URL:

www.microsys.ro

Full analysis: https://app.any.run/tasks/f057617c-b283-4aee-8312-d99023e32aae
Verdict: Malicious activity
Analysis date: October 20, 2023, 19:58:35
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
SHA1:

B083DC87E77EF5B242083739763EB0DC8F770B97

SHA256:

281E681301C248105C96BADFBD4DC2D737FF44AD45ED31C05CC36C41890BB17F

SSDEEP:

3:Edvh:U

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • saturnsetup.exe (PID: 4060)
      • saturnsetup.exe (PID: 2096)
    • Drops the executable file immediately after the start

      • saturnsetup.exe (PID: 4060)
      • saturnsetup.exe (PID: 2096)
      • saturnsetup.tmp (PID: 2520)
  • SUSPICIOUS

    • Reads the Windows owner or organization settings

      • saturnsetup.tmp (PID: 2520)
  • INFO

    • Application launched itself

      • iexplore.exe (PID: 1764)
    • Drops the executable file immediately after the start

      • iexplore.exe (PID: 3768)
    • The process uses the downloaded file

      • iexplore.exe (PID: 1764)
    • Create files in a temporary directory

      • saturnsetup.exe (PID: 4060)
      • saturnsetup.exe (PID: 2096)
    • Checks supported languages

      • saturnsetup.exe (PID: 4060)
      • saturnsetup.tmp (PID: 1628)
      • saturnsetup.exe (PID: 2096)
      • saturnsetup.tmp (PID: 2520)
      • Saturn.exe (PID: 4008)
      • Saturn.exe (PID: 2920)
    • Reads the computer name

      • saturnsetup.tmp (PID: 1628)
      • saturnsetup.tmp (PID: 2520)
      • Saturn.exe (PID: 2920)
      • Saturn.exe (PID: 4008)
    • Application was dropped or rewritten from another process

      • saturnsetup.tmp (PID: 1628)
      • saturnsetup.tmp (PID: 2520)
    • Creates files in the program directory

      • saturnsetup.tmp (PID: 2520)
    • Reads the machine GUID from the registry

      • Saturn.exe (PID: 4008)
      • Saturn.exe (PID: 2920)
    • Manual execution by a user

      • Saturn.exe (PID: 4008)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
50
Monitored processes
8
Malicious processes
5
Suspicious processes
0

Behavior graph

Click at the process to see the details
start drop and start drop and start iexplore.exe iexplore.exe saturnsetup.exe no specs saturnsetup.tmp no specs saturnsetup.exe saturnsetup.tmp no specs saturn.exe no specs saturn.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1628"C:\Users\admin\AppData\Local\Temp\is-FNL2N.tmp\saturnsetup.tmp" /SL5="$1A01A2,42849301,57344,C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\78RFYB7Z\saturnsetup.exe" C:\Users\admin\AppData\Local\Temp\is-FNL2N.tmp\saturnsetup.tmpsaturnsetup.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.52.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-fnl2n.tmp\saturnsetup.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
1764"C:\Program Files\Internet Explorer\iexplore.exe" "www.microsys.ro"C:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
2096"C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\78RFYB7Z\saturnsetup.exe" /SPAWNWND=$6034E /NOTIFYWND=$1A01A2 C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\78RFYB7Z\saturnsetup.exe
saturnsetup.tmp
User:
admin
Company:
Microsys Com Ltd.
Integrity Level:
HIGH
Description:
Moons of Saturn 3D Setup
Exit code:
0
Version:
Modules
Images
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ntdll.dll
c:\users\admin\appdata\local\microsoft\windows\temporary internet files\content.ie5\78rfyb7z\saturnsetup.exe
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
2520"C:\Users\admin\AppData\Local\Temp\is-NFPSN.tmp\saturnsetup.tmp" /SL5="$4034A,42849301,57344,C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\78RFYB7Z\saturnsetup.exe" /SPAWNWND=$6034E /NOTIFYWND=$1A01A2 C:\Users\admin\AppData\Local\Temp\is-NFPSN.tmp\saturnsetup.tmpsaturnsetup.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.52.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-nfpsn.tmp\saturnsetup.tmp
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ntdll.dll
2920"C:\Program Files\Moons of Saturn 3D\Saturn.exe"C:\Program Files\Moons of Saturn 3D\Saturn.exesaturnsetup.tmp
User:
admin
Company:
Microsys Com Ltd.
Integrity Level:
MEDIUM
Description:
Saturn
Exit code:
0
Version:
1.1.0.0
Modules
Images
c:\program files\moons of saturn 3d\saturn.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winmm.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
3768"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:1764 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
4008"C:\Program Files\Moons of Saturn 3D\Saturn.exe" C:\Program Files\Moons of Saturn 3D\Saturn.exeexplorer.exe
User:
admin
Company:
Microsys Com Ltd.
Integrity Level:
MEDIUM
Description:
Saturn
Exit code:
0
Version:
1.1.0.0
Modules
Images
c:\program files\moons of saturn 3d\saturn.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\winmm.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
4060"C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\78RFYB7Z\saturnsetup.exe" C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\78RFYB7Z\saturnsetup.exeiexplore.exe
User:
admin
Company:
Microsys Com Ltd.
Integrity Level:
MEDIUM
Description:
Moons of Saturn 3D Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\appdata\local\microsoft\windows\temporary internet files\content.ie5\78rfyb7z\saturnsetup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
Total events
19 097
Read events
18 994
Write events
97
Delete events
6

Modification events

(PID) Process:(1764) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPDaysSinceLastAutoMigration
Value:
0
(PID) Process:(1764) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchHighDateTime
Value:
30847387
(PID) Process:(1764) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
30847437
(PID) Process:(1764) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(1764) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(1764) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(1764) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(1764) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(1764) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(1764) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
Executable files
5
Suspicious files
61
Text files
203
Unknown types
0

Dropped files

PID
Process
Filename
Type
3768iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\24BD96D5497F70B3F510A6B53CD43F3E_3A89246FB90C5EE6620004F1AE0EB0EAbinary
MD5:A520B016B5CFE72FFD75B5137A0F99B8
SHA256:0ACDDA39BACC28CBCB30AD61A37F9113D4BF0E9F413A6E396EBBAADA64DC3487
3768iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\24BD96D5497F70B3F510A6B53CD43F3E_3A89246FB90C5EE6620004F1AE0EB0EAbinary
MD5:BFF1D762F629D36F897D14F030C5EEA2
SHA256:A9B259E61A189328107C3B900F126B62156B9FF5BC0BF662D03E5DD655744B66
3768iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\9IVKFTR6.htmhtml
MD5:E81D2A619053CCCD539DD94E203092F3
SHA256:72BE3791F38EDCF058C3E70FF94DD519C7C365891DF93197B59CF11004E748B3
3768iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YTOWV792\styles[1].csstext
MD5:05DF532440EAFAECF96A42FFA395886C
SHA256:D629AB67FEDC00348CF11A4506D87B0D34D81D06B63789F489420039DF43C3AD
3768iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\CAF4703619713E3F18D8A9D5D88D6288_F2DAF19C1F776537105D08FC8D978464binary
MD5:8C41FDCB43A815D9CB840D106F3ADE3B
SHA256:DE2C48F298BAE5800DC8F8D3DD2CFE0E3953C9C4A14D29EFAEFA4F194D3CE224
3768iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\WX2DYR7P.htmhtml
MD5:DCD99D24A68D2D3772C036B63BB124A6
SHA256:5E3D8E9D4DD4FA7932BBA5176D408D0C0CF78288F67182002CC01DCC9E40857C
3768iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5IWPIAR9\sb_icon_32[1].pngimage
MD5:913EC2F40636841BDF2BA57F28FDFB49
SHA256:0D919DFB8B27E15DD7E526B2CDA3C83FD8E2A07E30C7EFAE8B2008A333C3088C
3768iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\bc7icon32[1].pngimage
MD5:1EBE2D015594C07D0580F63F3D36EC50
SHA256:7351B9C304F220E09A3F5A4AAAA27390DA041F7F626D4FD7B22267D5D92AC647
3768iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5IWPIAR9\microsys7[1].pngimage
MD5:040E349CB5B124370F7A0E3E9D3B1D58
SHA256:56AA0C42B02497AC5DF715FDE728B5C0FFA2164861DBDD79465FCB81E6F97297
3768iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\bgproicon32x32[1].pngimage
MD5:D533CA2615D7C2B9008B6218C59505B6
SHA256:FB9EC2156C53A6B73FBE8FE693162A0A2192A2B46DA930798BDAB707743050ED
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
21
TCP/UDP connections
74
DNS requests
28
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3768
iexplore.exe
GET
200
95.140.236.128:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?f582ea511c70795b
unknown
compressed
4.66 Kb
unknown
3768
iexplore.exe
GET
301
172.67.219.199:80
http://www.microsys.ro/
unknown
html
232 b
unknown
3768
iexplore.exe
GET
200
142.250.186.35:80
http://ocsp.pki.goog/gtsr1/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBQwkcLWD4LqGJ7bE7B1XZsEbmfwUAQU5K8rJnEaK0gnhS9SZizv8IkTcT4CDQIDvFCjJ1PwkYAi7fE%3D
unknown
binary
724 b
unknown
3768
iexplore.exe
GET
200
142.250.186.35:80
http://ocsp.pki.goog/gts1c3/MFAwTjBMMEowSDAJBgUrDgMCGgUABBTHLnmK3f9hNLO67UdCuLvGwCQHYwQUinR%2Fr4XN7pXNPZzQ4kYU83E1HScCDx9GnoHWsw4QZ9qW7IsCPg%3D%3D
unknown
binary
470 b
unknown
3768
iexplore.exe
GET
200
142.250.186.35:80
http://ocsp.pki.goog/gsr1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCEHe9DWzbNvka6iEPxPBY0w0%3D
unknown
binary
1.41 Kb
unknown
3768
iexplore.exe
GET
200
142.250.186.35:80
http://ocsp.pki.goog/gts1c3/MFAwTjBMMEowSDAJBgUrDgMCGgUABBTHLnmK3f9hNLO67UdCuLvGwCQHYwQUinR%2Fr4XN7pXNPZzQ4kYU83E1HScCDx9GnoHWsw4QZ9qW7IsCPg%3D%3D
unknown
binary
470 b
unknown
3768
iexplore.exe
GET
200
142.250.186.35:80
http://ocsp.pki.goog/gts1c3/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBTHLnmK3f9hNLO67UdCuLvGwCQHYwQUinR%2Fr4XN7pXNPZzQ4kYU83E1HScCEQDHFurBkDkysBLRERRg7lfk
unknown
binary
472 b
unknown
3768
iexplore.exe
GET
200
142.250.186.35:80
http://ocsp.pki.goog/gtsr1/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBQwkcLWD4LqGJ7bE7B1XZsEbmfwUAQU5K8rJnEaK0gnhS9SZizv8IkTcT4CDQIDvFNZazTHGPUBUGY%3D
unknown
binary
724 b
unknown
3768
iexplore.exe
GET
200
142.250.186.35:80
http://ocsp.pki.goog/gts1c3/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBTHLnmK3f9hNLO67UdCuLvGwCQHYwQUinR%2Fr4XN7pXNPZzQ4kYU83E1HScCEQDq2dJghNRUhhD1jBCcUPXe
unknown
binary
472 b
unknown
3768
iexplore.exe
GET
200
142.250.186.35:80
http://ocsp.pki.goog/gts1c3/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBTHLnmK3f9hNLO67UdCuLvGwCQHYwQUinR%2Fr4XN7pXNPZzQ4kYU83E1HScCEQD50q2MxTvdnxLfPCm8%2F51a
unknown
binary
472 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2656
svchost.exe
239.255.255.250:1900
whitelisted
3768
iexplore.exe
172.67.219.199:80
www.microsys.ro
CLOUDFLARENET
US
unknown
4
System
192.168.100.255:137
whitelisted
3768
iexplore.exe
172.67.219.199:443
www.microsys.ro
CLOUDFLARENET
US
unknown
3768
iexplore.exe
95.140.236.128:80
ctldl.windowsupdate.com
LLNW
US
unknown
3768
iexplore.exe
142.250.186.35:80
ocsp.pki.goog
GOOGLE
US
whitelisted
3768
iexplore.exe
142.250.186.98:443
pagead2.googlesyndication.com
GOOGLE
US
unknown
3768
iexplore.exe
142.250.186.110:443
fundingchoicesmessages.google.com
GOOGLE
US
whitelisted
3768
iexplore.exe
142.250.186.66:443
googleads.g.doubleclick.net
GOOGLE
US
whitelisted
3768
iexplore.exe
142.250.186.106:443
fonts.googleapis.com
GOOGLE
US
whitelisted

DNS requests

Domain
IP
Reputation
www.microsys.ro
  • 172.67.219.199
  • 104.21.24.174
unknown
ctldl.windowsupdate.com
  • 95.140.236.128
  • 95.140.236.0
whitelisted
ocsp.pki.goog
  • 142.250.186.35
whitelisted
pagead2.googlesyndication.com
  • 142.250.186.98
whitelisted
fundingchoicesmessages.google.com
  • 142.250.186.110
whitelisted
googleads.g.doubleclick.net
  • 142.250.186.66
whitelisted
lh3.googleusercontent.com
  • 142.250.186.97
whitelisted
fonts.googleapis.com
  • 142.250.186.106
whitelisted
fonts.gstatic.com
  • 142.250.184.227
whitelisted
api.bing.com
  • 13.107.5.80
whitelisted

Threats

No threats detected
No debug info