File name:

vs_BuildTools.exe

Full analysis: https://app.any.run/tasks/e1d98c40-88b9-4213-9693-4384482ef4aa
Verdict: Malicious activity
Analysis date: September 06, 2024, 18:10:25
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
crypto-regex
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

E95EA545D65944F3FE4462DC69312694

SHA1:

6796279839C01946CB4B800D92D5355AA7C1C73D

SHA256:

751FC7138FACFE9A7D846945E4643FB592562964C2A3A4C6336B192D61913F5A

SSDEEP:

98304:OgxB3Dupa9JcAx30hoS4bMdqKR+km8IwyBPkH7XJCWBfVhDLcQJ5K6DRu4FiIepk:UAvqdhidyn

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Starts a Microsoft application from unusual location

      • vs_BuildTools.exe (PID: 5916)
    • Process drops legitimate windows executable

      • vs_BuildTools.exe (PID: 5916)
      • vs_setup_bootstrapper.exe (PID: 5700)
    • Reads security settings of Internet Explorer

      • vs_BuildTools.exe (PID: 5916)
      • vs_setup_bootstrapper.exe (PID: 5700)
      • setup.exe (PID: 5732)
    • Executable content was dropped or overwritten

      • vs_BuildTools.exe (PID: 5916)
      • vs_setup_bootstrapper.exe (PID: 5700)
    • The process drops C-runtime libraries

      • vs_setup_bootstrapper.exe (PID: 5700)
    • The process creates files with name similar to system file names

      • vs_setup_bootstrapper.exe (PID: 5700)
    • Found regular expressions for crypto-addresses (YARA)

      • vs_setup_bootstrapper.exe (PID: 5700)
    • Creates a software uninstall entry

      • vs_installer.windows.exe (PID: 6480)
    • Searches for installed software

      • vs_installer.windows.exe (PID: 6480)
  • INFO

    • Process checks computer location settings

      • vs_BuildTools.exe (PID: 5916)
    • The process uses the downloaded file

      • vs_BuildTools.exe (PID: 5916)
      • setup.exe (PID: 5732)
    • Checks supported languages

      • vs_BuildTools.exe (PID: 5916)
      • vs_setup_bootstrapper.exe (PID: 5700)
      • setup.exe (PID: 5732)
      • vs_installer.windows.exe (PID: 6480)
    • Reads the machine GUID from the registry

      • vs_BuildTools.exe (PID: 5916)
      • vs_setup_bootstrapper.exe (PID: 5700)
      • setup.exe (PID: 5732)
    • Reads the computer name

      • vs_BuildTools.exe (PID: 5916)
      • vs_setup_bootstrapper.exe (PID: 5700)
      • setup.exe (PID: 5732)
      • vs_installer.windows.exe (PID: 6480)
    • Create files in a temporary directory

      • vs_BuildTools.exe (PID: 5916)
      • vs_setup_bootstrapper.exe (PID: 5700)
      • setup.exe (PID: 5732)
    • Creates files in the program directory

      • vs_setup_bootstrapper.exe (PID: 5700)
      • setup.exe (PID: 5732)
    • Displays MAC addresses of computer network adapters

      • getmac.exe (PID: 5532)
    • Disables trace logs

      • vs_setup_bootstrapper.exe (PID: 5700)
      • setup.exe (PID: 5732)
    • Checks proxy server information

      • vs_setup_bootstrapper.exe (PID: 5700)
      • setup.exe (PID: 5732)
    • Reads CPU info

      • vs_setup_bootstrapper.exe (PID: 5700)
      • setup.exe (PID: 5732)
    • Reads the software policy settings

      • vs_setup_bootstrapper.exe (PID: 5700)
      • setup.exe (PID: 5732)
    • Creates files or folders in the user directory

      • vs_setup_bootstrapper.exe (PID: 5700)
      • setup.exe (PID: 5732)
    • Reads Environment values

      • setup.exe (PID: 5732)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable (generic) (52.9)
.exe | Generic Win/DOS Executable (23.5)
.exe | DOS Executable Generic (23.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:08:19 23:47:27+00:00
ImageFileCharacteristics: Executable, Large address aware, 32-bit
PEType: PE32
LinkerVersion: 14.16
CodeSize: 227328
InitializedDataSize: 199680
UninitializedDataSize: -
EntryPoint: 0x1dfd0
OSVersion: 5.1
ImageVersion: 10
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 17.11.35222.181
ProductVersionNumber: 17.11.35222.181
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Microsoft Corporation
FileDescription: Visual Studio Installer
FileVersion: 17.11.35222.181
InternalName: vs_buildtools.exe
OriginalFileName: vs_buildtools.exe
ProductName: Microsoft Visual Studio BuildTools
ProductVersion: Visual Studio 2022
LegalCopyright: © Microsoft Corporation. All rights reserved.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
137
Monitored processes
7
Malicious processes
3
Suspicious processes
1

Behavior graph

Click at the process to see the details
start vs_buildtools.exe THREAT vs_setup_bootstrapper.exe getmac.exe no specs conhost.exe no specs setup.exe vs_installer.windows.exe no specs conhost.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2768\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exevs_installer.windows.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
5124\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exegetmac.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
5532"getmac"C:\Windows\SysWOW64\getmac.exevs_setup_bootstrapper.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Displays NIC MAC information
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\getmac.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
5700"C:\Users\admin\AppData\Local\Temp\ed61ad5a2bb1f997d129dbb8ef2a\vs_bootstrapper_d15\vs_setup_bootstrapper.exe" --env "_SFX_CAB_EXE_PACKAGE:C:\Users\admin\AppData\Local\Temp\vs_BuildTools.exe _SFX_CAB_EXE_ORIGINALWORKINGDIR:C:\Users\admin\AppData\Local\Temp"C:\Users\admin\AppData\Local\Temp\ed61ad5a2bb1f997d129dbb8ef2a\vs_bootstrapper_d15\vs_setup_bootstrapper.exe
vs_BuildTools.exe
User:
admin
Company:
Microsoft
Integrity Level:
HIGH
Description:
Visual Studio Installer
Version:
3.11.2180.21897
Modules
Images
c:\users\admin\appdata\local\temp\ed61ad5a2bb1f997d129dbb8ef2a\vs_bootstrapper_d15\vs_setup_bootstrapper.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
5732"C:\Program Files (x86)\Microsoft Visual Studio\Installer\setup.exe" /finalizeInstall install --in "C:\ProgramData\Microsoft\VisualStudio\Packages\_bootstrapper\vs_setup_bootstrapper_202409061810390627.json" --locale en-US --activityId "05a3b5c4-58cd-447d-b39e-e183741f5196" --pipe "3c114f84-07ea-4b58-8ecd-c12b5a90f8a2"C:\Program Files (x86)\Microsoft Visual Studio\Installer\setup.exe
vs_setup_bootstrapper.exe
User:
admin
Company:
Microsoft
Integrity Level:
HIGH
Description:
Visual Studio Installer
Version:
3.11.2180.21897
Modules
Images
c:\program files (x86)\microsoft visual studio\installer\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
5916"C:\Users\admin\AppData\Local\Temp\vs_BuildTools.exe" C:\Users\admin\AppData\Local\Temp\vs_BuildTools.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Visual Studio Installer
Version:
17.11.35222.181
Modules
Images
c:\users\admin\appdata\local\temp\vs_buildtools.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\ole32.dll
6480"C:\Program Files (x86)\Microsoft Visual Studio\Installer\vs_installer.windows.exe" /finalizeinstall 6F320B93-EE3C-4826-85E0-ADF79F8D4C61 "Visual Studio Installer" "Microsoft Visual Studio Installer" 3.11.2180.21897 0 "C:\Program Files (x86)\Microsoft Visual Studio\Installer\setup.exe"C:\Program Files (x86)\Microsoft Visual Studio\Installer\vs_installer.windows.exesetup.exe
User:
admin
Company:
Microsoft
Integrity Level:
HIGH
Description:
Microsoft.VisualStudio.Installer.Windows
Exit code:
0
Version:
3.11.2180.21897
Modules
Images
c:\program files (x86)\microsoft visual studio\installer\vs_installer.windows.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
Total events
11 279
Read events
11 148
Write events
130
Delete events
1

Modification events

(PID) Process:(5700) vs_setup_bootstrapper.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\VisualStudio\Telemetry
Operation:writeName:UseCollector
Value:
0
(PID) Process:(5700) vs_setup_bootstrapper.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\VisualStudio\Telemetry\Default\v2
Operation:writeName:UseCollector
Value:
0
(PID) Process:(5700) vs_setup_bootstrapper.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\DeveloperTools
Operation:writeName:deviceid
Value:
0f1dcb50-d220-4895-886d-108ccde843e8
(PID) Process:(5700) vs_setup_bootstrapper.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\DeveloperTools\HardwareCache
Operation:writeName:Uuid
Value:
1d1fb0bb-21b9-4fc0-b017-a4dada231e17
(PID) Process:(5700) vs_setup_bootstrapper.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\DeveloperTools\HardwareCache
Operation:writeName:MachineGuid
Value:
bb926e54-e3ca-40fd-ae90-2764341e7792
(PID) Process:(5700) vs_setup_bootstrapper.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\DeveloperTools\HardwareCache
Operation:writeName:HardDriveSerialNumber
Value:
qm00001
(PID) Process:(5700) vs_setup_bootstrapper.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\vs_setup_bootstrapper_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(5700) vs_setup_bootstrapper.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\vs_setup_bootstrapper_RASAPI32
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(5700) vs_setup_bootstrapper.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\vs_setup_bootstrapper_RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(5700) vs_setup_bootstrapper.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\vs_setup_bootstrapper_RASAPI32
Operation:writeName:FileTracingMask
Value:
Executable files
447
Suspicious files
26
Text files
77
Unknown types
3

Dropped files

PID
Process
Filename
Type
5916vs_BuildTools.exeC:\Users\admin\AppData\Local\Temp\ed61ad5a2bb1f997d129dbb8ef2a\vs_bootstrapper_d15\HelpFile\1055\help.htmlhtml
MD5:C7B60E697671394781260D5B2CD21810
SHA256:CCF766B55CB0CC623F2705206A2AF04F2C83801580BC40A5AC20F644B814AB8F
5916vs_BuildTools.exeC:\Users\admin\AppData\Local\Temp\ed61ad5a2bb1f997d129dbb8ef2a\vs_bootstrapper_d15\HelpFile\1028\help.htmlhtml
MD5:EEAF8CBF54B4E891FF6BE38CF44E3814
SHA256:AAD5B2ACF30EB9C2DD35FF3B5C6C1A76CC4F1AE0AB6F382A635F5C329439F3AF
5916vs_BuildTools.exeC:\Users\admin\AppData\Local\Temp\ed61ad5a2bb1f997d129dbb8ef2a\vs_bootstrapper_d15\HelpFile\2052\help.htmlhtml
MD5:1BD86FBD65D005648103E050D9BEB9F1
SHA256:740117157B31BD5C634A232A0BA98A692B28ED2B4829EF52372200EB547D07CF
5916vs_BuildTools.exeC:\Users\admin\AppData\Local\Temp\ed61ad5a2bb1f997d129dbb8ef2a\vs_bootstrapper_d15\HelpFile\1033\help.htmlhtml
MD5:4F7415E811ACBDDED478B40C3E7B287E
SHA256:55846D86DBE60B1B663018D72BEFA0F53A61D34A4EB093563B93A41B2FAA34A5
5916vs_BuildTools.exeC:\Users\admin\AppData\Local\Temp\ed61ad5a2bb1f997d129dbb8ef2a\vs_bootstrapper_d15\HelpFile\1029\help.htmlhtml
MD5:432E50F4764D69625E5143571F823B6A
SHA256:C877FE7CD9544369A42A61B5C51264D74BFCA5B4BC5D4DD1FA703428261D6ABC
5916vs_BuildTools.exeC:\Users\admin\AppData\Local\Temp\ed61ad5a2bb1f997d129dbb8ef2a\vs_bootstrapper_d15\HelpFile\1040\help.htmlhtml
MD5:88289FD0D816A06C1A7B303397D0C122
SHA256:DF46CA96704CBEF3B79E0AA7A8B8239E7ACF12899B6C02A063F138C1F0F9FD34
5916vs_BuildTools.exeC:\Users\admin\AppData\Local\Temp\ed61ad5a2bb1f997d129dbb8ef2a\vs_bootstrapper_d15\HelpFile\1049\help.htmlhtml
MD5:66D963430209555CDCB8A5C0219BC60C
SHA256:D9AB0A8DB5A8409C5849AA4E1512576225E5B320EA79B0CDC83C2B4848401611
5916vs_BuildTools.exeC:\Users\admin\AppData\Local\Temp\ed61ad5a2bb1f997d129dbb8ef2a\vs_bootstrapper_d15\vs_setup_bootstrapper.exeexecutable
MD5:E24EF04DDB8A5474314D34CBD3FFA0C2
SHA256:49FC3EC8AB51C8F05591EE0FF0D9040BED994DBC3EF9A417A188C6D69A56952F
5916vs_BuildTools.exeC:\Users\admin\AppData\Local\Temp\ed61ad5a2bb1f997d129dbb8ef2a\vs_bootstrapper_d15\Microsoft.C2RSignatureReader.Interop.dllexecutable
MD5:6240940009ABE0240203A943741F22B2
SHA256:62D8143505B130E7DCD2488384C19827787F9370C132D0C05957E16C28C70447
5916vs_BuildTools.exeC:\Users\admin\AppData\Local\Temp\ed61ad5a2bb1f997d129dbb8ef2a\vs_bootstrapper_d15\HelpFile\3082\help.htmlhtml
MD5:0474106AC825B4F7727FF94576FC15C2
SHA256:A597AA82F35641455E12BD78662A05142F64BC221FF91D4EC4F2A8FA2983297F
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
8
TCP/UDP connections
54
DNS requests
28
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5700
vs_setup_bootstrapper.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicCodSigPCA2011_2011-07-08.crl
unknown
whitelisted
608
svchost.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
5700
vs_setup_bootstrapper.exe
GET
200
23.48.23.143:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut_2010-06-23.crl
unknown
whitelisted
5700
vs_setup_bootstrapper.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20Time-Stamp%20PCA%202010(1).crl
unknown
whitelisted
8
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6576
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
6576
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
5700
vs_setup_bootstrapper.exe
GET
200
23.48.23.143:80
http://crl.microsoft.com/pki/crl/products/MicCodSigPCA_2010-07-06.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
736
RUXIMICS.exe
40.127.240.158:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
2120
MoUsoCoreWorker.exe
40.127.240.158:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
4
System
192.168.100.255:138
whitelisted
608
svchost.exe
40.127.240.158:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
5700
vs_setup_bootstrapper.exe
152.199.19.161:443
az667904.vo.msecnd.net
EDGECAST
US
whitelisted
5700
vs_setup_bootstrapper.exe
23.213.170.81:443
go.microsoft.com
AKAMAI-AS
DE
whitelisted
5700
vs_setup_bootstrapper.exe
13.85.16.224:443
targetednotifications-tm.trafficmanager.net
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
608
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
608
svchost.exe
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
5700
vs_setup_bootstrapper.exe
2.22.34.124:443
aka.ms
AKAMAI-AS
IT
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.185.110
whitelisted
az667904.vo.msecnd.net
  • 152.199.19.161
whitelisted
go.microsoft.com
  • 23.213.170.81
  • 23.213.166.81
whitelisted
az700632.vo.msecnd.net
  • 152.199.19.161
whitelisted
targetednotifications-tm.trafficmanager.net
  • 13.85.16.224
whitelisted
settings-win.data.microsoft.com
  • 4.231.128.59
  • 51.104.136.2
whitelisted
www.microsoft.com
  • 23.35.229.160
whitelisted
aka.ms
  • 2.22.34.124
whitelisted
download.visualstudio.microsoft.com
  • 199.232.210.172
  • 199.232.214.172
  • 68.232.34.200
whitelisted
crl.microsoft.com
  • 23.48.23.143
  • 23.48.23.166
  • 23.48.23.156
whitelisted

Threats

No threats detected
No debug info