analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

OculusSetup.exe

Full analysis: https://app.any.run/tasks/f0ada7b7-0ae9-47ec-bbcd-d2f6512c64f1
Verdict: Malicious activity
Analysis date: October 05, 2022, 01:02:29
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

E7CFF4687088A6622AF7567C8E4F7FC3

SHA1:

E693F7F449BD008D76E1AFAC261CFF929156EFC6

SHA256:

418E52C649BB3C98B150C91A38153BAA70C775E82212DCB11B1B479D27056266

SSDEEP:

49152:CfQqO8QHKL7zeXfM6CvifgaAwS0ct1CPwDv3uF/XjxBZdKdaRH7wW7Z0:Na7zevblfgaAQo1CPwDv3uF/XmgRt0

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops executable file immediately after starts

      • OculusSetup.exe (PID: 2364)
      • OculusSetup.exe (PID: 2696)
    • Application was dropped or rewritten from another process

      • OculusSetup.exe (PID: 2696)
  • SUSPICIOUS

    • Reads the computer name

      • OculusSetup.exe (PID: 2364)
      • OculusSetup.exe (PID: 2696)
    • Checks supported languages

      • OculusSetup.exe (PID: 2364)
      • OculusSetup.exe (PID: 2696)
    • Drops a file with a compile date too recent

      • OculusSetup.exe (PID: 2364)
      • OculusSetup.exe (PID: 2696)
    • Executable content was dropped or overwritten

      • OculusSetup.exe (PID: 2364)
      • OculusSetup.exe (PID: 2696)
    • Reads Environment values

      • OculusSetup.exe (PID: 2696)
    • Reads the Windows organization settings

      • OculusSetup.exe (PID: 2696)
    • Reads CPU info

      • OculusSetup.exe (PID: 2696)
    • Reads Windows owner or organization settings

      • OculusSetup.exe (PID: 2696)
  • INFO

    • Checks supported languages

      • WISPTIS.EXE (PID: 4056)
    • Reads settings of System Certificates

      • OculusSetup.exe (PID: 2696)
    • Reads the computer name

      • WISPTIS.EXE (PID: 4056)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (76.4)
.exe | Win32 Executable (generic) (12.4)
.exe | Generic Win/DOS Executable (5.5)
.exe | DOS Executable Generic (5.5)

Summary

Architecture: IMAGE_FILE_MACHINE_I386
Subsystem: IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date: 2022-Jul-17 21:39:32
Detected languages:
  • English - United States
Debug artifacts:
  • C:\cygwin\data\sandcastle\boxes\trunk-hg-full-fbsource\arvr\projects\oculus_pc_infra\Support\Dawn\bin\Release\OculusSetup.pdb
CompanyName: Facebook Technologies, LLC
FileDescription: Oculus Setup
FileVersion: 1.74.0.0
InternalName: OculusSetup.exe
LegalCopyright: Copyright © Facebook Technologies, LLC
OriginalFilename: OculusSetup.exe
ProductName: Oculus Setup
ProductVersion: 1.74.0.0

DOS Header

e_magic: MZ
e_cblp: 144
e_cp: 3
e_crlc: -
e_cparhdr: 4
e_minalloc: -
e_maxalloc: 65535
e_ss: -
e_sp: 184
e_csum: -
e_ip: -
e_cs: -
e_ovno: -
e_oemid: -
e_oeminfo: -
e_lfanew: 264

PE Headers

Signature: PE
Machine: IMAGE_FILE_MACHINE_I386
NumberofSections: 5
TimeDateStamp: 2022-Jul-17 21:39:32
PointerToSymbolTable: -
NumberOfSymbols: -
SizeOfOptionalHeader: 224
Characteristics:
  • IMAGE_FILE_32BIT_MACHINE
  • IMAGE_FILE_EXECUTABLE_IMAGE

Sections

Name
Virtual Address
Virtual Size
Raw Size
Charateristics
Entropy
.text
4096
57138
57344
IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
6.61826
.rdata
61440
4618180
4618240
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
6.82715
.data
4681728
4996
2560
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
2.376
.rsrc
4689920
381120
381440
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
4.9843
.reloc
5074944
3996
4096
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
6.45908

Resources

Title
Entropy
Size
Codepage
Language
Type
1
5.03351
67624
UNKNOWN
English - United States
RT_ICON
2
5.09538
16936
UNKNOWN
English - United States
RT_ICON
3
5.09522
9640
UNKNOWN
English - United States
RT_ICON
4
5.07435
6760
UNKNOWN
English - United States
RT_ICON
5
5.17596
4264
UNKNOWN
English - United States
RT_ICON
6
5.04281
2440
UNKNOWN
English - United States
RT_ICON
7
5.12935
1128
UNKNOWN
English - United States
RT_ICON
8
4.90335
270376
UNKNOWN
English - United States
RT_ICON
101
2.91319
118
UNKNOWN
English - United States
RT_GROUP_ICON
1 (#2)
3.3955
796
UNKNOWN
English - United States
RT_VERSION

Imports

ADVAPI32.dll
KERNEL32.dll
RPCRT4.dll
SHELL32.dll
USER32.dll
No data.
screenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
42
Monitored processes
5
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
drop and start start oculussetup.exe no specs oculussetup.exe oculussetup.exe wisptis.exe no specs wisptis.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2592"C:\Users\admin\AppData\Local\Temp\OculusSetup.exe" C:\Users\admin\AppData\Local\Temp\OculusSetup.exeExplorer.EXE
User:
admin
Company:
Facebook Technologies, LLC
Integrity Level:
MEDIUM
Description:
Oculus Setup
Exit code:
3221226540
Version:
1.74.0.0
2364"C:\Users\admin\AppData\Local\Temp\OculusSetup.exe" C:\Users\admin\AppData\Local\Temp\OculusSetup.exe
Explorer.EXE
User:
admin
Company:
Facebook Technologies, LLC
Integrity Level:
HIGH
Description:
Oculus Setup
Version:
1.74.0.0
2696C:\Users\admin\AppData\Local\Temp\\OculusSetup-16c9517c-5182-4268-8fc9-b6238cbb530e\OculusSetup.exe --setupPath "C:\Users\admin\AppData\Local\Temp\OculusSetup.exe"C:\Users\admin\AppData\Local\Temp\OculusSetup-16c9517c-5182-4268-8fc9-b6238cbb530e\OculusSetup.exe
OculusSetup.exe
User:
admin
Company:
Facebook Technologies, LLC
Integrity Level:
HIGH
Description:
Oculus Setup
Version:
1.74.0.0
3696"C:\Windows\SYSTEM32\WISPTIS.EXE" /ManualLaunch;C:\Windows\SYSTEM32\WISPTIS.EXEOculusSetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Pen and Touch Input Component
Exit code:
3221226540
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
4056"C:\Windows\SYSTEM32\WISPTIS.EXE" /ManualLaunch;C:\Windows\SYSTEM32\WISPTIS.EXEOculusSetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Pen and Touch Input Component
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Total events
3 776
Read events
3 702
Write events
0
Delete events
0

Modification events

No data
Executable files
4
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
2696OculusSetup.exeC:\Users\admin\AppData\Local\Temp\OculusSetup-561e8a74-dc26-461c-8176-096374a4521a\DaybreakNative.dllexecutable
MD5:7384B4D44FD6AB9BC7B3F7140FF2FE8F
SHA256:840D9F8602F2E370EF9EF99249E79755BBA6BC9BC10C74D34DF5E34899F10239
2364OculusSetup.exeC:\Users\admin\AppData\Local\Temp\OculusSetup-16c9517c-5182-4268-8fc9-b6238cbb530e\OculusSetup.exeexecutable
MD5:081C2FE6EE93A8809085576E169EA9F0
SHA256:335B798C1782F548EA9EDAEFEE1F8B4CC002AAB7344F8F45404B88529B6FD750
2696OculusSetup.exeC:\Users\admin\AppData\Local\Temp\OculusSetup-561e8a74-dc26-461c-8176-096374a4521a\OafIpc.dllexecutable
MD5:4559DAE30A87671A4B1C0D7027ECFC7A
SHA256:7BD5CA653D856622B4DCAF85C5782EEF9F49764CFC960469BB9533A0E1C814E0
2696OculusSetup.exeC:\Users\admin\AppData\Local\Temp\OculusSetup-561e8a74-dc26-461c-8176-096374a4521a\libcrypto.dllexecutable
MD5:5E346D3611A909C930C81A1B852C7D17
SHA256:AD2698AA52E4ECFDE9FAAE4793E871E9DB4C4D5C927B0AC44FF2067A2EA491E1
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
3
DNS requests
2
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2696
OculusSetup.exe
185.60.216.49:443
graph.oculus.com
FACEBOOK
IE
unknown
2696
OculusSetup.exe
185.60.216.15:443
graph.facebook.com
FACEBOOK
IE
whitelisted

DNS requests

Domain
IP
Reputation
graph.oculus.com
  • 185.60.216.49
unknown
graph.facebook.com
  • 185.60.216.15
whitelisted

Threats

No threats detected
No debug info