File name:

setup (1).exe

Full analysis: https://app.any.run/tasks/04b189ca-cd57-443e-9df6-b25f286274a5
Verdict: Malicious activity
Threats:

Metamorfo is a trojan malware family that has been active since 2018. It remains a top threat, focusing on stealing victims’ financial information, including banking credentials and other data. The malware is known for targeting users in Brazil.

Analysis date: February 17, 2024, 19:25:29
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
metamorfo
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

930837FFA4B1DAA25CE89D78493B4824

SHA1:

40817A39CA1DE11CA3B76B135F738EF1818E6C0B

SHA256:

4DF278D7ACC5EF83C08CDD3D30AE93EEBFE996C75A58852DBDE93A25923A1DEF

SSDEEP:

98304:SN/g/U8pLl22orGmUlsBI83eBqwSmiWC+Vt7OO3/KlEGpCI783bT6x7ddz0piWJe:21TZVBe

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • setup (1).exe (PID: 3668)
      • setup (1).tmp (PID: 2752)
      • setup (1).exe (PID: 2964)
      • ZAM.exe (PID: 1888)
    • Creates a writable file in the system directory

      • ZAM.exe (PID: 1888)
      • ZAM.exe (PID: 3308)
    • Changes the autorun value in the registry

      • ZAM.exe (PID: 1888)
    • Registers / Runs the DLL via REGSVR32.EXE

      • ZAM.exe (PID: 1888)
    • METAMORFO has been detected (YARA)

      • ZAM.exe (PID: 1888)
      • ZAM.exe (PID: 3308)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • setup (1).exe (PID: 3668)
      • ZAM.exe (PID: 1888)
      • setup (1).tmp (PID: 2752)
      • setup (1).exe (PID: 2964)
    • Checks Windows Trust Settings

      • ZAM.exe (PID: 1888)
    • Reads settings of System Certificates

      • ZAM.exe (PID: 1888)
    • Reads security settings of Internet Explorer

      • ZAM.exe (PID: 1888)
    • Creates files in the driver directory

      • ZAM.exe (PID: 1888)
    • Executes as Windows Service

      • ZAM.exe (PID: 3308)
    • Drops a system driver (possible attempt to evade defenses)

      • ZAM.exe (PID: 1888)
    • Reads the Internet Settings

      • ZAM.exe (PID: 1888)
    • Creates/Modifies COM task schedule object

      • regsvr32.exe (PID: 1236)
    • Reads the Windows owner or organization settings

      • setup (1).tmp (PID: 2752)
    • Process drops legitimate windows executable

      • setup (1).tmp (PID: 2752)
  • INFO

    • Checks supported languages

      • setup (1).tmp (PID: 3864)
      • setup (1).exe (PID: 3668)
      • ZAM.exe (PID: 3460)
      • setup (1).exe (PID: 2964)
      • ZAM.exe (PID: 4060)
      • ZAM.exe (PID: 1836)
      • ZAM.exe (PID: 2572)
      • ZAM.exe (PID: 3996)
      • ZAM.exe (PID: 3488)
      • ZAM.exe (PID: 1740)
      • ZAM.exe (PID: 1888)
      • ZAM.exe (PID: 3308)
      • setup (1).tmp (PID: 2752)
    • Create files in a temporary directory

      • setup (1).tmp (PID: 2752)
      • setup (1).exe (PID: 3668)
      • setup (1).exe (PID: 2964)
    • Reads the computer name

      • ZAM.exe (PID: 4060)
      • setup (1).tmp (PID: 3864)
      • ZAM.exe (PID: 1836)
      • ZAM.exe (PID: 2572)
      • ZAM.exe (PID: 3996)
      • setup (1).tmp (PID: 2752)
      • ZAM.exe (PID: 3488)
      • ZAM.exe (PID: 1740)
      • ZAM.exe (PID: 1888)
      • ZAM.exe (PID: 3308)
      • ZAM.exe (PID: 3460)
    • Creates files or folders in the user directory

      • ZAM.exe (PID: 3460)
      • ZAM.exe (PID: 4060)
      • ZAM.exe (PID: 1836)
      • ZAM.exe (PID: 2572)
      • ZAM.exe (PID: 3996)
      • ZAM.exe (PID: 3488)
      • ZAM.exe (PID: 1740)
      • ZAM.exe (PID: 1888)
    • Creates files in the program directory

      • setup (1).tmp (PID: 2752)
      • ZAM.exe (PID: 1888)
    • Creates a software uninstall entry

      • setup (1).tmp (PID: 2752)
    • Reads the software policy settings

      • ZAM.exe (PID: 1888)
    • Reads the machine GUID from the registry

      • ZAM.exe (PID: 1888)
    • Reads CPU info

      • ZAM.exe (PID: 1888)
    • Checks proxy server information

      • ZAM.exe (PID: 1888)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable Delphi generic (45.2)
.dll | Win32 Dynamic Link Library (generic) (20.9)
.exe | Win32 Executable (generic) (14.3)
.exe | Win16/32 Executable Delphi generic (6.6)
.exe | Generic Win/DOS Executable (6.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2015:07:16 13:24:20+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 65024
InitializedDataSize: 53248
UninitializedDataSize: -
EntryPoint: 0x113bc
OSVersion: 5
ImageVersion: 6
SubsystemVersion: 5
Subsystem: Windows GUI
FileVersionNumber: 2.70.234.0
ProductVersionNumber: 2.70.234.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: Advanced Malware Protection
FileVersion: 2.70.234
LegalCopyright: © Copyright 2015
ProductName: Advanced Malware Protection
ProductVersion: 2.70.234
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
53
Monitored processes
14
Malicious processes
6
Suspicious processes
0

Behavior graph

Click at the process to see the details
start setup (1).exe setup (1).tmp no specs setup (1).exe setup (1).tmp zam.exe no specs zam.exe no specs zam.exe no specs zam.exe no specs zam.exe no specs zam.exe no specs zam.exe no specs #METAMORFO zam.exe #METAMORFO zam.exe no specs regsvr32.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1236C:\Windows\System32\regsvr32.exe /s "C:\Program Files\MalwareFox AntiMalware\ZAMShellExt32.dll"C:\Windows\System32\regsvr32.exeZAM.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1740"C:\Users\admin\AppData\Local\Temp\is-F6UFC.tmp\ZAM.exe" /process_partner_cert "C:\Program Files\MalwareFox AntiMalware\ZAM.exe|C:\Program Files\MalwareFox AntiMalware\res\mf.PKCS7"C:\Users\admin\AppData\Local\Temp\is-F6UFC.tmp\ZAM.exesetup (1).tmp
User:
admin
Company:
Zemana Ltd.
Integrity Level:
HIGH
Description:
ZAM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\is-f6ufc.tmp\zam.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\fltlib.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\rpcrt4.dll
1836"C:\Users\admin\AppData\Local\Temp\is-F6UFC.tmp\ZAM.exe" /is_safeonline_installedC:\Users\admin\AppData\Local\Temp\is-F6UFC.tmp\ZAM.exesetup (1).tmp
User:
admin
Company:
Zemana Ltd.
Integrity Level:
HIGH
Description:
ZAM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\is-f6ufc.tmp\zam.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\fltlib.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\rpcrt4.dll
1888"C:\Program Files\MalwareFox AntiMalware\ZAM.exe" /install /realtime_protection 1 /set_lang "English"C:\Program Files\MalwareFox AntiMalware\ZAM.exe
setup (1).tmp
User:
admin
Company:
Zemana Ltd.
Integrity Level:
HIGH
Description:
ZAM
Exit code:
0
Modules
Images
c:\program files\malwarefox antimalware\zam.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\fltlib.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\rpcrt4.dll
2572"C:\Users\admin\AppData\Local\Temp\is-F6UFC.tmp\ZAM.exe" /is_newer_version_installedC:\Users\admin\AppData\Local\Temp\is-F6UFC.tmp\ZAM.exesetup (1).tmp
User:
admin
Company:
Zemana Ltd.
Integrity Level:
HIGH
Description:
ZAM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\is-f6ufc.tmp\zam.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\fltlib.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\rpcrt4.dll
2752"C:\Users\admin\AppData\Local\Temp\is-39DN7.tmp\setup (1).tmp" /SL5="$100130,4909108,119296,C:\Users\admin\AppData\Local\Temp\setup (1).exe" /SPAWNWND=$17013E /NOTIFYWND=$E0170 C:\Users\admin\AppData\Local\Temp\is-39DN7.tmp\setup (1).tmp
setup (1).exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-39dn7.tmp\setup (1).tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2964"C:\Users\admin\AppData\Local\Temp\setup (1).exe" /SPAWNWND=$17013E /NOTIFYWND=$E0170 C:\Users\admin\AppData\Local\Temp\setup (1).exe
setup (1).tmp
User:
admin
Company:
Integrity Level:
HIGH
Description:
Advanced Malware Protection
Exit code:
0
Version:
2.70.234
Modules
Images
c:\users\admin\appdata\local\temp\setup (1).exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
3308"C:\Program Files\MalwareFox AntiMalware\ZAM.exe" /serviceC:\Program Files\MalwareFox AntiMalware\ZAM.exe
services.exe
User:
SYSTEM
Company:
Zemana Ltd.
Integrity Level:
SYSTEM
Description:
ZAM
Exit code:
0
Modules
Images
c:\program files\malwarefox antimalware\zam.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\fltlib.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\rpcrt4.dll
3460"C:\Users\admin\AppData\Local\Temp\is-F6UFC.tmp\ZAM.exe" /get_and_set_installer_partner_idC:\Users\admin\AppData\Local\Temp\is-F6UFC.tmp\ZAM.exesetup (1).tmp
User:
admin
Company:
Zemana Ltd.
Integrity Level:
HIGH
Description:
ZAM
Exit code:
206
Modules
Images
c:\users\admin\appdata\local\temp\is-f6ufc.tmp\zam.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\fltlib.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\rpcrt4.dll
3488"C:\Users\admin\AppData\Local\Temp\is-F6UFC.tmp\ZAM.exe" /killallC:\Users\admin\AppData\Local\Temp\is-F6UFC.tmp\ZAM.exesetup (1).tmp
User:
admin
Company:
Zemana Ltd.
Integrity Level:
HIGH
Description:
ZAM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\is-f6ufc.tmp\zam.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\fltlib.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\rpcrt4.dll
Total events
10 941
Read events
10 856
Write events
68
Delete events
17

Modification events

(PID) Process:(2752) setup (1).tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
C00A0000F08CD916D761DA01
(PID) Process:(2752) setup (1).tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:SessionHash
Value:
4A0CC473949B1CCB23FA371AF1F68BED4EB814C675D656745AB4A0178BC75ABA
(PID) Process:(2752) setup (1).tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Sequence
Value:
1
(PID) Process:(3460) ZAM.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion
Operation:writeName:CUID
Value:
122F47044D0197891995B5
(PID) Process:(3460) ZAM.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\ZmnGlobalSDK
Operation:writeName:CUID
Value:
122F47044D0197891995B5
(PID) Process:(3460) ZAM.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Zemana\AntiMalware
Operation:writeName:Premium
Value:
1
(PID) Process:(3460) ZAM.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\ZmnGlobalSDK
Operation:writeName:PermanentPartnerID
Value:
206
(PID) Process:(3460) ZAM.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\ZmnGlobalSDK
Operation:writeName:ZAMPartnerID
Value:
206
(PID) Process:(3460) ZAM.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\ZmnGlobalSDK
Operation:writeName:ZAMSubPartnerID
Value:
0
(PID) Process:(2752) setup (1).tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:RegFiles0000
Value:
C:\Program Files\MalwareFox AntiMalware\ZAM.exe
Executable files
11
Suspicious files
7
Text files
65
Unknown types
0

Dropped files

PID
Process
Filename
Type
2752setup (1).tmpC:\Users\admin\AppData\Local\Temp\is-F6UFC.tmp\_isetup\_shfoldr.dllexecutable
MD5:92DC6EF532FBB4A5C3201469A5B5EB63
SHA256:9884E9D1B4F8A873CCBD81F8AD0AE257776D2348D027D811A56475E028360D87
3668setup (1).exeC:\Users\admin\AppData\Local\Temp\is-2K5RQ.tmp\setup (1).tmpexecutable
MD5:8FF319D4A557B8C486EB4F0B642BDF5E
SHA256:883215FF90EDAF9497E2749BFA5FE431C1CBE66706BEB088AE6EF24705F7A52E
3460ZAM.exeC:\Users\admin\AppData\Local\Zemana\Tracer\ZAM.tracetext
MD5:C10ED6A4B868A140372DBDD0E777A694
SHA256:5CF5080775FED31F6570D2B5D6F355DFB3A412BF6BC37F9C40DED678800E9498
2752setup (1).tmpC:\Users\admin\AppData\Local\Temp\is-F6UFC.tmp\ZAM.exeexecutable
MD5:4474680EA04172B834F421C2AA4C2429
SHA256:7A26891DAAE5642D681310C70C97953C3E3CAB328233BB4819D76A39E67F6B32
2572ZAM.exeC:\Users\admin\AppData\Local\Zemana\Tracer\ZAM.tracetext
MD5:61112B8658257D00C269E7B10741475B
SHA256:25F598DD219F1698939CA7B63ACACB94FA74D63011302D2E56B28A9A169CD9C6
4060ZAM.exeC:\Users\admin\AppData\Local\Zemana\Tracer\ZAM.tracetext
MD5:9F43582423C73C19EA281DF03B863F7F
SHA256:2D019F9A83367E171F89B58BD0600B2BDD603B4E02CC0B01925B1279F9A0795E
1836ZAM.exeC:\Users\admin\AppData\Local\Zemana\Tracer\ZAM.tracetext
MD5:C01F6986EAA9EBCDBE89370302A60AF7
SHA256:E9BC064D68C98584D234697920A38B91D41F263C03F36A814BA7CA3A33A10E46
2964setup (1).exeC:\Users\admin\AppData\Local\Temp\is-39DN7.tmp\setup (1).tmpexecutable
MD5:8FF319D4A557B8C486EB4F0B642BDF5E
SHA256:883215FF90EDAF9497E2749BFA5FE431C1CBE66706BEB088AE6EF24705F7A52E
2752setup (1).tmpC:\Program Files\MalwareFox AntiMalware\res\is-SAH7K.tmpimage
MD5:8E4CE605CBF4633C82C7CBA4055D39AF
SHA256:2B237EFA1BA7259F656F5C737D86F0ED164287936225C51160BFD657EA873C63
2752setup (1).tmpC:\Program Files\MalwareFox AntiMalware\is-VVRKJ.tmpexecutable
MD5:4474680EA04172B834F421C2AA4C2429
SHA256:7A26891DAAE5642D681310C70C97953C3E3CAB328233BB4819D76A39E67F6B32
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
13
DNS requests
4
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1888
ZAM.exe
POST
200
208.109.191.195:80
http://zamcloud.zemana.com/api/client/settings/122F47044D0197891995B5/2/206/2070234/
unknown
text
1.41 Kb
unknown
1888
ZAM.exe
POST
200
208.109.191.195:80
http://zamcloud.zemana.com/api/ig2/check/2074664/
unknown
text
207 b
unknown
1888
ZAM.exe
POST
301
208.109.191.195:80
http://zamcloud.zemana.com/api/ig2/check/2074664
unknown
html
178 b
unknown
1888
ZAM.exe
POST
301
208.109.191.195:80
http://zamcloud.zemana.com/api/client/settings/122F47044D0197891995B5/2/206/2070234
unknown
html
178 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
1888
ZAM.exe
45.79.153.218:80
cdn9.zemana.com
Linode, LLC
US
unknown
1888
ZAM.exe
208.109.191.195:80
zamcloud.zemana.com
GO-DADDY-COM-LLC
US
unknown
1888
ZAM.exe
45.79.154.56:80
cdn.go.zemana.com
Linode, LLC
US
unknown

DNS requests

Domain
IP
Reputation
cdn9.zemana.com
  • 45.79.153.218
whitelisted
zamcloud.zemana.com
  • 208.109.191.195
whitelisted
dl12.zemana.com
  • 45.79.153.218
whitelisted
cdn.go.zemana.com
  • 45.79.154.56
whitelisted

Threats

No threats detected
No debug info