File name:

AmbaUSB-win64-Qt5-Win7-4.1.1-Setup.exe

Full analysis: https://app.any.run/tasks/52517280-9dba-459c-8286-d99cab411bf7
Verdict: Malicious activity
Analysis date: May 21, 2024, 21:51:23
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows, Nullsoft Installer self-extracting archive
MD5:

138146AE1F0C7DEB6968AA24364B683E

SHA1:

109FB1E88A7AE03834EF93BD7D29299A16B38898

SHA256:

4331C54B1EAC6678BFAA01974CAA2AFDE2790D6BE550104A84B46344A19F378E

SSDEEP:

98304:+TI8HV22zbTQKemxkRTCD0YScB+CKibbvhj3N5L2uoD+dxCrpADHKf8fvilIkxSn:w97uEOfTAdsC8S41DOOaYJPmd

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • AmbaUSB-win64-Qt5-Win7-4.1.1-Setup.exe (PID: 4088)
  • SUSPICIOUS

    • Malware-specific behavior (creating "System.dll" in Temp)

      • AmbaUSB-win64-Qt5-Win7-4.1.1-Setup.exe (PID: 4088)
    • Executable content was dropped or overwritten

      • AmbaUSB-win64-Qt5-Win7-4.1.1-Setup.exe (PID: 4088)
    • Drops a system driver (possible attempt to evade defenses)

      • AmbaUSB-win64-Qt5-Win7-4.1.1-Setup.exe (PID: 4088)
    • Process drops legitimate windows executable

      • AmbaUSB-win64-Qt5-Win7-4.1.1-Setup.exe (PID: 4088)
    • The process creates files with name similar to system file names

      • AmbaUSB-win64-Qt5-Win7-4.1.1-Setup.exe (PID: 4088)
    • Creates a software uninstall entry

      • AmbaUSB-win64-Qt5-Win7-4.1.1-Setup.exe (PID: 4088)
  • INFO

    • Reads the computer name

      • AmbaUSB-win64-Qt5-Win7-4.1.1-Setup.exe (PID: 4088)
    • Checks supported languages

      • AmbaUSB-win64-Qt5-Win7-4.1.1-Setup.exe (PID: 4088)
    • Create files in a temporary directory

      • AmbaUSB-win64-Qt5-Win7-4.1.1-Setup.exe (PID: 4088)
    • Creates files in the program directory

      • AmbaUSB-win64-Qt5-Win7-4.1.1-Setup.exe (PID: 4088)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2019:05:29 10:14:13+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit, No debug
PEType: PE32
LinkerVersion: 2.3
CodeSize: 35840
InitializedDataSize: 38400
UninitializedDataSize: 251392
EntryPoint: 0x40a6
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
37
Monitored processes
2
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start ambausb-win64-qt5-win7-4.1.1-setup.exe ambausb-win64-qt5-win7-4.1.1-setup.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
3984"C:\Users\admin\AmbaUSB-win64-Qt5-Win7-4.1.1-Setup.exe" C:\Users\admin\AmbaUSB-win64-Qt5-Win7-4.1.1-Setup.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\ambausb-win64-qt5-win7-4.1.1-setup.exe
c:\windows\system32\ntdll.dll
4088"C:\Users\admin\AmbaUSB-win64-Qt5-Win7-4.1.1-Setup.exe" C:\Users\admin\AmbaUSB-win64-Qt5-Win7-4.1.1-Setup.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\ambausb-win64-qt5-win7-4.1.1-setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\gdi32.dll
Total events
922
Read events
911
Write events
11
Delete events
0

Modification events

(PID) Process:(4088) AmbaUSB-win64-Qt5-Win7-4.1.1-Setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Ambarella AmbaUSB
Operation:writeName:DisplayName
Value:
Ambarella AmbaUSB 4.1.1
(PID) Process:(4088) AmbaUSB-win64-Qt5-Win7-4.1.1-Setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Ambarella AmbaUSB
Operation:writeName:UninstallString
Value:
C:\Program Files\Ambarella\AmbaUSB\Uninstall.exe
(PID) Process:(4088) AmbaUSB-win64-Qt5-Win7-4.1.1-Setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Ambarella AmbaUSB
Operation:writeName:InstallLocation
Value:
C:\Program Files\Ambarella\AmbaUSB
(PID) Process:(4088) AmbaUSB-win64-Qt5-Win7-4.1.1-Setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Ambarella AmbaUSB
Operation:writeName:DisplayIcon
Value:
C:\Program Files\Ambarella\AmbaUSB\share\pixmaps\AmbaUSB.ico
(PID) Process:(4088) AmbaUSB-win64-Qt5-Win7-4.1.1-Setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Ambarella AmbaUSB
Operation:writeName:Publisher
Value:
Ambarella
(PID) Process:(4088) AmbaUSB-win64-Qt5-Win7-4.1.1-Setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Ambarella AmbaUSB
Operation:writeName:DisplayVersion
Value:
4.1.1
(PID) Process:(4088) AmbaUSB-win64-Qt5-Win7-4.1.1-Setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Ambarella AmbaUSB
Operation:writeName:VersionMajor
Value:
4
(PID) Process:(4088) AmbaUSB-win64-Qt5-Win7-4.1.1-Setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Ambarella AmbaUSB
Operation:writeName:VersionMinor
Value:
1
(PID) Process:(4088) AmbaUSB-win64-Qt5-Win7-4.1.1-Setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Ambarella AmbaUSB
Operation:writeName:VersionPatch
Value:
1
(PID) Process:(4088) AmbaUSB-win64-Qt5-Win7-4.1.1-Setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Ambarella AmbaUSB
Operation:writeName:NoModify
Value:
1
Executable files
40
Suspicious files
53
Text files
199
Unknown types
21

Dropped files

PID
Process
Filename
Type
4088AmbaUSB-win64-Qt5-Win7-4.1.1-Setup.exeC:\Users\admin\AppData\Local\Temp\nsh94A2.tmp\modern-wizard.bmpimage
MD5:CBE40FD2B1EC96DAEDC65DA172D90022
SHA256:3AD2DC318056D0A2024AF1804EA741146CFC18CC404649A44610CBF8B2056CF2
4088AmbaUSB-win64-Qt5-Win7-4.1.1-Setup.exeC:\Program Files\Ambarella\AmbaUSB\bin\ambausb.exeexecutable
MD5:81E4D5E28355595B431FF1604FB35A59
SHA256:16B71AE479D6AB6D4556AAF0737264761BB9DEB089E3141BD5B3F5699CE81808
4088AmbaUSB-win64-Qt5-Win7-4.1.1-Setup.exeC:\Program Files\Ambarella\AmbaUSB\bin\Qt5Network.dllexecutable
MD5:260E23C352DA80F4211B03D5B7FDA550
SHA256:2D8541544DE49B4628E8AA3A7D426D3BF6055BF906B114F35E1F039DF3CE13A0
4088AmbaUSB-win64-Qt5-Win7-4.1.1-Setup.exeC:\Program Files\Ambarella\AmbaUSB\bin\Qt5Multimedia.dllexecutable
MD5:F706EB103DA2EE60BC139CB46A720670
SHA256:C7167E474D3520C86C42E84C8DA519449C60C5149F2BEADD4BC0775D43F03EB9
4088AmbaUSB-win64-Qt5-Win7-4.1.1-Setup.exeC:\Program Files\Ambarella\AmbaUSB\bin\libexpat-1.dllexecutable
MD5:7F242E43ACC6CAE735315FB96692CF91
SHA256:EC7CAD3B8BD8D3B2E0B0A6D601E5C3F918DAA7DF31DA858D68653AFA14CC588D
4088AmbaUSB-win64-Qt5-Win7-4.1.1-Setup.exeC:\Program Files\Ambarella\AmbaUSB\bin\libglib-2.0-0.dllexecutable
MD5:9CD6C8976201EE55CDD5E0C7E4FA11A0
SHA256:C06DF0F7B93DAC9C1C6AC64ABC6CFBA70E62A239D344F7F9B22FB599D442B114
4088AmbaUSB-win64-Qt5-Win7-4.1.1-Setup.exeC:\Users\admin\AppData\Local\Temp\nsh94A2.tmp\nsDialogs.dllexecutable
MD5:407630C1D777B4E3414CF9061A5EA862
SHA256:BC4AE7E1755B8735795832E793DD8443ED57DE6A56F71840AEBDE64247900FEF
4088AmbaUSB-win64-Qt5-Win7-4.1.1-Setup.exeC:\Users\admin\AppData\Local\Temp\nsh94A2.tmp\System.dllexecutable
MD5:AD6D8F6684E840633536F028C41DFAFD
SHA256:32F2128A7B3285634CB6A27E9EC91659C280CC9908A86651178E30002C069788
4088AmbaUSB-win64-Qt5-Win7-4.1.1-Setup.exeC:\Program Files\Ambarella\AmbaUSB\bin\Qt5Gui.dllexecutable
MD5:66DEFA033A6E4C8DA8C0692DD4C4737B
SHA256:D9931B6BB5AE175A1FCA65664ADEBF315D1CFD8AAC8681B75D63D1CBC27A951A
4088AmbaUSB-win64-Qt5-Win7-4.1.1-Setup.exeC:\Users\admin\AppData\Local\Temp\nsh94A2.tmp\UserInfo.dllexecutable
MD5:4205209C758CEAC51AF9A0F26A2BF175
SHA256:AFFCD37F0967AFCA46D6C3715CE05B09AF3275C72363981E3D1CF4E16A282CFB
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
3
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
unknown
224.0.0.252:5355
unknown

DNS requests

No data

Threats

No threats detected
No debug info