File name:

IONSetup v3.2.25092.01.exe

Full analysis: https://app.any.run/tasks/c30ed15f-8f73-463c-bcea-ece3b1b0883e
Verdict: Malicious activity
Analysis date: May 14, 2025, 19:08:14
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 5 sections
MD5:

4DC5CF71A9E0E59B6406DC1A27624D7D

SHA1:

7051BE34C86B23DA13EF8DCF8136D33A6F125839

SHA256:

5BB33D1C935823414061F5B63EA865537768C70A5C9BDE6677ACE1DCFC30D0EF

SSDEEP:

98304:ihUhnNBM/u74MsUQgzxgeoNXod1ee3p/Fd17CVUiHxYOKd7PUmEWJQH8a0Xbe/28:wc3oUIgHesN1FBFnCfI2uiTisFMRM

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • IONSetup v3.2.25092.01.exe (PID: 7624)
      • IONSetup v3.2.25092.01.exe (PID: 7512)
      • Setup.exe (PID: 7716)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • IONSetup v3.2.25092.01.exe (PID: 7624)
    • Process drops legitimate windows executable

      • IONSetup v3.2.25092.01.exe (PID: 7624)
    • Reads security settings of Internet Explorer

      • Setup.exe (PID: 7716)
    • Reads Microsoft Outlook installation path

      • Setup.exe (PID: 7716)
    • Reads Internet Explorer settings

      • Setup.exe (PID: 7716)
  • INFO

    • Reads the computer name

      • IONSetup v3.2.25092.01.exe (PID: 7624)
      • Setup.exe (PID: 7716)
    • Checks supported languages

      • Setup.exe (PID: 7716)
      • IONSetup v3.2.25092.01.exe (PID: 7624)
    • Reads the machine GUID from the registry

      • Setup.exe (PID: 7716)
    • Create files in a temporary directory

      • Setup.exe (PID: 7716)
      • IONSetup v3.2.25092.01.exe (PID: 7624)
    • Checks proxy server information

      • Setup.exe (PID: 7716)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2010:11:18 16:27:35+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 104960
InitializedDataSize: 68608
UninitializedDataSize: -
EntryPoint: 0x14b04
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.0
ProductVersionNumber: 1.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
CompanyName: -
FileDescription: -
FileVersion: 1.0.0.0
InternalName: se7zS.sfx
LegalCopyright: Copyright (c) 2013
OriginalFileName: 7zS.sfx.exe
ProductName: -
ProductVersion: 1.0.0.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
131
Monitored processes
3
Malicious processes
2
Suspicious processes
1

Behavior graph

Click at the process to see the details
start ionsetup v3.2.25092.01.exe setup.exe no specs ionsetup v3.2.25092.01.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
7512"C:\Users\admin\AppData\Local\Temp\IONSetup v3.2.25092.01.exe" C:\Users\admin\AppData\Local\Temp\IONSetup v3.2.25092.01.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\ionsetup v3.2.25092.01.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
7624"C:\Users\admin\AppData\Local\Temp\IONSetup v3.2.25092.01.exe" C:\Users\admin\AppData\Local\Temp\IONSetup v3.2.25092.01.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\ionsetup v3.2.25092.01.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\oleaut32.dll
7716.\ION\setup\Setup.exeC:\Users\admin\AppData\Local\Temp\7zSBB43.tmp\ION\setup\Setup.exeIONSetup v3.2.25092.01.exe
User:
admin
Company:
Schneider Electric
Integrity Level:
HIGH
Description:
Installer
Version:
2.3.14245.01
Modules
Images
c:\users\admin\appdata\local\temp\7zsbb43.tmp\ion\setup\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
Total events
2 267
Read events
2 262
Write events
5
Delete events
0

Modification events

(PID) Process:(7716) Setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(7716) Setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(7716) Setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\WindowsSearch
Operation:writeName:Version
Value:
WS not running
(PID) Process:(7716) Setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(7716) Setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main
Operation:writeName:DisableFirstRunCustomize
Value:
1
Executable files
34
Suspicious files
0
Text files
27
Unknown types
0

Dropped files

PID
Process
Filename
Type
7624IONSetup v3.2.25092.01.exeC:\Users\admin\AppData\Local\Temp\7zSBB43.tmp\ION\setup\Installers\IONE_x86.msi
MD5:
SHA256:
7624IONSetup v3.2.25092.01.exeC:\Users\admin\AppData\Local\Temp\7zSBB43.tmp\ION\setup\Installers\ProgramFiles_x86.msi
MD5:
SHA256:
7624IONSetup v3.2.25092.01.exeC:\Users\admin\AppData\Local\Temp\7zSBB43.tmp\ION\setup\Images\Pending.pngimage
MD5:3AE97BECDC05B28C90BE676532BFED97
SHA256:F6B2A17C6A8616DB678969FCA5090AD17A54B1F877DF4EB44F1008DFA33C969F
7624IONSetup v3.2.25092.01.exeC:\Users\admin\AppData\Local\Temp\7zSBB43.tmp\ION\setup\Images\Awaiting-Blank.pngimage
MD5:1371519789CE34FD9FECACE9C8447CB1
SHA256:A3C5776A8365B81F60A652CC7C750E187696E1417481C8BA1EE0F3E740B9E4C1
7624IONSetup v3.2.25092.01.exeC:\Users\admin\AppData\Local\Temp\7zSBB43.tmp\ION\setup\Images\White_Arrow.pngimage
MD5:75E66DABE2829407762AA1B309DB4A01
SHA256:B7C5A3485A014A7192B599F1E7C95564D2CCB5B8B4C2FF748073BAEE333C483A
7624IONSetup v3.2.25092.01.exeC:\Users\admin\AppData\Local\Temp\7zSBB43.tmp\ION\setup\Images\Awaiting.pngimage
MD5:C65BF899AA9956E3350820705F60C88C
SHA256:74E5A913AF0E8F5B330BABC4613F50FA73A2616AFB253BC0E0A7A73C26C700CF
7624IONSetup v3.2.25092.01.exeC:\Users\admin\AppData\Local\Temp\7zSBB43.tmp\ION\setup\Images\Banner.pngimage
MD5:B4C8E539763ACD03DD480576C85C3CE5
SHA256:CAA133A2B3A0F4B2AAF437DBBE86864ADD435E4DA25A6E282DD22DEECEE35190
7624IONSetup v3.2.25092.01.exeC:\Users\admin\AppData\Local\Temp\7zSBB43.tmp\ION\setup\Images\Fail.pngimage
MD5:4DDAFAA79ADF1A9E676A1AAA2D34095F
SHA256:14F6A94257E5F86121E57F12D47674933B22844C9615271EE7D746FD6205E47E
7624IONSetup v3.2.25092.01.exeC:\Users\admin\AppData\Local\Temp\7zSBB43.tmp\ION\setup\Images\Success.pngimage
MD5:88B650B2D06FED4F929195649CE128DF
SHA256:5971E3C769295FFB548A425D88D0F8209F7FBAAD1CF083E264B2D54923610C69
7624IONSetup v3.2.25092.01.exeC:\Users\admin\AppData\Local\Temp\7zSBB43.tmp\ION\setup\Images\Running.pngimage
MD5:B7FFC396D3165FF934B2374B3E381585
SHA256:CA13B14324C1974023D2F308C87E408165FB6A1EE51905238E722587E75A9E61
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
20
DNS requests
13
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6544
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
23.48.23.164:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6808
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
6808
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
2104
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
23.48.23.164:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
5496
MoUsoCoreWorker.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
2112
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3216
svchost.exe
172.211.123.249:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
6544
svchost.exe
40.126.31.69:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
whitelisted
crl.microsoft.com
  • 23.48.23.164
  • 23.48.23.168
  • 23.48.23.156
  • 23.48.23.169
  • 23.48.23.173
  • 23.48.23.158
  • 23.48.23.162
  • 23.48.23.161
  • 23.48.23.176
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
google.com
  • 142.250.185.174
whitelisted
client.wns.windows.com
  • 172.211.123.249
whitelisted
login.live.com
  • 40.126.31.69
  • 40.126.31.0
  • 20.190.159.64
  • 40.126.31.1
  • 20.190.159.68
  • 40.126.31.129
  • 40.126.31.128
  • 40.126.31.131
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
slscr.update.microsoft.com
  • 4.245.163.56
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 13.85.23.206
whitelisted

Threats

No threats detected
No debug info