File name:

C:\Users\admin\AppData\Local\Temp\Rar$EXb2468.46380\Passwd_2023_thepcworlds\Installer_6.1.86.1081_native.exe

Full analysis: https://app.any.run/tasks/a85cf0ae-2a06-47e1-a005-f70b82c6f01d
Verdict: Malicious activity
Analysis date: July 01, 2023, 09:11:12
OS: Windows 7 Professional Service Pack 1 (build: 7601, 64 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

5ABB56E80FB980604CA7667ECEB068DA

SHA1:

3744C04157BE5241E705E5A18CB7A89241D7F677

SHA256:

3FE53E8DB0D7B1F3943AA1ACF62A3648A2E941E8B4436D3A7163D322DF3B3571

SSDEEP:

393216:r0EjpxUtm9Vq5rJnQciJpnvOBv3etMDoC3JW0Bc7SK1VCnE:YEVedJnQRpvOctoX5c3P0E

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • msiexec.exe (PID: 2876)
      • msiexec.exe (PID: 1720)
  • SUSPICIOUS

    • Reads the Windows owner or organization settings

      • Installer_6.1.86.1081_native.exe (PID: 2444)
      • msiexec.exe (PID: 2912)
    • Executable content was dropped or overwritten

      • Installer_6.1.86.1081_native.exe (PID: 2444)
  • INFO

    • Checks supported languages

      • Installer_6.1.86.1081_native.exe (PID: 2444)
      • msiexec.exe (PID: 2912)
      • msiexec.exe (PID: 1720)
      • msiexec.exe (PID: 2876)
    • Reads the machine GUID from the registry

      • Installer_6.1.86.1081_native.exe (PID: 2444)
      • msiexec.exe (PID: 2912)
      • msiexec.exe (PID: 1720)
      • msiexec.exe (PID: 2876)
    • The process checks LSA protection

      • Installer_6.1.86.1081_native.exe (PID: 2444)
      • msiexec.exe (PID: 2912)
      • msiexec.exe (PID: 1720)
      • msiexec.exe (PID: 1232)
      • msiexec.exe (PID: 2876)
      • explorer.exe (PID: 2352)
    • Reads the computer name

      • Installer_6.1.86.1081_native.exe (PID: 2444)
      • msiexec.exe (PID: 2912)
      • msiexec.exe (PID: 1720)
      • msiexec.exe (PID: 2876)
    • Creates files or folders in the user directory

      • Installer_6.1.86.1081_native.exe (PID: 2444)
    • Reads Environment values

      • Installer_6.1.86.1081_native.exe (PID: 2444)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 2912)
    • Create files in a temporary directory

      • msiexec.exe (PID: 1232)
    • Manual execution by a user

      • explorer.exe (PID: 2352)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable (generic) (52.9)
.exe | Generic Win/DOS Executable (23.5)
.exe | DOS Executable Generic (23.5)

EXIF

EXE

ProductVersion: 4.0.6.177
ProductName: 3D Scratch Studio
OriginalFileName: sqlservr.exe
LegalCopyright: Copyright (C) 2023 Anodising Lab
InternalName: sqlservr
FileVersion: 4.0.6.177
FileDescription: 3D Scratch Studio Installer
CompanyName: Anodising Lab
CharacterSet: Unicode
LanguageCode: English (U.S.)
FileSubtype: -
ObjectFileType: Dynamic link library
FileOS: Win32
FileFlags: Debug
FileFlagsMask: 0x003f
ProductVersionNumber: 4.0.6.177
FileVersionNumber: 4.0.6.177
Subsystem: Windows GUI
SubsystemVersion: 6
ImageVersion: -
OSVersion: 6
EntryPoint: 0x1d68a4
UninitializedDataSize: -
InitializedDataSize: 1250304
CodeSize: 2482176
LinkerVersion: 14.35
PEType: PE32
ImageFileCharacteristics: Executable, Large address aware, 32-bit
TimeStamp: 2023:05:25 08:35:12+00:00
MachineType: Intel 386 or later, and compatibles

Summary

Architecture: IMAGE_FILE_MACHINE_I386
Subsystem: IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date: 25-May-2023 08:35:12
Detected languages:
  • English - United States
Debug artifacts:
  • C:\ReleaseAI\win\Release\stubs\x86\ExternalUi.pdb
CompanyName: Anodising Lab
FileDescription: 3D Scratch Studio Installer
FileVersion: 4.0.6.177
InternalName: sqlservr
LegalCopyright: Copyright (C) 2023 Anodising Lab
OriginalFileName: sqlservr.exe
ProductName: 3D Scratch Studio
ProductVersion: 4.0.6.177

DOS Header

Magic number: MZ
Bytes on last page of file: 0x0090
Pages in file: 0x0003
Relocations: 0x0000
Size of header: 0x0004
Min extra paragraphs: 0x0000
Max extra paragraphs: 0xFFFF
Initial SS value: 0x0000
Initial SP value: 0x00B8
Checksum: 0x0000
Initial IP value: 0x0000
Initial CS value: 0x0000
Overlay number: 0x0000
OEM identifier: 0x0000
OEM information: 0x0000
Address of NE header: 0x00000110

PE Headers

Signature: PE
Machine: IMAGE_FILE_MACHINE_I386
Number of sections: 5
Time date stamp: 25-May-2023 08:35:12
Pointer to Symbol Table: 0x00000000
Number of symbols: 0
Size of Optional Header: 0x00E0
Characteristics:
  • IMAGE_FILE_32BIT_MACHINE
  • IMAGE_FILE_EXECUTABLE_IMAGE
  • IMAGE_FILE_LARGE_ADDRESS_AWARE

Sections

Name
Virtual Address
Virtual Size
Raw Size
Charateristics
Entropy
.text
0x00001000
0x0025DFF6
0x0025E000
IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
6.45505
.rdata
0x0025F000
0x0008CB32
0x0008CC00
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
4.5825
.data
0x002EC000
0x0000D0E0
0x00003A00
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
4.83058
.rsrc
0x002FA000
0x00078D14
0x00078E00
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
7.24703
.reloc
0x00373000
0x00027FE4
0x00028000
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
6.51912

Resources

Title
Entropy
Size
Codepage
Language
Type
1
5.22699
2067
Latin 1 / Western European
English - United States
RT_MANIFEST
2
6.18063
2488
Latin 1 / Western European
English - United States
RT_ICON
3
5.77447
4392
Latin 1 / Western European
English - United States
RT_ICON
4
5.6957
9832
Latin 1 / Western European
English - United States
RT_ICON
5
6.11664
17448
Latin 1 / Western European
English - United States
RT_ICON
6
6.10505
22072
Latin 1 / Western European
English - United States
RT_ICON
7
6.16434
39208
Latin 1 / Western European
English - United States
RT_ICON
8
7.96092
16588
Latin 1 / Western European
English - United States
RT_ICON
9
3.29815
564
Latin 1 / Western European
English - United States
RT_STRING
10
3.15121
386
Latin 1 / Western European
English - United States
RT_STRING

Imports

KERNEL32.dll
msi.dll (delay-loaded)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
38
Monitored processes
6
Malicious processes
0
Suspicious processes
4

Behavior graph

Click at the process to see the details
start installer_6.1.86.1081_native.exe msiexec.exe msiexec.exe no specs msiexec.exe no specs msiexec.exe no specs explorer.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1232"C:\Windows\system32\msiexec.exe" /i "C:\Users\admin\AppData\Roaming\Anodising Lab\3D Scratch Studio 4.0.6.177\install\69BBB31\3D Scratch Studio.msi" /quiet /qn /norestart AI_SETUPEXEPATH=C:\Users\admin\AppData\Local\Temp\Installer_6.1.86.1081_native.exe SETUPEXEDIR=C:\Users\admin\AppData\Local\Temp\ EXE_CMD_LINE="/exenoupdates /forcecleanup /wintime 1688200755 " AI_EUIMSI=""C:\Windows\SysWOW64\msiexec.exeInstaller_6.1.86.1081_native.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
1603
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\syswow64\msiexec.exe
c:\windows\syswow64\ntdll.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\kernelbase.dll
1720C:\Windows\syswow64\MsiExec.exe -Embedding A1DBC10EFC15D75E4E1C563C8E86FCA4 CC:\Windows\SysWOW64\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\syswow64\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\wow64.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\kernelbase.dll
2352"C:\Windows\explorer.exe" C:\Windows\explorer.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2444"C:\Users\admin\AppData\Local\Temp\Installer_6.1.86.1081_native.exe" C:\Users\admin\AppData\Local\Temp\Installer_6.1.86.1081_native.exe
explorer.exe
User:
admin
Company:
Anodising Lab
Integrity Level:
MEDIUM
Description:
3D Scratch Studio Installer
Exit code:
1603
Version:
4.0.6.177
Modules
Images
c:\users\admin\appdata\local\temp\installer_6.1.86.1081_native.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64.dll
c:\windows\syswow64\kernelbase.dll
2876C:\Windows\syswow64\MsiExec.exe -Embedding 0E17E19F03850027CB7DC454326F81DCC:\Windows\SysWOW64\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\syswow64\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\kernelbase.dll
2912C:\Windows\system32\msiexec.exe /VC:\Windows\System32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
1 982
Read events
1 977
Write events
0
Delete events
5

Modification events

(PID) Process:(2912) msiexec.exeKey:HKEY_USERS\S-1-5-21-3896776584-4254864009-862391680-1000\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:Sequence
Value:
1
(PID) Process:(2912) msiexec.exeKey:HKEY_USERS\S-1-5-21-3896776584-4254864009-862391680-1000\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:SessionHash
Value:
21FBB7A243EB5CFCC8895F004C20C1E68AFDF13373650DB5966B157775DB6C5C
(PID) Process:(2912) msiexec.exeKey:HKEY_USERS\S-1-5-21-3896776584-4254864009-862391680-1000\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:Owner
Value:
600B000078F16804FCABD901
(PID) Process:(2912) msiexec.exeKey:HKEY_USERS\S-1-5-21-3896776584-4254864009-862391680-1000\Software\Microsoft\RestartManager\Session0000
Operation:delete keyName:(default)
Value:
(PID) Process:(2444) Installer_6.1.86.1081_native.exeKey:HKEY_CURRENT_USER\Software\AiTemp
Operation:delete keyName:(default)
Value:
Executable files
5
Suspicious files
0
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
2444Installer_6.1.86.1081_native.exeC:\Users\admin\AppData\Roaming\Anodising Lab\3D Scratch Studio 4.0.6.177\install\holder0.aiph
MD5:
SHA256:
2444Installer_6.1.86.1081_native.exeC:\Users\admin\AppData\Roaming\Anodising Lab\3D Scratch Studio 4.0.6.177\install\69BBB31\3D Scratch Studio.msiexecutable
MD5:D52EDE6573659F1591DCAA9365F9CAF8
SHA256:3BFF98CA89E53B45B383C04E0D66E0D97AC84DA775BE87F1DF249DE21751A43E
2444Installer_6.1.86.1081_native.exeC:\Users\admin\AppData\Local\Temp\MSI7E1C.tmpexecutable
MD5:9E0AEF52F6C03B2FEA067342D9D4F22F
SHA256:42B8ADAFCB4E8496D9822A0C504F449E56456528A9251C153381D3F63D197E5B
2912msiexec.exeC:\Windows\Installer\1d7ec8.msiexecutable
MD5:D52EDE6573659F1591DCAA9365F9CAF8
SHA256:3BFF98CA89E53B45B383C04E0D66E0D97AC84DA775BE87F1DF249DE21751A43E
2912msiexec.exeC:\Windows\Installer\MSI7F16.tmpexecutable
MD5:9E0AEF52F6C03B2FEA067342D9D4F22F
SHA256:42B8ADAFCB4E8496D9822A0C504F449E56456528A9251C153381D3F63D197E5B
2912msiexec.exeC:\Windows\Installer\MSI7F55.tmpexecutable
MD5:9E0AEF52F6C03B2FEA067342D9D4F22F
SHA256:42B8ADAFCB4E8496D9822A0C504F449E56456528A9251C153381D3F63D197E5B
1232msiexec.exeC:\Users\admin\AppData\Local\Temp\MSId7f64.LOGtext
MD5:D68F2AA9F1E7CCFCDAC44D7782713834
SHA256:67421F8BB8C4AE3BFD541FF05CB2D6454AA018227DA3FDE5EB07D04C69CDDAEA
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
3
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
328
svchost.exe
224.0.0.252:5355
unknown

DNS requests

No data

Threats

No threats detected
No debug info