File name:

mt5setup.exe

Full analysis: https://app.any.run/tasks/fd883094-f92b-4888-a224-8c36dbedf433
Verdict: Malicious activity
Analysis date: August 10, 2024, 12:12:32
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32+ executable (GUI) x86-64, for MS Windows
MD5:

7ED7CCB90D83858AF616BDFE8CDB9DE5

SHA1:

C63C4660C98228A68FDBD974E6FB3920A7207136

SHA256:

6D4EFBE4076F271C6AE6704AEABE3DEB4C806BF28830FFE7C276DC81118EDDF8

SSDEEP:

98304:sK73/AXmmYiBXL0iPf91NsdKuQ4KL7Tc4o24qIWbMxTlFbZ9mIYT/P3RnuL9nl0Q:pTATvr40d8Rlob

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Drops the executable file immediately after the start

      • mt5setup.exe (PID: 6732)
    • Reads the BIOS version

      • mt5setup.exe (PID: 6732)
      • mt5setup.exe (PID: 6920)
    • Reads security settings of Internet Explorer

      • mt5setup.exe (PID: 6732)
      • mt5setup.exe (PID: 6920)
    • Reads the date of Windows installation

      • mt5setup.exe (PID: 6732)
    • Application launched itself

      • mt5setup.exe (PID: 6732)
    • Checks Windows Trust Settings

      • mt5setup.exe (PID: 6920)
    • Reads Internet Explorer settings

      • mt5setup.exe (PID: 6920)
  • INFO

    • Checks supported languages

      • mt5setup.exe (PID: 6732)
      • mt5setup.exe (PID: 6920)
    • Checks proxy server information

      • mt5setup.exe (PID: 6732)
      • mt5setup.exe (PID: 6920)
    • Reads Windows Product ID

      • mt5setup.exe (PID: 6732)
      • mt5setup.exe (PID: 6920)
    • Reads the computer name

      • mt5setup.exe (PID: 6732)
      • mt5setup.exe (PID: 6920)
    • Process checks whether UAC notifications are on

      • mt5setup.exe (PID: 6732)
    • Process checks computer location settings

      • mt5setup.exe (PID: 6732)
    • Creates files in the program directory

      • mt5setup.exe (PID: 6920)
    • Reads the machine GUID from the registry

      • mt5setup.exe (PID: 6920)
    • Reads CPU info

      • mt5setup.exe (PID: 6920)
    • Reads the software policy settings

      • mt5setup.exe (PID: 6920)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic Win/DOS Executable (50)
.exe | DOS Executable Generic (49.9)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 1970:02:25 16:19:12+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 14.38
CodeSize: 1473024
InitializedDataSize: 2500608
UninitializedDataSize: -
EntryPoint: 0x455275b
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 5.0.0.4434
ProductVersionNumber: 5.0.0.4434
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Dynamic link library
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: https://www.metaquotes.net
CompanyName: MetaQuotes Ltd.
FileDescription: Setup
FileVersion: 5.0.0.4434
InternalName: Setup
LegalCopyright: © 2000-2024, MetaQuotes Ltd.
LegalTrademarks: MetaTrader
OriginalFileName: Setup
ProductName: Setup
ProductVersion: 5.0.0.4434
No data.
screenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
114
Monitored processes
2
Malicious processes
0
Suspicious processes
2

Behavior graph

Click at the process to see the details
start mt5setup.exe mt5setup.exe

Process information

PID
CMD
Path
Indicators
Parent process
6732"C:\Users\admin\Downloads\mt5setup.exe" C:\Users\admin\Downloads\mt5setup.exe
explorer.exe
User:
admin
Company:
MetaQuotes Ltd.
Integrity Level:
MEDIUM
Description:
Setup
Exit code:
0
Version:
5.0.0.4434
Modules
Images
c:\users\admin\downloads\mt5setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
6920"C:\Users\admin\Downloads\mt5setup.exe" C:\Users\admin\Downloads\mt5setup.exe
mt5setup.exe
User:
admin
Company:
MetaQuotes Ltd.
Integrity Level:
HIGH
Description:
Setup
Exit code:
0
Version:
5.0.0.4434
Modules
Images
c:\users\admin\downloads\mt5setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
Total events
4 578
Read events
4 563
Write events
15
Delete events
0

Modification events

(PID) Process:(6732) mt5setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\MetaQuotes Software
Operation:writeName:VideoAdapters
Value:
(PID) Process:(6732) mt5setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\MetaQuotes Software
Operation:writeName:ID
Value:
4947265853815180089
(PID) Process:(6732) mt5setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\MetaQuotes Software
Operation:writeName:Install.Time
Value:
1723291961
(PID) Process:(6732) mt5setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(6732) mt5setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(6732) mt5setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(6732) mt5setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(6920) mt5setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\MetaQuotes Software
Operation:writeName:VideoAdapters
Value:
(PID) Process:(6920) mt5setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\MetaQuotes Software
Operation:writeName:ID
Value:
4947265853815180089
(PID) Process:(6920) mt5setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\MetaQuotes Software
Operation:writeName:AP.Time
Value:
1723291970
Executable files
0
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

No data
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
349
DNS requests
8
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3888
svchost.exe
239.255.255.250:1900
whitelisted
4056
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
6732
mt5setup.exe
78.140.180.43:443
download.mql5.com
Webzilla B.V.
NL
unknown
6920
mt5setup.exe
78.140.180.43:443
download.mql5.com
Webzilla B.V.
NL
unknown
6920
mt5setup.exe
78.140.180.86:443
content.finteza.com
Webzilla B.V.
NL
unknown
4
System
192.168.100.255:137
whitelisted
6920
mt5setup.exe
117.20.41.198:443
INTERNAP-BLK4
SG
unknown

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
  • 40.127.240.158
whitelisted
google.com
  • 142.250.185.78
whitelisted
download.mql5.com
  • 78.140.180.43
  • 195.201.80.82
whitelisted
download.metatrader.com
  • 78.140.180.43
  • 195.201.80.82
unknown
content.finteza.com
  • 78.140.180.86
unknown
content.mql5.com
  • 78.140.180.86
unknown

Threats

No threats detected
No debug info