File name:

Setup.exe

Full analysis: https://app.any.run/tasks/c0bb6d08-22e2-41ec-afa9-ed5a59280dcf
Verdict: Malicious activity
Analysis date: May 12, 2025, 18:22:31
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 6 sections
MD5:

C470706E80F259B4B8D50CDB0D0566EC

SHA1:

2EDFC024BA05D9C0AFF832A2B3FBF77C79E4D7F9

SHA256:

2D66AB6196058FE8BE0E5653D8AE15AF99AEF370ED6994555F408E4A14CF02C6

SSDEEP:

98304:SJ70OtKMpo5PJecdpC+ZCY82yq/OjzNrE4gy0b685ggYSBgzCYryem+ROMFbY1nr:+AEE8S

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • setup_ui.exe (PID: 7420)
      • Setup.exe (PID: 7356)
      • Setup.exe (PID: 8148)
      • setup_ui.exe (PID: 7208)
    • Executable content was dropped or overwritten

      • Setup.exe (PID: 7356)
      • Setup.exe (PID: 8128)
      • Setup.exe (PID: 8148)
    • Starts itself from another location

      • Setup.exe (PID: 8128)
    • Application launched itself

      • Setup.exe (PID: 7356)
    • The process verifies whether the antivirus software is installed

      • Setup.exe (PID: 8148)
  • INFO

    • Reads the machine GUID from the registry

      • Setup.exe (PID: 7356)
      • setup_ui.exe (PID: 7420)
      • Setup.exe (PID: 8148)
      • setup_ui.exe (PID: 7208)
    • Checks supported languages

      • Setup.exe (PID: 7356)
      • setup_ui.exe (PID: 7420)
      • Setup.exe (PID: 8148)
      • Setup.exe (PID: 8128)
      • setup_ui.exe (PID: 7208)
    • Reads the computer name

      • Setup.exe (PID: 7356)
      • setup_ui.exe (PID: 7420)
      • Setup.exe (PID: 8128)
      • Setup.exe (PID: 8148)
      • setup_ui.exe (PID: 7208)
    • The sample compiled with english language support

      • Setup.exe (PID: 7356)
      • Setup.exe (PID: 8128)
      • Setup.exe (PID: 8148)
    • Create files in a temporary directory

      • Setup.exe (PID: 7356)
      • Setup.exe (PID: 8148)
    • Checks proxy server information

      • Setup.exe (PID: 7356)
      • Setup.exe (PID: 8148)
    • Process checks whether UAC notifications are on

      • Setup.exe (PID: 7356)
      • Setup.exe (PID: 8148)
    • Checks for the presence of KasperskyLab

      • Setup.exe (PID: 8148)
      • Setup.exe (PID: 7356)
    • Creates files or folders in the user directory

      • Setup.exe (PID: 7356)
    • Creates files in the program directory

      • Setup.exe (PID: 7356)
      • Setup.exe (PID: 8148)
    • Reads the software policy settings

      • Setup.exe (PID: 7356)
      • Setup.exe (PID: 8148)
    • Process checks computer location settings

      • Setup.exe (PID: 7356)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (76.4)
.exe | Win32 Executable (generic) (12.4)
.exe | Generic Win/DOS Executable (5.5)
.exe | DOS Executable Generic (5.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2025:04:16 07:20:24+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14.29
CodeSize: 255488
InitializedDataSize: 4478464
UninitializedDataSize: -
EntryPoint: 0x3b10
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 21.21.7.384
ProductVersionNumber: 21.21.7.384
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Kaspersky
FileDescription: Kaspersky [21.21.7.384.0.18.0]
FileVersion: 21.21.7.384
LegalCopyright: © 2025 AO Kaspersky Lab
LegalTrademarks: Registered trademarks and service marks are the property of their respective owners
ProductName: Kaspersky
ProductVersion: 21.21.7.384
InternalName: Setup
OriginalFileName: Setup.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
135
Monitored processes
7
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start setup.exe setup_ui.exe no specs sppextcomobj.exe no specs slui.exe no specs setup.exe setup.exe setup_ui.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
7208"C:\Users\admin\AppData\Local\Temp\4BCADCC1E5F20F114BDE817F87F669EE\setup_ui.exe" -cp=objref:TUVPVwEAAAAAAAAAAAAAAMAAAAAAAABGgQIAAAAAAAAp5DaDXeLbGaf+QFei8Bb5AqwAANQf//9mJptYeyVTgzgAIgAHAEQARQBTAEsAVABPAFAALQBKAEcATABMAEoATABEAAAABwAxADkAMgAuADEANgA4AC4AMQAwADAALgAxADQAAAAAAAkA//8AAB4A//8AABAA//8AAAoA//8AABYA//8AAB8A//8AAA4A//8AAAAA:C:\Users\admin\AppData\Local\Temp\4BCADCC1E5F20F114BDE817F87F669EE\setup_ui.exeSetup.exe
User:
admin
Company:
Kaspersky
Integrity Level:
MEDIUM
Description:
Kaspersky [21.21.7.384.0.18.0]
Version:
21.21.7.384
Modules
Images
c:\users\admin\appdata\local\temp\4bcadcc1e5f20f114bde817f87f669ee\setup_ui.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\version.dll
7356"C:\Users\admin\AppData\Local\Temp\Setup.exe" C:\Users\admin\AppData\Local\Temp\Setup.exe
explorer.exe
User:
admin
Company:
Kaspersky
Integrity Level:
MEDIUM
Description:
Kaspersky [21.21.7.384.0.18.0]
Version:
21.21.7.384
Modules
Images
c:\users\admin\appdata\local\temp\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acgenral.dll
7420"C:\Users\admin\AppData\Local\Temp\A2034451E5F20F114BDE817F87F669EE\setup_ui.exe" -cp=objref:TUVPVwEAAAAAAAAAAAAAAMAAAAAAAABGgQIAAAAAAABo3C+XwdOcmpNuJEyuHI6GAhQAALwc//8DdcNQ+uhxrzgAIgAHAEQARQBTAEsAVABPAFAALQBKAEcATABMAEoATABEAAAABwAxADkAMgAuADEANgA4AC4AMQAwADAALgAxADQAAAAAAAkA//8AAB4A//8AABAA//8AAAoA//8AABYA//8AAB8A//8AAA4A//8AAAAA:C:\Users\admin\AppData\Local\Temp\A2034451E5F20F114BDE817F87F669EE\setup_ui.exeSetup.exe
User:
admin
Company:
Kaspersky
Integrity Level:
MEDIUM
Description:
Kaspersky [21.21.7.384.0.18.0]
Exit code:
0
Version:
21.21.7.384
Modules
Images
c:\users\admin\appdata\local\temp\a2034451e5f20f114bde817f87f669ee\setup_ui.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\version.dll
7596C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
7632"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exeSppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
8128"C:\Users\admin\AppData\Local\Temp\Setup.exe" /-elevated=;"C:\Users\admin\AppData\Local\Temp\Setup.exe"C:\Users\admin\AppData\Local\Temp\Setup.exe
Setup.exe
User:
admin
Company:
Kaspersky
Integrity Level:
HIGH
Description:
Kaspersky [21.21.7.384.0.18.0]
Version:
21.21.7.384
Modules
Images
c:\users\admin\appdata\local\temp\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acgenral.dll
8148"C:\WINDOWS\temp\84EB2AC1E5F20F114BDE817F87F669EE\Setup.exe" /-elevated=;"C:\Users\admin\AppData\Local\Temp\Setup.exe"C:\Windows\Temp\84EB2AC1E5F20F114BDE817F87F669EE\Setup.exe
Setup.exe
User:
admin
Company:
Kaspersky
Integrity Level:
HIGH
Description:
Kaspersky [21.21.7.384.0.18.0]
Version:
21.21.7.384
Modules
Images
c:\windows\temp\84eb2ac1e5f20f114bde817f87f669ee\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acgenral.dll
Total events
11 627
Read events
11 456
Write events
167
Delete events
4

Modification events

(PID) Process:(7356) Setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\KasperskyLabSetup\Setup21.21.7.384.0.18.0
Operation:writeName:TrashFiles
Value:
C:\Users\admin\AppData\Local\Temp\discovery.cfg
(PID) Process:(7356) Setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\KasperskyLabSetup\Setup21.21.7.384.0.18.0\volatile
Operation:writeName:cp_storedResolvedType
Value:
-1
(PID) Process:(7356) Setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\KasperskyLabSetup\Setup21.21.7.384.0.18.0\volatile
Operation:writeName:cp_storedResolvedProductTier
Value:
0
(PID) Process:(7356) Setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\KasperskyLabSetup\Setup21.21.7.384.0.18.0\volatile
Operation:writeName:cp_storedResolvedStartupScenario
Value:
(PID) Process:(7356) Setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\KasperskyLabSetup\Setup21.21.7.384.0.18.0\volatile
Operation:writeName:cp_storedResolvedType
Value:
6
(PID) Process:(7356) Setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\KasperskyLabSetup\Setup21.21.7.384.0.18.0\volatile
Operation:writeName:cp_storedResolvedProductTier
Value:
236
(PID) Process:(7356) Setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\KasperskyLabSetup\Setup21.21.7.384.0.18.0\volatile
Operation:writeName:cp_storedResolvedStartupScenario
Value:
SignInCommercial
(PID) Process:(7356) Setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\KasperskyLabSetup\Setup21.21.7.384.0.18.0\volatile
Operation:writeName:PreferredUI
Value:
0
(PID) Process:(7356) Setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\KasperskyLabSetup\Setup21.21.7.384.0.18.0\volatile
Operation:writeName:PreferredUI
Value:
1
(PID) Process:(7356) Setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\KasperskyLabSetup\Setup21.21.7.384.0.18.0
Operation:writeName:TrashFiles
Value:
C:\Users\admin\AppData\Local\Temp\discovery.cfg C:\ProgramData\Kaspersky Lab Setup Files\SAAS21.21.7.384.0.18.0
Executable files
35
Suspicious files
32
Text files
52
Unknown types
3

Dropped files

PID
Process
Filename
Type
7356Setup.exeC:\Users\admin\AppData\Local\Temp\kl-setup-2025-05-12-18-22-39_SAAS.21.21.7.384.logbinary
MD5:AF16C14A9BC5CF694E6FB3A9B3BBAE3C
SHA256:CF58E1524799F8B0C7FE57AD349604A8A94F2E5A91269CB7B039125E2F22835C
7356Setup.exeC:\Users\admin\AppData\Local\Temp\1544302B-2F5E-11F0-B4ED-18F7786F96EE\downloader_neutral_SAAS.initext
MD5:1F8CE4B3A1AEE2EB28B106927CF8B76F
SHA256:B61D7E0071A6EB32A09A26105F0144FDDE42FBEB0BBBF8B9997B8E3431DC81E4
7356Setup.exeC:\Users\admin\AppData\Local\Temp\1544302B-2F5E-11F0-B4ED-18F7786F96EE\GuiStrings_SAAS.loctext
MD5:ECAA88F7FA0BF610A5A26CF545DCD3AA
SHA256:F1945CD6C19E56B3C1C78943EF5EC18116907A4CA1EFC40A57D48AB1DB7ADFC5
7356Setup.exeC:\Users\admin\AppData\Local\Temp\1544302B-2F5E-11F0-B4ED-18F7786F96EE\GuiStrings.lochtml
MD5:09C4E9F41C4B8BFDB6BF8916AF730ECD
SHA256:57BF969D3C10D5BE0A4B31B8E530C1E005622C8DC809EE4FBD4C214F3B3E9A37
7356Setup.exeC:\Users\admin\AppData\Local\Temp\1544302B-2F5E-11F0-B4ED-18F7786F96EE\downloader_neutral.initext
MD5:63727C1ECDD902A455CCB1ED3A5702C5
SHA256:725DDFCE3AAB347D28F8D8A4EB844DC8AD0BA7D53596AA9F118AD83F6A6075F5
7356Setup.exeC:\Users\admin\AppData\Local\Temp\A2034451E5F20F114BDE817F87F669EE\kl.setup.ui.dllexecutable
MD5:35464B0B8281A7A6F6577436A3042312
SHA256:9366179168B998AD9929E6BF3C610CB9EBE809C9B1C34D1D1BDAF2B34044B742
7356Setup.exeC:\Users\admin\AppData\Local\Temp\A2034451E5F20F114BDE817F87F669EE\kl.ui.framework.dllexecutable
MD5:7712DECC281FEBD03EBFFBC9538FEA09
SHA256:ED0BB23234EDA94743776F511605855A2CC4F74B8CFDADA9FA54B345D9A2A35E
7356Setup.exeC:\Users\admin\AppData\Local\Temp\A2034451E5F20F114BDE817F87F669EE\kl.ui.framework.uikit.dllbinary
MD5:4E3218D45A99D57C205F7DF4CDD939C0
SHA256:C80BB296C0700D0D045729EFB9F2B4F8F15AC431CABB9A955C2C258651B2AC6D
7356Setup.exeC:\Users\admin\AppData\Local\Temp\A2034451E5F20F114BDE817F87F669EE\kl.setup.ui.core.dllexecutable
MD5:9A1F97D8B717A07492AE65C8B0F6C824
SHA256:23DE41D5D15BC3E3847326834042F54FDEEB2DB5148E238920810DBD26E00766
7356Setup.exeC:\Users\admin\AppData\Local\Temp\A2034451E5F20F114BDE817F87F669EE\setup_ui.exeexecutable
MD5:E99E71FBA9C800CA5FFD06AC475FDA6C
SHA256:949473CB71782E59F729E91B71085FDAD05578A49DEB8960EDDD454DD7E6A697
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
8
TCP/UDP connections
44
DNS requests
15
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5496
MoUsoCoreWorker.exe
GET
200
23.48.23.176:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
23.48.23.176:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
69.192.161.161:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
69.192.161.161:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6544
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
7356
Setup.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAbY2QTVWENG9oovp1QifsQ%3D
unknown
whitelisted
1168
SIHClient.exe
GET
200
23.219.150.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
1168
SIHClient.exe
GET
200
23.219.150.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
2104
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5496
MoUsoCoreWorker.exe
23.48.23.176:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
23.48.23.176:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
5496
MoUsoCoreWorker.exe
69.192.161.161:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
69.192.161.161:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
3216
svchost.exe
172.211.123.250:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
7356
Setup.exe
82.202.185.148:443
ds.kaspersky.com
Kaspersky Lab Switzerland GmbH
CH
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.186.142
whitelisted
crl.microsoft.com
  • 23.48.23.176
  • 23.48.23.181
  • 23.48.23.177
  • 23.48.23.180
  • 23.48.23.185
  • 23.48.23.190
  • 23.48.23.173
  • 23.48.23.188
  • 23.48.23.183
whitelisted
www.microsoft.com
  • 69.192.161.161
  • 23.219.150.101
whitelisted
client.wns.windows.com
  • 172.211.123.250
whitelisted
ds.kaspersky.com
  • 82.202.185.148
  • 62.67.238.152
  • 82.202.184.184
  • 81.19.104.172
  • 62.67.238.151
  • 82.202.185.146
  • 82.202.184.193
  • 46.8.206.90
whitelisted
login.live.com
  • 20.190.160.20
  • 40.126.32.134
  • 40.126.32.68
  • 40.126.32.140
  • 20.190.160.64
  • 20.190.160.14
  • 40.126.32.133
  • 20.190.160.5
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
dm.s.kaspersky-labs.com
  • 80.239.174.35
  • 46.8.206.115
  • 80.231.123.135
unknown
settings-win.data.microsoft.com
  • 4.231.128.59
  • 40.127.240.158
whitelisted
slscr.update.microsoft.com
  • 4.245.163.56
whitelisted

Threats

No threats detected
No debug info