File name:

Instalador Hidro Build 1.4.0.exe

Full analysis: https://app.any.run/tasks/6dbd142d-ee56-45ee-bbb7-e1d31a9200d1
Verdict: Malicious activity
Analysis date: July 29, 2024, 16:48:30
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
installer
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

A4B8C10240293E31D4AA199610F78D89

SHA1:

76CDED2F78542EF691D73B6734EEBB33BACE731D

SHA256:

B1649A3EFBEB0F3F0D933BD9A8341FF952E97AFE8C98DF45C3EEEE6F7203C32A

SSDEEP:

98304:n6P4EyWqvpZTD2ilZP4caoZ852nL2q2dxr1Ps1ZqVWkCh21wqOvTkwmNZD/XV4Ix:xaBjDWiESaQauKO53

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • Instalador Hidro Build 1.4.0.exe (PID: 6656)
      • Instalador Hidro Build 1.4.0.tmp (PID: 6340)
      • Instalador Hidro Build 1.4.0.exe (PID: 5128)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • Instalador Hidro Build 1.4.0.tmp (PID: 2188)
    • Executable content was dropped or overwritten

      • Instalador Hidro Build 1.4.0.exe (PID: 6656)
      • Instalador Hidro Build 1.4.0.tmp (PID: 6340)
      • Instalador Hidro Build 1.4.0.exe (PID: 5128)
    • Reads the Windows owner or organization settings

      • Instalador Hidro Build 1.4.0.tmp (PID: 6340)
    • There is functionality for taking screenshot (YARA)

      • Hidro 1.4.exe (PID: 3868)
    • Reads the date of Windows installation

      • Instalador Hidro Build 1.4.0.tmp (PID: 2188)
  • INFO

    • Create files in a temporary directory

      • Instalador Hidro Build 1.4.0.exe (PID: 5128)
      • Instalador Hidro Build 1.4.0.exe (PID: 6656)
      • Instalador Hidro Build 1.4.0.tmp (PID: 6340)
      • Hidro 1.4.exe (PID: 3868)
    • Checks supported languages

      • Instalador Hidro Build 1.4.0.exe (PID: 5128)
      • Instalador Hidro Build 1.4.0.exe (PID: 6656)
      • Instalador Hidro Build 1.4.0.tmp (PID: 6340)
      • Hidro 1.4.exe (PID: 3868)
      • Instalador Hidro Build 1.4.0.tmp (PID: 2188)
    • Process checks computer location settings

      • Instalador Hidro Build 1.4.0.tmp (PID: 2188)
    • Reads the computer name

      • Instalador Hidro Build 1.4.0.tmp (PID: 6340)
      • Hidro 1.4.exe (PID: 3868)
      • Instalador Hidro Build 1.4.0.tmp (PID: 2188)
    • Checks proxy server information

      • slui.exe (PID: 2736)
    • Creates files in the program directory

      • Instalador Hidro Build 1.4.0.tmp (PID: 6340)
    • Reads the software policy settings

      • slui.exe (PID: 2736)
    • Creates files or folders in the user directory

      • Hidro 1.4.exe (PID: 3868)
    • Creates a software uninstall entry

      • Instalador Hidro Build 1.4.0.tmp (PID: 6340)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (77.7)
.exe | Win32 Executable Delphi generic (10)
.dll | Win32 Dynamic Link Library (generic) (4.6)
.exe | Win32 Executable (generic) (3.1)
.exe | Win16/32 Executable Delphi generic (1.4)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 1992:06:19 22:22:17+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 41472
InitializedDataSize: 11776
UninitializedDataSize: -
EntryPoint: 0xaa98
OSVersion: 1
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 0.0.0.0
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: Agência Nacional de Águas - ANA - Superintêndencia de Gestão
FileDescription: Hidro 1.4 Setup
FileVersion:
LegalCopyright:
ProductName: Hidro 1.4
ProductVersion:
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
147
Monitored processes
7
Malicious processes
3
Suspicious processes
1

Behavior graph

Click at the process to see the details
start instalador hidro build 1.4.0.exe instalador hidro build 1.4.0.tmp no specs instalador hidro build 1.4.0.exe instalador hidro build 1.4.0.tmp slui.exe slui.exe no specs THREAT hidro 1.4.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2188"C:\Users\admin\AppData\Local\Temp\is-7PUNT.tmp\Instalador Hidro Build 1.4.0.tmp" /SL5="$1B0180,13519603,54272,C:\Users\admin\AppData\Local\Temp\Instalador Hidro Build 1.4.0.exe" C:\Users\admin\AppData\Local\Temp\is-7PUNT.tmp\Instalador Hidro Build 1.4.0.tmpInstalador Hidro Build 1.4.0.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.52.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-7punt.tmp\instalador hidro build 1.4.0.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
2632C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
2736C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
3868"C:\Program Files (x86)\Hidro 1.4\Hidro 1.4.exe" /LOGC:\Program Files (x86)\Hidro 1.4\Hidro 1.4.exe
Instalador Hidro Build 1.4.0.tmp
User:
admin
Company:
SGH/ANA
Integrity Level:
MEDIUM
Description:
Sistema de Informações Hidrológicas
Version:
1.4.0.83
Modules
Images
c:\program files (x86)\hidro 1.4\hidro 1.4.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
5128"C:\Users\admin\AppData\Local\Temp\Instalador Hidro Build 1.4.0.exe" C:\Users\admin\AppData\Local\Temp\Instalador Hidro Build 1.4.0.exe
explorer.exe
User:
admin
Company:
Agência Nacional de Águas - ANA - Superintêndencia de Gestão
Integrity Level:
MEDIUM
Description:
Hidro 1.4 Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\appdata\local\temp\instalador hidro build 1.4.0.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
6340"C:\Users\admin\AppData\Local\Temp\is-HFKQH.tmp\Instalador Hidro Build 1.4.0.tmp" /SL5="$26023C,13519603,54272,C:\Users\admin\AppData\Local\Temp\Instalador Hidro Build 1.4.0.exe" /SPAWNWND=$1C02F4 /NOTIFYWND=$1B0180 C:\Users\admin\AppData\Local\Temp\is-HFKQH.tmp\Instalador Hidro Build 1.4.0.tmp
Instalador Hidro Build 1.4.0.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.52.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-hfkqh.tmp\instalador hidro build 1.4.0.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
6656"C:\Users\admin\AppData\Local\Temp\Instalador Hidro Build 1.4.0.exe" /SPAWNWND=$1C02F4 /NOTIFYWND=$1B0180 C:\Users\admin\AppData\Local\Temp\Instalador Hidro Build 1.4.0.exe
Instalador Hidro Build 1.4.0.tmp
User:
admin
Company:
Agência Nacional de Águas - ANA - Superintêndencia de Gestão
Integrity Level:
HIGH
Description:
Hidro 1.4 Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\appdata\local\temp\instalador hidro build 1.4.0.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
Total events
6 166
Read events
6 088
Write events
72
Delete events
6

Modification events

(PID) Process:(6340) Instalador Hidro Build 1.4.0.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
C418000028440D2CD7E1DA01
(PID) Process:(6340) Instalador Hidro Build 1.4.0.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:SessionHash
Value:
57392D25EBD34EA88F016E4935E5F5306E8E7F0B35A30F7F8445F2F2F8D77AAB
(PID) Process:(6340) Instalador Hidro Build 1.4.0.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:Sequence
Value:
1
(PID) Process:(6340) Instalador Hidro Build 1.4.0.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:RegFiles0000
Value:
C:\Program Files (x86)\Hidro 1.4\Hidro 1.4.exe
(PID) Process:(6340) Instalador Hidro Build 1.4.0.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:RegFilesHash
Value:
B6201F486F15C5E2EC5E7DD8CD63591B1F258810665CBAB294B952413E495B6C
(PID) Process:(6340) Instalador Hidro Build 1.4.0.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{C4EE9CF3-A201-4D99-AD3C-728A27ECB828}_is1
Operation:writeName:Inno Setup: Setup Version
Value:
5.5.9 (a)
(PID) Process:(6340) Instalador Hidro Build 1.4.0.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{C4EE9CF3-A201-4D99-AD3C-728A27ECB828}_is1
Operation:writeName:Inno Setup: App Path
Value:
C:\Program Files (x86)\Hidro 1.4
(PID) Process:(6340) Instalador Hidro Build 1.4.0.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{C4EE9CF3-A201-4D99-AD3C-728A27ECB828}_is1
Operation:writeName:InstallLocation
Value:
C:\Program Files (x86)\Hidro 1.4\
(PID) Process:(6340) Instalador Hidro Build 1.4.0.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{C4EE9CF3-A201-4D99-AD3C-728A27ECB828}_is1
Operation:writeName:Inno Setup: Icon Group
Value:
Hidro 1.4
(PID) Process:(6340) Instalador Hidro Build 1.4.0.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{C4EE9CF3-A201-4D99-AD3C-728A27ECB828}_is1
Operation:writeName:Inno Setup: User
Value:
admin
Executable files
7
Suspicious files
13
Text files
14
Unknown types
0

Dropped files

PID
Process
Filename
Type
6340Instalador Hidro Build 1.4.0.tmpC:\Program Files (x86)\Hidro 1.4\is-88GH4.tmp
MD5:
SHA256:
6340Instalador Hidro Build 1.4.0.tmpC:\Program Files (x86)\Hidro 1.4\Hidro.mdb
MD5:
SHA256:
6340Instalador Hidro Build 1.4.0.tmpC:\Users\admin\AppData\Local\Temp\is-SEP5A.tmp\_isetup\_setup64.tmpexecutable
MD5:E4211D6D009757C078A9FAC7FF4F03D4
SHA256:388A796580234EFC95F3B1C70AD4CB44BFDDC7BA0F9203BF4902B9929B136F95
6340Instalador Hidro Build 1.4.0.tmpC:\Program Files (x86)\Hidro 1.4\is-UU3LL.tmptext
MD5:E50867916E15E1C8290E81BCE0CC6687
SHA256:9DBA0BF43ED700B73EDD6BE0A8BFD8509F3E48844BD710152B6EDD307A2A31AA
6340Instalador Hidro Build 1.4.0.tmpC:\Program Files (x86)\Hidro 1.4\Hidro 1.0 - Manual do Usuário.pdfpdf
MD5:43638C138DC4847182C3801F414F4698
SHA256:45C4BAC86BC584A9F4926ACF18B878CFEC3B48BDCDC7594CB194FDFC94E16C37
6340Instalador Hidro Build 1.4.0.tmpC:\Program Files (x86)\Hidro 1.4\is-JM3I2.tmppdf
MD5:C2CBD4A85AFE680E17533781BE2AD716
SHA256:E81C3A8731AF6B38AD6C15BED2420F4BC868D36F9DEF121ADBE36B619101CE34
6340Instalador Hidro Build 1.4.0.tmpC:\Program Files (x86)\Hidro 1.4\is-B0O6Q.tmppdf
MD5:DD5BC01F827CA92AF7C89E03AA03B569
SHA256:D098FE733740299C25EF3FC33AC7E96D6B21FF01925150D6B1D74791914E24F8
6340Instalador Hidro Build 1.4.0.tmpC:\Program Files (x86)\Hidro 1.4\is-TRD8O.tmptext
MD5:ACBC40F6104AF6BD4C196060317C7264
SHA256:6136DD163BA52D5863FFD6B70C9F3AACE5D5551ABDD1599C5F2972F0A4F9FB98
6340Instalador Hidro Build 1.4.0.tmpC:\Program Files (x86)\Hidro 1.4\is-20L3P.tmp
MD5:
SHA256:
6340Instalador Hidro Build 1.4.0.tmpC:\Program Files (x86)\Hidro 1.4\Hidro.hlp
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
46
DNS requests
22
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5368
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
4424
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
4132
OfficeClickToRun.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
3676
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
5368
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEApDqVCbATUviZV57HIIulA%3D
unknown
whitelisted
5428
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2348
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
131.253.33.254:443
a-ring-fallback.msedge.net
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
6012
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
4580
slui.exe
40.91.76.224:443
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
104.126.37.170:443
www.bing.com
Akamai International B.V.
DE
unknown
996
RUXIMICS.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
4
System
192.168.100.255:138
whitelisted
3952
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:137
whitelisted
40.91.76.224:443
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 4.231.128.59
whitelisted
t-ring-fdv2.msedge.net
  • 13.107.237.254
unknown
a-ring-fallback.msedge.net
  • 131.253.33.254
unknown
www.bing.com
  • 104.126.37.170
  • 104.126.37.130
  • 104.126.37.171
  • 104.126.37.185
  • 104.126.37.131
  • 104.126.37.152
  • 104.126.37.137
  • 104.126.37.146
  • 104.126.37.145
  • 2.23.209.149
  • 2.23.209.189
  • 2.23.209.133
  • 2.23.209.179
  • 2.23.209.130
  • 2.23.209.182
  • 2.23.209.140
  • 2.23.209.187
whitelisted
google.com
  • 142.250.185.238
whitelisted
login.live.com
  • 40.126.32.76
  • 20.190.160.14
  • 40.126.32.140
  • 40.126.32.72
  • 20.190.160.17
  • 40.126.32.134
  • 20.190.160.22
  • 40.126.32.74
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
fp-afd-nocache-ccp.azureedge.net
  • 13.107.246.45
whitelisted
client.wns.windows.com
  • 40.113.103.199
whitelisted
fd.api.iris.microsoft.com
  • 20.103.156.88
whitelisted

Threats

No threats detected
No debug info