File name:

systeminformer-3.0.7660-release-setup.exe

Full analysis: https://app.any.run/tasks/337a3c4d-5f84-4d8b-8652-c2ace4dd9c0f
Verdict: Malicious activity
Analysis date: August 18, 2024, 23:22:01
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

0D909A4A638465A17BC9F37C5024E574

SHA1:

EAB2BC1CA6EBFA17B95B8CACEBCB04043238164E

SHA256:

A82821A4C18EF940354B84CD625CE0FD8ED5CFBA5418014063F054071BD5FCCD

SSDEEP:

98304:BfuShiqGEHMUGmL1Yt0zJWL9omlWA9ag2liM1UIWMK1CIV3YCQmJhax83+m13oLm:IlKBUMjqQBJa0Kq5JTtIYHTJ5LSGIuy

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Drops the executable file immediately after the start

      • systeminformer-3.0.7660-release-setup.exe (PID: 6580)
      • systeminformer-3.0.7660-release-setup.exe (PID: 6896)
    • Reads security settings of Internet Explorer

      • systeminformer-3.0.7660-release-setup.exe (PID: 6580)
      • systeminformer-3.0.7660-release-setup.exe (PID: 6896)
      • SystemInformer.exe (PID: 6232)
    • Application launched itself

      • systeminformer-3.0.7660-release-setup.exe (PID: 6580)
    • Reads the date of Windows installation

      • systeminformer-3.0.7660-release-setup.exe (PID: 6580)
      • systeminformer-3.0.7660-release-setup.exe (PID: 6896)
    • Executable content was dropped or overwritten

      • systeminformer-3.0.7660-release-setup.exe (PID: 6896)
    • The process creates files with name similar to system file names

      • systeminformer-3.0.7660-release-setup.exe (PID: 6896)
    • Checks Windows Trust Settings

      • SystemInformer.exe (PID: 6232)
    • Creates a software uninstall entry

      • systeminformer-3.0.7660-release-setup.exe (PID: 6896)
    • Drops a system driver (possible attempt to evade defenses)

      • systeminformer-3.0.7660-release-setup.exe (PID: 6896)
  • INFO

    • Checks supported languages

      • systeminformer-3.0.7660-release-setup.exe (PID: 6580)
      • systeminformer-3.0.7660-release-setup.exe (PID: 6896)
      • SystemInformer.exe (PID: 6232)
    • Reads the computer name

      • systeminformer-3.0.7660-release-setup.exe (PID: 6580)
      • systeminformer-3.0.7660-release-setup.exe (PID: 6896)
      • SystemInformer.exe (PID: 6232)
    • Process checks computer location settings

      • systeminformer-3.0.7660-release-setup.exe (PID: 6580)
      • systeminformer-3.0.7660-release-setup.exe (PID: 6896)
    • Creates files in the program directory

      • systeminformer-3.0.7660-release-setup.exe (PID: 6896)
    • Reads the time zone

      • SystemInformer.exe (PID: 6232)
    • Reads CPU info

      • SystemInformer.exe (PID: 6232)
    • Reads the software policy settings

      • SystemInformer.exe (PID: 6232)
    • Reads the machine GUID from the registry

      • SystemInformer.exe (PID: 6232)
    • Checks proxy server information

      • SystemInformer.exe (PID: 6232)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (64.6)
.dll | Win32 Dynamic Link Library (generic) (15.4)
.exe | Win32 Executable (generic) (10.5)
.exe | Generic Win/DOS Executable (4.6)
.exe | DOS Executable Generic (4.6)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2054:10:22 23:54:18+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14.39
CodeSize: 253952
InitializedDataSize: 15585280
UninitializedDataSize: -
EntryPoint: 0x20300
OSVersion: 6.1
ImageVersion: -
SubsystemVersion: 6.1
Subsystem: Windows GUI
FileVersionNumber: 3.0.12187.7660
ProductVersionNumber: 3.0.12187.7660
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
CompanyName: System Informer
FileDescription: System Informer - Setup
FileVersion: 3.0.12187.7660
InternalName: systeminformer-setup.exe
LegalCopyright: Copyright (c) Winsider Seminars & Solutions, Inc. All rights reserved.
OriginalFileName: systeminformer-setup.exe
ProductName: System Informer
ProductVersion: 3.0.12187.7660
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
134
Monitored processes
3
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start systeminformer-3.0.7660-release-setup.exe no specs systeminformer-3.0.7660-release-setup.exe systeminformer.exe

Process information

PID
CMD
Path
Indicators
Parent process
6232"C:\Program Files\SystemInformer\SystemInformer.exe" -channel releaseC:\Program Files\SystemInformer\SystemInformer.exe
systeminformer-3.0.7660-release-setup.exe
User:
admin
Company:
System Informer
Integrity Level:
HIGH
Description:
System Informer
Version:
3.0.12187.7660
Modules
Images
c:\program files\systeminformer\systeminformer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
6580"C:\Users\admin\AppData\Local\Temp\systeminformer-3.0.7660-release-setup.exe" C:\Users\admin\AppData\Local\Temp\systeminformer-3.0.7660-release-setup.exeexplorer.exe
User:
admin
Company:
System Informer
Integrity Level:
MEDIUM
Description:
System Informer - Setup
Exit code:
0
Version:
3.0.12187.7660
Modules
Images
c:\users\admin\appdata\local\temp\systeminformer-3.0.7660-release-setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\ole32.dll
6896"C:\Users\admin\AppData\Local\Temp\systeminformer-3.0.7660-release-setup.exe" "C:\Users\admin\AppData\Local\Temp\systeminformer-3.0.7660-release-setup.exe" C:\Users\admin\AppData\Local\Temp\systeminformer-3.0.7660-release-setup.exe
systeminformer-3.0.7660-release-setup.exe
User:
admin
Company:
System Informer
Integrity Level:
HIGH
Description:
System Informer - Setup
Exit code:
0
Version:
3.0.12187.7660
Modules
Images
c:\users\admin\appdata\local\temp\systeminformer-3.0.7660-release-setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\ole32.dll
Total events
16 741
Read events
16 685
Write events
54
Delete events
2

Modification events

(PID) Process:(6896) systeminformer-3.0.7660-release-setup.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
Operation:writeName:NodeSlots
Value:
020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202
(PID) Process:(6896) systeminformer-3.0.7660-release-setup.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
Operation:writeName:MRUListEx
Value:
04000000030000000E0000000F000000000000000C0000000D0000000B000000050000000A000000090000000800000001000000070000000600000002000000FFFFFFFF
(PID) Process:(6896) systeminformer-3.0.7660-release-setup.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\4
Operation:writeName:MRUListEx
Value:
040000000000000005000000020000000100000003000000FFFFFFFF
(PID) Process:(6896) systeminformer-3.0.7660-release-setup.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\119\Shell
Operation:writeName:SniffedFolderType
Value:
Documents
(PID) Process:(6896) systeminformer-3.0.7660-release-setup.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\3c\52C64B7E
Operation:writeName:@C:\Program Files (x86)\Common Files\system\wab32res.dll,-10100
Value:
Contacts
(PID) Process:(6896) systeminformer-3.0.7660-release-setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(6896) systeminformer-3.0.7660-release-setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(6896) systeminformer-3.0.7660-release-setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(6896) systeminformer-3.0.7660-release-setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(6896) systeminformer-3.0.7660-release-setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\CIDSizeMRU
Operation:writeName:5
Value:
730079007300740065006D0069006E0066006F0072006D00650072002D0033002E0030002E0037003600360030002D00720065006C0065006100730065002D00730065007400750070002E006500780065000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000B8010000A60000003804000086020000000000000000000000000000000000000100000000000000
Executable files
20
Suspicious files
23
Text files
6
Unknown types
0

Dropped files

PID
Process
Filename
Type
6896systeminformer-3.0.7660-release-setup.exeC:\Program Files\SystemInformer\COPYRIGHT.txttext
MD5:D97229C38736F130D83B1C9BA9F68703
SHA256:6DEB8978832A3B5CB8B4AD79F33EFAAC9857AC539D771EEBB3C5680A12436D2C
6896systeminformer-3.0.7660-release-setup.exeC:\Program Files\SystemInformer\EtwGuids.txttext
MD5:E5350380E5A9E4DC1A9432A299B6D4DE
SHA256:43426A3FB94A44B5F4092547A1DE5D9A676064BBCC485BD9B6A79EA1CB1598C8
6896systeminformer-3.0.7660-release-setup.exeC:\Program Files\SystemInformer\ksidyn.binbinary
MD5:93B34D4692A951C5463B7AB1571686B1
SHA256:841BBE82D443930DFC81F7AB80111B41695B28D96BC212E305496C2E60F08B82
6896systeminformer-3.0.7660-release-setup.exeC:\Program Files\SystemInformer\README.txttext
MD5:0CCC7E76DA4E38CD2F73BD197DEA80C3
SHA256:29C068275F2B99405DFED86B2C6C6E0722944B743565796B76FBF74F42DA8039
6896systeminformer-3.0.7660-release-setup.exeC:\Program Files\SystemInformer\PoolTag.txttext
MD5:1C9549CE1C01BBC922CD21D1D5A324E6
SHA256:28D7902155B300414F4277BF212E4D9415810A7960CC67F5DA58A706BE6BD51E
6896systeminformer-3.0.7660-release-setup.exeC:\Program Files\SystemInformer\ksi.dllexecutable
MD5:4857DA220E9B678865C0CCBBA22F4E94
SHA256:28A54EFCF5CEC9190D5AB210A50AF00C4ED91D1AD27C76C868FCD54D8C553FCF
6896systeminformer-3.0.7660-release-setup.exeC:\Program Files\SystemInformer\peview.exeexecutable
MD5:E3B648CE14CFC7C7AAED071E4CF4CF88
SHA256:9B455EBF6DAB83B374CFD1B9C76DA0F04D5F186D570E301F51923C553D959EEC
6896systeminformer-3.0.7660-release-setup.exeC:\Program Files\SystemInformer\peview.sigbinary
MD5:5C150254683E494D331BD040F56D4BAE
SHA256:EABEEE23DC3C2307F71560889AFDE24416DD589925A7C530007D0358878DB94B
6896systeminformer-3.0.7660-release-setup.exeC:\Program Files\SystemInformer\icon.pngimage
MD5:5352EBD888E7E6C1DABD20C4D6B921C5
SHA256:46E1C3D45F5085FA4F97F6BCB2AD0197DABB0E1C7EFD2A6CBA1A0BD3461E2387
6896systeminformer-3.0.7660-release-setup.exeC:\Program Files\SystemInformer\ksidyn.sigbinary
MD5:6569FE0F0ADC6F9530673A2C9C049599
SHA256:6E6EFBE6DF1F3A94DB4018B0220069E95AF60251892FC8D674045F71BA5F2C61
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
3
TCP/UDP connections
30
DNS requests
15
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1492
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6996
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
6572
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4100
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
2636
RUXIMICS.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
2120
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
3888
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:138
whitelisted
4100
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:137
whitelisted
3260
svchost.exe
40.115.3.253:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1492
svchost.exe
20.190.160.17:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1492
svchost.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 20.73.194.208
  • 51.124.78.146
whitelisted
google.com
  • 142.250.185.110
whitelisted
client.wns.windows.com
  • 40.115.3.253
whitelisted
login.live.com
  • 20.190.160.17
  • 40.126.32.76
  • 40.126.32.74
  • 20.190.160.14
  • 40.126.32.72
  • 20.190.160.22
  • 40.126.32.68
  • 40.126.32.138
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
arc.msn.com
  • 20.86.201.138
whitelisted
slscr.update.microsoft.com
  • 13.85.23.86
whitelisted
www.microsoft.com
  • 95.101.149.131
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 20.3.187.198
whitelisted
systeminformer.sourceforge.io
  • 104.18.10.31
  • 104.18.11.31
whitelisted

Threats

No threats detected
No debug info