download:

cspsetup-4.0.exe

Full analysis: https://app.any.run/tasks/8f58dc54-1ac7-4d1d-a410-af87baba882f
Verdict: Malicious activity
Analysis date: June 21, 2018, 11:12:19
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

ACD3D02ABD62414A9BAEFFFB407772C1

SHA1:

0669295401A1355C2A56D3437920DCA1793773F5

SHA256:

B4AAFA77770800C97ED69F08833C6CEBD3DE1A4DD2B1B3251B0933306AA204FE

SSDEEP:

98304:pzWDO2NzAaqcckfR01gMq2NHXCUWsHoQ3rkrQaDpvqw:pa9NcazJWgMqcCwHasKpvJ

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes settings of System certificates

      • msiexec.exe (PID: 3988)
    • Loads dropped or rewritten executable

      • msiexec.exe (PID: 2200)
      • lsass.exe (PID: 500)
      • setuptest.exe (PID: 2272)
    • Application was dropped or rewritten from another process

      • Setup.exe (PID: 3704)
      • setuptest.exe (PID: 2272)
  • SUSPICIOUS

    • Starts Microsoft Installer

      • Setup.exe (PID: 3704)
    • Creates COM task schedule object

      • msiexec.exe (PID: 3988)
    • Creates files in the Windows directory

      • msiexec.exe (PID: 3988)
      • MsiExec.exe (PID: 2744)
      • DrvInst.exe (PID: 2652)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 3988)
      • MsiExec.exe (PID: 2744)
      • cspsetup-4.0.exe (PID: 980)
      • DrvInst.exe (PID: 2652)
    • Removes files from Windows directory

      • DrvInst.exe (PID: 2652)
      • MsiExec.exe (PID: 2744)
    • Creates files in the driver directory

      • DrvInst.exe (PID: 2652)
      • MsiExec.exe (PID: 2744)
    • Creates or modifies windows services

      • DrvInst.exe (PID: 2652)
  • INFO

    • Creates a software uninstall entry

      • MsiExec.exe (PID: 2744)
      • msiexec.exe (PID: 3988)
    • Creates files in the program directory

      • MsiExec.exe (PID: 2744)
      • msiexec.exe (PID: 3988)
    • Application launched itself

      • msiexec.exe (PID: 3988)
    • Loads dropped or rewritten executable

      • MsiExec.exe (PID: 2744)
      • MsiExec.exe (PID: 1972)
    • Creates or modifies windows services

      • msiexec.exe (PID: 3988)
      • MsiExec.exe (PID: 2744)
      • vssvc.exe (PID: 3852)
    • Dropped object may contain URL's

      • MsiExec.exe (PID: 2744)
      • DrvInst.exe (PID: 2652)
      • msiexec.exe (PID: 3988)
      • cspsetup-4.0.exe (PID: 980)
    • Low-level read access rights to disk partition

      • vssvc.exe (PID: 3852)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic Win/DOS Executable (50)
.exe | DOS Executable Generic (49.9)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2014:04:10 11:32:18+02:00
PEType: PE32
LinkerVersion: 9
CodeSize: 76288
InitializedDataSize: 48128
UninitializedDataSize: -
EntryPoint: 0x12e1a
OSVersion: 5
ImageVersion: -
SubsystemVersion: 5
Subsystem: Windows GUI
FileVersionNumber: 4.0.9330.0
ProductVersionNumber: 4.0.9330.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Russian
CharacterSet: Unicode
CompanyName: Компания КРИПТО-ПРО
FileDescription: Приложение установки КриптоПро CSP
FileVersion: 4.0.9330.0
InternalName: CSPSetup
LegalCopyright: © Компания КРИПТО-ПРО. Все права защищены.
OriginalFileName: CSPSetup.exe
ProductName: КриптоПро CSP
ProductVersion: 4.0.9330.0
Tag040904B0: -

Summary

Architecture: IMAGE_FILE_MACHINE_I386
Subsystem: IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date: 10-Apr-2014 09:32:18
Detected languages:
  • English - United States
  • Russian - Russia
CompanyName: Компания КРИПТО-ПРО
FileDescription: Приложение установки КриптоПро CSP
FileVersion: 4.0.9330.0
InternalName: CSPSetup
LegalCopyright: © Компания КРИПТО-ПРО. Все права защищены.
OriginalFilename: CSPSetup.exe
ProductName: КриптоПро CSP
ProductVersion: 4.0.9330.0

DOS Header

Magic number: MZ
Bytes on last page of file: 0x0060
Pages in file: 0x0001
Relocations: 0x0000
Size of header: 0x0004
Min extra paragraphs: 0x0000
Max extra paragraphs: 0xFFFF
Initial SS value: 0x0000
Initial SP value: 0x00B8
Checksum: 0x0000
Initial IP value: 0x0000
Initial CS value: 0x0000
Overlay number: 0x0000
OEM identifier: 0x0000
OEM information: 0x0000
Address of NE header: 0x000000C8

PE Headers

Signature: PE
Machine: IMAGE_FILE_MACHINE_I386
Number of sections: 4
Time date stamp: 10-Apr-2014 09:32:18
Pointer to Symbol Table: 0x00000000
Number of symbols: 0
Size of Optional Header: 0x00E0
Characteristics:
  • IMAGE_FILE_32BIT_MACHINE
  • IMAGE_FILE_EXECUTABLE_IMAGE
  • IMAGE_FILE_RELOCS_STRIPPED

Sections

Name
Virtual Address
Virtual Size
Raw Size
Charateristics
Entropy
.text
0x00001000
0x00012832
0x00012A00
IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
6.56852
.rdata
0x00014000
0x000036A8
0x00003800
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
5.47354
.data
0x00018000
0x00002F60
0x00000A00
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
5.19473
.rsrc
0x0001B000
0x000079C8
0x00007A00
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
5.93158

Resources

Title
Entropy
Size
Codepage
Language
Type
1
5.23253
957
Latin 1 / Western European
English - United States
RT_MANIFEST
2
6.06246
2216
Latin 1 / Western European
English - United States
RT_ICON
3
6.13648
1736
Latin 1 / Western European
English - United States
RT_ICON
4
5.70051
1384
Latin 1 / Western European
English - United States
RT_ICON
5
5.67496
9640
Latin 1 / Western European
English - United States
RT_ICON
6
5.88598
4264
Latin 1 / Western European
English - United States
RT_ICON
7
6.01816
2440
Latin 1 / Western European
English - United States
RT_ICON
8
5.20072
1128
Latin 1 / Western European
English - United States
RT_ICON
101
2.85812
118
Latin 1 / Western European
English - United States
RT_GROUP_ICON

Imports

ADVAPI32.dll
COMCTL32.dll
GDI32.dll
KERNEL32.dll
OLEAUT32.dll
SHELL32.dll
USER32.dll
msvcrt.dll
ole32.dll
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
47
Monitored processes
12
Malicious processes
4
Suspicious processes
1

Behavior graph

Click at the process to see the details
drop and start start cspsetup-4.0.exe setup.exe no specs msiexec.exe no specs msiexec.exe msiexec.exe no specs msiexec.exe msiexec.exe lsass.exe drvinst.exe vssvc.exe no specs setuptest.exe no specs cspsetup-4.0.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
500C:\Windows\system32\lsass.exeC:\Windows\System32\lsass.exe
wininit.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Local Security Authority Process
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\lsass.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sspisrv.dll
c:\windows\system32\lsasrv.dll
c:\windows\system32\sechost.dll
c:\windows\system32\sspicli.dll
584"C:\Users\admin\AppData\Local\Temp\cspsetup-4.0.exe" C:\Users\admin\AppData\Local\Temp\cspsetup-4.0.exeexplorer.exe
User:
admin
Company:
Crypto-Pro LLC
Integrity Level:
MEDIUM
Description:
Crypto-Pro CSP Setup Application
Exit code:
3221226540
Version:
4.0.9330.0
Modules
Images
c:\users\admin\appdata\local\temp\cspsetup-4.0.exe
c:\systemroot\system32\ntdll.dll
980"C:\Users\admin\AppData\Local\Temp\cspsetup-4.0.exe" C:\Users\admin\AppData\Local\Temp\cspsetup-4.0.exe
explorer.exe
User:
admin
Company:
Crypto-Pro LLC
Integrity Level:
HIGH
Description:
Crypto-Pro CSP Setup Application
Exit code:
0
Version:
4.0.9330.0
Modules
Images
c:\users\admin\appdata\local\temp\cspsetup-4.0.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1204msiexec /i "C:\Users\admin\AppData\Local\Temp\CryptoPro_CSP_4.0.9330\csp-win32-kc1-eng.msi" /qb REBOOT=RC:\Windows\system32\msiexec.exeSetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1972C:\Windows\system32\MsiExec.exe -Embedding E14EBEF4E95446383C53D40303C024DFC:\Windows\system32\MsiExec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2200"C:\Windows\system32\msiexec.exe" /y "C:\Windows\system32\cpcng.dll"C:\Windows\system32\msiexec.exe
msiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2272"C:\Program Files\Crypto Pro\CSP\setuptest.exe" cpcspi.dllC:\Program Files\Crypto Pro\CSP\setuptest.exeMsiExec.exe
User:
admin
Company:
Crypto-Pro LLC
Integrity Level:
HIGH
Description:
CSP Driver functionality test
Exit code:
0
Version:
4.0.4556.0
Modules
Images
c:\program files\crypto pro\csp\setuptest.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\common files\crypto pro\appcompat\cpcrypt.dll
c:\windows\system32\psapi.dll
c:\windows\system32\rpcrt4.dll
2652DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{60c0cc4c-8135-7d89-98a3-0649d9b77b4e}\CProCtrl.inf" "0" "6aa369873" "000003CC" "WinSta0\Default" "000003EC" "208" "C:\Program Files\Common Files\Crypto Pro\AppCompat"C:\Windows\system32\DrvInst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\drvinst.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
2744C:\Windows\system32\MsiExec.exe -Embedding A79724498CD70EA44F8581DE5600DF86 M Global\MSI0000C:\Windows\system32\MsiExec.exe
msiexec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3704"C:\Users\admin\AppData\Local\Temp\CryptoPro_CSP_4.0.9330\Setup.exe" C:\Users\admin\AppData\Local\Temp\CryptoPro_CSP_4.0.9330\Setup.execspsetup-4.0.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\cryptopro_csp_4.0.9330\setup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msi.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
Total events
2 287
Read events
828
Write events
1 445
Delete events
14

Modification events

(PID) Process:(980) cspsetup-4.0.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(980) cspsetup-4.0.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
(PID) Process:(3988) msiexec.exeKey:HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000_CLASSES\Local Settings\MuiCache\93\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3988) msiexec.exeKey:HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
940F000025AAE2C95009D401
(PID) Process:(3988) msiexec.exeKey:HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\RestartManager\Session0000
Operation:writeName:SessionHash
Value:
1C903D89D38CE7D8015A00A91BB5178B0967CE89DAA3305BC46232D09A67EF84
(PID) Process:(3988) msiexec.exeKey:HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Sequence
Value:
1
(PID) Process:(1972) MsiExec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C8B655BB-28A0-4BB6-BDE1-D0826457B2DF}\InprocServer32
Operation:writeName:InprocServer32
Value:
000000CBB12338Y1UUANEXKYXDGQZ7P8QWH21XW904P1712HZFXGAU2QK8W8GNP31
(PID) Process:(3988) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\InProgress
Operation:writeName:
Value:
C:\Windows\Installer\1ab7f9.ipi
(PID) Process:(3988) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Operation:writeName:C:\Config.Msi\
Value:
(PID) Process:(3988) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
Operation:writeName:C:\Config.Msi\1ab7fa.rbs
Value:
30673241
Executable files
212
Suspicious files
20
Text files
58
Unknown types
27

Dropped files

PID
Process
Filename
Type
980cspsetup-4.0.exeC:\Users\admin\AppData\Local\Temp\CryptoPro_CSP_4.0.9330\csp-x64-kc1-eng.msiexecutable
MD5:F313387714D93A68B7BAA39F6D76C325
SHA256:05EBD743CFD47A6BB930429C29B101139815FDF4C4B15E18185FE8268739902E
980cspsetup-4.0.exeC:\Users\admin\AppData\Local\Temp\CryptoPro_CSP_4.0.9330\csp-win32-kc2-rus.msiexecutable
MD5:24EC75D38CC439D5A6F690A70D392D17
SHA256:DE982B44F6380A2EDBA9F64AB805A0A8DE49CBD46EF2C01968B9C8DE1FA68103
980cspsetup-4.0.exeC:\Users\admin\AppData\Local\Temp\CryptoPro_CSP_4.0.9330\csp-win32-kc3-eng.msiexecutable
MD5:22377EAE1E431670AE6CFDD67D518235
SHA256:5DD4B70B6EB440B6543033AED72746839E61C8DFBFF99759075CF649484A466F
980cspsetup-4.0.exeC:\Users\admin\AppData\Local\Temp\CryptoPro_CSP_4.0.9330\csp-win32-kc3-rus.msiexecutable
MD5:9B16E1052BEE1EA9FE35C0D85A83C457
SHA256:6948E443BD6341EEE6155233FA372CDE86B4D19078710BFB0054748CF7D40C11
980cspsetup-4.0.exeC:\Users\admin\AppData\Local\Temp\CryptoPro_CSP_4.0.9330\csp-x64-kc1-rus.msiexecutable
MD5:CA5961C3A1C0BC58BFD466E67903162A
SHA256:86916E9A073E8034D5473B9CC19BE46E5BE3E7DCA4835FA759A067FC3C3CC052
980cspsetup-4.0.exeC:\Users\admin\AppData\Local\Temp\CryptoPro_CSP_4.0.9330\csp-win32-kc1so-eng.msiexecutable
MD5:9127D1C44AC672C8C4A9E4671BEB3EC6
SHA256:884295307B57605DC3DE1BA41884BD823682F386278A58BD6ACE7D97A4C9E2C3
980cspsetup-4.0.exeC:\Users\admin\AppData\Local\Temp\CryptoPro_CSP_4.0.9330\csp-win32-kc1so-rus.msiexecutable
MD5:E9C3B7C887C340A56886F211BE7A0430
SHA256:A0A950CF859C49A62536A90AC7AF64E3CA9C9C605F4781C8D2EA52CA55E3EA7D
980cspsetup-4.0.exeC:\Users\admin\AppData\Local\Temp\CryptoPro_CSP_4.0.9330\csp-win32-kc1-eng.msiexecutable
MD5:762FD31D171AC7F2C23181FBB1DBA575
SHA256:D02AFB0B2CCFF9916D0019C3F9EA0A1C4D206E5E50C57AF67255A276BE1A620F
980cspsetup-4.0.exeC:\Users\admin\AppData\Local\Temp\CryptoPro_CSP_4.0.9330\csp-win32-kc1-rus.msiexecutable
MD5:B9CAF1BCF2C0E7A2D0062287DBC98441
SHA256:CBD07203818DA0EF0C0B7701883891618A53046EB4DCF35E93FCA900E85119AE
980cspsetup-4.0.exeC:\Users\admin\AppData\Local\Temp\CryptoPro_CSP_4.0.9330\csp-x64-kc3-rus.msiexecutable
MD5:B75C5B1604112163E65B014C03E9864D
SHA256:06492C95012DDD420977952C77878B09753CDDCE488C046B783B4EAF63554A5B
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
Process
Message
msiexec.exe
cpcng: Thread: file:line function text xcode(dcode) level: 0
lsass.exe
cpcng: Thread: file:line function text xcode(dcode) level: 0
MsiExec.exe
cpcspi: Thread: file:line function text xcode(dcode) level: 0
MsiExec.exe
function text level: 0
MsiExec.exe
cpui: Thread: file:line function text xcode(dcode) level: 0
lsass.exe
cpsspap: Thread: file:line function text xcode(dcode) level: 0