download:

/download/UnregisteredHyperCam2/HC2Setup.exe

Full analysis: https://app.any.run/tasks/8958fcaa-26c6-44af-a174-3474532e8eba
Verdict: Malicious activity
Analysis date: April 29, 2025, 21:06:03
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, RAR self-extracting archive, 4 sections
MD5:

F96A73B23464366E4158620B10FA52C5

SHA1:

1B048D127670EA9C113C3582C7D2BFDE2BC4B32A

SHA256:

6A06B2BA1A32B703D65F43D49DDAA8E74D8F5ADD21A8AB04AA0044937A5A50C5

SSDEEP:

24576:Lev+eq3WBaH4tnpWrcLkx0j6a0BkIgsgq4bSu2wU1DjsJMY9cLYelTgJORXs:a5BaYtnpWrcLkx0j6amkIgsgqASu2wU+

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • HC2Setup.exe (PID: 1748)
      • HC2Setup.exe (PID: 2624)
      • HyCam2.exe (PID: 1864)
      • HC2Setup.exe (PID: 3064)
      • HC2Setup.exe (PID: 288)
      • HyCam2.exe (PID: 2536)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • HC2Setup.exe (PID: 1748)
      • HyCam2.exe (PID: 1864)
      • HC2Setup.exe (PID: 288)
    • Reads security settings of Internet Explorer

      • HC2Setup.exe (PID: 1748)
      • HC2Setup.exe (PID: 288)
    • Reads the Internet Settings

      • HC2Setup.exe (PID: 1748)
      • HC2Setup.exe (PID: 288)
    • There is functionality for taking screenshot (YARA)

      • HyCam2.exe (PID: 1864)
    • Creates a software uninstall entry

      • HyCam2.exe (PID: 1864)
  • INFO

    • Checks supported languages

      • HC2Setup.exe (PID: 1748)
      • HyCam2.exe (PID: 1864)
      • HC2Setup.exe (PID: 288)
      • HyCam2.exe (PID: 2536)
    • The sample compiled with english language support

      • HC2Setup.exe (PID: 1748)
      • HyCam2.exe (PID: 1864)
      • HC2Setup.exe (PID: 288)
    • Reads the computer name

      • HC2Setup.exe (PID: 1748)
      • HyCam2.exe (PID: 1864)
      • HC2Setup.exe (PID: 288)
      • HyCam2.exe (PID: 2536)
    • Create files in a temporary directory

      • HC2Setup.exe (PID: 1748)
      • HC2Setup.exe (PID: 288)
    • Creates files in the program directory

      • HyCam2.exe (PID: 1864)
    • Manual execution by a user

      • HC2Setup.exe (PID: 3064)
      • HC2Setup.exe (PID: 288)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | WinRAR Self Extracting archive (94.8)
.scr | Windows screen saver (2.3)
.dll | Win32 Dynamic Link Library (generic) (1.2)
.exe | Win32 Executable (generic) (0.8)
.exe | Generic Win/DOS Executable (0.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2006:09:13 18:20:14+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 5
CodeSize: 77824
InitializedDataSize: 28672
UninitializedDataSize: -
EntryPoint: 0x1000
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
44
Monitored processes
6
Malicious processes
3
Suspicious processes
3

Behavior graph

Click at the process to see the details
start hc2setup.exe hycam2.exe hc2setup.exe no specs hc2setup.exe hycam2.exe no specs hc2setup.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
288"C:\Users\admin\Desktop\HC2Setup.exe" C:\Users\admin\Desktop\HC2Setup.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Modules
Images
c:\users\admin\desktop\hc2setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\gdi32.dll
1748"C:\Users\admin\Desktop\HC2Setup.exe" C:\Users\admin\Desktop\HC2Setup.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\desktop\hc2setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\gdi32.dll
1864"C:\Users\admin\AppData\Local\Temp\RarSFX0\HyCam2.exe" -installC:\Users\admin\AppData\Local\Temp\RarSFX0\HyCam2.exe
HC2Setup.exe
User:
admin
Company:
Hyperionics
Integrity Level:
HIGH
Description:
HyperCam
Exit code:
0
Version:
2, 14, 1, 0
Modules
Images
c:\users\admin\appdata\local\temp\rarsfx0\hycam2.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\winmm.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2536"C:\Users\admin\AppData\Local\Temp\RarSFX0\HyCam2.exe" -installC:\Users\admin\AppData\Local\Temp\RarSFX0\HyCam2.exeHC2Setup.exe
User:
admin
Company:
Hyperionics
Integrity Level:
HIGH
Description:
HyperCam
Version:
2, 14, 1, 0
Modules
Images
c:\users\admin\appdata\local\temp\rarsfx0\hycam2.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\winmm.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2624"C:\Users\admin\Desktop\HC2Setup.exe" C:\Users\admin\Desktop\HC2Setup.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\desktop\hc2setup.exe
c:\windows\system32\ntdll.dll
3064"C:\Users\admin\Desktop\HC2Setup.exe" C:\Users\admin\Desktop\HC2Setup.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\desktop\hc2setup.exe
c:\windows\system32\ntdll.dll
Total events
1 022
Read events
1 004
Write events
18
Delete events
0

Modification events

(PID) Process:(1748) HC2Setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(1748) HC2Setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(1748) HC2Setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(1748) HC2Setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(1864) HyCam2.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\HyperCam 2
Operation:writeName:DisplayName
Value:
HyperCam 2
(PID) Process:(1864) HyCam2.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\HyperCam 2
Operation:writeName:UninstallString
Value:
"C:\Program Files\HyCam2\UnHyCam2.exe"
(PID) Process:(288) HC2Setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(288) HC2Setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(288) HC2Setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(288) HC2Setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
Executable files
12
Suspicious files
61
Text files
9
Unknown types
0

Dropped files

PID
Process
Filename
Type
1748HC2Setup.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\8-8000d.wavbinary
MD5:1912519EA64D50843AE9084D37E8A0C1
SHA256:5F8D2BDA27A1036902C82778FF4C947AC57D63D558C1D6F0AA4B168489774538
1748HC2Setup.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\8-8000u.wavbinary
MD5:D6A10FFAB0437CB757CA0DD098B8B3A7
SHA256:F3B90092A7F0313D5D0B97AD470CE6D68AA4F4780B18D39560A4988520F4C849
1748HC2Setup.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\16-22050u.wavbinary
MD5:76F42715F524FB2110CA845520E101D8
SHA256:3B393414011D7CCF8A1EB588C3FFD627105EB33E9660D5BDC050455B3C7A215A
1748HC2Setup.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\HyCam2.exeexecutable
MD5:596580454699FDC01B48029905171BD3
SHA256:7465A6B09B41DBC3D0E3B564C6AC6334DC41FF2F3C2DC39BC9E37AEDE51B7272
1748HC2Setup.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\8-22050u.wavbinary
MD5:BF39380290ED50079B752A2593B9A50D
SHA256:C809DB4B1D49BB7F70A1E91FA8769563BD1E2BEFF8EC979B881713CD55FF99E9
1748HC2Setup.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\HomePage.urlbinary
MD5:92B609D63452D6F46670DDB55F4CABF6
SHA256:AE90F5CC0CA1194E999D1B7FAF382CAD743633876AFD5CD0585896E17EC32310
1748HC2Setup.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\16-11025u.wavbinary
MD5:12A8E35F4B87AAE6DF4D824D4BF2D601
SHA256:ED614186535078B71D7534F1B2A4DB00BB04389C81D7865D0241C7548A9B5D93
1748HC2Setup.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\16-11025d.wavbinary
MD5:C61B97FDEA6DE3AC4EC0DCAB8EDA621C
SHA256:15F65320D89520A615CFDBF952742B3FB9E2466F84794A18433AFD743C3C8709
1748HC2Setup.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\CamRes2.dllexecutable
MD5:302FF6A4B9F7AF939366600A818316C8
SHA256:DE326AFDCF4AC17D6E75D46499685C22F39F837E12348992CE768B2538D69372
1748HC2Setup.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\16-22050d.wavbinary
MD5:E00C8AE722FD731A639F34571375ADB1
SHA256:60C7BC95E033888F55022B12C9D9BAD16FC458B9E499515B2223FDF2D4F8E741
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
5
DNS requests
1
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
224.0.0.252:5355
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.186.110
whitelisted

Threats

No threats detected
No debug info