File name:

BSINSTALL.exe

Full analysis: https://app.any.run/tasks/4bbff5de-fe2b-4b3f-ba28-f429595a301a
Verdict: Malicious activity
Analysis date: August 31, 2018, 18:24:05
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
installer
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

0E9D923B97FA3CB3C0FA4B4745C734E7

SHA1:

14A3E50A4F82922C8CA992818AAA5B8A9C8E4890

SHA256:

20F60E2F1F21062EFE3EE870CA3E28E958219C01320A2EB599732F9B4C5FB293

SSDEEP:

49152:ukMUmJ3sOpVspklvTfg5JEV5OhJZ7beLvzC3j8mq79CjUa9UjQ0864bjk+:xMtJ3sOwKJfKjJZ7beLv23IH7WJ9Ujvc

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • GLB72CD.tmp (PID: 2072)
      • SAVEIN~1.EXE (PID: 3920)
      • Weather.exe (PID: 3140)
      • Save.exe (PID: 2896)
      • BearShare.exe (PID: 768)
      • BearShare.exe (PID: 2828)
    • Loads dropped or rewritten executable

      • GLB72CD.tmp (PID: 2072)
      • regsvr32.exe (PID: 2628)
    • Registers / Runs the DLL via REGSVR32.EXE

      • GLB72CD.tmp (PID: 2072)
    • Changes the autorun value in the registry

      • GLB72CD.tmp (PID: 2072)
      • SAVEIN~1.EXE (PID: 3920)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • GLB72CD.tmp (PID: 2072)
      • BSINSTALL.exe (PID: 2148)
      • SAVEIN~1.EXE (PID: 3920)
    • Removes files from Windows directory

      • GLB72CD.tmp (PID: 2072)
    • Starts application with an unusual extension

      • BSINSTALL.exe (PID: 2148)
    • Creates files in the Windows directory

      • GLB72CD.tmp (PID: 2072)
    • Creates files in the program directory

      • GLB72CD.tmp (PID: 2072)
      • SAVEIN~1.EXE (PID: 3920)
      • Save.exe (PID: 2896)
    • Creates a software uninstall entry

      • GLB72CD.tmp (PID: 2072)
      • SAVEIN~1.EXE (PID: 3920)
    • Creates COM task schedule object

      • regsvr32.exe (PID: 2628)
    • Modifies the open verb of a shell class

      • GLB72CD.tmp (PID: 2072)
    • Creates files in the user directory

      • SAVEIN~1.EXE (PID: 3920)
    • Reads internet explorer settings

      • Save.exe (PID: 2896)
      • Weather.exe (PID: 3140)
    • Application launched itself

      • BearShare.exe (PID: 768)
  • INFO

    • Dropped object may contain URL's

      • GLB72CD.tmp (PID: 2072)
      • SAVEIN~1.EXE (PID: 3920)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Wise Installer executable (91.7)
.exe | Win64 Executable (generic) (5.3)
.dll | Win32 Dynamic Link Library (generic) (1.2)
.exe | Win32 Executable (generic) (0.8)
.exe | Generic Win/DOS Executable (0.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 1999:04:08 22:24:47+02:00
PEType: PE32
LinkerVersion: 6
CodeSize: 512
InitializedDataSize: 2967040
UninitializedDataSize: -
EntryPoint: 0x1000
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 4.3.2.12
ProductVersionNumber: 4.3.2.12
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows 16-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
CompanyName: Free Peers, Inc.
FileDescription: BearShare Installer
FileVersion: 4.3.2.12
LegalCopyright: Copyright (C) 2001 Free Peers, Inc.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
45
Monitored processes
9
Malicious processes
5
Suspicious processes
1

Behavior graph

Click at the process to see the details
drop and start start drop and start drop and start drop and start drop and start bsinstall.exe glb72cd.tmp regsvr32.exe no specs savein~1.exe save.exe no specs weather.exe bearshare.exe no specs bearshare.exe no specs bsinstall.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
768"C:\Program Files\BearShare\BearShare.exe" C:\Program Files\BearShare\BearShare.exeGLB72CD.tmp
User:
admin
Company:
Free Peers, Inc.
Integrity Level:
HIGH
Description:
BearShare
Exit code:
0
Version:
4.3.2.12
Modules
Images
c:\progra~1\bearsh~1\bearsh~1.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\apphelp.dll
2072C:\Users\admin\AppData\Local\Temp\GLB72CD.tmp 4736 C:\Users\admin\AppData\Local\Temp\BSINST~1.EXEC:\Users\admin\AppData\Local\Temp\GLB72CD.tmp
BSINSTALL.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\glb72cd.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2148"C:\Users\admin\AppData\Local\Temp\BSINSTALL.exe" C:\Users\admin\AppData\Local\Temp\BSINSTALL.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\bsinstall.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\apphelp.dll
2628"C:\Windows\System32\regsvr32.exe" /s "C:\Program Files\BearShare\RunMSC.dll"C:\Windows\System32\regsvr32.exeGLB72CD.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2828"C:\Program Files\BearShare\BearShare.exe" C:\Program Files\BearShare\BearShare.exeBearShare.exe
User:
admin
Company:
Free Peers, Inc.
Integrity Level:
HIGH
Description:
BearShare
Exit code:
0
Version:
4.3.2.12
Modules
Images
c:\progra~1\bearsh~1\bearsh~1.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\apphelp.dll
2896"C:\Program Files\Save\Save.exe" C:\Program Files\Save\Save.exeSAVEIN~1.EXE
User:
admin
Company:
WhenU.com, Inc.
Integrity Level:
HIGH
Description:
Save!
Exit code:
0
Version:
2, 5, 4, 1
Modules
Images
c:\program files\save\save.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
3140"C:\Program Files\WeatherCast\Weather.exe" /qC:\Program Files\WeatherCast\Weather.exe
SAVEIN~1.EXE
User:
admin
Integrity Level:
HIGH
Description:
Weather
Exit code:
0
Version:
1, 5, 1, 1
Modules
Images
c:\program files\weathercast\weather.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
3188"C:\Users\admin\AppData\Local\Temp\BSINSTALL.exe" C:\Users\admin\AppData\Local\Temp\BSINSTALL.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\appdata\local\temp\bsinstall.exe
c:\systemroot\system32\ntdll.dll
3920"C:\Users\admin\AppData\Local\Temp\SAVEIN~1.EXE" /tEEPE1702 /d"BearShare" /f"C:\Program Files\BearShare\BearShare.exe" /o"zip=95811" /xC:\Users\admin\AppData\Local\Temp\SAVEIN~1.EXE
GLB72CD.tmp
User:
admin
Company:
WhenU.com, Inc.
Integrity Level:
HIGH
Description:
Save! Setup
Exit code:
0
Version:
2, 5, 4, 1
Modules
Images
c:\users\admin\appdata\local\temp\savein~1.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
Total events
898
Read events
698
Write events
193
Delete events
7

Modification events

(PID) Process:(2072) GLB72CD.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BearShare
Operation:writeName:DisplayName
Value:
BearShare
(PID) Process:(2072) GLB72CD.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BearShare
Operation:writeName:UninstallString
Value:
C:\PROGRA~1\BEARSH~1\UNWISE.EXE C:\PROGRA~1\BEARSH~1\INSTALL.LOG
(PID) Process:(2072) GLB72CD.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.gnu
Operation:writeName:
Value:
gnufile
(PID) Process:(2072) GLB72CD.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\gnufile
Operation:writeName:
Value:
gnutella
(PID) Process:(2072) GLB72CD.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\gnufile
Operation:writeName:BrowserFlags
Value:
8
(PID) Process:(2072) GLB72CD.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\gnufile
Operation:writeName:EditFlags
Value:
65536
(PID) Process:(2072) GLB72CD.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\gnufile\shell\open\command
Operation:writeName:
Value:
"C:\Program Files\BearShare\BearShare.exe" "%1"
(PID) Process:(2072) GLB72CD.tmpKey:HKEY_CURRENT_USER\AppEvents\EventLabels\BearShareChatNotifyMsg
Operation:writeName:
Value:
Chat Message Waiting
(PID) Process:(2072) GLB72CD.tmpKey:HKEY_CURRENT_USER\AppEvents\Schemes\Apps\BearShare
Operation:writeName:
Value:
BearShare
(PID) Process:(2072) GLB72CD.tmpKey:HKEY_CURRENT_USER\AppEvents\Schemes\Apps\BearShare\BearShareChatNotifyMsg
Operation:writeName:
Value:
Executable files
14
Suspicious files
1
Text files
50
Unknown types
11

Dropped files

PID
Process
Filename
Type
2072GLB72CD.tmpC:\Users\admin\AppData\Local\Temp\~GLH0000.TMP
MD5:
SHA256:
2072GLB72CD.tmpC:\Users\admin\AppData\Local\Temp\~GLH0001.TMP
MD5:
SHA256:
2072GLB72CD.tmpC:\Users\admin\AppData\Local\Temp\~GLH0002.TMP
MD5:
SHA256:
2072GLB72CD.tmpC:\Program Files\BearShare\~GLH0003.TMP
MD5:
SHA256:
2072GLB72CD.tmpC:\Program Files\BearShare\~GLH0004.TMP
MD5:
SHA256:
2072GLB72CD.tmpC:\Program Files\BearShare\~GLH0005.TMP
MD5:
SHA256:
2072GLB72CD.tmpC:\Program Files\BearShare\~GLH0006.TMP
MD5:
SHA256:
2072GLB72CD.tmpC:\Program Files\BearShare\~GLH0007.TMP
MD5:
SHA256:
2072GLB72CD.tmpC:\Program Files\BearShare\~GLH0008.TMP
MD5:
SHA256:
2072GLB72CD.tmpC:\Program Files\BearShare\sounds\~GLH0009.TMP
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
4
DNS requests
4
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3140
Weather.exe
GET
66.152.85.202:80
http://web.whenu.com/heartbeat?program=weather&partner=EEPE1702&id=EB9E47573EEC48DAA9379BF56D43D27C&ver=1.51&zip=95811
CA
unknown
3140
Weather.exe
GET
66.152.85.200:80
http://spapp.whenu.com/WeatherDB
CA
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
172.217.20.110:80
Google Inc.
US
whitelisted
3140
Weather.exe
66.152.85.202:80
web.whenu.com
Gamma Networking Inc.
CA
unknown
3140
Weather.exe
66.152.85.200:80
spapp.whenu.com
Gamma Networking Inc.
CA
unknown

DNS requests

Domain
IP
Reputation
dns.msftncsi.com
  • 131.107.255.255
shared
web.whenu.com
  • 66.152.85.202
unknown
spapp.whenu.com
  • 66.152.85.200
unknown

Threats

No threats detected
No debug info