File name:

StellarConverterforOST-Corporate.exe

Full analysis: https://app.any.run/tasks/13c56d3e-a892-466b-9b82-f80db34b36a9
Verdict: Malicious activity
Analysis date: February 05, 2024, 20:21:53
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

0B7602D29B0AEC5E7A226C1BF92F6FAD

SHA1:

D3679775711CFCB2E88F2AA6AB9FEE2F10572D17

SHA256:

428F377276573ED845C939D508BE6B446B2072F99444D70B1921F62D53BC503B

SSDEEP:

98304:b+cD4dn6kT3JF28Ujptchz2kCSmD9OYtHI7U7Jy3PgsERQgMypV6/l7T1MiEdePJ:xcKiJnk/i4kpFt9vGmImHFTPSjmzpT

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • StellarConverterforOST-Corporate.exe (PID: 1652)
      • StellarConverterforOST-Corporate.tmp (PID: 3248)
      • StellarConverterforOST-Corporate.exe (PID: 2380)
  • SUSPICIOUS

    • Reads the Windows owner or organization settings

      • StellarConverterforOST-Corporate.tmp (PID: 3248)
    • Executable content was dropped or overwritten

      • StellarConverterforOST-Corporate.exe (PID: 2380)
      • StellarConverterforOST-Corporate.tmp (PID: 3248)
      • StellarConverterforOST-Corporate.exe (PID: 1652)
    • Process drops legitimate windows executable

      • StellarConverterforOST-Corporate.tmp (PID: 3248)
    • Reads the Internet Settings

      • StellarConverterforOST-Corporate.tmp (PID: 1632)
    • Process drops SQLite DLL files

      • StellarConverterforOST-Corporate.tmp (PID: 3248)
    • The process drops C-runtime libraries

      • StellarConverterforOST-Corporate.tmp (PID: 3248)
  • INFO

    • Checks supported languages

      • StellarConverterforOST-Corporate.tmp (PID: 3248)
      • StellarConverterforOST-Corporate.exe (PID: 1652)
      • StellarConverterforOST-Corporate.exe (PID: 2380)
      • StellarConverterforOST-Corporate.tmp (PID: 1632)
    • Reads the computer name

      • StellarConverterforOST-Corporate.tmp (PID: 3248)
      • StellarConverterforOST-Corporate.tmp (PID: 1632)
    • Creates files in the program directory

      • StellarConverterforOST-Corporate.tmp (PID: 3248)
    • Create files in a temporary directory

      • StellarConverterforOST-Corporate.exe (PID: 1652)
      • StellarConverterforOST-Corporate.exe (PID: 2380)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (67.7)
.exe | Win32 EXE PECompact compressed (generic) (25.6)
.exe | Win32 Executable (generic) (2.7)
.exe | Win16/32 Executable Delphi generic (1.2)
.exe | Generic Win/DOS Executable (1.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:02:15 15:54:16+01:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 741888
InitializedDataSize: 195584
UninitializedDataSize: -
EntryPoint: 0xb5eec
OSVersion: 6.1
ImageVersion: 6
SubsystemVersion: 6.1
Subsystem: Windows GUI
FileVersionNumber: 12.1.0.3
ProductVersionNumber: 12.1.0.3
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: Stellar Information Technology Pvt Ltd.
FileDescription: Stellar Converter for OST
FileVersion: 12.1.0.3
LegalCopyright: Stellar Information Technology Pvt Ltd.
OriginalFileName:
ProductName: Stellar Converter for OST
ProductVersion: 12.1.0.3
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
45
Monitored processes
4
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
start stellarconverterforost-corporate.exe stellarconverterforost-corporate.tmp no specs stellarconverterforost-corporate.exe stellarconverterforost-corporate.tmp

Process information

PID
CMD
Path
Indicators
Parent process
1632"C:\Users\admin\AppData\Local\Temp\is-DD1C8.tmp\StellarConverterforOST-Corporate.tmp" /SL5="$F0184,15753498,938496,C:\Users\admin\AppData\Local\Temp\StellarConverterforOST-Corporate.exe" C:\Users\admin\AppData\Local\Temp\is-DD1C8.tmp\StellarConverterforOST-Corporate.tmpStellarConverterforOST-Corporate.exe
User:
admin
Company:
Stellar Information Technology Pvt Ltd.
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-dd1c8.tmp\stellarconverterforost-corporate.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1652"C:\Users\admin\AppData\Local\Temp\StellarConverterforOST-Corporate.exe" C:\Users\admin\AppData\Local\Temp\StellarConverterforOST-Corporate.exe
explorer.exe
User:
admin
Company:
Stellar Information Technology Pvt Ltd.
Integrity Level:
MEDIUM
Description:
Stellar Converter for OST
Exit code:
0
Version:
12.1.0.3
Modules
Images
c:\users\admin\appdata\local\temp\stellarconverterforost-corporate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\comctl32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
2380"C:\Users\admin\AppData\Local\Temp\StellarConverterforOST-Corporate.exe" /SPAWNWND=$1201B4 /NOTIFYWND=$F0184 C:\Users\admin\AppData\Local\Temp\StellarConverterforOST-Corporate.exe
StellarConverterforOST-Corporate.tmp
User:
admin
Company:
Stellar Information Technology Pvt Ltd.
Integrity Level:
HIGH
Description:
Stellar Converter for OST
Exit code:
0
Version:
12.1.0.3
Modules
Images
c:\users\admin\appdata\local\temp\stellarconverterforost-corporate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\comctl32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
3248"C:\Users\admin\AppData\Local\Temp\is-K6TSI.tmp\StellarConverterforOST-Corporate.tmp" /SL5="$E0182,15753498,938496,C:\Users\admin\AppData\Local\Temp\StellarConverterforOST-Corporate.exe" /SPAWNWND=$1201B4 /NOTIFYWND=$F0184 C:\Users\admin\AppData\Local\Temp\is-K6TSI.tmp\StellarConverterforOST-Corporate.tmp
StellarConverterforOST-Corporate.exe
User:
admin
Company:
Stellar Information Technology Pvt Ltd.
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-k6tsi.tmp\stellarconverterforost-corporate.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
Total events
1 305
Read events
1 186
Write events
119
Delete events
0

Modification events

(PID) Process:(3248) StellarConverterforOST-Corporate.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Stellar Data Recovery\Stellar Converter for OST
Operation:writeName:Path
Value:
C:\Program Files\Stellar Converter for OST
(PID) Process:(3248) StellarConverterforOST-Corporate.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Stellar Data Recovery\Stellar Converter for OST
Operation:writeName:Version
Value:
12.1.0.3
(PID) Process:(3248) StellarConverterforOST-Corporate.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Stellar Data Recovery\Stellar Converter for OST
Operation:writeName:ExeName
Value:
ost2pst
(PID) Process:(3248) StellarConverterforOST-Corporate.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Stellar Data Recovery\Stellar Converter for OST
Operation:writeName:ExePath64Bit
Value:
C:\Program Files\Stellar Converter for OST\
(PID) Process:(3248) StellarConverterforOST-Corporate.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Stellar Data Recovery\Stellar Converter for OST
Operation:writeName:ExeNameIntOstPst
Value:
ost2pst.exe
(PID) Process:(3248) StellarConverterforOST-Corporate.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Stellar Data Recovery\Stellar Converter for OST
Operation:writeName:Edition
Value:
Corporate
(PID) Process:(3248) StellarConverterforOST-Corporate.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Stellar Data Recovery\Stellar Converter for OST
Operation:writeName:UninstallURL
Value:
(PID) Process:(3248) StellarConverterforOST-Corporate.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Stellar Data Recovery\Stellar Converter for OST
Operation:writeName:ProductName
Value:
StellarConverterforOSTCorporate
(PID) Process:(3248) StellarConverterforOST-Corporate.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers
Operation:writeName:C:\Program Files\Stellar Converter for OST\ost2pst.exe
Value:
RUNASADMIN
(PID) Process:(3248) StellarConverterforOST-Corporate.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Stellar Data Recovery\Stellar Converter for OST
Operation:writeName:Update
Value:
http://www.stellarinfo.com/upgrade/software-upgrade.php
Executable files
68
Suspicious files
5
Text files
20
Unknown types
0

Dropped files

PID
Process
Filename
Type
1652StellarConverterforOST-Corporate.exeC:\Users\admin\AppData\Local\Temp\is-DD1C8.tmp\StellarConverterforOST-Corporate.tmpexecutable
MD5:FDA7716EC6108F4D859DEC1BA0B9BD95
SHA256:FFBA6B4CFB853A162DD99032C3D917A8F3EC384757A99029857B3265178F3501
2380StellarConverterforOST-Corporate.exeC:\Users\admin\AppData\Local\Temp\is-K6TSI.tmp\StellarConverterforOST-Corporate.tmpexecutable
MD5:FDA7716EC6108F4D859DEC1BA0B9BD95
SHA256:FFBA6B4CFB853A162DD99032C3D917A8F3EC384757A99029857B3265178F3501
3248StellarConverterforOST-Corporate.tmpC:\Program Files\Stellar Converter for OST\api-ms-win-core-localization-l1-2-0.dllexecutable
MD5:39475799BFAEE65894F94A0F15D0D1FB
SHA256:2D9F380091506EB22F0E92C68F6D8641C06FA92F733494FEE9836FD748A294D5
3248StellarConverterforOST-Corporate.tmpC:\Program Files\Stellar Converter for OST\is-0V273.tmpexecutable
MD5:F12C1674574B16DDC17F4CCF68955E59
SHA256:A88202B5B8E62EDEAFB536AF25580B2B1A437860D86CD5D8A6FBA3C89B46ACD6
3248StellarConverterforOST-Corporate.tmpC:\Program Files\Stellar Converter for OST\is-ABBE7.tmptext
MD5:5F57B5DAB81E3B496D8C694D26F2CA82
SHA256:ACE62E090016123A28C07BFB1FF74DC1914D498DF0C5F1AD957AB13558A098A7
3248StellarConverterforOST-Corporate.tmpC:\Program Files\Stellar Converter for OST\is-EINO2.tmpexecutable
MD5:915F1C029D8B51CE579FE6F5330A77CA
SHA256:8065D56D1442DE48A43B98FEC8A9788EE144D997604180629CE303EE9BA53D8E
3248StellarConverterforOST-Corporate.tmpC:\Program Files\Stellar Converter for OST\api-ms-win-core-processthreads-l1-1-1.dllexecutable
MD5:915F1C029D8B51CE579FE6F5330A77CA
SHA256:8065D56D1442DE48A43B98FEC8A9788EE144D997604180629CE303EE9BA53D8E
3248StellarConverterforOST-Corporate.tmpC:\Program Files\Stellar Converter for OST\is-N8GB3.tmpexecutable
MD5:7B2CAAFBE6B2C3D6CBF232610DCCC034
SHA256:BA0AFA1FADD4429693538AA2E85230EDCCC2E481F80B89666907D108D31BED8C
3248StellarConverterforOST-Corporate.tmpC:\Program Files\Stellar Converter for OST\api-ms-win-core-synch-l1-2-0.dllexecutable
MD5:F98687F24C22ED699DBC3721CDA79044
SHA256:EA02309A2DE376DC9321E2A1154ABFE39170762AC24E5925D5FB8F3E726D723F
3248StellarConverterforOST-Corporate.tmpC:\Program Files\Stellar Converter for OST\api-ms-win-core-timezone-l1-1-0.dllexecutable
MD5:7B2CAAFBE6B2C3D6CBF232610DCCC034
SHA256:BA0AFA1FADD4429693538AA2E85230EDCCC2E481F80B89666907D108D31BED8C
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown

DNS requests

No data

Threats

No threats detected
No debug info