File name:

SetupFile_65117.exe

Full analysis: https://app.any.run/tasks/7851151d-efbb-46b7-90d4-ef8fa37845f4
Verdict: Malicious activity
Analysis date: April 20, 2025, 16:37:22
OS: Windows 11 Professional (build: 22000, 64 bit)
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 5 sections
MD5:

23F040CD1F8DA2C9502B4C1ADD177FB8

SHA1:

4119B199DCE9832ED0DCB7DE795DB5441A95ED19

SHA256:

2F6B283128D186691CFEDA169101A6423A02D9C1161771C1B75C1757DA878525

SSDEEP:

196608:b3X5Ymc/rzhdoTc6/XVTUGCC3PZ4CbDw5+Og7koond7hwJZ+w:r5YDDrc1/XWGPZ4uDc+J+nvwJZR

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Searches for installed software

      • SetupFile_65117.exe (PID: 4368)
      • SetupFile_65117.exe (PID: 3568)
  • INFO

    • The sample compiled with english language support

      • SetupFile_65117.exe (PID: 3568)
    • Reads the computer name

      • SetupFile_65117.exe (PID: 4368)
      • SetupFile_65117.exe (PID: 3568)
    • Checks supported languages

      • SetupFile_65117.exe (PID: 3568)
      • SetupFile_65117.exe (PID: 4368)
    • Manual execution by a user

      • SetupFile_65117.exe (PID: 4368)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable (generic) (52.9)
.exe | Generic Win/DOS Executable (23.5)
.exe | DOS Executable Generic (23.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2025:03:17 12:57:44+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14
CodeSize: 3655168
InitializedDataSize: 286208
UninitializedDataSize: -
EntryPoint: 0x35f7e5
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.0
ProductVersionNumber: 1.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Permit Special
FileDescription: Digital clock 5 Permit Special
FileVersion: 1.0.0.0
ProductVersion: 1.0.0.0
LegalCopyright: Copyright 2010-2024 Permit Special
ProductName: Digital clock 5 Permit Special
No data.
screenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
101
Monitored processes
2
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start setupfile_65117.exe setupfile_65117.exe

Process information

PID
CMD
Path
Indicators
Parent process
3568"C:\Users\admin\Desktop\SetupFile_65117.exe" C:\Users\admin\Desktop\SetupFile_65117.exe
explorer.exe
User:
admin
Company:
Permit Special
Integrity Level:
MEDIUM
Description:
Digital clock 5 Permit Special
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\setupfile_65117.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64base.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64con.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
4368"C:\Users\admin\Desktop\SetupFile_65117.exe" C:\Users\admin\Desktop\SetupFile_65117.exe
explorer.exe
User:
admin
Company:
Permit Special
Integrity Level:
MEDIUM
Description:
Digital clock 5 Permit Special
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\setupfile_65117.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64base.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64con.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
Total events
803
Read events
803
Write events
0
Delete events
0

Modification events

No data
Executable files
0
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

No data
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
3
TCP/UDP connections
9
DNS requests
6
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2488
smartscreen.exe
GET
200
199.232.214.172:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?18690be70d2b568b
unknown
whitelisted
2488
smartscreen.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
1352
svchost.exe
GET
200
88.221.110.147:80
http://www.msftconnecttest.com/connecttest.txt
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1352
svchost.exe
88.221.110.216:80
Akamai International B.V.
DE
unknown
2488
smartscreen.exe
4.231.68.226:443
checkappexec.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2488
smartscreen.exe
199.232.214.172:80
ctldl.windowsupdate.com
FASTLY
US
whitelisted
2488
smartscreen.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
3568
SetupFile_65117.exe
104.26.3.250:443
marketappstore.com
CLOUDFLARENET
US
unknown
4448
MoUsoCoreWorker.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4368
SetupFile_65117.exe
104.26.3.250:443
marketappstore.com
CLOUDFLARENET
US
unknown
1352
svchost.exe
88.221.110.147:80
Akamai International B.V.
DE
unknown

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.185.238
whitelisted
checkappexec.microsoft.com
  • 4.231.68.226
whitelisted
ctldl.windowsupdate.com
  • 199.232.214.172
  • 199.232.210.172
whitelisted
marketappstore.com
  • 104.26.3.250
  • 172.67.72.48
  • 104.26.2.250
unknown
ocsp.digicert.com
  • 2.17.190.73
whitelisted
settings-win.data.microsoft.com
  • 51.104.136.2
whitelisted

Threats

PID
Process
Class
Message
1352
svchost.exe
Misc activity
ET INFO Microsoft Connection Test
No debug info