| File name: | internet-explorer-9-vista-32-11.0.0.4-installer_n1o6-p1.exe |
| Full analysis: | https://app.any.run/tasks/7b61f5bd-1571-4f84-80f3-127d8f89a309 |
| Verdict: | Malicious activity |
| Analysis date: | July 13, 2024, 06:37:46 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 3F6DFFF099A9E1AB628BEE91B15E219D |
| SHA1: | 3DF3906428C855244920239A92D4D33C17A189B2 |
| SHA256: | 5C46BF70E787E3EAEA8206838DC46392EECE561F9834E4D96CA90DA2279C52EA |
| SSDEEP: | 49152:z7HecD4dnbibBlYnCWFc7qThNUzuIrOWzfdi0cZDFb2XJlv0ZLyNEzYGTrEXo6dH:/+cD4dnHDGGhNUzuICk10oL0d6qYfXn1 |
| .exe | | | Inno Setup installer (53.5) |
|---|---|---|
| .exe | | | InstallShield setup (21) |
| .exe | | | Win32 EXE PECompact compressed (generic) (20.2) |
| .exe | | | Win32 Executable (generic) (2.1) |
| .exe | | | Win16/32 Executable Delphi generic (1) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2023:02:15 14:54:16+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi |
| PEType: | PE32 |
| LinkerVersion: | 2.25 |
| CodeSize: | 741888 |
| InitializedDataSize: | 89600 |
| UninitializedDataSize: | - |
| EntryPoint: | 0xb5eec |
| OSVersion: | 6.1 |
| ImageVersion: | 6 |
| SubsystemVersion: | 6.1 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 423.56.98.8907 |
| ProductVersionNumber: | 423.56.98.8907 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| Comments: | This installation was built with Inno Setup. |
| CompanyName: | |
| FileDescription: | Softonic ??????nternational SA |
| FileVersion: | 423.56.98.8907 |
| LegalCopyright: | ©2023 Softonic ??????nternational SA |
| OriginalFileName: | |
| ProductName: | Softonic ??????nternational SA |
| ProductVersion: | 3.1.5.7 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 640 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | rsSyncSvc.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 752 | "C:\Users\admin\AppData\Local\Temp\internet-explorer-9-vista-32-11.0.0.4-installer_n1o6-p1.exe" /SPAWNWND=$6028A /NOTIFYWND=$4025A | C:\Users\admin\AppData\Local\Temp\internet-explorer-9-vista-32-11.0.0.4-installer_n1o6-p1.exe | internet-explorer-9-vista-32-11.0.0.4-installer_n1o6-p1.tmp | ||||||||||||
User: admin Company: Integrity Level: HIGH Description: Softonic 𐌠nternational SA Exit code: 3221226525 Version: 423.56.98.8907 Modules
| |||||||||||||||
| 836 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=3696 --field-trial-handle=2200,i,12909960058439169378,16203410770200312074,262144 --variations-seed-version /prefetch:1 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Version: 122.0.2365.59 Modules
| |||||||||||||||
| 916 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-appcompat-clear --mojo-platform-channel-handle=2372 --field-trial-handle=2200,i,12909960058439169378,16203410770200312074,262144 --variations-seed-version /prefetch:3 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | msedge.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Version: 122.0.2365.59 Modules
| |||||||||||||||
| 2056 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=4324 --field-trial-handle=2200,i,12909960058439169378,16203410770200312074,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| 2120 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-appcompat-clear --mojo-platform-channel-handle=2512 --field-trial-handle=2404,i,10291872380224689653,17520700571927971159,262144 --variations-seed-version /prefetch:3 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| 2124 | "C:\Users\admin\AppData\Local\Temp\is-5SM44.tmp\internet-explorer-9-vista-32-11.0.0.4-installer_n1o6-p1.tmp" /SL5="$40264,837551,832512,C:\Users\admin\AppData\Local\Temp\internet-explorer-9-vista-32-11.0.0.4-installer_n1o6-p1.exe" /SPAWNWND=$6028A /NOTIFYWND=$4025A | C:\Users\admin\AppData\Local\Temp\is-5SM44.tmp\internet-explorer-9-vista-32-11.0.0.4-installer_n1o6-p1.tmp | internet-explorer-9-vista-32-11.0.0.4-installer_n1o6-p1.exe | ||||||||||||
User: admin Company: Integrity Level: HIGH Description: Setup/Uninstall Exit code: 3221226525 Version: 51.1052.0.0 Modules
| |||||||||||||||
| 2248 | "C:\Users\admin\AppData\Local\Temp\internet-explorer-9-vista-32-11.0.0.4-installer_n1o6-p1.exe" | C:\Users\admin\AppData\Local\Temp\internet-explorer-9-vista-32-11.0.0.4-installer_n1o6-p1.exe | explorer.exe | ||||||||||||
User: admin Company: Integrity Level: MEDIUM Description: Softonic 𐌠nternational SA Exit code: 3221226525 Version: 423.56.98.8907 Modules
| |||||||||||||||
| 2268 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --flag-switches-begin --flag-switches-end --do-not-de-elevate --single-argument https://gsf-fl.softonic.com/8de/eff/090f2611eb3e9349d134db18ed3bfec806/EIE11_EN-US_MCM_WIN764.EXE?Expires=1718681511&Signature=47697ad2afcd53bf6408a601a526a5765a49168a&url=https://internet-explorer-9-vista-32.softonic.com&Filename=EIE11_EN-US_MCM_WIN764.EXE | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Version: 122.0.2365.59 Modules
| |||||||||||||||
| 2636 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=5028 --field-trial-handle=2200,i,12909960058439169378,16203410770200312074,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| (PID) Process: | (2124) internet-explorer-9-vista-32-11.0.0.4-installer_n1o6-p1.tmp | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | Owner |
Value: 4C08000070E01730EFD4DA01 | |||
| (PID) Process: | (2124) internet-explorer-9-vista-32-11.0.0.4-installer_n1o6-p1.tmp | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | SessionHash |
Value: F75D4226EB4D466C97DDC7F3D6DF33E5264C7DC1EA59A3DB7DECCED9022C8511 | |||
| (PID) Process: | (2124) internet-explorer-9-vista-32-11.0.0.4-installer_n1o6-p1.tmp | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | Sequence |
Value: 1 | |||
| (PID) Process: | (2124) internet-explorer-9-vista-32-11.0.0.4-installer_n1o6-p1.tmp | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (2124) internet-explorer-9-vista-32-11.0.0.4-installer_n1o6-p1.tmp | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (2124) internet-explorer-9-vista-32-11.0.0.4-installer_n1o6-p1.tmp | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (2124) internet-explorer-9-vista-32-11.0.0.4-installer_n1o6-p1.tmp | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (4724) component0.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\component0_RASAPI32 |
| Operation: | write | Name: | EnableFileTracing |
Value: 0 | |||
| (PID) Process: | (4724) component0.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\component0_RASAPI32 |
| Operation: | write | Name: | EnableAutoFileTracing |
Value: 0 | |||
| (PID) Process: | (4724) component0.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\component0_RASAPI32 |
| Operation: | write | Name: | EnableConsoleTracing |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2248 | internet-explorer-9-vista-32-11.0.0.4-installer_n1o6-p1.exe | C:\Users\admin\AppData\Local\Temp\is-EBO33.tmp\internet-explorer-9-vista-32-11.0.0.4-installer_n1o6-p1.tmp | executable | |
MD5:E07653C6B6CC1B324F03B7976033F39B | SHA256:4F5D4EBA4FFD73C78906116CE2C2A065FECEBB4EAAC31DA58B71D4810BFCA95D | |||
| 2124 | internet-explorer-9-vista-32-11.0.0.4-installer_n1o6-p1.tmp | C:\Users\admin\AppData\Local\Temp\is-Q2TKC.tmp\is-GC850.tmp | image | |
MD5:1AA6F1A27C3C2E2CD0FB2F150F12B3C8 | SHA256:585F90989F147CB9AD19F38837EEA2822A0B614BA1C352FCD8A6696B0A000753 | |||
| 2124 | internet-explorer-9-vista-32-11.0.0.4-installer_n1o6-p1.tmp | C:\Users\admin\AppData\Local\Temp\is-Q2TKC.tmp\_isetup\_setup64.tmp | executable | |
MD5:E4211D6D009757C078A9FAC7FF4F03D4 | SHA256:388A796580234EFC95F3B1C70AD4CB44BFDDC7BA0F9203BF4902B9929B136F95 | |||
| 2124 | internet-explorer-9-vista-32-11.0.0.4-installer_n1o6-p1.tmp | C:\Users\admin\AppData\Local\Temp\is-Q2TKC.tmp\is-EU0GV.tmp | image | |
MD5:59517175811CBE3D29661469B5C8F05C | SHA256:355A9A67233E6C0BB173DCB05D84A588D9FCED6CFA2264684AA1F1DD09E1F0A5 | |||
| 752 | internet-explorer-9-vista-32-11.0.0.4-installer_n1o6-p1.exe | C:\Users\admin\AppData\Local\Temp\is-5SM44.tmp\internet-explorer-9-vista-32-11.0.0.4-installer_n1o6-p1.tmp | executable | |
MD5:E07653C6B6CC1B324F03B7976033F39B | SHA256:4F5D4EBA4FFD73C78906116CE2C2A065FECEBB4EAAC31DA58B71D4810BFCA95D | |||
| 2124 | internet-explorer-9-vista-32-11.0.0.4-installer_n1o6-p1.tmp | C:\Users\admin\AppData\Local\Temp\is-Q2TKC.tmp\component0.exe | executable | |
MD5:0074C8A5E44198959C8FDC6979A57A0E | SHA256:7891C7130AF3C6E0BF21CBC4F03F4D4C018C3751D1B1628C262AC9864B18F67E | |||
| 2124 | internet-explorer-9-vista-32-11.0.0.4-installer_n1o6-p1.tmp | C:\Users\admin\Downloads\internet-explorer-9-vista-32-11.0.0.4-installer.exe | html | |
MD5:26529E185D5C5D3851BAA60FC0B44A42 | SHA256:9EAA37B72C121B32330A925A09B919F8DC3E399EAE2C1858C8996BE97BAE1D58 | |||
| 5732 | rbxesybv.exe | C:\Users\admin\AppData\Local\Temp\7zS46677E0D\ArchiveUtilityx64.dll | executable | |
MD5:C70238BD9FB1A0B38F50A30BE7623EB7 | SHA256:88FB2446D4EAC42A41036354006AFADFCA5ACD38A0811110F7337DC5EC434884 | |||
| 4724 | component0.exe | C:\Users\admin\AppData\Local\Temp\rbxesybv.exe | executable | |
MD5:FE89F7FD6E0383D32A9721CEBAD0BF06 | SHA256:33E380D4166847E331F08A14FEDBC98EBD7A2D6FD2ED9E0E4FF37D17163B7785 | |||
| 5732 | rbxesybv.exe | C:\Users\admin\AppData\Local\Temp\7zS46677E0D\rsAtom.dll | executable | |
MD5:F5CF4F3E8DEDDC2BF3967B6BFF3E4499 | SHA256:9D31024A76DCAD5E2B39810DFF530450EE5A1B3ECBC08C72523E6E7EA7365A0B | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
1828 | MoUsoCoreWorker.exe | GET | 200 | 23.216.77.6:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
1828 | MoUsoCoreWorker.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
4004 | svchost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
4656 | SearchApp.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D | unknown | — | — | whitelisted |
3168 | backgroundTaskHost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D | unknown | — | — | whitelisted |
2208 | backgroundTaskHost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D | unknown | — | — | whitelisted |
7108 | SIHClient.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
7108 | SIHClient.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
7568 | WerFault.exe | GET | 200 | 23.216.77.28:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
7568 | WerFault.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2448 | svchost.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1004 | RUXIMICS.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
— | — | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
1828 | MoUsoCoreWorker.exe | 23.216.77.6:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
1828 | MoUsoCoreWorker.exe | 184.30.21.171:80 | www.microsoft.com | AKAMAI-AS | DE | unknown |
4032 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
6004 | svchost.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4656 | SearchApp.exe | 150.171.27.10:443 | www.bing.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | unknown |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
www.bing.com |
| whitelisted |
login.live.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
go.microsoft.com |
| whitelisted |
nexusrules.officeapps.live.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |