File name:

7640282150d51c407ffdfe2fab35f2c60b93b0dc56ac93ad2459b16789aec61b.exe

Full analysis: https://app.any.run/tasks/1f234ae8-5302-4f29-b653-7d2c1862cd48
Verdict: Malicious activity
Analysis date: March 08, 2024, 14:38:21
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
evasion
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

A3A38DB6F62269ED7CEE99FABB676135

SHA1:

39F4958AE7481B2A3E7452C2DFFB648EA5E200BE

SHA256:

7640282150D51C407FFDFE2FAB35F2C60B93B0DC56AC93AD2459B16789AEC61B

SSDEEP:

393216:dwe/rgn0aBYxNYoW9L2r2cWIZAYv7P/lZgH7M3SRXcJNcjJ03uk3doSNGHpz:qo8ZaNYohScWIhr3ikcjG353/+pz

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • 7640282150d51c407ffdfe2fab35f2c60b93b0dc56ac93ad2459b16789aec61b.exe (PID: 2600)
      • 7640282150d51c407ffdfe2fab35f2c60b93b0dc56ac93ad2459b16789aec61b.exe (PID: 4424)
      • 7640282150d51c407ffdfe2fab35f2c60b93b0dc56ac93ad2459b16789aec61b.tmp (PID: 1548)
      • 7za.exe (PID: 6508)
      • SAMSUNG_USB_Driver_for_Mobile_Phones.exe (PID: 7372)
    • Detects Cygwin installation

      • 7za.exe (PID: 6508)
  • SUSPICIOUS

    • Reads the date of Windows installation

      • 7640282150d51c407ffdfe2fab35f2c60b93b0dc56ac93ad2459b16789aec61b.tmp (PID: 6096)
      • SamFwTool.exe (PID: 7144)
    • Reads security settings of Internet Explorer

      • 7640282150d51c407ffdfe2fab35f2c60b93b0dc56ac93ad2459b16789aec61b.tmp (PID: 6096)
      • SamFwTool.exe (PID: 7144)
      • SAMSUNG_USB_Driver_for_Mobile_Phones.exe (PID: 7372)
    • Executable content was dropped or overwritten

      • 7640282150d51c407ffdfe2fab35f2c60b93b0dc56ac93ad2459b16789aec61b.exe (PID: 2600)
      • 7640282150d51c407ffdfe2fab35f2c60b93b0dc56ac93ad2459b16789aec61b.exe (PID: 4424)
      • 7640282150d51c407ffdfe2fab35f2c60b93b0dc56ac93ad2459b16789aec61b.tmp (PID: 1548)
      • 7za.exe (PID: 6508)
      • SAMSUNG_USB_Driver_for_Mobile_Phones.exe (PID: 7372)
    • Reads the Windows owner or organization settings

      • 7640282150d51c407ffdfe2fab35f2c60b93b0dc56ac93ad2459b16789aec61b.tmp (PID: 1548)
    • Drops 7-zip archiver for unpacking

      • 7640282150d51c407ffdfe2fab35f2c60b93b0dc56ac93ad2459b16789aec61b.tmp (PID: 1548)
      • 7za.exe (PID: 6508)
    • Non-standard symbols in registry

      • 7640282150d51c407ffdfe2fab35f2c60b93b0dc56ac93ad2459b16789aec61b.tmp (PID: 1548)
    • Process drops legitimate windows executable

      • 7za.exe (PID: 6508)
      • SAMSUNG_USB_Driver_for_Mobile_Phones.exe (PID: 7372)
    • The process creates files with name similar to system file names

      • 7za.exe (PID: 6508)
    • Starts CMD.EXE for commands execution

      • SamFwTool.exe (PID: 7144)
    • Uses DRIVERQUERY.EXE to obtain a list of installed device drivers

      • cmd.exe (PID: 1976)
    • Reads Internet Explorer settings

      • SamFwTool.exe (PID: 7144)
    • Drops a system driver (possible attempt to evade defenses)

      • 7za.exe (PID: 6508)
      • SAMSUNG_USB_Driver_for_Mobile_Phones.exe (PID: 7372)
    • Checks for external IP

      • SamFwTool.exe (PID: 7144)
    • Checks Windows Trust Settings

      • SAMSUNG_USB_Driver_for_Mobile_Phones.exe (PID: 7372)
  • INFO

    • Create files in a temporary directory

      • 7640282150d51c407ffdfe2fab35f2c60b93b0dc56ac93ad2459b16789aec61b.exe (PID: 2600)
      • 7640282150d51c407ffdfe2fab35f2c60b93b0dc56ac93ad2459b16789aec61b.exe (PID: 4424)
      • 7640282150d51c407ffdfe2fab35f2c60b93b0dc56ac93ad2459b16789aec61b.tmp (PID: 1548)
      • SAMSUNG_USB_Driver_for_Mobile_Phones.exe (PID: 7372)
    • Checks supported languages

      • 7640282150d51c407ffdfe2fab35f2c60b93b0dc56ac93ad2459b16789aec61b.exe (PID: 2600)
      • 7640282150d51c407ffdfe2fab35f2c60b93b0dc56ac93ad2459b16789aec61b.tmp (PID: 6096)
      • 7640282150d51c407ffdfe2fab35f2c60b93b0dc56ac93ad2459b16789aec61b.exe (PID: 4424)
      • 7640282150d51c407ffdfe2fab35f2c60b93b0dc56ac93ad2459b16789aec61b.tmp (PID: 1548)
      • 7za.exe (PID: 6508)
      • SamFwTool.exe (PID: 7144)
      • identity_helper.exe (PID: 7616)
      • SAMSUNG_USB_Driver_for_Mobile_Phones.exe (PID: 7372)
      • Setup.exe (PID: 6256)
      • Setup.exe (PID: 2228)
    • Reads the computer name

      • 7640282150d51c407ffdfe2fab35f2c60b93b0dc56ac93ad2459b16789aec61b.tmp (PID: 6096)
      • 7640282150d51c407ffdfe2fab35f2c60b93b0dc56ac93ad2459b16789aec61b.tmp (PID: 1548)
      • 7za.exe (PID: 6508)
      • SamFwTool.exe (PID: 7144)
      • SAMSUNG_USB_Driver_for_Mobile_Phones.exe (PID: 7372)
      • identity_helper.exe (PID: 7616)
      • Setup.exe (PID: 6256)
      • Setup.exe (PID: 2228)
    • Process checks computer location settings

      • 7640282150d51c407ffdfe2fab35f2c60b93b0dc56ac93ad2459b16789aec61b.tmp (PID: 6096)
      • SamFwTool.exe (PID: 7144)
    • Creates a software uninstall entry

      • 7640282150d51c407ffdfe2fab35f2c60b93b0dc56ac93ad2459b16789aec61b.tmp (PID: 1548)
    • Creates files in the program directory

      • 7640282150d51c407ffdfe2fab35f2c60b93b0dc56ac93ad2459b16789aec61b.tmp (PID: 1548)
      • SamFwTool.exe (PID: 7144)
      • Setup.exe (PID: 6256)
    • Reads the machine GUID from the registry

      • SamFwTool.exe (PID: 7144)
      • SAMSUNG_USB_Driver_for_Mobile_Phones.exe (PID: 7372)
    • Checks proxy server information

      • SamFwTool.exe (PID: 7144)
      • SAMSUNG_USB_Driver_for_Mobile_Phones.exe (PID: 7372)
    • Reads the software policy settings

      • SamFwTool.exe (PID: 7144)
      • SAMSUNG_USB_Driver_for_Mobile_Phones.exe (PID: 7372)
    • Reads Environment values

      • SamFwTool.exe (PID: 7144)
    • Reads Microsoft Office registry keys

      • SamFwTool.exe (PID: 7144)
      • msedge.exe (PID: 6120)
      • msedge.exe (PID: 7128)
    • Application launched itself

      • msedge.exe (PID: 6120)
      • msedge.exe (PID: 7128)
    • Manual execution by a user

      • msedge.exe (PID: 7128)
    • Drops the executable file immediately after the start

      • msedge.exe (PID: 7128)
      • msedge.exe (PID: 6504)
    • Executable content was dropped or overwritten

      • msedge.exe (PID: 7128)
      • msedge.exe (PID: 6504)
    • Creates files or folders in the user directory

      • SAMSUNG_USB_Driver_for_Mobile_Phones.exe (PID: 7372)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (53.5)
.exe | InstallShield setup (21)
.exe | Win32 EXE PECompact compressed (generic) (20.2)
.exe | Win32 Executable (generic) (2.1)
.exe | Win16/32 Executable Delphi generic (1)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:02:15 14:54:16+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 741888
InitializedDataSize: 89600
UninitializedDataSize: -
EntryPoint: 0xb5eec
OSVersion: 6.1
ImageVersion: 6
SubsystemVersion: 6.1
Subsystem: Windows GUI
FileVersionNumber: 0.0.0.0
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: SamFw.com
FileDescription: SamFw Tool Setup
FileVersion:
LegalCopyright:
OriginalFileName:
ProductName: SamFw Tool
ProductVersion: 4.9
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
207
Monitored processes
83
Malicious processes
7
Suspicious processes
0

Behavior graph

Click at the process to see the details
start 7640282150d51c407ffdfe2fab35f2c60b93b0dc56ac93ad2459b16789aec61b.exe 7640282150d51c407ffdfe2fab35f2c60b93b0dc56ac93ad2459b16789aec61b.tmp no specs 7640282150d51c407ffdfe2fab35f2c60b93b0dc56ac93ad2459b16789aec61b.exe 7640282150d51c407ffdfe2fab35f2c60b93b0dc56ac93ad2459b16789aec61b.tmp 7za.exe conhost.exe no specs samfwtool.exe cmd.exe no specs conhost.exe no specs driverquery.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs slui.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs samsung_usb_driver_for_mobile_phones.exe msedge.exe no specs msedge.exe no specs setup.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs setup.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
628"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=55 --mojo-platform-channel-handle=5420 --field-trial-handle=2052,i,12639552569971507042,11129559809253664268,262144 --variations-seed-version /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.66
844"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=57 --mojo-platform-channel-handle=7260 --field-trial-handle=2052,i,12639552569971507042,11129559809253664268,262144 --variations-seed-version /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.66
888\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
888"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=3996 --field-trial-handle=2052,i,12639552569971507042,11129559809253664268,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.66
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.66\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1148"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=3604 --field-trial-handle=2052,i,12639552569971507042,11129559809253664268,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.66
1152"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=4936 --field-trial-handle=2052,i,12639552569971507042,11129559809253664268,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.66
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.66\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1548"C:\Users\admin\AppData\Local\Temp\is-DEG8T.tmp\7640282150d51c407ffdfe2fab35f2c60b93b0dc56ac93ad2459b16789aec61b.tmp" /SL5="$501CC,58690757,832512,C:\Users\admin\AppData\Local\Temp\7640282150d51c407ffdfe2fab35f2c60b93b0dc56ac93ad2459b16789aec61b.exe" /SPAWNWND=$601C4 /NOTIFYWND=$B003E C:\Users\admin\AppData\Local\Temp\is-DEG8T.tmp\7640282150d51c407ffdfe2fab35f2c60b93b0dc56ac93ad2459b16789aec61b.tmp
7640282150d51c407ffdfe2fab35f2c60b93b0dc56ac93ad2459b16789aec61b.exe
User:
admin
Company:
SamFw.com
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-deg8t.tmp\7640282150d51c407ffdfe2fab35f2c60b93b0dc56ac93ad2459b16789aec61b.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comdlg32.dll
1548"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --mojo-platform-channel-handle=3328 --field-trial-handle=2052,i,12639552569971507042,11129559809253664268,262144 --variations-seed-version /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.66
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.66\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1624"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=10 --mojo-platform-channel-handle=4992 --field-trial-handle=2052,i,12639552569971507042,11129559809253664268,262144 --variations-seed-version /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.66
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.66\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1976"C:\WINDOWS\Sysnative\cmd.exe" /c driverquery /FO listC:\Windows\System32\cmd.exeSamFwTool.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
Total events
33 092
Read events
32 923
Write events
160
Delete events
9

Modification events

(PID) Process:(1548) 7640282150d51c407ffdfe2fab35f2c60b93b0dc56ac93ad2459b16789aec61b.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
0C0600002B2707536671DA01
(PID) Process:(1548) 7640282150d51c407ffdfe2fab35f2c60b93b0dc56ac93ad2459b16789aec61b.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:SessionHash
Value:
EC2E7A40EA8A7E751ACD4A2993EBBC0F4C6E08035A173A41871FC6733A73DEAF
(PID) Process:(1548) 7640282150d51c407ffdfe2fab35f2c60b93b0dc56ac93ad2459b16789aec61b.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:Sequence
Value:
1
(PID) Process:(1548) 7640282150d51c407ffdfe2fab35f2c60b93b0dc56ac93ad2459b16789aec61b.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:RegFiles0000
Value:
C:\SamFwTool\SamFwTool.exe
(PID) Process:(1548) 7640282150d51c407ffdfe2fab35f2c60b93b0dc56ac93ad2459b16789aec61b.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:RegFilesHash
Value:
0189B2E301F3527254419AA2D17A3BF52D2133DC99F49997B456486A7C1CE7E8
(PID) Process:(1548) 7640282150d51c407ffdfe2fab35f2c60b93b0dc56ac93ad2459b16789aec61b.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{B439569E-0B37-4DF7-A623-7EEF6645E414}_is1
Operation:writeName:Inno Setup: Setup Version
Value:
6.2.2
(PID) Process:(1548) 7640282150d51c407ffdfe2fab35f2c60b93b0dc56ac93ad2459b16789aec61b.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{B439569E-0B37-4DF7-A623-7EEF6645E414}_is1
Operation:writeName:Inno Setup: App Path
Value:
C:\SamFwTool
(PID) Process:(1548) 7640282150d51c407ffdfe2fab35f2c60b93b0dc56ac93ad2459b16789aec61b.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{B439569E-0B37-4DF7-A623-7EEF6645E414}_is1
Operation:writeName:InstallLocation
Value:
C:\SamFwTool\
(PID) Process:(1548) 7640282150d51c407ffdfe2fab35f2c60b93b0dc56ac93ad2459b16789aec61b.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{B439569E-0B37-4DF7-A623-7EEF6645E414}_is1
Operation:writeName:Inno Setup: Icon Group
Value:
(Default)
(PID) Process:(1548) 7640282150d51c407ffdfe2fab35f2c60b93b0dc56ac93ad2459b16789aec61b.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{B439569E-0B37-4DF7-A623-7EEF6645E414}_is1
Operation:writeName:Inno Setup: User
Value:
admin
Executable files
481
Suspicious files
402
Text files
97
Unknown types
180

Dropped files

PID
Process
Filename
Type
15487640282150d51c407ffdfe2fab35f2c60b93b0dc56ac93ad2459b16789aec61b.tmpC:\SamFwTool\is-0ABNJ.tmp
MD5:
SHA256:
15487640282150d51c407ffdfe2fab35f2c60b93b0dc56ac93ad2459b16789aec61b.tmpC:\SamFwTool\data.7z
MD5:
SHA256:
65087za.exeC:\SamFwTool\data\mtk_module.data
MD5:
SHA256:
26007640282150d51c407ffdfe2fab35f2c60b93b0dc56ac93ad2459b16789aec61b.exeC:\Users\admin\AppData\Local\Temp\is-NU9JM.tmp\7640282150d51c407ffdfe2fab35f2c60b93b0dc56ac93ad2459b16789aec61b.tmpexecutable
MD5:C40A8A7891124F63F741EE4E36AE459C
SHA256:7E865F2AB27C2CDC895CC42BA887C4968A85619D435D74C556CC8F8CE47E615C
15487640282150d51c407ffdfe2fab35f2c60b93b0dc56ac93ad2459b16789aec61b.tmpC:\SamFwTool\is-SGUVO.tmpexecutable
MD5:99B1E36598E55933E350430519B53B34
SHA256:72B4E02B59B6CF1BFEC786E2B1ACF98D31CDCEB906BEB115B52F3BBF07E02FB3
15487640282150d51c407ffdfe2fab35f2c60b93b0dc56ac93ad2459b16789aec61b.tmpC:\SamFwTool\SamFwTool.exeexecutable
MD5:99B1E36598E55933E350430519B53B34
SHA256:72B4E02B59B6CF1BFEC786E2B1ACF98D31CDCEB906BEB115B52F3BBF07E02FB3
15487640282150d51c407ffdfe2fab35f2c60b93b0dc56ac93ad2459b16789aec61b.tmpC:\SamFwTool\unins000.exeexecutable
MD5:5D0F19B994F04293B0DEADCB0206C032
SHA256:7C25D91F62420617D906506AD629317B6B036D6ACC3322726B782C9C651FE79D
15487640282150d51c407ffdfe2fab35f2c60b93b0dc56ac93ad2459b16789aec61b.tmpC:\SamFwTool\is-KI54Q.tmpexecutable
MD5:5D0F19B994F04293B0DEADCB0206C032
SHA256:7C25D91F62420617D906506AD629317B6B036D6ACC3322726B782C9C651FE79D
15487640282150d51c407ffdfe2fab35f2c60b93b0dc56ac93ad2459b16789aec61b.tmpC:\Users\admin\AppData\Local\Temp\is-86V29.tmp\_isetup\_setup64.tmpexecutable
MD5:E4211D6D009757C078A9FAC7FF4F03D4
SHA256:388A796580234EFC95F3B1C70AD4CB44BFDDC7BA0F9203BF4902B9929B136F95
44247640282150d51c407ffdfe2fab35f2c60b93b0dc56ac93ad2459b16789aec61b.exeC:\Users\admin\AppData\Local\Temp\is-DEG8T.tmp\7640282150d51c407ffdfe2fab35f2c60b93b0dc56ac93ad2459b16789aec61b.tmpexecutable
MD5:C40A8A7891124F63F741EE4E36AE459C
SHA256:7E865F2AB27C2CDC895CC42BA887C4968A85619D435D74C556CC8F8CE47E615C
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
25
TCP/UDP connections
262
DNS requests
281
Threats
5

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
7144
SamFwTool.exe
GET
200
208.95.112.1:80
http://ip-api.com/json
unknown
binary
288 b
unknown
7372
SAMSUNG_USB_Driver_for_Mobile_Phones.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSRXerF0eFeSWRripTgTkcJWMm7iQQUaDfg67Y7%2BF8Rhvv%2BYXsIiGX0TkICEAZoDO5GW4VvYTo73SBILnE%3D
unknown
binary
727 b
unknown
GET
206
152.199.19.161:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/bed08363-77ae-486c-b914-cf6de1078ac6?P1=1710493006&P2=404&P3=2&P4=cvZwBpRxztAu%2buTH3F3QqZLTh2EOGhToiiI%2bk7YnGqkMSe9K6iNReCihfD75Z2ZQEHZbUKzM1FGGv6uOTPuIXQ%3d%3d
unknown
binary
4.06 Kb
unknown
GET
206
152.199.19.161:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/bed08363-77ae-486c-b914-cf6de1078ac6?P1=1710493006&P2=404&P3=2&P4=cvZwBpRxztAu%2buTH3F3QqZLTh2EOGhToiiI%2bk7YnGqkMSe9K6iNReCihfD75Z2ZQEHZbUKzM1FGGv6uOTPuIXQ%3d%3d
unknown
binary
1.09 Kb
unknown
HEAD
200
152.199.19.161:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/bed08363-77ae-486c-b914-cf6de1078ac6?P1=1710493006&P2=404&P3=2&P4=cvZwBpRxztAu%2buTH3F3QqZLTh2EOGhToiiI%2bk7YnGqkMSe9K6iNReCihfD75Z2ZQEHZbUKzM1FGGv6uOTPuIXQ%3d%3d
unknown
unknown
GET
206
152.199.19.161:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/bed08363-77ae-486c-b914-cf6de1078ac6?P1=1710493006&P2=404&P3=2&P4=cvZwBpRxztAu%2buTH3F3QqZLTh2EOGhToiiI%2bk7YnGqkMSe9K6iNReCihfD75Z2ZQEHZbUKzM1FGGv6uOTPuIXQ%3d%3d
unknown
binary
1.65 Kb
unknown
6692
svchost.exe
POST
302
23.213.166.81:80
http://go.microsoft.com/fwlink/?LinkID=252669&clcid=0x409
unknown
unknown
6692
svchost.exe
POST
302
23.213.166.81:80
http://go.microsoft.com/fwlink/?LinkID=252669&clcid=0x409
unknown
unknown
6692
svchost.exe
POST
502
20.231.121.79:80
http://dmd.metaservices.microsoft.com/metadata.svc
unknown
html
183 b
unknown
6692
svchost.exe
POST
302
23.213.166.81:80
http://go.microsoft.com/fwlink/?LinkID=252669&clcid=0x409
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
239.255.255.250:1900
unknown
3308
svchost.exe
40.115.3.253:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
unknown
2704
backgroundTaskHost.exe
92.122.215.65:443
www.bing.com
Akamai International B.V.
DE
unknown
892
svchost.exe
20.190.160.17:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
40.115.3.253:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
unknown
4
System
192.168.100.255:137
whitelisted
892
svchost.exe
20.190.160.22:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6876
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6692
svchost.exe
23.213.166.81:80
go.microsoft.com
AKAMAI-AS
DE
unknown

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
whitelisted
go.microsoft.com
  • 23.213.166.81
whitelisted
dmd.metaservices.microsoft.com
  • 20.231.121.79
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 20.3.187.198
whitelisted
slscr.update.microsoft.com
  • 13.85.23.86
whitelisted
samfw.com
  • 188.114.96.3
  • 188.114.97.3
unknown
ip-api.com
  • 208.95.112.1
shared
activation-v2.sls.microsoft.com
  • 40.91.76.224
whitelisted
bit.ly
  • 67.199.248.11
  • 67.199.248.10
shared
edge.microsoft.com
  • 204.79.197.239
  • 13.107.21.239
whitelisted

Threats

PID
Process
Class
Message
7144
SamFwTool.exe
Potential Corporate Privacy Violation
AV POLICY Internal Host Retrieving External IP Address (ip-api. com)
7144
SamFwTool.exe
Device Retrieving External IP Address Detected
ET POLICY External IP Lookup ip-api.com
6504
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] A free CDN for open source projects (jsdelivr .net)
6504
msedge.exe
Device Retrieving External IP Address Detected
ET INFO External IP Address Lookup Domain (get .geojs .io) in DNS Lookup
6504
msedge.exe
Device Retrieving External IP Address Detected
ET INFO External IP Address Lookup Domain (get .geojs .io) in DNS Lookup
No debug info