| File name: | HP ALM Microsof Excel Add-In Setup.exe |
| Full analysis: | https://app.any.run/tasks/b71f8839-1351-4458-b47e-7b2ddd145594 |
| Verdict: | Malicious activity |
| Threats: | A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection. |
| Analysis date: | December 12, 2018, 14:24:10 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | CAD3673DB3064D90D2A7C1BB991BC33B |
| SHA1: | 89F9AA0ABB4050FB95321919C6B72271FF1AA43E |
| SHA256: | 1BE8380FDFF239B3C7F0B0E38DBB94F2D3861FDCEAC086BB6B798A77A0FDF862 |
| SSDEEP: | 196608:bK0/Lyqlch4+cgr7J6iZnzTkRAnfekUMHsTA3i07lL1rZZTiUMv5iQXLw5fDAQg1:bK0/LCrx8UWnYaz0l1NkUbQXGDngdj |
| .exe | | | InstallShield setup (15.6) |
|---|---|---|
| .exe | | | Win32 EXE PECompact compressed (generic) (15.1) |
| .exe | | | Win32 Executable MS Visual C++ (generic) (11.3) |
| .exe | | | Win64 Executable (generic) (10) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2012:04:25 02:38:18+02:00 |
| PEType: | PE32 |
| LinkerVersion: | 9 |
| CodeSize: | 623616 |
| InitializedDataSize: | 421376 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x76400 |
| OSVersion: | 5 |
| ImageVersion: | - |
| SubsystemVersion: | 5 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 12.20.0.377 |
| ProductVersionNumber: | 12.20.0.377 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Dynamic link library |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| CompanyName: | Hewlett-Packard |
| FileDescription: | HP ALM Microsoft Excel Add-in Set Up |
| FileVersion: | 12.20.0.377 |
| InternalName: | SetupSuite |
| LegalCopyright: | Copyright 1992-2014 Hewlett-Packard |
| OriginalFileName: | InstallShield SetupSuite.exe |
| ProductName: | HP ALM Microsoft Excel Add-in |
| ProductVersion: | 12.20.0.377 |
| InternalBuildNumber: | 115289 |
| ISInternalVersion: | 19.0.160 |
| ISInternalDescription: | Setup Suite Launcher Unicode |
| Architecture: | IMAGE_FILE_MACHINE_I386 |
|---|---|
| Subsystem: | IMAGE_SUBSYSTEM_WINDOWS_GUI |
| Compilation Date: | 25-Apr-2012 00:38:18 |
| Detected languages: |
|
| Debug artifacts: |
|
| CompanyName: | Flexera Software LLC |
| FileDescription: | Setup Suite Launcher Unicode |
| FileVersion: | 19.0.160 |
| InternalName: | SetupSuite |
| LegalCopyright: | Copyright (c) 2012 Flexera Software LLC. All Rights Reserved. |
| OriginalFilename: | InstallShield SetupSuite.exe |
| ProductName: | InstallShield |
| ProductVersion: | 19.0 |
| Internal Build Number: | 115289 |
| ISInternalVersion: | 19.0.160 |
| ISInternalDescription: | Setup Suite Launcher Unicode |
| Magic number: | MZ |
|---|---|
| Bytes on last page of file: | 0x0090 |
| Pages in file: | 0x0003 |
| Relocations: | 0x0000 |
| Size of header: | 0x0004 |
| Min extra paragraphs: | 0x0000 |
| Max extra paragraphs: | 0xFFFF |
| Initial SS value: | 0x0000 |
| Initial SP value: | 0x00B8 |
| Checksum: | 0x0000 |
| Initial IP value: | 0x0000 |
| Initial CS value: | 0x0000 |
| Overlay number: | 0x0000 |
| OEM identifier: | 0x0000 |
| OEM information: | 0x0000 |
| Address of NE header: | 0x000000F8 |
| Signature: | PE |
|---|---|
| Machine: | IMAGE_FILE_MACHINE_I386 |
| Number of sections: | 6 |
| Time date stamp: | 25-Apr-2012 00:38:18 |
| Pointer to Symbol Table: | 0x00000000 |
| Number of symbols: | 0 |
| Size of Optional Header: | 0x00E0 |
| Characteristics: |
|
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
|---|---|---|---|---|---|
.text | 0x00001000 | 0x000981C6 | 0x00098200 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.52544 |
.orpc | 0x0009A000 | 0x000001A2 | 0x00000200 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.77196 |
.rdata | 0x0009B000 | 0x00025D10 | 0x00025E00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.57958 |
.data | 0x000C1000 | 0x000079B8 | 0x00004A00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 5.0756 |
.rsrc | 0x000C9000 | 0x00030614 | 0x00030800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 3.97281 |
.reloc | 0x000FA000 | 0x0000BD72 | 0x0000BE00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 5.628 |
Title | Entropy | Size | Codepage | Language | Type |
|---|---|---|---|---|---|
1 | 5.02666 | 888 | Latin 1 / Western European | English - United States | RT_MANIFEST |
2 | 3.835 | 744 | Latin 1 / Western European | English - United States | RT_ICON |
3 | 3.35696 | 296 | Latin 1 / Western European | English - United States | RT_ICON |
4 | 6.14965 | 3752 | Latin 1 / Western European | English - United States | RT_ICON |
5 | 6.18448 | 2216 | Latin 1 / Western European | English - United States | RT_ICON |
6 | 4.85842 | 1384 | Latin 1 / Western European | English - United States | RT_ICON |
7 | 1.94502 | 72 | Latin 1 / Western European | English - United States | RT_STRING |
8 | 5.81004 | 4264 | Latin 1 / Western European | English - United States | RT_ICON |
9 | 6.06596 | 1128 | Latin 1 / Western European | English - United States | RT_ICON |
100 | 2.89097 | 132 | Latin 1 / Western European | English - United States | RT_GROUP_ICON |
ADVAPI32.dll |
KERNEL32.dll |
OLEAUT32.dll |
RPCRT4.dll |
SHELL32.dll |
USER32.dll |
VERSION.dll |
WINTRUST.dll |
msi.dll |
ole32.dll |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1484 | c:\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.exe install "c:\Program Files\Common Files\Microsoft Shared\VSTA\Pipeline.v10.0\AddInViews\Microsoft.VisualStudio.Tools.Applications.Runtime.v10.0.dll" /queue:3 /NoDependencies | c:\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.exe | — | MsiExec.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft Common Language Runtime native compiler Exit code: 0 Version: 4.6.1055.0 built by: NETFXREL2 | |||||||||||||||
| 1688 | vstor40_x86.exe /q | c:\0d2db275f52572465f5d484accdb\vstor40\vstor40_x86.exe | Setup.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft Visual Studio 2010 Tools for Office Runtime (x86) Setup Exit code: 0 Version: 10.0.40820.00 Modules
| |||||||||||||||
| 1816 | c:\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.exe install "c:\Program Files\Common Files\Microsoft Shared\VSTA\Pipeline.v10.0\AddInViews\Microsoft.VisualStudio.Tools.Applications.Runtime.v9.0.dll" /queue:3 /NoDependencies | c:\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.exe | — | MsiExec.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft Common Language Runtime native compiler Exit code: 0 Version: 4.6.1055.0 built by: NETFXREL2 | |||||||||||||||
| 1920 | c:\Windows\system32\MsiExec.exe -Embedding D9CE99C9ADA83463CCE98E75F6763231 M Global\MSI0000 | c:\Windows\system32\MsiExec.exe | — | msiexec.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2056 | c:\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.exe install "c:\Program Files\Common Files\Microsoft Shared\VSTA\Pipeline.v10.0\AddInSideAdapters\Microsoft.VisualStudio.Tools.Applications.AddInAdapter.v9.0.dll" /queue:3 /NoDependencies | c:\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.exe | — | MsiExec.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft Common Language Runtime native compiler Exit code: 0 Version: 4.6.1055.0 built by: NETFXREL2 | |||||||||||||||
| 2284 | C:\Windows\system32\msiexec.exe /V | C:\Windows\system32\msiexec.exe | services.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2296 | "C:\Users\admin\AppData\Local\Temp\{FA8D012D-D780-4A3A-86AE-0164F2D435C4}\{15965040-56BB-49B8-A88F-3525C48D9BA8}\vstor_redist.exe" | C:\Users\admin\AppData\Local\Temp\{FA8D012D-D780-4A3A-86AE-0164F2D435C4}\{15965040-56BB-49B8-A88F-3525C48D9BA8}\vstor_redist.exe | ExcelSetupx86.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft Visual Studio Tools for Office Runtime 2010 Redistributable Setup Exit code: 0 Version: 10.0.40820.00 Modules
| |||||||||||||||
| 2432 | c:\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.exe install "c:\Program Files\Common Files\Microsoft Shared\VSTA\Pipeline.v10.0\HostSideAdapters\Microsoft.VisualStudio.Tools.Applications.HostAdapter.v10.0.dll" /queue:3 /NoDependencies | c:\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.exe | — | MsiExec.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft Common Language Runtime native compiler Exit code: 0 Version: 4.6.1055.0 built by: NETFXREL2 | |||||||||||||||
| 2720 | c:\Windows\system32\MsiExec.exe -Embedding AA74B2D05FB715DB17818924A7E12253 | c:\Windows\system32\MsiExec.exe | — | msiexec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2808 | "C:\Users\admin\AppData\Local\Downloaded Installations\{596F34D7-732F-414A-A95D-69FD15BA836A}\ExcelSetupx86.exe" | C:\Users\admin\AppData\Local\Downloaded Installations\{596F34D7-732F-414A-A95D-69FD15BA836A}\ExcelSetupx86.exe | HP ALM Microsof Excel Add-In Setup.exe | ||||||||||||
User: admin Company: Hewlett-Packard Integrity Level: HIGH Description: HP ALM Addin Set Up Exit code: 0 Version: 12.20.0.377 Modules
| |||||||||||||||
| (PID) Process: | (3360) HP ALM Microsof Excel Add-In Setup.exe | Key: | HKEY_CURRENT_USER\Software\InstallShield\SuiteInstallers\{AFA5B66F-C0B3-4E55-A883-B4E92D08E4B7} |
| Operation: | write | Name: | InfoPath |
Value: C:\Users\admin\AppData\Local\Temp\{9A73D2C4-7194-4532-9F43-FF47CA5F7A64}\_isC867 | |||
| (PID) Process: | (3360) HP ALM Microsof Excel Add-In Setup.exe | Key: | HKEY_CURRENT_USER\Software\InstallShield\SuiteInstallers\{AFA5B66F-C0B3-4E55-A883-B4E92D08E4B7} |
| Operation: | write | Name: | Reboot |
Value: 1 | |||
| (PID) Process: | (3360) HP ALM Microsof Excel Add-In Setup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce |
| Operation: | write | Name: | {AFA5B66F-C0B3-4E55-A883-B4E92D08E4B7} |
Value: "C:\Users\admin\AppData\Local\Temp\HP ALM Microsof Excel Add-In Setup.exe" | |||
| (PID) Process: | (2808) ExcelSetupx86.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion |
| Operation: | write | Name: | %IS_PREREQ%-HP ALM Excel Addin x86 |
Value: 0 | |||
| (PID) Process: | (2808) ExcelSetupx86.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce |
| Operation: | write | Name: | ISSetupPrerequisistes |
Value: "C:\Users\admin\AppData\Local\Downloaded Installations\{596F34D7-732F-414A-A95D-69FD15BA836A}\ExcelSetupx86.exe" | |||
| (PID) Process: | (2808) ExcelSetupx86.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\ExcelSetupx86_RASAPI32 |
| Operation: | write | Name: | EnableFileTracing |
Value: 0 | |||
| (PID) Process: | (2808) ExcelSetupx86.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\ExcelSetupx86_RASAPI32 |
| Operation: | write | Name: | EnableConsoleTracing |
Value: 0 | |||
| (PID) Process: | (2808) ExcelSetupx86.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\ExcelSetupx86_RASAPI32 |
| Operation: | write | Name: | FileTracingMask |
Value: 4294901760 | |||
| (PID) Process: | (2808) ExcelSetupx86.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\ExcelSetupx86_RASAPI32 |
| Operation: | write | Name: | ConsoleTracingMask |
Value: 4294901760 | |||
| (PID) Process: | (2808) ExcelSetupx86.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\ExcelSetupx86_RASAPI32 |
| Operation: | write | Name: | MaxFileSize |
Value: 1048576 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2808 | ExcelSetupx86.exe | C:\Users\admin\AppData\Local\Temp\~E99B.tmp | — | |
MD5:— | SHA256:— | |||
| 2808 | ExcelSetupx86.exe | C:\Users\admin\AppData\Local\Temp\~E99C.tmp | — | |
MD5:— | SHA256:— | |||
| 3360 | HP ALM Microsof Excel Add-In Setup.exe | C:\Users\admin\AppData\Local\Temp\{9A73D2C4-7194-4532-9F43-FF47CA5F7A64}\setup.xml | xml | |
MD5:— | SHA256:— | |||
| 3360 | HP ALM Microsof Excel Add-In Setup.exe | C:\Users\admin\AppData\Local\Temp\{9A73D2C4-7194-4532-9F43-FF47CA5F7A64}\alm-small-logo.png | image | |
MD5:— | SHA256:— | |||
| 2808 | ExcelSetupx86.exe | C:\Users\admin\AppData\Local\Temp\_isE9CC..dll | — | |
MD5:— | SHA256:— | |||
| 3360 | HP ALM Microsof Excel Add-In Setup.exe | C:\Users\admin\AppData\Local\Temp\{9A73D2C4-7194-4532-9F43-FF47CA5F7A64}\_isC867 | text | |
MD5:— | SHA256:— | |||
| 3360 | HP ALM Microsof Excel Add-In Setup.exe | C:\Users\admin\AppData\Local\Temp\{9A73D2C4-7194-4532-9F43-FF47CA5F7A64}\Setup_UI.xml | text | |
MD5:— | SHA256:— | |||
| 2808 | ExcelSetupx86.exe | C:\Users\admin\AppData\Local\Temp\_isEA59..dll | — | |
MD5:— | SHA256:— | |||
| 3360 | HP ALM Microsof Excel Add-In Setup.exe | C:\Users\admin\AppData\Local\Temp\{9A73D2C4-7194-4532-9F43-FF47CA5F7A64}\alm-big-logo.png | image | |
MD5:— | SHA256:— | |||
| 3360 | HP ALM Microsof Excel Add-In Setup.exe | C:\Users\admin\AppData\Local\Downloaded Installations\{596F34D7-732F-414A-A95D-69FD15BA836A}\ExcelSetupx86.exe | executable | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2808 | ExcelSetupx86.exe | GET | — | 2.18.233.19:80 | http://download.microsoft.com/download/1/D/1/1D16DA35-34C2-47FB-9BA5-35EED9603C42/vstor_redist.exe | unknown | — | — | whitelisted |
2808 | ExcelSetupx86.exe | GET | 200 | 2.18.233.19:80 | http://download.microsoft.com/download/1/D/1/1D16DA35-34C2-47FB-9BA5-35EED9603C42/vstor_redist.exe | unknown | executable | 38.2 Mb | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2808 | ExcelSetupx86.exe | 2.18.233.19:80 | download.microsoft.com | Akamai International B.V. | — | whitelisted |
Domain | IP | Reputation |
|---|---|---|
download.microsoft.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
2808 | ExcelSetupx86.exe | A Network Trojan was detected | ET POLICY Installshield One Click Install User-Agent Toys File |
2808 | ExcelSetupx86.exe | Potential Corporate Privacy Violation | ET POLICY PE EXE or DLL Windows file download HTTP |
2808 | ExcelSetupx86.exe | Misc activity | ET INFO EXE - Served Attached HTTP |
2808 | ExcelSetupx86.exe | A Network Trojan was detected | ET POLICY Installshield One Click Install User-Agent Toys File |
2808 | ExcelSetupx86.exe | Potential Corporate Privacy Violation | ET POLICY PE EXE or DLL Windows file download HTTP |
2808 | ExcelSetupx86.exe | Misc activity | ET INFO EXE - Served Attached HTTP |