| File name: | KeePass-2.55-Setup.exe |
| Full analysis: | https://app.any.run/tasks/2f2bf994-3957-488b-b0f1-ceb95cd7771d |
| Verdict: | Malicious activity |
| Analysis date: | January 12, 2024, 21:18:46 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 85A374B5F3FA0402081C39B002619353 |
| SHA1: | 5754A7DE25E791EA26EED342F3839A823279EE98 |
| SHA256: | 37C2488E0D29E2ADE03827DD3D9C4C4563C4506B98BA24BB3EF1981FDD6D765D |
| SSDEEP: | 98304:L+cD4dndUSIh1GJwXuj5RZLud5xT/QFyBo9kp963Oi7mDwS6qybDZpyTnfqF0azo:nSLU1tx+Bk |
| .exe | | | Inno Setup installer (51.8) |
|---|---|---|
| .exe | | | InstallShield setup (20.3) |
| .exe | | | Win32 EXE PECompact compressed (generic) (19.6) |
| .dll | | | Win32 Dynamic Link Library (generic) (3.1) |
| .exe | | | Win32 Executable (generic) (2.1) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2023:02:15 15:54:16+01:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi |
| PEType: | PE32 |
| LinkerVersion: | 2.25 |
| CodeSize: | 741888 |
| InitializedDataSize: | 38400 |
| UninitializedDataSize: | - |
| EntryPoint: | 0xb5eec |
| OSVersion: | 6.1 |
| ImageVersion: | 6 |
| SubsystemVersion: | 6.1 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 2.55.0.0 |
| ProductVersionNumber: | 2.55.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| Comments: | This installation was built with Inno Setup. |
| CompanyName: | Dominik Reichl |
| FileDescription: | KeePass Password Safe 2.55 Setup |
| FileVersion: | 2.55.0.0 |
| LegalCopyright: | Copyright © 2003-2023 Dominik Reichl |
| OriginalFileName: | |
| ProductName: | KeePass Password Safe |
| ProductVersion: | 2.55 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 480 | "C:\Users\admin\Desktop\KeePass-2.55-Setup.exe" /SPAWNWND=$501B2 /NOTIFYWND=$301AA | C:\Users\admin\Desktop\KeePass-2.55-Setup.exe | KeePass-2.55-Setup.tmp | ||||||||||||
User: admin Company: Dominik Reichl Integrity Level: HIGH Description: KeePass Password Safe 2.55 Setup Exit code: 0 Version: 2.55.0.0 Modules
| |||||||||||||||
| 552 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --disable-quic --mojo-platform-channel-handle=1592 --field-trial-handle=1160,i,612328838109512418,10535124956103197967,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
| |||||||||||||||
| 664 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --disable-quic --mojo-platform-channel-handle=1276 --field-trial-handle=1160,i,612328838109512418,10535124956103197967,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | chrome.exe | ||||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
| |||||||||||||||
| 712 | "C:\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.exe" uninstall "C:\Program Files\KeePass Password Safe 2\KeePass.exe" | C:\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.exe | — | ShInstUtil.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft Common Language Runtime native compiler Exit code: 4294967295 Version: 4.8.3761.0 built by: NET48REL1 Modules
| |||||||||||||||
| 764 | "C:\Program Files\KeePass Password Safe 2\ShInstUtil.exe" net_check | C:\Program Files\KeePass Password Safe 2\ShInstUtil.exe | — | KeePass-2.55-Setup.tmp | |||||||||||
User: admin Company: Dominik Reichl Integrity Level: HIGH Description: ShInstUtil - KeePass Helper Utility Exit code: 0 Version: 2.55.0.0 Modules
| |||||||||||||||
| 796 | "C:\Program Files\Google\Chrome\Application\chrome.exe" "--disable-features=OptimizationGuideModelDownloading,OptimizationHintsFetching,OptimizationTargetPrediction,OptimizationHints" | C:\Program Files\Google\Chrome\Application\chrome.exe | explorer.exe | ||||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
| |||||||||||||||
| 1040 | "C:\Users\admin\AppData\Local\Temp\is-J6CFM.tmp\KeePass-2.55-Setup.tmp" /SL5="$400E6,3468729,781312,C:\Users\admin\Desktop\KeePass-2.55-Setup.exe" /SPAWNWND=$501B2 /NOTIFYWND=$301AA | C:\Users\admin\AppData\Local\Temp\is-J6CFM.tmp\KeePass-2.55-Setup.tmp | KeePass-2.55-Setup.exe | ||||||||||||
User: admin Company: Dominik Reichl Integrity Level: HIGH Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 Modules
| |||||||||||||||
| 1112 | "C:\Program Files\KeePass Password Safe 2\ShInstUtil.exe" preload_register | C:\Program Files\KeePass Password Safe 2\ShInstUtil.exe | — | KeePass-2.55-Setup.tmp | |||||||||||
User: admin Company: Dominik Reichl Integrity Level: HIGH Description: ShInstUtil - KeePass Helper Utility Exit code: 0 Version: 2.55.0.0 Modules
| |||||||||||||||
| 1484 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=8 --mojo-platform-channel-handle=1316 --field-trial-handle=1160,i,612328838109512418,10535124956103197967,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
| |||||||||||||||
| 1528 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1084 --field-trial-handle=1160,i,612328838109512418,10535124956103197967,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:2 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
| |||||||||||||||
| (PID) Process: | (2128) ShInstUtil.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (2128) ShInstUtil.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (2128) ShInstUtil.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (2128) ShInstUtil.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (1928) ngen.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\v2.0.50727\NGENService\Roots |
| Operation: | write | Name: | WorkPending |
Value: 0 | |||
| (PID) Process: | (1928) ngen.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\v2.0.50727\NGENService\Roots\C:/Program Files/KeePass Password Safe 2/KeePass.exe\0 |
| Operation: | write | Name: | ImageList |
Value: 0100000000020000006A00000043003A005C00500072006F006700720061006D002000460069006C00650073005C004B006500650050006100730073002000500061007300730077006F007200640020005300610066006500200032005C004B006500650050006100730073002E006500780065000000000000000000000000 | |||
| (PID) Process: | (1928) ngen.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\v2.0.50727\NGENService\Roots\C:/Program Files/KeePass Password Safe 2/KeePass.exe\0 |
| Operation: | write | Name: | Status |
Value: 2 | |||
| (PID) Process: | (796) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
| Operation: | write | Name: | failed_count |
Value: 0 | |||
| (PID) Process: | (796) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
| Operation: | write | Name: | state |
Value: 1 | |||
| (PID) Process: | (796) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty |
| Operation: | write | Name: | StatusCodes |
Value: 01000000 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1040 | KeePass-2.55-Setup.tmp | C:\Program Files\KeePass Password Safe 2\is-B3BAF.tmp | executable | |
MD5:99E2FD5C60D2FFF2582CA32D28BE8B18 | SHA256:9BEFAFF16298EEBF6D08C0E3892EAE93C27F0D2EE607178D69A40940000405AF | |||
| 1040 | KeePass-2.55-Setup.tmp | C:\Program Files\KeePass Password Safe 2\KeePass.exe | executable | |
MD5:ABE4019FFAA18ADA3AD992624327E8C3 | SHA256:AF2C492AF5BDD9F6BB5FD0973E70C9A6A31A6258F271EA6CB3424E501008124F | |||
| 1040 | KeePass-2.55-Setup.tmp | C:\Program Files\KeePass Password Safe 2\unins000.exe | executable | |
MD5:99E2FD5C60D2FFF2582CA32D28BE8B18 | SHA256:9BEFAFF16298EEBF6D08C0E3892EAE93C27F0D2EE607178D69A40940000405AF | |||
| 1040 | KeePass-2.55-Setup.tmp | C:\Program Files\KeePass Password Safe 2\KeePass.XmlSerializers.dll | executable | |
MD5:915464316DBE796726B387CF9758CDC4 | SHA256:CC0389A94DE3CB21E116173741EA6AFE1D310D58ED28991308E4818A81F26E1E | |||
| 480 | KeePass-2.55-Setup.exe | C:\Users\admin\AppData\Local\Temp\is-J6CFM.tmp\KeePass-2.55-Setup.tmp | executable | |
MD5:30B3079D01A8783CEF734E73341E904F | SHA256:2E53E5B4906B0743B22FE08538BD9772F20B6D54D4C9987A72E226C29C1923CD | |||
| 1040 | KeePass-2.55-Setup.tmp | C:\Program Files\KeePass Password Safe 2\KeePass.exe.config | xml | |
MD5:1E94157E4BE96C705ADB7322E889A5E7 | SHA256:A5666AB533FA9E5571F42F7B1718F60506E042B6B91C87D46D2B507CE6D84B54 | |||
| 1040 | KeePass-2.55-Setup.tmp | C:\Program Files\KeePass Password Safe 2\is-LHRCH.tmp | executable | |
MD5:ABE4019FFAA18ADA3AD992624327E8C3 | SHA256:AF2C492AF5BDD9F6BB5FD0973E70C9A6A31A6258F271EA6CB3424E501008124F | |||
| 1040 | KeePass-2.55-Setup.tmp | C:\Program Files\KeePass Password Safe 2\is-8R0U4.tmp | executable | |
MD5:047B76689E7C18DA2FABB17CD0B240D9 | SHA256:0ABA3B195D9DBF035676004DC938F46FC6D352F0FAC40D35BD8DBA13D2A07687 | |||
| 1040 | KeePass-2.55-Setup.tmp | C:\Program Files\KeePass Password Safe 2\ShInstUtil.exe | executable | |
MD5:047B76689E7C18DA2FABB17CD0B240D9 | SHA256:0ABA3B195D9DBF035676004DC938F46FC6D352F0FAC40D35BD8DBA13D2A07687 | |||
| 1040 | KeePass-2.55-Setup.tmp | C:\Program Files\KeePass Password Safe 2\KeePass.config.xml | xml | |
MD5:AC0F1E104F82D295C27646BFFF39FECC | SHA256:C4A3626BBCDFE4B17759E75582AD5F89BEAA28EFC857431F373E104FBE7B8440 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
856 | svchost.exe | GET | 206 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/adhioj45hzjkfunn7ccrbqyyhu3q_20230916.567854667.14/obedbbhbpmojnkanicioggnmelmoomoc_20230916.567854667.14_all_ENUS500000_lr7434qyx46lykosg2elaepqdi.crx3 | unknown | binary | 175 Kb | unknown |
856 | svchost.exe | GET | 206 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/adhioj45hzjkfunn7ccrbqyyhu3q_20230916.567854667.14/obedbbhbpmojnkanicioggnmelmoomoc_20230916.567854667.14_all_ENUS500000_lr7434qyx46lykosg2elaepqdi.crx3 | unknown | binary | 34.8 Kb | unknown |
856 | svchost.exe | GET | 206 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/adhioj45hzjkfunn7ccrbqyyhu3q_20230916.567854667.14/obedbbhbpmojnkanicioggnmelmoomoc_20230916.567854667.14_all_ENUS500000_lr7434qyx46lykosg2elaepqdi.crx3 | unknown | binary | 350 Kb | unknown |
856 | svchost.exe | GET | 206 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/adhioj45hzjkfunn7ccrbqyyhu3q_20230916.567854667.14/obedbbhbpmojnkanicioggnmelmoomoc_20230916.567854667.14_all_ENUS500000_lr7434qyx46lykosg2elaepqdi.crx3 | unknown | binary | 438 Kb | unknown |
856 | svchost.exe | GET | 206 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/adhioj45hzjkfunn7ccrbqyyhu3q_20230916.567854667.14/obedbbhbpmojnkanicioggnmelmoomoc_20230916.567854667.14_all_ENUS500000_lr7434qyx46lykosg2elaepqdi.crx3 | unknown | binary | 583 Kb | unknown |
856 | svchost.exe | GET | 206 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/adhioj45hzjkfunn7ccrbqyyhu3q_20230916.567854667.14/obedbbhbpmojnkanicioggnmelmoomoc_20230916.567854667.14_all_ENUS500000_lr7434qyx46lykosg2elaepqdi.crx3 | unknown | binary | 441 Kb | unknown |
856 | svchost.exe | GET | 206 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/adhioj45hzjkfunn7ccrbqyyhu3q_20230916.567854667.14/obedbbhbpmojnkanicioggnmelmoomoc_20230916.567854667.14_all_ENUS500000_lr7434qyx46lykosg2elaepqdi.crx3 | unknown | binary | 876 Kb | unknown |
856 | svchost.exe | GET | 206 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/adhioj45hzjkfunn7ccrbqyyhu3q_20230916.567854667.14/obedbbhbpmojnkanicioggnmelmoomoc_20230916.567854667.14_all_ENUS500000_lr7434qyx46lykosg2elaepqdi.crx3 | unknown | binary | 204 Kb | unknown |
856 | svchost.exe | GET | 206 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/adhioj45hzjkfunn7ccrbqyyhu3q_20230916.567854667.14/obedbbhbpmojnkanicioggnmelmoomoc_20230916.567854667.14_all_ENUS500000_lr7434qyx46lykosg2elaepqdi.crx3 | unknown | binary | 956 Kb | unknown |
2740 | KeePass.exe | GET | 200 | 45.79.136.44:80 | http://mitchcapper.com/keepass_versions.txt?KPFP | unknown | text | 71 b | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
664 | chrome.exe | 108.177.15.84:443 | accounts.google.com | GOOGLE | US | unknown |
796 | chrome.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
664 | chrome.exe | 142.250.186.35:443 | clientservices.googleapis.com | GOOGLE | US | whitelisted |
664 | chrome.exe | 216.58.206.36:443 | www.google.com | GOOGLE | US | whitelisted |
664 | chrome.exe | 142.250.185.67:443 | www.gstatic.com | GOOGLE | US | whitelisted |
664 | chrome.exe | 142.250.184.238:443 | apis.google.com | GOOGLE | US | whitelisted |
664 | chrome.exe | 142.250.186.46:443 | encrypted-tbn0.gstatic.com | GOOGLE | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
accounts.google.com |
| shared |
clientservices.googleapis.com |
| whitelisted |
www.google.com |
| whitelisted |
www.gstatic.com |
| whitelisted |
apis.google.com |
| whitelisted |
update.googleapis.com |
| whitelisted |
encrypted-tbn0.gstatic.com |
| whitelisted |
lh5.googleusercontent.com |
| whitelisted |
fonts.gstatic.com |
| whitelisted |
www.googleapis.com |
| whitelisted |