File name:

SFirmSetup.exe

Full analysis: https://app.any.run/tasks/3377ce39-6338-420c-b212-ec42e989c56f
Verdict: Malicious activity
Analysis date: July 10, 2025, 09:55:32
OS: Windows 10 Professional (build: 19044, 64 bit)
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 8 sections
MD5:

648F1D4E2F226562B12E24224DACE967

SHA1:

582233AD0454AD019BB189A4BEEAFEC25CE64A1C

SHA256:

1AEFD5D2190970D5EC42723530E1074DCE541C0B1E05BBB4395C672B59322AF3

SSDEEP:

98304:Z1CmA/W8pQa6+LxFLG1U2kcgbFg75EiyNRO53MVIli0r2OF93DQi8kSb5aml4TIr:/hFIHJ

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • SFirmSetup.exe (PID: 1332)
    • There is functionality for taking screenshot (YARA)

      • SFirmSetup.exe (PID: 1332)
    • Detected use of alternative data streams (AltDS)

      • SFirmSetup.exe (PID: 1332)
  • INFO

    • The sample compiled with german language support

      • SFirmSetup.exe (PID: 1332)
    • Checks supported languages

      • SFirmSetup.exe (PID: 1332)
    • Creates files in the program directory

      • SFirmSetup.exe (PID: 1332)
    • Reads the computer name

      • SFirmSetup.exe (PID: 1332)
    • Reads product name

      • SFirmSetup.exe (PID: 1332)
    • Checks proxy server information

      • SFirmSetup.exe (PID: 1332)
    • Reads Environment values

      • SFirmSetup.exe (PID: 1332)
    • Reads the software policy settings

      • SFirmSetup.exe (PID: 1332)
    • Reads the machine GUID from the registry

      • SFirmSetup.exe (PID: 1332)
    • Creates files or folders in the user directory

      • SFirmSetup.exe (PID: 1332)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable (generic) (3.6)
.exe | Generic Win/DOS Executable (1.6)
.exe | DOS Executable Generic (1.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:02:14 13:27:50+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14
CodeSize: 2404352
InitializedDataSize: 1882624
UninitializedDataSize: -
EntryPoint: 0x19af4a
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 4.0.84.6929
ProductVersionNumber: 4.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Dynamic link library
FileSubtype: -
LanguageCode: German
CharacterSet: Unicode
CompanyName: Star Finanz-Software Entwicklung und Vertriebs GmbH
FileDescription: SFirm 4 Setup
FileVersion: 4, 0, 84, 6929
InternalName: SFSFirmSetup
LegalCopyright: Copyright © 1999 - 2024 Star Finanz GmbH
OriginalFileName: SFirmSetup.EXE
ProductName: SFirm
ProductVersion: 4, 0, 0, 0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
136
Monitored processes
2
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start sfirmsetup.exe slui.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1332"C:\Users\admin\AppData\Local\Temp\SFirmSetup.exe" C:\Users\admin\AppData\Local\Temp\SFirmSetup.exe
explorer.exe
User:
admin
Company:
Star Finanz-Software Entwicklung und Vertriebs GmbH
Integrity Level:
MEDIUM
Description:
SFirm Setup
Exit code:
1
Version:
4, 0, 0, 0
Modules
Images
c:\users\admin\appdata\local\temp\sfirmsetup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
6780C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
Total events
928
Read events
922
Write events
6
Delete events
0

Modification events

(PID) Process:(1332) SFirmSetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\StarFinanz\SFirmV4\Setup
Operation:writeName:ConfirmedAgreementVersion
Value:
2
(PID) Process:(1332) SFirmSetup.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\3c\81B026AB
Operation:writeName:@%SystemRoot%\system32\dnsapi.dll,-103
Value:
Domain Name System (DNS) Server Trust
(PID) Process:(1332) SFirmSetup.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\3c\81B026AB
Operation:writeName:@%SystemRoot%\system32\WindowsPowerShell\v1.0\powershell.exe,-124
Value:
Document Encryption
(PID) Process:(1332) SFirmSetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(1332) SFirmSetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(1332) SFirmSetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
Executable files
0
Suspicious files
3
Text files
2
Unknown types
3

Dropped files

PID
Process
Filename
Type
1332SFirmSetup.exeC:\ProgramData\Star Finanz\SFirm\SetupV4\Download\sfirm-msi.tmp
MD5:
SHA256:
1332SFirmSetup.exeC:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\RR3E01RZ\sfirm55[1].msis
MD5:
SHA256:
1332SFirmSetup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B2FAF7692FD9FFBD64EDE317E42334BA_D7393C8F62BDE4D4CB606228BC7A711Ebinary
MD5:22121C002D7AAF527F7AC5655A41B29B
SHA256:3105DA9CD74826340204679ACE34BFDCC1816778E3172AA19DB6F4C3378DCBF6
1332SFirmSetup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B2FAF7692FD9FFBD64EDE317E42334BA_D7393C8F62BDE4D4CB606228BC7A711Eder
MD5:36526A34791653FF50B729E39A6E0E42
SHA256:501DDEB25ACE2262E3889BABC4646D0402C2B1E067DE357F3050D72C77FC3091
1332SFirmSetup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\07CEF2F654E3ED6050FFC9B6EB844250_BACC6CD2B29F18349081C9FD2343833Bder
MD5:6D55FC2F7A064DADEB175CABFE58C92D
SHA256:172087003AE276663EAF071CB17A0F693B70FC4BFC45B9CF6C1937121CF62FEB
1332SFirmSetup.exeC:\ProgramData\Star Finanz\SFirmV4 LOGS\2025-07-10_09-55-37_SFirmSetup_1332.logtext
MD5:10B71D84D376E170D02F44FB791DCAF7
SHA256:9EA1C9F108263D4C313B2A37BE9823CF9751DF5CA26FB290D36DF814E21E34A2
1332SFirmSetup.exeC:\ProgramData\Star Finanz\SFirm\SetupV4\Download\sfirm-msi.tmp:sfhresumetext
MD5:3D747FB55E0297EFB2349AE2DA0B5D8B
SHA256:F057ABC9D46F663B62772A05ECEC69D4F7958071BA6D32DBF5E650237137F3C3
1332SFirmSetup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\07CEF2F654E3ED6050FFC9B6EB844250_BACC6CD2B29F18349081C9FD2343833Bbinary
MD5:62B520423BE1BACE6DC453B132DE0C99
SHA256:FDEF9043B8B2CF9F7C17E7633ECC0165523C75EB47A5E094A697D31511192CCB
1332SFirmSetup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\72BA427A91F50409B9EAC87F2B59B951_044ABFEC4FEF2ABCECE58DECB4D0E420der
MD5:5951CFBEFA9A5ADDA20E39749E4DBF09
SHA256:AE767F356AE8BFE58AB914469095BF8EFD317F492FEF34014DFBEACBC3006D7A
1332SFirmSetup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\72BA427A91F50409B9EAC87F2B59B951_044ABFEC4FEF2ABCECE58DECB4D0E420binary
MD5:DCA83474B5AD99A9FDA0972FC756E0C4
SHA256:04906B5D9720D6280AE360E45A504E3E3FFB0DAFA4CAA9EFB2982099D7EB9A78
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
8
TCP/UDP connections
27
DNS requests
18
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1332
SFirmSetup.exe
GET
200
104.18.38.233:80
http://ocsp.comodoca.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRTtU9uFqgVGHhJwXZyWCNXmVR5ngQUoBEKIz6W8Qfs4q8p74Klf9AwpLQCEDlyRDr5IrdR19NsEN0xNZU%3D
unknown
whitelisted
1332
SFirmSetup.exe
GET
200
172.64.149.23:80
http://ocsp.usertrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTNMNJMNDqCqx8FcBWK16EHdimS6QQUU3m%2FWqorSs9UgOHYm8Cd8rIDZssCEBN9U5yqfDGppDNwGWiEeo0%3D
unknown
whitelisted
1332
SFirmSetup.exe
GET
200
104.18.38.233:80
http://ocsp.sectigo.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQh80WaEMqmyEvaHjlisSfVM4p8SAQUF9nWJSdn%2BTHCSUPZMDZEjGypT%2BsCEEEeCK3IXNvX6hPf%2BVQJhns%3D
unknown
whitelisted
420
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
1268
svchost.exe
GET
200
2.16.168.124:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
1268
svchost.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
1948
SIHClient.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
1948
SIHClient.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
1268
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5944
MoUsoCoreWorker.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4680
RUXIMICS.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
1332
SFirmSetup.exe
185.172.148.132:443
downloads.starfinanz.de
proinity GmbH
CH
malicious
420
svchost.exe
20.190.160.64:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1332
SFirmSetup.exe
104.18.38.233:80
ocsp.comodoca.com
CLOUDFLARENET
whitelisted
420
svchost.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
1332
SFirmSetup.exe
172.64.149.23:80
ocsp.comodoca.com
CLOUDFLARENET
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
  • 4.231.128.59
whitelisted
google.com
  • 142.250.181.238
whitelisted
downloads.starfinanz.de
  • 185.172.148.132
unknown
login.live.com
  • 20.190.160.64
  • 20.190.160.17
  • 20.190.160.66
  • 20.190.160.5
  • 20.190.160.4
  • 20.190.160.132
  • 20.190.160.20
  • 20.190.160.65
whitelisted
ocsp.comodoca.com
  • 104.18.38.233
  • 172.64.149.23
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
ocsp.usertrust.com
  • 172.64.149.23
  • 104.18.38.233
whitelisted
ocsp.sectigo.com
  • 104.18.38.233
  • 172.64.149.23
whitelisted
client.wns.windows.com
  • 172.211.123.249
whitelisted
crl.microsoft.com
  • 2.16.168.124
  • 2.16.168.114
whitelisted

Threats

No threats detected
No debug info