analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
URL:

http://freefr.dl.sourceforge.net/project/windirstat/windirstat/1.1.2%20installer%20re-release%20(more%20languages!)/windirstat1_1_2_setup.exe

Full analysis: https://app.any.run/tasks/76feaea2-63a8-4368-b29f-69f32509d862
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: May 20, 2019, 10:17:33
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
loader
Indicators:
MD5:

1E0BD823241D0C3A54174B47687AD838

SHA1:

798D4E8B14E99FC41306DE17D22BB28BA2B998CB

SHA256:

C0591E7D80F03AC7F9397C31A383A79BB75941146EA953C8C9FFA88B8A738AFD

SSDEEP:

3:N1KYQmlJ+2SuLAuUtHHPFVDEgXAttXAcHXphkzQ/Gdo8iRu4A:CYrJRnCtHHNVYgXSXLHXph0dyRu4A

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Downloads executable files from the Internet

      • iexplore.exe (PID: 3488)
    • Application was dropped or rewritten from another process

      • windirstat1_1_2_setup.exe (PID: 2180)
      • windirstat1_1_2_setup.exe (PID: 3592)
      • windirstat.exe (PID: 3696)
    • Loads dropped or rewritten executable

      • windirstat1_1_2_setup.exe (PID: 3592)
    • Actions looks like stealing of personal data

      • windirstat.exe (PID: 3696)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • iexplore.exe (PID: 2968)
      • iexplore.exe (PID: 3488)
      • windirstat1_1_2_setup.exe (PID: 3592)
    • Creates files in the program directory

      • windirstat1_1_2_setup.exe (PID: 3592)
    • Creates a software uninstall entry

      • windirstat1_1_2_setup.exe (PID: 3592)
  • INFO

    • Changes internet zones settings

      • iexplore.exe (PID: 2968)
    • Application launched itself

      • iexplore.exe (PID: 2968)
    • Manual execution by user

      • windirstat1_1_2_setup.exe (PID: 2180)
      • windirstat1_1_2_setup.exe (PID: 3592)
    • Creates files in the user directory

      • iexplore.exe (PID: 3488)
    • Reads Internet Cache Settings

      • iexplore.exe (PID: 2968)
      • iexplore.exe (PID: 3488)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
43
Monitored processes
5
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start drop and start iexplore.exe iexplore.exe windirstat1_1_2_setup.exe no specs windirstat1_1_2_setup.exe windirstat.exe

Process information

PID
CMD
Path
Indicators
Parent process
2968"C:\Program Files\Internet Explorer\iexplore.exe" http://freefr.dl.sourceforge.net/project/windirstat/windirstat/1.1.2%20installer%20re-release%20(more%20languages!)/windirstat1_1_2_setup.exeC:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
1
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
3488"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2968 CREDAT:71937C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
2180"C:\Users\admin\Desktop\windirstat1_1_2_setup.exe" C:\Users\admin\Desktop\windirstat1_1_2_setup.exeexplorer.exe
User:
admin
Company:
WDS Team
Integrity Level:
MEDIUM
Description:
WinDirStat 1.1.2
Exit code:
3221226540
Version:
1.1.2
3592"C:\Users\admin\Desktop\windirstat1_1_2_setup.exe" C:\Users\admin\Desktop\windirstat1_1_2_setup.exe
explorer.exe
User:
admin
Company:
WDS Team
Integrity Level:
HIGH
Description:
WinDirStat 1.1.2
Exit code:
0
Version:
1.1.2
3696"C:\Program Files\WinDirStat\windirstat.exe"C:\Program Files\WinDirStat\windirstat.exe
windirstat1_1_2_setup.exe
User:
admin
Company:
Seifert
Integrity Level:
HIGH
Description:
Windows Directory Statistics
Version:
1.1.2.80 (Unicode)
Total events
1 428
Read events
1 285
Write events
0
Delete events
0

Modification events

No data
Executable files
6
Suspicious files
1
Text files
40
Unknown types
15

Dropped files

PID
Process
Filename
Type
2968iexplore.exeC:\Users\admin\AppData\Local\Temp\~DF6C6A7EF4FCAAA0BB.TMP
MD5:
SHA256:
2968iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\H6QNMHE9\favicon[1].ico
MD5:
SHA256:
2968iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.ico
MD5:
SHA256:
2968iexplore.exeC:\Users\admin\AppData\Local\Temp\~DFAC63786B357FE527.TMP
MD5:
SHA256:
2968iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{8417CF2B-7AE8-11E9-B3B3-5254004A04AF}.dat
MD5:
SHA256:
3488iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\History\Low\History.IE5\index.datdat
MD5:4379F79AE1E6B83A110B05D3E1B3E20F
SHA256:D5144925A41BD3FC3429C896A2CC13195CE3D5928B8C673BD4346D3B220147BD
3488iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\index.datdat
MD5:5FEE817E7CBE61A4BBB8BB3034CEA0D4
SHA256:D70A7708ED4BCEB1C3381F15FFAA84605F252E4D4872AAE679FBB1B1C497C169
3488iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UXBZKFLM\desktop.iniini
MD5:4A3DEB274BB5F0212C2419D3D8D08612
SHA256:2842973D15A14323E08598BE1DFB87E54BF88A76BE8C7BC94C56B079446EDF38
2968iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\{8417CF2C-7AE8-11E9-B3B3-5254004A04AF}.datbinary
MD5:BDB9945945E9A1F84272EEB345206240
SHA256:BAB5FC8BEAED3F8DDB757EAA30DA1A32265821A3FE7C60A012D5C1643A0A937B
2968iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012019052020190521\index.datdat
MD5:B8139B771536915B84479D9CFBE6B39D
SHA256:F00AB854446EE284B7DE35B3848AD9791328E258BCE05F532F04D2766B9D01BC
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
2
DNS requests
2
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3488
iexplore.exe
GET
200
88.191.250.136:80
http://freefr.dl.sourceforge.net/project/windirstat/windirstat/1.1.2%20installer%20re-release%20(more%20languages!)/windirstat1_1_2_setup.exe
FR
executable
630 Kb
suspicious
2968
iexplore.exe
GET
200
204.79.197.200:80
http://www.bing.com/favicon.ico
US
image
237 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2968
iexplore.exe
204.79.197.200:80
www.bing.com
Microsoft Corporation
US
whitelisted
3488
iexplore.exe
88.191.250.136:80
freefr.dl.sourceforge.net
Free SAS
FR
suspicious

DNS requests

Domain
IP
Reputation
freefr.dl.sourceforge.net
  • 88.191.250.136
suspicious
www.bing.com
  • 204.79.197.200
  • 13.107.21.200
whitelisted

Threats

PID
Process
Class
Message
3488
iexplore.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
No debug info