File name:

InstantStormSetup-1.5.3.0.exe

Full analysis: https://app.any.run/tasks/b0e2809b-333e-4b42-88c5-8d666a14af3f
Verdict: Malicious activity
Analysis date: November 26, 2023, 12:31:40
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

9F37D75245993A0707203BCF33D1BED8

SHA1:

A0F376BC81282F56BEB9B4081A83100725D7C722

SHA256:

28C314F52F8EB9DB556BA72D3D880F079A373C58318FF4B8D73695910B0FFAB0

SSDEEP:

98304:YxwRfUthuFygFCTk+fjiGwzj2mXd7wUzJGHVucONpQfWUSgeu6xZSyRDRvNm3KMs:x15YqN

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • InstantStormSetup-1.5.3.0.exe (PID: 2692)
      • InstantStormSetup-1.5.3.0.exe (PID: 1988)
      • InstantStormSetup-1.5.3.0.tmp (PID: 3592)
    • Creates a writable file in the system directory

      • InstantStormSetup-1.5.3.0.tmp (PID: 3592)
    • Registers / Runs the DLL via REGSVR32.EXE

      • InstantStormSetup-1.5.3.0.tmp (PID: 3592)
  • SUSPICIOUS

    • Reads the Windows owner or organization settings

      • InstantStormSetup-1.5.3.0.tmp (PID: 3592)
    • Process drops legitimate windows executable

      • InstantStormSetup-1.5.3.0.tmp (PID: 3592)
    • Reads settings of System Certificates

      • fp7axwin.exe (PID: 2840)
    • Reads the Internet Settings

      • Endermanch@ChilledWindows.exe (PID: 1248)
  • INFO

    • Checks supported languages

      • InstantStormSetup-1.5.3.0.exe (PID: 2692)
      • InstantStormSetup-1.5.3.0.tmp (PID: 2708)
      • InstantStormSetup-1.5.3.0.exe (PID: 1988)
      • InstantStormSetup-1.5.3.0.tmp (PID: 3592)
      • fp7axwin.exe (PID: 2840)
      • wmpnscfg.exe (PID: 1936)
      • InstantStorm.exe (PID: 3200)
      • Endermanch@ChilledWindows.exe (PID: 1248)
    • Reads the computer name

      • InstantStormSetup-1.5.3.0.tmp (PID: 2708)
      • InstantStormSetup-1.5.3.0.tmp (PID: 3592)
      • fp7axwin.exe (PID: 2840)
      • wmpnscfg.exe (PID: 1936)
      • InstantStorm.exe (PID: 3200)
      • Endermanch@ChilledWindows.exe (PID: 1248)
    • Create files in a temporary directory

      • InstantStormSetup-1.5.3.0.exe (PID: 1988)
      • InstantStormSetup-1.5.3.0.exe (PID: 2692)
      • InstantStormSetup-1.5.3.0.tmp (PID: 3592)
      • InstantStorm.exe (PID: 3200)
    • Creates files in the program directory

      • InstantStormSetup-1.5.3.0.tmp (PID: 3592)
    • Creates files or folders in the user directory

      • InstantStormSetup-1.5.3.0.tmp (PID: 3592)
      • fp7axwin.exe (PID: 2840)
      • InstantStorm.exe (PID: 3200)
    • Reads the machine GUID from the registry

      • fp7axwin.exe (PID: 2840)
      • wmpnscfg.exe (PID: 1936)
      • InstantStorm.exe (PID: 3200)
      • Endermanch@ChilledWindows.exe (PID: 1248)
    • Reads CPU info

      • fp7axwin.exe (PID: 2840)
      • InstantStorm.exe (PID: 3200)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 1936)
      • InstantStorm.exe (PID: 3200)
      • control.exe (PID: 3464)
      • WinRAR.exe (PID: 2892)
      • Endermanch@ChilledWindows.exe (PID: 1248)
    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 2892)
    • Checks proxy server information

      • Endermanch@ChilledWindows.exe (PID: 1248)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable PowerBASIC/Win 9.x (51.2)
.exe | Inno Setup installer (37.9)
.exe | Win32 Executable Delphi generic (4.9)
.dll | Win32 Dynamic Link Library (generic) (2.2)
.exe | Win32 Executable (generic) (1.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 1992:06:20 00:22:17+02:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 37376
InitializedDataSize: 24576
UninitializedDataSize: -
EntryPoint: 0x9a54
OSVersion: 1
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 0.0.0.0
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
Comments: This installation was built with Inno Setup.
CompanyName: Jan Kolarik & Ondrej Vaverka
FileDescription: InstantStorm Setup
FileVersion:
LegalCopyright:
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
57
Monitored processes
12
Malicious processes
4
Suspicious processes
1

Behavior graph

Click at the process to see the details
start instantstormsetup-1.5.3.0.exe no specs instantstormsetup-1.5.3.0.tmp no specs instantstormsetup-1.5.3.0.exe instantstormsetup-1.5.3.0.tmp no specs regsvr32.exe no specs fp7axwin.exe wmpnscfg.exe no specs instantstorm.exe no specs PhotoViewer.dll no specs control.exe no specs winrar.exe no specs endermanch@chilledwindows.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1128"C:\Windows\system32\regsvr32.exe" /s "C:\Windows\system32\comdlg32.ocx"C:\Windows\System32\regsvr32.exeInstantStormSetup-1.5.3.0.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1248"C:\Users\admin\Desktop\ChilledWindows\Endermanch@ChilledWindows.exe" C:\Users\admin\Desktop\ChilledWindows\Endermanch@ChilledWindows.exeexplorer.exe
User:
admin
Company:
GAMELASTER
Integrity Level:
MEDIUM
Description:
ChilledWindows
Exit code:
3221225547
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\chilledwindows\endermanch@chilledwindows.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1936"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\ole32.dll
1988"C:\Users\admin\Desktop\InstantStormSetup-1.5.3.0.exe" /SPAWNWND=$9016A /NOTIFYWND=$7019C C:\Users\admin\Desktop\InstantStormSetup-1.5.3.0.exe
InstantStormSetup-1.5.3.0.tmp
User:
admin
Company:
Jan Kolarik & Ondrej Vaverka
Integrity Level:
HIGH
Description:
InstantStorm Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\desktop\instantstormsetup-1.5.3.0.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
2692"C:\Users\admin\Desktop\InstantStormSetup-1.5.3.0.exe" C:\Users\admin\Desktop\InstantStormSetup-1.5.3.0.exeexplorer.exe
User:
admin
Company:
Jan Kolarik & Ondrej Vaverka
Integrity Level:
MEDIUM
Description:
InstantStorm Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\desktop\instantstormsetup-1.5.3.0.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
2708"C:\Users\admin\AppData\Local\Temp\is-ROKK5.tmp\InstantStormSetup-1.5.3.0.tmp" /SL5="$7019C,2587357,62976,C:\Users\admin\Desktop\InstantStormSetup-1.5.3.0.exe" C:\Users\admin\AppData\Local\Temp\is-ROKK5.tmp\InstantStormSetup-1.5.3.0.tmpInstantStormSetup-1.5.3.0.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.49.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-rokk5.tmp\instantstormsetup-1.5.3.0.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
2840"C:\Program Files\InstantStorm\bin\fp7axwin.exe" /QC:\Program Files\InstantStorm\bin\fp7axwin.exe
InstantStormSetup-1.5.3.0.tmp
User:
admin
Company:
Jan Kolarik & Ondrej Vaverka
Integrity Level:
HIGH
Description:
Screensaver created with InstantStorm
Exit code:
0
Version:
1.5.3.0
Modules
Images
c:\program files\instantstorm\bin\fp7axwin.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2892"C:\Program Files\WinRAR\WinRAR.exe" x -iext -ow -ver -- "C:\Users\admin\Desktop\ChilledWindows.zip" C:\Users\admin\Desktop\ChilledWindows\C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3116C:\Windows\system32\DllHost.exe /Processid:{76D0CB12-7604-4048-B83C-1005C7DDC503}C:\Windows\System32\dllhost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
COM Surrogate
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\dllhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3200"C:\Program Files\InstantStorm\InstantStorm.exe" C:\Program Files\InstantStorm\InstantStorm.exeexplorer.exe
User:
admin
Company:
Jan Kolarik & Ondrej Vaverka
Integrity Level:
MEDIUM
Description:
InstantStorm
Exit code:
0
Version:
1.05.0003
Modules
Images
c:\program files\instantstorm\instantstorm.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvbvm60.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
Total events
5 142
Read events
5 081
Write events
50
Delete events
11

Modification events

(PID) Process:(1128) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F9043C85-F6F2-101A-A3C9-08002B2F49FB}
Operation:delete keyName:(default)
Value:
(PID) Process:(1128) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7629CFA2-3FE5-101B-A3C9-08002B2F49FB}
Operation:delete keyName:(default)
Value:
(PID) Process:(1128) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7629CFA4-3FE5-101B-A3C9-08002B2F49FB}
Operation:delete keyName:(default)
Value:
(PID) Process:(1128) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3C4F3BE5-47EB-101B-A3C9-08002B2F49FB}
Operation:delete keyName:(default)
Value:
(PID) Process:(1128) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3C4F3BE3-47EB-101B-A3C9-08002B2F49FB}
Operation:delete keyName:(default)
Value:
(PID) Process:(1128) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3C4F3BE7-47EB-101B-A3C9-08002B2F49FB}
Operation:delete keyName:(default)
Value:
(PID) Process:(1936) wmpnscfg.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{964F4DB6-FBCA-4BC4-9908-E2CBE5E1E624}\{5C353150-1FBE-48FE-86FE-0A77E5DC2E89}
Operation:delete keyName:(default)
Value:
(PID) Process:(1936) wmpnscfg.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{964F4DB6-FBCA-4BC4-9908-E2CBE5E1E624}
Operation:delete keyName:(default)
Value:
(PID) Process:(1936) wmpnscfg.exeKey:HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Health\{D24A4828-2741-4883-8D48-A367F2DF2990}
Operation:delete keyName:(default)
Value:
(PID) Process:(3200) InstantStorm.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
Operation:writeName:NodeSlots
Value:
0202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202
Executable files
35
Suspicious files
93
Text files
40
Unknown types
0

Dropped files

PID
Process
Filename
Type
3592InstantStormSetup-1.5.3.0.tmpC:\ProgramData\Microsoft\Windows\Start Menu\Programs\is-I8SE7.tmp
MD5:
SHA256:
3592InstantStormSetup-1.5.3.0.tmpC:\ProgramData\Microsoft\Windows\Start Menu\Programs\InstantStorm 1.0.lnk
MD5:
SHA256:
3592InstantStormSetup-1.5.3.0.tmpC:\ProgramData\Microsoft\Windows\Start Menu\Programs\is-S353N.tmp
MD5:
SHA256:
3592InstantStormSetup-1.5.3.0.tmpC:\ProgramData\Microsoft\Windows\Start Menu\Programs\InstantStorm 0.9.lnk
MD5:
SHA256:
3592InstantStormSetup-1.5.3.0.tmpC:\Program Files\InstantStorm\is-9KQKS.tmp
MD5:
SHA256:
3592InstantStormSetup-1.5.3.0.tmpC:\Program Files\InstantStorm\leesmij.txt
MD5:
SHA256:
3592InstantStormSetup-1.5.3.0.tmpC:\Program Files\InstantStorm\is-9OG7C.tmp
MD5:
SHA256:
3592InstantStormSetup-1.5.3.0.tmpC:\Program Files\InstantStorm\czytajto.txt
MD5:
SHA256:
3592InstantStormSetup-1.5.3.0.tmpC:\Program Files\InstantStorm\WindowsVista_StandardUser.regtext
MD5:F3B25701FE362EC84616A93A45CE9998
SHA256:B3D510EF04275CA8E698E5B3CBB0ECE3949EF9252F0CDC839E9EE347409A2209
2692InstantStormSetup-1.5.3.0.exeC:\Users\admin\AppData\Local\Temp\is-ROKK5.tmp\InstantStormSetup-1.5.3.0.tmpexecutable
MD5:8E48C8EFDAD1FD993EE8035A0815CB82
SHA256:F785518BA36AE17080B3B05F330CA39651521E2DF5E385C8EEFD38E0A42DAE4E
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
11
DNS requests
4
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2840
fp7axwin.exe
POST
200
192.229.221.95:80
http://ocsp.digicert.com/
unknown
binary
471 b
unknown
2840
fp7axwin.exe
POST
200
192.229.221.95:80
http://ocsp.digicert.com/
unknown
binary
471 b
unknown
2840
fp7axwin.exe
POST
200
192.229.221.95:80
http://ocsp.digicert.com/
unknown
binary
471 b
unknown
2840
fp7axwin.exe
POST
200
192.229.221.95:80
http://ocsp.digicert.com/
unknown
binary
471 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:137
whitelisted
2588
svchost.exe
239.255.255.250:1900
whitelisted
2840
fp7axwin.exe
2.19.228.131:443
geo2.adobe.com
AKAMAI-AS
FR
unknown
2840
fp7axwin.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
2840
fp7axwin.exe
2.23.66.176:443
fpdownload.macromedia.com
AKAMAI-AS
DE
unknown

DNS requests

Domain
IP
Reputation
geo2.adobe.com
  • 2.19.228.131
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
fpdownload.macromedia.com
  • 2.23.66.176
whitelisted

Threats

No threats detected
No debug info