File name:

Binance SmartFlash v8.0 (Update 2025).exe

Full analysis: https://app.any.run/tasks/98cbd26d-c7aa-401e-bf2c-718ed5f5c4a6
Verdict: Malicious activity
Analysis date: June 21, 2025, 23:53:39
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
inno
installer
delphi
golang
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 11 sections
MD5:

34552EF791FCAA949C716309778A7007

SHA1:

10C8242D5DEA9FB908DAAD65D97BFF6D82E426C9

SHA256:

7E689228ED42139AA22EFB8DE9B8B657E9731B5E6CFF0E181BA8E7330BC8289C

SSDEEP:

98304:2LVIF8P3n1BLHxtD59KEKjSvDlud09eRHqWlfoClRRq/dZUkYvzkIp8SYb0pXK2N:a07yTNwp

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • Binance SmartFlash v8.0 (Update 2025).exe (PID: 6812)
      • Binance SmartFlash v8.0 (Update 2025).exe (PID: 4500)
    • Registers / Runs the DLL via REGSVR32.EXE

      • Binance SmartFlash v8.0 (Update 2025).tmp (PID: 6652)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • Binance SmartFlash v8.0 (Update 2025).tmp (PID: 1520)
      • Binance SmartFlash v8.0 (Update 2025).exe (PID: 6812)
      • Binance SmartFlash v8.0 (Update 2025).exe (PID: 4500)
      • Binance SmartFlash v8.0 (Update 2025).tmp (PID: 6652)
    • Reads the Windows owner or organization settings

      • Binance SmartFlash v8.0 (Update 2025).tmp (PID: 1520)
      • Binance SmartFlash v8.0 (Update 2025).tmp (PID: 6652)
    • Reads security settings of Internet Explorer

      • Binance SmartFlash v8.0 (Update 2025).tmp (PID: 1520)
    • The process hide an interactive prompt from the user

      • regsvr32.exe (PID: 6428)
    • Starts POWERSHELL.EXE for commands execution

      • regsvr32.exe (PID: 6428)
    • The process bypasses the loading of PowerShell profile settings

      • regsvr32.exe (PID: 6428)
  • INFO

    • Checks supported languages

      • Binance SmartFlash v8.0 (Update 2025).exe (PID: 6812)
      • Binance SmartFlash v8.0 (Update 2025).tmp (PID: 1520)
      • Binance SmartFlash v8.0 (Update 2025).exe (PID: 4500)
      • Binance SmartFlash v8.0 (Update 2025).tmp (PID: 6652)
    • Create files in a temporary directory

      • Binance SmartFlash v8.0 (Update 2025).exe (PID: 6812)
      • Binance SmartFlash v8.0 (Update 2025).tmp (PID: 1520)
      • Binance SmartFlash v8.0 (Update 2025).exe (PID: 4500)
      • Binance SmartFlash v8.0 (Update 2025).tmp (PID: 6652)
    • Reads the computer name

      • Binance SmartFlash v8.0 (Update 2025).tmp (PID: 1520)
      • Binance SmartFlash v8.0 (Update 2025).tmp (PID: 6652)
    • Process checks computer location settings

      • Binance SmartFlash v8.0 (Update 2025).tmp (PID: 1520)
    • Creates files or folders in the user directory

      • Binance SmartFlash v8.0 (Update 2025).tmp (PID: 6652)
    • Checks if a key exists in the options dictionary (POWERSHELL)

      • powershell.exe (PID: 2512)
      • powershell.exe (PID: 6172)
    • Compiled with Borland Delphi (YARA)

      • Binance SmartFlash v8.0 (Update 2025).tmp (PID: 6652)
      • Binance SmartFlash v8.0 (Update 2025).exe (PID: 4500)
    • Detects InnoSetup installer (YARA)

      • Binance SmartFlash v8.0 (Update 2025).exe (PID: 4500)
      • Binance SmartFlash v8.0 (Update 2025).tmp (PID: 6652)
    • Application based on Golang

      • Binance SmartFlash v8.0 (Update 2025).tmp (PID: 6652)
      • regsvr32.exe (PID: 6428)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (65.1)
.exe | Win32 EXE PECompact compressed (generic) (24.6)
.dll | Win32 Dynamic Link Library (generic) (3.9)
.exe | Win32 Executable (generic) (2.6)
.exe | Win16/32 Executable Delphi generic (1.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2009:10:16 00:38:20+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 2.25
CodeSize: 704512
InitializedDataSize: 107520
UninitializedDataSize: -
EntryPoint: 0xacfe0
OSVersion: 6.1
ImageVersion: -
SubsystemVersion: 6.1
Subsystem: Windows GUI
FileVersionNumber: 0.0.0.0
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: Windows SQM Consolidator Setup
FileVersion:
LegalCopyright:
OriginalFileName:
ProductName: Windows SQM Consolidator
ProductVersion: 10.0.19041.1
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
145
Monitored processes
10
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
start binance smartflash v8.0 (update 2025).exe binance smartflash v8.0 (update 2025).tmp binance smartflash v8.0 (update 2025).exe binance smartflash v8.0 (update 2025).tmp regsvr32.exe no specs powershell.exe no specs conhost.exe no specs powershell.exe no specs conhost.exe no specs slui.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1380C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
1520"C:\Users\admin\AppData\Local\Temp\is-RGIDU.tmp\Binance SmartFlash v8.0 (Update 2025).tmp" /SL5="$50316,2424516,813056,C:\Users\admin\AppData\Local\Temp\Binance SmartFlash v8.0 (Update 2025).exe" C:\Users\admin\AppData\Local\Temp\is-RGIDU.tmp\Binance SmartFlash v8.0 (Update 2025).tmp
Binance SmartFlash v8.0 (Update 2025).exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
1
Modules
Images
c:\users\admin\appdata\local\temp\is-rgidu.tmp\binance smartflash v8.0 (update 2025).tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comdlg32.dll
2148\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exepowershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2512"powershell" -Command "if (Get-ScheduledTask | Where-Object { $_.Actions.Execute -eq 'regsvr32' -and $_.Actions.Arguments -eq '/s /i:googlechromebusiness.msi \"\\?\C:\Users\admin\AppData\Local\9Plum.pfx\"' }) { exit 0 } else { exit 1 }"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeregsvr32.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows PowerShell
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
4500"C:\Users\admin\AppData\Local\Temp\Binance SmartFlash v8.0 (Update 2025).exe" /VERYSILENTC:\Users\admin\AppData\Local\Temp\Binance SmartFlash v8.0 (Update 2025).exe
Binance SmartFlash v8.0 (Update 2025).tmp
User:
admin
Company:
Integrity Level:
MEDIUM
Description:
Windows SQM Consolidator Setup
Version:
Modules
Images
c:\users\admin\appdata\local\temp\binance smartflash v8.0 (update 2025).exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comctl32.dll
5436\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exepowershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
6172"PowerShell.exe" -NoProfile -NonInteractive -Command -C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeregsvr32.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows PowerShell
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
6428"C:\WINDOWS\Sysnative\regsvr32.exe" /s /i:googlechromebusiness.msi "C:\Users\admin\AppData\Local\9Plum.pfx"C:\Windows\System32\regsvr32.exeBinance SmartFlash v8.0 (Update 2025).tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft(C) Register Server
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
6652"C:\Users\admin\AppData\Local\Temp\is-AEINO.tmp\Binance SmartFlash v8.0 (Update 2025).tmp" /SL5="$702E4,2424516,813056,C:\Users\admin\AppData\Local\Temp\Binance SmartFlash v8.0 (Update 2025).exe" /VERYSILENTC:\Users\admin\AppData\Local\Temp\is-AEINO.tmp\Binance SmartFlash v8.0 (Update 2025).tmp
Binance SmartFlash v8.0 (Update 2025).exe
User:
admin
Company:
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-aeino.tmp\binance smartflash v8.0 (update 2025).tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comdlg32.dll
6812"C:\Users\admin\AppData\Local\Temp\Binance SmartFlash v8.0 (Update 2025).exe" C:\Users\admin\AppData\Local\Temp\Binance SmartFlash v8.0 (Update 2025).exe
explorer.exe
User:
admin
Company:
Integrity Level:
MEDIUM
Description:
Windows SQM Consolidator Setup
Exit code:
1
Version:
Modules
Images
c:\users\admin\appdata\local\temp\binance smartflash v8.0 (update 2025).exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comctl32.dll
Total events
12 428
Read events
12 428
Write events
0
Delete events
0

Modification events

No data
Executable files
6
Suspicious files
1
Text files
4
Unknown types
0

Dropped files

PID
Process
Filename
Type
1520Binance SmartFlash v8.0 (Update 2025).tmpC:\Users\admin\AppData\Local\Temp\is-UAVD2.tmp\_isetup\_setup64.tmpexecutable
MD5:E4211D6D009757C078A9FAC7FF4F03D4
SHA256:388A796580234EFC95F3B1C70AD4CB44BFDDC7BA0F9203BF4902B9929B136F95
6812Binance SmartFlash v8.0 (Update 2025).exeC:\Users\admin\AppData\Local\Temp\is-RGIDU.tmp\Binance SmartFlash v8.0 (Update 2025).tmpexecutable
MD5:18C15FD86017204D5A62154F5E0C10C9
SHA256:432CDC5E07C353E61258921016C82F3661144AF58AD2A6BED95D28CC6A53D6D5
6652Binance SmartFlash v8.0 (Update 2025).tmpC:\Users\admin\AppData\Local\Temp\is-L9Q85.tmp\_isetup\_setup64.tmpexecutable
MD5:E4211D6D009757C078A9FAC7FF4F03D4
SHA256:388A796580234EFC95F3B1C70AD4CB44BFDDC7BA0F9203BF4902B9929B136F95
4500Binance SmartFlash v8.0 (Update 2025).exeC:\Users\admin\AppData\Local\Temp\is-AEINO.tmp\Binance SmartFlash v8.0 (Update 2025).tmpexecutable
MD5:18C15FD86017204D5A62154F5E0C10C9
SHA256:432CDC5E07C353E61258921016C82F3661144AF58AD2A6BED95D28CC6A53D6D5
6172powershell.exeC:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_obm0jfcj.hw4.psm1text
MD5:D17FE0A3F47BE24A6453E9EF58C94641
SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
6652Binance SmartFlash v8.0 (Update 2025).tmpC:\Users\admin\AppData\Local\9Plum.pfxexecutable
MD5:26A6D8658198167661549A64C32C096B
SHA256:5E3EA2DCD14788E86BD3E88EF2E30C15710AB3412FF0A04225211C3DAAC711B0
2512powershell.exeC:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_eqmvimjo.kum.ps1text
MD5:D17FE0A3F47BE24A6453E9EF58C94641
SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
6172powershell.exeC:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_bp04fmx2.5az.ps1text
MD5:D17FE0A3F47BE24A6453E9EF58C94641
SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
2512powershell.exeC:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_dncl5x1o.q5i.psm1text
MD5:D17FE0A3F47BE24A6453E9EF58C94641
SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
6652Binance SmartFlash v8.0 (Update 2025).tmpC:\Users\admin\AppData\Local\is-5CTM9.tmpexecutable
MD5:26A6D8658198167661549A64C32C096B
SHA256:5E3EA2DCD14788E86BD3E88EF2E30C15710AB3412FF0A04225211C3DAAC711B0
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
21
DNS requests
15
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1268
svchost.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
1268
svchost.exe
GET
200
23.55.104.172:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
3620
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
3944
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
3620
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
5944
MoUsoCoreWorker.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1268
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4868
RUXIMICS.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
1268
svchost.exe
23.55.104.172:80
crl.microsoft.com
Akamai International B.V.
US
whitelisted
1268
svchost.exe
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
5944
MoUsoCoreWorker.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
3620
SIHClient.exe
20.12.23.50:443
slscr.update.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
3620
SIHClient.exe
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
  • 51.124.78.146
whitelisted
google.com
  • 142.250.185.78
whitelisted
crl.microsoft.com
  • 23.55.104.172
  • 23.55.104.190
whitelisted
www.microsoft.com
  • 95.101.149.131
whitelisted
slscr.update.microsoft.com
  • 20.12.23.50
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 20.3.187.198
whitelisted
login.live.com
  • 20.190.159.71
  • 40.126.31.71
  • 40.126.31.3
  • 40.126.31.0
  • 40.126.31.2
  • 20.190.159.0
  • 40.126.31.130
  • 20.190.159.75
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
client.wns.windows.com
  • 172.211.123.250
whitelisted
activation-v2.sls.microsoft.com
  • 40.91.76.224
whitelisted

Threats

No threats detected
No debug info