File name:

SecuriteInfo.com.decompression.bomb.7964.8235

Full analysis: https://app.any.run/tasks/ec0a0247-e5eb-4807-931b-2b4c2acc8ed2
Verdict: Malicious activity
Analysis date: October 27, 2023, 04:06:27
OS: Windows 7 Professional Service Pack 1 (build: 7601, 64 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

42E1C69F630C8F718FF0417602C409B1

SHA1:

661BC31F6F89FDD9511574F8E1ECD843ED80A739

SHA256:

1D57B5247C3DF074D866FB036F64F5630EE8CA5814077803E3A1AD9504732C1A

SSDEEP:

98304:Ju0i+Veaq8/szm8NbAKw1N/efyzlpL0XWpVNiL9H/DNKVo5S3M/DQNeudLUJsVnN:1ZIFCdE+

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • SecuriteInfo.com.decompression.bomb.7964.8235.exe (PID: 2204)
      • SecuriteInfo.com.decompression.bomb.7964.8235.tmp (PID: 1512)
      • SecuriteInfo.com.decompression.bomb.7964.8235.exe (PID: 1980)
    • Loads dropped or rewritten executable

      • SecuriteInfo.com.decompression.bomb.7964.8235.tmp (PID: 1512)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • SecuriteInfo.com.decompression.bomb.7964.8235.tmp (PID: 1512)
    • Reads the Windows owner or organization settings

      • SecuriteInfo.com.decompression.bomb.7964.8235.tmp (PID: 1512)
  • INFO

    • Checks supported languages

      • SecuriteInfo.com.decompression.bomb.7964.8235.tmp (PID: 1584)
      • SecuriteInfo.com.decompression.bomb.7964.8235.exe (PID: 2204)
      • SecuriteInfo.com.decompression.bomb.7964.8235.tmp (PID: 1512)
      • SecuriteInfo.com.decompression.bomb.7964.8235.exe (PID: 1980)
    • Reads the computer name

      • SecuriteInfo.com.decompression.bomb.7964.8235.tmp (PID: 1584)
      • SecuriteInfo.com.decompression.bomb.7964.8235.tmp (PID: 1512)
    • Create files in a temporary directory

      • SecuriteInfo.com.decompression.bomb.7964.8235.exe (PID: 1980)
      • SecuriteInfo.com.decompression.bomb.7964.8235.tmp (PID: 1512)
      • SecuriteInfo.com.decompression.bomb.7964.8235.exe (PID: 2204)
    • Application was dropped or rewritten from another process

      • SecuriteInfo.com.decompression.bomb.7964.8235.tmp (PID: 1512)
      • SecuriteInfo.com.decompression.bomb.7964.8235.tmp (PID: 1584)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (77.7)
.exe | Win32 Executable Delphi generic (10)
.dll | Win32 Dynamic Link Library (generic) (4.6)
.exe | Win32 Executable (generic) (3.1)
.exe | Win16/32 Executable Delphi generic (1.4)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 1992:06:20 00:22:17+02:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 37888
InitializedDataSize: 43520
UninitializedDataSize: -
EntryPoint: 0x9b80
OSVersion: 1
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 0.0.0.0
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Chinese (Simplified)
CharacterSet: ASCII
Comments: 此安装程序由 Inno Setup 构建。
CompanyName: Aodun Software, Ltd.
FileDescription: 傲盾加速器 5.70 Setup
FileVersion: 5.70
LegalCopyright: Aodun Software, Ltd.
ProductName: 傲盾加速器 5.70
ProductVersion: 5.70
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
36
Monitored processes
4
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
drop and start start drop and start securiteinfo.com.decompression.bomb.7964.8235.exe no specs securiteinfo.com.decompression.bomb.7964.8235.tmp no specs securiteinfo.com.decompression.bomb.7964.8235.exe securiteinfo.com.decompression.bomb.7964.8235.tmp no specs

Process information

PID
CMD
Path
Indicators
Parent process
1512"C:\Users\admin\AppData\Local\Temp\is-7SHJS.tmp\SecuriteInfo.com.decompression.bomb.7964.8235.tmp" /SL5="$1E01AC,8914699,82432,C:\Users\admin\AppData\Local\Temp\SecuriteInfo.com.decompression.bomb.7964.8235.exe" /SPAWNWND=$100170 /NOTIFYWND=$1D01B6 C:\Users\admin\AppData\Local\Temp\is-7SHJS.tmp\SecuriteInfo.com.decompression.bomb.7964.8235.tmpSecuriteInfo.com.decompression.bomb.7964.8235.exe
User:
admin
Integrity Level:
HIGH
Description:
安装/卸载
Exit code:
0
Version:
51.52.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-7shjs.tmp\securiteinfo.com.decompression.bomb.7964.8235.tmp
c:\windows\syswow64\ntdll.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\kernelbase.dll
1584"C:\Users\admin\AppData\Local\Temp\is-EEOTE.tmp\SecuriteInfo.com.decompression.bomb.7964.8235.tmp" /SL5="$1D01B6,8914699,82432,C:\Users\admin\AppData\Local\Temp\SecuriteInfo.com.decompression.bomb.7964.8235.exe" C:\Users\admin\AppData\Local\Temp\is-EEOTE.tmp\SecuriteInfo.com.decompression.bomb.7964.8235.tmpSecuriteInfo.com.decompression.bomb.7964.8235.exe
User:
admin
Integrity Level:
MEDIUM
Description:
安装/卸载
Exit code:
0
Version:
51.52.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-eeote.tmp\securiteinfo.com.decompression.bomb.7964.8235.tmp
c:\windows\syswow64\ntdll.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\kernelbase.dll
1980"C:\Users\admin\AppData\Local\Temp\SecuriteInfo.com.decompression.bomb.7964.8235.exe" /SPAWNWND=$100170 /NOTIFYWND=$1D01B6 C:\Users\admin\AppData\Local\Temp\SecuriteInfo.com.decompression.bomb.7964.8235.exe
SecuriteInfo.com.decompression.bomb.7964.8235.tmp
User:
admin
Company:
Aodun Software, Ltd.
Integrity Level:
HIGH
Description:
傲盾加速器 5.70 Setup
Exit code:
0
Version:
5.70
Modules
Images
c:\users\admin\appdata\local\temp\securiteinfo.com.decompression.bomb.7964.8235.exe
c:\windows\syswow64\ntdll.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\kernelbase.dll
2204"C:\Users\admin\AppData\Local\Temp\SecuriteInfo.com.decompression.bomb.7964.8235.exe" C:\Users\admin\AppData\Local\Temp\SecuriteInfo.com.decompression.bomb.7964.8235.exeexplorer.exe
User:
admin
Company:
Aodun Software, Ltd.
Integrity Level:
MEDIUM
Description:
傲盾加速器 5.70 Setup
Exit code:
0
Version:
5.70
Modules
Images
c:\users\admin\appdata\local\temp\securiteinfo.com.decompression.bomb.7964.8235.exe
c:\windows\syswow64\ntdll.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\kernelbase.dll
Total events
834
Read events
834
Write events
0
Delete events
0

Modification events

No data
Executable files
5
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
1512SecuriteInfo.com.decompression.bomb.7964.8235.tmpC:\Users\admin\AppData\Local\Temp\is-691RG.tmp\_isetup\_setup64.tmpexecutable
MD5:4FF75F505FDDCC6A9AE62216446205D9
SHA256:A4C86FC4836AC728D7BD96E7915090FD59521A9E74F1D06EF8E5A47C8695FD81
1512SecuriteInfo.com.decompression.bomb.7964.8235.tmpC:\Users\admin\AppData\Local\Temp\is-691RG.tmp\_isetup\_shfoldr.dllexecutable
MD5:92DC6EF532FBB4A5C3201469A5B5EB63
SHA256:9884E9D1B4F8A873CCBD81F8AD0AE257776D2348D027D811A56475E028360D87
1980SecuriteInfo.com.decompression.bomb.7964.8235.exeC:\Users\admin\AppData\Local\Temp\is-7SHJS.tmp\SecuriteInfo.com.decompression.bomb.7964.8235.tmpexecutable
MD5:B9471CF24E3B8894916A04906335B871
SHA256:6F0753D49B9E12676D3BF39AD206681CF7CC3A776C21C4778CEFBC068816DFD6
2204SecuriteInfo.com.decompression.bomb.7964.8235.exeC:\Users\admin\AppData\Local\Temp\is-EEOTE.tmp\SecuriteInfo.com.decompression.bomb.7964.8235.tmpexecutable
MD5:B9471CF24E3B8894916A04906335B871
SHA256:6F0753D49B9E12676D3BF39AD206681CF7CC3A776C21C4778CEFBC068816DFD6
1512SecuriteInfo.com.decompression.bomb.7964.8235.tmpC:\Users\admin\AppData\Local\Temp\is-691RG.tmp\_isetup\_RegDLL.tmpexecutable
MD5:4248FA25D2F50EBE23EAD46140933013
SHA256:5200596D2349CD7FEB4DBD4C78EB7D67FE334838460A3C290575A4B3E4CC6633
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
6
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
324
svchost.exe
224.0.0.252:5355
unknown
1956
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:138
whitelisted

DNS requests

No data

Threats

No threats detected
No debug info