| File name: | f5epi_setup.exe |
| Full analysis: | https://app.any.run/tasks/a0d6b128-b9d3-471e-b799-7bf1fb95da38 |
| Verdict: | Malicious activity |
| Analysis date: | June 12, 2024, 14:39:26 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, InstallShield self-extracting archive |
| MD5: | 33CCEB813D55B041895CD6882E5EB782 |
| SHA1: | 7D0176EB8218A8E3982ACCA14BDC171740D94E45 |
| SHA256: | 24595EE7C0C56CF482AD3DAA173D060F5E9410CFC14118DFF2A9D2B40BEF03D4 |
| SSDEEP: | 98304:wzclPocfoqyqX5VvywhIcYuMiFXDfD7Np/3iiFE2yi5DVmtqXrR2O8Zz5OJnrKgb:wbQIjHf2 |
| .exe | | | Win64 Executable (generic) (64.6) |
|---|---|---|
| .dll | | | Win32 Dynamic Link Library (generic) (15.4) |
| .exe | | | Win32 Executable (generic) (10.5) |
| .exe | | | Generic Win/DOS Executable (4.6) |
| .exe | | | DOS Executable Generic (4.6) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2022:07:15 14:00:00+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, Large address aware, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 107520 |
| InitializedDataSize: | 20992 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x19d0c |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 22.1.0.0 |
| ProductVersionNumber: | 22.1.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Windows NT 32-bit |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| CompanyName: | Igor Pavlov |
| FileDescription: | 7z Setup SFX |
| FileVersion: | 22.01 |
| InternalName: | 7zS.sfx |
| LegalCopyright: | Copyright (c) 1999-2022 Igor Pavlov |
| OriginalFileName: | 7zS.sfx.exe |
| ProductName: | 7-Zip |
| ProductVersion: | 22.01 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1036 | "C:\Users\admin\AppData\Local\Temp\7zSC8FD7B10\cabinstaller.exe" | C:\Users\admin\AppData\Local\Temp\7zSC8FD7B10\cabinstaller.exe | cabinstaller.exe | ||||||||||||
User: admin Company: F5 Networks, Inc. Integrity Level: HIGH Description: F5 Networks Package installer Exit code: 0 Version: 7242, 2023, 0428, 0523 Modules
| |||||||||||||||
| 1184 | "C:\Windows\Downloaded Program Files\F5PolicyServer.exe" /RegServer | C:\Windows\Downloaded Program Files\F5PolicyServer.exe | — | cabinstaller.exe | |||||||||||
User: admin Company: F5 Networks, Inc. Integrity Level: HIGH Description: F5 Networks Client Policy Server Exit code: 0 Version: 7242, 2023, 0428, 0523 Modules
| |||||||||||||||
| 1284 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Google\Chrome\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Google\Chrome\User Data\Crashpad" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win32 --annotation=prod=Chrome --annotation=ver=109.0.5414.120 --initial-client-data=0xc8,0xcc,0xd0,0x9c,0xd4,0x6e058b38,0x6e058b48,0x6e058b54 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Version: 109.0.5414.120 Modules
| |||||||||||||||
| 1440 | "C:\Windows\Downloaded Program Files\f5epi.exe" /RegServer | C:\Windows\Downloaded Program Files\f5epi.exe | — | cabinstaller.exe | |||||||||||
User: admin Company: F5 Networks, Inc. Integrity Level: HIGH Description: F5 Networks Endpoint Inspector Exit code: 0 Version: 7242, 2023, 0428, 0523 Modules
| |||||||||||||||
| 1580 | C:\Windows\system32\DllHost.exe /Processid:{76D0CB12-7604-4048-B83C-1005C7DDC503} | C:\Windows\System32\dllhost.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: COM Surrogate Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1872 | "C:\Windows\Downloaded Program Files\f5unistall.exe" /createshortcut | C:\Windows\Downloaded Program Files\f5unistall.exe | cabinstaller.exe | ||||||||||||
User: admin Company: F5 Networks, Inc. Integrity Level: HIGH Description: F5 Networks Components Troubleshooting Exit code: 0 Version: 7242, 2023, 0428, 0523 Modules
| |||||||||||||||
| 1884 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --disable-quic --mojo-platform-channel-handle=1616 --field-trial-handle=1136,i,6255025830239531323,1639194313995039789,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Version: 109.0.5414.120 Modules
| |||||||||||||||
| 2012 | "C:\Program Files\Google\Chrome\Application\chrome.exe" "--disable-features=OptimizationGuideModelDownloading,OptimizationHintsFetching,OptimizationTargetPrediction,OptimizationHints" | C:\Program Files\Google\Chrome\Application\chrome.exe | — | explorer.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Version: 109.0.5414.120 Modules
| |||||||||||||||
| 2044 | "C:\Windows\Downloaded Program Files\F5InstH.exe" /RegServer | C:\Windows\Downloaded Program Files\F5InstH.exe | — | cabinstaller.exe | |||||||||||
User: admin Company: F5 Networks, Inc. Integrity Level: HIGH Description: F5 Networks InstallerHelper Module Exit code: 0 Version: 7242, 2023, 0428, 0523 Modules
| |||||||||||||||
| 2272 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --disable-quic --mojo-platform-channel-handle=1340 --field-trial-handle=1136,i,6255025830239531323,1639194313995039789,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Version: 109.0.5414.120 Modules
| |||||||||||||||
| (PID) Process: | (4012) cabinstaller.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (4012) cabinstaller.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (4012) cabinstaller.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (4012) cabinstaller.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (1036) cabinstaller.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (1036) cabinstaller.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (1036) cabinstaller.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (1036) cabinstaller.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (1036) cabinstaller.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (1036) cabinstaller.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Root\Certificates |
| Operation: | delete value | Name: | 9F6134C5FA75E4FDDE631B232BE961D6D4B97DB6 |
Value: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3980 | f5epi_setup.exe | C:\Users\admin\AppData\Local\Temp\7zSC8FD7B10\cabinstaller.exe | executable | |
MD5:F4CD1E2275BA8F1D68A748218CDA8292 | SHA256:9AAF2C27509E85FF84039EB3830E81274DBEA4B182DE17127808E533F622ED2B | |||
| 1036 | cabinstaller.exe | C:\Users\admin\AppData\Local\Temp\F5_TMP_18294131996318232235\InstallerControl.cab | compressed | |
MD5:E610B7BCD64D109F1393F58CDE9E5928 | SHA256:7733C43DEC66D94DAD70749B308119CA3D1999116C2F084D818585DF063CB3BE | |||
| 3980 | f5epi_setup.exe | C:\Users\admin\AppData\Local\Temp\7zSC8FD7B10\setup.inf | text | |
MD5:55C70C470A2BFC0EF22130122167A927 | SHA256:CAB189E3BEF7166E8381DC5D0274071E8DD4479A0C964013BB8494693C418C9A | |||
| 3980 | f5epi_setup.exe | C:\Users\admin\AppData\Local\Temp\7zSC8FD7B10\f5InspectionHost.cab | compressed | |
MD5:7FD28B817A96C76A1DEA0BAA60A0A909 | SHA256:6255708B24CF96667A946B0100888A7B9F1947EF445D908C4BEA0D3B907A1033 | |||
| 3980 | f5epi_setup.exe | C:\Users\admin\AppData\Local\Temp\7zSC8FD7B10\InstallerControl.cab | compressed | |
MD5:E610B7BCD64D109F1393F58CDE9E5928 | SHA256:7733C43DEC66D94DAD70749B308119CA3D1999116C2F084D818585DF063CB3BE | |||
| 1036 | cabinstaller.exe | C:\Windows\Downloaded Program Files\F5InstH.exe | executable | |
MD5:6527CC32ECAD96BA796CBFE7CF8591BC | SHA256:92C0A1C7D00F408EE580DFF2A05C38ABE3E2A8FE1412B977904B2619359DA98B | |||
| 1036 | cabinstaller.exe | C:\Users\admin\AppData\Local\Temp\F5_TMP_18294131996318232235\uregsvr.exe | executable | |
MD5:290D1BA6ADEADF03D0F3D04D26956D0A | SHA256:5EEC4212F157FBBA420331FC4C71505F78990FD99C64B2DE39320687B75E99EB | |||
| 1036 | cabinstaller.exe | C:\Windows\Downloaded Program Files\uregsvr.exe | executable | |
MD5:290D1BA6ADEADF03D0F3D04D26956D0A | SHA256:5EEC4212F157FBBA420331FC4C71505F78990FD99C64B2DE39320687B75E99EB | |||
| 1036 | cabinstaller.exe | C:\Users\admin\AppData\Local\Temp\F5_TMP_18294131996318232235\InstallerControl.inf | text | |
MD5:F9FA0545B96F1B7BF98CB36F18E1904E | SHA256:630AB59E7A9E6F0838735722F15360F248A86815BCEC2D1679CC232E1A5801EE | |||
| 1036 | cabinstaller.exe | C:\Windows\Downloaded Program Files\InstallerControl.dll | executable | |
MD5:AF27E9033157B41B347BEB18F0B79694 | SHA256:A2F334269297EC46F321B51F98BEC49659582E0B5B613A8C962BF7C5BF7399A3 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1088 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |