVRD21C.tmp.cvr
MD5:
SHA256:
3200WINWORD.EXEC:\Users\admin\AppData\Local\Temp\CVRE789.tmp.cvr
MD5:
SHA256:
2480Setup Meter Tap 3 v1.0.4.exeC:\Users\admin\AppData\Local\Temp\is-ESN4V.tmp\Setup Meter Tap 3 v1.0.4.tmpexecutable
MD5:90FC739C83CD19766ACB562C66A7D0E2
SHA256:821BD11693BF4B4B2B9F3C196036E1F4902ABD95FB26873EA6C43E123B8C9431
1448Setup Meter Tap 3 v1.0.4.tmpC:\Users\admin\AppData\Local\Temp\is-CR8JS.tmp\SKIN.CJSTYLESexecutable
MD5:5F87CAF3F7CF63DDE8E6AF53BDF31289
SHA256:4731982B02B067D3F5A5A7518279A9265A49FB0F7B3F8DC3D61B82A5359D4940
2840WINWORD.EXEC:\Users\admin\Desktop\~$obaleg.rtfbinary
MD5:76D66ED004B53EB5BC1E007EA149433D
SHA256:DAB845757789E75DD33CEA05F95F7F4EC34EB66163C2D429E7DF8266377AE505
2840WINWORD.EXEC:\Users\admin\AppData\Roaming\Microsoft\Office\Recent\globaleg.rtf.LNKbinary
MD5:930CB81DA43A4AE846F252D8822AC6B1
SHA256:53E313EA3FB2061AB43E80BD2BB18A6EE84A3958C767D7C1DBEACD915AD9E641
2840WINWORD.EXEC:\Users\admin\AppData\Roaming\Microsoft\Templates\~$Normal.dotmbinary
MD5:9763C631F4C2F0AF9D5F400699747E51
SHA256:4AB15D9D4CBBF5137B44111E747F4526FDD77E8BE46CCCF98DE8A8940FFB6C61
1448Setup Meter Tap 3 v1.0.4.tmpC:\Users\admin\AppData\Local\Temp\is-CR8JS.tmp\ISSKINU.DLLexecutable
MD5:F30AFCCD6FAFC1CAD4567ADA824C9358
SHA256:E28D16FAD16BCA8198C47D7DD44ACFD362DD6BA1654F700ADD8AAF2C0732622D
2840WINWORD.EXEC:\Users\admin\AppData\Roaming\Microsoft\Office\Recent\index.dattext
MD5:62D434CE1B2212E36D6968B8143BAAA4
SHA256:69FDB369F798C17C45807FE3DB57D521125F05166185DFDA799B6C9B108FF9EF
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
2588
svchost.exe
239.255.255.250:1900
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown

DNS requests

No data

Threats

No threats detected
No debug info