download:

/download/UnregisteredHyperCam2/HC2Setup.exe

Full analysis: https://app.any.run/tasks/8958fcaa-26c6-44af-a174-3474532e8eba
Verdict: Malicious activity
Analysis date: April 29, 2025, 21:06:03
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, RAR self-extracting archive, 4 sections
MD5:

F96A73B23464366E4158620B10FA52C5

SHA1:

1B048D127670EA9C113C3582C7D2BFDE2BC4B32A

SHA256:

6A06B2BA1A32B703D65F43D49DDAA8E74D8F5ADD21A8AB04AA0044937A5A50C5

SSDEEP:

24576:Lev+eq3WBaH4tnpWrcLkx0j6a0BkIgsgq4bSu2wU1DjsJMY9cLYelTgJORXs:a5BaYtnpWrcLkx0j6amkIgsgqASu2wU+

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • HC2Setup.exe (PID: 1748)
      • HC2Setup.exe (PID: 2624)
      • HyCam2.exe (PID: 1864)
      • HC2Setup.exe (PID: 3064)
      • HC2Setup.exe (PID: 288)
      • HyCam2.exe (PID: 2536)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • HC2Setup.exe (PID: 1748)
      • HyCam2.exe (PID: 1864)
      • HC2Setup.exe (PID: 288)
    • Reads security settings of Internet Explorer

      • HC2Setup.exe (PID: 1748)
      • HC2Setup.exe (PID: 288)
    • Reads the Internet Settings

      • HC2Setup.exe (PID: 1748)
      • HC2Setup.exe (PID: 288)
    • There is functionality for taking screenshot (YARA)

      • HyCam2.exe (PID: 1864)
    • Creates a software uninstall entry

      • HyCam2.exe (PID: 1864)
  • INFO

    • Checks supported languages

      • HC2Setup.exe (PID: 1748)
      • HyCam2.exe (PID: 1864)
      • HC2Setup.exe (PID: 288)
      • HyCam2.exe (PID: 2536)
    • Create files in a temporary directory

      • HC2Setup.exe (PID: 1748)
      • HC2Setup.exe (PID: 288)
    • The sample compiled with english language support

      • HC2Setup.exe (PID: 1748)
      • HyCam2.exe (PID: 1864)
      • HC2Setup.exe (PID: 288)
    • Reads the computer name

      • HC2Setup.exe (PID: 1748)
      • HyCam2.exe (PID: 1864)
      • HC2Setup.exe (PID: 288)
      • HyCam2.exe (PID: 2536)
    • Creates files in the program directory

      • HyCam2.exe (PID: 1864)
    • Manual execution by a user

      • HC2Setup.exe (PID: 3064)
      • HC2Setup.exe (PID: 288)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | WinRAR Self Extracting archive (94.8)
.scr | Windows screen saver (2.3)
.dll | Win32 Dynamic Link Library (generic) (1.2)
.exe | Win32 Executable (generic) (0.8)
.exe | Generic Win/DOS Executable (0.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2006:09:13 18:20:14+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 5
CodeSize: 77824
InitializedDataSize: 28672
UninitializedDataSize: -
EntryPoint: 0x1000
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
44
Monitored processes
6
Malicious processes
3
Suspicious processes
3

Behavior graph

Click at the process to see the details
start hc2setup.exe hycam2.exe hc2setup.exe no specs hc2setup.exe hycam2.exe no specs hc2setup.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
288"C:\Users\admin\Desktop\HC2Setup.exe" C:\Users\admin\Desktop\HC2Setup.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Modules
Images
c:\users\admin\desktop\hc2setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\gdi32.dll
1748"C:\Users\admin\Desktop\HC2Setup.exe" C:\Users\admin\Desktop\HC2Setup.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\desktop\hc2setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\gdi32.dll
1864"C:\Users\admin\AppData\Local\Temp\RarSFX0\HyCam2.exe" -installC:\Users\admin\AppData\Local\Temp\RarSFX0\HyCam2.exe
HC2Setup.exe
User:
admin
Company:
Hyperionics
Integrity Level:
HIGH
Description:
HyperCam
Exit code:
0
Version:
2, 14, 1, 0
Modules
Images
c:\users\admin\appdata\local\temp\rarsfx0\hycam2.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\winmm.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2536"C:\Users\admin\AppData\Local\Temp\RarSFX0\HyCam2.exe" -installC:\Users\admin\AppData\Local\Temp\RarSFX0\HyCam2.exeHC2Setup.exe
User:
admin
Company:
Hyperionics
Integrity Level:
HIGH
Description:
HyperCam
Version:
2, 14, 1, 0
Modules
Images
c:\users\admin\appdata\local\temp\rarsfx0\hycam2.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\winmm.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2624"C:\Users\admin\Desktop\HC2Setup.exe" C:\Users\admin\Desktop\HC2Setup.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\desktop\hc2setup.exe
c:\windows\system32\ntdll.dll
3064"C:\Users\admin\Desktop\HC2Setup.exe" C:\Users\admin\Desktop\HC2Setup.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\desktop\hc2setup.exe
c:\windows\system32\ntdll.dll
Total events
1 022
Read events
1 004
Write events
18
Delete events
0

Modification events

(PID) Process:(1748) HC2Setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(1748) HC2Setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(1748) HC2Setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(1748) HC2Setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(1864) HyCam2.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\HyperCam 2
Operation:writeName:DisplayName
Value:
HyperCam 2
(PID) Process:(1864) HyCam2.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\HyperCam 2
Operation:writeName:UninstallString
Value:
"C:\Program Files\HyCam2\UnHyCam2.exe"
(PID) Process:(288) HC2Setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(288) HC2Setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(288) HC2Setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(288) HC2Setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
Executable files
12
Suspicious files
61
Text files
9
Unknown types
0

Dropped files

PID
Process
Filename
Type
1748HC2Setup.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\8-8000u.wavbinary
MD5:D6A10FFAB0437CB757CA0DD098B8B3A7
SHA256:F3B90092A7F0313D5D0B97AD470CE6D68AA4F4780B18D39560A4988520F4C849
1748HC2Setup.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\8-11025d.wavbinary
MD5:A8BBF1676207514D90693EE2FB0364F8
SHA256:D6A44B57B047E4FBCF4886A713CC5143AF065D157FD4972334DD7B5861798FE5
1748HC2Setup.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\8-8000d.wavbinary
MD5:1912519EA64D50843AE9084D37E8A0C1
SHA256:5F8D2BDA27A1036902C82778FF4C947AC57D63D558C1D6F0AA4B168489774538
1748HC2Setup.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\16-11025d.wavbinary
MD5:C61B97FDEA6DE3AC4EC0DCAB8EDA621C
SHA256:15F65320D89520A615CFDBF952742B3FB9E2466F84794A18433AFD743C3C8709
1748HC2Setup.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\16-22050d.wavbinary
MD5:E00C8AE722FD731A639F34571375ADB1
SHA256:60C7BC95E033888F55022B12C9D9BAD16FC458B9E499515B2223FDF2D4F8E741
1748HC2Setup.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\8-11025u.wavbinary
MD5:C928167AE840C4D092D2D11157458B72
SHA256:C1D1F055679140D002EEADCD16FD2D72FA6BDC03E0649520E1CF4EEEA6182EF7
1748HC2Setup.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\8-44100d.wavbinary
MD5:38A775466B8DC0A1F2D7E04F34F72BD9
SHA256:FF20BEF1BA7566685B22F5F92DD215178A312DB97DA4C6C743585405F5C040ED
1748HC2Setup.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\16-22050u.wavbinary
MD5:76F42715F524FB2110CA845520E101D8
SHA256:3B393414011D7CCF8A1EB588C3FFD627105EB33E9660D5BDC050455B3C7A215A
1748HC2Setup.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\16-44100d.wavbinary
MD5:77F67F35EE1E4F5BF4F76CCC072550BE
SHA256:46F00FEF0CEBE38DEEFBBA59F859B4A72906FA4A894DB552B0AFDB213C61FCFE
1748HC2Setup.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\8-22050u.wavbinary
MD5:BF39380290ED50079B752A2593B9A50D
SHA256:C809DB4B1D49BB7F70A1E91FA8769563BD1E2BEFF8EC979B881713CD55FF99E9
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
5
DNS requests
1
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
224.0.0.252:5355
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.186.110
whitelisted

Threats

No threats detected
No debug info