File name: | Roshade.Setup.3.3.1.exe |
Full analysis: | https://app.any.run/tasks/6d2a74da-337d-47a0-9c67-511ac2bee87e |
Verdict: | Malicious activity |
Analysis date: | April 29, 2025, 14:08:38 |
OS: | Windows 10 Professional (build: 19044, 64 bit) |
Indicators: | |
MIME: | application/vnd.microsoft.portable-executable |
File info: | PE32+ executable (GUI) x86-64, for MS Windows, 3 sections |
MD5: | FE51CDAC1D70CC17A57CAE25C164BF47 |
SHA1: | 814144CB9DF1C25942321FF04BB9B64BA55FC5FC |
SHA256: | 83FD3EB8248B4A41AB7BCBBE193D93E57BC0034D20259C6E21DC6A427CFE0DCD |
SSDEEP: | 98304:wSUoEyUQRr+SLX5fuK5QBEcMXiqvC7CjpLgMFX7e1V0fZAICcB5E3d66cIKwZ/0e:wn1QVFX5fZqBEcqvC2jTx76V0BACY3db |
.exe | | | UPX compressed Win32 Executable (87.1) |
---|---|---|
.exe | | | Generic Win/DOS Executable (6.4) |
.exe | | | DOS Executable Generic (6.4) |
MachineType: | AMD AMD64 |
---|---|
TimeStamp: | 2023:04:22 10:23:43+00:00 |
ImageFileCharacteristics: | Executable, Large address aware |
PEType: | PE32+ |
LinkerVersion: | 14.31 |
CodeSize: | 5988352 |
InitializedDataSize: | 8192 |
UninitializedDataSize: | 7053312 |
EntryPoint: | 0xc70170 |
OSVersion: | 6 |
ImageVersion: | - |
SubsystemVersion: | 6 |
Subsystem: | Windows GUI |
FileVersionNumber: | 3.3.1.0 |
ProductVersionNumber: | 3.3.1.0 |
FileFlagsMask: | 0x003f |
FileFlags: | (none) |
FileOS: | Windows NT 32-bit |
ObjectFileType: | Executable application |
FileSubtype: | - |
LanguageCode: | Neutral |
CharacterSet: | Unicode |
ProductName: | setup |
FileVersion: | 3.3.1 |
ProductVersion: | 3.3.1 |
FileDescription: | setup |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
644 | C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\Install\{D194B51B-FD62-4F79-A1F5-AA7635B107A4}\EDGEMITMP_0F709.tmp\setup.exe --type=crashpad-handler /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\EdgeWebView\User Data\Crashpad" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=135.0.7049.115 --annotation=exe=C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\Install\{D194B51B-FD62-4F79-A1F5-AA7635B107A4}\EDGEMITMP_0F709.tmp\setup.exe --annotation=plat=Win64 --annotation=prod=Edge --annotation=ver=135.0.3179.98 --initial-client-data=0x2c4,0x2c8,0x2cc,0x2a0,0x2d0,0x7ff713b67608,0x7ff713b67614,0x7ff713b67620 | C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\Install\{D194B51B-FD62-4F79-A1F5-AA7635B107A4}\EDGEMITMP_0F709.tmp\setup.exe | — | setup.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Installer Version: 135.0.3179.98 Modules
| |||||||||||||||
2384 | C:\WINDOWS\system32\SppExtComObj.exe -Embedding | C:\Windows\System32\SppExtComObj.Exe | — | svchost.exe | |||||||||||
User: NETWORK SERVICE Company: Microsoft Corporation Integrity Level: SYSTEM Description: KMS Connection Broker Version: 10.0.19041.3996 (WinBuild.160101.0800) Modules
| |||||||||||||||
2908 | C:\Users\admin\AppData\Local\Temp\EUC565.tmp\MicrosoftEdgeUpdate.exe /installsource taggedmi /install "appguid={F3017226-FE2A-4295-8BDF-00C3A9A7E4C5}&appname=Microsoft%20Edge%20Webview2%20Runtime&needsadmin=prefers" | C:\Users\admin\AppData\Local\Temp\EUC565.tmp\MicrosoftEdgeUpdate.exe | wv.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Modules
| |||||||||||||||
4040 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --disable-quic --no-appcompat-clear --mojo-platform-channel-handle=2196 --field-trial-handle=1912,i,16556532848869780940,8570919988484655556,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version /prefetch:3 | C:\Program Files\Google\Chrome\Application\chrome.exe | chrome.exe | ||||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Version: 122.0.6261.70 Modules
| |||||||||||||||
4068 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --no-appcompat-clear --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=11 --mojo-platform-channel-handle=4932 --field-trial-handle=1912,i,16556532848869780940,8570919988484655556,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 122.0.6261.70 Modules
| |||||||||||||||
4408 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --disable-quic --no-appcompat-clear --mojo-platform-channel-handle=2336 --field-trial-handle=1912,i,16556532848869780940,8570919988484655556,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Version: 122.0.6261.70 Modules
| |||||||||||||||
5048 | "C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\Install\{D194B51B-FD62-4F79-A1F5-AA7635B107A4}\MicrosoftEdge_X64_135.0.3179.98.exe" --msedgewebview --verbose-logging --do-not-launch-msedge --user-level | C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\Install\{D194B51B-FD62-4F79-A1F5-AA7635B107A4}\MicrosoftEdge_X64_135.0.3179.98.exe | MicrosoftEdgeUpdate.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Installer Version: 135.0.3179.98 Modules
| |||||||||||||||
5344 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Google\Chrome\User Data" /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Google\Chrome\User Data\Crashpad" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win64 --annotation=prod=Chrome --annotation=ver=122.0.6261.70 --initial-client-data=0x220,0x224,0x228,0x1d0,0x22c,0x7ffc88b5dc40,0x7ffc88b5dc4c,0x7ffc88b5dc58 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Version: 122.0.6261.70 Modules
| |||||||||||||||
5608 | "C:\Users\admin\AppData\Local\Temp\Roshade.Setup.3.3.1.exe" | C:\Users\admin\AppData\Local\Temp\Roshade.Setup.3.3.1.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Description: setup Version: 3.3.1 Modules
| |||||||||||||||
5668 | "C:\Users\admin\AppData\Local\Temp\wv.exe" | C:\Users\admin\AppData\Local\Temp\wv.exe | Roshade.Setup.3.3.1.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Update Setup Version: 1.3.195.49 Modules
|
(PID) Process: | (6724) chrome.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\BLBeacon |
Operation: | write | Name: | failed_count |
Value: 0 | |||
(PID) Process: | (6724) chrome.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\BLBeacon |
Operation: | write | Name: | state |
Value: 2 | |||
(PID) Process: | (6724) chrome.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\BLBeacon |
Operation: | write | Name: | state |
Value: 1 | |||
(PID) Process: | (6724) chrome.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\StabilityMetrics |
Operation: | write | Name: | user_experience_metrics.stability.exited_cleanly |
Value: 0 | |||
(PID) Process: | (6724) chrome.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96} |
Operation: | write | Name: | usagestats |
Value: 0 | |||
(PID) Process: | (2908) MicrosoftEdgeUpdate.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\EdgeUpdate |
Operation: | delete value | Name: | eulaaccepted |
Value: | |||
(PID) Process: | (2908) MicrosoftEdgeUpdate.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\EdgeUpdate |
Operation: | write | Name: | path |
Value: C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe | |||
(PID) Process: | (2908) MicrosoftEdgeUpdate.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\EdgeUpdate |
Operation: | write | Name: | UninstallCmdLine |
Value: "C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /uninstall | |||
(PID) Process: | (2908) MicrosoftEdgeUpdate.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\EdgeUpdate\Clients\{F3C4FE00-EFD5-403B-9569-398A20F1BA4A} |
Operation: | write | Name: | pv |
Value: 1.3.195.49 | |||
(PID) Process: | (2908) MicrosoftEdgeUpdate.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\EdgeUpdate\Clients\{F3C4FE00-EFD5-403B-9569-398A20F1BA4A} |
Operation: | write | Name: | name |
Value: Microsoft Edge Update |
PID | Process | Filename | Type | |
---|---|---|---|---|
5668 | wv.exe | C:\Users\admin\AppData\Local\Temp\EUC565.tmp\MicrosoftEdgeUpdateComRegisterShell64.exe | executable | |
MD5:A6D59861272EE24F43DDE137AB82B116 | SHA256:B3CE6EAC6BD0EAFFCCE5EA212C66A9C9A1344ED3DA86B5AE4BD5173B38990975 | |||
5668 | wv.exe | C:\Users\admin\AppData\Local\Temp\EUC565.tmp\msedgeupdate.dll | executable | |
MD5:34366289614548C60837E31DA6477A6E | SHA256:6EE3E95AA78DBD5B3F469F670072574AFA16EA00EE2A7077472BF0405F572635 | |||
5668 | wv.exe | C:\Users\admin\AppData\Local\Temp\EUC565.tmp\psuser_64.dll | executable | |
MD5:2D354F794E3F058A9D5D54DCBC3955EE | SHA256:06AB39D80A773024070B1A3A6CF57F3D736E964B959F6C1DDDB2FEA1C1E65411 | |||
5608 | Roshade.Setup.3.3.1.exe | C:\Users\admin\AppData\Local\Temp\wv.exe | executable | |
MD5:FA04ED70DC9743693C0B62776547BBF4 | SHA256:0A7FF586F6F5A830729949F301A444E4C565898463EBA1C7E907B3FE6EFC5267 | |||
5668 | wv.exe | C:\Users\admin\AppData\Local\Temp\EUC565.tmp\MicrosoftEdgeUpdateBroker.exe | executable | |
MD5:3183363DEE370C1ADB75B36D381C37DB | SHA256:A7DFC2A3833234D4378D5E5FF9F856BCFD5877FC769A11B17E738CF77D8000FD | |||
5668 | wv.exe | C:\Users\admin\AppData\Local\Temp\EUC565.tmp\MicrosoftEdgeComRegisterShellARM64.exe | executable | |
MD5:B2CA6C419F03D1AF9B283E8E696504DC | SHA256:274769D85EDB42835AA57E8A88FA300FD2B826E0DB6CC860A777244FCC883344 | |||
5668 | wv.exe | C:\Users\admin\AppData\Local\Temp\EUC565.tmp\psmachine_64.dll | executable | |
MD5:1F2C831EEA682084A8D08408A9A004C4 | SHA256:495B00D765FAAE46790E2B64FDA520CC6A2B344E88930527BC760E4EA351D5D6 | |||
5668 | wv.exe | C:\Users\admin\AppData\Local\Temp\EUC565.tmp\psmachine.dll | executable | |
MD5:F10322ED75B0567C0A69DBF1163F9503 | SHA256:7F82575A1DDD50364E8816B6525B3EC23C333138B58A8420CC0DC742326B4071 | |||
5668 | wv.exe | C:\Users\admin\AppData\Local\Temp\EUC565.tmp\psmachine_arm64.dll | executable | |
MD5:B4B144416C736F399F3AB4D9B9615ECC | SHA256:649AA23F9B426A7CF70143D64E969F9FE0A799B9A491620AC8FE7A6E7122CCA8 | |||
5668 | wv.exe | C:\Users\admin\AppData\Local\Temp\EUC565.tmp\psuser_arm64.dll | executable | |
MD5:6EDE259800392668309579B7C3EF1AD6 | SHA256:D8BF544B95EAFF7A7CB8CA9765AD74C3DBE192B79049E23722C169381F1605BD |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
756 | lsass.exe | GET | 200 | 2.23.77.188:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEApDqVCbATUviZV57HIIulA%3D | unknown | — | — | whitelisted |
8140 | svchost.exe | HEAD | 200 | 199.232.210.172:80 | http://msedge.f.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/bef3bb0b-b1c2-4068-a2cd-1eae1dd922b4?P1=1746540540&P2=404&P3=2&P4=R8Ukh2GtJeqrxc56n4HoUbKEJofno3V%2fX5w%2fcZGwpSlnL1nlHLRYpNjW2StEr7sonulYxApXOiTBpkEdOnZudQ%3d%3d | unknown | — | — | whitelisted |
6544 | svchost.exe | GET | 200 | 2.23.77.188:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
7852 | SIHClient.exe | GET | 200 | 95.101.149.131:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
8140 | svchost.exe | GET | 200 | 199.232.210.172:80 | http://msedge.f.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/bef3bb0b-b1c2-4068-a2cd-1eae1dd922b4?P1=1746540540&P2=404&P3=2&P4=R8Ukh2GtJeqrxc56n4HoUbKEJofno3V%2fX5w%2fcZGwpSlnL1nlHLRYpNjW2StEr7sonulYxApXOiTBpkEdOnZudQ%3d%3d | unknown | — | — | whitelisted |
7852 | SIHClient.exe | GET | 200 | 95.101.149.131:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
— | — | 20.73.194.208:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
2104 | svchost.exe | 20.73.194.208:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
5608 | Roshade.Setup.3.3.1.exe | 95.100.186.9:443 | go.microsoft.com | AKAMAI-AS | FR | whitelisted |
756 | lsass.exe | 2.23.77.188:80 | ocsp.digicert.com | AKAMAI-AS | DE | whitelisted |
5608 | Roshade.Setup.3.3.1.exe | 2.16.168.117:443 | msedge.sf.dl.delivery.mp.microsoft.com | Akamai International B.V. | RU | whitelisted |
3216 | svchost.exe | 172.211.123.250:443 | client.wns.windows.com | MICROSOFT-CORP-MSN-AS-BLOCK | FR | whitelisted |
6544 | svchost.exe | 40.126.31.67:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
6544 | svchost.exe | 2.23.77.188:80 | ocsp.digicert.com | AKAMAI-AS | DE | whitelisted |
2112 | svchost.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
Domain | IP | Reputation |
---|---|---|
google.com |
| whitelisted |
go.microsoft.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
msedge.sf.dl.delivery.mp.microsoft.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
login.live.com |
| whitelisted |
settings-win.data.microsoft.com |
| whitelisted |
clientservices.googleapis.com |
| whitelisted |
accounts.google.com |
| whitelisted |
www.google.com |
| whitelisted |
PID | Process | Class | Message |
---|---|---|---|
— | — | Misc activity | ET INFO Packed Executable Download |