File name:

csvtovcard_setup.exe

Full analysis: https://app.any.run/tasks/7348e6a7-6002-4a5b-ad5e-1eb4c87c4831
Verdict: Malicious activity
Analysis date: November 20, 2023, 14:20:07
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

7B2F0C64EC1F05177D7E456A182F64C5

SHA1:

757E2FEF8E27D41837BE368095432A0F39AF6F70

SHA256:

1E6B9CB70E187AB7F28F5D7F6F2AADE2441DDA0C316E3A0AF407145707BCA67E

SSDEEP:

6144:AZrdCPcgBCFb9iV2in2YvjsvTWXvkmby66SnlmAeIc5hagbkGfPi/VZhp:erdghBmhI26vjCTWXvjmNSkAVyhScahp

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • csvtovcard_setup.exe (PID: 3384)
      • csvtovcard_setup.exe (PID: 3508)
      • csvtovcard_setup.tmp (PID: 3472)
  • SUSPICIOUS

    • Reads the Windows owner or organization settings

      • csvtovcard_setup.tmp (PID: 3472)
    • Process drops legitimate windows executable

      • csvtovcard_setup.tmp (PID: 3472)
    • Reads Internet Explorer settings

      • csvtovcard.exe (PID: 3276)
  • INFO

    • Checks supported languages

      • csvtovcard_setup.exe (PID: 3384)
      • csvtovcard_setup.exe (PID: 3508)
      • csvtovcard_setup.tmp (PID: 3472)
      • csvtovcard.exe (PID: 3276)
      • csvtovcard_setup.tmp (PID: 3440)
      • wmpnscfg.exe (PID: 2112)
    • Reads the computer name

      • csvtovcard_setup.tmp (PID: 3440)
      • csvtovcard.exe (PID: 3276)
      • csvtovcard_setup.tmp (PID: 3472)
      • wmpnscfg.exe (PID: 2112)
    • Create files in a temporary directory

      • csvtovcard_setup.exe (PID: 3384)
      • csvtovcard_setup.exe (PID: 3508)
      • csvtovcard_setup.tmp (PID: 3472)
    • Manual execution by a user

      • WINWORD.EXE (PID: 3756)
      • WINWORD.EXE (PID: 3732)
      • WINWORD.EXE (PID: 3532)
      • chrome.exe (PID: 3616)
      • wmpnscfg.exe (PID: 2112)
    • Creates files in the program directory

      • csvtovcard_setup.tmp (PID: 3472)
    • Application launched itself

      • chrome.exe (PID: 3616)
    • Reads the machine GUID from the registry

      • wmpnscfg.exe (PID: 2112)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (71.1)
.exe | Win32 Executable Delphi generic (9.1)
.scr | Windows screen saver (8.4)
.dll | Win32 Dynamic Link Library (generic) (4.2)
.exe | Win32 Executable (generic) (2.9)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 1992:06:20 00:22:17+02:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 40448
InitializedDataSize: 17920
UninitializedDataSize: -
EntryPoint: 0xa5f8
OSVersion: 1
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 0.0.0.0
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: csvtovcard.com
FileDescription: CSV to vCard Setup
FileVersion:
LegalCopyright:
ProductName: CSV to vCard
ProductVersion:
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
62
Monitored processes
21
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
start csvtovcard_setup.exe no specs csvtovcard_setup.tmp no specs csvtovcard_setup.exe csvtovcard_setup.tmp no specs csvtovcard.exe no specs winword.exe no specs winword.exe no specs winword.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs wmpnscfg.exe no specs chrome.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
528"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1120 --field-trial-handle=1172,i,9631778059746665402,16563413852657030133,131072 /prefetch:2C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
588"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --first-renderer-process --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --mojo-platform-channel-handle=2104 --field-trial-handle=1172,i,9631778059746665402,16563413852657030133,131072 /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
756"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Google\Chrome\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Google\Chrome\User Data\Crashpad" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win32 --annotation=prod=Chrome --annotation=ver=109.0.5414.120 --initial-client-data=0xc8,0xcc,0xd0,0x9c,0xd4,0x64a48b38,0x64a48b48,0x64a48b54C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1660"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=1540 --field-trial-handle=1172,i,9631778059746665402,16563413852657030133,131072 /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1700"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3512 --field-trial-handle=1172,i,9631778059746665402,16563413852657030133,131072 /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1812"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=2116 --field-trial-handle=1172,i,9631778059746665402,16563413852657030133,131072 /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1816"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1344 --field-trial-handle=1172,i,9631778059746665402,16563413852657030133,131072 /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exe
chrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
2112"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\ole32.dll
2640"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --use-gl=angle --use-angle=swiftshader-webgl --mojo-platform-channel-handle=1548 --field-trial-handle=1172,i,9631778059746665402,16563413852657030133,131072 /prefetch:2C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
2880"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=3072 --field-trial-handle=1172,i,9631778059746665402,16563413852657030133,131072 /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
Total events
8 051
Read events
7 483
Write events
128
Delete events
440

Modification events

(PID) Process:(3472) csvtovcard_setup.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:RegFilesHash
Value:
6F8C75DDD695099621ED856942367F09109E6F73D7A1E8B553C47DA8B755F02D
(PID) Process:(3472) csvtovcard_setup.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:RegFiles0000
Value:
C:\Program Files\CSV to vCard\csvtovcard.exe
(PID) Process:(3472) csvtovcard_setup.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:Sequence
Value:
1
(PID) Process:(3472) csvtovcard_setup.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:SessionHash
Value:
C20525854F8C4350F4C0C68E0E62E4BDCE92470F893310F12B65360AE8B83142
(PID) Process:(3472) csvtovcard_setup.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:Owner
Value:
900D000004900EAEBC1BDA01
(PID) Process:(3472) csvtovcard_setup.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete keyName:(default)
Value:
(PID) Process:(3756) WINWORD.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1033
Value:
On
(PID) Process:(3756) WINWORD.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1041
Value:
On
(PID) Process:(3756) WINWORD.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1046
Value:
On
(PID) Process:(3756) WINWORD.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1036
Value:
On
Executable files
8
Suspicious files
72
Text files
30
Unknown types
0

Dropped files

PID
Process
Filename
Type
3756WINWORD.EXEC:\Users\admin\AppData\Local\Temp\CVR472A.tmp.cvr
MD5:
SHA256:
3472csvtovcard_setup.tmpC:\Program Files\CSV to vCard\is-T95VI.tmptext
MD5:C6F591E082525FA0066C5742B56F07D5
SHA256:21A474D891D6302696C0FE83DF2B5C51EA2152065FD4F22360CACCFE0FCB03F1
3732WINWORD.EXEC:\Users\admin\AppData\Local\Temp\CVR6522.tmp.cvr
MD5:
SHA256:
3472csvtovcard_setup.tmpC:\ProgramData\Microsoft\Windows\Start Menu\Programs\CSV to vCard\CSV to vCard.lnkbinary
MD5:73ADF76834AD161A69410256D02ACFB5
SHA256:9DED682371111176E7618935E3223B40E116E1A2D0D76F844061946F4F917D37
3472csvtovcard_setup.tmpC:\Users\Public\Desktop\CSV to vCard.lnkbinary
MD5:D5A874901E623CE1EDA2A30A3ACBA4B2
SHA256:612E992281EAF62FA00344CAD06CD56421D8B7ED66330382C5EFBFD659D677A4
3472csvtovcard_setup.tmpC:\Program Files\CSV to vCard\unins000.exeexecutable
MD5:36B6923A995D6326F16EBC6B8F84A895
SHA256:58CE666D6AF980EF137906758856B25984F568F0C3AEA26103F336C983D8560A
3472csvtovcard_setup.tmpC:\Program Files\CSV to vCard\unins000.datbinary
MD5:B79B4B6FE18F9823D74FA5EC4F23FF3D
SHA256:DA6705D9A8105607F6B78B860FB4AF6FA47AA4FBA9C2EEE7E8708FF502A60B5E
3472csvtovcard_setup.tmpC:\Program Files\CSV to vCard\is-I4FO7.tmpexecutable
MD5:36B6923A995D6326F16EBC6B8F84A895
SHA256:58CE666D6AF980EF137906758856B25984F568F0C3AEA26103F336C983D8560A
3472csvtovcard_setup.tmpC:\Program Files\CSV to vCard\csvtovcard.exeexecutable
MD5:FF48BF4E933C110BA4F1BFD9D531D315
SHA256:80A8B6DB6F5D5DB1ECEF7B1590E6200607333709335F94D1082489ECE08371AC
3532WINWORD.EXEC:\Users\admin\AppData\Local\Temp\CVR803C.tmp.cvr
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
15
DNS requests
15
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:137
whitelisted
2588
svchost.exe
239.255.255.250:1900
whitelisted
1816
chrome.exe
142.250.186.77:443
accounts.google.com
GOOGLE
US
unknown
3616
chrome.exe
239.255.255.250:1900
whitelisted
1816
chrome.exe
142.250.186.100:443
www.google.com
GOOGLE
US
whitelisted
1816
chrome.exe
142.250.186.163:443
clientservices.googleapis.com
GOOGLE
US
whitelisted
1816
chrome.exe
142.250.185.99:443
www.gstatic.com
GOOGLE
US
whitelisted
1816
chrome.exe
142.250.185.142:443
apis.google.com
GOOGLE
US
whitelisted

DNS requests

Domain
IP
Reputation
clientservices.googleapis.com
  • 142.250.186.163
whitelisted
accounts.google.com
  • 142.250.186.77
shared
www.google.com
  • 142.250.186.100
whitelisted
www.gstatic.com
  • 142.250.185.99
whitelisted
apis.google.com
  • 142.250.185.142
whitelisted
update.googleapis.com
  • 172.217.23.99
whitelisted

Threats

No threats detected
No debug info