File name:

TeamsSetup.exe

Full analysis: https://app.any.run/tasks/392d47bd-bfc2-416d-9121-8946ff09eaef
Verdict: Malicious activity
Analysis date: February 06, 2024, 20:46:42
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

D28A4095CF0851F16C2A90F2DD73C782

SHA1:

A2A2448BDD20065F442D7C0BBB305E88B5EE75E4

SHA256:

552BB7B692037B738954341444377F1F13759BB49213FBEB42B91B7F632CC409

SSDEEP:

49152:9ZhIlVmOquOk1XkmdqdFSlqZlssh7TOmZqv03XhpLC8CEqLcKQmhbXPlAECbw9c7:9ZhIlGozYFSlqZlsshfOm4vGhpg997Ax

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • TeamsSetup.exe (PID: 1380)
      • Update.exe (PID: 1392)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • TeamsSetup.exe (PID: 1380)
      • Update.exe (PID: 1392)
    • Process drops legitimate windows executable

      • TeamsSetup.exe (PID: 1380)
      • Update.exe (PID: 1392)
    • Starts a Microsoft application from unusual location

      • TeamsSetup.exe (PID: 1380)
    • Reads the Internet Settings

      • Update.exe (PID: 1392)
    • Reads settings of System Certificates

      • Update.exe (PID: 1392)
    • Checks Windows Trust Settings

      • Update.exe (PID: 1392)
    • Reads security settings of Internet Explorer

      • Update.exe (PID: 1392)
  • INFO

    • Creates files or folders in the user directory

      • TeamsSetup.exe (PID: 1380)
      • Update.exe (PID: 1392)
    • Checks supported languages

      • TeamsSetup.exe (PID: 1380)
      • Update.exe (PID: 1392)
    • Reads the computer name

      • Update.exe (PID: 1392)
    • Reads the machine GUID from the registry

      • Update.exe (PID: 1392)
    • Reads Environment values

      • Update.exe (PID: 1392)
    • Reads Microsoft Office registry keys

      • Update.exe (PID: 1392)
    • Create files in a temporary directory

      • Update.exe (PID: 1392)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable (generic) (52.9)
.exe | Generic Win/DOS Executable (23.5)
.exe | DOS Executable Generic (23.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:11:30 22:59:41+01:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14.16
CodeSize: 215040
InitializedDataSize: 1209344
UninitializedDataSize: -
EntryPoint: 0x14510
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 1.6.0.35961
ProductVersionNumber: 1.6.0.35961
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
FileDescription: Microsoft Teams
FileVersion: 1.6.00.35961
InternalName: Setup.exe
LegalCopyright: Copyright (C) 2016 Microsoft. All rights reserved.
OriginalFileName: Setup.exe
ProductName: Microsoft Teams
ProductVersion: 1.6.00.35961
SquirrelAwareVersion: 1
CompanyName: Microsoft Corporation
No data.
screenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
38
Monitored processes
2
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start teamssetup.exe update.exe

Process information

PID
CMD
Path
Indicators
Parent process
1380"C:\Users\admin\AppData\Local\Temp\TeamsSetup.exe" C:\Users\admin\AppData\Local\Temp\TeamsSetup.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Teams
Exit code:
0
Version:
1.6.00.35961
Modules
Images
c:\users\admin\appdata\local\temp\teamssetup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
1392"C:\Users\admin\AppData\Local\SquirrelTemp\Update.exe" --install . --exeName=TeamsSetup.exe --bootstrapperModeC:\Users\admin\AppData\Local\SquirrelTemp\Update.exe
TeamsSetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Teams classic
Exit code:
0
Version:
3.3.9.1
Modules
Images
c:\users\admin\appdata\local\squirreltemp\update.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
Total events
4 055
Read events
4 040
Write events
15
Delete events
0

Modification events

(PID) Process:(1392) Update.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1392) Update.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Direct3D\MostRecentApplication
Operation:writeName:Name
Value:
Explorer.EXE
Executable files
3
Suspicious files
5
Text files
3
Unknown types
0

Dropped files

PID
Process
Filename
Type
1380TeamsSetup.exeC:\Users\admin\AppData\Local\SquirrelTemp\endpoint.jsonbinary
MD5:1AFCC3A53B2154F10E73BB2E766F4E05
SHA256:00D7742CA8257126B875ED941A04FD500111EC0AD557984D825619F09E93972E
1380TeamsSetup.exeC:\Users\admin\AppData\Local\SquirrelTemp\Update.exeexecutable
MD5:5498BD5D88A45FE41BD737C64F43DA0F
SHA256:360AF51FB3DAE55FBE80CFFC1269DF039399B698061245B87E805A2E6B83F803
1392Update.exeC:\Users\admin\AppData\Roaming\Microsoft\Teams\teams_install_session.jsonbinary
MD5:B02234C61140F38266CA0D2A889399AB
SHA256:001F922F05B8BAEBE642FECDFBFAF7AB06C071D9ABCA676EFFD8CAB341D18218
1380TeamsSetup.exeC:\Users\admin\AppData\Local\SquirrelTemp\background.gifimage
MD5:FF1F29DCA0451246C3CA6CB7B023434F
SHA256:753D7D351E427246E2B6CC86C45E21F952939E306C3EB2FDB1BD7D67842C64B8
1380TeamsSetup.exeC:\Users\admin\AppData\Local\SquirrelTemp\downloading.gifimage
MD5:3488A1749B859E969C01BA981036FAB6
SHA256:C3FA333FDBCE95D504AEE31912993DC17AB31324428F557AC774F7E98B049B99
1392Update.exeC:\Users\admin\AppData\Local\Microsoft\Teams\setup.jsonbinary
MD5:C0D610F51BE2C368EC99C92668EC9435
SHA256:948DA6AFD35E48C348F3E752D92B32F9710BDED2412D3967C9A460E1C62273CE
1392Update.exeC:\Users\admin\AppData\Local\SquirrelTemp\setup.jsonbinary
MD5:C0D610F51BE2C368EC99C92668EC9435
SHA256:948DA6AFD35E48C348F3E752D92B32F9710BDED2412D3967C9A460E1C62273CE
1392Update.exeC:\Users\admin\AppData\Local\Microsoft\Teams\packages\Teams-1.7.00.1864-full.nupkgcompressed
MD5:473488B996513BAD2B7A4D9B3E10CF88
SHA256:ED92ABE39E74EF852DF88192B82207DC0CD3C5A6273FE0A6043EA5E56C0E38C9
1392Update.exeC:\Users\admin\AppData\Local\Microsoft\Teams\Update.exeexecutable
MD5:5498BD5D88A45FE41BD737C64F43DA0F
SHA256:360AF51FB3DAE55FBE80CFFC1269DF039399B698061245B87E805A2E6B83F803
1392Update.exeC:\Users\admin\AppData\Roaming\Microsoft\Teams\SquirrelTelemetry.logtext
MD5:FC849BBAEEFD79520A46D35A100BABD8
SHA256:6411083FC748F1ACE3AAAC0D573397C139642B489EC2C5D4F1977E6FDD5CCD6E
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
8
DNS requests
3
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1392
Update.exe
52.123.128.14:443
teams.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
1080
svchost.exe
224.0.0.252:5355
unknown
1392
Update.exe
20.189.173.11:443
mobile.pipe.aria.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown

DNS requests

Domain
IP
Reputation
teams.microsoft.com
  • 52.123.128.14
  • 52.123.129.14
whitelisted
statics.teams.cdn.office.net
  • 52.123.128.14
  • 52.123.129.14
whitelisted
mobile.pipe.aria.microsoft.com
  • 20.189.173.11
whitelisted

Threats

No threats detected
Process
Message
Update.exe
Update.exe Information: 0 :
Update.exe
TelemetryManagerImpl creation started
Update.exe
Update.exe Information: 0 :
Update.exe
Starting TelemetryManager constructor
Update.exe
Update.exe Information: 0 :
Update.exe
Performance counters are disabled. Skipping creation of counters category.
Update.exe
Update.exe Information: 0 :
Update.exe
RecordBatcherTask with ID 4 started.
Update.exe
Update.exe Information: 0 :
Update.exe
DataPackageSender with UserAgent name: AST-exe-C#, version: 3.3.9.1, [Ast_Default_Source]