File name:

btweb_installer.exe

Full analysis: https://app.any.run/tasks/4dab049d-7268-4fe9-b8b5-e269f48dcc8f
Verdict: Malicious activity
Analysis date: November 13, 2023, 09:47:42
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

ECD3E630F8C01AF4B4C6E8F3BAFC0C8F

SHA1:

C189692F04D302A4B55F5A921F8CBE93094C585E

SHA256:

7A9A9AA3270CE6099C0404E49CF3DCB8F286AFA2705AB087DDDCE839AA823356

SSDEEP:

49152:Y7HecD4dnbibBlXcqTGiloIPsZAYuCInBvFIdzmlb0o2/GF9337SQ958hcHDGyl4:k+cD4dnzIloIPEAY/iBdo3UF9337SQ9m

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • btweb_installer.exe (PID: 3436)
      • btweb_installer.exe (PID: 3412)
  • SUSPICIOUS

    • Reads the Windows owner or organization settings

      • btweb_installer.tmp (PID: 3404)
    • Reads settings of System Certificates

      • btweb_installer.tmp (PID: 3404)
    • Reads the Internet Settings

      • btweb_installer.tmp (PID: 3404)
  • INFO

    • Checks supported languages

      • btweb_installer.exe (PID: 3436)
      • wmpnscfg.exe (PID: 3448)
      • btweb_installer.tmp (PID: 3156)
      • btweb_installer.exe (PID: 3412)
      • btweb_installer.tmp (PID: 3404)
      • wmpnscfg.exe (PID: 3380)
    • Reads the computer name

      • wmpnscfg.exe (PID: 3448)
      • btweb_installer.tmp (PID: 3156)
      • btweb_installer.tmp (PID: 3404)
      • wmpnscfg.exe (PID: 3380)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 3448)
      • wmpnscfg.exe (PID: 3380)
    • Reads the machine GUID from the registry

      • wmpnscfg.exe (PID: 3448)
      • btweb_installer.tmp (PID: 3404)
      • wmpnscfg.exe (PID: 3380)
    • Create files in a temporary directory

      • btweb_installer.exe (PID: 3436)
      • btweb_installer.exe (PID: 3412)
      • btweb_installer.tmp (PID: 3404)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (67.7)
.exe | Win32 EXE PECompact compressed (generic) (25.6)
.exe | Win32 Executable (generic) (2.7)
.exe | Win16/32 Executable Delphi generic (1.2)
.exe | Generic Win/DOS Executable (1.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:02:15 15:54:16+01:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 741888
InitializedDataSize: 101376
UninitializedDataSize: -
EntryPoint: 0xb5eec
OSVersion: 6.1
ImageVersion: 6
SubsystemVersion: 6.1
Subsystem: Windows GUI
FileVersionNumber: 1.4.0.0
ProductVersionNumber: 1.4.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: BіtТorrеnt Web®
FileVersion: 1.4
LegalCopyright: ©2022 RainBerry Inc. All Rights Reserved
OriginalFileName:
ProductName: BіtТorrеnt Web®
ProductVersion: 1.4
No data.
screenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
43
Monitored processes
6
Malicious processes
3
Suspicious processes
1

Behavior graph

Click at the process to see the details
start btweb_installer.exe no specs wmpnscfg.exe no specs btweb_installer.tmp no specs btweb_installer.exe btweb_installer.tmp wmpnscfg.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
3156"C:\Users\admin\AppData\Local\Temp\is-H3KK1.tmp\btweb_installer.tmp" /SL5="$50194,867750,844288,C:\Users\admin\AppData\Local\Temp\btweb_installer.exe" C:\Users\admin\AppData\Local\Temp\is-H3KK1.tmp\btweb_installer.tmpbtweb_installer.exe
User:
admin
Company:
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-h3kk1.tmp\btweb_installer.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3380"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\ole32.dll
3404"C:\Users\admin\AppData\Local\Temp\is-OLM42.tmp\btweb_installer.tmp" /SL5="$70186,867750,844288,C:\Users\admin\AppData\Local\Temp\btweb_installer.exe" /SPAWNWND=$401F4 /NOTIFYWND=$50194 C:\Users\admin\AppData\Local\Temp\is-OLM42.tmp\btweb_installer.tmp
btweb_installer.exe
User:
admin
Company:
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-olm42.tmp\btweb_installer.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3412"C:\Users\admin\AppData\Local\Temp\btweb_installer.exe" /SPAWNWND=$401F4 /NOTIFYWND=$50194 C:\Users\admin\AppData\Local\Temp\btweb_installer.exe
btweb_installer.tmp
User:
admin
Company:
Integrity Level:
HIGH
Description:
BіtТorrеnt Web®
Exit code:
0
Version:
1.4
Modules
Images
c:\users\admin\appdata\local\temp\btweb_installer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\comctl32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
3436"C:\Users\admin\AppData\Local\Temp\btweb_installer.exe" C:\Users\admin\AppData\Local\Temp\btweb_installer.exeexplorer.exe
User:
admin
Company:
Integrity Level:
MEDIUM
Description:
BіtТorrеnt Web®
Exit code:
0
Version:
1.4
Modules
Images
c:\users\admin\appdata\local\temp\btweb_installer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\comctl32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
3448"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\ole32.dll
Total events
3 866
Read events
3 846
Write events
12
Delete events
8

Modification events

(PID) Process:(3448) wmpnscfg.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{EA5D170E-6828-4EF0-AF7B-B5A324CC6E41}\{0C716894-8DA1-49A6-A113-193621F7BAB4}
Operation:delete keyName:(default)
Value:
(PID) Process:(3448) wmpnscfg.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{EA5D170E-6828-4EF0-AF7B-B5A324CC6E41}
Operation:delete keyName:(default)
Value:
(PID) Process:(3448) wmpnscfg.exeKey:HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Health\{86897002-B53B-49B9-92F1-910CA3D85C6E}
Operation:delete keyName:(default)
Value:
(PID) Process:(3404) btweb_installer.tmpKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\17A\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3380) wmpnscfg.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{DBE3BC7A-B266-4F66-955D-2F81D875BB44}\{2E506889-3406-4667-8776-B79B4BFF9760}
Operation:delete keyName:(default)
Value:
(PID) Process:(3380) wmpnscfg.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{EA5D170E-6828-4EF0-AF7B-B5A324CC6E41}\{2E506889-3406-4667-8776-B79B4BFF9760}
Operation:delete keyName:(default)
Value:
(PID) Process:(3380) wmpnscfg.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{EA5D170E-6828-4EF0-AF7B-B5A324CC6E41}
Operation:delete keyName:(default)
Value:
(PID) Process:(3380) wmpnscfg.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{DBE3BC7A-B266-4F66-955D-2F81D875BB44}
Operation:delete keyName:(default)
Value:
(PID) Process:(3380) wmpnscfg.exeKey:HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Health\{836DB1DB-B061-4472-99E7-B949E18F9153}
Operation:delete keyName:(default)
Value:
Executable files
2
Suspicious files
0
Text files
4
Unknown types
0

Dropped files

PID
Process
Filename
Type
3412btweb_installer.exeC:\Users\admin\AppData\Local\Temp\is-OLM42.tmp\btweb_installer.tmpexecutable
MD5:88667DC04C45BC54EF986924A3274C8D
SHA256:37056D866A31EDF33ED8154ACC15671CE7F0DDAE90D03F43C785A66B0EF93F34
3436btweb_installer.exeC:\Users\admin\AppData\Local\Temp\is-H3KK1.tmp\btweb_installer.tmpexecutable
MD5:88667DC04C45BC54EF986924A3274C8D
SHA256:37056D866A31EDF33ED8154ACC15671CE7F0DDAE90D03F43C785A66B0EF93F34
3404btweb_installer.tmpC:\Users\admin\AppData\Local\Temp\is-EKJJC.tmp\is-UN8S8.tmpimage
MD5:4CFFF8DC30D353CD3D215FD3A5DBAC24
SHA256:0C430E56D69435D8AB31CBB5916A73A47D11EF65B37D289EE7D11130ADF25856
3404btweb_installer.tmpC:\Users\admin\AppData\Local\Temp\is-EKJJC.tmp\WebAdvisor.pngimage
MD5:4CFFF8DC30D353CD3D215FD3A5DBAC24
SHA256:0C430E56D69435D8AB31CBB5916A73A47D11EF65B37D289EE7D11130ADF25856
3404btweb_installer.tmpC:\Users\admin\AppData\Local\Temp\is-EKJJC.tmp\license.rtftext
MD5:CA9C80605FF244AE36C584FFFFA09435
SHA256:81C21179CB42FA44D8B7AA07925081B899F0EF5F18AC00FFB75B303309078634
3404btweb_installer.tmpC:\Users\admin\AppData\Local\Temp\is-EKJJC.tmp\Logo.pngimage
MD5:D0743D0DB691B4E932DCF098F070C5FC
SHA256:93520D9E40F227FD89021341ABAD301D2351704D1509711587E3D4F6FE35FB59
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
13
DNS requests
7
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
3404
btweb_installer.tmp
52.222.250.12:443
ddpha3v19918o.cloudfront.net
AMAZON-02
US
unknown
4
System
192.168.100.255:138
whitelisted
2588
svchost.exe
239.255.255.250:1900
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
3404
btweb_installer.tmp
18.245.78.7:443
d2kwh3hmp4tuay.cloudfront.net
US
unknown
3404
btweb_installer.tmp
18.245.86.105:443
api.playanext.com
US
unknown
3404
btweb_installer.tmp
52.222.206.24:443
d2uh0cbk8qzp9r.cloudfront.net
AMAZON-02
US
unknown
3404
btweb_installer.tmp
67.215.238.66:443
download-lb.utorrent.com
ASN-QUADRANET-GLOBAL
US
unknown

DNS requests

Domain
IP
Reputation
ddpha3v19918o.cloudfront.net
  • 52.222.250.12
  • 52.222.250.86
  • 52.222.250.93
  • 52.222.250.35
unknown
d2kwh3hmp4tuay.cloudfront.net
  • 18.245.78.7
  • 18.245.78.172
  • 18.245.78.62
  • 18.245.78.165
unknown
api.playanext.com
  • 18.245.86.105
  • 18.245.86.26
  • 18.245.86.84
  • 18.245.86.79
whitelisted
d2uh0cbk8qzp9r.cloudfront.net
  • 52.222.206.24
  • 52.222.206.149
  • 52.222.206.14
  • 52.222.206.74
unknown
download-lb.utorrent.com
  • 67.215.238.66
whitelisted

Threats

No threats detected
No debug info