File name:

Siap_3_1_R5_Master-3.1.5.exe

Full analysis: https://app.any.run/tasks/d589d27b-f57f-44fa-ab5d-2565553c4b17
Verdict: Malicious activity
Analysis date: September 16, 2024, 13:37:03
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

18F13C71BE5F60F5782272568D29800C

SHA1:

93893C6DEFDF9E69FEFBC9C319C54D31D4237FBA

SHA256:

76B838753C3902FEE0F2DB693DCC16000B6F12D81DD2B5FB70797AB18E7D13BF

SSDEEP:

196608:Mf55fyIuuuyU8B6Cosac2Aryy70KhvRACBG4wNFMutstf3Rnu4:Mf5Fy6uy3Bacdyy70KhvC8WautstfI4

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • Siap_3_1_R5_Master-3.1.5.exe (PID: 7116)
      • SETUP.EXE (PID: 3316)
      • Setup1.exe (PID: 6684)
    • Starts a Microsoft application from unusual location

      • SETUP.EXE (PID: 6672)
      • SETUP.EXE (PID: 3316)
    • Drops a file with a rarely used extension (PIF)

      • Setup1.exe (PID: 6684)
    • Creates a software uninstall entry

      • Setup1.exe (PID: 6684)
    • Creates/Modifies COM task schedule object

      • Setup1.exe (PID: 6684)
  • INFO

    • Checks supported languages

      • Siap_3_1_R5_Master-3.1.5.exe (PID: 7116)
      • SETUP.EXE (PID: 3316)
      • Setup1.exe (PID: 6684)
      • siap.exe (PID: 2096)
    • Reads the computer name

      • Siap_3_1_R5_Master-3.1.5.exe (PID: 7116)
      • SETUP.EXE (PID: 3316)
      • Setup1.exe (PID: 6684)
      • siap.exe (PID: 2096)
    • Manual execution by a user

      • SETUP.EXE (PID: 3316)
      • SETUP.EXE (PID: 6672)
      • siap.exe (PID: 2096)
    • Creates files or folders in the user directory

      • SETUP.EXE (PID: 3316)
      • Setup1.exe (PID: 6684)
      • siap.exe (PID: 2096)
    • Create files in a temporary directory

      • Setup1.exe (PID: 6684)
      • siap.exe (PID: 2096)
    • Creates files in the program directory

      • Setup1.exe (PID: 6684)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable Borland Delphi 6 (93.8)
.dll | Win32 Dynamic Link Library (generic) (2.3)
.exe | Win32 Executable (generic) (1.6)
.exe | Win16/32 Executable Delphi generic (0.7)
.exe | Generic Win/DOS Executable (0.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 1992:06:19 22:22:17+00:00
ImageFileCharacteristics: Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 28672
InitializedDataSize: 9216
UninitializedDataSize: -
EntryPoint: 0x7d50
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
120
Monitored processes
6
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start siap_3_1_r5_master-3.1.5.exe setup.exe no specs setup.exe setup1.exe rundll32.exe no specs siap.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2096"C:\Program Files (x86)\S.I.Ap\AFIP\siap.exe" C:\Program Files (x86)\S.I.Ap\AFIP\siap.exeexplorer.exe
User:
admin
Company:
AFIP
Integrity Level:
MEDIUM
Description:
Sistema concentrador para aplicaciones de AFIP
Version:
3.01.0041
Modules
Images
c:\program files (x86)\s.i.ap\afip\siap.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvbvm50.dll
3316"C:\Users\admin\Desktop\SETUP.EXE" C:\Users\admin\Desktop\SETUP.EXE
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Instalación de Bootstrap para Visual Basic Setup Toolkit
Exit code:
0
Version:
5.00.3716
Modules
Images
c:\users\admin\desktop\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acgenral.dll
4252C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -EmbeddingC:\Windows\System32\rundll32.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shcore.dll
c:\windows\system32\imagehlp.dll
6672"C:\Users\admin\Desktop\SETUP.EXE" C:\Users\admin\Desktop\SETUP.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Instalación de Bootstrap para Visual Basic Setup Toolkit
Exit code:
3221226540
Version:
5.00.3716
Modules
Images
c:\users\admin\desktop\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
6684C:\Windows\Setup1.exe "C:\Users\admin\Desktop\" "C:\WINDOWS\ST5UNST.000" "C:\WINDOWS\ST5UNST.EXE"C:\Windows\Setup1.exe
SETUP.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Visual Basic 5.0 Setup Toolkit
Exit code:
0
Version:
5.00.3716
Modules
Images
c:\windows\setup1.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acgenral.dll
7116"C:\Users\admin\Desktop\Siap_3_1_R5_Master-3.1.5.exe" C:\Users\admin\Desktop\Siap_3_1_R5_Master-3.1.5.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\siap_3_1_r5_master-3.1.5.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
Total events
1 606
Read events
1 065
Write events
450
Delete events
91

Modification events

(PID) Process:(3316) SETUP.EXEKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\SharedDlls
Operation:writeName:C:\Windows\System32\VB5StKit.dll
Value:
1
(PID) Process:(3316) SETUP.EXEKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\SharedDlls
Operation:writeName:C:\Windows\System32\VB5ES.dll
Value:
1
(PID) Process:(3316) SETUP.EXEKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\SharedDlls
Operation:writeName:C:\Windows\System32\MSVBVM50.dll
Value:
1
(PID) Process:(3316) SETUP.EXEKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\SharedDlls
Operation:writeName:C:\Windows\System32\StdOle2.tlb
Value:
2
(PID) Process:(3316) SETUP.EXEKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\SharedDlls
Operation:writeName:C:\Windows\System32\OleAut32.dll
Value:
2
(PID) Process:(3316) SETUP.EXEKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\SharedDlls
Operation:writeName:C:\Windows\System32\OlePro32.dll
Value:
2
(PID) Process:(3316) SETUP.EXEKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\SharedDlls
Operation:writeName:C:\Windows\System32\AsycFilt.dll
Value:
2
(PID) Process:(3316) SETUP.EXEKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\SharedDlls
Operation:writeName:C:\Windows\System32\Ctl3d32.dll
Value:
2
(PID) Process:(3316) SETUP.EXEKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\SharedDlls
Operation:writeName:C:\Windows\System32\ComCat.dll
Value:
2
(PID) Process:(3316) SETUP.EXEKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{A4C466B8-499F-101B-BB78-00AA00383CBB}\TypeLib
Operation:writeName:Version
Value:
5.0
Executable files
244
Suspicious files
115
Text files
7
Unknown types
12

Dropped files

PID
Process
Filename
Type
7116Siap_3_1_R5_Master-3.1.5.exeC:\Users\admin\Desktop\VALIDTEXTBOX.OC_binary
MD5:465E48F2E401A901EB30A896199BD0FE
SHA256:27EF35C6865D9BF80E01F848AF2BCA763250C31F220D1F2233118D494D448A1B
7116Siap_3_1_R5_Master-3.1.5.exeC:\Users\admin\Desktop\XCEEDZIP.OC_binary
MD5:6DC5D59BDE0F98DC494EEE1111B2388F
SHA256:FBDCB3032CC3CC8E2563D6DA8E4AD3B4040CAD259A9BBF144173BDD72FDB011B
7116Siap_3_1_R5_Master-3.1.5.exeC:\Users\admin\Desktop\StdOle2.tl_ex_
MD5:73263567055D3A180BECA87AEDC09EC3
SHA256:4E482FE258691453453C929FC335B6D16EC13E59C72C3A93E2F585CE94C81975
7116Siap_3_1_R5_Master-3.1.5.exeC:\Users\admin\Desktop\SETUP.LSTtext
MD5:618F75FD4AFFBB272F96C68E56A849CE
SHA256:03878A7448EFB6770198AFC249309B01FF9240E39848211A3909DB0D6B2AE7C7
7116Siap_3_1_R5_Master-3.1.5.exeC:\Users\admin\Desktop\DKWIN.PI_binary
MD5:08C260DB790D2DDB26F2DAD63D90C6A8
SHA256:B84F4AD5DA72E699954A8AE34D7A4FAA571D1B31C3A1C5FECE692DA91AB0225E
7116Siap_3_1_R5_Master-3.1.5.exeC:\Users\admin\Desktop\CmCtlES.dl_ex_
MD5:5DDC8ACC17C763DEA39F675D60025A4D
SHA256:FF195AF5992FFC44E3226E9F72DD8F8F50B8D7232DD39ABF5FF83AAF4286C6EE
7116Siap_3_1_R5_Master-3.1.5.exeC:\Users\admin\Desktop\SETUP.EXEexecutable
MD5:904108EED4A7BC2D0BEA2946240E6146
SHA256:AB5CD6DC33919D2792201EF2827209B21675663265F2AB5E3A8AAA64BE743CF0
7116Siap_3_1_R5_Master-3.1.5.exeC:\Users\admin\Desktop\CmDlgES.dl_binary
MD5:A6154D2486D74D85B416EC4C29EE4F50
SHA256:0C851C98FABF1EBECFDE50E325B49C81C448AC1F84D3FF20B106C06830F4AE77
7116Siap_3_1_R5_Master-3.1.5.exeC:\Users\admin\Desktop\CO2C40EN.DL_binary
MD5:6B5AF805E6BA4137BA8E3FB8D7C21A5E
SHA256:D82F1CFB7C30413AE31FE6FFCE984A4F370736DFA5B63A7909561627E15CBEE7
7116Siap_3_1_R5_Master-3.1.5.exeC:\Users\admin\Desktop\AsycFilt.dl_binary
MD5:ED8562CE287D7D00971C7593E1C26387
SHA256:93CC5E7EF4008395B53C5514A19D6C72BED89A056B778202B1424C05C8932779
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
17
DNS requests
9
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2120
MoUsoCoreWorker.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6124
svchost.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
2384
SIHClient.exe
GET
200
23.52.120.96:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
2384
SIHClient.exe
GET
200
23.52.120.96:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2120
MoUsoCoreWorker.exe
88.221.169.152:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
6124
svchost.exe
88.221.169.152:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
3888
svchost.exe
239.255.255.250:1900
whitelisted
3260
svchost.exe
13.64.180.106:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:137
whitelisted
2384
SIHClient.exe
20.114.59.183:443
slscr.update.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
2384
SIHClient.exe
23.52.120.96:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
2384
SIHClient.exe
13.95.31.18:443
fe3cr.delivery.mp.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
whitelisted
www.microsoft.com
  • 88.221.169.152
  • 23.52.120.96
whitelisted
google.com
  • 142.250.186.174
whitelisted
client.wns.windows.com
  • 13.64.180.106
whitelisted
slscr.update.microsoft.com
  • 20.114.59.183
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 13.95.31.18
whitelisted

Threats

No threats detected
No debug info