| File name: | kaspersky4win202121.18.5.438aen_46538.exe |
| Full analysis: | https://app.any.run/tasks/d71b0e5d-d4b2-46bb-b285-f84f943718fb |
| Verdict: | Malicious activity |
| Analysis date: | August 26, 2024, 14:53:23 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 7CB68AEBCBCF5B24CF6BE6F6719154AE |
| SHA1: | D0514994D65FDBB7A4E0F820B4C9D61B56DB200C |
| SHA256: | B2BF771B47C19817E62903401E948379E2794FD932D7494ABAFC86BC291BE69C |
| SSDEEP: | 98304:Wa7U4cWFyYp9GKoym6Vl9aKFFsbRcAZOk5qHPP13JApJCJPMt1o3ma2fwTT+Dj9A:dMVBro |
| .exe | | | Win64 Executable (generic) (76.4) |
|---|---|---|
| .exe | | | Win32 Executable (generic) (12.4) |
| .exe | | | Generic Win/DOS Executable (5.5) |
| .exe | | | DOS Executable Generic (5.5) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2000:04:01 13:47:06+00:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 14.29 |
| CodeSize: | 248832 |
| InitializedDataSize: | 4413952 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x4260 |
| OSVersion: | 6 |
| ImageVersion: | - |
| SubsystemVersion: | 6 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 21.18.5.438 |
| ProductVersionNumber: | 21.18.5.438 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Windows NT 32-bit |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| CompanyName: | Kaspersky |
| FileDescription: | Kaspersky [21.18.5.438.0.301.0 (a)] |
| FileVersion: | 21.18.5.438 |
| LegalCopyright: | © 2024 AO Kaspersky Lab |
| LegalTrademarks: | Registered trademarks and service marks are the property of their respective owners |
| ProductName: | Kaspersky |
| ProductVersion: | 21.18.5.438 |
| InternalName: | Setup |
| OriginalFileName: | Setup.exe |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2368 | "C:\Users\admin\Desktop\kaspersky4win202121.18.5.438aen_46538.exe" /-elevated=;"C:\Users\admin\Desktop\kaspersky4win202121.18.5.438aen_46538.exe" | C:\Users\admin\Desktop\kaspersky4win202121.18.5.438aen_46538.exe | kaspersky4win202121.18.5.438aen_46538.exe | ||||||||||||
User: admin Company: Kaspersky Integrity Level: HIGH Description: Kaspersky [21.18.5.438.0.301.0 (a)] Version: 21.18.5.438 Modules
| |||||||||||||||
| 2820 | "C:\WINDOWS\temp\3BF19D00BB36FE114B3E817F87F669EE\kaspersky4win202121.18.5.438aen_46538.exe" /-elevated=;"C:\Users\admin\Desktop\kaspersky4win202121.18.5.438aen_46538.exe" | C:\Windows\Temp\3BF19D00BB36FE114B3E817F87F669EE\kaspersky4win202121.18.5.438aen_46538.exe | kaspersky4win202121.18.5.438aen_46538.exe | ||||||||||||
User: admin Company: Kaspersky Integrity Level: HIGH Description: Kaspersky [21.18.5.438.0.301.0 (a)] Version: 21.18.5.438 Modules
| |||||||||||||||
| 3448 | "C:\Users\admin\AppData\Local\Temp\7392CE00BB36FE114B3E817F87F669EE\setup_ui.exe" -cp=objref:TUVPVwEAAAAAAAAAAAAAAMAAAAAAAABGgQIAAAAAAAD9/wH1nuaxBQwaMHc1P8XhAsAAAAQL//+SNuTffJfwyzgAIgAHAEQARQBTAEsAVABPAFAALQBKAEcATABMAEoATABEAAAABwAxADkAMgAuADEANgA4AC4AMQAwADAALgA0ADAAAAAAAAkA//8AAB4A//8AABAA//8AAAoA//8AABYA//8AAB8A//8AAA4A//8AAAAA: | C:\Users\admin\AppData\Local\Temp\7392CE00BB36FE114B3E817F87F669EE\setup_ui.exe | kaspersky4win202121.18.5.438aen_46538.exe | ||||||||||||
User: admin Company: Kaspersky Integrity Level: MEDIUM Description: Kaspersky [21.18.5.438.0.301.0 (a)] Version: 21.18.5.438 Modules
| |||||||||||||||
| 4976 | "C:\Users\admin\AppData\Local\Temp\093F737FAB36FE114B3E817F87F669EE\setup_ui.exe" -cp=objref:TUVPVwEAAAAAAAAAAAAAAMAAAAAAAABGgQIAAAAAAADDUJEa/OGT39zmxyD78dhUAkQAADQY//92gicW7YBlMTgAIgAHAEQARQBTAEsAVABPAFAALQBKAEcATABMAEoATABEAAAABwAxADkAMgAuADEANgA4AC4AMQAwADAALgA0ADAAAAAAAAkA//8AAB4A//8AABAA//8AAAoA//8AABYA//8AAB8A//8AAA4A//8AAAAA: | C:\Users\admin\AppData\Local\Temp\093F737FAB36FE114B3E817F87F669EE\setup_ui.exe | kaspersky4win202121.18.5.438aen_46538.exe | ||||||||||||
User: admin Company: Kaspersky Integrity Level: MEDIUM Description: Kaspersky [21.18.5.438.0.301.0 (a)] Exit code: 0 Version: 21.18.5.438 Modules
| |||||||||||||||
| 6196 | "C:\Users\admin\Desktop\kaspersky4win202121.18.5.438aen_46538.exe" | C:\Users\admin\Desktop\kaspersky4win202121.18.5.438aen_46538.exe | explorer.exe | ||||||||||||
User: admin Company: Kaspersky Integrity Level: MEDIUM Description: Kaspersky [21.18.5.438.0.301.0 (a)] Version: 21.18.5.438 Modules
| |||||||||||||||
| (PID) Process: | (6196) kaspersky4win202121.18.5.438aen_46538.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\KasperskyLabSetup\Setup21.18.5.438.0.301.0\volatile |
| Operation: | write | Name: | cp_storedResolvedType |
Value: -1 | |||
| (PID) Process: | (6196) kaspersky4win202121.18.5.438aen_46538.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\KasperskyLabSetup\Setup21.18.5.438.0.301.0\volatile |
| Operation: | write | Name: | cp_storedResolvedProductTier |
Value: 0 | |||
| (PID) Process: | (6196) kaspersky4win202121.18.5.438aen_46538.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\KasperskyLabSetup\Setup21.18.5.438.0.301.0\volatile |
| Operation: | write | Name: | cp_storedResolvedStartupScenario |
Value: | |||
| (PID) Process: | (6196) kaspersky4win202121.18.5.438aen_46538.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\KasperskyLabSetup\Setup21.18.5.438.0.301.0\volatile |
| Operation: | write | Name: | cp_storedResolvedType |
Value: 4 | |||
| (PID) Process: | (6196) kaspersky4win202121.18.5.438aen_46538.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\KasperskyLabSetup\Setup21.18.5.438.0.301.0\volatile |
| Operation: | write | Name: | cp_storedResolvedProductTier |
Value: 230 | |||
| (PID) Process: | (6196) kaspersky4win202121.18.5.438aen_46538.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\KasperskyLabSetup\Setup21.18.5.438.0.301.0\volatile |
| Operation: | write | Name: | cp_storedResolvedStartupScenario |
Value: Free | |||
| (PID) Process: | (6196) kaspersky4win202121.18.5.438aen_46538.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\KasperskyLabSetup\Setup21.18.5.438.0.301.0\volatile |
| Operation: | write | Name: | PreferredUI |
Value: 0 | |||
| (PID) Process: | (6196) kaspersky4win202121.18.5.438aen_46538.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\KasperskyLabSetup\Setup21.18.5.438.0.301.0\volatile |
| Operation: | write | Name: | PreferredUI |
Value: 1 | |||
| (PID) Process: | (4976) setup_ui.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (4976) setup_ui.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6196 | kaspersky4win202121.18.5.438aen_46538.exe | C:\Users\admin\AppData\Local\Temp\F737F391-63BA-11EF-B4E3-18F7786F96EE\GuiStrings.loc | html | |
MD5:09C4E9F41C4B8BFDB6BF8916AF730ECD | SHA256:57BF969D3C10D5BE0A4B31B8E530C1E005622C8DC809EE4FBD4C214F3B3E9A37 | |||
| 6196 | kaspersky4win202121.18.5.438aen_46538.exe | C:\Users\admin\AppData\Local\Temp\kl-setup-2024-08-26-14-53-34_KFA.21.18.5.438.log | text | |
MD5:CAEE3B29C64DF2A5C140F779B22850FB | SHA256:1D9A2F7B17BA481AD4ABE8BCFAB18C57AC760740FA6AB90D19D518A181137651 | |||
| 6196 | kaspersky4win202121.18.5.438aen_46538.exe | C:\Users\admin\AppData\Local\Temp\093F737FAB36FE114B3E817F87F669EE\kl.setup.ui.visuals.dll | executable | |
MD5:70F74920E8265226EA92AAE61E555DF1 | SHA256:6AC4FF8FD298F8F78C825EB714C801F026DB14A1862EEC9562952B59A2F862F8 | |||
| 6196 | kaspersky4win202121.18.5.438aen_46538.exe | C:\Users\admin\AppData\Local\Temp\F737F391-63BA-11EF-B4E3-18F7786F96EE\downloader_neutral_KFA.ini | text | |
MD5:2E10B2D4181D2F07D2DD305BD4285BD5 | SHA256:CBB72CDC1E461226C7D0E49E7EF955F77DFEEF4F7FE12D0D8A8D0CF9658EDC78 | |||
| 6196 | kaspersky4win202121.18.5.438aen_46538.exe | C:\Users\admin\AppData\Local\Temp\093F737FAB36FE114B3E817F87F669EE\kl.ui.framework.uikit.dll | binary | |
MD5:05B722EDF678407E6DA411924D11BF74 | SHA256:41EB3558586EE2EACC0822B725FBA7F755F54C7B0AC450DFEBA5A59057192B44 | |||
| 6196 | kaspersky4win202121.18.5.438aen_46538.exe | C:\Users\admin\AppData\Local\Temp\093F737FAB36FE114B3E817F87F669EE\kl.ui.framework.localization.dll | executable | |
MD5:2985B28C3485039CBEE81B840B5437B4 | SHA256:586C371ECC1B17C7CAC9F8D72961D9D6504B0BF855CA3501262BB0338C6654A4 | |||
| 6196 | kaspersky4win202121.18.5.438aen_46538.exe | C:\Users\admin\AppData\Local\Temp\093F737FAB36FE114B3E817F87F669EE\kl.ui.framework.dll | executable | |
MD5:676BDC05672D36E2EF7DE38AA83A2803 | SHA256:79C7455735EB0B7E8B3CF46DA78B06FB81229169D85039AFAB44CA74FE3F9A43 | |||
| 6196 | kaspersky4win202121.18.5.438aen_46538.exe | C:\Users\admin\AppData\Local\Temp\093F737FAB36FE114B3E817F87F669EE\sharpvectorcore.dll | executable | |
MD5:9620B9B61A710C8A2178747A74D066AC | SHA256:3929EF5D1C09611BDE783054CDAA6F19E07A9F22C7E9C85EDF9510D13C7C423E | |||
| 6196 | kaspersky4win202121.18.5.438aen_46538.exe | C:\Users\admin\AppData\Local\Temp\093F737FAB36FE114B3E817F87F669EE\setup_ui.exe | executable | |
MD5:43E870E61765A8B5B208F633AB9351F8 | SHA256:251DC9804BFB37B50897594F508BCD629D4A45D5C749AAAFB4B5E84D195F68AE | |||
| 6196 | kaspersky4win202121.18.5.438aen_46538.exe | C:\Users\admin\AppData\Local\Temp\093F737FAB36FE114B3E817F87F669EE\kl.setup.ui.interoplayer.dll | executable | |
MD5:B7E44CF662827B55D7F1AFF8AD75BD01 | SHA256:A82B14A1F48329B1288E92CBE72C033C1446FB813F6A8551A86C5DC1ADE7AA16 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | GET | 200 | 46.8.206.115:443 | https://dm.s.kaspersky-labs.com/bases/kavkis2021mr18/Kaspersky4Win/kdscrl.rdb.z | unknown | compressed | 5.85 Kb | unknown |
— | — | GET | 200 | 82.202.185.148:443 | https://ds.kaspersky.com/cfg/107/21.18.5.438.0.301.0 | unknown | binary | 29.9 Kb | unknown |
— | — | GET | 200 | 80.231.123.135:443 | https://dm.s.kaspersky-labs.com/kleaner/kavkis_21.18/global/index-kleaner-2.txt | unknown | text | 4.03 Kb | unknown |
— | — | GET | 200 | 109.248.196.5:443 | https://dm.s.kaspersky-labs.com/en/Kaspersky4Win/21.18.5.438/product.msi.z | unknown | compressed | 5.97 Mb | unknown |
— | — | GET | 200 | 80.231.123.135:443 | https://dm.s.kaspersky-labs.com/en/Kaspersky4Win/21.18.5.438/x64/index2.txt | unknown | text | 5.89 Kb | unknown |
— | — | GET | 200 | 109.248.196.5:443 | https://dm.s.kaspersky-labs.com/bases/kavkis2021mr18/kaspersky4win/index-bases-x64-2.txt | unknown | text | 4.62 Kb | unknown |
— | — | GET | 200 | 81.19.104.172:443 | https://ds.kaspersky.com/cfg/107/21.18.5.438.0.301.0 | unknown | binary | 29.9 Kb | unknown |
— | — | GET | 200 | 109.248.196.5:443 | https://dm.s.kaspersky-labs.com/en/Kaspersky4Win/21.18.5.438/x64/index2.txt | unknown | text | 5.89 Kb | unknown |
— | — | GET | 200 | 82.202.184.184:443 | https://ds.kaspersky.com/cfg/107/21.18.5.438.0.301.0 | unknown | binary | 29.9 Kb | unknown |
— | — | GET | 200 | 80.231.123.135:443 | https://dm.s.kaspersky-labs.com/bases/kavkis2021mr18/kaspersky4win/index-bases-x64-2.txt | unknown | text | 4.62 Kb | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 192.168.100.255:138 | — | — | — | whitelisted |
6160 | RUXIMICS.exe | 4.231.128.59:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
2120 | MoUsoCoreWorker.exe | 4.231.128.59:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
5796 | svchost.exe | 4.231.128.59:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
6196 | kaspersky4win202121.18.5.438aen_46538.exe | 62.67.238.151:443 | ds.kaspersky.com | LEVEL3 | GB | whitelisted |
2120 | MoUsoCoreWorker.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
5796 | svchost.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
3888 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
4324 | svchost.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
6196 | kaspersky4win202121.18.5.438aen_46538.exe | 46.8.206.115:443 | dm.s.kaspersky-labs.com | Solucions Valencianes i Noves Tecnologies SL | ES | suspicious |
Domain | IP | Reputation |
|---|---|---|
google.com |
| whitelisted |
ds.kaspersky.com |
| whitelisted |
settings-win.data.microsoft.com |
| whitelisted |
dm.s.kaspersky-labs.com |
| unknown |
Process | Message |
|---|---|
setup_ui.exe | setup_ui.exe Information: 0 : |
setup_ui.exe | LocalizationEngine Making localization parameters
|
setup_ui.exe | setup_ui.exe Information: 0 : |
setup_ui.exe | Core DisplayCulture = en-US
DisplayCulture.FullLocalization = en
FormatCulture = en-US
|
setup_ui.exe | setup_ui.exe Information: 0 : |
setup_ui.exe | Core OS: Major=10, Minor=0, Build=19045, Type=Workstation
|
setup_ui.exe | setup_ui.exe Information: 0 : |
setup_ui.exe | Core OS: Major=10, Minor=0, Build=19045, Type=Workstation
|
setup_ui.exe | setup_ui.exe Information: 0 : |
setup_ui.exe | TextScaleService IsEnabled is set to True.
|