File name:

AnyViewerSetup[1].exe

Full analysis: https://app.any.run/tasks/c523ff9c-dbe7-4d01-83b6-a9767277fc83
Verdict: Malicious activity
Analysis date: October 30, 2023, 17:59:42
OS: Windows 7 Professional Service Pack 1 (build: 7601, 64 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

1C428D6EE030D606CE0F4BCBB03BD3FA

SHA1:

E8FABC81D2C49C23B9F951636D5A0769E02F1E47

SHA256:

9E8F522F7002903B634E692F0CA336073A10640D99AADDA5DACBC8B2FD52679F

SSDEEP:

393216:DD81u4YkuadCm/bZfQW8OVYtNlooEou6Tsw/NdWMrG:DDYXYh8FZfT8OVYXlooT9lG

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • AnyViewerSetup[1].exe (PID: 584)
      • AnyViewerSetup[1].tmp (PID: 2424)
    • Loads dropped or rewritten executable

      • AnyViewerSetup[1].tmp (PID: 2424)
  • SUSPICIOUS

    • Reads the Windows owner or organization settings

      • AnyViewerSetup[1].tmp (PID: 2424)
    • Process drops legitimate windows executable

      • AnyViewerSetup[1].tmp (PID: 2424)
  • INFO

    • Checks supported languages

      • AnyViewerSetup[1].exe (PID: 584)
      • AnyViewerSetup[1].tmp (PID: 2424)
    • Create files in a temporary directory

      • AnyViewerSetup[1].exe (PID: 584)
      • AnyViewerSetup[1].tmp (PID: 2424)
    • Application was dropped or rewritten from another process

      • AnyViewerSetup[1].tmp (PID: 2424)
    • Reads the computer name

      • AnyViewerSetup[1].tmp (PID: 2424)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (67.1)
.exe | InstallShield setup (26.3)
.exe | Win32 Executable (generic) (2.7)
.exe | Win16/32 Executable Delphi generic (1.2)
.exe | Generic Win/DOS Executable (1.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2012:10:02 07:04:04+02:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 86016
InitializedDataSize: 531968
UninitializedDataSize: -
EntryPoint: 0x16478
OSVersion: 5
ImageVersion: 6
SubsystemVersion: 5
Subsystem: Windows GUI
FileVersionNumber: 4.1.1.0
ProductVersionNumber: 4.1.1.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: AOMEI International Network Limited
FileDescription: AnyViewer Setup
FileVersion: 4.1.1.0
LegalCopyright: Copyright © 2023 AnyViewer All rights reserved
ProductName: AnyViewer
ProductVersion: 4,1,1,0
No data.
screenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
35
Monitored processes
3
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
drop and start start anyviewersetup[1].exe anyviewersetup[1].tmp no specs anyviewersetup[1].exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
584"C:\Users\admin\AppData\Local\Temp\AnyViewerSetup[1].exe" C:\Users\admin\AppData\Local\Temp\AnyViewerSetup[1].exe
explorer.exe
User:
admin
Company:
AOMEI International Network Limited
Integrity Level:
HIGH
Description:
AnyViewer Setup
Exit code:
0
Version:
4.1.1.0
Modules
Images
c:\users\admin\appdata\local\temp\anyviewersetup[1].exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\user32.dll
c:\windows\system32\wow64.dll
c:\windows\syswow64\gdi32.dll
1612"C:\Users\admin\AppData\Local\Temp\AnyViewerSetup[1].exe" C:\Users\admin\AppData\Local\Temp\AnyViewerSetup[1].exeexplorer.exe
User:
admin
Company:
AOMEI International Network Limited
Integrity Level:
MEDIUM
Description:
AnyViewer Setup
Exit code:
3221226540
Version:
4.1.1.0
Modules
Images
c:\users\admin\appdata\local\temp\anyviewersetup[1].exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
2424"C:\Users\admin\AppData\Local\Temp\is-A89G9.tmp\AnyViewerSetup[1].tmp" /SL5="$80136,42112524,619008,C:\Users\admin\AppData\Local\Temp\AnyViewerSetup[1].exe" C:\Users\admin\AppData\Local\Temp\is-A89G9.tmp\AnyViewerSetup[1].tmpAnyViewerSetup[1].exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-a89g9.tmp\anyviewersetup[1].tmp
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\wow64.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\oleaut32.dll
Total events
154
Read events
154
Write events
0
Delete events
0

Modification events

No data
Executable files
8
Suspicious files
0
Text files
34
Unknown types
0

Dropped files

PID
Process
Filename
Type
2424AnyViewerSetup[1].tmpC:\Users\admin\AppData\Local\Temp\is-HJKCS.tmp\icon_d.pngimage
MD5:51D8B58303422DC807C774C0C9C774D3
SHA256:E16EEB7A299B9678C194CB8DF304988B72B4CA1516C513F2BDAB4F761CFDB839
2424AnyViewerSetup[1].tmpC:\Users\admin\AppData\Local\Temp\is-HJKCS.tmp\PathFormat.dllexecutable
MD5:ED26AEDADE2F4CA5DA61FF5BAA1A16D7
SHA256:0DE968FFD4A6C60413CAC739DCCB1B162F8F93F3DB754728FDE8738E52706FA4
2424AnyViewerSetup[1].tmpC:\Users\admin\AppData\Local\Temp\is-HJKCS.tmp\iconclose.pngimage
MD5:4B00487FF65448660795F0932ED58419
SHA256:F81CBF673E0A8C2708CC6C2E84F589A4E347255CAB30AB68C064CF41C7B9E684
2424AnyViewerSetup[1].tmpC:\Users\admin\AppData\Local\Temp\is-HJKCS.tmp\iconminimize.pngimage
MD5:48B8FE1B77DFBC4B929245E1866634D6
SHA256:9EF1A17CBC12F12E0DE6CCB45B99B21733BC24156FB97E4116894AF879F0F194
2424AnyViewerSetup[1].tmpC:\Users\admin\AppData\Local\Temp\is-HJKCS.tmp\bgtop_es.pngimage
MD5:956624E242249F6C392223828E9327E8
SHA256:B56E2FEDBFFC739526FD753A9FAA660BC0E5557121D0927515324E059C702099
2424AnyViewerSetup[1].tmpC:\Users\admin\AppData\Local\Temp\is-HJKCS.tmp\Install.pngimage
MD5:751EB7CF228F6065B3383AB1AEBF7312
SHA256:268F885FBF96203FD8A5252A83F0B2B905EB896A7E91454CBB3FBE9DE081A96E
2424AnyViewerSetup[1].tmpC:\Users\admin\AppData\Local\Temp\is-HJKCS.tmp\bgtop_en.pngimage
MD5:9C4B61A02E0162334D1906822FEF1299
SHA256:6A9B6B78690530FB501039A85FB6C9570F5FDE23B42B78010A9E4B75607E7B3F
2424AnyViewerSetup[1].tmpC:\Users\admin\AppData\Local\Temp\is-HJKCS.tmp\bgtop_fr.pngimage
MD5:BC5F98049368B9895B133DBD4E9D1347
SHA256:9C05B8AB828437A06082C0CB526660348ECA2F9DEBB61B9999FB1BCD07FC9310
2424AnyViewerSetup[1].tmpC:\Users\admin\AppData\Local\Temp\is-HJKCS.tmp\bgtop_cn.pngimage
MD5:F383C04E706BD30A2F3077E47199D0B2
SHA256:2DFDB860E7A707BF3EF29DA7095D0F8DB9A56B0F4B11A2F000E109050E97CBDC
2424AnyViewerSetup[1].tmpC:\Users\admin\AppData\Local\Temp\is-HJKCS.tmp\bgtop_de.pngimage
MD5:2D5E8155051686B373849CEAAFAD1F11
SHA256:3776E11421FA2CDD751DEDD0E6F604933C164C3F5D86DA39DD5CD12A32723AE4
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
5
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
1956
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:138
whitelisted
324
svchost.exe
224.0.0.252:5355
unknown

DNS requests

No data

Threats

No threats detected
No debug info