File name:

chsetup-1.46 (1).exe

Full analysis: https://app.any.run/tasks/d566a05e-c9b6-4a41-8f51-65f362f872f9
Verdict: Malicious activity
Analysis date: January 27, 2024, 17:56:08
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

7D3B88C49E4D85A28362A3D193C44D79

SHA1:

B8A7A3A46B58D6675815CCB0F52BA6D15A0C6743

SHA256:

8C26A5415210F4942138A8599159781BDC9AC6EA42908CEA364A6C34B5C23164

SSDEEP:

98304:o0OC0pO5S+IfaJzyn2U/XJe37qClomSqPEykVj3W9m2xFJ6iZEYBl5e67aWjAg+w:PBQIEi4zjTt7RV3qh

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • chsetup-1.46 (1).exe (PID: 2640)
      • chsetup-1.46 (1).exe (PID: 2724)
      • chsetup-1.46 (1).tmp (PID: 2484)
    • Registers / Runs the DLL via REGSVR32.EXE

      • chsetup-1.46 (1).tmp (PID: 2484)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • chsetup-1.46 (1).exe (PID: 2640)
      • chsetup-1.46 (1).exe (PID: 2724)
      • chsetup-1.46 (1).tmp (PID: 2484)
    • Reads the Windows owner or organization settings

      • chsetup-1.46 (1).tmp (PID: 2484)
    • Process drops legitimate windows executable

      • chsetup-1.46 (1).tmp (PID: 2484)
    • Uses REG/REGEDIT.EXE to modify registry

      • chsetup-1.46 (1).tmp (PID: 984)
    • The process drops C-runtime libraries

      • chsetup-1.46 (1).tmp (PID: 2484)
    • Reads the Internet Settings

      • ch.exe (PID: 1496)
  • INFO

    • Create files in a temporary directory

      • chsetup-1.46 (1).exe (PID: 2640)
      • chsetup-1.46 (1).exe (PID: 2724)
    • Checks supported languages

      • chsetup-1.46 (1).exe (PID: 2640)
      • chsetup-1.46 (1).exe (PID: 2724)
      • chsetup-1.46 (1).tmp (PID: 984)
      • chsetup-1.46 (1).tmp (PID: 2484)
      • ch.exe (PID: 1496)
      • ch.exe (PID: 3072)
    • Reads the computer name

      • chsetup-1.46 (1).tmp (PID: 984)
      • chsetup-1.46 (1).tmp (PID: 2484)
      • ch.exe (PID: 3072)
      • ch.exe (PID: 1496)
    • Creates files in the program directory

      • chsetup-1.46 (1).tmp (PID: 2484)
    • Creates files or folders in the user directory

      • ch.exe (PID: 1496)
      • ch.exe (PID: 3072)
    • Reads Environment values

      • ch.exe (PID: 1496)
    • Checks proxy server information

      • ch.exe (PID: 1496)
    • Reads product name

      • ch.exe (PID: 1496)
    • Reads the machine GUID from the registry

      • ch.exe (PID: 1496)
    • Manual execution by a user

      • ch.exe (PID: 3072)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable Delphi generic (45.2)
.dll | Win32 Dynamic Link Library (generic) (20.9)
.exe | Win32 Executable (generic) (14.3)
.exe | Win16/32 Executable Delphi generic (6.6)
.exe | Generic Win/DOS Executable (6.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2018:06:14 15:27:46+02:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 66560
InitializedDataSize: 53760
UninitializedDataSize: -
EntryPoint: 0x1181c
OSVersion: 5
ImageVersion: 6
SubsystemVersion: 5
Subsystem: Windows GUI
FileVersionNumber: 0.0.0.0
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: Józef Starosczyk
FileDescription: Copy Handler Setup
FileVersion: 1.46
LegalCopyright: Copyright © 2001-2016 Józef Starosczyk
ProductName: Copy Handler
ProductVersion: 1.46
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
51
Monitored processes
8
Malicious processes
4
Suspicious processes
1

Behavior graph

Click at the process to see the details
start chsetup-1.46 (1).exe chsetup-1.46 (1).tmp no specs chsetup-1.46 (1).exe chsetup-1.46 (1).tmp regsvr32.exe no specs reg.exe no specs ch.exe ch.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
984"C:\Users\admin\AppData\Local\Temp\is-9F312.tmp\chsetup-1.46 (1).tmp" /SL5="$8010A,10043098,121344,C:\Users\admin\AppData\Local\Temp\chsetup-1.46 (1).exe" C:\Users\admin\AppData\Local\Temp\is-9F312.tmp\chsetup-1.46 (1).tmpchsetup-1.46 (1).exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-9f312.tmp\chsetup-1.46 (1).tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1496"C:\Program Files\Copy Handler\ch.exe"C:\Program Files\Copy Handler\ch.exe
chsetup-1.46 (1).tmp
User:
admin
Company:
Integrity Level:
MEDIUM
Description:
Copy Handler
Exit code:
0
Version:
1.46
Modules
Images
c:\program files\copy handler\ch.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\winmm.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2484"C:\Users\admin\AppData\Local\Temp\is-8EFCT.tmp\chsetup-1.46 (1).tmp" /SL5="$120128,10043098,121344,C:\Users\admin\AppData\Local\Temp\chsetup-1.46 (1).exe" /SPAWNWND=$1800E6 /NOTIFYWND=$8010A C:\Users\admin\AppData\Local\Temp\is-8EFCT.tmp\chsetup-1.46 (1).tmp
chsetup-1.46 (1).exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-8efct.tmp\chsetup-1.46 (1).tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2640"C:\Users\admin\AppData\Local\Temp\chsetup-1.46 (1).exe" C:\Users\admin\AppData\Local\Temp\chsetup-1.46 (1).exe
explorer.exe
User:
admin
Company:
Józef Starosczyk
Integrity Level:
MEDIUM
Description:
Copy Handler Setup
Exit code:
0
Version:
1.46
Modules
Images
c:\users\admin\appdata\local\temp\chsetup-1.46 (1).exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2724"C:\Users\admin\AppData\Local\Temp\chsetup-1.46 (1).exe" /SPAWNWND=$1800E6 /NOTIFYWND=$8010A C:\Users\admin\AppData\Local\Temp\chsetup-1.46 (1).exe
chsetup-1.46 (1).tmp
User:
admin
Company:
Józef Starosczyk
Integrity Level:
HIGH
Description:
Copy Handler Setup
Exit code:
0
Version:
1.46
Modules
Images
c:\users\admin\appdata\local\temp\chsetup-1.46 (1).exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2792"Reg.exe" delete "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "Copy Handler" /fC:\Windows\System32\reg.exechsetup-1.46 (1).tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Registry Console Tool
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\reg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2828"C:\Windows\system32\regsvr32.exe" /s "C:\Program Files\Copy Handler\chext.dll"C:\Windows\System32\regsvr32.exechsetup-1.46 (1).tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3072"C:\Program Files\Copy Handler\ch.exe" C:\Program Files\Copy Handler\ch.exeexplorer.exe
User:
admin
Company:
Integrity Level:
MEDIUM
Description:
Copy Handler
Exit code:
0
Version:
1.46
Modules
Images
c:\program files\copy handler\ch.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\winmm.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
Total events
1 736
Read events
1 720
Write events
10
Delete events
6

Modification events

(PID) Process:(1496) ch.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(1496) ch.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
460000005B010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(2484) chsetup-1.46 (1).tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:RegFilesHash
Value:
77C543E873C204480C0506C1A7A8F4A7BB4C4940C9E3792CD89DDBB98D0067F3
(PID) Process:(2484) chsetup-1.46 (1).tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:RegFiles0000
Value:
C:\Program Files\Copy Handler\help\english.chm
(PID) Process:(2484) chsetup-1.46 (1).tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:Sequence
Value:
1
(PID) Process:(2484) chsetup-1.46 (1).tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:SessionHash
Value:
30E45371593795EDCCA39913580F45845C76C0904D8BB013071389020096B1C3
(PID) Process:(2484) chsetup-1.46 (1).tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:Owner
Value:
B4090000143F46214A51DA01
(PID) Process:(2484) chsetup-1.46 (1).tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete keyName:(default)
Value:
(PID) Process:(1496) ch.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(1496) ch.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
Executable files
134
Suspicious files
14
Text files
39
Unknown types
0

Dropped files

PID
Process
Filename
Type
2640chsetup-1.46 (1).exeC:\Users\admin\AppData\Local\Temp\is-9F312.tmp\chsetup-1.46 (1).tmpexecutable
MD5:34ACC2BDB45A9C436181426828C4CB49
SHA256:9C81817ACD4982632D8C7F1DF3898FCA1477577738184265D735F49FC5480F07
2484chsetup-1.46 (1).tmpC:\Program Files\Copy Handler\help\is-2TCON.tmpbinary
MD5:AE337A599A929989554442FBBC071889
SHA256:A2BC8B445F26F0CA4F87EC90F153190EA6DCC67C4F67F6B261987BB8D96C900F
2484chsetup-1.46 (1).tmpC:\Program Files\Copy Handler\help\english.chmbinary
MD5:09147CECA3BF448120AE5DDE3486D454
SHA256:521972F1C87E9C72A6A78960A5D58E09A336C23560D0174A84ABF3A893A1E1E3
2484chsetup-1.46 (1).tmpC:\Program Files\Copy Handler\unins000.exeexecutable
MD5:C3E055D3198C015413003CDC8281E551
SHA256:25C98E0794BCCF189A32FBE88776B2D29E612F46CDEC4C8AA3551BBC1DE503DD
2484chsetup-1.46 (1).tmpC:\Program Files\Copy Handler\langs\is-HGR83.tmptext
MD5:BDD93A1EC8CB340735E5BA32FCC5F208
SHA256:D9BE5ACA1A8F7DC47B9762AE44B59A0AD7685795DAA7831C2BF332A3FC25FC8A
2484chsetup-1.46 (1).tmpC:\Program Files\Copy Handler\langs\chinese.lngtext
MD5:BE639C6B414A34D093E41F8BAC09B335
SHA256:0B6E0805B5DE1AF3C20C0AE281FA79380ECA6F3D36F0824D60F3288C669B1A8C
2484chsetup-1.46 (1).tmpC:\Program Files\Copy Handler\langs\bulgarian.lngtext
MD5:BDD93A1EC8CB340735E5BA32FCC5F208
SHA256:D9BE5ACA1A8F7DC47B9762AE44B59A0AD7685795DAA7831C2BF332A3FC25FC8A
2484chsetup-1.46 (1).tmpC:\Program Files\Copy Handler\langs\is-2N9LM.tmptext
MD5:B426270C8DC69D6832E0EB04B127B441
SHA256:2B1E3AEDFA24CF1189C401BC4522990E7FD89FEE6A493256AA0C6FF94D38AC0D
2484chsetup-1.46 (1).tmpC:\Program Files\Copy Handler\langs\is-N65F5.tmptext
MD5:BE639C6B414A34D093E41F8BAC09B335
SHA256:0B6E0805B5DE1AF3C20C0AE281FA79380ECA6F3D36F0824D60F3288C669B1A8C
2484chsetup-1.46 (1).tmpC:\Program Files\Copy Handler\langs\is-GOS6K.tmptext
MD5:3D2E8F1C7629C801C24EBDB6A44D1779
SHA256:4679EF93F0924BAA783E5C8348A44561FD2BC282C9D811900AAB3DEEF806B2E1
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
6
DNS requests
1
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1080
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1496
ch.exe
95.155.96.168:443
www.copyhandler.com
Netia SA
PL
unknown

DNS requests

Domain
IP
Reputation
www.copyhandler.com
  • 95.155.96.168
unknown

Threats

No threats detected
No debug info