| File name: | kaspersky4win202121.16.6.467ru_45357.exe |
| Full analysis: | https://app.any.run/tasks/eb37de0f-1990-4357-811d-c88571defbf7 |
| Verdict: | Malicious activity |
| Analysis date: | May 14, 2024, 11:43:41 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 63C9A22C500DF9925F2E513AE1091653 |
| SHA1: | BC93F45C412173045C0E39CB1B6A622C52669DE0 |
| SHA256: | 47F5CE81CE33612610A6EFC353A0735A4BAF8486A898D7ECEADB8A58D2415DFC |
| SSDEEP: | 98304:g37Sg7FX9xYuq/adLg37g73UStI6phCP9KAOPfmtwlsLPt6Hk7J0SHlQ9Lp7BKUp:HcFYx9g |
| .exe | | | Win64 Executable (generic) (76.4) |
|---|---|---|
| .exe | | | Win32 Executable (generic) (12.4) |
| .exe | | | Generic Win/DOS Executable (5.5) |
| .exe | | | DOS Executable Generic (5.5) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2008:01:14 07:47:03+00:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 14.29 |
| CodeSize: | 233472 |
| InitializedDataSize: | 4243456 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x4200 |
| OSVersion: | 6 |
| ImageVersion: | - |
| SubsystemVersion: | 6 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 21.16.6.467 |
| ProductVersionNumber: | 21.16.6.467 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Windows NT 32-bit |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| CompanyName: | Лаборатория Касперского |
| FileDescription: | Kaspersky [21.16.6.467.0.5.0] |
| FileVersion: | 21.16.6.467 |
| LegalCopyright: | © 2024 АО "Лаборатория Касперского" |
| LegalTrademarks: | Зарегистрированные товарные знаки и знаки обслуживания являются собственностью их правообладателей |
| ProductName: | Kaspersky |
| ProductVersion: | 21.16.6.467 |
| InternalName: | Setup |
| OriginalFileName: | Setup.exe |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 524 | "C:\ProgramData\Kaspersky Lab Setup Files\KFA21.17.7.539.0.2.0\au_setup_3B92CCF2-11E7-11EF-9E36-12A9866C77DE\startup.exe" -auto_update_mode="C:\Users\admin\AppData\Local\Temp\kaspersky4win202121.16.6.467ru_45357.exe" /-self_remove -l=ru-RU -xpos=270 -ypos=64 -prevsetupver=21.16.6.467.0.5.0 | C:\ProgramData\Kaspersky Lab Setup Files\KFA21.17.7.539.0.2.0\au_setup_3B92CCF2-11E7-11EF-9E36-12A9866C77DE\startup.exe | kaspersky4win202121.16.6.467ru_45357.exe | ||||||||||||
User: admin Company: Лаборатория Касперского Integrity Level: MEDIUM Description: Kaspersky [21.17.7.539.0.2.0] Version: 21.17.7.539 Modules
| |||||||||||||||
| 1580 | "C:\Program Files\Windows Media Player\wmpnscfg.exe" | C:\Program Files\Windows Media Player\wmpnscfg.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Network Sharing Service Configuration Application Exit code: 0 Version: 12.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1960 | "C:\ProgramData\Kaspersky Lab Setup Files\KFA21.17.7.539.0.2.0\au_setup_3B92CCF2-11E7-11EF-9E36-12A9866C77DE\startup.exe" /-elevated=;"C:\ProgramData\Kaspersky Lab Setup Files\KFA21.17.7.539.0.2.0\au_setup_3B92CCF2-11E7-11EF-9E36-12A9866C77DE\startup.exe" | C:\ProgramData\Kaspersky Lab Setup Files\KFA21.17.7.539.0.2.0\au_setup_3B92CCF2-11E7-11EF-9E36-12A9866C77DE\startup.exe | startup.exe | ||||||||||||
User: admin Company: Лаборатория Касперского Integrity Level: HIGH Description: Kaspersky [21.17.7.539.0.2.0] Version: 21.17.7.539 Modules
| |||||||||||||||
| 2272 | "C:\Users\admin\AppData\Local\Temp\kaspersky4win202121.16.6.467ru_45357.exe" -cleanup="C:\Users\admin\AppData\Local\Temp\FECC29B37E11FE11E963219A68C677ED;3980" | C:\Users\admin\AppData\Local\Temp\kaspersky4win202121.16.6.467ru_45357.exe | — | kaspersky4win202121.16.6.467ru_45357.exe | |||||||||||
User: admin Company: Лаборатория Касперского Integrity Level: MEDIUM Description: Kaspersky [21.16.6.467.0.5.0] Exit code: 0 Version: 21.16.6.467 Modules
| |||||||||||||||
| 2480 | "C:\Windows\temp\3D4C30547E11FE11E963219A68C677ED\startup.exe" /-elevated=;"C:\ProgramData\Kaspersky Lab Setup Files\KFA21.17.7.539.0.2.0\au_setup_3B92CCF2-11E7-11EF-9E36-12A9866C77DE\startup.exe" | C:\Windows\Temp\3D4C30547E11FE11E963219A68C677ED\startup.exe | startup.exe | ||||||||||||
User: admin Company: Лаборатория Касперского Integrity Level: HIGH Description: Kaspersky [21.17.7.539.0.2.0] Version: 21.17.7.539 Modules
| |||||||||||||||
| 3980 | "C:\Users\admin\AppData\Local\Temp\kaspersky4win202121.16.6.467ru_45357.exe" | C:\Users\admin\AppData\Local\Temp\kaspersky4win202121.16.6.467ru_45357.exe | explorer.exe | ||||||||||||
User: admin Company: Лаборатория Касперского Integrity Level: MEDIUM Description: Kaspersky [21.16.6.467.0.5.0] Exit code: 0 Version: 21.16.6.467 Modules
| |||||||||||||||
| (PID) Process: | (3980) kaspersky4win202121.16.6.467ru_45357.exe | Key: | HKEY_CURRENT_USER\Software\KasperskyLabSetup\Setup21.16.6.467.0.5.0\volatile |
| Operation: | write | Name: | cp_storedResolvedType |
Value: -1 | |||
| (PID) Process: | (3980) kaspersky4win202121.16.6.467ru_45357.exe | Key: | HKEY_CURRENT_USER\Software\KasperskyLabSetup\Setup21.16.6.467.0.5.0\volatile |
| Operation: | write | Name: | cp_storedResolvedProductTier |
Value: 0 | |||
| (PID) Process: | (3980) kaspersky4win202121.16.6.467ru_45357.exe | Key: | HKEY_CURRENT_USER\Software\KasperskyLabSetup\Setup21.16.6.467.0.5.0\volatile |
| Operation: | write | Name: | cp_storedResolvedStartupScenario |
Value: | |||
| (PID) Process: | (3980) kaspersky4win202121.16.6.467ru_45357.exe | Key: | HKEY_CURRENT_USER\Software\KasperskyLabSetup\Setup21.16.6.467.0.5.0\volatile |
| Operation: | write | Name: | cp_storedResolvedType |
Value: 4 | |||
| (PID) Process: | (3980) kaspersky4win202121.16.6.467ru_45357.exe | Key: | HKEY_CURRENT_USER\Software\KasperskyLabSetup\Setup21.16.6.467.0.5.0\volatile |
| Operation: | write | Name: | cp_storedResolvedProductTier |
Value: 230 | |||
| (PID) Process: | (3980) kaspersky4win202121.16.6.467ru_45357.exe | Key: | HKEY_CURRENT_USER\Software\KasperskyLabSetup\Setup21.16.6.467.0.5.0\volatile |
| Operation: | write | Name: | cp_storedResolvedStartupScenario |
Value: Free | |||
| (PID) Process: | (3980) kaspersky4win202121.16.6.467ru_45357.exe | Key: | HKEY_CURRENT_USER\Software\KasperskyLabSetup\Setup21.16.6.467.0.5.0\volatile |
| Operation: | write | Name: | PreferredUI |
Value: 0 | |||
| (PID) Process: | (3980) kaspersky4win202121.16.6.467ru_45357.exe | Key: | HKEY_CURRENT_USER\Software\KasperskyLabSetup\Setup21.16.6.467.0.5.0\volatile |
| Operation: | write | Name: | PreferredUI |
Value: 1 | |||
| (PID) Process: | (3980) kaspersky4win202121.16.6.467ru_45357.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (3980) kaspersky4win202121.16.6.467ru_45357.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3980 | kaspersky4win202121.16.6.467ru_45357.exe | C:\Users\admin\AppData\Local\Temp\kl-setup-2024-05-14-12-43-52_KFA.21.16.6.467.log | — | |
MD5:— | SHA256:— | |||
| 3980 | kaspersky4win202121.16.6.467ru_45357.exe | C:\Users\admin\AppData\Local\Temp\3B92CCF0-11E7-11EF-9E36-12A9866C77DE\downloader_neutral.ini | text | |
MD5:1224967A336A831FC3D44D58BB3B471E | SHA256:20019DA9AFBEE4E3E2A9A1F9D32AD53DD4E3BC23368FC8E5E5F77758026F812A | |||
| 3980 | kaspersky4win202121.16.6.467ru_45357.exe | C:\Users\admin\AppData\Local\Temp\kl-setup-2024-05-14-12-43-52_KAV.21.16.6.467.log | text | |
MD5:3A1AD6B754288D32FB47BD451BDAAE6B | SHA256:CA407E53B74C5BE42938F87E0376770C1315ABBDFBE0C8B6CFEA3D7F5BD1B01F | |||
| 3980 | kaspersky4win202121.16.6.467ru_45357.exe | C:\Users\admin\AppData\Local\Temp\FECC29B37E11FE11E963219A68C677ED\kl.setup.ui.dll | executable | |
MD5:BB9DF6ED16BAD5BBCDE9B106E11DFF6F | SHA256:DC5F2821548E5A660FC920224846994DA0169972F18A15E04FC9943A6A08F734 | |||
| 3980 | kaspersky4win202121.16.6.467ru_45357.exe | C:\Users\admin\AppData\Local\Temp\FECC29B37E11FE11E963219A68C677ED\kl.setup.ui.visuals.dll | executable | |
MD5:5BCC51F3BB85949E37FFC08CF1501F70 | SHA256:FDCBE09D8C6EE7681E88BBF7BBCC6C87F089D034E00DF6A422C3482F4A99A2BD | |||
| 3980 | kaspersky4win202121.16.6.467ru_45357.exe | C:\Users\admin\AppData\Local\Temp\FECC29B37E11FE11E963219A68C677ED\kl.setup.ui.core.dll | executable | |
MD5:78FB3F1E9F69BECA863AF1FF7713249C | SHA256:323AA8D8707A030BF245D6031B7FB439C929A3A24C5621A03276114691E45AAC | |||
| 3980 | kaspersky4win202121.16.6.467ru_45357.exe | C:\Users\admin\AppData\Local\Temp\FECC29B37E11FE11E963219A68C677ED\kl.ui.framework.uikit.b2c.dll | executable | |
MD5:FB389C9C3C063163F5609608405F66BC | SHA256:7E97138FE069A260A05BAD7BEDDC31FC54D0909F36728AB0EFA761E7580393DF | |||
| 3980 | kaspersky4win202121.16.6.467ru_45357.exe | C:\Users\admin\AppData\Local\Temp\FECC29B37E11FE11E963219A68C677ED\setup.dll | executable | |
MD5:986033838280C8D36C4FCC14B03CAA35 | SHA256:42ABFB0FD3D1FBA8832F5EB2AA0E0D42A10B60F4A033C1B3838668287A4E88D6 | |||
| 3980 | kaspersky4win202121.16.6.467ru_45357.exe | C:\Users\admin\AppData\Local\Temp\FECC29B37E11FE11E963219A68C677ED\sharpvectorconverterswpf.dll | executable | |
MD5:CA5E6167B66C384F62E56FE0E1757AF3 | SHA256:A9EDC78BC8DD9E6AB098C96D2F26949BF8CC7C1F1071C5D96154022DAC685979 | |||
| 3980 | kaspersky4win202121.16.6.467ru_45357.exe | C:\Users\admin\AppData\Local\Temp\FECC29B37E11FE11E963219A68C677ED\sharpvectorcss.dll | executable | |
MD5:25E40483458B8083EB12D38B6CEAD136 | SHA256:1A87D710B34B187F75E9213C95AB5EB129DA63906F122035E7BADF7044C929C9 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3980 | kaspersky4win202121.16.6.467ru_45357.exe | GET | 200 | 80.231.123.135:80 | http://crl.kaspersky.com/aia/KasperskyLabPublicServicesRootCertificationAuthority.crt | unknown | — | — | unknown |
3980 | kaspersky4win202121.16.6.467ru_45357.exe | GET | 200 | 199.232.210.172:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?2f209f4c903930da | unknown | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | unknown |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 224.0.0.252:5355 | — | — | — | unknown |
3980 | kaspersky4win202121.16.6.467ru_45357.exe | 62.67.238.152:443 | ds.kaspersky.com | LEVEL3 | GB | unknown |
3980 | kaspersky4win202121.16.6.467ru_45357.exe | 80.231.123.135:80 | crl.kaspersky.com | AS6453 | FR | unknown |
3980 | kaspersky4win202121.16.6.467ru_45357.exe | 199.232.210.172:80 | ctldl.windowsupdate.com | FASTLY | US | unknown |
3980 | kaspersky4win202121.16.6.467ru_45357.exe | 130.117.190.147:443 | crl.kaspersky.com | COGENT-174 | DE | unknown |
524 | startup.exe | 62.67.238.152:443 | ds.kaspersky.com | LEVEL3 | GB | unknown |
524 | startup.exe | 130.117.190.147:443 | crl.kaspersky.com | COGENT-174 | DE | unknown |
2480 | startup.exe | 62.67.238.152:443 | ds.kaspersky.com | LEVEL3 | GB | unknown |
Domain | IP | Reputation |
|---|---|---|
ds.kaspersky.com |
| unknown |
crl.kaspersky.com |
| whitelisted |
ctldl.windowsupdate.com |
| whitelisted |
dm.s.kaspersky-labs.com |
| unknown |
Process | Message |
|---|---|
kaspersky4win202121.16.6.467ru_45357.exe | kaspersky4win202121.16.6.467ru_45357.exe Information: 0 : |
kaspersky4win202121.16.6.467ru_45357.exe | LocalizationEngine Making localization parameters
|
kaspersky4win202121.16.6.467ru_45357.exe | kaspersky4win202121.16.6.467ru_45357.exe Information: 0 : |
kaspersky4win202121.16.6.467ru_45357.exe | Core DisplayCulture = ru-RU
DisplayCulture.FullLocalization = ru-RU
FormatCulture = en-US
|
kaspersky4win202121.16.6.467ru_45357.exe | Interactivity Trigger[2232551] attached to MainWindow
|
kaspersky4win202121.16.6.467ru_45357.exe | Interactivity Trigger[56151142] attached to MainWindow
|
kaspersky4win202121.16.6.467ru_45357.exe | Interactivity Trigger[26065365] attached to MainWindow
|
kaspersky4win202121.16.6.467ru_45357.exe | kaspersky4win202121.16.6.467ru_45357.exe Information: 0 : |
kaspersky4win202121.16.6.467ru_45357.exe | kaspersky4win202121.16.6.467ru_45357.exe Information: 0 : |
kaspersky4win202121.16.6.467ru_45357.exe | Core OnApplicationStartup
|