File name:

Install.exe

Full analysis: https://app.any.run/tasks/e643f132-27cf-4b7f-812f-4b4ff82a9581
Verdict: Malicious activity
Analysis date: May 20, 2022, 17:04:04
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Petite compressed, ACE self-extracting archive
MD5:

CD9566B81C030E2B7561E5C7F84A9075

SHA1:

9F56EB92177DF277C7A769205CEE6165D566432E

SHA256:

9979E5C59F5F20AE75C1242DD9AFC6C5023632C3F1CE460CCCB21D8EB818886E

SSDEEP:

12288:Mmmc/l/xXRqXXtMHnGVa2/Wj0IMOS+15wU5DRc7Nxhu4wLzqUSvGg0x:Nl/xXRqX94nfOk0rOSOD9ONAXTxxx

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops executable file immediately after starts

      • Install.exe (PID: 3696)
  • SUSPICIOUS

    • Reads the computer name

      • Install.exe (PID: 3696)
    • Drops a file with a compile date too recent

      • Install.exe (PID: 3696)
    • Creates files in the program directory

      • Install.exe (PID: 3696)
    • Creates a directory in Program Files

      • Install.exe (PID: 3696)
    • Executable content was dropped or overwritten

      • Install.exe (PID: 3696)
    • Checks supported languages

      • Install.exe (PID: 3696)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.dll | Win32 Dynamic Link Library (generic) (43.5)
.exe | Win32 Executable (generic) (29.8)
.exe | Generic Win/DOS Executable (13.2)
.exe | DOS Executable Generic (13.2)

EXIF

EXE

Subsystem: Windows GUI
SubsystemVersion: 4
ImageVersion: -
OSVersion: 1
EntryPoint: 0x3b042
UninitializedDataSize: -
InitializedDataSize: 75776
CodeSize: 83968
LinkerVersion: 2.25
PEType: PE32
TimeStamp: 1992:06:20 00:22:17+02:00
MachineType: Intel 386 or later, and compatibles
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
37
Monitored processes
2
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start install.exe install.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2040"C:\Users\admin\AppData\Local\Temp\Install.exe" C:\Users\admin\AppData\Local\Temp\Install.exeExplorer.EXE
User:
admin
Company:
e-merge GmbH
Integrity Level:
MEDIUM
Description:
Sfx-Factory! Self-Extractor
Exit code:
3221226540
Version:
2.1.0.0
Modules
Images
c:\users\admin\appdata\local\temp\install.exe
c:\windows\system32\ntdll.dll
3696"C:\Users\admin\AppData\Local\Temp\Install.exe" C:\Users\admin\AppData\Local\Temp\Install.exe
Explorer.EXE
User:
admin
Company:
e-merge GmbH
Integrity Level:
HIGH
Description:
Sfx-Factory! Self-Extractor
Exit code:
0
Version:
2.1.0.0
Modules
Images
c:\users\admin\appdata\local\temp\install.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
Total events
1 402
Read events
1 402
Write events
0
Delete events
0

Modification events

No data
Executable files
6
Suspicious files
1
Text files
3
Unknown types
6

Dropped files

PID
Process
Filename
Type
3696Install.exeC:\program files\DivX_311alpha\DIVX_c32.axexecutable
MD5:
SHA256:
3696Install.exeC:\program files\DivX_311alpha\SetStereo.exeexecutable
MD5:
SHA256:
3696Install.exeC:\program files\DivX_311alpha\DivX Site.urltext
MD5:
SHA256:
3696Install.exeC:\program files\DivX_311alpha\DivXc32f.dllexecutable
MD5:
SHA256:
3696Install.exeC:\program files\DivX_311alpha\Register_DivX.exeexecutable
MD5:
SHA256:
3696Install.exeC:\program files\DivX_311alpha\DivXc32.dllexecutable
MD5:
SHA256:
3696Install.exeC:\program files\DivX_311alpha\DivXa32.acmacm
MD5:
SHA256:
3696Install.exeC:\program files\DivX_311alpha\DivX MPEG4 Video Codec.txttext
MD5:
SHA256:
3696Install.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\DivX ;-) MPEG-4 Video Codec\DivX ;-) Site.lnklnk
MD5:
SHA256:
3696Install.exeC:\program files\DivX_311alpha\DivX.infbinary
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info