File name:

SetupSecureFolders.exe

Full analysis: https://app.any.run/tasks/c685892b-8617-471a-b343-060b8fdcfe10
Verdict: Malicious activity
Analysis date: April 13, 2025, 10:34:34
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
upx
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 5 sections
MD5:

BC75ED68BD5A50AF1CFCBCCFA06E7E7B

SHA1:

6568E012F2169D3F570BCAC6159857C990B42F80

SHA256:

355F9C7AE0CCB2885D1CB6AFFB4BA89102A78BE43EB2604A90084BCB34CA1DD4

SSDEEP:

98304:bi/GwFms5VGmzZ73lksq8HhxxZ2/L3UsUyi89nnhkuqtnqHdyaaV4mLM4/BlgPNO:eBHtVe2Zl

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • SetupSecureFolders.exe (PID: 7628)
      • SecureFolders.exe (PID: 6272)
    • Executable content was dropped or overwritten

      • SetupSecureFolders.exe (PID: 7628)
      • SecureFolders.exe (PID: 6572)
    • Creates files in the driver directory

      • SecureFolders.exe (PID: 6572)
    • Creates or modifies Windows services

      • SecureFolders.exe (PID: 6572)
    • Drops a system driver (possible attempt to evade defenses)

      • SecureFolders.exe (PID: 6572)
    • Creates file in the systems drive root

      • SecureFolders.exe (PID: 6272)
  • INFO

    • Creates files in the program directory

      • SetupSecureFolders.exe (PID: 7628)
      • SecureFolders.exe (PID: 6572)
    • The sample compiled with english language support

      • SetupSecureFolders.exe (PID: 7628)
      • SecureFolders.exe (PID: 6572)
    • UPX packer has been detected

      • SetupSecureFolders.exe (PID: 7628)
    • Checks proxy server information

      • SetupSecureFolders.exe (PID: 7628)
      • SecureFolders.exe (PID: 6272)
    • Checks supported languages

      • SetupSecureFolders.exe (PID: 7628)
      • SecureFolders.exe (PID: 6572)
      • SecureFolders.exe (PID: 7580)
      • SecureFolders.exe (PID: 6272)
    • Reads the computer name

      • SetupSecureFolders.exe (PID: 7628)
      • SecureFolders.exe (PID: 7580)
      • SecureFolders.exe (PID: 6272)
    • Create files in a temporary directory

      • svchost.exe (PID: 7680)
    • Process checks computer location settings

      • SetupSecureFolders.exe (PID: 7628)
    • Manual execution by a user

      • SecureFolders.exe (PID: 7580)
      • SecureFolders.exe (PID: 6272)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (30.7)
.exe | UPX compressed Win32 Executable (30.1)
.exe | Win32 EXE Yoda's Crypter (29.5)
.exe | Win32 Executable (generic) (5)
.exe | Generic Win/DOS Executable (2.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2014:07:21 15:55:44+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 9
CodeSize: 102912
InitializedDataSize: 3908608
UninitializedDataSize: -
EntryPoint: 0xd117
OSVersion: 5
ImageVersion: -
SubsystemVersion: 5
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.9
ProductVersionNumber: 1.0.0.9
FileFlagsMask: 0x0017
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Promosoft Software Limited
FileDescription: Secure Folders
FileVersion: 1.0.0.9
InternalName: SecureFolders.exe
LegalCopyright: (c) Promosoft Software Limited. All rights reserved.
OriginalFileName: SecureFolders.exe
ProductName: Secure Folders
ProductVersion: 1.0.0.9
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
137
Monitored processes
8
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start setupsecurefolders.exe svchost.exe sppextcomobj.exe no specs slui.exe no specs securefolders.exe securefolders.exe no specs securefolders.exe setupsecurefolders.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
6272"C:\Users\admin\Desktop\SecureFolders.exe" C:\Users\admin\Desktop\SecureFolders.exe
explorer.exe
User:
admin
Company:
Promosoft Software Limited
Integrity Level:
MEDIUM
Description:
Secure Folders
Version:
1.0.0.9
Modules
Images
c:\users\admin\desktop\securefolders.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\ws2_32.dll
c:\windows\syswow64\rpcrt4.dll
6572"C:\Users\admin\Desktop\SecureFolders.exe" /op:install_driver_registryC:\Users\admin\Desktop\SecureFolders.exe
SetupSecureFolders.exe
User:
admin
Company:
Promosoft Software Limited
Integrity Level:
HIGH
Description:
Secure Folders
Exit code:
0
Version:
1.0.0.9
Modules
Images
c:\users\admin\desktop\securefolders.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\ws2_32.dll
7576"C:\Users\admin\Desktop\SetupSecureFolders.exe" C:\Users\admin\Desktop\SetupSecureFolders.exeexplorer.exe
User:
admin
Company:
Promosoft Software Limited
Integrity Level:
MEDIUM
Description:
Secure Folders
Exit code:
3221226540
Version:
1.0.0.9
Modules
Images
c:\users\admin\desktop\setupsecurefolders.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
7580"C:\Users\admin\Desktop\SecureFolders.exe" C:\Users\admin\Desktop\SecureFolders.exeexplorer.exe
User:
admin
Company:
Promosoft Software Limited
Integrity Level:
MEDIUM
Description:
Secure Folders
Exit code:
0
Version:
1.0.0.9
Modules
Images
c:\users\admin\desktop\securefolders.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\ws2_32.dll
7628"C:\Users\admin\Desktop\SetupSecureFolders.exe" C:\Users\admin\Desktop\SetupSecureFolders.exe
explorer.exe
User:
admin
Company:
Promosoft Software Limited
Integrity Level:
HIGH
Description:
Secure Folders
Exit code:
1
Version:
1.0.0.9
Modules
Images
c:\users\admin\desktop\setupsecurefolders.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
7680C:\WINDOWS\System32\svchost.exe -k netsvcs -p -s BITSC:\Windows\System32\svchost.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Host Process for Windows Services
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\kernel.appcore.dll
7900C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
7932"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exeSppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
Total events
7 865
Read events
7 829
Write events
35
Delete events
1

Modification events

(PID) Process:(7628) SetupSecureFolders.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Persisted
Operation:writeName:C:\Users\admin\Desktop\SetupSecureFolders.exe
Value:
1
(PID) Process:(7628) SetupSecureFolders.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(7628) SetupSecureFolders.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(7628) SetupSecureFolders.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(7680) svchost.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\BITS
Operation:writeName:PerfMMFileName
Value:
Global\MMF_BITS29bb3390-4bbb-4217-9844-60111949316f
(PID) Process:(7628) SetupSecureFolders.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
Operation:writeName:Browse For Folder Width
Value:
318
(PID) Process:(7628) SetupSecureFolders.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
Operation:writeName:Browse For Folder Height
Value:
288
(PID) Process:(6572) SecureFolders.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\certsys
Operation:writeName:ImagePath
Value:
\SystemRoot\system32\drivers\certsys.sys
(PID) Process:(6572) SecureFolders.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\certsys
Operation:writeName:270
Value:
fa99b726
(PID) Process:(6572) SecureFolders.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\certsys
Operation:writeName:Type
Value:
1
Executable files
3
Suspicious files
4
Text files
3
Unknown types
0

Dropped files

PID
Process
Filename
Type
7628SetupSecureFolders.exeC:\ProgramData\{CF93D06A-43BB-4aa4-A4FB-99880124E1AB}.logtext
MD5:31EAF2B95224B72E4C87527AF7CD7B49
SHA256:5DC8F4224EB8A6CEC76AC6677D684E0D92234D0603CB6A64036E3AC8ADDA3CC8
7628SetupSecureFolders.exeC:\Users\admin\Desktop\SecureFolders.exeexecutable
MD5:841009D76C10C65FC34F3833173552D3
SHA256:1446F68F31EE406CE7590BF56DE58273F0DF7A49FF46AD89C9ABD39DA3AAFC34
7680svchost.exeC:\ProgramData\Microsoft\Network\Downloader\qmgr.jfmbinary
MD5:83B89C7945749BF8E29D2A7C8EC7DAC0
SHA256:BF6E96FDBE01B53A2A73F2D3FE7AD82DBF696401BA4745A2D941981F7C3EEFBB
7628SetupSecureFolders.exeC:\ProgramData\{28D5D3C0-9147-4bb7-B2D0-453118720FE3}\upddll.binexecutable
MD5:DB2E0BD7B1D890632F955EB08A1FABC7
SHA256:B6F3EE5885F0F89F5B10881A82185B7949250AE1496E01E5F2A5ACE5643589F9
7680svchost.exeC:\Users\admin\AppData\Local\Temp\BITBAA7.tmpbinary
MD5:140AAD5E4FDB1E38804EB7DAD2E90F0F
SHA256:C7D5CC220D1060540BD10ED8B20B9BDF8AF0697C37592B532A95E2D6A4C0A6A1
7680svchost.exeC:\ProgramData\Microsoft\Network\Downloader\qmgr.dbbinary
MD5:ADE3D8A0FBF7F87F07B018994AF82868
SHA256:C82BA2F4E2EFF71125FBCE71A2406CACB687B49B43380A0DC414B232C5A16DB9
6572SecureFolders.exeC:\ProgramData\{CF93D06A-43BB-4aa4-A4FB-99880124E1AC}.logtext
MD5:0EDA07CD51933D1CADE221723DDC0C4A
SHA256:6A6BFB7E9E629F9B948F9D3469FF550DECB677E6CB5F3028B1231236783C2DA9
7680svchost.exeC:\ProgramData\Microsoft\Network\Downloader\edb.logbinary
MD5:980093A2B12773C777501DB0E2D1E118
SHA256:94577086AD7B0D04F69CA10CEF552964D0E53A86E414502B90E8FD80A5D44F0A
6572SecureFolders.exeC:\Windows\System32\drivers\certsys.sysexecutable
MD5:EE5FBB361F4DDDA9121008C1905A1144
SHA256:04B461794313041D245E0D7F9A1C14D41267A9F6A6BF628B754D738DDDE6C0C0
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
11
TCP/UDP connections
26
DNS requests
14
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
23.216.77.25:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
7628
SetupSecureFolders.exe
GET
302
23.82.16.56:80
http://securefoldersfree.com/update/ver.php?v=1.0.0.9&t=beta
unknown
malicious
7680
svchost.exe
HEAD
302
23.82.16.56:80
http://securefoldersfree.com/update/ver.php?v=1.0.0.9&t=beta
unknown
malicious
7628
SetupSecureFolders.exe
GET
200
199.59.243.228:80
http://survey-smiles.com/
unknown
whitelisted
7680
svchost.exe
HEAD
200
199.59.243.228:80
http://survey-smiles.com/
unknown
whitelisted
7680
svchost.exe
GET
200
23.82.16.56:80
http://securefoldersfree.com/update/ver.php?v=1.0.0.9&t=beta
unknown
malicious
7680
svchost.exe
GET
200
23.82.16.56:80
http://securefoldersfree.com/update/ver.php?v=1.0.0.9&t=beta
unknown
malicious
6544
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
7232
SIHClient.exe
GET
200
23.209.214.100:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
6272
SecureFolders.exe
GET
200
23.82.16.56:80
http://securefoldersfree.com/update/ver.php?v=1.0.0.9&t=beta
unknown
malicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
23.216.77.25:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
3812
svchost.exe
239.255.255.250:1900
whitelisted
7628
SetupSecureFolders.exe
23.82.16.56:80
securefoldersfree.com
LEASEWEB-USA-SFO
US
malicious
7628
SetupSecureFolders.exe
199.59.243.228:80
survey-smiles.com
AMAZON-02
US
whitelisted
3216
svchost.exe
172.211.123.250:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
7680
svchost.exe
23.82.16.56:80
securefoldersfree.com
LEASEWEB-USA-SFO
US
malicious
7680
svchost.exe
199.59.243.228:80
survey-smiles.com
AMAZON-02
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 51.104.136.2
whitelisted
crl.microsoft.com
  • 23.216.77.25
  • 23.216.77.6
  • 23.216.77.20
  • 23.216.77.22
whitelisted
google.com
  • 142.250.185.78
whitelisted
securefoldersfree.com
  • 23.82.16.56
malicious
survey-smiles.com
  • 199.59.243.228
whitelisted
client.wns.windows.com
  • 172.211.123.250
whitelisted
login.live.com
  • 20.190.160.22
  • 20.190.160.132
  • 40.126.32.72
  • 40.126.32.134
  • 20.190.160.14
  • 20.190.160.17
  • 20.190.160.65
  • 40.126.32.76
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
slscr.update.microsoft.com
  • 4.175.87.197
whitelisted
www.microsoft.com
  • 23.209.214.100
whitelisted

Threats

No threats detected
No debug info