File name:

xvirus-setup.exe

Full analysis: https://app.any.run/tasks/31b04fcf-16b8-41ec-b07e-0d487740d6bc
Verdict: Malicious activity
Analysis date: October 13, 2019, 23:33:14
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
installer
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
MD5:

EE826A11EEC5F15201AA12168AB8F6B1

SHA1:

DE92D7E6C70439E283801A592FF200EAE0CA781F

SHA256:

C0E2E1E4D71C468132BAB2CB332F3BF7B16AAA2A032E47CA88065E05FF7E2724

SSDEEP:

24576:opoqmGUNhs+VxEB8dwyGrI2SsMOaCNBOU6J0RyVHihL:19GUyBk2SsMO9B5l

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • Xvirus Anti-Malware.exe (PID: 2356)
    • Application was dropped or rewritten from another process

      • Xvirus Anti-Malware.exe (PID: 2356)
    • Uses Task Scheduler to run other applications

      • Xvirus Anti-Malware.exe (PID: 2356)
    • Loads the Task Scheduler COM API

      • SchTasks.exe (PID: 3856)
  • SUSPICIOUS

    • Creates a software uninstall entry

      • xvirus-setup.exe (PID: 2916)
    • Creates files in the program directory

      • xvirus-setup.exe (PID: 2916)
      • Xvirus Anti-Malware.exe (PID: 2356)
    • Executable content was dropped or overwritten

      • xvirus-setup.exe (PID: 2916)
    • Creates files in the user directory

      • xvirus-setup.exe (PID: 2916)
  • INFO

    • Dropped object may contain Bitcoin addresses

      • xvirus-setup.exe (PID: 2916)
      • Xvirus Anti-Malware.exe (PID: 2356)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic CIL Executable (.NET, Mono, etc.) (35.6)
.exe | InstallShield setup (20.9)
.exe | Win32 Executable MS Visual C++ (generic) (15.1)
.exe | Win64 Executable (generic) (13.4)
.scr | Windows screen saver (6.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2017:06:04 17:32:30+02:00
PEType: PE32
LinkerVersion: 11
CodeSize: 2946560
InitializedDataSize: 37376
UninitializedDataSize: -
EntryPoint: 0x2d13fe
OSVersion: 4
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 7.0.5.0
ProductVersionNumber: 7.0.5.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: Xvirus Installer
CompanyName: Xvirus
FileDescription: Xvirus Anti-Malware Installer
FileVersion: 7.0.5.0
InternalName: Xvirus Installer.exe
LegalCopyright: Copyright © Xvirus 2017
LegalTrademarks: Xvirus
OriginalFileName: Xvirus Installer.exe
ProductName: Xvirus Installer
ProductVersion: 7.0.5.0
AssemblyVersion: 7.0.5.0

Summary

Architecture: IMAGE_FILE_MACHINE_I386
Subsystem: IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date: 04-Jun-2017 15:32:30
Comments: Xvirus Installer
CompanyName: Xvirus
FileDescription: Xvirus Anti-Malware Installer
FileVersion: 7.0.5.0
InternalName: Xvirus Installer.exe
LegalCopyright: Copyright © Xvirus 2017
LegalTrademarks: Xvirus
OriginalFilename: Xvirus Installer.exe
ProductName: Xvirus Installer
ProductVersion: 7.0.5.0
Assembly Version: 7.0.5.0

DOS Header

Magic number: MZ
Bytes on last page of file: 0x0090
Pages in file: 0x0003
Relocations: 0x0000
Size of header: 0x0004
Min extra paragraphs: 0x0000
Max extra paragraphs: 0xFFFF
Initial SS value: 0x0000
Initial SP value: 0x00B8
Checksum: 0x0000
Initial IP value: 0x0000
Initial CS value: 0x0000
Overlay number: 0x0000
OEM identifier: 0x0000
OEM information: 0x0000
Address of NE header: 0x00000080

PE Headers

Signature: PE
Machine: IMAGE_FILE_MACHINE_I386
Number of sections: 4
Time date stamp: 04-Jun-2017 15:32:30
Pointer to Symbol Table: 0x00000000
Number of symbols: 0
Size of Optional Header: 0x00E0
Characteristics:
  • IMAGE_FILE_32BIT_MACHINE
  • IMAGE_FILE_EXECUTABLE_IMAGE

Sections

Name
Virtual Address
Virtual Size
Raw Size
Charateristics
Entropy
.text
0x00002000
0x002CF404
0x002CF600
IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
5.66269
.sdata
0x002D2000
0x00000138
0x00000200
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
0.673107
.rsrc
0x002D4000
0x00008DC8
0x00008E00
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
3.08004
.reloc
0x002DE000
0x0000000C
0x00000200
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
0.0815394

Resources

Title
Entropy
Size
Codepage
Language
Type
1
5.04075
2861
UNKNOWN
UNKNOWN
RT_MANIFEST
2
2.78667
1128
UNKNOWN
UNKNOWN
RT_ICON
3
2.35678
4264
UNKNOWN
UNKNOWN
RT_ICON
4
2.54287
9640
UNKNOWN
UNKNOWN
RT_ICON
5
2.08832
16936
UNKNOWN
UNKNOWN
RT_ICON
32512
2.68598
62
UNKNOWN
UNKNOWN
RT_GROUP_ICON

Imports

mscoree.dll
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
43
Monitored processes
4
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
drop and start start xvirus-setup.exe xvirus anti-malware.exe schtasks.exe no specs xvirus-setup.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
940"C:\Users\admin\AppData\Local\Temp\xvirus-setup.exe" C:\Users\admin\AppData\Local\Temp\xvirus-setup.exeexplorer.exe
User:
admin
Company:
Xvirus
Integrity Level:
MEDIUM
Description:
Xvirus Anti-Malware Installer
Exit code:
3221226540
Version:
7.0.5.0
Modules
Images
c:\users\admin\appdata\local\temp\xvirus-setup.exe
c:\systemroot\system32\ntdll.dll
2356"C:\Program Files\Xvirus Anti-Malware\Xvirus Anti-Malware.exe" C:\Program Files\Xvirus Anti-Malware\Xvirus Anti-Malware.exe
xvirus-setup.exe
User:
admin
Company:
Xvirus
Integrity Level:
HIGH
Description:
Xvirus Anti-Malware
Exit code:
0
Version:
7.0.5.0
Modules
Images
c:\program files\xvirus anti-malware\xvirus anti-malware.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2916"C:\Users\admin\AppData\Local\Temp\xvirus-setup.exe" C:\Users\admin\AppData\Local\Temp\xvirus-setup.exe
explorer.exe
User:
admin
Company:
Xvirus
Integrity Level:
HIGH
Description:
Xvirus Anti-Malware Installer
Exit code:
0
Version:
7.0.5.0
Modules
Images
c:\users\admin\appdata\local\temp\xvirus-setup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3856SchTasks /Create /F /XML "C:\xvirus\startup.xml" /TN "Xvirus startup"C:\Windows\system32\SchTasks.exeXvirus Anti-Malware.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Manages scheduled tasks
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\schtasks.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
Total events
288
Read events
244
Write events
44
Delete events
0

Modification events

(PID) Process:(2916) xvirus-setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Xvirus Anti-Malware
Operation:writeName:Contact
Value:
support@xvirus.net
(PID) Process:(2916) xvirus-setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Xvirus Anti-Malware
Operation:writeName:DisplayIcon
Value:
C:\Program Files\Xvirus Anti-Malware\Unin.exe,0
(PID) Process:(2916) xvirus-setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Xvirus Anti-Malware
Operation:writeName:DisplayName
Value:
Xvirus Anti-Malware
(PID) Process:(2916) xvirus-setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Xvirus Anti-Malware
Operation:writeName:DisplayVersion
Value:
7.0.5.0
(PID) Process:(2916) xvirus-setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Xvirus Anti-Malware
Operation:writeName:HelpLink
Value:
http://www.xvirus.net
(PID) Process:(2916) xvirus-setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Xvirus Anti-Malware
Operation:writeName:Publisher
Value:
Xvirus
(PID) Process:(2916) xvirus-setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Xvirus Anti-Malware
Operation:writeName:URLInfoAbout
Value:
http://www.xvirus.net
(PID) Process:(2916) xvirus-setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Xvirus Anti-Malware
Operation:writeName:UninstallString
Value:
C:\Program Files\Xvirus Anti-Malware\Unin.exe
(PID) Process:(2916) xvirus-setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(2916) xvirus-setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
Executable files
8
Suspicious files
1
Text files
59
Unknown types
2

Dropped files

PID
Process
Filename
Type
2916xvirus-setup.exeC:\Program Files\Xvirus Anti-Malware\database\whitelist.xdbtext
MD5:F45A7438E0546268FD78FC24766635D2
SHA256:FEBC534E8E9EBC8F0522354C4CA059562E0627D251AB47093B8BAFB4EE3857A7
2916xvirus-setup.exeC:\Program Files\Xvirus Anti-Malware\shellfolder.exeexecutable
MD5:EE7B8FC1EBD5EB794FB034DC5E6B41B0
SHA256:840C63C719009A7E5F19903B1416555E0F698345840948E7023BADC691BE67F2
2916xvirus-setup.exeC:\Program Files\Xvirus Anti-Malware\VoodooAi.dllexecutable
MD5:932245B4C89AFFE71E684A859DE72587
SHA256:B2F25716AAA37FA7454A0CDA7DD73BE80C1EEC179D94DC8CC0EE50AA56D41D58
2916xvirus-setup.exeC:\Program Files\Xvirus Anti-Malware\shellfile.exeexecutable
MD5:D291CD2D33AD06E8A85C8539DC8BF08B
SHA256:0E520551C75B61FC9B25CEB55B81D78D3A0A906491FE1A2EE8CE1B8B877D755D
2916xvirus-setup.exeC:\Program Files\Xvirus Anti-Malware\Features.dllexecutable
MD5:AC02D28A8E9BA8376758C0C8B87819B9
SHA256:08730788D074BAD92E1795BF78E3023F67C398387C208D111EF3F273DB81F86E
2916xvirus-setup.exeC:\Program Files\Xvirus Anti-Malware\database\heurlist.xdbtext
MD5:88D18CDDB23FC5C1B8E94D835D5D1D2D
SHA256:43C3445121F08B3EE06A70E52553E69DA6A6B75C358C5A063BB5C4BDBB07D572
2916xvirus-setup.exeC:\Program Files\Xvirus Anti-Malware\language\Estonian (Eesti).lngtext
MD5:FF5807B4FF9415DEB120AE8C146B25BB
SHA256:08B43342C17013B28F0EB760CB6887D5474E5F54B5FA8A47CEDF7AF9ED296714
2916xvirus-setup.exeC:\Program Files\Xvirus Anti-Malware\language\Serbian (srpski).lngtext
MD5:572ECB06D2FA9E02AF6637A8422A767B
SHA256:C0CA63DFF9A46A5EA7FB184712218B580D9E85479C1C7A0C58009A93B635DDBF
2916xvirus-setup.exeC:\Program Files\Xvirus Anti-Malware\xvirusstart.exeexecutable
MD5:3BD1D71482C05A466AD251F2A51E1734
SHA256:2907720A31FAF7BACFC571E60A39B32D52609C81800675CB9FEC9DD5BF56FBDE
2916xvirus-setup.exeC:\Program Files\Xvirus Anti-Malware\language\English.lngtext
MD5:3EF9A2A2E60D9FBAD35241583D7D4DD6
SHA256:AD4B906D63AA0F37063DFA77322549E2229B1C0AB01E71DAE152417DBA16C46F
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
16
TCP/UDP connections
3
DNS requests
2
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2356
Xvirus Anti-Malware.exe
GET
193.70.91.28:80
http://cloud.xvirus.net/database/heurlist.txt
FR
suspicious
2356
Xvirus Anti-Malware.exe
GET
193.70.91.28:80
http://cloud.xvirus.net/database/whitelist.txt
FR
suspicious
2356
Xvirus Anti-Malware.exe
GET
193.70.91.28:80
http://cloud.xvirus.net/database/reglist.txt
FR
suspicious
2356
Xvirus Anti-Malware.exe
GET
200
193.70.91.28:80
http://xvirus.net/download/amv.txt
FR
text
7 b
suspicious
2356
Xvirus Anti-Malware.exe
GET
200
193.70.91.28:80
http://cloud.xvirus.net/database/dailylist.txt
FR
text
158 Kb
suspicious
2356
Xvirus Anti-Malware.exe
GET
200
193.70.91.28:80
http://cloud.xvirus.net/database/heurdb2.txt
FR
text
2 b
suspicious
2356
Xvirus Anti-Malware.exe
GET
200
193.70.91.28:80
http://cloud.xvirus.net/database/heurdb.txt
FR
text
3 b
suspicious
2356
Xvirus Anti-Malware.exe
GET
200
193.70.91.28:80
http://cloud.xvirus.net/database/vendornumber.txt
FR
text
2 b
suspicious
2356
Xvirus Anti-Malware.exe
GET
200
193.70.91.28:80
http://cloud.xvirus.net/database/dailydb.txt
FR
text
4 b
suspicious
2356
Xvirus Anti-Malware.exe
GET
200
193.70.91.28:80
http://cloud.xvirus.net/database/dailywv.txt
FR
text
2 b
suspicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2356
Xvirus Anti-Malware.exe
193.70.91.28:80
xvirus.net
OVH SAS
FR
suspicious

DNS requests

Domain
IP
Reputation
xvirus.net
  • 193.70.91.28
suspicious
cloud.xvirus.net
  • 193.70.91.28
suspicious

Threats

No threats detected
No debug info