| File name: | Setup-3.2.exe |
| Full analysis: | https://app.any.run/tasks/d7e7490b-353a-47a1-a1cb-c20f7ac855ea |
| Verdict: | Malicious activity |
| Analysis date: | December 07, 2024, 05:01:41 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, 4 sections |
| MD5: | 466B07082D6F413AEF4F0FE1E9915A36 |
| SHA1: | 468C55A07803C3426CCA837B63C2E40D3AFA7AEC |
| SHA256: | C3E32AF98959E1CB8A8D91861F4C7A88DCF2A21B3F7035276F8FA2DBC6809130 |
| SSDEEP: | 98304:Oj/Rm+jxnMDrz+dikKP3ZkII2VVbVgknk2O8wB9QRPVT/yruevCk1MSGJJBrttwE:if6llTwZGeAd |
| .exe | | | Win32 Executable MS Visual C++ (generic) (35.8) |
|---|---|---|
| .exe | | | Win64 Executable (generic) (31.7) |
| .scr | | | Windows screen saver (15) |
| .dll | | | Win32 Dynamic Link Library (generic) (7.5) |
| .exe | | | Win32 Executable (generic) (5.1) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2004:04:19 04:44:28+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 66048 |
| InitializedDataSize: | 47616 |
| UninitializedDataSize: | - |
| EntryPoint: | 0xc7f8 |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 10.0.0.159 |
| ProductVersionNumber: | 10.0.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Windows NT 32-bit |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| CompanyName: | InstallShield Software Corporation |
| FileDescription: | Setup.exe |
| FileVersion: | 10.0.159 |
| InternalName: | Setup |
| OriginalFileName: | Setup.exe |
| LegalCopyright: | Copyright (C) 2004 InstallShield Software Corp. |
| ProductName: | InstallShield (R) |
| ProductVersion: | 10 |
| OLESelfRegister: | - |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 236 | C:\WINDOWS\system32\DllHost.exe /Processid:{F32D97DF-E3E5-4CB9-9E3E-0EB5B4E49801} | C:\Windows\System32\dllhost.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: COM Surrogate Exit code: 1073807364 Version: 10.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2076 | REG ADD HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System /v EnableLUA /t REG_DWORD /d 0 /f | C:\Windows\SysWOW64\reg.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Registry Console Tool Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2212 | "C:\Program Files (x86)\Common Files\InstallShield\UpdateService\agent.exe" /l{37365259-9D37-4FBE-9204-08B4034623B6} /1033 | C:\Program Files (x86)\Common Files\InstallShield\UpdateService\agent.exe | — | Setup-3.2.exe | |||||||||||
User: admin Company: InstallShield Software Corporation Integrity Level: HIGH Description: InstallShield Update Service Agent Exit code: 0 Version: 3, 00, 100, 1165 Modules
| |||||||||||||||
| 3416 | "C:\Program Files (x86)\Common Files\InstallShield\UpdateService\agent.exe" /ssi{37365259-9D37-4FBE-9204-08B4034623B6},30:CEDBD7DF79AC27FF2EAC809FDE9C978FB9FBF78F49EBA788CE1B5788DE8BA7589E2C575FF9AC | C:\Program Files (x86)\Common Files\InstallShield\UpdateService\agent.exe | — | Setup-3.2.exe | |||||||||||
User: admin Company: InstallShield Software Corporation Integrity Level: HIGH Description: InstallShield Update Service Agent Exit code: 0 Version: 3, 00, 100, 1165 Modules
| |||||||||||||||
| 3664 | "C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe" -set "C:\Program Files (x86)\Common Files\InstallShield\UpdateService\isuspm.exe /scheduler" -wk 1 | C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe | — | ISUSPM.exe | |||||||||||
User: admin Company: InstallShield Software Corporation Integrity Level: HIGH Description: InstallShield Update Service Scheduler Exit code: 0 Version: 3, 00, 100, 1161 Modules
| |||||||||||||||
| 4984 | "C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe" -start | C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe | — | issch.exe | |||||||||||
User: admin Company: InstallShield Software Corporation Integrity Level: HIGH Description: InstallShield Update Service Scheduler Exit code: 1073807364 Version: 3, 00, 100, 1161 Modules
| |||||||||||||||
| 6244 | C:\WINDOWS\system32\vssvc.exe | C:\Windows\System32\VSSVC.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft® Volume Shadow Copy Service Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6492 | "C:\Users\admin\AppData\Local\Temp\Setup-3.2.exe" | C:\Users\admin\AppData\Local\Temp\Setup-3.2.exe | — | explorer.exe | |||||||||||
User: admin Company: InstallShield Software Corporation Integrity Level: MEDIUM Description: Setup.exe Exit code: 3221226540 Version: 10.0.159 Modules
| |||||||||||||||
| 6676 | "C:\Users\admin\AppData\Local\Temp\Setup-3.2.exe" | C:\Users\admin\AppData\Local\Temp\Setup-3.2.exe | explorer.exe | ||||||||||||
User: admin Company: InstallShield Software Corporation Integrity Level: HIGH Description: Setup.exe Exit code: 1073807364 Version: 10.0.159 Modules
| |||||||||||||||
| 6696 | -deleter | C:\Users\admin\AppData\Local\Temp\Setup-3.2.exe | Setup-3.2.exe | ||||||||||||
User: admin Company: InstallShield Software Corporation Integrity Level: HIGH Description: Setup.exe Exit code: 1073807364 Version: 10.0.159 Modules
| |||||||||||||||
| (PID) Process: | (6696) Setup-3.2.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{F4817E4B-04B6-11D3-8862-00C04F72F303}\InProcServer32 |
| Operation: | write | Name: | ThreadingModel |
Value: Both | |||
| (PID) Process: | (6696) Setup-3.2.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{AA7E2068-CB55-11D2-8094-00104B1F9838}\TypeLib |
| Operation: | write | Name: | Version |
Value: 1.0 | |||
| (PID) Process: | (6696) Setup-3.2.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{AA7E2068-CB55-11D2-8094-00104B1F9838}\TypeLib |
| Operation: | write | Name: | Version |
Value: 1.0 | |||
| (PID) Process: | (6696) Setup-3.2.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{AA7E2066-CB55-11D2-8094-00104B1F9838}\TypeLib |
| Operation: | write | Name: | Version |
Value: 1.0 | |||
| (PID) Process: | (6696) Setup-3.2.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{AA7E2066-CB55-11D2-8094-00104B1F9838}\TypeLib |
| Operation: | write | Name: | Version |
Value: 1.0 | |||
| (PID) Process: | (6696) Setup-3.2.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{CC096170-E2CB-11D2-80C8-00104B1F6CEA}\TypeLib |
| Operation: | write | Name: | Version |
Value: 1.0 | |||
| (PID) Process: | (6696) Setup-3.2.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{CC096170-E2CB-11D2-80C8-00104B1F6CEA}\TypeLib |
| Operation: | write | Name: | Version |
Value: 1.0 | |||
| (PID) Process: | (6696) Setup-3.2.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{8C3C1B11-E59D-11D2-B40B-00A024B9DDDD}\TypeLib |
| Operation: | write | Name: | Version |
Value: 1.0 | |||
| (PID) Process: | (6696) Setup-3.2.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8C3C1B11-E59D-11D2-B40B-00A024B9DDDD}\TypeLib |
| Operation: | write | Name: | Version |
Value: 1.0 | |||
| (PID) Process: | (6696) Setup-3.2.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{8C3C1B13-E59D-11D2-B40B-00A024B9DDDD}\TypeLib |
| Operation: | write | Name: | Version |
Value: 1.0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6696 | Setup-3.2.exe | C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\10\00\Intel32\isp5C6D.tmp\setup.dll | executable | |
MD5:68717AF4B31DA63EA902DFBFCCA08394 | SHA256:D0D9266F4299A4F37F4207B90FEBA81DB587A31890CFB77951A95A3B00CAE842 | |||
| 6696 | Setup-3.2.exe | C:\Users\admin\AppData\Local\Temp\bye5B23.tmp\Disk1\layout.bin | binary | |
MD5:56EA5F777AD60921AC5796BA11128669 | SHA256:A1A86C69A5CE403DD0E1B8387CA81060B92BE253A7F0A5A785638224B640DD1E | |||
| 6696 | Setup-3.2.exe | C:\Users\admin\AppData\Local\Temp\bye5B23.tmp\Disk1\setup.isn | binary | |
MD5:13B4A6BEB33353B63DE31E771072CB6B | SHA256:37441528C8BA2D1EB1EF5821689D689D6F95DEC5FEBEB3D59D77689610E624E0 | |||
| 6696 | Setup-3.2.exe | C:\Users\admin\AppData\Local\Temp\bye5B23.tmp\Disk1\setup.exe | executable | |
MD5:DD11E8FED01AC201C24C7DF5F786ADF5 | SHA256:41F2795146EC6AC1EDD4B3B95174622BC27F5AFAC7E932160C5CEFCE9F63F449 | |||
| 6696 | Setup-3.2.exe | C:\Users\admin\AppData\Local\Temp\bye5B23.tmp\Disk1\data1.cab | compressed | |
MD5:7B4E7EEBDC86F9E9A39BD0B13A8AFDB4 | SHA256:47E6403282592DDD3336AF531DF64B598FC79402C3B806A0EF94DE7B001578FC | |||
| 6696 | Setup-3.2.exe | C:\Users\admin\AppData\Local\Temp\bye5B23.tmp\Disk1\data1.hdr | binary | |
MD5:FC7EB81027B3145FF59C8E6795063994 | SHA256:442DCF29DFB976B0145ECF9A42A2E3071B9455CCB854FB7AD6B42AE11B76B5B0 | |||
| 6696 | Setup-3.2.exe | C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\10\00\Intel32\set5C6E.tmp | ex_ | |
MD5:0FA6C08B935872DBDA9DE3C5866931EA | SHA256:628E00BCC0621FAE1F9E94D6275B438275782D5ACEEC5B9FF4970E08051BEB82 | |||
| 6696 | Setup-3.2.exe | C:\Users\admin\AppData\Local\Temp\bye5B23.tmp\Disk1\setup.ini | text | |
MD5:867510F2A2D1D7BD5C70BED25FD41BEB | SHA256:6895D742CB29109B4D1EEDB9D176603E1DDF3340560642EF01AE457CF0CD08E7 | |||
| 6696 | Setup-3.2.exe | C:\Users\admin\AppData\Local\Temp\ISPackFiles.ini | text | |
MD5:5DBC3F2F08C3755009FC2736E472001E | SHA256:5021C3E3C78E9438A120929C6CD4D4CF038787FF488DAC8ADBB00843C1F29DBA | |||
| 6696 | Setup-3.2.exe | C:\Users\admin\AppData\Local\Temp\bye5B23.tmp\Disk1\engine32.cab | compressed | |
MD5:832E1E8EF0E4A2E8045383EB541F1610 | SHA256:BAE58709C4BCDB6F9D3F60E72F44CE3DBC53D004BC5092BAD7E4A49936D4F0F3 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
5064 | SearchApp.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D | unknown | — | — | whitelisted |
— | — | GET | 200 | 2.16.241.12:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
— | — | GET | 200 | 95.101.149.131:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
— | — | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
6372 | backgroundTaskHost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D | unknown | — | — | whitelisted |
1804 | SIHClient.exe | GET | 200 | 95.101.149.131:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
1804 | SIHClient.exe | GET | 200 | 95.101.149.131:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4712 | MoUsoCoreWorker.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
2148 | svchost.exe | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
5064 | SearchApp.exe | 2.23.209.189:443 | www.bing.com | Akamai International B.V. | GB | whitelisted |
— | — | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
5064 | SearchApp.exe | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
— | — | 2.16.241.12:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
— | — | 95.101.149.131:80 | www.microsoft.com | Akamai International B.V. | NL | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1176 | svchost.exe | 40.126.32.134:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
www.bing.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
login.live.com |
| whitelisted |
go.microsoft.com |
| whitelisted |
arc.msn.com |
| whitelisted |
fd.api.iris.microsoft.com |
| whitelisted |