File name:

KeePass-2.56-Setup.exe

Full analysis: https://app.any.run/tasks/bb791afc-645f-443d-b0b6-cab9593d89cd
Verdict: Malicious activity
Analysis date: April 29, 2024, 10:27:31
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

86A0D58D2AE89C639D940DBDA48308DF

SHA1:

1280F427D149A8C5CA797A9EA29E711A3FA2B5EF

SHA256:

92529DC0E6449ECA21688601020455505462819217B8E8D51F6E7B1DD05A69EF

SSDEEP:

98304:S+cD4dnKqmr95TQTVAwAzj/CoYpmqOrvwoZEu9YrfO+6dRtr4rKW3o7GpMuhUGsB:upr0kisZ3

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • KeePass-2.56-Setup.exe (PID: 4000)
      • KeePass-2.56-Setup.exe (PID: 1116)
      • KeePass-2.56-Setup.tmp (PID: 748)
      • mscorsvw.exe (PID: 1664)
    • Changes the autorun value in the registry

      • ShInstUtil.exe (PID: 2024)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • KeePass-2.56-Setup.exe (PID: 1116)
      • KeePass-2.56-Setup.exe (PID: 4000)
      • KeePass-2.56-Setup.tmp (PID: 748)
      • mscorsvw.exe (PID: 1664)
    • Reads the Windows owner or organization settings

      • KeePass-2.56-Setup.tmp (PID: 748)
    • Reads security settings of Internet Explorer

      • ShInstUtil.exe (PID: 1184)
    • Reads the Internet Settings

      • ShInstUtil.exe (PID: 1184)
  • INFO

    • Checks supported languages

      • KeePass-2.56-Setup.exe (PID: 4000)
      • KeePass-2.56-Setup.tmp (PID: 4016)
      • KeePass-2.56-Setup.exe (PID: 1116)
      • KeePass-2.56-Setup.tmp (PID: 748)
      • ShInstUtil.exe (PID: 1876)
      • ShInstUtil.exe (PID: 2024)
      • ngen.exe (PID: 1292)
      • ngen.exe (PID: 1580)
      • mscorsvw.exe (PID: 728)
      • mscorsvw.exe (PID: 1664)
      • ShInstUtil.exe (PID: 1184)
      • KeePass.exe (PID: 1812)
    • Reads the computer name

      • KeePass-2.56-Setup.tmp (PID: 4016)
      • KeePass-2.56-Setup.tmp (PID: 748)
      • ShInstUtil.exe (PID: 1184)
      • ngen.exe (PID: 1292)
      • ngen.exe (PID: 1580)
      • mscorsvw.exe (PID: 728)
      • mscorsvw.exe (PID: 1664)
      • KeePass.exe (PID: 1812)
    • Create files in a temporary directory

      • KeePass-2.56-Setup.exe (PID: 4000)
      • KeePass-2.56-Setup.exe (PID: 1116)
    • Creates files in the program directory

      • KeePass-2.56-Setup.tmp (PID: 748)
    • Creates a software uninstall entry

      • KeePass-2.56-Setup.tmp (PID: 748)
    • Reads the machine GUID from the registry

      • mscorsvw.exe (PID: 728)
      • ngen.exe (PID: 1580)
      • mscorsvw.exe (PID: 1664)
      • KeePass.exe (PID: 1812)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (51.8)
.exe | InstallShield setup (20.3)
.exe | Win32 EXE PECompact compressed (generic) (19.6)
.dll | Win32 Dynamic Link Library (generic) (3.1)
.exe | Win32 Executable (generic) (2.1)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:02:15 14:54:16+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 741888
InitializedDataSize: 38400
UninitializedDataSize: -
EntryPoint: 0xb5eec
OSVersion: 6.1
ImageVersion: 6
SubsystemVersion: 6.1
Subsystem: Windows GUI
FileVersionNumber: 2.56.0.0
ProductVersionNumber: 2.56.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: Dominik Reichl
FileDescription: KeePass Password Safe 2.56 Setup
FileVersion: 2.56.0.0
LegalCopyright: Copyright © 2003-2024 Dominik Reichl
OriginalFileName:
ProductName: KeePass Password Safe
ProductVersion: 2.56
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
49
Monitored processes
12
Malicious processes
4
Suspicious processes
1

Behavior graph

Click at the process to see the details
start keepass-2.56-setup.exe keepass-2.56-setup.tmp no specs keepass-2.56-setup.exe keepass-2.56-setup.tmp shinstutil.exe no specs shinstutil.exe shinstutil.exe no specs ngen.exe no specs ngen.exe no specs mscorsvw.exe no specs mscorsvw.exe keepass.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
728C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -StartupEvent 108 -InterruptEvent 0 -NGENProcess f8 -Pipe 104 -Comment "NGen Worker Process"C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exengen.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
.NET Runtime Optimization Service
Exit code:
0
Version:
4.8.3761.0 built by: NET48REL1
Modules
Images
c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\vcruntime140_clr0400.dll
c:\windows\system32\ucrtbase_clr0400.dll
748"C:\Users\admin\AppData\Local\Temp\is-2MOGC.tmp\KeePass-2.56-Setup.tmp" /SL5="$2013C,3482807,781312,C:\Users\admin\AppData\Local\Temp\KeePass-2.56-Setup.exe" /SPAWNWND=$20130 /NOTIFYWND=$30136 C:\Users\admin\AppData\Local\Temp\is-2MOGC.tmp\KeePass-2.56-Setup.tmp
KeePass-2.56-Setup.exe
User:
admin
Company:
Dominik Reichl
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-2mogc.tmp\keepass-2.56-setup.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1116"C:\Users\admin\AppData\Local\Temp\KeePass-2.56-Setup.exe" /SPAWNWND=$20130 /NOTIFYWND=$30136 C:\Users\admin\AppData\Local\Temp\KeePass-2.56-Setup.exe
KeePass-2.56-Setup.tmp
User:
admin
Company:
Dominik Reichl
Integrity Level:
HIGH
Description:
KeePass Password Safe 2.56 Setup
Exit code:
0
Version:
2.56.0.0
Modules
Images
c:\users\admin\appdata\local\temp\keepass-2.56-setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\comctl32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
1184"C:\Program Files\KeePass Password Safe 2\ShInstUtil.exe" ngen_installC:\Program Files\KeePass Password Safe 2\ShInstUtil.exeKeePass-2.56-Setup.tmp
User:
admin
Company:
Dominik Reichl
Integrity Level:
HIGH
Description:
ShInstUtil - KeePass Helper Utility
Exit code:
0
Version:
2.56.0.0
Modules
Images
c:\program files\keepass password safe 2\shinstutil.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1292"C:\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.exe" uninstall "C:\Program Files\KeePass Password Safe 2\KeePass.exe"C:\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.exeShInstUtil.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Common Language Runtime native compiler
Exit code:
4294967295
Version:
4.8.3761.0 built by: NET48REL1
Modules
Images
c:\windows\microsoft.net\framework\v4.0.30319\ngen.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\vcruntime140_clr0400.dll
c:\windows\system32\ucrtbase_clr0400.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
1580"C:\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.exe" install "C:\Program Files\KeePass Password Safe 2\KeePass.exe"C:\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.exeShInstUtil.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Common Language Runtime native compiler
Exit code:
0
Version:
4.8.3761.0 built by: NET48REL1
Modules
Images
c:\windows\microsoft.net\framework\v4.0.30319\ngen.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\vcruntime140_clr0400.dll
c:\windows\system32\ucrtbase_clr0400.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
1664C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -StartupEvent 108 -InterruptEvent 0 -NGENProcess 100 -Pipe f8 -Comment "NGen Worker Process"C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
ngen.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
.NET Runtime Optimization Service
Exit code:
0
Version:
4.8.3761.0 built by: NET48REL1
Modules
Images
c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\vcruntime140_clr0400.dll
c:\windows\system32\ucrtbase_clr0400.dll
1812"C:\Program Files\KeePass Password Safe 2\KeePass.exe"C:\Program Files\KeePass Password Safe 2\KeePass.exeKeePass-2.56-Setup.tmp
User:
admin
Company:
Dominik Reichl
Integrity Level:
MEDIUM
Description:
KeePass
Version:
2.56.0.0
Modules
Images
c:\program files\keepass password safe 2\keepass.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1876"C:\Program Files\KeePass Password Safe 2\ShInstUtil.exe" net_checkC:\Program Files\KeePass Password Safe 2\ShInstUtil.exeKeePass-2.56-Setup.tmp
User:
admin
Company:
Dominik Reichl
Integrity Level:
HIGH
Description:
ShInstUtil - KeePass Helper Utility
Exit code:
0
Version:
2.56.0.0
Modules
Images
c:\program files\keepass password safe 2\shinstutil.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2024"C:\Program Files\KeePass Password Safe 2\ShInstUtil.exe" preload_registerC:\Program Files\KeePass Password Safe 2\ShInstUtil.exe
KeePass-2.56-Setup.tmp
User:
admin
Company:
Dominik Reichl
Integrity Level:
HIGH
Description:
ShInstUtil - KeePass Helper Utility
Exit code:
0
Version:
2.56.0.0
Modules
Images
c:\program files\keepass password safe 2\shinstutil.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
Total events
19 769
Read events
19 696
Write events
65
Delete events
8

Modification events

(PID) Process:(748) KeePass-2.56-Setup.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
EC0200005C1F88DE1F9ADA01
(PID) Process:(748) KeePass-2.56-Setup.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:SessionHash
Value:
A4A46F070BEB57A07CACFE09AF2468B1ECCB5B922659C7CE9D638F65E9927009
(PID) Process:(748) KeePass-2.56-Setup.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Sequence
Value:
1
(PID) Process:(748) KeePass-2.56-Setup.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:RegFiles0000
Value:
C:\Program Files\KeePass Password Safe 2\KeePass.exe
(PID) Process:(748) KeePass-2.56-Setup.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:RegFilesHash
Value:
00C64E0DE8D112E3498F5EC3070C7D23C73A51B8734218DC8C398A1B38BA3284
(PID) Process:(748) KeePass-2.56-Setup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\kdbxfile
Operation:writeName:AlwaysShowExt
Value:
(PID) Process:(748) KeePass-2.56-Setup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KeePassPasswordSafe2_is1
Operation:writeName:Inno Setup: Setup Version
Value:
6.2.2
(PID) Process:(748) KeePass-2.56-Setup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KeePassPasswordSafe2_is1
Operation:writeName:Inno Setup: App Path
Value:
C:\Program Files\KeePass Password Safe 2
(PID) Process:(748) KeePass-2.56-Setup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KeePassPasswordSafe2_is1
Operation:writeName:InstallLocation
Value:
C:\Program Files\KeePass Password Safe 2\
(PID) Process:(748) KeePass-2.56-Setup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KeePassPasswordSafe2_is1
Operation:writeName:Inno Setup: Icon Group
Value:
KeePass Password Safe 2
Executable files
15
Suspicious files
5
Text files
17
Unknown types
1

Dropped files

PID
Process
Filename
Type
1116KeePass-2.56-Setup.exeC:\Users\admin\AppData\Local\Temp\is-2MOGC.tmp\KeePass-2.56-Setup.tmpexecutable
MD5:354613DD35E43746F934C0E9D7B2543C
SHA256:C11513E77B5CD81F07E33111D7A36F5EE4CF551113E30414DE753A4C101173D6
748KeePass-2.56-Setup.tmpC:\Program Files\KeePass Password Safe 2\License.txttext
MD5:5AF8E0FC895189C0C6F89D80D639EFD7
SHA256:B3D47DF09908E56B4BAFBF7C2D44FA2AC032912803B10054C17CECF668A1FDF1
748KeePass-2.56-Setup.tmpC:\Program Files\KeePass Password Safe 2\KeePass.exeexecutable
MD5:B4250862F4D1F151D2EDC123AB2C8A77
SHA256:09D730282184EC2BA4CC8C1C089837B323E7B6BAB0101206E206455D903E4D2A
748KeePass-2.56-Setup.tmpC:\Program Files\KeePass Password Safe 2\KeePass.exe.configxml
MD5:FF0C23B97DF708CCA2030A96C914C3A9
SHA256:3348D697FE118AAA0FDD36087C5105D9B9AF14ABFD0FB10568C118941637C26E
748KeePass-2.56-Setup.tmpC:\Program Files\KeePass Password Safe 2\KeePassLibC32.dllexecutable
MD5:C1BC729504FE427891E874B97267F3E6
SHA256:6D9DFD0EF869660E7F9C0E278C1571CE5B0DD01D82E0B7265D97FAAC36CAC6E4
748KeePass-2.56-Setup.tmpC:\Program Files\KeePass Password Safe 2\is-Q1OKU.tmpexecutable
MD5:F5D989C6A6AFC473B8C5E2C4CF1586A5
SHA256:783053F791AC52C7E5600209A5C83C18419D4DD093BE9541839D38549F13F91B
748KeePass-2.56-Setup.tmpC:\Program Files\KeePass Password Safe 2\is-JF7O3.tmpxml
MD5:FF0C23B97DF708CCA2030A96C914C3A9
SHA256:3348D697FE118AAA0FDD36087C5105D9B9AF14ABFD0FB10568C118941637C26E
748KeePass-2.56-Setup.tmpC:\Program Files\KeePass Password Safe 2\KeePass.XmlSerializers.dllexecutable
MD5:89E19D93A58FAC5DB151666E4BABD019
SHA256:0A9FB364207DE3FF6B072B63C3EF35929DB58C77F8CCA5BC11C61B9D195207F0
748KeePass-2.56-Setup.tmpC:\Program Files\KeePass Password Safe 2\ShInstUtil.exeexecutable
MD5:F5D989C6A6AFC473B8C5E2C4CF1586A5
SHA256:783053F791AC52C7E5600209A5C83C18419D4DD093BE9541839D38549F13F91B
748KeePass-2.56-Setup.tmpC:\Program Files\KeePass Password Safe 2\is-PEB7B.tmpchm
MD5:F1E91BBFB6C07F28B3DDAEF0D8CCF5B4
SHA256:08CD534EAEE14158C892486EAD5B2870F2AC6BC1CD1F0425ED31E9CE98DB39F9
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
3
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
unknown
224.0.0.252:5355
unknown

DNS requests

No data

Threats

No threats detected
No debug info