File name:

webcammax-8.0.7.8-installer_mI0o-t1.exe

Full analysis: https://app.any.run/tasks/7043d967-a666-4eb8-9b99-4db436c8291e
Verdict: Malicious activity
Analysis date: April 27, 2023, 03:41:58
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
installer
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

C1D88A9AB528045D41090D9B3B720F5B

SHA1:

72362B24004F028118F33A8AFEB9E43D38BE643E

SHA256:

93C5E379C1FB4C2327B2D8A5D0CFCC374583A861DBACA9C960D70AE4A02CAECB

SSDEEP:

24576:94nXubIQGyxbPV0db26WjurAQK421t0YKbDVfcqOlsoO0drNBuLy1zoHf2MPN+R:9qe3f6VrAV5leDlMlsRmpgtf1Q

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • webcammax-8.0.7.8-installer_mI0o-t1.exe (PID: 6240)
      • webcammax-8.0.7.8-installer_mI0o-t1.exe (PID: 3848)
      • webcammax-8.0.7.8-installer_mI0o-t1.tmp (PID: 3216)
    • Reads the date of Windows installation

      • webcammax-8.0.7.8-installer_mI0o-t1.tmp (PID: 4768)
    • Reads the Windows owner or organization settings

      • webcammax-8.0.7.8-installer_mI0o-t1.tmp (PID: 3216)
    • Reads settings of System Certificates

      • webcammax-8.0.7.8-installer_mI0o-t1.tmp (PID: 3216)
  • INFO

    • Checks supported languages

      • webcammax-8.0.7.8-installer_mI0o-t1.tmp (PID: 4768)
      • webcammax-8.0.7.8-installer_mI0o-t1.exe (PID: 6240)
      • webcammax-8.0.7.8-installer_mI0o-t1.exe (PID: 3848)
      • webcammax-8.0.7.8-installer_mI0o-t1.tmp (PID: 3216)
    • The process checks LSA protection

      • webcammax-8.0.7.8-installer_mI0o-t1.tmp (PID: 4768)
      • webcammax-8.0.7.8-installer_mI0o-t1.tmp (PID: 3216)
    • Reads the computer name

      • webcammax-8.0.7.8-installer_mI0o-t1.tmp (PID: 4768)
      • webcammax-8.0.7.8-installer_mI0o-t1.tmp (PID: 3216)
    • Create files in a temporary directory

      • webcammax-8.0.7.8-installer_mI0o-t1.exe (PID: 6240)
      • webcammax-8.0.7.8-installer_mI0o-t1.exe (PID: 3848)
      • webcammax-8.0.7.8-installer_mI0o-t1.tmp (PID: 3216)
    • Process checks computer location settings

      • webcammax-8.0.7.8-installer_mI0o-t1.tmp (PID: 4768)
    • Reads the machine GUID from the registry

      • webcammax-8.0.7.8-installer_mI0o-t1.tmp (PID: 3216)
    • Reads the software policy settings

      • webcammax-8.0.7.8-installer_mI0o-t1.tmp (PID: 3216)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (53.5)
.exe | InstallShield setup (21)
.exe | Win32 EXE PECompact compressed (generic) (20.2)
.exe | Win32 Executable (generic) (2.1)
.exe | Win16/32 Executable Delphi generic (1)

EXIF

EXE

ProductVersion: 8.7.2431
ProductName: Capturāl Lmk
OriginalFileName:
LegalCopyright: ©2023 Capturāl Lmk
FileVersion: 8.7.2431
FileDescription: Capturāl Lmk
CompanyName:
Comments: This installation was built with Inno Setup.
CharacterSet: Unicode
LanguageCode: Neutral
FileSubtype: -
ObjectFileType: Executable application
FileOS: Win32
FileFlags: (none)
FileFlagsMask: 0x003f
ProductVersionNumber: 8.7.2431.0
FileVersionNumber: 8.7.2431.0
Subsystem: Windows GUI
SubsystemVersion: 6.1
ImageVersion: 6
OSVersion: 6.1
EntryPoint: 0xb5eec
UninitializedDataSize: -
InitializedDataSize: 89088
CodeSize: 741376
LinkerVersion: 2.25
PEType: PE32
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
TimeStamp: 2021:06:03 08:09:11+00:00
MachineType: Intel 386 or later, and compatibles

Summary

Architecture: IMAGE_FILE_MACHINE_I386
Subsystem: IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date: 03-Jun-2021 08:09:11
Detected languages:
  • English - United States
Comments: This installation was built with Inno Setup.
CompanyName: -
FileDescription: Capturāl Lmk
FileVersion: 8.7.2431
LegalCopyright: ©2023 Capturāl Lmk
OriginalFileName: -
ProductName: Capturāl Lmk
ProductVersion: 8.7.2431

DOS Header

Magic number: MZ
Bytes on last page of file: 0x0050
Pages in file: 0x0002
Relocations: 0x0000
Size of header: 0x0004
Min extra paragraphs: 0x000F
Max extra paragraphs: 0xFFFF
Initial SS value: 0x0000
Initial SP value: 0x00B8
Checksum: 0x0000
Initial IP value: 0x0000
Initial CS value: 0x0000
Overlay number: 0x001A
OEM identifier: 0x0000
OEM information: 0x0000
Address of NE header: 0x00000100

PE Headers

Signature: PE
Machine: IMAGE_FILE_MACHINE_I386
Number of sections: 10
Time date stamp: 03-Jun-2021 08:09:11
Pointer to Symbol Table: 0x00000000
Number of symbols: 0
Size of Optional Header: 0x00E0
Characteristics:
  • IMAGE_FILE_32BIT_MACHINE
  • IMAGE_FILE_BYTES_REVERSED_HI
  • IMAGE_FILE_BYTES_REVERSED_LO
  • IMAGE_FILE_EXECUTABLE_IMAGE
  • IMAGE_FILE_LINE_NUMS_STRIPPED
  • IMAGE_FILE_LOCAL_SYMS_STRIPPED
  • IMAGE_FILE_RELOCS_STRIPPED

Sections

Name
Virtual Address
Virtual Size
Raw Size
Charateristics
Entropy
.text
0x00001000
0x000B361C
0x000B3800
IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
6.35606
.itext
0x000B5000
0x00001688
0x00001800
IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
5.97275
.data
0x000B7000
0x000037A4
0x00003800
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
5.0444
.bss
0x000BB000
0x00006DE8
0x00000000
IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
0
.idata
0x000C2000
0x00000F36
0x00001000
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
4.8987
.didata
0x000C3000
0x000001A4
0x00000200
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
2.75636
.edata
0x000C4000
0x0000009A
0x00000200
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
1.87222
.tls
0x000C5000
0x00000018
0x00000000
IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
0
.rdata
0x000C6000
0x0000005D
0x00000200
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
1.38389
.rsrc
0x000C7000
0x00010E00
0x00010E00
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
3.71258

Resources

Title
Entropy
Size
Codepage
Language
Type
1
5.18295
1830
UNKNOWN
English - United States
RT_MANIFEST
2
1.98658
1640
UNKNOWN
English - United States
RT_ICON
3
2.01586
744
UNKNOWN
English - United States
RT_ICON
4
2.1704
296
UNKNOWN
English - United States
RT_ICON
5
1.912
5672
UNKNOWN
English - United States
RT_ICON
6
1.8663
3752
UNKNOWN
English - United States
RT_ICON
7
1.49649
2216
UNKNOWN
English - United States
RT_ICON
8
0.972379
1384
UNKNOWN
English - United States
RT_ICON
9
7.68913
4837
UNKNOWN
English - United States
RT_ICON
10
2.03031
16936
UNKNOWN
English - United States
RT_ICON

Imports

advapi32.dll
comctl32.dll
kernel32.dll
kernel32.dll (delay-loaded)
netapi32.dll
oleaut32.dll
user32.dll
version.dll

Exports

Title
Ordinal
Address
dbkFCallWrapperAddr
1
0x000BE63C
__dbk_fcall_wrapper
2
0x0000D0A0
TMethodImplementationIntercept
3
0x00054060
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
131
Monitored processes
4
Malicious processes
3
Suspicious processes
1

Behavior graph

Click at the process to see the details
start webcammax-8.0.7.8-installer_mi0o-t1.exe webcammax-8.0.7.8-installer_mi0o-t1.tmp no specs webcammax-8.0.7.8-installer_mi0o-t1.exe webcammax-8.0.7.8-installer_mi0o-t1.tmp

Process information

PID
CMD
Path
Indicators
Parent process
3216"C:\Users\admin\AppData\Local\Temp\is-67875.tmp\webcammax-8.0.7.8-installer_mI0o-t1.tmp" /SL5="$E01D0,878064,831488,C:\Users\admin\AppData\Local\Temp\webcammax-8.0.7.8-installer_mI0o-t1.exe" /SPAWNWND=$1002D4 /NOTIFYWND=$1502A8 C:\Users\admin\AppData\Local\Temp\is-67875.tmp\webcammax-8.0.7.8-installer_mI0o-t1.tmp
webcammax-8.0.7.8-installer_mI0o-t1.exe
User:
admin
Company:
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
1
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-67875.tmp\webcammax-8.0.7.8-installer_mi0o-t1.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comdlg32.dll
3848"C:\Users\admin\AppData\Local\Temp\webcammax-8.0.7.8-installer_mI0o-t1.exe" /SPAWNWND=$1002D4 /NOTIFYWND=$1502A8 C:\Users\admin\AppData\Local\Temp\webcammax-8.0.7.8-installer_mI0o-t1.exe
webcammax-8.0.7.8-installer_mI0o-t1.tmp
User:
admin
Company:
Integrity Level:
HIGH
Description:
Capturāl Lmk
Exit code:
1
Version:
8.7.2431
Modules
Images
c:\users\admin\appdata\local\temp\webcammax-8.0.7.8-installer_mi0o-t1.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
4768"C:\Users\admin\AppData\Local\Temp\is-VNK5B.tmp\webcammax-8.0.7.8-installer_mI0o-t1.tmp" /SL5="$1502A8,878064,831488,C:\Users\admin\AppData\Local\Temp\webcammax-8.0.7.8-installer_mI0o-t1.exe" C:\Users\admin\AppData\Local\Temp\is-VNK5B.tmp\webcammax-8.0.7.8-installer_mI0o-t1.tmpwebcammax-8.0.7.8-installer_mI0o-t1.exe
User:
admin
Company:
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
1
Version:
51.1052.0.0
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\users\admin\appdata\local\temp\is-vnk5b.tmp\webcammax-8.0.7.8-installer_mi0o-t1.tmp
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\mpr.dll
6240"C:\Users\admin\AppData\Local\Temp\webcammax-8.0.7.8-installer_mI0o-t1.exe" C:\Users\admin\AppData\Local\Temp\webcammax-8.0.7.8-installer_mI0o-t1.exe
explorer.exe
User:
admin
Company:
Integrity Level:
MEDIUM
Description:
Capturāl Lmk
Exit code:
1
Version:
8.7.2431
Modules
Images
c:\users\admin\appdata\local\temp\webcammax-8.0.7.8-installer_mi0o-t1.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
Total events
8 458
Read events
8 450
Write events
0
Delete events
8

Modification events

(PID) Process:(3216) webcammax-8.0.7.8-installer_mI0o-t1.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:delete valueName:Sequence
Value:
1
(PID) Process:(3216) webcammax-8.0.7.8-installer_mI0o-t1.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:delete valueName:SessionHash
Value:
61B1C2EAC51BB59988C55C614C3296CDAD62AA76F63CE4419E1B413FDED9BDED
(PID) Process:(3216) webcammax-8.0.7.8-installer_mI0o-t1.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:delete valueName:Owner
Value:
900C00008AB4CF3DBA78D901
(PID) Process:(3216) webcammax-8.0.7.8-installer_mI0o-t1.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:delete keyName:(default)
Value:
Executable files
8
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
3216webcammax-8.0.7.8-installer_mI0o-t1.tmpC:\Users\admin\AppData\Local\Temp\is-0THAV.tmp\_isetup\_setup64.tmpexecutable
MD5:E4211D6D009757C078A9FAC7FF4F03D4
SHA256:388A796580234EFC95F3B1C70AD4CB44BFDDC7BA0F9203BF4902B9929B136F95
3216webcammax-8.0.7.8-installer_mI0o-t1.tmpC:\Users\admin\AppData\Local\Temp\is-0THAV.tmp\botva2.dllexecutable
MD5:67965A5957A61867D661F05AE1F4773E
SHA256:450B9B0BA25BF068AFBC2B23D252585A19E282939BF38326384EA9112DFD0105
6240webcammax-8.0.7.8-installer_mI0o-t1.exeC:\Users\admin\AppData\Local\Temp\is-VNK5B.tmp\webcammax-8.0.7.8-installer_mI0o-t1.tmpexecutable
MD5:C0F25F98885A7400AA89EA7D34865DEE
SHA256:7C231A1B64A851045E359D5E94B93611DE04D55C653CB9C375C92124C5D1F5CA
3848webcammax-8.0.7.8-installer_mI0o-t1.exeC:\Users\admin\AppData\Local\Temp\is-67875.tmp\webcammax-8.0.7.8-installer_mI0o-t1.tmpexecutable
MD5:C0F25F98885A7400AA89EA7D34865DEE
SHA256:7C231A1B64A851045E359D5E94B93611DE04D55C653CB9C375C92124C5D1F5CA
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
22
DNS requests
15
Threats
29

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
5756
svchost.exe
40.126.31.71:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2360
SIHClient.exe
40.127.169.103:443
slscr.update.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2360
SIHClient.exe
20.166.126.56:443
fe3cr.delivery.mp.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3408
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3216
webcammax-8.0.7.8-installer_mI0o-t1.tmp
18.66.107.32:443
ds0ipd79cknej.cloudfront.net
AMAZON-02
US
suspicious

DNS requests

Domain
IP
Reputation
officeclient.microsoft.com
  • 52.109.52.148
whitelisted
settings-win.data.microsoft.com
  • 51.104.136.2
whitelisted
ds0ipd79cknej.cloudfront.net
  • 18.66.107.32
  • 18.66.107.82
  • 18.66.107.145
  • 18.66.107.117
malicious
slscr.update.microsoft.com
  • 40.127.169.103
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 20.166.126.56
whitelisted
nexusrules.officeapps.live.com
  • 52.109.13.64
whitelisted

Threats

Found threats are available for the paid subscriptions
29 ETPRO signatures available at the full report
No debug info