File name:

vs_BuildTools.exe

Full analysis: https://app.any.run/tasks/e1d98c40-88b9-4213-9693-4384482ef4aa
Verdict: Malicious activity
Analysis date: September 06, 2024, 18:10:25
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
crypto-regex
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

E95EA545D65944F3FE4462DC69312694

SHA1:

6796279839C01946CB4B800D92D5355AA7C1C73D

SHA256:

751FC7138FACFE9A7D846945E4643FB592562964C2A3A4C6336B192D61913F5A

SSDEEP:

98304:OgxB3Dupa9JcAx30hoS4bMdqKR+km8IwyBPkH7XJCWBfVhDLcQJ5K6DRu4FiIepk:UAvqdhidyn

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • vs_BuildTools.exe (PID: 5916)
      • vs_setup_bootstrapper.exe (PID: 5700)
    • Reads security settings of Internet Explorer

      • vs_BuildTools.exe (PID: 5916)
      • vs_setup_bootstrapper.exe (PID: 5700)
      • setup.exe (PID: 5732)
    • Executable content was dropped or overwritten

      • vs_BuildTools.exe (PID: 5916)
      • vs_setup_bootstrapper.exe (PID: 5700)
    • Starts a Microsoft application from unusual location

      • vs_BuildTools.exe (PID: 5916)
    • The process drops C-runtime libraries

      • vs_setup_bootstrapper.exe (PID: 5700)
    • The process creates files with name similar to system file names

      • vs_setup_bootstrapper.exe (PID: 5700)
    • Creates a software uninstall entry

      • vs_installer.windows.exe (PID: 6480)
    • Searches for installed software

      • vs_installer.windows.exe (PID: 6480)
    • Found regular expressions for crypto-addresses (YARA)

      • vs_setup_bootstrapper.exe (PID: 5700)
  • INFO

    • Checks supported languages

      • vs_BuildTools.exe (PID: 5916)
      • vs_setup_bootstrapper.exe (PID: 5700)
      • setup.exe (PID: 5732)
      • vs_installer.windows.exe (PID: 6480)
    • Reads the machine GUID from the registry

      • vs_BuildTools.exe (PID: 5916)
      • vs_setup_bootstrapper.exe (PID: 5700)
      • setup.exe (PID: 5732)
    • Displays MAC addresses of computer network adapters

      • getmac.exe (PID: 5532)
    • Reads the computer name

      • vs_BuildTools.exe (PID: 5916)
      • vs_setup_bootstrapper.exe (PID: 5700)
      • setup.exe (PID: 5732)
      • vs_installer.windows.exe (PID: 6480)
    • Create files in a temporary directory

      • vs_BuildTools.exe (PID: 5916)
      • vs_setup_bootstrapper.exe (PID: 5700)
      • setup.exe (PID: 5732)
    • The process uses the downloaded file

      • vs_BuildTools.exe (PID: 5916)
      • setup.exe (PID: 5732)
    • Process checks computer location settings

      • vs_BuildTools.exe (PID: 5916)
    • Reads CPU info

      • vs_setup_bootstrapper.exe (PID: 5700)
      • setup.exe (PID: 5732)
    • Disables trace logs

      • vs_setup_bootstrapper.exe (PID: 5700)
      • setup.exe (PID: 5732)
    • Creates files in the program directory

      • vs_setup_bootstrapper.exe (PID: 5700)
      • setup.exe (PID: 5732)
    • Checks proxy server information

      • vs_setup_bootstrapper.exe (PID: 5700)
      • setup.exe (PID: 5732)
    • Creates files or folders in the user directory

      • vs_setup_bootstrapper.exe (PID: 5700)
      • setup.exe (PID: 5732)
    • Reads the software policy settings

      • vs_setup_bootstrapper.exe (PID: 5700)
      • setup.exe (PID: 5732)
    • Reads Environment values

      • setup.exe (PID: 5732)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable (generic) (52.9)
.exe | Generic Win/DOS Executable (23.5)
.exe | DOS Executable Generic (23.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:08:19 23:47:27+00:00
ImageFileCharacteristics: Executable, Large address aware, 32-bit
PEType: PE32
LinkerVersion: 14.16
CodeSize: 227328
InitializedDataSize: 199680
UninitializedDataSize: -
EntryPoint: 0x1dfd0
OSVersion: 5.1
ImageVersion: 10
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 17.11.35222.181
ProductVersionNumber: 17.11.35222.181
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Microsoft Corporation
FileDescription: Visual Studio Installer
FileVersion: 17.11.35222.181
InternalName: vs_buildtools.exe
OriginalFileName: vs_buildtools.exe
ProductName: Microsoft Visual Studio BuildTools
ProductVersion: Visual Studio 2022
LegalCopyright: © Microsoft Corporation. All rights reserved.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
137
Monitored processes
7
Malicious processes
3
Suspicious processes
1

Behavior graph

Click at the process to see the details
start vs_buildtools.exe THREAT vs_setup_bootstrapper.exe getmac.exe no specs conhost.exe no specs setup.exe vs_installer.windows.exe no specs conhost.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2768\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exevs_installer.windows.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
5124\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exegetmac.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
5532"getmac"C:\Windows\SysWOW64\getmac.exevs_setup_bootstrapper.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Displays NIC MAC information
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\getmac.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
5700"C:\Users\admin\AppData\Local\Temp\ed61ad5a2bb1f997d129dbb8ef2a\vs_bootstrapper_d15\vs_setup_bootstrapper.exe" --env "_SFX_CAB_EXE_PACKAGE:C:\Users\admin\AppData\Local\Temp\vs_BuildTools.exe _SFX_CAB_EXE_ORIGINALWORKINGDIR:C:\Users\admin\AppData\Local\Temp"C:\Users\admin\AppData\Local\Temp\ed61ad5a2bb1f997d129dbb8ef2a\vs_bootstrapper_d15\vs_setup_bootstrapper.exe
vs_BuildTools.exe
User:
admin
Company:
Microsoft
Integrity Level:
HIGH
Description:
Visual Studio Installer
Version:
3.11.2180.21897
Modules
Images
c:\users\admin\appdata\local\temp\ed61ad5a2bb1f997d129dbb8ef2a\vs_bootstrapper_d15\vs_setup_bootstrapper.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
5732"C:\Program Files (x86)\Microsoft Visual Studio\Installer\setup.exe" /finalizeInstall install --in "C:\ProgramData\Microsoft\VisualStudio\Packages\_bootstrapper\vs_setup_bootstrapper_202409061810390627.json" --locale en-US --activityId "05a3b5c4-58cd-447d-b39e-e183741f5196" --pipe "3c114f84-07ea-4b58-8ecd-c12b5a90f8a2"C:\Program Files (x86)\Microsoft Visual Studio\Installer\setup.exe
vs_setup_bootstrapper.exe
User:
admin
Company:
Microsoft
Integrity Level:
HIGH
Description:
Visual Studio Installer
Version:
3.11.2180.21897
Modules
Images
c:\program files (x86)\microsoft visual studio\installer\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
5916"C:\Users\admin\AppData\Local\Temp\vs_BuildTools.exe" C:\Users\admin\AppData\Local\Temp\vs_BuildTools.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Visual Studio Installer
Version:
17.11.35222.181
Modules
Images
c:\users\admin\appdata\local\temp\vs_buildtools.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\ole32.dll
6480"C:\Program Files (x86)\Microsoft Visual Studio\Installer\vs_installer.windows.exe" /finalizeinstall 6F320B93-EE3C-4826-85E0-ADF79F8D4C61 "Visual Studio Installer" "Microsoft Visual Studio Installer" 3.11.2180.21897 0 "C:\Program Files (x86)\Microsoft Visual Studio\Installer\setup.exe"C:\Program Files (x86)\Microsoft Visual Studio\Installer\vs_installer.windows.exesetup.exe
User:
admin
Company:
Microsoft
Integrity Level:
HIGH
Description:
Microsoft.VisualStudio.Installer.Windows
Exit code:
0
Version:
3.11.2180.21897
Modules
Images
c:\program files (x86)\microsoft visual studio\installer\vs_installer.windows.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
Total events
11 279
Read events
11 148
Write events
130
Delete events
1

Modification events

(PID) Process:(5700) vs_setup_bootstrapper.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\VisualStudio\Telemetry
Operation:writeName:UseCollector
Value:
0
(PID) Process:(5700) vs_setup_bootstrapper.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\VisualStudio\Telemetry\Default\v2
Operation:writeName:UseCollector
Value:
0
(PID) Process:(5700) vs_setup_bootstrapper.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\DeveloperTools
Operation:writeName:deviceid
Value:
0f1dcb50-d220-4895-886d-108ccde843e8
(PID) Process:(5700) vs_setup_bootstrapper.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\DeveloperTools\HardwareCache
Operation:writeName:Uuid
Value:
1d1fb0bb-21b9-4fc0-b017-a4dada231e17
(PID) Process:(5700) vs_setup_bootstrapper.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\DeveloperTools\HardwareCache
Operation:writeName:MachineGuid
Value:
bb926e54-e3ca-40fd-ae90-2764341e7792
(PID) Process:(5700) vs_setup_bootstrapper.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\DeveloperTools\HardwareCache
Operation:writeName:HardDriveSerialNumber
Value:
qm00001
(PID) Process:(5700) vs_setup_bootstrapper.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\vs_setup_bootstrapper_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(5700) vs_setup_bootstrapper.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\vs_setup_bootstrapper_RASAPI32
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(5700) vs_setup_bootstrapper.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\vs_setup_bootstrapper_RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(5700) vs_setup_bootstrapper.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\vs_setup_bootstrapper_RASAPI32
Operation:writeName:FileTracingMask
Value:
Executable files
447
Suspicious files
26
Text files
77
Unknown types
3

Dropped files

PID
Process
Filename
Type
5916vs_BuildTools.exeC:\Users\admin\AppData\Local\Temp\ed61ad5a2bb1f997d129dbb8ef2a\vs_bootstrapper_d15\Microsoft.C2RSignatureReader.Interop.dllexecutable
MD5:6240940009ABE0240203A943741F22B2
SHA256:62D8143505B130E7DCD2488384C19827787F9370C132D0C05957E16C28C70447
5916vs_BuildTools.exeC:\Users\admin\AppData\Local\Temp\ed61ad5a2bb1f997d129dbb8ef2a\vs_bootstrapper_d15\HelpFile\1040\help.htmlhtml
MD5:88289FD0D816A06C1A7B303397D0C122
SHA256:DF46CA96704CBEF3B79E0AA7A8B8239E7ACF12899B6C02A063F138C1F0F9FD34
5916vs_BuildTools.exeC:\Users\admin\AppData\Local\Temp\ed61ad5a2bb1f997d129dbb8ef2a\vs_bootstrapper_d15\HelpFile\2052\help.htmlhtml
MD5:1BD86FBD65D005648103E050D9BEB9F1
SHA256:740117157B31BD5C634A232A0BA98A692B28ED2B4829EF52372200EB547D07CF
5916vs_BuildTools.exeC:\Users\admin\AppData\Local\Temp\ed61ad5a2bb1f997d129dbb8ef2a\vs_bootstrapper_d15\HelpFile\1029\help.htmlhtml
MD5:432E50F4764D69625E5143571F823B6A
SHA256:C877FE7CD9544369A42A61B5C51264D74BFCA5B4BC5D4DD1FA703428261D6ABC
5916vs_BuildTools.exeC:\Users\admin\AppData\Local\Temp\ed61ad5a2bb1f997d129dbb8ef2a\vs_bootstrapper_d15\Microsoft.Identity.Client.Extensions.Msal.dllexecutable
MD5:352EE196CD65C98B729065AAF6F5C9E3
SHA256:6CEAA8B598E7985D5637AB1659566DFF9C1FDA37EDF0F044759B56444F739018
5916vs_BuildTools.exeC:\Users\admin\AppData\Local\Temp\ed61ad5a2bb1f997d129dbb8ef2a\vs_bootstrapper_d15\HelpFile\1042\help.htmlhtml
MD5:8125E76142C8438863F35CE5B8E63E57
SHA256:929A97C8A9A4EA4F72E2F17DBB20E76E604B7F1255F20874AA1C44AEC0F456C1
5916vs_BuildTools.exeC:\Users\admin\AppData\Local\Temp\ed61ad5a2bb1f997d129dbb8ef2a\vs_bootstrapper_d15\Microsoft.Identity.Client.dllexecutable
MD5:5B4952B8D74C11BBD787E480595012D4
SHA256:BCAA10EDE80BD7FC552F6C685DD5528A99BEAC2E2A60C5906D979FA6200127C5
5916vs_BuildTools.exeC:\Users\admin\AppData\Local\Temp\ed61ad5a2bb1f997d129dbb8ef2a\vs_bootstrapper_d15\HelpFile\1055\help.htmlhtml
MD5:C7B60E697671394781260D5B2CD21810
SHA256:CCF766B55CB0CC623F2705206A2AF04F2C83801580BC40A5AC20F644B814AB8F
5916vs_BuildTools.exeC:\Users\admin\AppData\Local\Temp\ed61ad5a2bb1f997d129dbb8ef2a\vs_bootstrapper_d15\HelpFile\1045\help.htmlhtml
MD5:9147BC24EACE34955B865DAA39DAD8AB
SHA256:322DB9FFDB987D0C824A4DE3B8DB40722BCAF95833DCF90E7B5F250A841E592B
5916vs_BuildTools.exeC:\Users\admin\AppData\Local\Temp\ed61ad5a2bb1f997d129dbb8ef2a\vs_bootstrapper_d15\Microsoft.Identity.Client.Broker.dllexecutable
MD5:0616C47711CD8E496DE1CDF7A37DCED9
SHA256:2F8F83D478736EDDF80D531B5772AF61D4F70FBFADA671C9EC3D16E1CEBD7EF3
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
8
TCP/UDP connections
54
DNS requests
28
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
608
svchost.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
5700
vs_setup_bootstrapper.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicCodSigPCA2011_2011-07-08.crl
unknown
whitelisted
5700
vs_setup_bootstrapper.exe
GET
200
23.48.23.143:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut_2010-06-23.crl
unknown
whitelisted
8
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
5700
vs_setup_bootstrapper.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20Time-Stamp%20PCA%202010(1).crl
unknown
whitelisted
6576
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
6576
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
5700
vs_setup_bootstrapper.exe
GET
200
23.48.23.143:80
http://crl.microsoft.com/pki/crl/products/MicCodSigPCA_2010-07-06.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
736
RUXIMICS.exe
40.127.240.158:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
2120
MoUsoCoreWorker.exe
40.127.240.158:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
4
System
192.168.100.255:138
whitelisted
608
svchost.exe
40.127.240.158:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
5700
vs_setup_bootstrapper.exe
152.199.19.161:443
az667904.vo.msecnd.net
EDGECAST
US
whitelisted
5700
vs_setup_bootstrapper.exe
23.213.170.81:443
go.microsoft.com
AKAMAI-AS
DE
whitelisted
5700
vs_setup_bootstrapper.exe
13.85.16.224:443
targetednotifications-tm.trafficmanager.net
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
608
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
608
svchost.exe
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
5700
vs_setup_bootstrapper.exe
2.22.34.124:443
aka.ms
AKAMAI-AS
IT
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.185.110
whitelisted
az667904.vo.msecnd.net
  • 152.199.19.161
whitelisted
go.microsoft.com
  • 23.213.170.81
  • 23.213.166.81
whitelisted
az700632.vo.msecnd.net
  • 152.199.19.161
whitelisted
targetednotifications-tm.trafficmanager.net
  • 13.85.16.224
whitelisted
settings-win.data.microsoft.com
  • 4.231.128.59
  • 51.104.136.2
whitelisted
www.microsoft.com
  • 23.35.229.160
whitelisted
aka.ms
  • 2.22.34.124
whitelisted
download.visualstudio.microsoft.com
  • 199.232.210.172
  • 199.232.214.172
  • 68.232.34.200
whitelisted
crl.microsoft.com
  • 23.48.23.143
  • 23.48.23.166
  • 23.48.23.156
whitelisted

Threats

No threats detected
No debug info