| File name: | IONSetup v3.2.25092.01.exe |
| Full analysis: | https://app.any.run/tasks/c30ed15f-8f73-463c-bcea-ece3b1b0883e |
| Verdict: | Malicious activity |
| Analysis date: | May 14, 2025, 19:08:14 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, 5 sections |
| MD5: | 4DC5CF71A9E0E59B6406DC1A27624D7D |
| SHA1: | 7051BE34C86B23DA13EF8DCF8136D33A6F125839 |
| SHA256: | 5BB33D1C935823414061F5B63EA865537768C70A5C9BDE6677ACE1DCFC30D0EF |
| SSDEEP: | 98304:ihUhnNBM/u74MsUQgzxgeoNXod1ee3p/Fd17CVUiHxYOKd7PUmEWJQH8a0Xbe/28:wc3oUIgHesN1FBFnCfI2uiTisFMRM |
| .exe | | | Win32 Executable MS Visual C++ (generic) (42.2) |
|---|---|---|
| .exe | | | Win64 Executable (generic) (37.3) |
| .dll | | | Win32 Dynamic Link Library (generic) (8.8) |
| .exe | | | Win32 Executable (generic) (6) |
| .exe | | | Generic Win/DOS Executable (2.7) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2010:11:18 16:27:35+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 104960 |
| InitializedDataSize: | 68608 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x14b04 |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.0.0.0 |
| ProductVersionNumber: | 1.0.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Windows NT 32-bit |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| CompanyName: | - |
| FileDescription: | - |
| FileVersion: | 1.0.0.0 |
| InternalName: | se7zS.sfx |
| LegalCopyright: | Copyright (c) 2013 |
| OriginalFileName: | 7zS.sfx.exe |
| ProductName: | - |
| ProductVersion: | 1.0.0.0 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 7512 | "C:\Users\admin\AppData\Local\Temp\IONSetup v3.2.25092.01.exe" | C:\Users\admin\AppData\Local\Temp\IONSetup v3.2.25092.01.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 3221226540 Version: 1.0.0.0 Modules
| |||||||||||||||
| 7624 | "C:\Users\admin\AppData\Local\Temp\IONSetup v3.2.25092.01.exe" | C:\Users\admin\AppData\Local\Temp\IONSetup v3.2.25092.01.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: HIGH Version: 1.0.0.0 Modules
| |||||||||||||||
| 7716 | .\ION\setup\Setup.exe | C:\Users\admin\AppData\Local\Temp\7zSBB43.tmp\ION\setup\Setup.exe | — | IONSetup v3.2.25092.01.exe | |||||||||||
User: admin Company: Schneider Electric Integrity Level: HIGH Description: Installer Version: 2.3.14245.01 Modules
| |||||||||||||||
| (PID) Process: | (7716) Setup.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
| (PID) Process: | (7716) Setup.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (7716) Setup.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\WindowsSearch |
| Operation: | write | Name: | Version |
Value: WS not running | |||
| (PID) Process: | (7716) Setup.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (7716) Setup.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main |
| Operation: | write | Name: | DisableFirstRunCustomize |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 7624 | IONSetup v3.2.25092.01.exe | C:\Users\admin\AppData\Local\Temp\7zSBB43.tmp\ION\setup\Installers\IONE_x86.msi | — | |
MD5:— | SHA256:— | |||
| 7624 | IONSetup v3.2.25092.01.exe | C:\Users\admin\AppData\Local\Temp\7zSBB43.tmp\ION\setup\Installers\ProgramFiles_x86.msi | — | |
MD5:— | SHA256:— | |||
| 7624 | IONSetup v3.2.25092.01.exe | C:\Users\admin\AppData\Local\Temp\7zSBB43.tmp\ION\setup\Images\Pending.png | image | |
MD5:3AE97BECDC05B28C90BE676532BFED97 | SHA256:F6B2A17C6A8616DB678969FCA5090AD17A54B1F877DF4EB44F1008DFA33C969F | |||
| 7624 | IONSetup v3.2.25092.01.exe | C:\Users\admin\AppData\Local\Temp\7zSBB43.tmp\ION\setup\Images\Awaiting-Blank.png | image | |
MD5:1371519789CE34FD9FECACE9C8447CB1 | SHA256:A3C5776A8365B81F60A652CC7C750E187696E1417481C8BA1EE0F3E740B9E4C1 | |||
| 7624 | IONSetup v3.2.25092.01.exe | C:\Users\admin\AppData\Local\Temp\7zSBB43.tmp\ION\setup\Images\White_Arrow.png | image | |
MD5:75E66DABE2829407762AA1B309DB4A01 | SHA256:B7C5A3485A014A7192B599F1E7C95564D2CCB5B8B4C2FF748073BAEE333C483A | |||
| 7624 | IONSetup v3.2.25092.01.exe | C:\Users\admin\AppData\Local\Temp\7zSBB43.tmp\ION\setup\Images\Awaiting.png | image | |
MD5:C65BF899AA9956E3350820705F60C88C | SHA256:74E5A913AF0E8F5B330BABC4613F50FA73A2616AFB253BC0E0A7A73C26C700CF | |||
| 7624 | IONSetup v3.2.25092.01.exe | C:\Users\admin\AppData\Local\Temp\7zSBB43.tmp\ION\setup\Images\Banner.png | image | |
MD5:B4C8E539763ACD03DD480576C85C3CE5 | SHA256:CAA133A2B3A0F4B2AAF437DBBE86864ADD435E4DA25A6E282DD22DEECEE35190 | |||
| 7624 | IONSetup v3.2.25092.01.exe | C:\Users\admin\AppData\Local\Temp\7zSBB43.tmp\ION\setup\Images\Fail.png | image | |
MD5:4DDAFAA79ADF1A9E676A1AAA2D34095F | SHA256:14F6A94257E5F86121E57F12D47674933B22844C9615271EE7D746FD6205E47E | |||
| 7624 | IONSetup v3.2.25092.01.exe | C:\Users\admin\AppData\Local\Temp\7zSBB43.tmp\ION\setup\Images\Success.png | image | |
MD5:88B650B2D06FED4F929195649CE128DF | SHA256:5971E3C769295FFB548A425D88D0F8209F7FBAAD1CF083E264B2D54923610C69 | |||
| 7624 | IONSetup v3.2.25092.01.exe | C:\Users\admin\AppData\Local\Temp\7zSBB43.tmp\ION\setup\Images\Running.png | image | |
MD5:B7FFC396D3165FF934B2374B3E381585 | SHA256:CA13B14324C1974023D2F308C87E408165FB6A1EE51905238E722587E75A9E61 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
6544 | svchost.exe | GET | 200 | 2.17.190.73:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
— | — | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
— | — | GET | 200 | 23.48.23.164:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
5496 | MoUsoCoreWorker.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
6808 | SIHClient.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
6808 | SIHClient.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
2104 | svchost.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
— | — | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
— | — | 23.48.23.164:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
— | — | 184.30.21.171:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
5496 | MoUsoCoreWorker.exe | 184.30.21.171:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
2112 | svchost.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
3216 | svchost.exe | 172.211.123.249:443 | client.wns.windows.com | MICROSOFT-CORP-MSN-AS-BLOCK | FR | whitelisted |
6544 | svchost.exe | 40.126.31.69:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
login.live.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |
fe3cr.delivery.mp.microsoft.com |
| whitelisted |