File name:

AnyViewerSetup[1].exe

Full analysis: https://app.any.run/tasks/c523ff9c-dbe7-4d01-83b6-a9767277fc83
Verdict: Malicious activity
Analysis date: October 30, 2023, 17:59:42
OS: Windows 7 Professional Service Pack 1 (build: 7601, 64 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

1C428D6EE030D606CE0F4BCBB03BD3FA

SHA1:

E8FABC81D2C49C23B9F951636D5A0769E02F1E47

SHA256:

9E8F522F7002903B634E692F0CA336073A10640D99AADDA5DACBC8B2FD52679F

SSDEEP:

393216:DD81u4YkuadCm/bZfQW8OVYtNlooEou6Tsw/NdWMrG:DDYXYh8FZfT8OVYXlooT9lG

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • AnyViewerSetup[1].exe (PID: 584)
      • AnyViewerSetup[1].tmp (PID: 2424)
    • Loads dropped or rewritten executable

      • AnyViewerSetup[1].tmp (PID: 2424)
  • SUSPICIOUS

    • Reads the Windows owner or organization settings

      • AnyViewerSetup[1].tmp (PID: 2424)
    • Process drops legitimate windows executable

      • AnyViewerSetup[1].tmp (PID: 2424)
  • INFO

    • Checks supported languages

      • AnyViewerSetup[1].exe (PID: 584)
      • AnyViewerSetup[1].tmp (PID: 2424)
    • Create files in a temporary directory

      • AnyViewerSetup[1].tmp (PID: 2424)
      • AnyViewerSetup[1].exe (PID: 584)
    • Reads the computer name

      • AnyViewerSetup[1].tmp (PID: 2424)
    • Application was dropped or rewritten from another process

      • AnyViewerSetup[1].tmp (PID: 2424)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (67.1)
.exe | InstallShield setup (26.3)
.exe | Win32 Executable (generic) (2.7)
.exe | Win16/32 Executable Delphi generic (1.2)
.exe | Generic Win/DOS Executable (1.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2012:10:02 07:04:04+02:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 86016
InitializedDataSize: 531968
UninitializedDataSize: -
EntryPoint: 0x16478
OSVersion: 5
ImageVersion: 6
SubsystemVersion: 5
Subsystem: Windows GUI
FileVersionNumber: 4.1.1.0
ProductVersionNumber: 4.1.1.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: AOMEI International Network Limited
FileDescription: AnyViewer Setup
FileVersion: 4.1.1.0
LegalCopyright: Copyright © 2023 AnyViewer All rights reserved
ProductName: AnyViewer
ProductVersion: 4,1,1,0
No data.
screenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
35
Monitored processes
3
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
drop and start start anyviewersetup[1].exe anyviewersetup[1].tmp no specs anyviewersetup[1].exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
584"C:\Users\admin\AppData\Local\Temp\AnyViewerSetup[1].exe" C:\Users\admin\AppData\Local\Temp\AnyViewerSetup[1].exe
explorer.exe
User:
admin
Company:
AOMEI International Network Limited
Integrity Level:
HIGH
Description:
AnyViewer Setup
Exit code:
0
Version:
4.1.1.0
Modules
Images
c:\users\admin\appdata\local\temp\anyviewersetup[1].exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\user32.dll
c:\windows\system32\wow64.dll
c:\windows\syswow64\gdi32.dll
1612"C:\Users\admin\AppData\Local\Temp\AnyViewerSetup[1].exe" C:\Users\admin\AppData\Local\Temp\AnyViewerSetup[1].exeexplorer.exe
User:
admin
Company:
AOMEI International Network Limited
Integrity Level:
MEDIUM
Description:
AnyViewer Setup
Exit code:
3221226540
Version:
4.1.1.0
Modules
Images
c:\users\admin\appdata\local\temp\anyviewersetup[1].exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
2424"C:\Users\admin\AppData\Local\Temp\is-A89G9.tmp\AnyViewerSetup[1].tmp" /SL5="$80136,42112524,619008,C:\Users\admin\AppData\Local\Temp\AnyViewerSetup[1].exe" C:\Users\admin\AppData\Local\Temp\is-A89G9.tmp\AnyViewerSetup[1].tmpAnyViewerSetup[1].exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-a89g9.tmp\anyviewersetup[1].tmp
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\wow64.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\oleaut32.dll
Total events
154
Read events
154
Write events
0
Delete events
0

Modification events

No data
Executable files
8
Suspicious files
0
Text files
34
Unknown types
0

Dropped files

PID
Process
Filename
Type
584AnyViewerSetup[1].exeC:\Users\admin\AppData\Local\Temp\is-A89G9.tmp\AnyViewerSetup[1].tmpexecutable
MD5:8CE6B53DED85E3DDD7BD5CFF708B5A83
SHA256:3CB8AE64D7CCBF948F83B069A2ED9BE9479D278A34C07E54796B80DA69516C9C
2424AnyViewerSetup[1].tmpC:\Users\admin\AppData\Local\Temp\is-HJKCS.tmp\_isetup\_shfoldr.dllexecutable
MD5:92DC6EF532FBB4A5C3201469A5B5EB63
SHA256:9884E9D1B4F8A873CCBD81F8AD0AE257776D2348D027D811A56475E028360D87
2424AnyViewerSetup[1].tmpC:\Users\admin\AppData\Local\Temp\is-HJKCS.tmp\botva2.dllexecutable
MD5:0177746573EED407F8DCA8A9E441AA49
SHA256:A4B61626A1626FDABEC794E4F323484AA0644BAA1C905A5DCF785DC34564F008
2424AnyViewerSetup[1].tmpC:\Users\admin\AppData\Local\Temp\is-HJKCS.tmp\CallbackCtrl.dllexecutable
MD5:E4AAA24DD6549CA02E0FC45302345DD0
SHA256:9FB8C2522B2C5F826BACD1BF5CB42AF70AA2080FB680F96E747D3900EB40A6F9
2424AnyViewerSetup[1].tmpC:\Users\admin\AppData\Local\Temp\is-HJKCS.tmp\PathFormat.dllexecutable
MD5:ED26AEDADE2F4CA5DA61FF5BAA1A16D7
SHA256:0DE968FFD4A6C60413CAC739DCCB1B162F8F93F3DB754728FDE8738E52706FA4
2424AnyViewerSetup[1].tmpC:\Users\admin\AppData\Local\Temp\is-HJKCS.tmp\_isetup\_setup64.tmpexecutable
MD5:4FF75F505FDDCC6A9AE62216446205D9
SHA256:A4C86FC4836AC728D7BD96E7915090FD59521A9E74F1D06EF8E5A47C8695FD81
2424AnyViewerSetup[1].tmpC:\Users\admin\AppData\Local\Temp\is-HJKCS.tmp\_isetup\_isdecmp.dllexecutable
MD5:A813D18268AFFD4763DDE940246DC7E5
SHA256:E19781AABE466DD8779CB9C8FA41BBB73375447066BB34E876CF388A6ED63C64
2424AnyViewerSetup[1].tmpC:\Users\admin\AppData\Local\Temp\is-HJKCS.tmp\MFCButton.dllexecutable
MD5:2581AE0A7A36A6A389EA9CEBB4F01F39
SHA256:E9304127981FD0B4E7F5CC2C19D8618B7DEB0C3C9149045AF66C5F7D6AA89222
2424AnyViewerSetup[1].tmpC:\Users\admin\AppData\Local\Temp\is-HJKCS.tmp\icon_d.pngimage
MD5:51D8B58303422DC807C774C0C9C774D3
SHA256:E16EEB7A299B9678C194CB8DF304988B72B4CA1516C513F2BDAB4F761CFDB839
2424AnyViewerSetup[1].tmpC:\Users\admin\AppData\Local\Temp\is-HJKCS.tmp\iconclose.pngimage
MD5:4B00487FF65448660795F0932ED58419
SHA256:F81CBF673E0A8C2708CC6C2E84F589A4E347255CAB30AB68C064CF41C7B9E684
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
5
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
1956
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:138
whitelisted
324
svchost.exe
224.0.0.252:5355
unknown

DNS requests

No data

Threats

No threats detected
No debug info