File name:

setup_lib_v3.exe

Full analysis: https://app.any.run/tasks/ccf406a4-f8ef-4d89-b3b0-a4356ade6126
Verdict: Malicious activity
Analysis date: November 22, 2023, 10:56:34
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

B373CDF58224002865E5CB8ECC3F0508

SHA1:

774E8F7A92E2614A6F5E13CDBA4E4E41869F8C6D

SHA256:

8FD8A042402DD42814E989506086D7A7F932961191148E0C901A842714057083

SSDEEP:

98304:1+nv5cUwSXSAZqQvWB99zGO/HqTSxNMr6yYOeSMlDK12a2AWHsOHLPKJluPqR/Ty:VM4

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • setup_lib_v3.exe (PID: 3624)
      • setup_lib_v3.tmp (PID: 3380)
      • setup_lib_v3.exe (PID: 3632)
      • setup_lib_v3.tmp (PID: 3656)
    • Registers / Runs the DLL via REGSVR32.EXE

      • setup_lib_v3.tmp (PID: 3656)
  • SUSPICIOUS

    • Reads the Windows owner or organization settings

      • setup_lib_v3.tmp (PID: 3380)
      • setup_lib_v3.tmp (PID: 3656)
    • Process drops legitimate windows executable

      • setup_lib_v3.tmp (PID: 3380)
      • setup_lib_v3.tmp (PID: 3656)
    • Reads the Internet Settings

      • setup_lib_v3.tmp (PID: 3380)
  • INFO

    • Checks supported languages

      • setup_lib_v3.exe (PID: 3624)
      • setup_lib_v3.tmp (PID: 3380)
      • setup_lib_v3.exe (PID: 3632)
      • setup_lib_v3.tmp (PID: 3656)
    • Create files in a temporary directory

      • setup_lib_v3.exe (PID: 3624)
      • setup_lib_v3.tmp (PID: 3380)
      • setup_lib_v3.exe (PID: 3632)
      • setup_lib_v3.tmp (PID: 3656)
    • Manual execution by a user

      • setup_lib_v3.exe (PID: 3624)
    • Reads the computer name

      • setup_lib_v3.tmp (PID: 3380)
      • setup_lib_v3.tmp (PID: 3656)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable Delphi generic (45.2)
.dll | Win32 Dynamic Link Library (generic) (20.9)
.exe | Win32 Executable (generic) (14.3)
.exe | Win16/32 Executable Delphi generic (6.6)
.exe | Generic Win/DOS Executable (6.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2014:07:09 09:58:13+02:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 65024
InitializedDataSize: 53248
UninitializedDataSize: -
EntryPoint: 0x113bc
OSVersion: 5
ImageVersion: 6
SubsystemVersion: 5
Subsystem: Windows GUI
FileVersionNumber: 1.3.0.1
ProductVersionNumber: 1.3.0.1
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: zlib data compression library
FileVersion: 1.3.0.1
LegalCopyright: © 1995-2006 Jean-loup Gailly & Mark Adler
ProductName: zlib13
ProductVersion: 1.3.0.1
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
44
Monitored processes
6
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
start runas.exe no specs setup_lib_v3.exe setup_lib_v3.tmp no specs setup_lib_v3.exe no specs setup_lib_v3.tmp no specs regsvr32.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
3156"C:\Windows\System32\runas.exe" /user:administrator C:\Users\admin\Desktop\setup_lib_v3.exeC:\Windows\System32\runas.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Run As Utility
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\runas.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\credui.dll
c:\windows\system32\user32.dll
3380"C:\Users\admin\AppData\Local\Temp\is-CNSJ4.tmp\setup_lib_v3.tmp" /SL5="$90134,2491388,119296,C:\Users\admin\Desktop\setup_lib_v3.exe" C:\Users\admin\AppData\Local\Temp\is-CNSJ4.tmp\setup_lib_v3.tmpsetup_lib_v3.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
1
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-cnsj4.tmp\setup_lib_v3.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
3624"C:\Users\admin\Desktop\setup_lib_v3.exe" C:\Users\admin\Desktop\setup_lib_v3.exe
explorer.exe
User:
admin
Company:
Integrity Level:
HIGH
Description:
zlib data compression library
Exit code:
1
Version:
1.3.0.1
Modules
Images
c:\users\admin\desktop\setup_lib_v3.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
3632"C:\Users\admin\Desktop\setup_lib_v3.exe" /verysilent /sp-C:\Users\admin\Desktop\setup_lib_v3.exesetup_lib_v3.tmp
User:
admin
Company:
Integrity Level:
HIGH
Description:
zlib data compression library
Exit code:
0
Version:
1.3.0.1
Modules
Images
c:\users\admin\desktop\setup_lib_v3.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
3644"regsvr32" C:\zlib\zlib13.dllC:\Windows\System32\regsvr32.exesetup_lib_v3.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3656"C:\Users\admin\AppData\Local\Temp\is-OGGG9.tmp\setup_lib_v3.tmp" /SL5="$A0134,2491388,119296,C:\Users\admin\Desktop\setup_lib_v3.exe" /verysilent /sp-C:\Users\admin\AppData\Local\Temp\is-OGGG9.tmp\setup_lib_v3.tmpsetup_lib_v3.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-oggg9.tmp\setup_lib_v3.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
Total events
262
Read events
244
Write events
8
Delete events
10

Modification events

(PID) Process:(3380) setup_lib_v3.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3380) setup_lib_v3.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(3380) setup_lib_v3.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(3380) setup_lib_v3.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(3380) setup_lib_v3.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:Sequence
Value:
1
(PID) Process:(3380) setup_lib_v3.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:SessionHash
Value:
8847F3D8CAF6B480B8B9EE1581EB26E9A908BC8A6F8CC5D83A94318D0E32BBBE
(PID) Process:(3380) setup_lib_v3.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:Owner
Value:
340D00009C65DBA6321DDA01
(PID) Process:(3380) setup_lib_v3.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete keyName:(default)
Value:
(PID) Process:(3656) setup_lib_v3.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:RegFilesHash
Value:
A583BDAD2DDF211E7F441440E6035CAD72AE3C518C4EE66C70C722598586BEB2
(PID) Process:(3656) setup_lib_v3.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:RegFiles0000
Value:
C:\zlib\zlib13.dll
Executable files
6
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
3656setup_lib_v3.tmpC:\zlib\is-PFH19.tmpexecutable
MD5:342FAC31EB0F331F558114A0385F9B40
SHA256:E7FEB941EC0838DAC58CF9CD48699AC60252001DC98EBD09F357CB14985D6398
3624setup_lib_v3.exeC:\Users\admin\AppData\Local\Temp\is-CNSJ4.tmp\setup_lib_v3.tmpexecutable
MD5:BE49CB708B9B78C088992095890FDBCE
SHA256:E24A20096EAF4C2A5C89D15D4E58EFCE8140E57EF86CA7F73BA7CA64DEAFC27D
3656setup_lib_v3.tmpC:\zlib\zlib13.dllexecutable
MD5:342FAC31EB0F331F558114A0385F9B40
SHA256:E7FEB941EC0838DAC58CF9CD48699AC60252001DC98EBD09F357CB14985D6398
3656setup_lib_v3.tmpC:\Users\admin\AppData\Local\Temp\is-PKL09.tmp\_isetup\_shfoldr.dllexecutable
MD5:92DC6EF532FBB4A5C3201469A5B5EB63
SHA256:9884E9D1B4F8A873CCBD81F8AD0AE257776D2348D027D811A56475E028360D87
3380setup_lib_v3.tmpC:\Users\admin\AppData\Local\Temp\is-FAR0O.tmp\_isetup\_shfoldr.dllexecutable
MD5:92DC6EF532FBB4A5C3201469A5B5EB63
SHA256:9884E9D1B4F8A873CCBD81F8AD0AE257776D2348D027D811A56475E028360D87
3632setup_lib_v3.exeC:\Users\admin\AppData\Local\Temp\is-OGGG9.tmp\setup_lib_v3.tmpexecutable
MD5:BE49CB708B9B78C088992095890FDBCE
SHA256:E24A20096EAF4C2A5C89D15D4E58EFCE8140E57EF86CA7F73BA7CA64DEAFC27D
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
2588
svchost.exe
239.255.255.250:1900
whitelisted

DNS requests

No data

Threats

No threats detected
No debug info