File name:

Transtype Pro 3 Setup for Windows.exe

Full analysis: https://app.any.run/tasks/e43f841e-d007-416b-9901-f058363fe9d9
Verdict: Malicious activity
Analysis date: January 20, 2024, 23:22:30
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed
MD5:

3DFD222A815AC7253F61C7273E03E05C

SHA1:

E50EABABFA1CAE38F83DB113830F069A9A1C723C

SHA256:

68C58BBE79631B4B8BE2CF44B1DEAC20211DCFB1290CA16B8D0F829147B4F90C

SSDEEP:

98304:CyORIILjegyoa4u/u8MKJ8RclJ4zyvFIV4p9n4vqH+kaQsxptvfAErl4ySijefj0:48JepaK/8rh17Q

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • Transtype Pro 3 Setup for Windows.exe (PID: 2420)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • Transtype Pro 3 Setup for Windows.exe (PID: 2420)
    • The process creates files with name similar to system file names

      • Transtype Pro 3 Setup for Windows.exe (PID: 2420)
    • Process drops legitimate windows executable

      • Transtype Pro 3 Setup for Windows.exe (PID: 2420)
    • The process drops C-runtime libraries

      • Transtype Pro 3 Setup for Windows.exe (PID: 2420)
  • INFO

    • Checks supported languages

      • Transtype Pro 3 Setup for Windows.exe (PID: 2420)
    • Reads the computer name

      • Transtype Pro 3 Setup for Windows.exe (PID: 2420)
    • Creates files in the program directory

      • Transtype Pro 3 Setup for Windows.exe (PID: 2420)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | UPX compressed Win32 Executable (38.2)
.exe | Win32 EXE Yoda's Crypter (37.5)
.dll | Win32 Dynamic Link Library (generic) (9.2)
.exe | Win32 Executable (generic) (6.3)
.exe | Win16/32 Executable Delphi generic (2.9)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 1992:06:20 00:22:17+02:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 135168
InitializedDataSize: 24576
UninitializedDataSize: 290816
EntryPoint: 0x67ff0
OSVersion: 1
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
37
Monitored processes
2
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start transtype pro 3 setup for windows.exe transtype pro 3 setup for windows.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2036"C:\Users\admin\AppData\Local\Temp\Transtype Pro 3 Setup for Windows.exe" C:\Users\admin\AppData\Local\Temp\Transtype Pro 3 Setup for Windows.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\appdata\local\temp\transtype pro 3 setup for windows.exe
c:\windows\system32\ntdll.dll
2420"C:\Users\admin\AppData\Local\Temp\Transtype Pro 3 Setup for Windows.exe" C:\Users\admin\AppData\Local\Temp\Transtype Pro 3 Setup for Windows.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\transtype pro 3 setup for windows.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\gdi32.dll
Total events
897
Read events
897
Write events
0
Delete events
0

Modification events

No data
Executable files
33
Suspicious files
12
Text files
176
Unknown types
0

Dropped files

PID
Process
Filename
Type
2420Transtype Pro 3 Setup for Windows.exeC:\Temp\1E980QOM\Transtype Pro 3 Setup for Windows\presetup\watermark.bmpimage
MD5:04CD48A87A7AA1D2EEE8098A55FF64DC
SHA256:D9F88B7CAD552D3117C1C9B700DEF1E60BA901420778FAB68E1A3D3F96DAEA44
2420Transtype Pro 3 Setup for Windows.exeC:\Temp\1E980QOM\Transtype Pro 3 Setup for Windows\presetup.bmpimage
MD5:8B19386E4344AF881F752EE5BFD3EEE8
SHA256:0E9CFF39F93498CF001D3755F7F77165E5EF3207E88E468DD384AC141AA56822
2420Transtype Pro 3 Setup for Windows.exeC:\Temp\1E980QOM\Transtype Pro 3 Setup for Windows\presetup\banner.bmpimage
MD5:2AC80F5708A0DD77F84668DF5B2B6861
SHA256:88EC1C664C1FCC891C305D8F420FA3B9F4DBD7A9A9B615D92B1F3CA2EB96F076
2420Transtype Pro 3 Setup for Windows.exeC:\Temp\1E980QOM\Transtype Pro 3 Setup for Windows\presetup\butt_que.bmpbinary
MD5:4F5D1E167800776B74DF65838D636D0A
SHA256:613348F024A96D4CBB4775C1A0DE71E44128F3DD353B66E94B8EBB2469D8579F
2420Transtype Pro 3 Setup for Windows.exeC:\Temp\1E980QOM\Transtype Pro 3 Setup for Windows\presetup.rgnbinary
MD5:4C53358F3DDDADFCCBA8DFD0C91F8DED
SHA256:4A2BFE0977756DD8ED38EF1A67365BE130E431C3CDFE4A3127D9AD9D7AD438B2
2420Transtype Pro 3 Setup for Windows.exeC:\Temp\1E980QOM\Transtype Pro 3 Setup for Windows\presetup\butt_warn.bmpbinary
MD5:D09B4C254CB705048E7CBBECD9FBC9DA
SHA256:4FC68C530E8B6738A032534299A986D47FC0C89735D79348023E109DCD7499EF
2420Transtype Pro 3 Setup for Windows.exeC:\Temp\1E980QOM\Transtype Pro 3 Setup for Windows\presetup\butt_inf.bmpbinary
MD5:30C329D00A541432E06B4E834040AEFF
SHA256:FFD33DC73D3744259701039190463AED3B7ED4E4A3DE5034494EE753DD9D15F9
2420Transtype Pro 3 Setup for Windows.exeC:\Temp\1E980QOM\Transtype Pro 3 Setup for Windows\presetup\unbanner.bmpimage
MD5:CBBA7EA044E942C03BB05DE1E78E19D7
SHA256:B40F3772EDE3F93A063F656FC36A38E1C60D6C2B10D5076E5670E50010BB1684
2420Transtype Pro 3 Setup for Windows.exeC:\Temp\1E980QOM\Transtype Pro 3 Setup for Windows\presetup\unwatermark.bmpimage
MD5:3CD2EF4F3374DDBD04A75F7739AD4142
SHA256:8E7ECFF5894DB405492F2E2F7912D6A67B32A9061700B32D080284B5C3891E46
2420Transtype Pro 3 Setup for Windows.exeC:\Temp\1E980QOM\Transtype Pro 3 Setup for Windows\presetup\bg_fls5.bmpimage
MD5:F63610F1F786D069A9D2C8651D795FF0
SHA256:721214B2F111D56A962C62C77D6C09CFE5ACEAB8873D7AF253F707A6F302801D
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown

DNS requests

No data

Threats

No threats detected
No debug info