File name:

OculusSetup.exe

Full analysis: https://app.any.run/tasks/f0ada7b7-0ae9-47ec-bbcd-d2f6512c64f1
Verdict: Malicious activity
Analysis date: October 05, 2022, 01:02:29
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

E7CFF4687088A6622AF7567C8E4F7FC3

SHA1:

E693F7F449BD008D76E1AFAC261CFF929156EFC6

SHA256:

418E52C649BB3C98B150C91A38153BAA70C775E82212DCB11B1B479D27056266

SSDEEP:

49152:CfQqO8QHKL7zeXfM6CvifgaAwS0ct1CPwDv3uF/XjxBZdKdaRH7wW7Z0:Na7zevblfgaAQo1CPwDv3uF/XmgRt0

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops executable file immediately after starts

      • OculusSetup.exe (PID: 2364)
      • OculusSetup.exe (PID: 2696)
    • Application was dropped or rewritten from another process

      • OculusSetup.exe (PID: 2696)
  • SUSPICIOUS

    • Checks supported languages

      • OculusSetup.exe (PID: 2364)
      • OculusSetup.exe (PID: 2696)
    • Reads the computer name

      • OculusSetup.exe (PID: 2364)
      • OculusSetup.exe (PID: 2696)
    • Executable content was dropped or overwritten

      • OculusSetup.exe (PID: 2364)
      • OculusSetup.exe (PID: 2696)
    • Drops a file with a compile date too recent

      • OculusSetup.exe (PID: 2364)
      • OculusSetup.exe (PID: 2696)
    • Reads Environment values

      • OculusSetup.exe (PID: 2696)
    • Reads Windows owner or organization settings

      • OculusSetup.exe (PID: 2696)
    • Reads CPU info

      • OculusSetup.exe (PID: 2696)
    • Reads the Windows organization settings

      • OculusSetup.exe (PID: 2696)
  • INFO

    • Reads settings of System Certificates

      • OculusSetup.exe (PID: 2696)
    • Checks supported languages

      • WISPTIS.EXE (PID: 4056)
    • Reads the computer name

      • WISPTIS.EXE (PID: 4056)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (76.4)
.exe | Win32 Executable (generic) (12.4)
.exe | Generic Win/DOS Executable (5.5)
.exe | DOS Executable Generic (5.5)

Summary

Architecture: IMAGE_FILE_MACHINE_I386
Subsystem: IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date: 2022-Jul-17 21:39:32
Detected languages:
  • English - United States
Debug artifacts:
  • C:\cygwin\data\sandcastle\boxes\trunk-hg-full-fbsource\arvr\projects\oculus_pc_infra\Support\Dawn\bin\Release\OculusSetup.pdb
CompanyName: Facebook Technologies, LLC
FileDescription: Oculus Setup
FileVersion: 1.74.0.0
InternalName: OculusSetup.exe
LegalCopyright: Copyright © Facebook Technologies, LLC
OriginalFilename: OculusSetup.exe
ProductName: Oculus Setup
ProductVersion: 1.74.0.0

DOS Header

e_magic: MZ
e_cblp: 144
e_cp: 3
e_crlc: -
e_cparhdr: 4
e_minalloc: -
e_maxalloc: 65535
e_ss: -
e_sp: 184
e_csum: -
e_ip: -
e_cs: -
e_ovno: -
e_oemid: -
e_oeminfo: -
e_lfanew: 264

PE Headers

Signature: PE
Machine: IMAGE_FILE_MACHINE_I386
NumberofSections: 5
TimeDateStamp: 2022-Jul-17 21:39:32
PointerToSymbolTable: -
NumberOfSymbols: -
SizeOfOptionalHeader: 224
Characteristics:
  • IMAGE_FILE_32BIT_MACHINE
  • IMAGE_FILE_EXECUTABLE_IMAGE

Sections

Name
Virtual Address
Virtual Size
Raw Size
Charateristics
Entropy
.text
4096
57138
57344
IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
6.61826
.rdata
61440
4618180
4618240
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
6.82715
.data
4681728
4996
2560
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
2.376
.rsrc
4689920
381120
381440
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
4.9843
.reloc
5074944
3996
4096
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
6.45908

Resources

Title
Entropy
Size
Codepage
Language
Type
1
5.03351
67624
UNKNOWN
English - United States
RT_ICON
2
5.09538
16936
UNKNOWN
English - United States
RT_ICON
3
5.09522
9640
UNKNOWN
English - United States
RT_ICON
4
5.07435
6760
UNKNOWN
English - United States
RT_ICON
5
5.17596
4264
UNKNOWN
English - United States
RT_ICON
6
5.04281
2440
UNKNOWN
English - United States
RT_ICON
7
5.12935
1128
UNKNOWN
English - United States
RT_ICON
8
4.90335
270376
UNKNOWN
English - United States
RT_ICON
101
2.91319
118
UNKNOWN
English - United States
RT_GROUP_ICON
1 (#2)
3.3955
796
UNKNOWN
English - United States
RT_VERSION

Imports

ADVAPI32.dll
KERNEL32.dll
RPCRT4.dll
SHELL32.dll
USER32.dll
No data.
screenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
42
Monitored processes
5
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
drop and start start oculussetup.exe oculussetup.exe wisptis.exe no specs wisptis.exe no specs oculussetup.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2364"C:\Users\admin\AppData\Local\Temp\OculusSetup.exe" C:\Users\admin\AppData\Local\Temp\OculusSetup.exe
Explorer.EXE
User:
admin
Company:
Facebook Technologies, LLC
Integrity Level:
HIGH
Description:
Oculus Setup
Exit code:
0
Version:
1.74.0.0
Modules
Images
c:\users\admin\appdata\local\temp\oculussetup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\lpk.dll
c:\windows\system32\user32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msvcrt.dll
2592"C:\Users\admin\AppData\Local\Temp\OculusSetup.exe" C:\Users\admin\AppData\Local\Temp\OculusSetup.exeExplorer.EXE
User:
admin
Company:
Facebook Technologies, LLC
Integrity Level:
MEDIUM
Description:
Oculus Setup
Exit code:
3221226540
Version:
1.74.0.0
Modules
Images
c:\users\admin\appdata\local\temp\oculussetup.exe
c:\windows\system32\ntdll.dll
2696C:\Users\admin\AppData\Local\Temp\\OculusSetup-16c9517c-5182-4268-8fc9-b6238cbb530e\OculusSetup.exe --setupPath "C:\Users\admin\AppData\Local\Temp\OculusSetup.exe"C:\Users\admin\AppData\Local\Temp\OculusSetup-16c9517c-5182-4268-8fc9-b6238cbb530e\OculusSetup.exe
OculusSetup.exe
User:
admin
Company:
Facebook Technologies, LLC
Integrity Level:
HIGH
Description:
Oculus Setup
Exit code:
0
Version:
1.74.0.0
Modules
Images
c:\users\admin\appdata\local\temp\oculussetup-16c9517c-5182-4268-8fc9-b6238cbb530e\oculussetup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3696"C:\Windows\SYSTEM32\WISPTIS.EXE" /ManualLaunch;C:\Windows\SYSTEM32\WISPTIS.EXEOculusSetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Pen and Touch Input Component
Exit code:
3221226540
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\wisptis.exe
c:\windows\system32\ntdll.dll
4056"C:\Windows\SYSTEM32\WISPTIS.EXE" /ManualLaunch;C:\Windows\SYSTEM32\WISPTIS.EXEOculusSetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Pen and Touch Input Component
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\wisptis.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
Total events
3 776
Read events
3 702
Write events
74
Delete events
0

Modification events

(PID) Process:(2696) OculusSetup.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ASP.NET_4.0.30319\Names
Operation:writeName:l201w9Ztsk5jVlSiacz3pXWWUTI6FNp8mro1pzrCKiElvxKeRbqpXvPADqcWRBYTStlbj5Vqn7bNbiAd2Bqv4wTQSdJQB20NYGuQq3tyK75df1gvCuK1T5
Value:
2696
(PID) Process:(2696) OculusSetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\OculusSetup_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(2696) OculusSetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\OculusSetup_RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(2696) OculusSetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\OculusSetup_RASAPI32
Operation:writeName:FileTracingMask
Value:
(PID) Process:(2696) OculusSetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\OculusSetup_RASAPI32
Operation:writeName:ConsoleTracingMask
Value:
(PID) Process:(2696) OculusSetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\OculusSetup_RASAPI32
Operation:writeName:MaxFileSize
Value:
1048576
(PID) Process:(2696) OculusSetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\OculusSetup_RASAPI32
Operation:writeName:FileDirectory
Value:
%windir%\tracing
(PID) Process:(2696) OculusSetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\OculusSetup_RASMANCS
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(2696) OculusSetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\OculusSetup_RASMANCS
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(2696) OculusSetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\OculusSetup_RASMANCS
Operation:writeName:FileTracingMask
Value:
Executable files
4
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
2364OculusSetup.exeC:\Users\admin\AppData\Local\Temp\OculusSetup-16c9517c-5182-4268-8fc9-b6238cbb530e\OculusSetup.exeexecutable
MD5:
SHA256:
2696OculusSetup.exeC:\Users\admin\AppData\Local\Temp\OculusSetup-561e8a74-dc26-461c-8176-096374a4521a\DaybreakNative.dllexecutable
MD5:
SHA256:
2696OculusSetup.exeC:\Users\admin\AppData\Local\Temp\OculusSetup-561e8a74-dc26-461c-8176-096374a4521a\OafIpc.dllexecutable
MD5:4559DAE30A87671A4B1C0D7027ECFC7A
SHA256:7BD5CA653D856622B4DCAF85C5782EEF9F49764CFC960469BB9533A0E1C814E0
2696OculusSetup.exeC:\Users\admin\AppData\Local\Temp\OculusSetup-561e8a74-dc26-461c-8176-096374a4521a\libcrypto.dllexecutable
MD5:5E346D3611A909C930C81A1B852C7D17
SHA256:AD2698AA52E4ECFDE9FAAE4793E871E9DB4C4D5C927B0AC44FF2067A2EA491E1
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
3
DNS requests
2
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2696
OculusSetup.exe
185.60.216.15:443
graph.facebook.com
FACEBOOK
IE
whitelisted
2696
OculusSetup.exe
185.60.216.49:443
graph.oculus.com
FACEBOOK
IE
unknown

DNS requests

Domain
IP
Reputation
graph.oculus.com
  • 185.60.216.49
unknown
graph.facebook.com
  • 185.60.216.15
whitelisted

Threats

No threats detected
No debug info