| File name: | StartIsBack++_v2.9.20_patched.exe |
| Full analysis: | https://app.any.run/tasks/1c9309f9-f660-455d-8474-6d1aa20d027e |
| Verdict: | Malicious activity |
| Analysis date: | March 24, 2025, 12:41:46 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, 5 sections |
| MD5: | 0EB73314DF184EE74B474249783AC8F7 |
| SHA1: | 1BD8E0CB15DEAE490A5275AA733D2569C2EC9888 |
| SHA256: | A7BBC17D33FCED6EFC4E56FBEB6DA557C6B5A5E81FEEC634105B31D6E2BE67FE |
| SSDEEP: | 49152:rl5geQnKgOtT/PT4JT4PkTzDZ/GCEGRSdbvpvECsQK14rkjdmlnYIgBwdkArXg31:Z5k2DPsRjZ+C/RSdaQwDjUlDiBbHHgVE |
| .exe | | | Win64 Executable (generic) (64.6) |
|---|---|---|
| .dll | | | Win32 Dynamic Link Library (generic) (15.4) |
| .exe | | | Win32 Executable (generic) (10.5) |
| .exe | | | Generic Win/DOS Executable (4.6) |
| .exe | | | DOS Executable Generic (4.6) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2017:05:08 19:27:11+00:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 12 |
| CodeSize: | 32256 |
| InitializedDataSize: | 55808 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x1741 |
| OSVersion: | 6 |
| ImageVersion: | - |
| SubsystemVersion: | 6 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.0.0.1000 |
| ProductVersionNumber: | 1.0.0.1000 |
| FileFlagsMask: | 0x0000 |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| CompanyName: | www.startisback.com |
| FileDescription: | StartIsBack++ setup SFX |
| FileVersion: | 1.0.0 |
| LegalCopyright: | Copyright (C) 2012-2017, Tihiy |
| OriginalFileName: | 7-zip SfxSetup.exe |
| ProductName: | StartIsBack |
| ProductVersion: | 1.0.0 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 552 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | taskkill.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 896 | "C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEvent | C:\Windows\System32\slui.exe | — | SppExtComObj.Exe | |||||||||||
User: NETWORK SERVICE Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows Activation Client Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1852 | "C:\Users\admin\AppData\Local\Temp\SIBSFX.0D00A950\StartIsBackCfg.exe" /install | C:\Users\admin\AppData\Local\Temp\SIBSFX.0D00A950\StartIsBackCfg.exe | StartIsBack++_v2.9.20_patched.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Description: StartIsBack configuration Exit code: 0 Version: 5.9.20.3594 Modules
| |||||||||||||||
| 2088 | "C:\Users\admin\AppData\Local\StartIsBack\StartScreen.exe" /unpin | C:\Users\admin\AppData\Local\StartIsBack\StartScreen.exe | — | explorer.exe | |||||||||||
User: admin Company: www.startisback.com Integrity Level: MEDIUM Description: StartIsBack Helper Tool Exit code: 0 Version: 5.9.8 Modules
| |||||||||||||||
| 2384 | "C:\Users\admin\AppData\Local\Temp\StartIsBack++_v2.9.20_patched.exe" | C:\Users\admin\AppData\Local\Temp\StartIsBack++_v2.9.20_patched.exe | explorer.exe | ||||||||||||
User: admin Company: www.startisback.com Integrity Level: MEDIUM Description: StartIsBack++ setup SFX Exit code: 0 Version: 1.0.0 Modules
| |||||||||||||||
| 4236 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | taskkill.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 4256 | C:\WINDOWS\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.3989_none_7ddb45627cb30e03\TiWorker.exe -Embedding | C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.3989_none_7ddb45627cb30e03\TiWorker.exe | — | svchost.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows Modules Installer Worker Version: 10.0.19041.3989 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 4400 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | taskkill.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 4556 | taskkill.exe /F /IM explorer* | C:\Windows\SysWOW64\taskkill.exe | — | StartIsBackCfg.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Terminates Processes Exit code: 128 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 4616 | "C:\WINDOWS\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\TextInputHost.exe" -ServerName:InputApp.AppXjd5de1g66v206tj52m9d0dtpppx4cgpn.mca | C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\TextInputHost.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Version: 123.26505.0.0 Modules
| |||||||||||||||
| (PID) Process: | (1852) StartIsBackCfg.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\StartIsBack |
| Operation: | write | Name: | InstallLocation |
Value: C:\Users\admin\AppData\Local\StartIsBack\ | |||
| (PID) Process: | (1852) StartIsBackCfg.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\StartIsBack |
| Operation: | write | Name: | Publisher |
Value: startisback.com | |||
| (PID) Process: | (1852) StartIsBackCfg.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\StartIsBack |
| Operation: | write | Name: | NoModify |
Value: 1 | |||
| (PID) Process: | (1852) StartIsBackCfg.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\StartIsBack |
| Operation: | write | Name: | NoRepair |
Value: 1 | |||
| (PID) Process: | (1852) StartIsBackCfg.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\StartIsBack |
| Operation: | write | Name: | DisplayName |
Value: StartIsBack++ | |||
| (PID) Process: | (1852) StartIsBackCfg.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\StartIsBack |
| Operation: | write | Name: | DisplayIcon |
Value: C:\Users\admin\AppData\Local\StartIsBack\StartIsBackCfg.exe,0 | |||
| (PID) Process: | (1852) StartIsBackCfg.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\StartIsBack |
| Operation: | write | Name: | DisplayVersion |
Value: 2.9.20 | |||
| (PID) Process: | (1852) StartIsBackCfg.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\StartIsBack |
| Operation: | write | Name: | UninstallString |
Value: C:\Users\admin\AppData\Local\StartIsBack\StartIsBackCfg.exe /uninstall | |||
| (PID) Process: | (1852) StartIsBackCfg.exe | Key: | HKEY_CLASSES_ROOT\CLSID\{c71c41f1-ddad-42dc-a8fc-f5bfc61df958}\InProcServer32 |
| Operation: | write | Name: | ThreadingModel |
Value: Apartment | |||
| (PID) Process: | (1852) StartIsBackCfg.exe | Key: | HKEY_CLASSES_ROOT\CLSID\{a2a9545d-a0c2-42b4-9708-a0b2badd77c9} |
| Operation: | write | Name: | ImplementsVerbs |
Value: startpin;startunpin | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2384 | StartIsBack++_v2.9.20_patched.exe | C:\Users\admin\AppData\Local\Temp\SIBSFX.0D00A950\Orbs\Shamrock.orb | executable | |
MD5:EF55E07E1A2E47BB2BB749046CD150B2 | SHA256:1A8DAC51758C66A1BB03FBC227B5EDB52EF7379FA3603B62EB3307005D06C9B5 | |||
| 2384 | StartIsBack++_v2.9.20_patched.exe | C:\Users\admin\AppData\Local\Temp\SIBSFX.0D00A950\Styles\Plain10.msstyles | executable | |
MD5:A69385279536210958FB9C86CAB229D6 | SHA256:3955FC60D3B7C4A1BADD831FDE82269261407CF9D459C65B429E8ABC769ADEED | |||
| 1852 | StartIsBackCfg.exe | C:\Users\admin\AppData\Local\StartIsBack\Orbs\StartIsBack_Ei8htOrb_v2_by_PainteR.bmp | image | |
MD5:641328C75E6B117545211DB22DAFCAA0 | SHA256:76A72C9AD77843B58223DD588483AC1265A31C15AAEB47EE66D1925DE787644B | |||
| 1852 | StartIsBackCfg.exe | C:\Users\admin\AppData\Local\StartIsBack\StartIsBackCfg.exe | executable | |
MD5:C392E6AA793E52A0AECA50A9F2A3610B | SHA256:39883CB9FA44F6E0FC09E539F23047E36C8DCDDB356CD26DEED8A8E9F495F077 | |||
| 1852 | StartIsBackCfg.exe | C:\Users\admin\AppData\Local\StartIsBack\Orbs\Shamrock.orb | executable | |
MD5:EF55E07E1A2E47BB2BB749046CD150B2 | SHA256:1A8DAC51758C66A1BB03FBC227B5EDB52EF7379FA3603B62EB3307005D06C9B5 | |||
| 1852 | StartIsBackCfg.exe | C:\Users\admin\AppData\Local\StartIsBack\StartScreen.exe | executable | |
MD5:A2D6E2201BE02973328038457AA64BBA | SHA256:F4E76ABF0DF055FAE97863708412773B51197BAE0DDD9692A9509E824D847DF0 | |||
| 2384 | StartIsBack++_v2.9.20_patched.exe | C:\Users\admin\AppData\Local\Temp\SIBSFX.0D00A950\StartIsBack32.dll | executable | |
MD5:4795F1E028E7AB6368FA64DCCD451671 | SHA256:5ED82AA747C6F2A7164CC5DA5449A0B094DE27EEF3BE51E496DBCD9B367D9022 | |||
| 2384 | StartIsBack++_v2.9.20_patched.exe | C:\Users\admin\AppData\Local\Temp\SIBSFX.0D00A950\Styles\Windows 7.msstyles | executable | |
MD5:B6A2892C151CCD59D0B4C4C1777DAAC5 | SHA256:0C6E681A8091BA888E58473CCEEAE590C88A405BB30DCB344F940ACF27290CE8 | |||
| 1852 | StartIsBackCfg.exe | C:\Users\admin\AppData\Local\StartIsBack\StartIsBack32.dll | executable | |
MD5:4795F1E028E7AB6368FA64DCCD451671 | SHA256:5ED82AA747C6F2A7164CC5DA5449A0B094DE27EEF3BE51E496DBCD9B367D9022 | |||
| 2384 | StartIsBack++_v2.9.20_patched.exe | C:\Users\admin\AppData\Local\Temp\SIBSFX.0D00A950\StartIsBack64.dll | executable | |
MD5:BED4FFEF522B5B10F2605FF01EE3C288 | SHA256:125BC1C4EECD6724BB48A0562E0E9CF9322911E3E9517408D9467D903F9232CA | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | GET | 200 | 2.16.164.72:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
5496 | MoUsoCoreWorker.exe | GET | 200 | 2.16.164.72:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
6544 | svchost.exe | GET | 200 | 184.30.131.245:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
6924 | SearchApp.exe | GET | 200 | 2.23.77.188:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D | unknown | — | — | whitelisted |
744 | backgroundTaskHost.exe | GET | 200 | 184.30.131.245:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D | unknown | — | — | whitelisted |
7096 | BackgroundTransferHost.exe | GET | 200 | 2.23.77.188:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D | unknown | — | — | whitelisted |
5024 | SIHClient.exe | GET | 200 | 23.219.150.101:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
5024 | SIHClient.exe | GET | 200 | 23.219.150.101:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
— | — | 51.124.78.146:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
— | — | 2.16.164.72:80 | crl.microsoft.com | Akamai International B.V. | NL | whitelisted |
5496 | MoUsoCoreWorker.exe | 2.16.164.72:80 | crl.microsoft.com | Akamai International B.V. | NL | whitelisted |
2104 | svchost.exe | 51.124.78.146:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
6544 | svchost.exe | 40.126.32.136:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
6544 | svchost.exe | 184.30.131.245:80 | ocsp.digicert.com | AKAMAI-AS | US | whitelisted |
3216 | svchost.exe | 40.113.103.199:443 | client.wns.windows.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
2112 | svchost.exe | 51.124.78.146:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
744 | backgroundTaskHost.exe | 20.223.35.26:443 | arc.msn.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
Domain | IP | Reputation |
|---|---|---|
google.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
login.live.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
arc.msn.com |
| whitelisted |
www.bing.com |
| whitelisted |
th.bing.com |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |