File name:

OInstall.exe

Full analysis: https://app.any.run/tasks/472c75be-0436-407f-a26f-11732eb9af8b
Verdict: Malicious activity
Analysis date: January 15, 2024, 21:02:40
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed
MD5:

EBC58647462AD9C76395EF451064D115

SHA1:

14E470812F13B278B2694A4CEC5737A39784E9DD

SHA256:

414155BF11893EC64BA0F4FFB7DE92885090845A0761CF8F6743462AA5991D5E

SSDEEP:

196608:2ZnMGjZsDEsCaYsGEHy61bgUhufRswPU2/V8Gd83/PALDP0PiaQxhwf+9zYul28S:WnjZhsCOU6ZgfPPPuGdnv0fzfoDYtB

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • OInstall.exe (PID: 2408)
      • files.dat (PID: 784)
  • SUSPICIOUS

    • Starts CMD.EXE for commands execution

      • OInstall.exe (PID: 2408)
    • Process drops legitimate windows executable

      • OInstall.exe (PID: 2408)
      • files.dat (PID: 784)
      • expand.exe (PID: 2732)
    • Drops 7-zip archiver for unpacking

      • OInstall.exe (PID: 2408)
    • The executable file from the user directory is run by the CMD process

      • files.dat (PID: 784)
      • test.dat (PID: 2936)
      • test.dat (PID: 3128)
    • Starts application with an unusual extension

      • cmd.exe (PID: 492)
      • cmd.exe (PID: 3192)
      • cmd.exe (PID: 3096)
    • Executable content was dropped or overwritten

      • OInstall.exe (PID: 2408)
      • files.dat (PID: 784)
      • expand.exe (PID: 2732)
    • The process drops C-runtime libraries

      • files.dat (PID: 784)
      • expand.exe (PID: 2732)
    • Uses REG/REGEDIT.EXE to modify registry

      • OInstall.exe (PID: 2408)
      • cmd.exe (PID: 2380)
      • cmd.exe (PID: 2940)
      • cmd.exe (PID: 2944)
      • cmd.exe (PID: 3276)
      • cmd.exe (PID: 3204)
      • cmd.exe (PID: 2880)
      • cmd.exe (PID: 2836)
    • Starts POWERSHELL.EXE for commands execution

      • OInstall.exe (PID: 2408)
    • Probably download files using WebClient

      • OInstall.exe (PID: 2408)
    • Reads the Internet Settings

      • powershell.exe (PID: 2304)
      • powershell.exe (PID: 2596)
      • powershell.exe (PID: 2588)
    • The Powershell connects to the Internet

      • powershell.exe (PID: 2304)
      • powershell.exe (PID: 2588)
      • powershell.exe (PID: 2596)
    • Unusual connection from system programs

      • powershell.exe (PID: 2304)
      • powershell.exe (PID: 2588)
      • powershell.exe (PID: 2596)
    • Connects to unusual port

      • test.dat (PID: 3128)
      • test.dat (PID: 2936)
  • INFO

    • Checks supported languages

      • OInstall.exe (PID: 2408)
      • files.dat (PID: 784)
      • test.dat (PID: 3128)
      • test.dat (PID: 2936)
    • Reads the computer name

      • OInstall.exe (PID: 2408)
      • test.dat (PID: 3128)
      • test.dat (PID: 2936)
    • Reads Environment values

      • OInstall.exe (PID: 2408)
    • Create files in a temporary directory

      • OInstall.exe (PID: 2408)
      • files.dat (PID: 784)
      • expand.exe (PID: 2628)
    • Creates files in the program directory

      • expand.exe (PID: 2732)
      • expand.exe (PID: 1196)
      • OInstall.exe (PID: 2408)
    • Drops the executable file immediately after the start

      • expand.exe (PID: 2732)
    • Reads the machine GUID from the registry

      • test.dat (PID: 2936)
    • Reads Microsoft Office registry keys

      • reg.exe (PID: 1644)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | UPX compressed Win32 Executable (76)
.exe | Win32 Executable (generic) (12.6)
.exe | Generic Win/DOS Executable (5.6)
.exe | DOS Executable Generic (5.6)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2021:09:08 10:23:35+02:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 2.5
CodeSize: 11350016
InitializedDataSize: 90112
UninitializedDataSize: 11218944
EntryPoint: 0x1585eb0
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 7.3.3.0
ProductVersionNumber: 7.3.3.0
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Unknown (0)
ObjectFileType: Unknown
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
ProductName: Office 2013-2021 C2R Install
FileDescription: Office 2013-2021 C2R Install
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
101
Monitored processes
41
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
start oinstall.exe cmd.exe no specs files.dat reg.exe no specs powershell.exe expand.exe no specs powershell.exe no specs powershell.exe expand.exe powershell.exe expand.exe no specs officeclicktorun.exe no specs cmd.exe no specs reg.exe no specs cmd.exe no specs reg.exe no specs cmd.exe no specs reg.exe no specs cmd.exe no specs reg.exe no specs cmd.exe no specs reg.exe no specs cmd.exe no specs test.dat cmd.exe no specs test.dat cmd.exe no specs reg.exe no specs cmd.exe no specs reg.exe no specs cmd.exe no specs cscript.exe no specs cmd.exe no specs cscript.exe no specs cmd.exe no specs cscript.exe no specs cmd.exe no specs cscript.exe no specs reg.exe no specs reg.exe no specs oinstall.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
128"C:\Users\admin\AppData\Local\Temp\OInstall.exe" C:\Users\admin\AppData\Local\Temp\OInstall.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Office 2013-2021 C2R Install
Exit code:
3221226540
Modules
Images
c:\users\admin\appdata\local\temp\oinstall.exe
c:\windows\system32\ntdll.dll
492"C:\Windows\System32\cmd.exe" /D /c files.dat -y -pkmsautoC:\Windows\System32\cmd.exeOInstall.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
784files.dat -y -pkmsautoC:\Users\admin\AppData\Local\Temp\files\files.dat
cmd.exe
User:
admin
Company:
Igor Pavlov
Integrity Level:
HIGH
Description:
7z Console SFX
Exit code:
0
Version:
9.20
Modules
Images
c:\users\admin\appdata\local\temp\files\files.dat
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1196"expand" i321033.cab -F:* "C:\Program Files\Common Files\microsoft Shared\ClickToRun"C:\Windows\System32\expand.exeOInstall.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
LZ Expansion Utility
Exit code:
0
Version:
6.1.7601.24535 (win7sp1_ldr_escrow.191105-1059)
Modules
Images
c:\windows\system32\expand.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\cabinet.dll
1544"C:\Windows\System32\reg.exe" add HKLM\Software\Policies\Microsoft\Office\16.0\Common\OfficeUpdate /v UpdateBranch /d Current /fC:\Windows\System32\reg.exeOInstall.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Registry Console Tool
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\reg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1644REG QUERY HKLM\Software\Microsoft\Office /s /v Path /reg:64C:\Windows\System32\reg.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Registry Console Tool
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\reg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2304"powershell" -command "& { (New-Object Net.WebClient).DownloadFile('http://officecdn.microsoft.com/pr/492350f6-3a01-4f97-b9c0-c7c6ddf67d60/Office/Data/v32.cab', 'C:\Users\admin\AppData\Local\Temp\over651044\v32.cab') }"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
OInstall.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows PowerShell
Exit code:
0
Version:
10.0.14409.1005 (rs1_srvoob.161208-1155)
Modules
Images
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\atl.dll
c:\windows\system32\user32.dll
2380"C:\Windows\System32\cmd.exe" /D /c reg.exe add "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Configuration" /f /v "AudienceId" /t REG_SZ /d 492350f6-3a01-4f97-b9c0-c7c6ddf67d60C:\Windows\System32\cmd.exeOInstall.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2408"C:\Users\admin\AppData\Local\Temp\OInstall.exe" C:\Users\admin\AppData\Local\Temp\OInstall.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Description:
Office 2013-2021 C2R Install
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\oinstall.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\gdi32.dll
2548"C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe" deliverymechanism=492350f6-3a01-4f97-b9c0-c7c6ddf67d60 platform=x86 productreleaseid=none culture=en-us defaultplatform=False lcid=1033 b= storeid= forceupgrade=True piniconstotaskbar=False pidkeys=XQNVK-8JYDB-WJ9W3-YJ8YR-WFG99,YG9NW-3K39V-2T3HJ-93F3Q-G83KT,PD3PC-RHNGV-FXJ29-8JK7D-RJRJK forceappshutdown=True autoactivate=1 productstoadd=ProPlusVolume.16_en-us_x-none|ProjectProVolume.16_en-us_x-none|VisioProVolume.16_en-us_x-none scenario=unknown updatesenabled.16=True acceptalleulas.16=True cdnbaseurl.16=http://officecdn.microsoft.com/pr/492350f6-3a01-4f97-b9c0-c7c6ddf67d60 version.16=16.0.17126.20132 mediatype.16=CDN baseurl.16=http://officecdn.microsoft.com/pr/492350f6-3a01-4f97-b9c0-c7c6ddf67d60 sourcetype.16=CDN displaylevel=True uninstallpreviousversion=True ProPlusVolume.excludedapps.16=onedrive,teams ProjectProVolume.excludedapps.16=onedrive,teams VisioProVolume.excludedapps.16=onedrive,teamsC:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exeOInstall.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Office Click-to-Run (SxS)
Exit code:
3221225785
Version:
16.0.17126.20132
Modules
Images
c:\program files\common files\microsoft shared\clicktorun\officeclicktorun.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
Total events
4 304
Read events
4 303
Write events
1
Delete events
0

Modification events

(PID) Process:(2408) OInstall.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\MediaResources\DirectSound\Speaker Configuration
Operation:writeName:Speaker Configuration
Value:
4
Executable files
219
Suspicious files
16
Text files
29
Unknown types
0

Dropped files

PID
Process
Filename
Type
2408OInstall.exeC:\Users\admin\AppData\Local\Temp\files\setup.exeexecutable
MD5:072A2EFEA576956E465AFF2492A1C7F4
SHA256:EE3875ABD5D49A1891C8818820F61A1E5D0382DF37B5A5B72E175B2B6C70A9C2
2588powershell.exeC:\Users\admin\AppData\Local\Temp\over651044\i320.cab
MD5:
SHA256:
784files.datC:\Users\admin\AppData\Local\Temp\files\Uninstall.xmltext
MD5:364F86F97324EA82FE0D142CD01CF6DD
SHA256:09D5B42140BAB13165BA97FBD0E77792304C3C93555BE02C3DCE21A7A69C66DD
2712powershell.exeC:\Users\admin\AppData\Local\Temp\c1umyizz.ort.ps1binary
MD5:C4CA4238A0B923820DCC509A6F75849B
SHA256:
2304powershell.exeC:\Users\admin\AppData\Local\Temp\over651044\v32.cabcompressed
MD5:A620A25286339C928EBD242985905A8C
SHA256:8337A932BF3A4483B43BE6BBAAA30554D3EE9E1A041BE70451BD59F08182FBEE
2304powershell.exeC:\Users\admin\AppData\Local\Temp\hsqsdchh.mqq.ps1binary
MD5:C4CA4238A0B923820DCC509A6F75849B
SHA256:
2304powershell.exeC:\Users\admin\AppData\Local\Temp\5sma5rkv.hpv.psm1binary
MD5:C4CA4238A0B923820DCC509A6F75849B
SHA256:
784files.datC:\Users\admin\AppData\Local\Temp\files\x64\msvcr100.dllexecutable
MD5:DF3CA8D16BDED6A54977B30E66864D33
SHA256:1D1A1AE540BA132F998D60D3622F0297B6E86AE399332C3B47462D7C0F560A36
2304powershell.exeC:\Users\admin\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractivebinary
MD5:446DD1CF97EABA21CF14D03AEBC79F27
SHA256:A7DE5177C68A64BD48B36D49E2853799F4EBCFA8E4761F7CC472F333DC5F65CF
2628expand.exeC:\Windows\Logs\DPX\setupact.logtext
MD5:439F4BC4B4D9759B819691C8980A9D66
SHA256:C27828DE28691507659FC39F0E6FB6EE29AB4A76541D32E131D2AC9392F40EF0
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
3
TCP/UDP connections
9
DNS requests
5
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2304
powershell.exe
GET
200
23.32.238.18:80
http://officecdn.microsoft.com/pr/492350f6-3a01-4f97-b9c0-c7c6ddf67d60/Office/Data/v32.cab
unknown
compressed
11.2 Kb
unknown
2588
powershell.exe
GET
200
2.19.198.201:80
http://officecdn.microsoft.com/pr/492350f6-3a01-4f97-b9c0-c7c6ddf67d60/Office/Data/16.0.17126.20132/i320.cab
unknown
compressed
25.3 Mb
unknown
2596
powershell.exe
GET
200
152.199.21.175:80
http://officecdn.microsoft.com/pr/492350f6-3a01-4f97-b9c0-c7c6ddf67d60/Office/Data/16.0.17126.20132/i321033.cab
unknown
compressed
9.74 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
2304
powershell.exe
23.32.238.18:80
officecdn.microsoft.com
Akamai International B.V.
DE
unknown
2588
powershell.exe
2.19.198.201:80
officecdn.microsoft.com
Akamai International B.V.
DE
unknown
2596
powershell.exe
152.199.21.175:80
officecdn.microsoft.com
EDGECAST
DE
whitelisted
3128
test.dat
20.222.16.243:1688
kms.loli.beer
MICROSOFT-CORP-MSN-AS-BLOCK
JP
unknown
2936
test.dat
107.175.77.7:1688
kms.03k.org
AS-COLOCROSSING
US
unknown

DNS requests

Domain
IP
Reputation
officecdn.microsoft.com
  • 23.32.238.18
  • 2.19.198.201
  • 23.32.238.80
  • 152.199.21.175
whitelisted
kms.loli.beer
  • 20.222.16.243
unknown
kms.03k.org
  • 107.175.77.7
unknown

Threats

No threats detected
No debug info