File name:

Radmin upper starter.exe

Full analysis: https://app.any.run/tasks/69e104e0-c920-40d3-8e71-acfe2489f110
Verdict: Malicious activity
Threats:

Adware is a form of malware that targets users with unwanted advertisements, often disrupting their browsing experience. It typically infiltrates systems through software bundling, malicious websites, or deceptive downloads. Once installed, it may track user activity, collect sensitive data, and display intrusive ads, including pop-ups or banners. Some advanced adware variants can bypass security measures and establish persistence on devices, making removal challenging. Additionally, adware can create vulnerabilities that other malware can exploit, posing a significant risk to user privacy and system security.

Analysis date: May 07, 2026, 18:01:26
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
delphi
inno
installer
adware
innosetup
stealer
loader
arch-scr
opera
tool
arch-html
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 11 sections
MD5:

9A84A24E9826CBDEBB13F5DCC20607A1

SHA1:

02CE7F8FDC22C39CC2FEECC65030B793BF1B3CBF

SHA256:

548BCFC97A5468D47ADB062738674A8C93A8AF0CC49BCA735A3617F1C0AFE9CA

SSDEEP:

98304:kPXS+DPCqpT/nobF7L79C1bDS7DVlKVdniNxJAdA8vSsnWrdqwn/3vV7IPjDERWV:Ycxp+cYvq74xL1Cr70hrbuTHQb

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • INNOSETUP has been detected (SURICATA)

      • Radmin upper starter.tmp (PID: 7596)
    • Steals credentials from Web Browsers

      • seederexe.exe (PID: 4524)
      • browser.exe (PID: 4260)
      • opera.exe (PID: 4776)
    • Actions looks like stealing of personal data

      • seederexe.exe (PID: 4524)
      • browser.exe (PID: 4260)
      • browser.exe (PID: 8996)
    • Runs injected code in another process

      • 0f8d37f7a1e833cce17aec7f07cec5d6.exe (PID: 1108)
      • 0f8d37f7a1e833cce17aec7f07cec5d6.exe (PID: 4348)
      • 0f8d37f7a1e833cce17aec7f07cec5d6.exe (PID: 7408)
      • 0f8d37f7a1e833cce17aec7f07cec5d6.exe (PID: 7420)
      • 0f8d37f7a1e833cce17aec7f07cec5d6.exe (PID: 8100)
      • 0f8d37f7a1e833cce17aec7f07cec5d6.exe (PID: 8184)
    • Application was injected by another process

      • explorer.exe (PID: 4696)
    • Proxy execution via Explorer

      • Radmin upper starter.tmp (PID: 7596)
    • Changes the autorun value in the registry

      • assistant_installer.exe (PID: 4116)
      • opera.exe (PID: 4776)
      • browser.exe (PID: 4260)
    • Vulnerable driver has been detected

      • 360TS_Setup.exe (PID: 4524)
  • SUSPICIOUS

    • Reads the Windows owner or organization settings

      • Radmin upper starter.tmp (PID: 7596)
      • msiexec.exe (PID: 5708)
    • Executable content was dropped or overwritten

      • Radmin upper starter.exe (PID: 7096)
      • Radmin upper starter.tmp (PID: 7596)
      • 494a7424778584e0a7d350e7ffc3b82f.exe (PID: 6532)
      • 64ccc8d0b6144df4b3670dd9873febef.exe (PID: 7364)
      • Yandex.exe (PID: 6952)
      • 69594a5c0bbed8127c3c330dd2dab37d.exe (PID: 4260)
      • installer.exe (PID: 8036)
      • ybAB30.tmp (PID: 1456)
      • Opera_GX_assistant_131.0.5877.36_Setup.exe_sfx.exe (PID: 7688)
      • installer.exe (PID: 2340)
      • setup.exe (PID: 7160)
      • installer.exe (PID: 5852)
      • assistant_installer.exe (PID: 4116)
      • opera_autoupdate.exe (PID: 11232)
      • 360TS_Setup.exe (PID: 11932)
      • 360TS_Setup.exe (PID: 4524)
    • Silent install from TEMP directory

      • 5a7269deea1b7df16cf550f1b6efbb9d.exe (PID: 6112)
      • msiexec.exe (PID: 572)
    • Application launched itself

      • installer.exe (PID: 8036)
      • 494a7424778584e0a7d350e7ffc3b82f.exe (PID: 6532)
      • installer.exe (PID: 2340)
      • setup.exe (PID: 7160)
      • assistant_installer.exe (PID: 6924)
      • vplist.exe (PID: 7788)
      • explorer.exe (PID: 2936)
      • installer.exe (PID: 5852)
      • assistant_installer.exe (PID: 4116)
      • assistant_installer.exe (PID: 7392)
      • browser.exe (PID: 4260)
      • browser_assistant.exe (PID: 7936)
      • opera.exe (PID: 4776)
      • installer.exe (PID: 10412)
      • opera_autoupdate.exe (PID: 10288)
      • browser.exe (PID: 10648)
      • opera_autoupdate.exe (PID: 11232)
    • Access to an unwanted program domain was detected

      • Radmin upper starter.tmp (PID: 7596)
    • Starts a Microsoft application from unusual location

      • YandexPackSetup.exe (PID: 7836)
    • Starts itself from another location

      • installer.exe (PID: 8036)
      • Yandex.exe (PID: 6952)
      • setup.exe (PID: 7160)
      • assistant_installer.exe (PID: 4116)
      • 360TS_Setup.exe (PID: 11932)
    • Reads Mozilla Firefox installation path

      • seederexe.exe (PID: 4524)
      • browser.exe (PID: 4260)
      • opera.exe (PID: 4776)
    • Changes the title of the Internet Explorer window

      • seederexe.exe (PID: 4524)
    • Changes the Home page of Internet Explorer

      • seederexe.exe (PID: 4524)
    • Possible stealing from browsers

      • seederexe.exe (PID: 4524)
      • opera_crashreporter.exe (PID: 7596)
      • opera_crashreporter.exe (PID: 3552)
      • opera.exe (PID: 4776)
      • opera_crashreporter.exe (PID: 2724)
      • opera_crashreporter.exe (PID: 7424)
      • browser_assistant.exe (PID: 3104)
      • opera_crashreporter.exe (PID: 8432)
      • browser_assistant.exe (PID: 7936)
      • opera_crashreporter.exe (PID: 7424)
      • opera_crashreporter.exe (PID: 9948)
    • The process creates files with name similar to system file names

      • Yandex.exe (PID: 6952)
      • setup.exe (PID: 7160)
    • The process executes files with name similar to system file names

      • Yandex.exe (PID: 6952)
      • Radmin upper starter.tmp (PID: 7596)
      • setup.exe (PID: 7160)
      • explorer.exe (PID: 2936)
    • Drops 7-zip archiver for unpacking

      • Radmin upper starter.tmp (PID: 7596)
      • 360TS_Setup.exe (PID: 4524)
    • Starts application with an unusual extension

      • {53116BF1-7A1A-4A91-B77B-2E0971A0036C}.exe (PID: 4352)
    • Explorer used for Indirect Command Execution

      • explorer.exe (PID: 5584)
    • Searches for installed software

      • setup.exe (PID: 7160)
      • installer.exe (PID: 5852)
      • browser_assistant.exe (PID: 7936)
    • Reads the date of Windows installation

      • explorer.exe (PID: 2936)
      • installer.exe (PID: 5852)
      • opera.exe (PID: 4776)
    • The process executes JS scripts

      • wscript.exe (PID: 9332)
    • The process executes via Task Scheduler

      • opera_autoupdate.exe (PID: 11232)
    • The process verifies whether the antivirus software is installed

      • 360TS_Setup.exe (PID: 4524)
    • Drops a system driver (possible attempt to evade defenses)

      • 360TS_Setup.exe (PID: 4524)
    • Creates file in the systems drive root

      • 360TS_Setup.exe (PID: 4524)
  • INFO

    • Detects InnoSetup installer (YARA)

      • Radmin upper starter.tmp (PID: 7596)
      • Radmin upper starter.exe (PID: 7096)
    • Compiled with Borland Delphi (YARA)

      • Radmin upper starter.tmp (PID: 7596)
      • Radmin upper starter.exe (PID: 7096)
    • Reads Environment values

      • Radmin upper starter.exe (PID: 7096)
      • Radmin upper starter.tmp (PID: 7596)
      • identity_helper.exe (PID: 11172)
      • identity_helper.exe (PID: 7768)
      • identity_helper.exe (PID: 8868)
    • The sample compiled with russian language support

      • Radmin upper starter.tmp (PID: 7596)
      • msiexec.exe (PID: 572)
      • setup.exe (PID: 7160)
      • 360TS_Setup.exe (PID: 4524)
    • Create files in a temporary directory

      • Radmin upper starter.exe (PID: 7096)
      • 494a7424778584e0a7d350e7ffc3b82f.exe (PID: 6532)
      • Radmin upper starter.tmp (PID: 7596)
      • 5a7269deea1b7df16cf550f1b6efbb9d.exe (PID: 6112)
      • installer.exe (PID: 8036)
      • 494a7424778584e0a7d350e7ffc3b82f.exe (PID: 1108)
      • YandexPackSetup.exe (PID: 7836)
      • 64ccc8d0b6144df4b3670dd9873febef.exe (PID: 7364)
      • msiexec.exe (PID: 572)
      • seederexe.exe (PID: 4524)
      • lite_installer.exe (PID: 4784)
      • Yandex.exe (PID: 6952)
      • {53116BF1-7A1A-4A91-B77B-2E0971A0036C}.exe (PID: 4352)
      • sender.exe (PID: 3276)
      • ybAB30.tmp (PID: 1456)
      • setup.exe (PID: 7160)
      • Opera_GX_assistant_131.0.5877.36_Setup.exe_sfx.exe (PID: 7688)
      • installer.exe (PID: 5852)
      • browser.exe (PID: 4260)
      • browser.exe (PID: 8408)
      • opera.exe (PID: 4776)
      • opera_autoupdate.exe (PID: 11232)
      • 360TS_Setup.exe (PID: 11932)
      • 360TS_Setup.exe (PID: 4524)
    • Reads security settings of Internet Explorer

      • explorer.exe (PID: 4696)
      • Radmin upper starter.tmp (PID: 7596)
      • 494a7424778584e0a7d350e7ffc3b82f.exe (PID: 6532)
      • installer.exe (PID: 8036)
      • 64ccc8d0b6144df4b3670dd9873febef.exe (PID: 7364)
      • lite_installer.exe (PID: 4784)
      • Yandex.exe (PID: 6952)
      • {53116BF1-7A1A-4A91-B77B-2E0971A0036C}.exe (PID: 4352)
      • explorer.exe (PID: 3612)
      • setup.exe (PID: 7160)
      • explorer.exe (PID: 3424)
      • explorer.exe (PID: 2936)
      • installer.exe (PID: 5852)
      • browser_assistant.exe (PID: 7936)
      • browser.exe (PID: 4260)
      • 360TS_Setup.exe (PID: 4524)
    • Checks supported languages

      • Radmin upper starter.tmp (PID: 7596)
      • Radmin upper starter.exe (PID: 7096)
      • 494a7424778584e0a7d350e7ffc3b82f.exe (PID: 6532)
      • 5a7269deea1b7df16cf550f1b6efbb9d.exe (PID: 6112)
      • installer.exe (PID: 8036)
      • installer.exe (PID: 2268)
      • installer.exe (PID: 1400)
      • 494a7424778584e0a7d350e7ffc3b82f.exe (PID: 1108)
      • YandexPackSetup.exe (PID: 7836)
      • 64ccc8d0b6144df4b3670dd9873febef.exe (PID: 7364)
      • installer.exe (PID: 2340)
      • msiexec.exe (PID: 5708)
      • installer.exe (PID: 2364)
      • msiexec.exe (PID: 572)
      • seederexe.exe (PID: 4524)
      • lite_installer.exe (PID: 4784)
      • Yandex.exe (PID: 6952)
      • explorer.exe (PID: 3612)
      • {53116BF1-7A1A-4A91-B77B-2E0971A0036C}.exe (PID: 4352)
      • sender.exe (PID: 3276)
      • 69594a5c0bbed8127c3c330dd2dab37d.exe (PID: 4260)
      • ybAB30.tmp (PID: 1456)
      • 0f8d37f7a1e833cce17aec7f07cec5d6.exe (PID: 1108)
      • 0f8d37f7a1e833cce17aec7f07cec5d6.exe (PID: 8184)
      • 0f8d37f7a1e833cce17aec7f07cec5d6.exe (PID: 4348)
      • Opera_GX_assistant_131.0.5877.36_Setup.exe_sfx.exe (PID: 7688)
      • 0f8d37f7a1e833cce17aec7f07cec5d6.exe (PID: 7420)
      • setup.exe (PID: 7160)
      • setup.exe (PID: 1304)
      • 0f8d37f7a1e833cce17aec7f07cec5d6.exe (PID: 8100)
      • 0f8d37f7a1e833cce17aec7f07cec5d6.exe (PID: 7408)
      • assistant_installer.exe (PID: 6924)
      • assistant_installer.exe (PID: 7368)
      • vplist.exe (PID: 7788)
      • vplist.exe (PID: 4680)
      • vplist.exe (PID: 8184)
      • vplist.exe (PID: 3092)
      • vplist.exe (PID: 2396)
      • installer.exe (PID: 5852)
      • installer.exe (PID: 1528)
      • explorer.exe (PID: 7324)
      • explorer.exe (PID: 2936)
      • clidmgr.exe (PID: 3200)
      • clidmgr.exe (PID: 1140)
      • assistant_installer.exe (PID: 6804)
      • assistant_installer.exe (PID: 7392)
      • assistant_installer.exe (PID: 7352)
      • browser_assistant.exe (PID: 7936)
      • opera.exe (PID: 6504)
      • opera.exe (PID: 4776)
      • browser.exe (PID: 4260)
      • browser.exe (PID: 7816)
      • opera.exe (PID: 6896)
      • browser_assistant.exe (PID: 3104)
      • opera.exe (PID: 5412)
      • opera.exe (PID: 5648)
      • opera_crashreporter.exe (PID: 7596)
      • opera_crashreporter.exe (PID: 3552)
      • opera_crashreporter.exe (PID: 2724)
      • opera.exe (PID: 6424)
      • opera.exe (PID: 7800)
      • opera.exe (PID: 6084)
      • opera.exe (PID: 5116)
      • opera.exe (PID: 5824)
      • opera.exe (PID: 4272)
      • opera.exe (PID: 6392)
      • opera.exe (PID: 2396)
      • opera_crashreporter.exe (PID: 7424)
      • opera_gx_splash.exe (PID: 8368)
      • opera.exe (PID: 8384)
      • opera_crashreporter.exe (PID: 8432)
      • opera.exe (PID: 6896)
      • opera_crashreporter.exe (PID: 7424)
      • browser.exe (PID: 8968)
      • browser.exe (PID: 9072)
      • browser.exe (PID: 9144)
      • browser.exe (PID: 9132)
      • browser.exe (PID: 7424)
      • browser.exe (PID: 8408)
      • browser.exe (PID: 8976)
      • assistant_installer.exe (PID: 4116)
      • browser.exe (PID: 8996)
      • browser.exe (PID: 6536)
      • browser.exe (PID: 8500)
      • browser.exe (PID: 664)
      • browser_assistant.exe (PID: 1192)
      • browser.exe (PID: 5716)
      • browser.exe (PID: 9224)
      • opera.exe (PID: 9400)
      • opera.exe (PID: 9444)
      • opera.exe (PID: 9472)
      • opera.exe (PID: 9592)
      • opera.exe (PID: 9528)
      • opera.exe (PID: 9568)
      • opera.exe (PID: 9600)
      • opera.exe (PID: 9584)
      • opera.exe (PID: 9688)
      • opera.exe (PID: 9832)
      • opera.exe (PID: 9840)
      • opera.exe (PID: 10228)
      • opera_crashreporter.exe (PID: 9948)
      • opera.exe (PID: 10212)
      • opera.exe (PID: 10108)
      • opera.exe (PID: 10196)
      • opera.exe (PID: 10220)
      • opera.exe (PID: 9700)
      • opera.exe (PID: 10204)
      • opera.exe (PID: 8780)
      • opera.exe (PID: 8832)
      • opera.exe (PID: 8796)
      • opera.exe (PID: 8480)
      • browser.exe (PID: 9948)
      • opera.exe (PID: 10404)
      • opera.exe (PID: 10424)
      • opera.exe (PID: 10444)
      • opera.exe (PID: 10504)
      • opera.exe (PID: 684)
      • opera.exe (PID: 9324)
      • opera.exe (PID: 8740)
      • browser.exe (PID: 10676)
      • browser.exe (PID: 10728)
      • browser.exe (PID: 10684)
      • browser.exe (PID: 10724)
      • browser.exe (PID: 10696)
      • browser.exe (PID: 10760)
      • browser.exe (PID: 10720)
      • browser.exe (PID: 10704)
      • browser.exe (PID: 10752)
      • browser.exe (PID: 10768)
      • browser.exe (PID: 10744)
      • browser.exe (PID: 10776)
      • browser.exe (PID: 10792)
      • browser.exe (PID: 10868)
      • installer.exe (PID: 10412)
      • browser.exe (PID: 10784)
      • browser.exe (PID: 10712)
      • browser.exe (PID: 10812)
      • browser.exe (PID: 11248)
      • browser.exe (PID: 11256)
      • browser.exe (PID: 10840)
      • installer.exe (PID: 11092)
      • browser.exe (PID: 11240)
      • browser.exe (PID: 5412)
      • browser.exe (PID: 10736)
      • browser.exe (PID: 7608)
      • browser.exe (PID: 10648)
      • opera_autoupdate.exe (PID: 10288)
      • browser.exe (PID: 10700)
      • browser.exe (PID: 8516)
      • browser.exe (PID: 10132)
      • browser.exe (PID: 7320)
      • browser.exe (PID: 11088)
      • opera_autoupdate.exe (PID: 11312)
      • browser.exe (PID: 9960)
      • browser.exe (PID: 11636)
      • opera.exe (PID: 9328)
      • opera_autoupdate.exe (PID: 11232)
      • browser.exe (PID: 12032)
      • opera_autoupdate.exe (PID: 8040)
      • opera.exe (PID: 9748)
      • opera.exe (PID: 10224)
      • opera.exe (PID: 13068)
      • opera.exe (PID: 13276)
      • opera.exe (PID: 13128)
      • opera.exe (PID: 13296)
      • opera.exe (PID: 13304)
      • opera.exe (PID: 8256)
      • identity_helper.exe (PID: 11172)
      • opera.exe (PID: 10476)
      • opera.exe (PID: 12568)
      • browser.exe (PID: 7608)
      • opera.exe (PID: 10940)
      • opera.exe (PID: 13112)
      • opera.exe (PID: 13120)
      • opera.exe (PID: 11068)
      • browser.exe (PID: 12500)
      • installer.exe (PID: 12580)
      • browser.exe (PID: 9912)
      • browser.exe (PID: 13108)
      • identity_helper.exe (PID: 7768)
      • 360TS_Setup.exe (PID: 11932)
      • 360TS_Setup.exe (PID: 4524)
      • opera.exe (PID: 9020)
      • identity_helper.exe (PID: 8868)
      • opera.exe (PID: 12416)
      • opera.exe (PID: 12120)
    • Reads the computer name

      • Radmin upper starter.tmp (PID: 7596)
      • 494a7424778584e0a7d350e7ffc3b82f.exe (PID: 6532)
      • installer.exe (PID: 8036)
      • msiexec.exe (PID: 5708)
      • YandexPackSetup.exe (PID: 7836)
      • 64ccc8d0b6144df4b3670dd9873febef.exe (PID: 7364)
      • msiexec.exe (PID: 572)
      • lite_installer.exe (PID: 4784)
      • installer.exe (PID: 2340)
      • seederexe.exe (PID: 4524)
      • 494a7424778584e0a7d350e7ffc3b82f.exe (PID: 1108)
      • Yandex.exe (PID: 6952)
      • explorer.exe (PID: 3612)
      • {53116BF1-7A1A-4A91-B77B-2E0971A0036C}.exe (PID: 4352)
      • sender.exe (PID: 3276)
      • 69594a5c0bbed8127c3c330dd2dab37d.exe (PID: 4260)
      • ybAB30.tmp (PID: 1456)
      • setup.exe (PID: 7160)
      • vplist.exe (PID: 7788)
      • assistant_installer.exe (PID: 6924)
      • vplist.exe (PID: 2396)
      • vplist.exe (PID: 8184)
      • vplist.exe (PID: 3092)
      • installer.exe (PID: 5852)
      • explorer.exe (PID: 2936)
      • clidmgr.exe (PID: 3200)
      • assistant_installer.exe (PID: 4116)
      • clidmgr.exe (PID: 1140)
      • assistant_installer.exe (PID: 7392)
      • browser.exe (PID: 4260)
      • opera.exe (PID: 6504)
      • opera.exe (PID: 4776)
      • opera.exe (PID: 6896)
      • browser_assistant.exe (PID: 7936)
      • opera.exe (PID: 5412)
      • opera.exe (PID: 2396)
      • opera.exe (PID: 7800)
      • opera.exe (PID: 5648)
      • opera_gx_splash.exe (PID: 8368)
      • opera.exe (PID: 8384)
      • browser.exe (PID: 8968)
      • browser.exe (PID: 8996)
      • browser.exe (PID: 9144)
      • browser.exe (PID: 9132)
      • browser.exe (PID: 8408)
      • opera.exe (PID: 9832)
      • browser.exe (PID: 9948)
      • opera.exe (PID: 10108)
      • installer.exe (PID: 10412)
      • browser.exe (PID: 10840)
      • browser.exe (PID: 10648)
      • opera_autoupdate.exe (PID: 11312)
      • opera_autoupdate.exe (PID: 10288)
      • opera_autoupdate.exe (PID: 11232)
      • opera_autoupdate.exe (PID: 8040)
      • identity_helper.exe (PID: 11172)
      • browser.exe (PID: 13108)
      • identity_helper.exe (PID: 7768)
      • 360TS_Setup.exe (PID: 11932)
      • 360TS_Setup.exe (PID: 4524)
      • identity_helper.exe (PID: 8868)
      • opera.exe (PID: 12416)
    • Process checks computer location settings

      • Radmin upper starter.tmp (PID: 7596)
      • 494a7424778584e0a7d350e7ffc3b82f.exe (PID: 6532)
      • msiexec.exe (PID: 572)
      • Yandex.exe (PID: 6952)
      • explorer.exe (PID: 3612)
      • vplist.exe (PID: 4680)
      • explorer.exe (PID: 2936)
      • opera.exe (PID: 4776)
      • opera.exe (PID: 6392)
      • browser.exe (PID: 4260)
      • browser.exe (PID: 7424)
      • browser.exe (PID: 6536)
      • browser.exe (PID: 5716)
      • opera.exe (PID: 9400)
      • opera.exe (PID: 9444)
      • opera.exe (PID: 9472)
      • opera.exe (PID: 9528)
      • browser.exe (PID: 9224)
      • opera.exe (PID: 9700)
      • opera.exe (PID: 9688)
      • opera.exe (PID: 9840)
      • opera.exe (PID: 8480)
      • browser.exe (PID: 10132)
      • opera.exe (PID: 9748)
      • opera.exe (PID: 10224)
      • opera.exe (PID: 13304)
      • opera.exe (PID: 12568)
      • browser.exe (PID: 7608)
      • opera.exe (PID: 10940)
      • opera.exe (PID: 11068)
      • browser.exe (PID: 9912)
      • 64ccc8d0b6144df4b3670dd9873febef.exe (PID: 7364)
      • 360TS_Setup.exe (PID: 4524)
      • opera.exe (PID: 9020)
      • opera.exe (PID: 12120)
    • Reads the machine GUID from the registry

      • 494a7424778584e0a7d350e7ffc3b82f.exe (PID: 6532)
      • msiexec.exe (PID: 5708)
      • installer.exe (PID: 8036)
      • 64ccc8d0b6144df4b3670dd9873febef.exe (PID: 7364)
      • seederexe.exe (PID: 4524)
      • lite_installer.exe (PID: 4784)
      • {53116BF1-7A1A-4A91-B77B-2E0971A0036C}.exe (PID: 4352)
      • setup.exe (PID: 7160)
      • vplist.exe (PID: 8184)
      • explorer.exe (PID: 2936)
      • installer.exe (PID: 5852)
      • opera.exe (PID: 4776)
      • browser_assistant.exe (PID: 7936)
      • browser.exe (PID: 4260)
      • opera_autoupdate.exe (PID: 10288)
      • opera_autoupdate.exe (PID: 11312)
      • opera_autoupdate.exe (PID: 11232)
      • opera_autoupdate.exe (PID: 8040)
      • 360TS_Setup.exe (PID: 4524)
      • opera.exe (PID: 12416)
    • Creates files or folders in the user directory

      • 494a7424778584e0a7d350e7ffc3b82f.exe (PID: 6532)
      • installer.exe (PID: 2268)
      • installer.exe (PID: 8036)
      • msiexec.exe (PID: 572)
      • 64ccc8d0b6144df4b3670dd9873febef.exe (PID: 7364)
      • msiexec.exe (PID: 5708)
      • seederexe.exe (PID: 4524)
      • lite_installer.exe (PID: 4784)
      • Yandex.exe (PID: 6952)
      • explorer.exe (PID: 3612)
      • explorer.exe (PID: 4696)
      • {53116BF1-7A1A-4A91-B77B-2E0971A0036C}.exe (PID: 4352)
      • 69594a5c0bbed8127c3c330dd2dab37d.exe (PID: 4260)
      • Radmin upper starter.tmp (PID: 7596)
      • setup.exe (PID: 1304)
      • setup.exe (PID: 7160)
      • installer.exe (PID: 2340)
      • vplist.exe (PID: 7788)
      • vplist.exe (PID: 8184)
      • installer.exe (PID: 5852)
      • explorer.exe (PID: 2936)
      • assistant_installer.exe (PID: 4116)
      • opera.exe (PID: 4776)
      • browser.exe (PID: 4260)
      • browser.exe (PID: 8996)
      • opera.exe (PID: 2396)
      • browser.exe (PID: 10648)
      • browser.exe (PID: 9960)
      • opera_autoupdate.exe (PID: 11312)
      • opera_autoupdate.exe (PID: 10288)
      • browser_assistant.exe (PID: 7936)
      • opera_autoupdate.exe (PID: 11232)
      • 360TS_Setup.exe (PID: 4524)
      • opera.exe (PID: 12416)
    • The sample compiled with english language support

      • 494a7424778584e0a7d350e7ffc3b82f.exe (PID: 6532)
      • Radmin upper starter.tmp (PID: 7596)
      • 64ccc8d0b6144df4b3670dd9873febef.exe (PID: 7364)
      • 69594a5c0bbed8127c3c330dd2dab37d.exe (PID: 4260)
      • ybAB30.tmp (PID: 1456)
      • Opera_GX_assistant_131.0.5877.36_Setup.exe_sfx.exe (PID: 7688)
      • installer.exe (PID: 2340)
      • setup.exe (PID: 7160)
      • installer.exe (PID: 5852)
      • assistant_installer.exe (PID: 4116)
      • opera_autoupdate.exe (PID: 11232)
      • 360TS_Setup.exe (PID: 4524)
    • Disables trace logs

      • 64ccc8d0b6144df4b3670dd9873febef.exe (PID: 7364)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 5708)
      • msiexec.exe (PID: 572)
    • Manual execution by a user

      • {53116BF1-7A1A-4A91-B77B-2E0971A0036C}.exe (PID: 4352)
      • browser.exe (PID: 4260)
      • browser_assistant.exe (PID: 1192)
      • wscript.exe (PID: 9332)
      • opera.exe (PID: 9832)
      • browser.exe (PID: 10648)
      • msedge.exe (PID: 10848)
      • msedge.exe (PID: 11584)
      • msedge.exe (PID: 10788)
    • Creates a software uninstall entry

      • Yandex.exe (PID: 6952)
      • Radmin upper starter.tmp (PID: 7596)
      • setup.exe (PID: 7160)
      • installer.exe (PID: 5852)
    • There is functionality for taking screenshot (YARA)

      • installer.exe (PID: 8036)
      • installer.exe (PID: 2268)
      • installer.exe (PID: 2340)
      • installer.exe (PID: 2364)
    • Launching a file from a Registry key

      • assistant_installer.exe (PID: 4116)
      • opera.exe (PID: 4776)
      • browser.exe (PID: 4260)
    • Reads CPU info

      • opera.exe (PID: 4776)
      • browser.exe (PID: 4260)
    • OPERA mutex has been found

      • opera.exe (PID: 4776)
      • browser_assistant.exe (PID: 7936)
      • opera_autoupdate.exe (PID: 10288)
      • opera_autoupdate.exe (PID: 11232)
    • JScript runtime error (SCRIPT)

      • wscript.exe (PID: 9332)
    • Application launched itself

      • msedge.exe (PID: 10848)
      • msedge.exe (PID: 9640)
      • msedge.exe (PID: 7856)
    • The sample compiled with chinese language support

      • 360TS_Setup.exe (PID: 4524)
      • 360TS_Setup.exe (PID: 11932)
    • The sample compiled with turkish language support

      • 360TS_Setup.exe (PID: 4524)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (53.5)
.exe | InstallShield setup (21)
.exe | Win32 EXE PECompact compressed (generic) (20.2)
.exe | Win32 Executable (generic) (2.1)
.exe | Win16/32 Executable Delphi generic (1)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2025:09:23 05:03:52+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 2.25
CodeSize: 716800
InitializedDataSize: 231424
UninitializedDataSize: -
EntryPoint: 0xb0028
OSVersion: 6.1
ImageVersion: -
SubsystemVersion: 6.1
Subsystem: Windows GUI
FileVersionNumber: 1.3.2.5
ProductVersionNumber: 1.3.2.5
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: SuperVpns Setup
FileVersion: 1.3.2.5
LegalCopyright:
OriginalFileName:
ProductName: SuperVpns
ProductVersion: 1.3.2.5
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
409
Monitored processes
254
Malicious processes
15
Suspicious processes
18

Behavior graph

Click at the process to see the details
start radmin upper starter.exe #INNOSETUP radmin upper starter.tmp slui.exe 494a7424778584e0a7d350e7ffc3b82f.exe 5a7269deea1b7df16cf550f1b6efbb9d.exe no specs installer.exe installer.exe installer.exe no specs yandexpacksetup.exe 64ccc8d0b6144df4b3670dd9873febef.exe no specs 494a7424778584e0a7d350e7ffc3b82f.exe msiexec.exe 64ccc8d0b6144df4b3670dd9873febef.exe installer.exe msiexec.exe installer.exe lite_installer.exe seederexe.exe yandex.exe explorer.exe no specs {53116bf1-7a1a-4a91-b77b-2e0971a0036c}.exe sender.exe 69594a5c0bbed8127c3c330dd2dab37d.exe conhost.exe no specs ybab30.tmp 0f8d37f7a1e833cce17aec7f07cec5d6.exe no specs conhost.exe no specs 0f8d37f7a1e833cce17aec7f07cec5d6.exe no specs conhost.exe no specs 0f8d37f7a1e833cce17aec7f07cec5d6.exe no specs conhost.exe no specs 0f8d37f7a1e833cce17aec7f07cec5d6.exe no specs conhost.exe no specs 0f8d37f7a1e833cce17aec7f07cec5d6.exe no specs conhost.exe no specs setup.exe 0f8d37f7a1e833cce17aec7f07cec5d6.exe no specs conhost.exe no specs setup.exe no specs opera_gx_assistant_131.0.5877.36_setup.exe_sfx.exe assistant_installer.exe assistant_installer.exe explorer.exe no specs explorer.exe no specs vplist.exe no specs vplist.exe no specs vplist.exe vplist.exe vplist.exe no specs comppkgsrv.exe no specs installer.exe installer.exe explorer.exe no specs explorer.exe no specs clidmgr.exe conhost.exe no specs assistant_installer.exe clidmgr.exe assistant_installer.exe conhost.exe no specs assistant_installer.exe assistant_installer.exe browser_assistant.exe opera.exe no specs opera.exe browser.exe browser.exe no specs opera_crashreporter.exe opera_crashreporter.exe opera.exe no specs opera_crashreporter.exe browser_assistant.exe opera.exe no specs opera.exe no specs opera_crashreporter.exe opera.exe opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera_crashreporter.exe opera_gx_splash.exe no specs opera.exe no specs opera_crashreporter.exe unsecapp.exe no specs browser.exe no specs browser.exe no specs browser.exe browser.exe no specs browser.exe no specs browser.exe no specs browser.exe no specs browser.exe no specs browser.exe no specs browser.exe no specs browser.exe no specs browser_assistant.exe no specs browser.exe no specs browser.exe no specs wscript.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera_crashreporter.exe opera.exe no specs browser.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs browser.exe no specs opera.exe no specs installer.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs browser.exe no specs browser.exe no specs browser.exe no specs browser.exe no specs browser.exe no specs browser.exe no specs browser.exe no specs browser.exe no specs browser.exe no specs browser.exe no specs browser.exe no specs browser.exe no specs browser.exe no specs browser.exe no specs browser.exe no specs browser.exe no specs browser.exe no specs browser.exe no specs installer.exe opera_autoupdate.exe browser.exe no specs browser.exe no specs browser.exe no specs browser.exe no specs browser.exe no specs opera.exe no specs opera_autoupdate.exe browser.exe no specs browser.exe no specs msedge.exe browser.exe no specs browser.exe no specs browser.exe no specs browser.exe no specs browser.exe no specs opera_autoupdate.exe msedge.exe no specs browser.exe no specs msedge.exe no specs browser.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs opera.exe no specs opera_autoupdate.exe msedge.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs msedge.exe no specs opera.exe no specs msedge.exe no specs opera.exe no specs opera.exe no specs msedge.exe no specs opera.exe no specs identity_helper.exe no specs identity_helper.exe no specs opera.exe no specs opera.exe no specs msedge.exe no specs browser.exe no specs msedge.exe no specs opera.exe no specs opera.exe no specs installer.exe no specs browser.exe no specs browser.exe no specs browser.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs 360ts_setup.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs THREAT 360ts_setup.exe opera.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs opera.exe no specs msedge.exe no specs opera.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs explorer.exe

Process information

PID
CMD
Path
Indicators
Parent process
572C:\Windows\syswow64\MsiExec.exe -Embedding 2AB4EC7C58C7AF04587A1867080C1BF8C:\Windows\SysWOW64\msiexec.exe
msiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
572"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=asset_store.mojom.AssetStoreService --lang=en-US --service-sandbox-type=asset_store_service --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=5396,i,16277221965873848330,2482046548670969684,262144 --variations-seed-version --mojo-platform-channel-handle=5344 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
664"C:\Users\admin\AppData\Local\Yandex\YandexBrowser\Application\browser.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=ru --service-sandbox-type=service --user-id=fc3a9bf7-95c6-4851-b080-4da126828d18 --brand-id=yandex --partner-id=pseudoportal-ru --force-high-res-timeticks=disabled --process-name="Data Decoder Service" --metrics-shmem-handle=5512,i,456960185445453856,2680512523518288148,524288 --field-trial-handle=2296,i,8336610126682692322,12241379417081207169,262144 --enable-features=ShortcutNameWithAlice --variations-seed-version --pseudonymization-salt-handle=2316,i,15533988006593828163,16855270876582279897,4 --trace-process-track-uuid=3190708999430457380 --mojo-platform-channel-handle=5612 --brver=26.4.1.1026 /prefetch:8C:\Users\admin\AppData\Local\Yandex\YandexBrowser\Application\browser.exebrowser.exe
User:
admin
Company:
YANDEX LLC
Integrity Level:
LOW
Description:
Yandex with voice assistant Alice
Exit code:
0
Version:
26.4.1.1026
Modules
Images
c:\users\admin\appdata\local\yandex\yandexbrowser\application\browser.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\yandex\yandexbrowser\application\26.4.1.1026\browser_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\winmm.dll
c:\windows\system32\advapi32.dll
684"C:\Users\admin\AppData\Local\Programs\Opera GX\opera.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --enable-quic --no-pre-read-main-dll --force-high-res-timeticks=disabled --with-feature:address-bar-dropdown-unfiltered-full=off --with-feature:address-bar-intent=on --with-feature:ai-writing-mode-in-context-menu=on --with-feature:cashback-assistant=off --with-feature:certificate-transparency-enforcement=on --with-feature:cms-tracking-rules=on --with-feature:continue-filter=on --with-feature:domain-suggestions-competitors=on --with-feature:feature-remote-disable-updates-testing-flag=off --with-feature:feature-remote-updates-testing-flag=on --with-feature:fun-voice-messages=on --with-feature:gx-post-mortem=on --with-feature:gx-streamlabs-promo-text=on --with-feature:hide-navigations-from-extensions=on --with-feature:image-search-support=on --with-feature:installer-experiment-test=off --with-feature:installer-move-opera-exe=off --with-feature:installer-verify-ipc-client=off --with-feature:platform-software-h264-encoder-in-gpu=on --with-feature:realtime-impressions-reporting=on --with-feature:run-at-startup-default=on --with-feature:sd-suggestions-external=on --with-feature:session-restore-add-ebay-attributions=on --with-feature:session-restore-add-partners-attributions=on --with-feature:sitecheck-age=on --with-feature:tiktok-panel=on --with-feature:universal-skip-button=on --with-feature:vpn-pro-v4-support=on --ab-tests=GXCTest50-test:DNA-99214_GXCTest50 --metrics-shmem-handle=8288,i,7172144403501064552,9169294562377881462,524288 --field-trial-handle=1936,i,18253844420133592679,11574932614697622539,262144 --enable-features=CertificateTransparencyAskBeforeEnabling,MultiThreadedUiCompositor,NativeNotifications,PlatformSoftwareH264EncoderInGpu,SystemNotifications --disable-features=AutoPictureInPictureForVideoPlayback,AutoPictureInPictureVideoHeuristics,CapitalOneCashbackProtection,SkiaGraphite,SyncWorkspacesInSessions --variations-seed-version --pseudonymization-salt-handle=1940,i,8805148154076195906,3126835723025971229,4 --trace-process-track-uuid=3190709017234252511 --mojo-platform-channel-handle=8356 /prefetch:8C:\Users\admin\AppData\Local\Programs\Opera GX\opera.exeopera.exe
User:
admin
Company:
Opera Software
Integrity Level:
LOW
Description:
Opera GX Internet Browser
Exit code:
0
Version:
131.0.5877.36
Modules
Images
c:\users\admin\appdata\local\programs\opera gx\opera.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\programs\opera gx\131.0.5877.36\opera_elf.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\winmm.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shcore.dll
c:\windows\system32\combase.dll
1108C:\Users\admin\AppData\Local\Temp\is-DI7L3.tmp\494a7424778584e0a7d350e7ffc3b82f.exe --stat dwnldr/p=418804/cnt=0/dt=2/ct=1/rt=0 --dh 2400 --st 1778176932C:\Users\admin\AppData\Local\Temp\is-DI7L3.tmp\494a7424778584e0a7d350e7ffc3b82f.exe
494a7424778584e0a7d350e7ffc3b82f.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup Downloader
Exit code:
0
Version:
0.1.0.33
Modules
Images
c:\users\admin\appdata\local\temp\is-di7l3.tmp\494a7424778584e0a7d350e7ffc3b82f.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
1108"C:\Users\admin\AppData\Local\Temp\is-DI7L3.tmp\0f8d37f7a1e833cce17aec7f07cec5d6.exe" "C:\Users\admin\AppData\Local\Programs\SuperVpns\Яндекс.Игры.lnk" 5386C:\Users\admin\AppData\Local\Temp\is-DI7L3.tmp\0f8d37f7a1e833cce17aec7f07cec5d6.exeRadmin upper starter.tmp
User:
admin
Company:
Technosys Corporation
Integrity Level:
MEDIUM
Description:
Pin To Taskbar
Exit code:
0
Version:
0.99.9.1
Modules
Images
c:\users\admin\appdata\local\temp\is-di7l3.tmp\0f8d37f7a1e833cce17aec7f07cec5d6.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
1140"C:\Users\admin\AppData\Local\Yandex\YandexBrowser\Application\clidmgr.exe" --appid=yabrowser --vendor-xml-path="C:\Users\admin\AppData\Local\Yandex\YandexBrowser\Temp\source7160_1083786260\Browser-bin\clids_yandex_second.xml"C:\Users\admin\AppData\Local\Yandex\YandexBrowser\Application\clidmgr.exe
setup.exe
User:
admin
Company:
Yandex
Integrity Level:
MEDIUM
Description:
ClidManagerModule
Exit code:
0
Version:
1,0,0,44
Modules
Images
c:\users\admin\appdata\local\yandex\yandexbrowser\application\clidmgr.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
1192"C:\Users\admin\AppData\Local\Programs\Opera GX\assistant\browser_assistant.exe"C:\Users\admin\AppData\Local\Programs\Opera GX\assistant\browser_assistant.exeexplorer.exe
User:
admin
Company:
Opera Software
Integrity Level:
MEDIUM
Description:
Opera GX Browser Assistant
Exit code:
0
Version:
131.0.5877.36
Modules
Images
c:\users\admin\appdata\local\programs\opera gx\assistant\browser_assistant.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\advapi32.dll
c:\windows\syswow64\msvcrt.dll
1304C:\Users\admin\AppData\Local\Temp\YB_BF010.tmp\setup.exe --type=crashpad-handler /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Yandex\YandexBrowser\User Data\Crashpad" --url=https://crash-reports.browser.yandex.net/submit --annotation=machine_id= --annotation=main_process_pid=7160 --annotation=plat=Win64 --annotation=prod=Yandex --annotation=session_logout=False --annotation=ver=26.4.1.1026 --initial-client-data=0x2a4,0x2a8,0x2ac,0x224,0x2b0,0x7ff73659f970,0x7ff73659f97c,0x7ff73659f988C:\Users\admin\AppData\Local\Temp\YB_BF010.tmp\setup.exesetup.exe
User:
admin
Company:
YANDEX LLC
Integrity Level:
MEDIUM
Description:
Yandex
Exit code:
0
Version:
26.4.1.1026
Modules
Images
c:\users\admin\appdata\local\temp\yb_bf010.tmp\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
1400"C:\Users\admin\AppData\Local\Temp\.opera\b0ce1337-bbaf-4a88-909d-a164dbc6d0c6 Opera GX Installer Temp\installer.exe" --versionC:\Users\admin\AppData\Local\Temp\.opera\b0ce1337-bbaf-4a88-909d-a164dbc6d0c6 Opera GX Installer Temp\installer.exeinstaller.exe
User:
admin
Company:
Opera Software
Integrity Level:
MEDIUM
Description:
Opera GX Installer
Exit code:
0
Version:
131.0.5877.36
Modules
Images
c:\users\admin\appdata\local\temp\.opera\b0ce1337-bbaf-4a88-909d-a164dbc6d0c6 opera gx installer temp\installer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
Total events
139 574
Read events
137 187
Write events
2 247
Delete events
140

Modification events

(PID) Process:(4696) explorer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Security and Maintenance\Checks\{C8E6F269-B90A-4053-A3BE-499AFCEC98C4}.check.0
Operation:writeName:CheckSetting
Value:
23004100430042006C006F00620000000000000000000000010000000000000000000000
(PID) Process:(7596) Radmin upper starter.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
AC1D0000E7406B894BDEDC01
(PID) Process:(7596) Radmin upper starter.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:SessionHash
Value:
4A137229D28DA7B032CACA0ECBB700ABB77EFEBEFA77CBA067B0E072136A2D64
(PID) Process:(7596) Radmin upper starter.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:Sequence
Value:
1
(PID) Process:(4696) explorer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:000000000017028C
Operation:writeName:VirtualDesktop
Value:
100000003030445602603FA5B72DE44882A417B3949BF781
(PID) Process:(4696) explorer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FeatureUsage\AppLaunch
Operation:writeName:Microsoft.Windows.Explorer
Value:
68
(PID) Process:(4696) explorer.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
Operation:writeName:NodeSlots
Value:
02020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202
(PID) Process:(4696) explorer.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
Operation:writeName:MRUListEx
Value:
03000000040000000000000012000000110000000E000000100000000F0000000C0000000D0000000B000000050000000A000000090000000800000001000000070000000600000002000000FFFFFFFF
(PID) Process:(4696) explorer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar
Operation:writeName:Locked
Value:
1
(PID) Process:(4696) explorer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Ribbon
Operation:writeName:MinimizedStateTabletModeOff
Value:
0
Executable files
745
Suspicious files
2 877
Text files
1 960
Unknown types
290

Dropped files

PID
Process
Filename
Type
4696explorer.exeC:\Users\admin\AppData\Local\Microsoft\PenWorkspace\DiscoverCacheData.dattext
MD5:E49C56350AEDF784BFE00E444B879672
SHA256:A8BD235303668981563DFB5AAE338CB802817C4060E2C199B7C84901D57B7E1E
7836YandexPackSetup.exeC:\Users\admin\AppData\Local\Temp\{5B964E0E-B9A3-4276-9ED9-4D5A5720747A}\YandexSearch.msi
MD5:
SHA256:
5708msiexec.exeC:\Windows\Installer\e99ab.msi
MD5:
SHA256:
6532494a7424778584e0a7d350e7ffc3b82f.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\9CB4373A4252DE8D2212929836304EC5_1AB74AA2E3A56E1B8AD8D3FEC287554Ebinary
MD5:4119DA37B2956780D74AE848CAA98681
SHA256:B6D0873B7E3BA9A0E2A8ABFD258001398B4430FD9D5358E5D966B70EA7FEB742
7096Radmin upper starter.exeC:\Users\admin\AppData\Local\Temp\is-9UMF1.tmp\Radmin upper starter.tmpexecutable
MD5:6D9CAF53A070CEBC13CD566EE3E90917
SHA256:F89BF805CB24892FBEC41B7C1EAB8C5A03E620EC2DF8436CC2E92FD4E5269EB4
6532494a7424778584e0a7d350e7ffc3b82f.exeC:\Users\admin\AppData\Local\Temp\7F4987FB1A6E43d69E3E94B29EB75926\seed.txttext
MD5:0283ED0EEE6998607137643223C4E475
SHA256:E73F672CE0B6D8401D0E6C3AFB9E34FE9CF9276816170B5709020E973F681DB4
6532494a7424778584e0a7d350e7ffc3b82f.exeC:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\KCV3KQBA\YandexPackSetup[1].exebinary
MD5:3FB846D3691F3D98A34E669E1B9B5BF6
SHA256:EAD7A779CABAE642D09BE07283CC99E53C84ECF90349444E0D0AC4BF9901FE47
7596Radmin upper starter.tmpC:\Users\admin\AppData\Local\Temp\is-DI7L3.tmp\494a7424778584e0a7d350e7ffc3b82f.exeexecutable
MD5:B9314504E592D42CB36534415A62B3AF
SHA256:C60C3A7D20B575FDEEB723E12A11C2602E73329DC413FC6D88F72E6F87E38B49
7596Radmin upper starter.tmpC:\Users\admin\AppData\Local\Temp\is-DI7L3.tmp\is-TSBSD.tmpexecutable
MD5:B9314504E592D42CB36534415A62B3AF
SHA256:C60C3A7D20B575FDEEB723E12A11C2602E73329DC413FC6D88F72E6F87E38B49
7596Radmin upper starter.tmpC:\Users\admin\AppData\Local\Temp\is-DI7L3.tmp\5a7269deea1b7df16cf550f1b6efbb9d.exeexecutable
MD5:9881926EC7E3C950E6B2E455E5BAF5F8
SHA256:E7B005B92E6C7DFB09FF9052649379D4CA7F31B1D75990BA18C4480FB3C6AD6D
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
604
TCP/UDP connections
395
DNS requests
366
Threats
13

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5276
MoUsoCoreWorker.exe
GET
304
4.231.128.59:443
https://settings-win.data.microsoft.com/settings/v3.0/wsd/muse?ProcessorClockSpeed=3094&FlightIds=&UpdateOfferedDays=4294967295&BranchReadinessLevel=CB&OEMManufacturerName=DELL&IsCloudDomainJoined=0&ProcessorIdentifier=AMD64%20Family%2023%20Model%201%20Stepping%202&sku=48&ActivationChannel=Retail&AttrDataVer=186&IsMDMEnrolled=0&ProcessorCores=6&ProcessorModel=AMD%20Ryzen%205%203500%206-Core%20Processor&TotalPhysicalRAM=6144&PrimaryDiskType=4294967295&FlightingBranchName=&ChassisTypeId=1&OEMModelNumber=DELL&SystemVolumeTotalCapacity=260281&sampleId=95271487&deviceClass=Windows.Desktop&App=muse&DisableDualScan=0&AppVer=10.0&OEMSubModel=J5CR&locale=en-US&IsAlwaysOnAlwaysConnectedCapable=0&ms=0&DefaultUserRegion=244&UpdateServiceUrl=http%3A%2F%2Fneverupdatewindows10.com&osVer=10.0.19045.4046.amd64fre.vb_release.191206-1406&os=windows&deviceId=s%3ABAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&DeferQualityUpdatePeriodInDays=0&ring=Retail&DeferFeatureUpdatePeriodInDays=30
US
whitelisted
6924
SIHClient.exe
GET
304
74.178.240.61:443
https://slscr.update.microsoft.com/SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.4046/0?CH=686&L=en-US&P=&PT=0x30&WUA=10.0.19041.3996&MK=DELL&MD=DELL
US
whitelisted
GET
200
204.79.197.203:80
http://oneocsp.microsoft.com/ocsp/MFQwUjBQME4wTDAJBgUrDgMCGgUABBQ3L3%2F%2Fa6ADK8NraY2GXzVaYrHG4AQUb6t%2B2v%2BXQ3LsO2d33oJhNYhHQoUCEzMAAAAGb6JMMcOVb6sAAAAAAAY%3D
US
binary
923 b
whitelisted
5316
svchost.exe
POST
400
40.126.31.73:443
https://login.live.com/ppsecure/deviceaddcredential.srf
US
text
204 b
whitelisted
6924
SIHClient.exe
GET
200
135.232.92.97:443
https://fe3cr.delivery.mp.microsoft.com/clientwebservice/ping
US
whitelisted
6924
SIHClient.exe
GET
200
74.178.240.61:443
https://slscr.update.microsoft.com/sls/ping
US
whitelisted
6924
SIHClient.exe
GET
304
74.178.240.61:443
https://slscr.update.microsoft.com/SLS/%7BE7A50285-D08D-499D-9FF8-180FDC2332BC%7D/x64/10.0.19045.4046/0?CH=686&L=en-US&P=&PT=0x30&WUA=10.0.19041.3996&MK=DELL&MD=DELL
US
whitelisted
7596
Radmin upper starter.tmp
GET
302
37.9.64.225:443
https://download.yandex.ru/yandex-pack/downloader/downloader.exe
RS
unknown
5316
svchost.exe
GET
200
23.11.40.157:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAz1vQYrVgL0erhQLCPM8GY%3D
NL
binary
471 b
whitelisted
5316
svchost.exe
POST
400
40.126.31.73:443
https://login.live.com/ppsecure/deviceaddcredential.srf
US
text
204 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
Not routed
whitelisted
4212
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
5276
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
7352
slui.exe
48.192.1.65:443
activation-v2.sls.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
5532
SearchApp.exe
2.16.241.201:443
www.bing.com
AKAMAI-ASN1
NL
whitelisted
23.11.40.157:80
ocsp.digicert.com
AKAMAI-AMS
NL
whitelisted
204.79.197.203:80
oneocsp.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:138
Not routed
whitelisted
5316
svchost.exe
40.126.31.73:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
5316
svchost.exe
23.11.40.157:80
ocsp.digicert.com
AKAMAI-AMS
NL
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 4.231.128.59
whitelisted
activation-v2.sls.microsoft.com
  • 48.192.1.65
  • 48.192.1.64
whitelisted
www.bing.com
  • 2.16.241.201
  • 2.16.241.205
  • 2.16.241.225
  • 2.16.241.218
  • 2.16.241.222
  • 2.16.241.204
  • 2.16.241.219
  • 2.16.241.206
  • 2.16.241.207
  • 92.123.104.62
  • 92.123.104.4
  • 92.123.104.52
  • 92.123.104.67
  • 92.123.104.58
  • 92.123.104.63
  • 92.123.104.59
  • 92.123.104.66
  • 92.123.104.60
whitelisted
ocsp.digicert.com
  • 23.11.40.157
  • 23.11.32.159
whitelisted
oneocsp.microsoft.com
  • 204.79.197.203
whitelisted
google.com
  • 192.178.183.100
  • 192.178.183.139
  • 192.178.183.101
  • 192.178.183.102
  • 192.178.183.138
  • 192.178.183.113
whitelisted
login.live.com
  • 40.126.31.73
  • 20.190.159.131
  • 20.190.159.0
  • 40.126.31.67
  • 20.190.159.130
  • 40.126.31.69
  • 20.190.159.4
  • 20.190.159.75
whitelisted
client.wns.windows.com
  • 172.211.123.248
  • 172.211.123.249
whitelisted
crl.microsoft.com
  • 2.16.164.128
  • 2.16.164.9
  • 2.16.164.120
  • 2.16.164.25
  • 2.16.164.34
  • 2.16.164.115
  • 2.16.164.10
  • 2.16.164.122
  • 2.16.164.33
  • 2.16.164.51
  • 2.16.164.32
  • 2.16.164.99
  • 2.16.164.49
  • 2.16.164.106
  • 2.16.164.114
  • 2.16.164.107
  • 2.16.164.40
whitelisted
www.microsoft.com
  • 23.52.181.212
whitelisted

Threats

PID
Process
Class
Message
5276
MoUsoCoreWorker.exe
Unknown Traffic
ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW)
7596
Radmin upper starter.tmp
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] InnoSetup Installer
7596
Radmin upper starter.tmp
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] InnoSetup Installer
7596
Radmin upper starter.tmp
Misc activity
ET INFO Packed Executable Download
6532
494a7424778584e0a7d350e7ffc3b82f.exe
Misc activity
ET INFO Packed Executable Download
4784
lite_installer.exe
Misc activity
ET INFO EXE - Served Attached HTTP
7596
Radmin upper starter.tmp
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] InnoSetup Installer
7596
Radmin upper starter.tmp
Misc activity
ET INFO EXE - Served Attached HTTP
7596
Radmin upper starter.tmp
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] InnoSetup Installer
7596
Radmin upper starter.tmp
Misc activity
ET INFO Packed Executable Download
Process
Message
installer.exe
RecursiveDirectoryCreate( C:\Users\admin\AppData\Roaming\Opera Software\Opera GX Stable directory exists )
YandexPackSetup.exe
IsAlreadyRun() In
YandexPackSetup.exe
IsMSISrvFree() Out ret = 1
YandexPackSetup.exe
IsMSISrvFree() In
YandexPackSetup.exe
IsAlreadyRun() Out : ret (BOOL) = 0
YandexPackSetup.exe
IsMSISrvFree() : OpenMutex() err ret = 2
YandexPackSetup.exe
GetSidFromEnumSess(): LsaGetLogonSessionData(0) err = 5
YandexPackSetup.exe
GetSidFromEnumSess(): i = 6 : szUserName = admin, szDomain = DESKTOP-JGLLJLD, dwSessionId = 0
YandexPackSetup.exe
GetLoggedCreds_WTSSessionInfo(): szUserName = admin, szDomain = DESKTOP-JGLLJLD, dwSessionId = 1
YandexPackSetup.exe
GetSidFromEnumSess(): i = 4 : szUserName = admin, szDomain = DESKTOP-JGLLJLD, dwSessionId = 0