File name:

StartAllBack_3.7.11_setup.exe

Full analysis: https://app.any.run/tasks/e588f63f-71d1-40f7-8dc9-6c589f05f1d5
Verdict: Malicious activity
Analysis date: July 21, 2024, 03:02:26
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32+ executable (GUI) x86-64, for MS Windows
MD5:

6696CCF233E08B82318D0E766B417EF1

SHA1:

78792ACB45BE9F1F0BF93429D0B5247E49890858

SHA256:

3C4421A6D604758D0BDA4B858D72023422DA273F4A3FE557913C3C965B5CDB53

SSDEEP:

98304:qVHHjGbwrmoMlCZBOmkMSRQdk9CPR3Sz+yrReUHdwfmBkNePiDf/RSLwGlgQ/Mzm:OyBZX

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • StartAllBack_3.7.11_setup.exe (PID: 7096)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • StartAllBack_3.7.11_setup.exe (PID: 7096)
    • Reads the date of Windows installation

      • StartAllBack_3.7.11_setup.exe (PID: 7096)
    • Executable content was dropped or overwritten

      • StartAllBack_3.7.11_setup.exe (PID: 7096)
  • INFO

    • Reads the computer name

      • StartAllBack_3.7.11_setup.exe (PID: 7096)
      • StartAllBackCfg.exe (PID: 6940)
    • Checks supported languages

      • StartAllBack_3.7.11_setup.exe (PID: 7096)
      • StartAllBackCfg.exe (PID: 6940)
    • Process checks computer location settings

      • StartAllBack_3.7.11_setup.exe (PID: 7096)
    • Create files in a temporary directory

      • StartAllBack_3.7.11_setup.exe (PID: 7096)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (87.3)
.exe | Generic Win/DOS Executable (6.3)
.exe | DOS Executable Generic (6.3)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2024:04:20 16:00:09+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 14.39
CodeSize: 34304
InitializedDataSize: 54784
UninitializedDataSize: -
EntryPoint: 0x1880
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.1000
ProductVersionNumber: 1.0.0.1000
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: www.startallback.com
FileDescription: StartAllBack setup SFX
FileVersion: 1.0.0
LegalCopyright: Copyright (C) 2012-2022, Tihiy
OriginalFileName: 7-zip SfxSetup.exe
ProductName: StartAllBack
ProductVersion: 1.0.0
No data.
screenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
133
Monitored processes
3
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start startallback_3.7.11_setup.exe startallbackcfg.exe no specs slui.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
3540C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
6940"C:\Users\admin\AppData\Local\Temp\SIBSFX.2F890BB8\StartAllBackCfg.exe" /install C:\Users\admin\AppData\Local\Temp\SIBSFX.2F890BB8\StartAllBackCfg.exeStartAllBack_3.7.11_setup.exe
User:
admin
Integrity Level:
MEDIUM
Description:
StartAllBack
Exit code:
0
Version:
3.7.11.4916
Modules
Images
c:\users\admin\appdata\local\temp\sibsfx.2f890bb8\startallbackcfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
7096"C:\Users\admin\StartAllBack_3.7.11_setup.exe" C:\Users\admin\StartAllBack_3.7.11_setup.exe
explorer.exe
User:
admin
Company:
www.startallback.com
Integrity Level:
MEDIUM
Description:
StartAllBack setup SFX
Exit code:
0
Version:
1.0.0
Modules
Images
c:\users\admin\startallback_3.7.11_setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
Total events
4 133
Read events
4 133
Write events
0
Delete events
0

Modification events

No data
Executable files
15
Suspicious files
0
Text files
47
Unknown types
0

Dropped files

PID
Process
Filename
Type
7096StartAllBack_3.7.11_setup.exeC:\Users\admin\AppData\Local\Temp\SIBSFX.2F890BB8\Orbs\clover.svgimage
MD5:47B9BE5D069D6873CC9BFC3FC7C3B9B2
SHA256:1E0E1EA6149FFFE9A6D09A77B404FE17DB7D455D1036FAEBDC168B1CE5869282
7096StartAllBack_3.7.11_setup.exeC:\Users\admin\AppData\Local\Temp\SIBSFX.2F890BB8\Orbs\w8logo.svgimage
MD5:F13738B41B7A2042C53DD228601639E0
SHA256:C75684410793A98A051A1CF95395709C73E9589037D47BE3F6277B4AC355B7FB
7096StartAllBack_3.7.11_setup.exeC:\Users\admin\AppData\Local\Temp\SIBSFX.2F890BB8\Ribbon\theme-dark\Windows.AddRemovePrograms.svgimage
MD5:E0F7EF3D2F36317931A42DDDD494C9C2
SHA256:F51C5B5B68F6BC5104188A93F145CA2D6E57D94636FDA34E41599BAE0E5EC682
7096StartAllBack_3.7.11_setup.exeC:\Users\admin\AppData\Local\Temp\SIBSFX.2F890BB8\Ribbon\theme-dark\Windows.MoveToMenu.svgimage
MD5:7BEACB39451CA90854D81DC79B25F579
SHA256:40F70DB8F7814ACF922E25411F82F9D9B9420D30E34F5C6199B8488E260CA13F
7096StartAllBack_3.7.11_setup.exeC:\Users\admin\AppData\Local\Temp\SIBSFX.2F890BB8\Ribbon\theme-dark\windows.hideSelected.svgimage
MD5:AEA15430DEF6CFDA52866C7ACCE670CB
SHA256:931320E31E415B420AA1985D2B7305D4F3B1D2F1D8FFDDB18C01690AA84F3D20
7096StartAllBack_3.7.11_setup.exeC:\Users\admin\AppData\Local\Temp\SIBSFX.2F890BB8\Ribbon\theme-dark\windows.help.svgimage
MD5:613988BED41860A9CD8716E840F1B43A
SHA256:2AED30DCCA71F8D120CFFC6B01C318BF1898E62615045FEA5E33E1552F289E93
7096StartAllBack_3.7.11_setup.exeC:\Users\admin\AppData\Local\Temp\SIBSFX.2F890BB8\Ribbon\theme-dark\windows.folderoptions.svgimage
MD5:FB052EE6B0D4EB3A0AC028075E212E49
SHA256:3615AD11593E0FA41C9FCEBE32B9E96865CF13A27640F87802AA3C33730A05EB
7096StartAllBack_3.7.11_setup.exeC:\Users\admin\AppData\Local\Temp\SIBSFX.2F890BB8\Ribbon\theme-dark\Windows.CopyToMenu.svgimage
MD5:719B1C337F9362D872C788C1B8A443F2
SHA256:0D4EFB27E6C7B774206155DD6ABDDD2CC85635A467C869C7675DA196869A5E2B
7096StartAllBack_3.7.11_setup.exeC:\Users\admin\AppData\Local\Temp\SIBSFX.2F890BB8\Ribbon\theme-dark\windows.layout.svgimage
MD5:2105FF4F8F0FEFEFA00B5DDD93ED9D79
SHA256:F39D73C1CD814615AA74CE9FC04A4B7F4C83156B2173875134EAA3F60FB70C7E
7096StartAllBack_3.7.11_setup.exeC:\Users\admin\AppData\Local\Temp\SIBSFX.2F890BB8\Ribbon\theme-dark\windows.open.svgimage
MD5:536711AA27AAF290C2410DCDA8E2B591
SHA256:412A37D3E1856910F22C2C35071EAE274E3D83047E7A33339F31F501CC5579B2
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
36
DNS requests
8
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4716
svchost.exe
20.190.159.4:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
20.190.159.4:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
7856
svchost.exe
4.208.221.206:443
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
20.199.58.43:443
arc.msn.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
unknown
4032
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:138
whitelisted
20.223.35.26:443
fd.api.iris.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown

DNS requests

Domain
IP
Reputation
login.live.com
  • 20.190.159.4
  • 20.190.159.73
  • 20.190.159.68
  • 20.190.159.2
  • 20.190.159.71
  • 40.126.31.67
  • 40.126.31.69
  • 40.126.31.73
whitelisted
settings-win.data.microsoft.com
  • 40.127.240.158
  • 51.104.136.2
whitelisted
google.com
  • 172.217.18.14
whitelisted
arc.msn.com
  • 20.199.58.43
whitelisted
fd.api.iris.microsoft.com
  • 20.223.35.26
whitelisted
activation-v2.sls.microsoft.com
  • 40.91.76.224
whitelisted

Threats

No threats detected
No debug info