| File name: | Roshade.Setup.3.3.1.exe |
| Full analysis: | https://app.any.run/tasks/6d2a74da-337d-47a0-9c67-511ac2bee87e |
| Verdict: | Malicious activity |
| Analysis date: | April 29, 2025, 14:08:38 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32+ executable (GUI) x86-64, for MS Windows, 3 sections |
| MD5: | FE51CDAC1D70CC17A57CAE25C164BF47 |
| SHA1: | 814144CB9DF1C25942321FF04BB9B64BA55FC5FC |
| SHA256: | 83FD3EB8248B4A41AB7BCBBE193D93E57BC0034D20259C6E21DC6A427CFE0DCD |
| SSDEEP: | 98304:wSUoEyUQRr+SLX5fuK5QBEcMXiqvC7CjpLgMFX7e1V0fZAICcB5E3d66cIKwZ/0e:wn1QVFX5fZqBEcqvC2jTx76V0BACY3db |
| .exe | | | UPX compressed Win32 Executable (87.1) |
|---|---|---|
| .exe | | | Generic Win/DOS Executable (6.4) |
| .exe | | | DOS Executable Generic (6.4) |
| MachineType: | AMD AMD64 |
|---|---|
| TimeStamp: | 2023:04:22 10:23:43+00:00 |
| ImageFileCharacteristics: | Executable, Large address aware |
| PEType: | PE32+ |
| LinkerVersion: | 14.31 |
| CodeSize: | 5988352 |
| InitializedDataSize: | 8192 |
| UninitializedDataSize: | 7053312 |
| EntryPoint: | 0xc70170 |
| OSVersion: | 6 |
| ImageVersion: | - |
| SubsystemVersion: | 6 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 3.3.1.0 |
| ProductVersionNumber: | 3.3.1.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Windows NT 32-bit |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| ProductName: | setup |
| FileVersion: | 3.3.1 |
| ProductVersion: | 3.3.1 |
| FileDescription: | setup |
PID | CMD | Path | Indicators | Parent process |
|---|---|---|---|---|
| 644 | C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\Install\{D194B51B-FD62-4F79-A1F5-AA7635B107A4}\EDGEMITMP_0F709.tmp\setup.exe --type=crashpad-handler /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\EdgeWebView\User Data\Crashpad" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=135.0.7049.115 --annotation=exe=C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\Install\{D194B51B-FD62-4F79-A1F5-AA7635B107A4}\EDGEMITMP_0F709.tmp\setup.exe --annotation=plat=Win64 --annotation=prod=Edge --annotation=ver=135.0.3179.98 --initial-client-data=0x2c4,0x2c8,0x2cc,0x2a0,0x2d0,0x7ff713b67608,0x7ff713b67614,0x7ff713b67620 | C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\Install\{D194B51B-FD62-4F79-A1F5-AA7635B107A4}\EDGEMITMP_0F709.tmp\setup.exe | — | setup.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Installer Version: 135.0.3179.98 | ||||
| 2384 | C:\WINDOWS\system32\SppExtComObj.exe -Embedding | C:\Windows\System32\SppExtComObj.Exe | — | svchost.exe |
User: NETWORK SERVICE Company: Microsoft Corporation Integrity Level: SYSTEM Description: KMS Connection Broker Version: 10.0.19041.3996 (WinBuild.160101.0800) | ||||
| 2908 | C:\Users\admin\AppData\Local\Temp\EUC565.tmp\MicrosoftEdgeUpdate.exe /installsource taggedmi /install "appguid={F3017226-FE2A-4295-8BDF-00C3A9A7E4C5}&appname=Microsoft%20Edge%20Webview2%20Runtime&needsadmin=prefers" | C:\Users\admin\AppData\Local\Temp\EUC565.tmp\MicrosoftEdgeUpdate.exe | wv.exe | |
User: admin Integrity Level: MEDIUM | ||||
| 4040 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --disable-quic --no-appcompat-clear --mojo-platform-channel-handle=2196 --field-trial-handle=1912,i,16556532848869780940,8570919988484655556,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version /prefetch:3 | C:\Program Files\Google\Chrome\Application\chrome.exe | chrome.exe | |
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Version: 122.0.6261.70 | ||||
| 4068 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --no-appcompat-clear --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=11 --mojo-platform-channel-handle=4932 --field-trial-handle=1912,i,16556532848869780940,8570919988484655556,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe |
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 122.0.6261.70 | ||||
| 4408 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --disable-quic --no-appcompat-clear --mojo-platform-channel-handle=2336 --field-trial-handle=1912,i,16556532848869780940,8570919988484655556,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe |
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Version: 122.0.6261.70 | ||||
| 5048 | "C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\Install\{D194B51B-FD62-4F79-A1F5-AA7635B107A4}\MicrosoftEdge_X64_135.0.3179.98.exe" --msedgewebview --verbose-logging --do-not-launch-msedge --user-level | C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\Install\{D194B51B-FD62-4F79-A1F5-AA7635B107A4}\MicrosoftEdge_X64_135.0.3179.98.exe | MicrosoftEdgeUpdate.exe | |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Installer Version: 135.0.3179.98 | ||||
| 5344 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Google\Chrome\User Data" /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Google\Chrome\User Data\Crashpad" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win64 --annotation=prod=Chrome --annotation=ver=122.0.6261.70 --initial-client-data=0x220,0x224,0x228,0x1d0,0x22c,0x7ffc88b5dc40,0x7ffc88b5dc4c,0x7ffc88b5dc58 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe |
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Version: 122.0.6261.70 | ||||
| 5608 | "C:\Users\admin\AppData\Local\Temp\Roshade.Setup.3.3.1.exe" | C:\Users\admin\AppData\Local\Temp\Roshade.Setup.3.3.1.exe | explorer.exe | |
User: admin Integrity Level: MEDIUM Description: setup Version: 3.3.1 | ||||
| 5668 | "C:\Users\admin\AppData\Local\Temp\wv.exe" | C:\Users\admin\AppData\Local\Temp\wv.exe | Roshade.Setup.3.3.1.exe | |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Update Setup Version: 1.3.195.49 | ||||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 5668 | wv.exe | C:\Users\admin\AppData\Local\Temp\EUC565.tmp\msedgeupdate.dll | executable | |
MD5:34366289614548C60837E31DA6477A6E | SHA256:6EE3E95AA78DBD5B3F469F670072574AFA16EA00EE2A7077472BF0405F572635 | |||
| 5668 | wv.exe | C:\Users\admin\AppData\Local\Temp\EUC565.tmp\psmachine.dll | executable | |
MD5:F10322ED75B0567C0A69DBF1163F9503 | SHA256:9DB888B286DC32656B936D5E1438D39D46DA82212826F36C29DD99FCB0419803 | |||
| 5668 | wv.exe | C:\Users\admin\AppData\Local\Temp\EUC565.tmp\MicrosoftEdgeUpdate.exe | executable | |
MD5:BBD650A482ED31B5FD9B1C1636A08EA1 | SHA256:C78F97F6E2DB213366AFB7EF57720CC0801CAFB428C436E8C8A780AB74F4C1E2 | |||
| 5668 | wv.exe | C:\Users\admin\AppData\Local\Temp\EUC565.tmp\psmachine_64.dll | executable | |
MD5:1F2C831EEA682084A8D08408A9A004C4 | SHA256:70991CB93309773CED85BE9FF4D687957A207FBD04F695A13273704DED1FB15B | |||
| 5668 | wv.exe | C:\Users\admin\AppData\Local\Temp\EUC565.tmp\MicrosoftEdgeUpdateOnDemand.exe | executable | |
MD5:23E508DF04911742E9051987A1FDDB99 | SHA256:49E43D73672AA99A5E2950D2421824B405834D7F94FC8CEFD7B3984ECAB258BD | |||
| 5668 | wv.exe | C:\Users\admin\AppData\Local\Temp\EUC565.tmp\MicrosoftEdgeUpdateComRegisterShell64.exe | executable | |
MD5:A6D59861272EE24F43DDE137AB82B116 | SHA256:146DC78518FDACB266295EE49CDB48E898D74B7F23B5C08D006D64577CDD6C6D | |||
| 5668 | wv.exe | C:\Users\admin\AppData\Local\Temp\EUC565.tmp\MicrosoftEdgeComRegisterShellARM64.exe | executable | |
MD5:B2CA6C419F03D1AF9B283E8E696504DC | SHA256:1AD04F1EF3A5C1DC31EFE1F08FAF6ABD35C0721E10D11DE31823DDBF5882E0D4 | |||
| 5668 | wv.exe | C:\Users\admin\AppData\Local\Temp\EUC565.tmp\psmachine_arm64.dll | executable | |
MD5:B4B144416C736F399F3AB4D9B9615ECC | SHA256:5EABB44405E975BF59F32A82A47CE49C7F26AF198443115CC02BBCB1E35F27E2 | |||
| 5668 | wv.exe | C:\Users\admin\AppData\Local\Temp\EUC565.tmp\MicrosoftEdgeUpdateBroker.exe | executable | |
MD5:3183363DEE370C1ADB75B36D381C37DB | SHA256:228BB625B37700C215E3B23C7E7DEEDE8931B32646CEBB80E3CFBFE9BE945EDB | |||
| 5668 | wv.exe | C:\Users\admin\AppData\Local\Temp\EUC565.tmp\EdgeUpdate.dat | binary | |
MD5:369BBC37CFF290ADB8963DC5E518B9B8 | SHA256:3D7EC761BEF1B1AF418B909F1C81CE577C769722957713FDAFBC8131B0A0C7D3 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
756 | lsass.exe | GET | 200 | 2.23.77.188:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEApDqVCbATUviZV57HIIulA%3D | unknown | — | — | whitelisted |
8140 | svchost.exe | HEAD | 200 | 199.232.210.172:80 | http://msedge.f.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/bef3bb0b-b1c2-4068-a2cd-1eae1dd922b4?P1=1746540540&P2=404&P3=2&P4=R8Ukh2GtJeqrxc56n4HoUbKEJofno3V%2fX5w%2fcZGwpSlnL1nlHLRYpNjW2StEr7sonulYxApXOiTBpkEdOnZudQ%3d%3d | unknown | — | — | whitelisted |
6544 | svchost.exe | GET | 200 | 2.23.77.188:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
7852 | SIHClient.exe | GET | 200 | 95.101.149.131:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
7852 | SIHClient.exe | GET | 200 | 95.101.149.131:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
8140 | svchost.exe | GET | 200 | 199.232.210.172:80 | http://msedge.f.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/bef3bb0b-b1c2-4068-a2cd-1eae1dd922b4?P1=1746540540&P2=404&P3=2&P4=R8Ukh2GtJeqrxc56n4HoUbKEJofno3V%2fX5w%2fcZGwpSlnL1nlHLRYpNjW2StEr7sonulYxApXOiTBpkEdOnZudQ%3d%3d | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
— | — | 20.73.194.208:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
2104 | svchost.exe | 20.73.194.208:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
5608 | Roshade.Setup.3.3.1.exe | 95.100.186.9:443 | go.microsoft.com | AKAMAI-AS | FR | whitelisted |
756 | lsass.exe | 2.23.77.188:80 | ocsp.digicert.com | AKAMAI-AS | DE | whitelisted |
5608 | Roshade.Setup.3.3.1.exe | 2.16.168.117:443 | msedge.sf.dl.delivery.mp.microsoft.com | Akamai International B.V. | RU | whitelisted |
3216 | svchost.exe | 172.211.123.250:443 | client.wns.windows.com | MICROSOFT-CORP-MSN-AS-BLOCK | FR | whitelisted |
6544 | svchost.exe | 40.126.31.67:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
6544 | svchost.exe | 2.23.77.188:80 | ocsp.digicert.com | AKAMAI-AS | DE | whitelisted |
2112 | svchost.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
Domain | IP | Reputation |
|---|---|---|
google.com |
| whitelisted |
go.microsoft.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
msedge.sf.dl.delivery.mp.microsoft.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
login.live.com |
| whitelisted |
settings-win.data.microsoft.com |
| whitelisted |
clientservices.googleapis.com |
| whitelisted |
accounts.google.com |
| whitelisted |
www.google.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
8140 | svchost.exe | Misc activity | ET INFO Packed Executable Download |