| File name: | MEmuSetup.exe |
| Full analysis: | https://app.any.run/tasks/ef5edf4f-6946-4010-815d-35ec29d506bc |
| Verdict: | Malicious activity |
| Analysis date: | April 22, 2024, 08:47:23 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive |
| MD5: | A017A267684609D270A093416DC766C4 |
| SHA1: | 300EAC0B72D0D4D8F1DB4778DC7792B8E4245838 |
| SHA256: | 6B8335AEB7947C8F901D6A96827AD18094CC03C7FBE6E9535D7122805D415CFE |
| SSDEEP: | 98304:/iU+P96j5KNIWbNvqpws+66z0QgLX7r4K91+mLLO7xH19iGG28j3t/ti9UYlSWee:lUtJh2+m0b0ID+9pBCCznm/KtQ |
| .exe | | | Win32 Executable MS Visual C++ (generic) (67.4) |
|---|---|---|
| .dll | | | Win32 Dynamic Link Library (generic) (14.2) |
| .exe | | | Win32 Executable (generic) (9.7) |
| .exe | | | Generic Win/DOS Executable (4.3) |
| .exe | | | DOS Executable Generic (4.3) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2023:07:02 02:09:48+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 27136 |
| InitializedDataSize: | 184832 |
| UninitializedDataSize: | 2048 |
| EntryPoint: | 0x3532 |
| OSVersion: | 4 |
| ImageVersion: | 6 |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1424 | C:\Users\admin\AppData\Local\Temp\nsjDD7C.tmp\p30b90d.exe | C:\Users\admin\AppData\Local\Temp\nsjDD7C.tmp\p30b90d.exe | MEmuSetup.exe | ||||||||||||
User: admin Company: Microvirt Software Technology Co. Ltd. Integrity Level: HIGH Description: MEmu Installer Version: 9.0.0.0 Modules
| |||||||||||||||
| 3416 | "C:\Users\admin\AppData\Local\Temp\MEmuSetup.exe" | C:\Users\admin\AppData\Local\Temp\MEmuSetup.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 3221226540 Modules
| |||||||||||||||
| 3664 | "C:\Users\admin\AppData\Local\Temp\MEmuSetup.exe" | C:\Users\admin\AppData\Local\Temp\MEmuSetup.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 2 Modules
| |||||||||||||||
| (PID) Process: | (3664) MEmuSetup.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager |
| Operation: | write | Name: | PendingFileRenameOperations |
Value: \??\C:\Users\admin\AppData\Local\Temp\nsjDD7C.tmp\p30b90d.exe | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1424 | p30b90d.exe | C:\Program Files\Microvirt\tempDir\Setup.exe.setting.gq1424 | — | |
MD5:— | SHA256:— | |||
| 1424 | p30b90d.exe | C:\Program Files\Microvirt\tempDir\Setup.exe.setting | — | |
MD5:— | SHA256:— | |||
| 1424 | p30b90d.exe | C:\Program Files\Microvirt\tempDir\Setup.exe.setting.em1424 | — | |
MD5:— | SHA256:— | |||
| 1424 | p30b90d.exe | C:\Program Files\Microvirt\tempDir\Setup.exe.setting.Xd1424 | — | |
MD5:— | SHA256:— | |||
| 1424 | p30b90d.exe | C:\Program Files\Microvirt\tempDir\Setup.exe.setting.Gg1424 | — | |
MD5:— | SHA256:— | |||
| 1424 | p30b90d.exe | C:\Program Files\Microvirt\tempDir\Setup.exe.setting.qn1424 | — | |
MD5:— | SHA256:— | |||
| 1424 | p30b90d.exe | C:\Program Files\Microvirt\tempDir\Setup.exe.setting.wx1424 | — | |
MD5:— | SHA256:— | |||
| 1424 | p30b90d.exe | C:\Program Files\Microvirt\tempDir\Setup.exe.setting.nf1424 | — | |
MD5:— | SHA256:— | |||
| 1424 | p30b90d.exe | C:\Program Files\Microvirt\tempDir\Setup.exe.setting.Of1424 | — | |
MD5:— | SHA256:— | |||
| 1424 | p30b90d.exe | C:\Program Files\Microvirt\tempDir\Setup.exe.setting.vz1424 | — | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
1424 | p30b90d.exe | HEAD | 200 | 18.245.31.108:80 | http://dl.memuplay.com/download/MEmu-Setup-9.1.2.0-ha8edcb97c.exe | unknown | — | — | unknown |
1424 | p30b90d.exe | GET | — | 18.245.31.108:80 | http://dl.memuplay.com/download/MEmu-Setup-9.1.2.0-ha8edcb97c.exe | unknown | — | — | unknown |
1424 | p30b90d.exe | GET | 200 | 13.224.194.85:80 | http://d1s13cf1vqydcj.cloudfront.net/installer/394543/624398141519 | unknown | — | — | unknown |
1424 | p30b90d.exe | GET | 200 | 185.23.181.28:80 | http://stat.microvirt.com/new_market/service.php?action=postmemusetupinfo&table=memusetupinfo&packageName=p30b90d&insMode=ins&version=1.0.1.0&channel=cd5e1e00&silence=0&currPage=StepStart&lifeCycle=0&exitCode=0&mac=12:A9:86:6C:77:DE&error=&initTime=0&initTime=0&acceptCount=-1&declineCount=-1&installOffers=-1 | unknown | — | — | unknown |
1424 | p30b90d.exe | GET | 200 | 185.23.181.28:80 | http://stat.microvirt.com/new_market/service.php?action=postmemusetupinfo&table=memusetupinfo&packageName=p30b90d&insMode=ins&version=1.0.1.0&channel=cd5e1e00&silence=0&currPage=ShowWelcomePage&lifeCycle=0&exitCode=0&mac=12:A9:86:6C:77:DE&error=&initTime=0&initTime=0&acceptCount=-1&declineCount=-1&installOffers=-1 | unknown | — | — | unknown |
1424 | p30b90d.exe | GET | 200 | 185.23.181.28:80 | http://stat.microvirt.com/new_market/service.php?action=postmemusetupinfo&table=memusetupinfo&packageName=p30b90d&insMode=ins&version=1.0.1.0&channel=cd5e1e00&silence=0&currPage=ShowInstallPage&lifeCycle=0&exitCode=0&mac=12:A9:86:6C:77:DE&error=&initTime=0&initTime=0&acceptCount=-1&declineCount=-1&installOffers=-1 | unknown | — | — | unknown |
1424 | p30b90d.exe | GET | 200 | 185.23.181.26:80 | http://www.microvirt.com/new_market/service.php?action=getrelease&abroad=1&channel= | unknown | — | — | unknown |
1424 | p30b90d.exe | GET | 200 | 185.23.181.28:80 | http://stat.microvirt.com/new_market/service.php?action=postmemusetupinfo&table=memusetupinfo&packageName=p30b90d&insMode=ins&version=1.0.1.0&channel=cd5e1e00&silence=0&currPage=ClickInstallBtn&lifeCycle=0&exitCode=0&mac=12:A9:86:6C:77:DE&error=&initTime=0&initTime=0&acceptCount=-1&declineCount=-1&installOffers=-1 | unknown | — | — | unknown |
1424 | p30b90d.exe | GET | 302 | 18.66.122.33:80 | http://www.memuplay.com/download-en.php?file_name=MEmu-Setup-9.1.2.0-ha8edcb97c&from=offline_installer | unknown | — | — | unknown |
1424 | p30b90d.exe | GET | 200 | 185.23.181.28:80 | http://stat.microvirt.com/new_market/service.php?action=postmemusetupinfo&table=memusetupinfo&packageName=p30b90d&insMode=ins&version=1.0.1.0&channel=cd5e1e00&silence=0&currPage=ShowStartDownloadPackage&lifeCycle=0&exitCode=0&mac=12:A9:86:6C:77:DE&error=&initTime=0&initTime=0&acceptCount=-1&declineCount=-1&installOffers=0 | unknown | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
— | — | 224.0.0.252:5355 | — | — | — | unknown |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
1424 | p30b90d.exe | 13.224.194.85:80 | d1s13cf1vqydcj.cloudfront.net | AMAZON-02 | US | whitelisted |
1424 | p30b90d.exe | 185.23.181.28:80 | stat.microvirt.com | Kaopu Cloud HK Limited | DE | unknown |
1424 | p30b90d.exe | 185.23.181.26:80 | stat.microvirt.com | Kaopu Cloud HK Limited | DE | unknown |
1424 | p30b90d.exe | 18.66.122.33:80 | www.memuplay.com | AMAZON-02 | US | unknown |
1424 | p30b90d.exe | 18.245.31.108:80 | dl.memuplay.com | — | US | unknown |
Domain | IP | Reputation |
|---|---|---|
stat.microvirt.com |
| unknown |
d1s13cf1vqydcj.cloudfront.net |
| unknown |
www.microvirt.com |
| unknown |
www.memuplay.com |
| unknown |
dl.memuplay.com |
| unknown |
PID | Process | Class | Message |
|---|---|---|---|
1424 | p30b90d.exe | Potential Corporate Privacy Violation | ET POLICY PE EXE or DLL Windows file download HTTP |
Process | Message |
|---|---|
p30b90d.exe | QObject::connect: No such signal QNetworkReplyHttpImpl::error()
|
p30b90d.exe | QWindowsWindow::setGeometryDp: Unable to set geometry 21x14+320+106 on QWidgetWindow/'QCheckBoxClassWindow'. Resulting geometry: 104x14+320+106 (frame: 4, 23, 4, 4, custom margin: 0, 0, 0, 0, minimum size: 0x0, maximum size: 16777215x16777215).
|
p30b90d.exe | QWindowsWindow::setGeometryDp: Unable to set geometry 55x14+320+106 on QWidgetWindow/'QLabelClassWindow'. Resulting geometry: 104x14+320+106 (frame: 4, 23, 4, 4, custom margin: 0, 0, 0, 0, minimum size: 0x0, maximum size: 16777215x16777215).
|
p30b90d.exe | QWindowsWindow::setGeometryDp: Unable to set geometry 21x14+320+106 on QWidgetWindow/'QCheckBoxClassWindow'. Resulting geometry: 104x14+320+106 (frame: 4, 23, 4, 4, custom margin: 0, 0, 0, 0, minimum size: 0x0, maximum size: 16777215x16777215).
|
p30b90d.exe | QWindowsWindow::setGeometryDp: Unable to set geometry 66x14+320+106 on QWidgetWindow/'QLabelClassWindow'. Resulting geometry: 104x14+320+106 (frame: 4, 23, 4, 4, custom margin: 0, 0, 0, 0, minimum size: 0x0, maximum size: 16777215x16777215).
|
p30b90d.exe | QObject::connect: No such signal QNetworkReplyHttpImpl::error()
|
p30b90d.exe | QObject::connect: No such signal QNetworkReplyHttpImpl::error()
|
p30b90d.exe | QObject::killTimer: Timers cannot be stopped from another thread
|
p30b90d.exe | QObject::~QObject: Timers cannot be stopped from another thread
|
p30b90d.exe | QObject::killTimer: Timers cannot be stopped from another thread
|