File name:

setup.exe

Full analysis: https://app.any.run/tasks/de196755-2edd-4315-98f5-448039f81d15
Verdict: Malicious activity
Analysis date: November 10, 2023, 19:28:55
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

655D0B6603C70764622B0EE676772FAB

SHA1:

9737FDA4694D32C70B11820FAA1E848ACF509EC9

SHA256:

AFAF7883EF59A181410EAC098CD704BF851074D63136E9307BB2A68E0A9D66ED

SSDEEP:

12288:ggsWEylbdvc6cHvE9tqZZrAttJVVVVVVVVVVVVVVVVVVVOVVVVVVVVVVVVVVVVVU:ggsWJYERjz6Q

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • setup.exe (PID: 3128)
      • NDP461-KB3102438-Web.exe (PID: 3856)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • setup.exe (PID: 3128)
      • Setup.exe (PID: 3944)
    • Reads the Internet Settings

      • setup.exe (PID: 3128)
      • Setup.exe (PID: 3944)
    • Reads settings of System Certificates

      • setup.exe (PID: 3128)
      • Setup.exe (PID: 3944)
    • Checks Windows Trust Settings

      • setup.exe (PID: 3128)
      • Setup.exe (PID: 3944)
    • Process drops legitimate windows executable

      • setup.exe (PID: 3128)
      • NDP461-KB3102438-Web.exe (PID: 3856)
    • Adds/modifies Windows certificates

      • NDP461-KB3102438-Web.exe (PID: 3856)
  • INFO

    • Reads the computer name

      • setup.exe (PID: 3128)
      • wmpnscfg.exe (PID: 3564)
      • NDP461-KB3102438-Web.exe (PID: 3856)
      • Setup.exe (PID: 3944)
      • SetupUtility.exe (PID: 3984)
      • SetupUtility.exe (PID: 4000)
      • TMPB774.tmp.exe (PID: 3976)
    • Create files in a temporary directory

      • setup.exe (PID: 3128)
      • NDP461-KB3102438-Web.exe (PID: 3856)
      • Setup.exe (PID: 3944)
      • SetupUtility.exe (PID: 3984)
      • TMPB774.tmp.exe (PID: 3976)
    • Checks supported languages

      • setup.exe (PID: 3128)
      • wmpnscfg.exe (PID: 3564)
      • NDP461-KB3102438-Web.exe (PID: 3856)
      • Setup.exe (PID: 3944)
      • SetupUtility.exe (PID: 3984)
      • SetupUtility.exe (PID: 4000)
      • TMPB774.tmp.exe (PID: 3976)
    • Checks proxy server information

      • setup.exe (PID: 3128)
    • Reads the machine GUID from the registry

      • setup.exe (PID: 3128)
      • wmpnscfg.exe (PID: 3564)
      • NDP461-KB3102438-Web.exe (PID: 3856)
      • Setup.exe (PID: 3944)
      • SetupUtility.exe (PID: 3984)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 3564)
    • Creates files or folders in the user directory

      • setup.exe (PID: 3128)
      • Setup.exe (PID: 3944)
    • Reads Environment values

      • Setup.exe (PID: 3944)
    • Reads CPU info

      • Setup.exe (PID: 3944)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable (generic) (52.9)
.exe | Generic Win/DOS Executable (23.5)
.exe | DOS Executable Generic (23.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2017:10:06 04:16:55+02:00
ImageFileCharacteristics: Executable, Large address aware, 32-bit
PEType: PE32
LinkerVersion: 14.1
CodeSize: 374784
InitializedDataSize: 430592
UninitializedDataSize: -
EntryPoint: 0x35267
OSVersion: 5.1
ImageVersion: 10
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 15.0.27005.2
ProductVersionNumber: 15.0.27005.2
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: -
FileDescription: Setup
FileVersion: 15.0.27005.2 built by: D15REL
InternalName: setup.exe
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFileName: setup.exe
ProductName: -
ProductVersion: 15.0.27005.2
No data.
screenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
45
Monitored processes
8
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start setup.exe wmpnscfg.exe no specs ndp461-kb3102438-web.exe no specs ndp461-kb3102438-web.exe setup.exe setuputility.exe no specs setuputility.exe no specs tmpb774.tmp.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
3128"C:\Users\admin\AppData\Local\Temp\setup.exe" C:\Users\admin\AppData\Local\Temp\setup.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup
Exit code:
0
Version:
15.0.27005.2 built by: D15REL
Modules
Images
c:\users\admin\appdata\local\temp\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
3516"C:\Users\admin\AppData\Local\Temp\VSD6EBC.tmp\DotNetFX461\NDP461-KB3102438-Web.exe" /q /norestart /ChainingPackage FullX64Bootstrapper /lcid 1033C:\Users\admin\AppData\Local\Temp\VSD6EBC.tmp\DotNetFX461\NDP461-KB3102438-Web.exesetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft .NET Framework 4.6.1 Setup
Exit code:
3221226540
Version:
4.6.01055.00
Modules
Images
c:\users\admin\appdata\local\temp\vsd6ebc.tmp\dotnetfx461\ndp461-kb3102438-web.exe
c:\windows\system32\ntdll.dll
3564"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\ole32.dll
3856"C:\Users\admin\AppData\Local\Temp\VSD6EBC.tmp\DotNetFX461\NDP461-KB3102438-Web.exe" /q /norestart /ChainingPackage FullX64Bootstrapper /lcid 1033C:\Users\admin\AppData\Local\Temp\VSD6EBC.tmp\DotNetFX461\NDP461-KB3102438-Web.exe
setup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft .NET Framework 4.6.1 Setup
Exit code:
0
Version:
4.6.01055.00
Modules
Images
c:\users\admin\appdata\local\temp\vsd6ebc.tmp\dotnetfx461\ndp461-kb3102438-web.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\gdi32.dll
3944C:\50a3dd900eb4fa4e38\\Setup.exe /q /norestart /ChainingPackage FullX64Bootstrapper /lcid 1033 /x86 /x64 /webC:\50a3dd900eb4fa4e38\Setup.exe
NDP461-KB3102438-Web.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Setup Installer
Exit code:
0
Version:
14.0.1055.0 built by: NETFXREL2
Modules
Images
c:\50a3dd900eb4fa4e38\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\50a3dd900eb4fa4e38\setupengine.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
3976TMPB774.tmp.exe /Q /X:C:\50a3dd900eb4fa4e38\TMPB774.tmp.exe.tmpC:\50a3dd900eb4fa4e38\TMPB774.tmp.exeSetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft .NET Framework 4.6.1 Setup
Exit code:
0
Version:
4.6.01055.00
Modules
Images
c:\50a3dd900eb4fa4e38\tmpb774.tmp.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\gdi32.dll
3984SetupUtility.exe /aupauseC:\50a3dd900eb4fa4e38\SetupUtility.exeSetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft .NET Framework 4.5 Setup
Exit code:
0
Version:
14.0.1055.0 built by: NETFXREL2
Modules
Images
c:\50a3dd900eb4fa4e38\setuputility.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
4000SetupUtility.exe /screbootC:\50a3dd900eb4fa4e38\SetupUtility.exeSetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft .NET Framework 4.5 Setup
Exit code:
0
Version:
14.0.1055.0 built by: NETFXREL2
Modules
Images
c:\50a3dd900eb4fa4e38\setuputility.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
12 402
Read events
12 360
Write events
37
Delete events
5

Modification events

(PID) Process:(3128) setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3128) setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(3128) setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(3128) setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(3128) setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(3128) setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
4600000059010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(3128) setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(3128) setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(3128) setup.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\17A\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3564) wmpnscfg.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{0B23B1E7-E740-4C61-9914-C5A40373EBAF}\{EEFBF990-3652-4FA8-9597-88B17B702C31}
Operation:delete keyName:(default)
Value:
Executable files
38
Suspicious files
22
Text files
80
Unknown types
0

Dropped files

PID
Process
Filename
Type
3128setup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\80237EE4964FC9C409AAF55BF996A292_D46D6FA25B74360E1349F9015B5CCE53binary
MD5:0A6E9F80A65387118D94EC5C01E197AA
SHA256:A5AAE7D9F0DE1DC8353252D157A3CE31DF660EBBA4FD31A33AC3408A943911D8
3128setup.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\78RFYB7Z\NDP461-KB3102436-x86-x64-AllOS-ESN[1].exeexecutable
MD5:75F76DAB6DF5D6B6F327D1B5729AA8EE
SHA256:21CC26F9F83A2C14AAF03D0887E138400177C455761C89DD246ABBF46F62DA6A
3128setup.exeC:\Users\admin\AppData\Local\Temp\VSD6EBC.tmp\setup.exeexecutable
MD5:655D0B6603C70764622B0EE676772FAB
SHA256:AFAF7883EF59A181410EAC098CD704BF851074D63136E9307BB2A68E0A9D66ED
3128setup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\57C8EDB95DF3F0AD4EE2DC2B8CFD4157compressed
MD5:1BFE591A4FE3D91B03CDF26EAACD8F89
SHA256:9CF94355051BF0F4A45724CA20D1CC02F76371B963AB7D1E38BD8997737B13D8
3128setup.exeC:\Users\admin\AppData\Local\Temp\VSD6EBC.tmp\DotNetFX461\NDP461-KB3102436-x86-x64-AllOS-ESN.exeexecutable
MD5:75F76DAB6DF5D6B6F327D1B5729AA8EE
SHA256:21CC26F9F83A2C14AAF03D0887E138400177C455761C89DD246ABBF46F62DA6A
3128setup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\1F657678CDAD5400251B323D207EA54Fbinary
MD5:839A3145057932596326B0129D44A1D5
SHA256:9CBF22FAE0DD53A7395556CE6154AA14A0D03360AA8C51CFEA05D1FD8819E043
3128setup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\1F657678CDAD5400251B323D207EA54Fbinary
MD5:15511CF2697F2FE7ECD529175458ED9B
SHA256:8237A21909EB16A2EBC702D49280BD279FA1020326701A0A905AF5F4F65EB15D
3128setup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506compressed
MD5:F3441B8572AAE8801C04F3060B550443
SHA256:6720349E7D82EE0A8E73920D3C2B7CB2912D9FCF2EDB6FD98F2F12820158B0BF
3128setup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506binary
MD5:41E41FDEB399FFAA198FB84BD1BD7E56
SHA256:7EF59979FAAC72429FBF3F3056822D0CA66E3E32361C804B491F913729BDD053
3856NDP461-KB3102438-Web.exeC:\50a3dd900eb4fa4e38\header.bmpimage
MD5:41C22EFA84CA74F0CE7076EB9A482E38
SHA256:255025A0D79EF2DAC04BD610363F966EF58328400BF31E1F8915E676478CD750
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
17
TCP/UDP connections
17
DNS requests
10
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3128
setup.exe
GET
302
69.192.162.125:80
http://go.microsoft.com/fwlink/?linkid=671731&clcid=0xc0a
unknown
unknown
3128
setup.exe
GET
302
69.192.162.125:80
http://go.microsoft.com/fwlink/?linkid=671728&clcid=0x409
unknown
unknown
3944
Setup.exe
GET
302
23.43.62.58:80
http://go.microsoft.com/fwlink/?LinkId=671733&clcid=0x409
unknown
unknown
3944
Setup.exe
GET
200
23.216.77.6:80
http://crl.microsoft.com/pki/crl/products/MicTimStaPCA_2010-07-01.crl
unknown
binary
555 b
unknown
3944
Setup.exe
GET
200
23.216.77.6:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut_2010-06-23.crl
unknown
binary
824 b
unknown
3128
setup.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEA177el9ggmWelJjG4vdGL0%3D
unknown
binary
471 b
unknown
3128
setup.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pki/certs/MicCodSigPCA_08-31-2010.crt
unknown
der
1.44 Kb
unknown
3128
setup.exe
GET
200
67.27.141.126:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?329ca16cd264587e
unknown
compressed
4.66 Kb
unknown
3128
setup.exe
GET
200
23.216.77.6:80
http://crl.microsoft.com/pki/crl/products/microsoftrootcert.crl
unknown
der
767 b
unknown
3128
setup.exe
GET
200
67.27.141.126:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?dc4901e1247eea5c
unknown
compressed
61.6 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
2588
svchost.exe
239.255.255.250:1900
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
whitelisted
3128
setup.exe
69.192.162.125:80
go.microsoft.com
AKAMAI-AS
DE
unknown
3128
setup.exe
104.122.27.233:443
download.microsoft.com
AKAMAI-AS
DE
unknown
3128
setup.exe
67.27.141.126:80
ctldl.windowsupdate.com
LEVEL3
US
unknown
3128
setup.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
3128
setup.exe
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
3128
setup.exe
23.216.77.6:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted

DNS requests

Domain
IP
Reputation
go.microsoft.com
  • 69.192.162.125
  • 23.43.62.58
whitelisted
download.microsoft.com
  • 104.122.27.233
whitelisted
ctldl.windowsupdate.com
  • 67.27.141.126
  • 8.238.41.126
  • 8.238.38.126
  • 8.238.41.254
  • 8.253.145.120
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
www.microsoft.com
  • 23.35.229.160
  • 88.221.125.143
whitelisted
crl.microsoft.com
  • 23.216.77.6
  • 23.216.77.28
whitelisted
download.visualstudio.microsoft.com
  • 68.232.34.200
whitelisted

Threats

No threats detected
No debug info