File name:

Grass_4.28.0_x64-setup.exe

Full analysis: https://app.any.run/tasks/321433cf-4a5f-45cd-af83-301af77ea475
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: October 31, 2024, 22:29:36
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
loader
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive, 5 sections
MD5:

C297BA1811486746089AC428B9B59AD2

SHA1:

8EC1B7E044E5DAD824B609B633D24A70AA4DFF97

SHA256:

43112520B679C53B3B25EB2A4DCA3A0508DF524959AA40BC42409FF582C11116

SSDEEP:

98304:RJ8/XkJW5LPhevQ8q6exiwR+oSx7KjiPwp8mGusnuFmRSBOrTutkdVUKfnKO0EEc:Rz4yDTI7gKJwW/acEuIQ9tQSa

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • The process creates files with name similar to system file names

      • Grass_4.28.0_x64-setup.exe (PID: 1804)
    • Executable content was dropped or overwritten

      • Grass_4.28.0_x64-setup.exe (PID: 1804)
      • MicrosoftEdgeWebview2Setup.exe (PID: 6392)
    • Starts a Microsoft application from unusual location

      • MicrosoftEdgeWebview2Setup.exe (PID: 6392)
      • MicrosoftEdgeUpdate.exe (PID: 7104)
    • Process drops legitimate windows executable

      • MicrosoftEdgeUpdate.exe (PID: 7104)
      • MicrosoftEdgeWebview2Setup.exe (PID: 6392)
      • Grass_4.28.0_x64-setup.exe (PID: 1804)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • Grass_4.28.0_x64-setup.exe (PID: 1804)
    • Potential Corporate Privacy Violation

      • Grass_4.28.0_x64-setup.exe (PID: 1804)
  • INFO

    • Checks supported languages

      • Grass_4.28.0_x64-setup.exe (PID: 1804)
    • Reads the computer name

      • Grass_4.28.0_x64-setup.exe (PID: 1804)
    • Create files in a temporary directory

      • Grass_4.28.0_x64-setup.exe (PID: 1804)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2021:09:25 21:56:47+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 26624
InitializedDataSize: 141824
UninitializedDataSize: 2048
EntryPoint: 0x3640
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 4.28.0.0
ProductVersionNumber: 4.28.0.0
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
FileDescription: -
FileVersion: 4.28.0
LegalCopyright: © Grass Foundation, 2024. All rights reserved.
ProductName: Grass
ProductVersion: 4.28.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
135
Monitored processes
5
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start grass_4.28.0_x64-setup.exe microsoftedgewebview2setup.exe microsoftedgeupdate.exe wermgr.exe grass_4.28.0_x64-setup.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
712"C:\WINDOWS\system32\wermgr.exe" "-outproc" "0" "7104" "2044" "1796" "2052" "0" "0" "0" "0" "0" "0" "0" "0" C:\Windows\SysWOW64\wermgr.exe
MicrosoftEdgeUpdate.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\wermgr.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
1804"C:\Users\admin\AppData\Local\Temp\Grass_4.28.0_x64-setup.exe" C:\Users\admin\AppData\Local\Temp\Grass_4.28.0_x64-setup.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Version:
4.28.0
Modules
Images
c:\users\admin\appdata\local\temp\grass_4.28.0_x64-setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
3532"C:\Users\admin\AppData\Local\Temp\Grass_4.28.0_x64-setup.exe" C:\Users\admin\AppData\Local\Temp\Grass_4.28.0_x64-setup.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Version:
4.28.0
Modules
Images
c:\users\admin\appdata\local\temp\grass_4.28.0_x64-setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
6392C:\Users\admin\AppData\Local\Temp\MicrosoftEdgeWebview2Setup.exe /silent /installC:\Users\admin\AppData\Local\Temp\MicrosoftEdgeWebview2Setup.exe
Grass_4.28.0_x64-setup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge Update Setup
Exit code:
2147747592
Version:
1.3.195.25
Modules
Images
c:\users\admin\appdata\local\temp\microsoftedgewebview2setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
7104"C:\Program Files (x86)\Microsoft\Temp\EUE807.tmp\MicrosoftEdgeUpdate.exe" /silent /install "appguid={F3017226-FE2A-4295-8BDF-00C3A9A7E4C5}&appname=Microsoft%20Edge%20Webview2%20Runtime&needsadmin=prefers"C:\Program Files (x86)\Microsoft\Temp\EUE807.tmp\MicrosoftEdgeUpdate.exe
MicrosoftEdgeWebview2Setup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge Update
Exit code:
2147747592
Version:
1.3.195.25
Modules
Images
c:\program files (x86)\microsoft\temp\eue807.tmp\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\ole32.dll
Total events
4 141
Read events
4 107
Write events
32
Delete events
2

Modification events

(PID) Process:(7104) MicrosoftEdgeUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MicrosoftEdgeUpdate.exe
Operation:writeName:DisableExceptionChainValidation
Value:
0
(PID) Process:(7104) MicrosoftEdgeUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate\PersistedPings\{02A3C83C-9516-4E9B-96E9-C6089E2E5C8E}
Operation:writeName:PersistedPingString
Value:
<?xml version="1.0" encoding="UTF-8"?><request protocol="3.0" updater="Omaha" updaterversion="1.3.195.25" shell_version="1.3.147.37" ismachine="1" sessionid="{BB6416B1-F649-42AF-9C5F-7C63E321785C}" userid="{FD984739-A122-4DB0-BE5B-46E3E09D84E4}" installsource="otherinstallcmd" requestid="{02A3C83C-9516-4E9B-96E9-C6089E2E5C8E}" dedup="cr" domainjoined="0"><hw logical_cpus="4" physmemory="4" disk_type="2" sse="1" sse2="1" sse3="1" ssse3="1" sse41="1" sse42="1" avx="1"/><os platform="win" version="10.0.19045.4046" sp="" arch="x64" product_type="48" is_wip="0" is_in_lockdown_mode="0"/><oem product_manufacturer="DELL" product_name="DELL"/><exp etag="&quot;r452t1+k2Tgq/HXzjvFNBRhopBWR9sbjXxqeUDH9uX0=&quot;"/><app appid="{F3C4FE00-EFD5-403B-9569-398A20F1BA4A}" version="1.3.185.17" nextversion="1.3.195.25" lang="" brand="" client=""><event eventtype="2" eventresult="1" errorcode="0" extracode1="0" system_uptime_ticks="5856206246" install_time_ms="422"/></app></request>
(PID) Process:(7104) MicrosoftEdgeUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate\PersistedPings\{02A3C83C-9516-4E9B-96E9-C6089E2E5C8E}
Operation:writeName:PersistedPingTime
Value:
133748873967412719
(PID) Process:(7104) MicrosoftEdgeUpdate.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\EdgeUpdate\proxy
Operation:writeName:source
Value:
auto
(PID) Process:(7104) MicrosoftEdgeUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate\PersistedPings\{02A3C83C-9516-4E9B-96E9-C6089E2E5C8E}
Operation:delete keyName:(default)
Value:
(PID) Process:(7104) MicrosoftEdgeUpdate.exeKey:\REGISTRY\A\{67c58658-eefc-0b22-1427-ea88460548cd}\Root\InventoryApplicationFile
Operation:writeName:WritePermissionsCheck
Value:
1
(PID) Process:(7104) MicrosoftEdgeUpdate.exeKey:\REGISTRY\A\{67c58658-eefc-0b22-1427-ea88460548cd}\Root\InventoryApplicationFile\PermissionsCheckTestKey
Operation:delete keyName:(default)
Value:
(PID) Process:(712) wermgr.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\IdentityCRL\ClockData
Operation:writeName:ClockTimeSeconds
Value:
E504246700000000
(PID) Process:(712) wermgr.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\IdentityCRL\ClockData
Operation:writeName:TickCount
Value:
42F3080000000000
(PID) Process:(7104) MicrosoftEdgeUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate\UsageStats\Daily\Timings
Operation:writeName:setup_lock_acquire_ms
Value:
0300000000000000000000000000000000000000000000000000000000000000
Executable files
204
Suspicious files
5
Text files
6
Unknown types
2

Dropped files

PID
Process
Filename
Type
6392MicrosoftEdgeWebview2Setup.exeC:\Program Files (x86)\Microsoft\Temp\EUE807.tmp\MicrosoftEdgeComRegisterShellARM64.exeexecutable
MD5:D16DEAB532387BB817FCAA50B9BD8972
SHA256:BA27CA798445934D02BE72A0FAA198539DFA38E922C06BDD93EB3070EE12311B
6392MicrosoftEdgeWebview2Setup.exeC:\Program Files (x86)\Microsoft\Temp\EUE807.tmp\MicrosoftEdgeUpdateComRegisterShell64.exeexecutable
MD5:8CDA2D501C51F0869A69D5951F2AEC5E
SHA256:208497513FF0C793E6DC0A9935D73DFC37887C875FE00AFF4DFAEB3854054D31
6392MicrosoftEdgeWebview2Setup.exeC:\Program Files (x86)\Microsoft\Temp\EUE807.tmp\MicrosoftEdgeUpdateBroker.exeexecutable
MD5:A79F7F8BC9B419E4B18316B2770747E1
SHA256:1856E95BA698594D5DF6A589DEA635C114762BF40A7B43160069E47FFE5080F6
6392MicrosoftEdgeWebview2Setup.exeC:\Program Files (x86)\Microsoft\Temp\EUE807.tmp\MicrosoftEdgeUpdate.exeexecutable
MD5:1509ED11B3781E023E9C0A491BFDAC80
SHA256:F626890B39920D9FA35EBCC31D448B75DF05FE4A7A424C2B5CEB95C7D61E5D71
6392MicrosoftEdgeWebview2Setup.exeC:\Program Files (x86)\Microsoft\Temp\EUE807.tmp\psuser_arm64.dllexecutable
MD5:B51A99AA9384A2697750B9CA6E30567D
SHA256:1567C3B69B505D9FA8D33928B6508F67277BAD0BB8C0D4A529D8BE3D6CE97E5F
1804Grass_4.28.0_x64-setup.exeC:\Users\admin\AppData\Local\Temp\nsgC908.tmp\modern-wizard.bmpimage
MD5:35294D23C7AD734CF72E51A6265DE20F
SHA256:BD1B474C41C064F8116619D6ADA8653FD5EA3E544C62F53755011F2012EBFE76
6392MicrosoftEdgeWebview2Setup.exeC:\Program Files (x86)\Microsoft\Temp\EUE807.tmp\psuser_64.dllexecutable
MD5:16CB0B937BE08D65067B1A4F755E89A1
SHA256:54467B33C5A347E7A3CE1AD3EA0E06F59F7A46132C7DCA6E38BB56F48D74CD8D
6392MicrosoftEdgeWebview2Setup.exeC:\Program Files (x86)\Microsoft\Temp\EUE807.tmp\psmachine.dllexecutable
MD5:D784C91F463DAF63DB3B0621D2F6530B
SHA256:6941FB408480FD8E5936248310DBF6823F1003D84328CCBF9CA56604B3A6DF52
6392MicrosoftEdgeWebview2Setup.exeC:\Program Files (x86)\Microsoft\Temp\EUE807.tmp\psuser.dllexecutable
MD5:0407DC1F6D634CE9B2891656814E77C5
SHA256:9172E1E9EC6BF144B9B38131FBE8401EB028E5428A890D46C0F45F5AF13F5561
6392MicrosoftEdgeWebview2Setup.exeC:\Program Files (x86)\Microsoft\Temp\EUE807.tmp\psmachine_arm64.dllexecutable
MD5:517D9F4A900BC852A7E5B8C07C65B7FD
SHA256:86305CC725B00D82F049BA4DA267C17FBB8839706058524997039D5834FD1ED4
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
11
TCP/UDP connections
49
DNS requests
25
Threats
5

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5488
MoUsoCoreWorker.exe
GET
200
2.16.168.11:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
6376
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
1804
Grass_4.28.0_x64-setup.exe
GET
200
2.20.245.139:80
http://msedge.sf.dl.delivery.mp.microsoft.com/filestreamingservice/files/1b33f4e1-227e-4265-b9e9-3751aeeb2efe/MicrosoftEdgeWebview2Setup.exe
unknown
whitelisted
5596
SIHClient.exe
GET
200
2.23.9.218:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
712
wermgr.exe
GET
200
2.23.9.218:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
712
wermgr.exe
GET
200
2.16.168.12:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
3860
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
5596
SIHClient.exe
GET
200
2.23.9.218:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
4360
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
5488
MoUsoCoreWorker.exe
GET
200
2.23.9.218:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
6944
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
23.212.110.200:443
www.bing.com
Akamai International B.V.
CZ
whitelisted
4080
RUXIMICS.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5488
MoUsoCoreWorker.exe
2.16.168.11:80
crl.microsoft.com
Akamai International B.V.
RU
whitelisted
5488
MoUsoCoreWorker.exe
2.23.9.218:80
www.microsoft.com
AKAMAI-AS
CZ
whitelisted
4020
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:138
whitelisted
6376
svchost.exe
40.126.32.76:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
  • 40.127.240.158
whitelisted
www.bing.com
  • 23.212.110.200
  • 23.212.110.136
  • 23.212.110.217
  • 23.212.110.144
  • 23.212.110.218
  • 23.212.110.187
  • 23.212.110.147
  • 23.212.110.208
  • 23.212.110.185
whitelisted
crl.microsoft.com
  • 2.16.168.11
  • 2.16.168.12
whitelisted
www.microsoft.com
  • 2.23.9.218
whitelisted
google.com
  • 142.250.185.110
whitelisted
login.live.com
  • 40.126.32.76
  • 20.190.160.22
  • 40.126.32.138
  • 40.126.32.74
  • 40.126.32.68
  • 40.126.32.136
  • 40.126.32.133
  • 20.190.160.14
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
go.microsoft.com
  • 2.23.10.89
whitelisted
th.bing.com
  • 23.212.110.185
  • 23.212.110.200
  • 23.212.110.136
  • 23.212.110.217
  • 23.212.110.144
  • 23.212.110.218
  • 23.212.110.187
  • 23.212.110.147
  • 23.212.110.208
whitelisted
msedge.sf.dl.delivery.mp.microsoft.com
  • 2.20.245.139
  • 2.20.245.140
whitelisted

Threats

PID
Process
Class
Message
1804
Grass_4.28.0_x64-setup.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
4 ETPRO signatures available at the full report
No debug info