File name:

Grass_4.28.0_x64-setup.exe

Full analysis: https://app.any.run/tasks/321433cf-4a5f-45cd-af83-301af77ea475
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: October 31, 2024, 22:29:36
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
loader
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive, 5 sections
MD5:

C297BA1811486746089AC428B9B59AD2

SHA1:

8EC1B7E044E5DAD824B609B633D24A70AA4DFF97

SHA256:

43112520B679C53B3B25EB2A4DCA3A0508DF524959AA40BC42409FF582C11116

SSDEEP:

98304:RJ8/XkJW5LPhevQ8q6exiwR+oSx7KjiPwp8mGusnuFmRSBOrTutkdVUKfnKO0EEc:Rz4yDTI7gKJwW/acEuIQ9tQSa

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • MicrosoftEdgeWebview2Setup.exe (PID: 6392)
      • Grass_4.28.0_x64-setup.exe (PID: 1804)
    • Process drops legitimate windows executable

      • MicrosoftEdgeWebview2Setup.exe (PID: 6392)
      • Grass_4.28.0_x64-setup.exe (PID: 1804)
      • MicrosoftEdgeUpdate.exe (PID: 7104)
    • The process creates files with name similar to system file names

      • Grass_4.28.0_x64-setup.exe (PID: 1804)
    • Potential Corporate Privacy Violation

      • Grass_4.28.0_x64-setup.exe (PID: 1804)
    • Starts a Microsoft application from unusual location

      • MicrosoftEdgeWebview2Setup.exe (PID: 6392)
      • MicrosoftEdgeUpdate.exe (PID: 7104)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • Grass_4.28.0_x64-setup.exe (PID: 1804)
  • INFO

    • Checks supported languages

      • Grass_4.28.0_x64-setup.exe (PID: 1804)
    • Create files in a temporary directory

      • Grass_4.28.0_x64-setup.exe (PID: 1804)
    • Reads the computer name

      • Grass_4.28.0_x64-setup.exe (PID: 1804)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2021:09:25 21:56:47+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 26624
InitializedDataSize: 141824
UninitializedDataSize: 2048
EntryPoint: 0x3640
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 4.28.0.0
ProductVersionNumber: 4.28.0.0
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
FileDescription: -
FileVersion: 4.28.0
LegalCopyright: © Grass Foundation, 2024. All rights reserved.
ProductName: Grass
ProductVersion: 4.28.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
135
Monitored processes
5
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start grass_4.28.0_x64-setup.exe microsoftedgewebview2setup.exe microsoftedgeupdate.exe wermgr.exe grass_4.28.0_x64-setup.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
712"C:\WINDOWS\system32\wermgr.exe" "-outproc" "0" "7104" "2044" "1796" "2052" "0" "0" "0" "0" "0" "0" "0" "0" C:\Windows\SysWOW64\wermgr.exe
MicrosoftEdgeUpdate.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\wermgr.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
1804"C:\Users\admin\AppData\Local\Temp\Grass_4.28.0_x64-setup.exe" C:\Users\admin\AppData\Local\Temp\Grass_4.28.0_x64-setup.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Version:
4.28.0
Modules
Images
c:\users\admin\appdata\local\temp\grass_4.28.0_x64-setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
3532"C:\Users\admin\AppData\Local\Temp\Grass_4.28.0_x64-setup.exe" C:\Users\admin\AppData\Local\Temp\Grass_4.28.0_x64-setup.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Version:
4.28.0
Modules
Images
c:\users\admin\appdata\local\temp\grass_4.28.0_x64-setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
6392C:\Users\admin\AppData\Local\Temp\MicrosoftEdgeWebview2Setup.exe /silent /installC:\Users\admin\AppData\Local\Temp\MicrosoftEdgeWebview2Setup.exe
Grass_4.28.0_x64-setup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge Update Setup
Exit code:
2147747592
Version:
1.3.195.25
Modules
Images
c:\users\admin\appdata\local\temp\microsoftedgewebview2setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
7104"C:\Program Files (x86)\Microsoft\Temp\EUE807.tmp\MicrosoftEdgeUpdate.exe" /silent /install "appguid={F3017226-FE2A-4295-8BDF-00C3A9A7E4C5}&appname=Microsoft%20Edge%20Webview2%20Runtime&needsadmin=prefers"C:\Program Files (x86)\Microsoft\Temp\EUE807.tmp\MicrosoftEdgeUpdate.exe
MicrosoftEdgeWebview2Setup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge Update
Exit code:
2147747592
Version:
1.3.195.25
Modules
Images
c:\program files (x86)\microsoft\temp\eue807.tmp\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\ole32.dll
Total events
4 141
Read events
4 107
Write events
32
Delete events
2

Modification events

(PID) Process:(7104) MicrosoftEdgeUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MicrosoftEdgeUpdate.exe
Operation:writeName:DisableExceptionChainValidation
Value:
0
(PID) Process:(7104) MicrosoftEdgeUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate\PersistedPings\{02A3C83C-9516-4E9B-96E9-C6089E2E5C8E}
Operation:writeName:PersistedPingString
Value:
<?xml version="1.0" encoding="UTF-8"?><request protocol="3.0" updater="Omaha" updaterversion="1.3.195.25" shell_version="1.3.147.37" ismachine="1" sessionid="{BB6416B1-F649-42AF-9C5F-7C63E321785C}" userid="{FD984739-A122-4DB0-BE5B-46E3E09D84E4}" installsource="otherinstallcmd" requestid="{02A3C83C-9516-4E9B-96E9-C6089E2E5C8E}" dedup="cr" domainjoined="0"><hw logical_cpus="4" physmemory="4" disk_type="2" sse="1" sse2="1" sse3="1" ssse3="1" sse41="1" sse42="1" avx="1"/><os platform="win" version="10.0.19045.4046" sp="" arch="x64" product_type="48" is_wip="0" is_in_lockdown_mode="0"/><oem product_manufacturer="DELL" product_name="DELL"/><exp etag="&quot;r452t1+k2Tgq/HXzjvFNBRhopBWR9sbjXxqeUDH9uX0=&quot;"/><app appid="{F3C4FE00-EFD5-403B-9569-398A20F1BA4A}" version="1.3.185.17" nextversion="1.3.195.25" lang="" brand="" client=""><event eventtype="2" eventresult="1" errorcode="0" extracode1="0" system_uptime_ticks="5856206246" install_time_ms="422"/></app></request>
(PID) Process:(7104) MicrosoftEdgeUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate\PersistedPings\{02A3C83C-9516-4E9B-96E9-C6089E2E5C8E}
Operation:writeName:PersistedPingTime
Value:
133748873967412719
(PID) Process:(7104) MicrosoftEdgeUpdate.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\EdgeUpdate\proxy
Operation:writeName:source
Value:
auto
(PID) Process:(7104) MicrosoftEdgeUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate\PersistedPings\{02A3C83C-9516-4E9B-96E9-C6089E2E5C8E}
Operation:delete keyName:(default)
Value:
(PID) Process:(7104) MicrosoftEdgeUpdate.exeKey:\REGISTRY\A\{67c58658-eefc-0b22-1427-ea88460548cd}\Root\InventoryApplicationFile
Operation:writeName:WritePermissionsCheck
Value:
1
(PID) Process:(7104) MicrosoftEdgeUpdate.exeKey:\REGISTRY\A\{67c58658-eefc-0b22-1427-ea88460548cd}\Root\InventoryApplicationFile\PermissionsCheckTestKey
Operation:delete keyName:(default)
Value:
(PID) Process:(712) wermgr.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\IdentityCRL\ClockData
Operation:writeName:ClockTimeSeconds
Value:
E504246700000000
(PID) Process:(712) wermgr.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\IdentityCRL\ClockData
Operation:writeName:TickCount
Value:
42F3080000000000
(PID) Process:(7104) MicrosoftEdgeUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate\UsageStats\Daily\Timings
Operation:writeName:setup_lock_acquire_ms
Value:
0300000000000000000000000000000000000000000000000000000000000000
Executable files
204
Suspicious files
5
Text files
6
Unknown types
2

Dropped files

PID
Process
Filename
Type
6392MicrosoftEdgeWebview2Setup.exeC:\Program Files (x86)\Microsoft\Temp\EUE807.tmp\MicrosoftEdgeUpdate.exeexecutable
MD5:1509ED11B3781E023E9C0A491BFDAC80
SHA256:F626890B39920D9FA35EBCC31D448B75DF05FE4A7A424C2B5CEB95C7D61E5D71
6392MicrosoftEdgeWebview2Setup.exeC:\Program Files (x86)\Microsoft\Temp\EUE807.tmp\MicrosoftEdgeUpdateBroker.exeexecutable
MD5:A79F7F8BC9B419E4B18316B2770747E1
SHA256:1856E95BA698594D5DF6A589DEA635C114762BF40A7B43160069E47FFE5080F6
1804Grass_4.28.0_x64-setup.exeC:\Users\admin\AppData\Local\Temp\MicrosoftEdgeWebview2Setup.exeexecutable
MD5:A05C87DD1C5BEF14C7C75F48BF4D01EA
SHA256:274E12D01E0CAE083202DF4A809C1C153B02CB3CA121C19C43B0AAA1C3A53A40
6392MicrosoftEdgeWebview2Setup.exeC:\Program Files (x86)\Microsoft\Temp\EUE807.tmp\psmachine_64.dllexecutable
MD5:D3CFF1EF3EF23D314C8736EDCE0D8E6D
SHA256:48937A055CE355CE8CC3E9D12758B2EF065991F163DA7342479292668042270F
1804Grass_4.28.0_x64-setup.exeC:\Users\admin\AppData\Local\Temp\nsgC908.tmp\System.dllexecutable
MD5:CFF85C549D536F651D4FB8387F1976F2
SHA256:8DC562CDA7217A3A52DB898243DE3E2ED68B80E62DDCB8619545ED0B4E7F65A8
1804Grass_4.28.0_x64-setup.exeC:\Users\admin\AppData\Local\Temp\nsgC908.tmp\nsDialogs.dllexecutable
MD5:6C3F8C94D0727894D706940A8A980543
SHA256:56B96ADD1978B1ABBA286F7F8982B0EFBE007D4A48B3DED6A4D408E01D753FE2
1804Grass_4.28.0_x64-setup.exeC:\Users\admin\AppData\Local\Temp\nsgC908.tmp\modern-wizard.bmpimage
MD5:35294D23C7AD734CF72E51A6265DE20F
SHA256:BD1B474C41C064F8116619D6ADA8653FD5EA3E544C62F53755011F2012EBFE76
6392MicrosoftEdgeWebview2Setup.exeC:\Program Files (x86)\Microsoft\Temp\EUE807.tmp\EdgeUpdate.dathiv
MD5:369BBC37CFF290ADB8963DC5E518B9B8
SHA256:3D7EC761BEF1B1AF418B909F1C81CE577C769722957713FDAFBC8131B0A0C7D3
6392MicrosoftEdgeWebview2Setup.exeC:\Program Files (x86)\Microsoft\Temp\EUE807.tmp\MicrosoftEdgeUpdateOnDemand.exeexecutable
MD5:64309E5DDEF493FCD044041E31B44494
SHA256:43F54C9E85C0BBC86F9AACDAB40682E330D6D58BAD89A400FD6F609F72285FE2
6392MicrosoftEdgeWebview2Setup.exeC:\Program Files (x86)\Microsoft\Temp\EUE807.tmp\MicrosoftEdgeComRegisterShellARM64.exeexecutable
MD5:D16DEAB532387BB817FCAA50B9BD8972
SHA256:BA27CA798445934D02BE72A0FAA198539DFA38E922C06BDD93EB3070EE12311B
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
11
TCP/UDP connections
49
DNS requests
25
Threats
5

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5488
MoUsoCoreWorker.exe
GET
200
2.16.168.11:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5488
MoUsoCoreWorker.exe
GET
200
2.23.9.218:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6376
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
4360
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
1804
Grass_4.28.0_x64-setup.exe
GET
301
2.23.10.89:80
http://go.microsoft.com/fwlink/p/?LinkId=2124703
unknown
whitelisted
1804
Grass_4.28.0_x64-setup.exe
GET
200
2.20.245.139:80
http://msedge.sf.dl.delivery.mp.microsoft.com/filestreamingservice/files/1b33f4e1-227e-4265-b9e9-3751aeeb2efe/MicrosoftEdgeWebview2Setup.exe
unknown
whitelisted
712
wermgr.exe
GET
200
2.23.9.218:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
712
wermgr.exe
GET
200
2.16.168.12:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5596
SIHClient.exe
GET
200
2.23.9.218:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
3860
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
6944
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
23.212.110.200:443
www.bing.com
Akamai International B.V.
CZ
whitelisted
4080
RUXIMICS.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5488
MoUsoCoreWorker.exe
2.16.168.11:80
crl.microsoft.com
Akamai International B.V.
RU
whitelisted
5488
MoUsoCoreWorker.exe
2.23.9.218:80
www.microsoft.com
AKAMAI-AS
CZ
whitelisted
4020
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:138
whitelisted
6376
svchost.exe
40.126.32.76:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
  • 40.127.240.158
whitelisted
www.bing.com
  • 23.212.110.200
  • 23.212.110.136
  • 23.212.110.217
  • 23.212.110.144
  • 23.212.110.218
  • 23.212.110.187
  • 23.212.110.147
  • 23.212.110.208
  • 23.212.110.185
whitelisted
crl.microsoft.com
  • 2.16.168.11
  • 2.16.168.12
whitelisted
www.microsoft.com
  • 2.23.9.218
whitelisted
google.com
  • 142.250.185.110
whitelisted
login.live.com
  • 40.126.32.76
  • 20.190.160.22
  • 40.126.32.138
  • 40.126.32.74
  • 40.126.32.68
  • 40.126.32.136
  • 40.126.32.133
  • 20.190.160.14
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
go.microsoft.com
  • 2.23.10.89
whitelisted
th.bing.com
  • 23.212.110.185
  • 23.212.110.200
  • 23.212.110.136
  • 23.212.110.217
  • 23.212.110.144
  • 23.212.110.218
  • 23.212.110.187
  • 23.212.110.147
  • 23.212.110.208
whitelisted
msedge.sf.dl.delivery.mp.microsoft.com
  • 2.20.245.139
  • 2.20.245.140
whitelisted

Threats

PID
Process
Class
Message
1804
Grass_4.28.0_x64-setup.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
4 ETPRO signatures available at the full report
No debug info