download:

/download/setup_free.exe

Full analysis: https://app.any.run/tasks/cc27db46-8042-4196-9331-7cd0b46fdeff
Verdict: Malicious activity
Analysis date: February 27, 2024, 12:04:00
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

EEDE7AB503AA94332AC687F34AFFD094

SHA1:

7AEEE770D314F1652E994EAEB5EAEC529F00A2A0

SHA256:

C0BB615B7EE2CA6D27F4026B7111B788C15A1839B8A05E0CF5A6A90A40CBE513

SSDEEP:

98304:LdzvjOWHjBdhlpHG4R2NQiXOJhlDiGoedudtBW43jv7OXcrnU6K867MGrsOOCTm4:5c8

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • setup_free.exe (PID: 3668)
      • setup_free.exe (PID: 2964)
      • setup_free.tmp (PID: 2752)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • setup_free.exe (PID: 3668)
      • setup_free.exe (PID: 2964)
      • setup_free.tmp (PID: 2752)
    • Process drops legitimate windows executable

      • setup_free.tmp (PID: 2752)
    • Reads the Windows owner or organization settings

      • setup_free.tmp (PID: 2752)
  • INFO

    • Checks supported languages

      • setup_free.exe (PID: 3668)
      • setup_free.tmp (PID: 3700)
      • setup_free.exe (PID: 2964)
      • setup_free.tmp (PID: 2752)
      • VBReFormer Free.exe (PID: 1040)
      • wmpnscfg.exe (PID: 2756)
    • Reads the computer name

      • setup_free.tmp (PID: 3700)
      • setup_free.tmp (PID: 2752)
      • VBReFormer Free.exe (PID: 1040)
      • wmpnscfg.exe (PID: 2756)
    • Create files in a temporary directory

      • setup_free.exe (PID: 3668)
      • setup_free.exe (PID: 2964)
      • setup_free.tmp (PID: 2752)
      • VBReFormer Free.exe (PID: 1040)
    • Creates files in the program directory

      • setup_free.tmp (PID: 2752)
    • Creates a software uninstall entry

      • setup_free.tmp (PID: 2752)
    • Reads Environment values

      • VBReFormer Free.exe (PID: 1040)
    • Reads the machine GUID from the registry

      • VBReFormer Free.exe (PID: 1040)
    • Creates files or folders in the user directory

      • VBReFormer Free.exe (PID: 1040)
    • Reads mouse settings

      • VBReFormer Free.exe (PID: 1040)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 2756)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable Delphi generic (45.2)
.dll | Win32 Dynamic Link Library (generic) (20.9)
.exe | Win32 Executable (generic) (14.3)
.exe | Win16/32 Executable Delphi generic (6.6)
.exe | Generic Win/DOS Executable (6.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2014:07:09 07:58:13+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 65024
InitializedDataSize: 71168
UninitializedDataSize: -
EntryPoint: 0x113bc
OSVersion: 5
ImageVersion: 6
SubsystemVersion: 5
Subsystem: Windows GUI
FileVersionNumber: 0.0.0.0
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: Decompiler-vb.net
FileDescription: VBReFormer 2015 Free Setup
FileVersion:
LegalCopyright: Copyright © Decompiler-VB.net - Sylvain Bruyere, Inc.
ProductName: VBReFormer 2015 Free
ProductVersion: 6.4.353
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
44
Monitored processes
6
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
start setup_free.exe setup_free.tmp no specs setup_free.exe setup_free.tmp vbreformer free.exe no specs wmpnscfg.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1040"C:\Program Files\VBReFormer\VBReFormer Free.exe"C:\Program Files\VBReFormer\VBReFormer Free.exesetup_free.tmp
User:
admin
Company:
Decompiler-VB.net
Integrity Level:
MEDIUM
Exit code:
0
Version:
6.04.0353
Modules
Images
c:\program files\vbreformer\vbreformer free.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\vbreformer\msvbvm60.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
2752"C:\Users\admin\AppData\Local\Temp\is-CRI66.tmp\setup_free.tmp" /SL5="$100130,3184566,137216,C:\Users\admin\AppData\Local\Temp\setup_free.exe" /SPAWNWND=$18013E /NOTIFYWND=$E0170 C:\Users\admin\AppData\Local\Temp\is-CRI66.tmp\setup_free.tmp
setup_free.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-cri66.tmp\setup_free.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2756"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2964"C:\Users\admin\AppData\Local\Temp\setup_free.exe" /SPAWNWND=$18013E /NOTIFYWND=$E0170 C:\Users\admin\AppData\Local\Temp\setup_free.exe
setup_free.tmp
User:
admin
Company:
Decompiler-vb.net
Integrity Level:
HIGH
Description:
VBReFormer 2015 Free Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\appdata\local\temp\setup_free.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
3668"C:\Users\admin\AppData\Local\Temp\setup_free.exe" C:\Users\admin\AppData\Local\Temp\setup_free.exe
explorer.exe
User:
admin
Company:
Decompiler-vb.net
Integrity Level:
MEDIUM
Description:
VBReFormer 2015 Free Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\appdata\local\temp\setup_free.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
3700"C:\Users\admin\AppData\Local\Temp\is-M2DDO.tmp\setup_free.tmp" /SL5="$E0170,3184566,137216,C:\Users\admin\AppData\Local\Temp\setup_free.exe" C:\Users\admin\AppData\Local\Temp\is-M2DDO.tmp\setup_free.tmpsetup_free.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-m2ddo.tmp\setup_free.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
Total events
10 461
Read events
10 351
Write events
100
Delete events
10

Modification events

(PID) Process:(2752) setup_free.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
C00A0000B45E50147569DA01
(PID) Process:(2752) setup_free.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:SessionHash
Value:
590B7ABCE09D879FC528184471170C89101077D2577C266D61C4D054D71FD4A9
(PID) Process:(2752) setup_free.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Sequence
Value:
1
(PID) Process:(2752) setup_free.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:RegFiles0000
Value:
C:\Program Files\VBReFormer\VBReFormer Free.exe
(PID) Process:(2752) setup_free.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:RegFilesHash
Value:
4D76FEA8FD352E75DD7129255906B276FC3800A0C18956774B9443AA70FD9F1F
(PID) Process:(2752) setup_free.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\VBReFormer 2015 Free_is1
Operation:writeName:Inno Setup: Setup Version
Value:
5.5.5 (u)
(PID) Process:(2752) setup_free.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\VBReFormer 2015 Free_is1
Operation:writeName:Inno Setup: App Path
Value:
C:\Program Files\VBReFormer
(PID) Process:(2752) setup_free.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\VBReFormer 2015 Free_is1
Operation:writeName:InstallLocation
Value:
C:\Program Files\VBReFormer\
(PID) Process:(2752) setup_free.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\VBReFormer 2015 Free_is1
Operation:writeName:Inno Setup: Icon Group
Value:
VBReFormer
(PID) Process:(2752) setup_free.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\VBReFormer 2015 Free_is1
Operation:writeName:Inno Setup: User
Value:
admin
Executable files
38
Suspicious files
4
Text files
10
Unknown types
1

Dropped files

PID
Process
Filename
Type
2752setup_free.tmpC:\Program Files\VBReFormer\VBReFormer Free.exeexecutable
MD5:372DBC6D33D00BDF48935CC1CE2247C1
SHA256:A34B9310691D9024C3E8A284F6115CF52B90659BB957CECC5C635BC8E8256B3F
2752setup_free.tmpC:\Program Files\VBReFormer\unins000.exeexecutable
MD5:7632B3482585291443E87D74688E8E7A
SHA256:62FC7A5E655476B3045856233D367C7731356E8C71652A278831FDC6A0916679
2752setup_free.tmpC:\Users\admin\AppData\Local\Temp\is-6DMKG.tmp\_isetup\_isdecmp.dllexecutable
MD5:3ADAA386B671C2DF3BAE5B39DC093008
SHA256:71CD2F5BC6E13B8349A7C98697C6D2E3FCDEEA92699CEDD591875BEA869FAE38
2964setup_free.exeC:\Users\admin\AppData\Local\Temp\is-CRI66.tmp\setup_free.tmpexecutable
MD5:DF9EE5D241496DABB2F303A959EC8D8A
SHA256:0BBD03CCEF315B865CE4AFFF98C057586B59A09CEFC3E13A058B9C48965349B6
3668setup_free.exeC:\Users\admin\AppData\Local\Temp\is-M2DDO.tmp\setup_free.tmpexecutable
MD5:DF9EE5D241496DABB2F303A959EC8D8A
SHA256:0BBD03CCEF315B865CE4AFFF98C057586B59A09CEFC3E13A058B9C48965349B6
2752setup_free.tmpC:\Users\admin\AppData\Local\Temp\is-6DMKG.tmp\_isetup\_shfoldr.dllexecutable
MD5:92DC6EF532FBB4A5C3201469A5B5EB63
SHA256:9884E9D1B4F8A873CCBD81F8AD0AE257776D2348D027D811A56475E028360D87
2752setup_free.tmpC:\Program Files\VBReFormer\is-KO8MS.tmpexecutable
MD5:7632B3482585291443E87D74688E8E7A
SHA256:62FC7A5E655476B3045856233D367C7731356E8C71652A278831FDC6A0916679
2752setup_free.tmpC:\Program Files\VBReFormer\Copyright.rtftext
MD5:9B66B703F32C053232673316F06E4B74
SHA256:1CB54303C3A8CE8F40DC536B6520EA783999DB1070F5D8A789248BFFC6DC46AB
2752setup_free.tmpC:\Program Files\VBReFormer\is-03QBI.tmptext
MD5:D5E57099BBE37D8365ABCFD4CD98CD8C
SHA256:A15A500B6F490629BC81ABA508F956249E9F9AC01AD7D876EA02217BEFDD46A1
2752setup_free.tmpC:\Program Files\VBReFormer\is-UT1OQ.tmptext
MD5:9B66B703F32C053232673316F06E4B74
SHA256:1CB54303C3A8CE8F40DC536B6520EA783999DB1070F5D8A789248BFFC6DC46AB
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
unknown
4
System
192.168.100.255:138
unknown
1080
svchost.exe
224.0.0.252:5355
unknown

DNS requests

No data

Threats

No threats detected
No debug info