File name:

Setup-3.2.exe

Full analysis: https://app.any.run/tasks/d7e7490b-353a-47a1-a1cb-c20f7ac855ea
Verdict: Malicious activity
Analysis date: December 07, 2024, 05:01:41
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 4 sections
MD5:

466B07082D6F413AEF4F0FE1E9915A36

SHA1:

468C55A07803C3426CCA837B63C2E40D3AFA7AEC

SHA256:

C3E32AF98959E1CB8A8D91861F4C7A88DCF2A21B3F7035276F8FA2DBC6809130

SSDEEP:

98304:Oj/Rm+jxnMDrz+dikKP3ZkII2VVbVgknk2O8wB9QRPVT/yruevCk1MSGJJBrttwE:if6llTwZGeAd

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • Setup-3.2.exe (PID: 6696)
    • Executes as Windows Service

      • VSSVC.exe (PID: 6244)
    • Application launched itself

      • Setup-3.2.exe (PID: 6676)
      • issch.exe (PID: 3664)
    • Creates/Modifies COM task schedule object

      • Setup-3.2.exe (PID: 6696)
    • Searches for installed software

      • dllhost.exe (PID: 7164)
    • Starts CMD.EXE for commands execution

      • Setup-3.2.exe (PID: 6696)
    • Uses REG/REGEDIT.EXE to modify registry

      • cmd.exe (PID: 6804)
    • Drops a system driver (possible attempt to evade defenses)

      • Setup-3.2.exe (PID: 6696)
  • INFO

    • Creates files in the program directory

      • Setup-3.2.exe (PID: 6696)
    • Create files in a temporary directory

      • Setup-3.2.exe (PID: 6696)
    • Checks supported languages

      • Setup-3.2.exe (PID: 6676)
      • Setup-3.2.exe (PID: 6696)
    • Reads the machine GUID from the registry

      • Setup-3.2.exe (PID: 6696)
    • Reads the computer name

      • Setup-3.2.exe (PID: 6696)
    • Manages system restore points

      • SrTasks.exe (PID: 6812)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (35.8)
.exe | Win64 Executable (generic) (31.7)
.scr | Windows screen saver (15)
.dll | Win32 Dynamic Link Library (generic) (7.5)
.exe | Win32 Executable (generic) (5.1)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2004:04:19 04:44:28+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 66048
InitializedDataSize: 47616
UninitializedDataSize: -
EntryPoint: 0xc7f8
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 10.0.0.159
ProductVersionNumber: 10.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: InstallShield Software Corporation
FileDescription: Setup.exe
FileVersion: 10.0.159
InternalName: Setup
OriginalFileName: Setup.exe
LegalCopyright: Copyright (C) 2004 InstallShield Software Corp.
ProductName: InstallShield (R)
ProductVersion: 10
OLESelfRegister: -
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
147
Monitored processes
17
Malicious processes
2
Suspicious processes
1

Behavior graph

Click at the process to see the details
start setup-3.2.exe setup-3.2.exe SPPSurrogate no specs vssvc.exe no specs srtasks.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs reg.exe no specs agent.exe no specs agent.exe no specs isuspm.exe no specs agent.exe no specs issch.exe no specs issch.exe no specs SPPSurrogate no specs setup-3.2.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
236C:\WINDOWS\system32\DllHost.exe /Processid:{F32D97DF-E3E5-4CB9-9E3E-0EB5B4E49801}C:\Windows\System32\dllhost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
COM Surrogate
Exit code:
1073807364
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\dllhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\msvcrt.dll
2076REG ADD HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System /v EnableLUA /t REG_DWORD /d 0 /fC:\Windows\SysWOW64\reg.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Registry Console Tool
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\reg.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
2212"C:\Program Files (x86)\Common Files\InstallShield\UpdateService\agent.exe" /l{37365259-9D37-4FBE-9204-08B4034623B6} /1033C:\Program Files (x86)\Common Files\InstallShield\UpdateService\agent.exeSetup-3.2.exe
User:
admin
Company:
InstallShield Software Corporation
Integrity Level:
HIGH
Description:
InstallShield Update Service Agent
Exit code:
0
Version:
3, 00, 100, 1165
Modules
Images
c:\program files (x86)\common files\installshield\updateservice\agent.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acspecfc.dll
3416"C:\Program Files (x86)\Common Files\InstallShield\UpdateService\agent.exe" /ssi{37365259-9D37-4FBE-9204-08B4034623B6},30:CEDBD7DF79AC27FF2EAC809FDE9C978FB9FBF78F49EBA788CE1B5788DE8BA7589E2C575FF9ACC:\Program Files (x86)\Common Files\InstallShield\UpdateService\agent.exeSetup-3.2.exe
User:
admin
Company:
InstallShield Software Corporation
Integrity Level:
HIGH
Description:
InstallShield Update Service Agent
Exit code:
0
Version:
3, 00, 100, 1165
Modules
Images
c:\program files (x86)\common files\installshield\updateservice\agent.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acspecfc.dll
3664"C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe" -set "C:\Program Files (x86)\Common Files\InstallShield\UpdateService\isuspm.exe /scheduler" -wk 1C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exeISUSPM.exe
User:
admin
Company:
InstallShield Software Corporation
Integrity Level:
HIGH
Description:
InstallShield Update Service Scheduler
Exit code:
0
Version:
3, 00, 100, 1161
Modules
Images
c:\program files (x86)\common files\installshield\updateservice\issch.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acspecfc.dll
4984"C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe" -startC:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exeissch.exe
User:
admin
Company:
InstallShield Software Corporation
Integrity Level:
HIGH
Description:
InstallShield Update Service Scheduler
Exit code:
1073807364
Version:
3, 00, 100, 1161
Modules
Images
c:\program files (x86)\common files\installshield\updateservice\issch.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acspecfc.dll
6244C:\WINDOWS\system32\vssvc.exeC:\Windows\System32\VSSVC.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Volume Shadow Copy Service
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\vssvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
6492"C:\Users\admin\AppData\Local\Temp\Setup-3.2.exe" C:\Users\admin\AppData\Local\Temp\Setup-3.2.exeexplorer.exe
User:
admin
Company:
InstallShield Software Corporation
Integrity Level:
MEDIUM
Description:
Setup.exe
Exit code:
3221226540
Version:
10.0.159
Modules
Images
c:\users\admin\appdata\local\temp\setup-3.2.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
6676"C:\Users\admin\AppData\Local\Temp\Setup-3.2.exe" C:\Users\admin\AppData\Local\Temp\Setup-3.2.exe
explorer.exe
User:
admin
Company:
InstallShield Software Corporation
Integrity Level:
HIGH
Description:
Setup.exe
Exit code:
1073807364
Version:
10.0.159
Modules
Images
c:\users\admin\appdata\local\temp\setup-3.2.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acspecfc.dll
6696 -deleter C:\Users\admin\AppData\Local\Temp\Setup-3.2.exe
Setup-3.2.exe
User:
admin
Company:
InstallShield Software Corporation
Integrity Level:
HIGH
Description:
Setup.exe
Exit code:
1073807364
Version:
10.0.159
Modules
Images
c:\users\admin\appdata\local\temp\setup-3.2.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acspecfc.dll
Total events
4 260
Read events
3 553
Write events
683
Delete events
24

Modification events

(PID) Process:(6696) Setup-3.2.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{F4817E4B-04B6-11D3-8862-00C04F72F303}\InProcServer32
Operation:writeName:ThreadingModel
Value:
Both
(PID) Process:(6696) Setup-3.2.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{AA7E2068-CB55-11D2-8094-00104B1F9838}\TypeLib
Operation:writeName:Version
Value:
1.0
(PID) Process:(6696) Setup-3.2.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{AA7E2068-CB55-11D2-8094-00104B1F9838}\TypeLib
Operation:writeName:Version
Value:
1.0
(PID) Process:(6696) Setup-3.2.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{AA7E2066-CB55-11D2-8094-00104B1F9838}\TypeLib
Operation:writeName:Version
Value:
1.0
(PID) Process:(6696) Setup-3.2.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{AA7E2066-CB55-11D2-8094-00104B1F9838}\TypeLib
Operation:writeName:Version
Value:
1.0
(PID) Process:(6696) Setup-3.2.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{CC096170-E2CB-11D2-80C8-00104B1F6CEA}\TypeLib
Operation:writeName:Version
Value:
1.0
(PID) Process:(6696) Setup-3.2.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{CC096170-E2CB-11D2-80C8-00104B1F6CEA}\TypeLib
Operation:writeName:Version
Value:
1.0
(PID) Process:(6696) Setup-3.2.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{8C3C1B11-E59D-11D2-B40B-00A024B9DDDD}\TypeLib
Operation:writeName:Version
Value:
1.0
(PID) Process:(6696) Setup-3.2.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8C3C1B11-E59D-11D2-B40B-00A024B9DDDD}\TypeLib
Operation:writeName:Version
Value:
1.0
(PID) Process:(6696) Setup-3.2.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{8C3C1B13-E59D-11D2-B40B-00A024B9DDDD}\TypeLib
Operation:writeName:Version
Value:
1.0
Executable files
139
Suspicious files
41
Text files
463
Unknown types
0

Dropped files

PID
Process
Filename
Type
6696Setup-3.2.exeC:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\10\00\Intel32\isp5C6D.tmp\setup.dllexecutable
MD5:68717AF4B31DA63EA902DFBFCCA08394
SHA256:D0D9266F4299A4F37F4207B90FEBA81DB587A31890CFB77951A95A3B00CAE842
6696Setup-3.2.exeC:\Users\admin\AppData\Local\Temp\bye5B23.tmp\Disk1\layout.binbinary
MD5:56EA5F777AD60921AC5796BA11128669
SHA256:A1A86C69A5CE403DD0E1B8387CA81060B92BE253A7F0A5A785638224B640DD1E
6696Setup-3.2.exeC:\Users\admin\AppData\Local\Temp\bye5B23.tmp\Disk1\setup.isnbinary
MD5:13B4A6BEB33353B63DE31E771072CB6B
SHA256:37441528C8BA2D1EB1EF5821689D689D6F95DEC5FEBEB3D59D77689610E624E0
6696Setup-3.2.exeC:\Users\admin\AppData\Local\Temp\bye5B23.tmp\Disk1\setup.exeexecutable
MD5:DD11E8FED01AC201C24C7DF5F786ADF5
SHA256:41F2795146EC6AC1EDD4B3B95174622BC27F5AFAC7E932160C5CEFCE9F63F449
6696Setup-3.2.exeC:\Users\admin\AppData\Local\Temp\bye5B23.tmp\Disk1\data1.cabcompressed
MD5:7B4E7EEBDC86F9E9A39BD0B13A8AFDB4
SHA256:47E6403282592DDD3336AF531DF64B598FC79402C3B806A0EF94DE7B001578FC
6696Setup-3.2.exeC:\Users\admin\AppData\Local\Temp\bye5B23.tmp\Disk1\data1.hdrbinary
MD5:FC7EB81027B3145FF59C8E6795063994
SHA256:442DCF29DFB976B0145ECF9A42A2E3071B9455CCB854FB7AD6B42AE11B76B5B0
6696Setup-3.2.exeC:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\10\00\Intel32\set5C6E.tmpex_
MD5:0FA6C08B935872DBDA9DE3C5866931EA
SHA256:628E00BCC0621FAE1F9E94D6275B438275782D5ACEEC5B9FF4970E08051BEB82
6696Setup-3.2.exeC:\Users\admin\AppData\Local\Temp\bye5B23.tmp\Disk1\setup.initext
MD5:867510F2A2D1D7BD5C70BED25FD41BEB
SHA256:6895D742CB29109B4D1EEDB9D176603E1DDF3340560642EF01AE457CF0CD08E7
6696Setup-3.2.exeC:\Users\admin\AppData\Local\Temp\ISPackFiles.initext
MD5:5DBC3F2F08C3755009FC2736E472001E
SHA256:5021C3E3C78E9438A120929C6CD4D4CF038787FF488DAC8ADBB00843C1F29DBA
6696Setup-3.2.exeC:\Users\admin\AppData\Local\Temp\bye5B23.tmp\Disk1\engine32.cabcompressed
MD5:832E1E8EF0E4A2E8045383EB541F1610
SHA256:BAE58709C4BCDB6F9D3F60E72F44CE3DBC53D004BC5092BAD7E4A49936D4F0F3
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
33
DNS requests
19
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5064
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
GET
200
2.16.241.12:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6372
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
1804
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
1804
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4712
MoUsoCoreWorker.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
2148
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5064
SearchApp.exe
2.23.209.189:443
www.bing.com
Akamai International B.V.
GB
whitelisted
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5064
SearchApp.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
2.16.241.12:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
1176
svchost.exe
40.126.32.134:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
  • 20.73.194.208
  • 4.231.128.59
whitelisted
www.bing.com
  • 2.23.209.189
  • 2.23.209.187
  • 2.23.209.140
  • 2.23.209.133
  • 2.23.209.135
  • 2.23.209.130
  • 2.23.209.185
  • 2.23.209.131
  • 2.23.209.193
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
crl.microsoft.com
  • 2.16.241.12
  • 2.16.241.19
whitelisted
google.com
  • 216.58.212.174
whitelisted
www.microsoft.com
  • 95.101.149.131
whitelisted
login.live.com
  • 40.126.32.134
  • 40.126.32.140
  • 40.126.32.138
  • 40.126.32.72
  • 40.126.32.76
  • 40.126.32.133
  • 20.190.160.17
  • 40.126.32.68
whitelisted
go.microsoft.com
  • 23.32.186.57
whitelisted
arc.msn.com
  • 20.223.35.26
whitelisted
fd.api.iris.microsoft.com
  • 20.103.156.88
whitelisted

Threats

No threats detected
No debug info