File name:

mt5setup.exe

Full analysis: https://app.any.run/tasks/dc6e0cb9-29ad-43dc-98ea-2eb47a1a56ec
Verdict: Malicious activity
Analysis date: August 10, 2024, 12:10:41
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32+ executable (GUI) x86-64, for MS Windows
MD5:

7ED7CCB90D83858AF616BDFE8CDB9DE5

SHA1:

C63C4660C98228A68FDBD974E6FB3920A7207136

SHA256:

6D4EFBE4076F271C6AE6704AEABE3DEB4C806BF28830FFE7C276DC81118EDDF8

SSDEEP:

98304:sK73/AXmmYiBXL0iPf91NsdKuQ4KL7Tc4o24qIWbMxTlFbZ9mIYT/P3RnuL9nl0Q:pTATvr40d8Rlob

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads the BIOS version

      • mt5setup.exe (PID: 6728)
      • mt5setup.exe (PID: 6948)
    • Reads security settings of Internet Explorer

      • mt5setup.exe (PID: 6728)
      • mt5setup.exe (PID: 6948)
    • Reads the date of Windows installation

      • mt5setup.exe (PID: 6728)
    • Application launched itself

      • mt5setup.exe (PID: 6728)
    • Drops the executable file immediately after the start

      • mt5setup.exe (PID: 6728)
    • Checks Windows Trust Settings

      • mt5setup.exe (PID: 6948)
    • Reads Internet Explorer settings

      • mt5setup.exe (PID: 6948)
  • INFO

    • Checks proxy server information

      • mt5setup.exe (PID: 6728)
      • mt5setup.exe (PID: 6948)
    • Reads Windows Product ID

      • mt5setup.exe (PID: 6728)
      • mt5setup.exe (PID: 6948)
    • Process checks whether UAC notifications are on

      • mt5setup.exe (PID: 6728)
    • Reads the computer name

      • mt5setup.exe (PID: 6728)
      • mt5setup.exe (PID: 6948)
    • Checks supported languages

      • mt5setup.exe (PID: 6948)
      • mt5setup.exe (PID: 6728)
    • Process checks computer location settings

      • mt5setup.exe (PID: 6728)
    • Creates files in the program directory

      • mt5setup.exe (PID: 6948)
    • Reads the machine GUID from the registry

      • mt5setup.exe (PID: 6948)
    • Reads CPU info

      • mt5setup.exe (PID: 6948)
    • Reads the software policy settings

      • mt5setup.exe (PID: 6948)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic Win/DOS Executable (50)
.exe | DOS Executable Generic (49.9)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 1970:02:25 16:19:12+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 14.38
CodeSize: 1473024
InitializedDataSize: 2500608
UninitializedDataSize: -
EntryPoint: 0x455275b
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 5.0.0.4434
ProductVersionNumber: 5.0.0.4434
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Dynamic link library
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: https://www.metaquotes.net
CompanyName: MetaQuotes Ltd.
FileDescription: Setup
FileVersion: 5.0.0.4434
InternalName: Setup
LegalCopyright: © 2000-2024, MetaQuotes Ltd.
LegalTrademarks: MetaTrader
OriginalFileName: Setup
ProductName: Setup
ProductVersion: 5.0.0.4434
No data.
screenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
117
Monitored processes
2
Malicious processes
0
Suspicious processes
2

Behavior graph

Click at the process to see the details
start mt5setup.exe mt5setup.exe

Process information

PID
CMD
Path
Indicators
Parent process
6728"C:\Users\admin\AppData\Local\Temp\mt5setup.exe" C:\Users\admin\AppData\Local\Temp\mt5setup.exe
explorer.exe
User:
admin
Company:
MetaQuotes Ltd.
Integrity Level:
MEDIUM
Description:
Setup
Exit code:
0
Version:
5.0.0.4434
Modules
Images
c:\users\admin\appdata\local\temp\mt5setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
6948"C:\Users\admin\AppData\Local\Temp\mt5setup.exe" C:\Users\admin\AppData\Local\Temp\mt5setup.exe
mt5setup.exe
User:
admin
Company:
MetaQuotes Ltd.
Integrity Level:
HIGH
Description:
Setup
Exit code:
0
Version:
5.0.0.4434
Modules
Images
c:\users\admin\appdata\local\temp\mt5setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
Total events
7 232
Read events
7 217
Write events
15
Delete events
0

Modification events

(PID) Process:(6728) mt5setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\MetaQuotes Software
Operation:writeName:VideoAdapters
Value:
(PID) Process:(6728) mt5setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\MetaQuotes Software
Operation:writeName:ID
Value:
5010828105620835017
(PID) Process:(6728) mt5setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\MetaQuotes Software
Operation:writeName:Install.Time
Value:
1723291849
(PID) Process:(6728) mt5setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(6728) mt5setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(6728) mt5setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(6728) mt5setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(6948) mt5setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\MetaQuotes Software
Operation:writeName:VideoAdapters
Value:
(PID) Process:(6948) mt5setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\MetaQuotes Software
Operation:writeName:ID
Value:
5010828105620835017
(PID) Process:(6948) mt5setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\MetaQuotes Software
Operation:writeName:AP.Time
Value:
1723291869
Executable files
0
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

No data
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
347
DNS requests
8
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
3140
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
3888
svchost.exe
239.255.255.250:1900
whitelisted
4324
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
6728
mt5setup.exe
78.140.180.43:443
download.mql5.com
Webzilla B.V.
NL
unknown
6948
mt5setup.exe
78.140.180.43:443
download.mql5.com
Webzilla B.V.
NL
unknown
6948
mt5setup.exe
78.140.180.86:443
content.finteza.com
Webzilla B.V.
NL
unknown
6948
mt5setup.exe
88.212.232.132:443
United Network LLC
RU
unknown
6948
mt5setup.exe
117.20.41.198:443
INTERNAP-BLK4
SG
unknown

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 51.124.78.146
whitelisted
google.com
  • 142.250.186.142
whitelisted
download.mql5.com
  • 78.140.180.43
  • 195.201.80.82
whitelisted
download.metatrader.com
  • 78.140.180.43
  • 195.201.80.82
unknown
content.finteza.com
  • 78.140.180.86
unknown
content.mql5.com
  • 78.140.180.86
unknown

Threats

No threats detected
No debug info