File name:

setup.exe

Full analysis: https://app.any.run/tasks/58bf2e01-d41c-4cb4-aa8c-c0afd79120fa
Verdict: Malicious activity
Analysis date: January 24, 2022, 20:25:54
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

0171E557093F33929439C2E8EE1743F3

SHA1:

F759C5424E00E07CF5A8FF0E9094A9813CD2A734

SHA256:

35DB24CC2DFB0EE2AB233641A193DECC39400BB27DB1B1E2FBBFFFB7D5E1BE2F

SSDEEP:

98304:7NHwpkO57QZjB6Ssmh9H9XeYB74P0FyX+p6FG0TH16+/nq5RxnzOQv66i:epkOSNBl74ny6FG0//nq5RxnzOQm

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • launcher.exe (PID: 2144)
    • Application was dropped or rewritten from another process

      • launcher.exe (PID: 2144)
    • Drops executable file immediately after starts

      • launcher.exe (PID: 2144)
  • SUSPICIOUS

    • Creates a software uninstall entry

      • setup.exe (PID: 3684)
    • Changes IE settings (feature browser emulation)

      • launcher.exe (PID: 2144)
    • Executable content was dropped or overwritten

      • setup.exe (PID: 3684)
      • launcher.exe (PID: 2144)
    • Reads the computer name

      • setup.exe (PID: 3684)
      • launcher.exe (PID: 2144)
    • Checks supported languages

      • launcher.exe (PID: 2144)
      • setup.exe (PID: 3684)
    • Drops a file with too old compile date

      • launcher.exe (PID: 2144)
    • Creates files in the user directory

      • setup.exe (PID: 3684)
    • Drops a file that was compiled in debug mode

      • launcher.exe (PID: 2144)
    • Creates files in the program directory

      • setup.exe (PID: 3684)
    • Creates a directory in Program Files

      • setup.exe (PID: 3684)
  • INFO

    • Manual execution by user

      • launcher.exe (PID: 2144)
    • Reads settings of System Certificates

      • launcher.exe (PID: 2144)
    • Checks Windows Trust Settings

      • launcher.exe (PID: 2144)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (35.8)
.exe | Win64 Executable (generic) (31.7)
.scr | Windows screen saver (15)
.dll | Win32 Dynamic Link Library (generic) (7.5)
.exe | Win32 Executable (generic) (5.1)

EXIF

EXE

SpecialBuild: -
ProductVersion: 2,0,0,45
ProductName: PopcornRP Launcher Installationsprogramm...
PrivateBuild: -
OriginalFileName: -
LegalTrademarks: -
LegalCopyright: -
InternalName: -
FileVersion: 2,0,0,45
FileDescription: -
CompanyName: -
Comments: -
CharacterSet: Unicode
LanguageCode: English (U.S.)
FileSubtype: -
ObjectFileType: Executable application
FileOS: Windows NT 32-bit
FileFlags: (none)
FileFlagsMask: 0x003f
ProductVersionNumber: 2.0.0.45
FileVersionNumber: 2.0.0.45
Subsystem: Windows GUI
SubsystemVersion: 4
ImageVersion: -
OSVersion: 4
EntryPoint: 0x1b832
UninitializedDataSize: -
InitializedDataSize: 81920
CodeSize: 135168
LinkerVersion: 6
PEType: PE32
TimeStamp: 2015:10:02 17:38:34+02:00
MachineType: Intel 386 or later, and compatibles
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
41
Monitored processes
3
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start setup.exe launcher.exe setup.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2144"C:\Program Files\PopcornRP Launcher\launcher.exe" C:\Program Files\PopcornRP Launcher\launcher.exe
Explorer.EXE
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Version:
1.54
Modules
Images
c:\program files\popcornrp launcher\launcher.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\lpk.dll
3684"C:\Users\admin\AppData\Local\Temp\setup.exe" C:\Users\admin\AppData\Local\Temp\setup.exe
Explorer.EXE
User:
admin
Integrity Level:
HIGH
Exit code:
0
Version:
2,0,0,45
Modules
Images
c:\windows\system32\ntdll.dll
c:\users\admin\appdata\local\temp\setup.exe
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\shlwapi.dll
3980"C:\Users\admin\AppData\Local\Temp\setup.exe" C:\Users\admin\AppData\Local\Temp\setup.exeExplorer.EXE
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Version:
2,0,0,45
Modules
Images
c:\users\admin\appdata\local\temp\setup.exe
c:\windows\system32\ntdll.dll
Total events
9 910
Read events
9 860
Write events
48
Delete events
2

Modification events

(PID) Process:(3684) setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\PopcornRP Launcher
Operation:writeName:DisplayName
Value:
PopcornRP Launcher
(PID) Process:(3684) setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\PopcornRP Launcher
Operation:writeName:UninstallString
Value:
C:\Program Files\PopcornRP Launcher\Uninstal.exe
(PID) Process:(2144) launcher.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Direct3D\MostRecentApplication
Operation:writeName:Name
Value:
launcher.exe
(PID) Process:(2144) launcher.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION
Operation:writeName:edrt.exe
Value:
11111
(PID) Process:(2144) launcher.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION
Operation:writeName:edrt.vhost.exe
Value:
11111
(PID) Process:(2144) launcher.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(2144) launcher.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
460000003B010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A80164000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(2144) launcher.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2144) launcher.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(2144) launcher.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
Executable files
49
Suspicious files
10
Text files
322
Unknown types
7

Dropped files

PID
Process
Filename
Type
3684setup.exeC:\Program Files\PopcornRP Launcher\Uninstal.$Aexecutable
MD5:
SHA256:
3684setup.exeC:\Program Files\PopcornRP Launcher\assets\popcorn.icoimage
MD5:
SHA256:
3684setup.exeC:\Program Files\PopcornRP Launcher\data\DISCORD.$Aimage
MD5:
SHA256:
3684setup.exeC:\Program Files\PopcornRP Launcher\data\launch.insbinary
MD5:
SHA256:
3684setup.exeC:\Program Files\PopcornRP Launcher\data\p1_bg.$Aimage
MD5:
SHA256:
3684setup.exeC:\Program Files\PopcornRP Launcher\data\p1_button0aimage
MD5:
SHA256:
3684setup.exeC:\Program Files\PopcornRP Launcher\data\p1_button0a.$Aimage
MD5:
SHA256:
3684setup.exeC:\Program Files\PopcornRP Launcher\Uninstal.exeexecutable
MD5:
SHA256:
3684setup.exeC:\Program Files\PopcornRP Launcher\data\DISCORDimage
MD5:
SHA256:
3684setup.exeC:\Program Files\PopcornRP Launcher\data\p0_bgimage
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
6
DNS requests
7
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2144
launcher.exe
GET
200
92.123.194.108:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?d2123cdb36abc3e4
unknown
compressed
59.9 Kb
whitelisted
2144
launcher.exe
GET
200
92.123.194.108:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?952a1e9d4ec0bf97
unknown
compressed
4.70 Kb
whitelisted
2144
launcher.exe
GET
200
92.123.194.108:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?ae014e30d38085cb
unknown
compressed
4.70 Kb
whitelisted
2144
launcher.exe
GET
200
92.123.194.108:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?4195ccf5bc654096
unknown
compressed
59.9 Kb
whitelisted
2144
launcher.exe
GET
200
23.32.238.51:80
http://r3.o.lencr.org/MFMwUTBPME0wSzAJBgUrDgMCGgUABBRI2smg%2ByvTLU%2Fw3mjS9We3NfmzxAQUFC6zF7dYVsuuUAlA5h%2BvnYsUwsYCEgMWm9uThZJ1f5R%2FlPJMRQ2scQ%3D%3D
US
der
503 b
shared
2144
launcher.exe
GET
200
23.45.105.185:80
http://x1.c.lencr.org/
NL
der
717 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2144
launcher.exe
92.123.194.108:80
ctldl.windowsupdate.com
Akamai International B.V.
suspicious
2144
launcher.exe
23.32.238.51:80
r3.o.lencr.org
XO Communications
US
unknown
2144
launcher.exe
23.45.105.185:80
x1.c.lencr.org
Akamai International B.V.
NL
unknown
2144
launcher.exe
91.216.248.21:443
popcornrp.com
23media GmbH
DE
malicious

DNS requests

Domain
IP
Reputation
popcornrp.com
  • 91.216.248.21
  • 91.216.248.22
  • 91.216.248.23
malicious
ctldl.windowsupdate.com
  • 92.123.194.108
  • 92.123.194.121
  • 8.253.95.249
  • 8.248.115.254
  • 8.248.141.254
  • 67.26.83.254
  • 67.27.157.126
whitelisted
x1.c.lencr.org
  • 23.45.105.185
whitelisted
r3.o.lencr.org
  • 23.32.238.51
  • 23.32.238.67
shared

Threats

No threats detected
Process
Message
launcher.exe
Start app
launcher.exe
Start app
launcher.exe
Start app
launcher.exe
Start app
launcher.exe
End app
launcher.exe
End app