File name:

ovisetup.exe

Full analysis: https://app.any.run/tasks/6ad85068-131b-4815-9ec5-f140c71a720f
Verdict: Malicious activity
Analysis date: February 18, 2024, 18:28:43
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

1692AEC61DDCDDA471DEFA199C62D25A

SHA1:

484AF221468DDB534B74E12970DE80D5DFEE2B28

SHA256:

84BDE632C5BFD2A7FF84E579E6F7561543CA0AAD6D8E7275DAE5926BA4F561C1

SSDEEP:

49152:9Hox6U/D1LbDxklrSWZAhizWV4yFK73bBxaaNNG0pHSdtDLboHTBWpHg6UvM98Il:2x6qaAVpchNG0pHA57HgR0

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • ovisetup.exe (PID: 3700)
      • dxwebsetup.exe (PID: 3428)
      • dxwsetup.exe (PID: 4060)
    • Changes the autorun value in the registry

      • dxwebsetup.exe (PID: 3428)
    • Creates a writable file in the system directory

      • dxwsetup.exe (PID: 4060)
    • Actions looks like stealing of personal data

      • ovisetup.exe (PID: 3700)
      • OpenIV.exe (PID: 2560)
      • OpenIV.exe (PID: 3336)
  • SUSPICIOUS

    • Reads the Internet Settings

      • ovisetup.exe (PID: 3700)
      • dxwsetup.exe (PID: 4060)
      • OpenIV.exe (PID: 2560)
      • OpenIV.exe (PID: 3336)
    • Reads settings of System Certificates

      • ovisetup.exe (PID: 3700)
      • dxwsetup.exe (PID: 4060)
      • OpenIV.exe (PID: 2560)
      • OpenIV.exe (PID: 3336)
    • Executable content was dropped or overwritten

      • ovisetup.exe (PID: 3700)
      • dxwebsetup.exe (PID: 3428)
      • dxwsetup.exe (PID: 4060)
    • Process drops legitimate windows executable

      • ovisetup.exe (PID: 3700)
      • dxwebsetup.exe (PID: 3428)
      • dxwsetup.exe (PID: 4060)
    • Starts a Microsoft application from unusual location

      • dxwebsetup.exe (PID: 2036)
      • dxwebsetup.exe (PID: 3428)
      • dxwsetup.exe (PID: 4060)
    • Reads security settings of Internet Explorer

      • ovisetup.exe (PID: 3700)
      • dxwsetup.exe (PID: 4060)
    • Searches for installed software

      • dllhost.exe (PID: 3912)
      • dxwsetup.exe (PID: 4060)
    • Creates/Modifies COM task schedule object

      • dxwsetup.exe (PID: 4060)
    • Creates a software uninstall entry

      • ovisetup.exe (PID: 3700)
    • Executes as Windows Service

      • VSSVC.exe (PID: 3164)
    • Checks Windows Trust Settings

      • dxwsetup.exe (PID: 4060)
  • INFO

    • Checks supported languages

      • ovisetup.exe (PID: 3700)
      • dxwebsetup.exe (PID: 3428)
      • dxwsetup.exe (PID: 4060)
      • OpenIV.exe (PID: 2560)
      • OpenIV.exe (PID: 3336)
    • Reads product name

      • ovisetup.exe (PID: 3700)
      • OpenIV.exe (PID: 2560)
      • OpenIV.exe (PID: 3336)
    • Create files in a temporary directory

      • ovisetup.exe (PID: 3700)
      • dxwebsetup.exe (PID: 3428)
      • dxwsetup.exe (PID: 4060)
    • Reads the computer name

      • ovisetup.exe (PID: 3700)
      • dxwsetup.exe (PID: 4060)
      • OpenIV.exe (PID: 2560)
      • OpenIV.exe (PID: 3336)
    • Process checks whether UAC notifications are on

      • ovisetup.exe (PID: 3700)
    • Reads Environment values

      • ovisetup.exe (PID: 3700)
      • OpenIV.exe (PID: 2560)
      • OpenIV.exe (PID: 3336)
    • Checks proxy server information

      • ovisetup.exe (PID: 3700)
      • dxwsetup.exe (PID: 4060)
    • Reads the software policy settings

      • ovisetup.exe (PID: 3700)
      • dxwsetup.exe (PID: 4060)
      • OpenIV.exe (PID: 2560)
      • OpenIV.exe (PID: 3336)
    • Reads the machine GUID from the registry

      • ovisetup.exe (PID: 3700)
      • dxwsetup.exe (PID: 4060)
      • OpenIV.exe (PID: 2560)
      • OpenIV.exe (PID: 3336)
    • Creates files or folders in the user directory

      • dxwsetup.exe (PID: 4060)
      • ovisetup.exe (PID: 3700)
      • OpenIV.exe (PID: 2560)
    • Manual execution by a user

      • OpenIV.exe (PID: 3336)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (67.7)
.exe | Win32 EXE PECompact compressed (generic) (25.6)
.exe | Win32 Executable (generic) (2.7)
.exe | Win16/32 Executable Delphi generic (1.2)
.exe | Generic Win/DOS Executable (1.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2022:01:10 20:31:28+00:00
ImageFileCharacteristics: Executable, No line numbers, No symbols, Large address aware, Bytes reversed lo, 32-bit, Removable run from swap, Net run from swap, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 3798528
InitializedDataSize: 827392
UninitializedDataSize: -
EntryPoint: 0x3a03e8
OSVersion: 5
ImageVersion: -
SubsystemVersion: 5
Subsystem: Windows GUI
FileVersionNumber: 4.1.0.47
ProductVersionNumber: 4.1.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Russian
CharacterSet: Windows, Cyrillic
CompanyName: New Technology Studio
FileDescription: OpenIV setup
FileVersion: 4.1.0.47
InternalName: setup.exe
LegalCopyright: © New Technology Studio
OriginalFileName: ovisetup.exe
ProductName: OpenIV
ProductVersion: 4.1.0.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
53
Monitored processes
8
Malicious processes
6
Suspicious processes
0

Behavior graph

Click at the process to see the details
start ovisetup.exe dxwebsetup.exe no specs dxwebsetup.exe dxwsetup.exe vssvc.exe no specs SPPSurrogate no specs openiv.exe openiv.exe

Process information

PID
CMD
Path
Indicators
Parent process
2036"C:\Users\admin\AppData\Local\Temp\OpenIV Setup_0017F2CC\dxwebsetup.exe" /QC:\Users\admin\AppData\Local\Temp\OpenIV Setup_0017F2CC\dxwebsetup.exeovisetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
DirectX 9.0 Web setup
Exit code:
3221226540
Version:
9.29.1974.0
Modules
Images
c:\users\admin\appdata\local\temp\openiv setup_0017f2cc\dxwebsetup.exe
c:\windows\system32\ntdll.dll
2560"C:\Users\admin\AppData\Local\New Technology Studio\Apps\OpenIV\OpenIV.exe" C:\Users\admin\AppData\Local\New Technology Studio\Apps\OpenIV\OpenIV.exe
ovisetup.exe
User:
admin
Company:
New Technology Studio
Integrity Level:
MEDIUM
Description:
OpenIV
Exit code:
0
Version:
4.1.0.1502
Modules
Images
c:\users\admin\appdata\local\new technology studio\apps\openiv\openiv.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
3164C:\Windows\system32\vssvc.exeC:\Windows\System32\VSSVC.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Volume Shadow Copy Service
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\vssvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3336"C:\Users\admin\AppData\Local\New Technology Studio\Apps\OpenIV\OpenIV.exe" C:\Users\admin\AppData\Local\New Technology Studio\Apps\OpenIV\OpenIV.exe
explorer.exe
User:
admin
Company:
New Technology Studio
Integrity Level:
MEDIUM
Description:
OpenIV
Exit code:
0
Version:
4.1.0.1502
Modules
Images
c:\users\admin\appdata\local\new technology studio\apps\openiv\openiv.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
3428"C:\Users\admin\AppData\Local\Temp\OpenIV Setup_0017F2CC\dxwebsetup.exe" /QC:\Users\admin\AppData\Local\Temp\OpenIV Setup_0017F2CC\dxwebsetup.exe
ovisetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
DirectX 9.0 Web setup
Exit code:
0
Version:
9.29.1974.0
Modules
Images
c:\users\admin\appdata\local\temp\openiv setup_0017f2cc\dxwebsetup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3700"C:\Users\admin\Desktop\ovisetup.exe" C:\Users\admin\Desktop\ovisetup.exe
explorer.exe
User:
admin
Company:
New Technology Studio
Integrity Level:
MEDIUM
Description:
OpenIV setup
Exit code:
0
Version:
4.1.0.47
Modules
Images
c:\users\admin\desktop\ovisetup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
3912C:\Windows\system32\DllHost.exe /Processid:{F32D97DF-E3E5-4CB9-9E3E-0EB5B4E49801}C:\Windows\System32\dllhost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
COM Surrogate
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\dllhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
4060C:\Users\admin\AppData\Local\Temp\IXP000.TMP\dxwsetup.exe /windowsupdateC:\Users\admin\AppData\Local\Temp\IXP000.TMP\dxwsetup.exe
dxwebsetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
DirectX Setup
Exit code:
0
Version:
4.9.0.0904
Modules
Images
c:\users\admin\appdata\local\temp\ixp000.tmp\dxwsetup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
Total events
54 394
Read events
53 948
Write events
428
Delete events
18

Modification events

(PID) Process:(3700) ovisetup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(3700) ovisetup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:delete valueName:ProxyServer
Value:
(PID) Process:(3700) ovisetup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:delete valueName:ProxyOverride
Value:
(PID) Process:(3700) ovisetup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:delete valueName:AutoConfigURL
Value:
(PID) Process:(3700) ovisetup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:delete valueName:AutoDetect
Value:
(PID) Process:(3700) ovisetup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
460000005C010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(3700) ovisetup.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3700) ovisetup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3700) ovisetup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(3700) ovisetup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
Executable files
370
Suspicious files
436
Text files
803
Unknown types
172

Dropped files

PID
Process
Filename
Type
3700ovisetup.exeC:\Users\admin\AppData\Local\Temp\OpenIV_Setup_Install.logtext
MD5:3FA9AB7E63E1D0689FFA03E303ED3AC7
SHA256:FAAE1826A141C810995334469053A266C475406076EFD0EE3C74F15712C3584F
3428dxwebsetup.exeC:\Users\admin\AppData\Local\Temp\IXP000.TMP\dsetup.dllexecutable
MD5:984CAD22FA542A08C5D22941B888D8DC
SHA256:57BC22850BB8E0BCC511A9B54CD3DA18EEC61F3088940C07D63B9B74E7FE2308
4060dxwsetup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\80237EE4964FC9C409AAF55BF996A292_E503B048B745DFA14B81FCFC68D6DECEder
MD5:1BE42D1504E4D082EF24A0508AF687A9
SHA256:A84C606862B5405327BCB808211ADEB2A949ED8CA7A7DF081D0D891362E57814
3428dxwebsetup.exeC:\Users\admin\AppData\Local\Temp\IXP000.TMP\dxwsetup.exeexecutable
MD5:AC3A5F7BE8CD13A863B50AB5FE00B71C
SHA256:8F5E89298E3DC2E22D47515900C37CCA4EE121C5BA06A6D962D40AD6E1A595DA
3700ovisetup.exeC:\Users\admin\AppData\Local\Temp\OpenIV Setup_0017F2CC\dxwebsetup.exeexecutable
MD5:BCBB7C0CD9696068988953990EC5BD11
SHA256:34F64699D4830145CAE69BD40115B1F326E70FC6A98456CB3DF996D947DDDCA4
3428dxwebsetup.exeC:\Users\admin\AppData\Local\Temp\IXP000.TMP\dsetup32.dllexecutable
MD5:A5412A144F63D639B47FCC1BA68CB029
SHA256:8A011DA043A4B81E2B3D41A332E0FF23A65D546BD7636E8BC74885E8746927D6
3428dxwebsetup.exeC:\Users\admin\AppData\Local\Temp\IXP000.TMP\dxwsetup.inftext
MD5:AD8982EAA02C7AD4D7CDCBC248CAA941
SHA256:D63C35E9B43EB0F28FFC28F61C9C9A306DA9C9DE3386770A7EB19FAA44DBFC00
3428dxwebsetup.exeC:\Users\admin\AppData\Local\Temp\IXP000.TMP\dxwsetup.ciftext
MD5:7B1FBE9F5F43B2261234B78FE115CF8E
SHA256:762FF640013DB2BD4109D7DF43A867303093815751129BD1E33F16BF02E52CCE
4060dxwsetup.exeC:\Windows\system32\directx\websetup\SET7DB.tmpexecutable
MD5:984CAD22FA542A08C5D22941B888D8DC
SHA256:57BC22850BB8E0BCC511A9B54CD3DA18EEC61F3088940C07D63B9B74E7FE2308
4060dxwsetup.exeC:\Windows\Logs\DirectX.logtext
MD5:11877358E331D67E4A0A6226E771E574
SHA256:224EC25DD68E59A630F46EF33DBBD8090264B5FB7A80E81135354226ACD27DE8
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
88
TCP/UDP connections
25
DNS requests
6
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4060
dxwsetup.exe
GET
302
23.32.97.192:80
http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/dxupdate.cab
unknown
unknown
4060
dxwsetup.exe
GET
304
184.24.77.205:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?dd4108ad84189a59
unknown
unknown
4060
dxwsetup.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEALnkXH7gCHpP%2BLZg4NMUMA%3D
unknown
binary
471 b
unknown
4060
dxwsetup.exe
GET
302
23.32.97.192:80
http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Feb2006_xact_x86.cab
unknown
unknown
4060
dxwsetup.exe
GET
302
23.32.97.192:80
http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Apr2006_xact_x86.cab
unknown
unknown
4060
dxwsetup.exe
GET
302
23.32.97.192:80
http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Apr2006_xinput_x86.cab
unknown
unknown
4060
dxwsetup.exe
GET
302
23.32.97.192:80
http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Jun2006_xact_x86.cab
unknown
unknown
4060
dxwsetup.exe
GET
302
23.32.97.192:80
http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Aug2006_xact_x86.cab
unknown
unknown
4060
dxwsetup.exe
GET
302
23.32.97.192:80
http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Aug2006_xinput_x86.cab
unknown
unknown
4060
dxwsetup.exe
GET
302
23.32.97.192:80
http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Oct2006_xact_x86.cab
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
3700
ovisetup.exe
188.114.96.3:443
ntscorp.ru
CLOUDFLARENET
NL
unknown
4060
dxwsetup.exe
23.32.97.192:80
download.microsoft.com
AKAMAI-AS
SE
unknown
4060
dxwsetup.exe
23.32.97.192:443
download.microsoft.com
AKAMAI-AS
SE
unknown
4060
dxwsetup.exe
184.24.77.205:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown
4060
dxwsetup.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
1080
svchost.exe
93.184.221.240:80
ctldl.windowsupdate.com
EDGECAST
GB
whitelisted
2560
OpenIV.exe
188.114.96.3:443
ntscorp.ru
CLOUDFLARENET
NL
unknown

DNS requests

Domain
IP
Reputation
ntscorp.ru
  • 188.114.96.3
  • 188.114.97.3
unknown
download.microsoft.com
  • 23.32.97.192
whitelisted
ctldl.windowsupdate.com
  • 184.24.77.205
  • 184.24.77.197
  • 184.24.77.174
  • 184.24.77.207
  • 184.24.77.173
  • 184.24.77.209
  • 184.24.77.199
  • 184.24.77.208
  • 184.24.77.206
  • 93.184.221.240
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
api.openiv.com
  • 51.75.124.107
unknown

Threats

No threats detected
Process
Message
dxwsetup.exe
DLL_PROCESS_ATTACH
dxwsetup.exe
DLL_PROCESS_ATTACH
dxwsetup.exe
DLL_PROCESS_DETACH
dxwsetup.exe
DLL_PROCESS_DETACH