File name:

JavaSetup8u431.exe

Full analysis: https://app.any.run/tasks/baa81143-d6ee-4229-9dff-50a3c78caa3e
Verdict: Malicious activity
Analysis date: November 25, 2024, 13:25:17
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 5 sections
MD5:

1C098B289611A95A1A84A77AFE64620E

SHA1:

3A13FEA5DAF0F6E9BC6932DFBA6582C5420B8BE5

SHA256:

641D91C2036584022FF85C76450B367B7031DD2FC845A507C7B5948EEB2696FC

SSDEEP:

98304:hElcskemmZ0kFLexrtaXBFvR/hTwMqfZeW3nTZ8aO:u

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • JavaSetup8u431.exe (PID: 6180)
      • LZMA_EXE (PID: 7120)
      • installer.exe (PID: 6512)
      • JavaSetup8u431.exe (PID: 6224)
    • The process drops C-runtime libraries

      • msiexec.exe (PID: 5472)
    • Process drops legitimate windows executable

      • msiexec.exe (PID: 5472)
    • Starts application with an unusual extension

      • JavaSetup8u431.exe (PID: 6224)
  • INFO

    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 5472)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (76.4)
.exe | Win32 Executable (generic) (12.4)
.exe | Generic Win/DOS Executable (5.5)
.exe | DOS Executable Generic (5.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:09:30 08:52:08+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14.36
CodeSize: 200192
InitializedDataSize: 2157568
UninitializedDataSize: -
EntryPoint: 0x1046b
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 8.0.4310.10
ProductVersionNumber: 8.0.4310.10
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Oracle Corporation
FileDescription: Java Platform SE binary
FileVersion: 8.0.4310.10
FullVersion: 1.8.0_431-b10
InternalName: Setup Launcher
LegalCopyright: Copyright © 2024
OriginalFileName: online_wrapper-cab.exe
ProductName: Java Platform SE 8 U431
ProductVersion: 8.0.4310.10
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
149
Monitored processes
22
Malicious processes
1
Suspicious processes
1

Behavior graph

Click at the process to see the details
start javasetup8u431.exe javasetup8u431.exe lzma_exe conhost.exe no specs lzma_exe no specs conhost.exe no specs msiexec.exe msiexec.exe no specs installer.exe javaw.exe ssvagent.exe no specs javaws.exe jp2launcher.exe no specs javaws.exe jp2launcher.exe no specs msiexec.exe no specs msiexec.exe no specs msiexec.exe no specs msiexec.exe no specs msiexec.exe no specs javaw.exe no specs javasetup8u431.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
640C:\Windows\syswow64\MsiExec.exe -Embedding BBD7FD37A1A27A739BAF6E593F9749D9 E Global\MSI0000C:\Windows\SysWOW64\msiexec.exemsiexec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.3636 (WinBuild.160101.0800)
2072\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeLZMA_EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3524C:\Windows\syswow64\MsiExec.exe -Embedding 7C903948D3C333680596E39624EDA6C0C:\Windows\SysWOW64\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.3636 (WinBuild.160101.0800)
3584"C:\Program Files (x86)\Java\jre1.8.0_431\bin\javaw.exe" -Xshare:dump -Djdk.disableLastUsageTrackingC:\Program Files (x86)\Java\jre1.8.0_431\bin\javaw.exe
installer.exe
User:
SYSTEM
Company:
Oracle Corporation
Integrity Level:
SYSTEM
Description:
Java(TM) Platform SE binary
Exit code:
0
Version:
8.0.4310.10
Modules
Images
c:\program files (x86)\java\jre1.8.0_431\bin\javaw.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\advapi32.dll
c:\windows\syswow64\msvcrt.dll
3780"C:\Users\admin\AppData\LocalLow\Oracle\Java\jre1.8.0_431\LZMA_EXE" d "C:\Users\admin\AppData\LocalLow\Oracle\Java\jre1.8.0_431\jre1.8.0_431.msi" "C:\Users\admin\AppData\LocalLow\Oracle\Java\jre1.8.0_431\msi.tmp"C:\Users\admin\AppData\LocalLow\Oracle\Java\jre1.8.0_431\LZMA_EXEJavaSetup8u431.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\locallow\oracle\java\jre1.8.0_431\lzma_exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
4596"C:\Users\admin\AppData\Local\Temp\JavaSetup8u431.exe" C:\Users\admin\AppData\Local\Temp\JavaSetup8u431.exeexplorer.exe
User:
admin
Company:
Oracle Corporation
Integrity Level:
MEDIUM
Description:
Java Platform SE binary
Exit code:
3221226540
Version:
8.0.4310.10
Modules
Images
c:\users\admin\appdata\local\temp\javasetup8u431.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
4840C:\Windows\syswow64\MsiExec.exe -Embedding E15566A3483F5718D9A14C56D4669133C:\Windows\SysWOW64\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
5028C:\Windows\syswow64\MsiExec.exe -Embedding D3CB5B425C33FB440F40BFA3394072AEC:\Windows\SysWOW64\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.3636 (WinBuild.160101.0800)
5472C:\WINDOWS\system32\msiexec.exe /VC:\Windows\System32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
5548C:\Windows\syswow64\MsiExec.exe -Embedding 40A078A244205C33CEFC2624E894A531 E Global\MSI0000C:\Windows\SysWOW64\msiexec.exemsiexec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.3636 (WinBuild.160101.0800)
Total events
15 242
Read events
9 426
Write events
5 795
Delete events
21

Modification events

(PID) Process:(6224) JavaSetup8u431.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\JavaSoft
Operation:delete valueName:InstallStatus
Value:
(PID) Process:(6224) JavaSetup8u431.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(6224) JavaSetup8u431.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(6224) JavaSetup8u431.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(6224) JavaSetup8u431.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\LowRegistry
Operation:delete valueName:AddToFavoritesInitialSelection
Value:
(PID) Process:(6224) JavaSetup8u431.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\LowRegistry
Operation:delete valueName:AddToFeedsInitialSelection
Value:
(PID) Process:(6224) JavaSetup8u431.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\JavaSoft\Java Update\Policy
Operation:writeName:Country
Value:
BR
(PID) Process:(6224) JavaSetup8u431.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\JavaSoft\Java Update\Policy
Operation:writeName:Method
Value:
jcab
(PID) Process:(6224) JavaSetup8u431.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\JavaSoft\Java Update\Policy
Operation:writeName:PostStatusUrl
Value:
https://sjremetrics.java.com/b/ss//6
(PID) Process:(5472) msiexec.exeKey:HKEY_USERS\S-1-5-21-1693682860-607145093-2874071422-1001\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
60150000DB2E6F8A3D3FDB01
Executable files
205
Suspicious files
68
Text files
109
Unknown types
10

Dropped files

PID
Process
Filename
Type
6224JavaSetup8u431.exeC:\Users\admin\AppData\LocalLow\Oracle\Java\jre1.8.0_431\jds1272562.tmp
MD5:
SHA256:
6224JavaSetup8u431.exeC:\Users\admin\AppData\LocalLow\Oracle\Java\jre1.8.0_431\jre1.8.0_431.msi
MD5:
SHA256:
3780LZMA_EXEC:\Users\admin\AppData\LocalLow\Oracle\Java\jre1.8.0_431\msi.tmp
MD5:
SHA256:
5472msiexec.exeC:\Windows\Installer\13c315.msi
MD5:
SHA256:
6180JavaSetup8u431.exeC:\Users\admin\AppData\Local\Temp\jusched.logtext
MD5:13791F6187E617D766E4A6497BA5ACE9
SHA256:E519D4CE42EA80038E265E8EC16B8414346A8A3CE9283E369A71E117D847FCB2
6224JavaSetup8u431.exeC:\Users\admin\AppData\LocalLow\Oracle\Java\jre1.8.0_431\jds1272563.tmpcompressed
MD5:55518E53A79666E8CCE391314DEB2C57
SHA256:9A8E80C5DFF74D0570ED540435624DAFABC2B8970F87C1999330E2032543FABA
6224JavaSetup8u431.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\698460A0B6E60F2F602361424D832905_8BB23D43DE574E82F2BEE0DF0EC47EEBbinary
MD5:69CF62DF9450671915B7B6D82D7E7A26
SHA256:03C8B40BFFFE9AB75F48149461E392BB21E73B37DAD0DBA45398FA85187DF157
6224JavaSetup8u431.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B398B80134F72209547439DB21AB308D_A4CF52CCA82D7458083F7280801A3A04der
MD5:712C6697294F9393801D8408E1DC3848
SHA256:6851F7AC489AC36C34FBCF0F42F96AD8E48907BAD907D280EF008BDFD291D9A6
6224JavaSetup8u431.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B398B80134F72209547439DB21AB308D_A4CF52CCA82D7458083F7280801A3A04binary
MD5:486E47825E86E31D4879EF75BA03CF46
SHA256:C140385C73D4871C743CCE98E82D5A6FA1AE0607EDE8E0CFAA6316A89F6712F3
6224JavaSetup8u431.exeC:\Users\admin\AppData\LocalLow\Oracle\Java\jre1.8.0_431\au.msicompressed
MD5:55518E53A79666E8CCE391314DEB2C57
SHA256:9A8E80C5DFF74D0570ED540435624DAFABC2B8970F87C1999330E2032543FABA
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
12
TCP/UDP connections
40
DNS requests
21
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
2.16.164.17:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
4712
MoUsoCoreWorker.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6224
JavaSetup8u431.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAbY2QTVWENG9oovp1QifsQ%3D
unknown
whitelisted
5064
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
1176
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6224
JavaSetup8u431.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT3xL4LQLXDRDM9P665TW442vrsUQQUReuir%2FSSy4IxLVGLp6chnfNtyA8CEA6bGI750C3n79tQ4ghAGFo%3D
unknown
whitelisted
6224
JavaSetup8u431.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSRXerF0eFeSWRripTgTkcJWMm7iQQUaDfg67Y7%2BF8Rhvv%2BYXsIiGX0TkICEAYOL4%2BeG4vlGNX%2BK2nPzLE%3D
unknown
whitelisted
6224
JavaSetup8u431.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfIs%2BLjDtGwQ09XEB1Yeq%2BtX%2BBgQQU7NfjgtJxXWRM3y5nP%2Be6mK4cD08CEAitQLJg0pxMn17Nqb2Trtk%3D
unknown
whitelisted
4668
SIHClient.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4328
svchost.exe
4.231.128.59:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5064
SearchApp.exe
2.23.209.171:443
www.bing.com
Akamai International B.V.
GB
whitelisted
4.231.128.59:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2.16.164.17:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
4712
MoUsoCoreWorker.exe
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4712
MoUsoCoreWorker.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6224
JavaSetup8u431.exe
104.102.54.38:443
javadl-esd-secure.oracle.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
www.bing.com
  • 2.23.209.171
  • 2.23.209.162
  • 2.23.209.160
  • 2.23.209.158
  • 2.23.209.168
  • 2.23.209.156
  • 2.23.209.167
  • 2.23.209.166
  • 2.23.209.161
whitelisted
crl.microsoft.com
  • 2.16.164.17
  • 2.16.164.107
  • 2.16.164.18
  • 2.16.164.40
  • 2.16.164.106
whitelisted
www.microsoft.com
  • 95.101.149.131
  • 88.221.169.152
whitelisted
google.com
  • 142.250.185.142
whitelisted
settings-win.data.microsoft.com
  • 51.124.78.146
  • 20.73.194.208
whitelisted
javadl-esd-secure.oracle.com
  • 104.102.54.38
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
javadl.oracle.com
  • 104.102.54.38
whitelisted
sdlc-esd.oracle.com
  • 23.212.88.77
whitelisted
login.live.com
  • 40.126.32.136
  • 20.190.160.20
  • 40.126.32.140
  • 40.126.32.133
  • 40.126.32.138
  • 20.190.160.17
  • 20.190.160.22
  • 40.126.32.134
whitelisted

Threats

No threats detected
No debug info