File name:

Setup-3.2.exe

Full analysis: https://app.any.run/tasks/d7e7490b-353a-47a1-a1cb-c20f7ac855ea
Verdict: Malicious activity
Analysis date: December 07, 2024, 05:01:41
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 4 sections
MD5:

466B07082D6F413AEF4F0FE1E9915A36

SHA1:

468C55A07803C3426CCA837B63C2E40D3AFA7AEC

SHA256:

C3E32AF98959E1CB8A8D91861F4C7A88DCF2A21B3F7035276F8FA2DBC6809130

SSDEEP:

98304:Oj/Rm+jxnMDrz+dikKP3ZkII2VVbVgknk2O8wB9QRPVT/yruevCk1MSGJJBrttwE:if6llTwZGeAd

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Application launched itself

      • Setup-3.2.exe (PID: 6676)
      • issch.exe (PID: 3664)
    • Creates/Modifies COM task schedule object

      • Setup-3.2.exe (PID: 6696)
    • Searches for installed software

      • dllhost.exe (PID: 7164)
    • Executes as Windows Service

      • VSSVC.exe (PID: 6244)
    • Executable content was dropped or overwritten

      • Setup-3.2.exe (PID: 6696)
    • Starts CMD.EXE for commands execution

      • Setup-3.2.exe (PID: 6696)
    • Drops a system driver (possible attempt to evade defenses)

      • Setup-3.2.exe (PID: 6696)
    • Uses REG/REGEDIT.EXE to modify registry

      • cmd.exe (PID: 6804)
  • INFO

    • Checks supported languages

      • Setup-3.2.exe (PID: 6696)
      • Setup-3.2.exe (PID: 6676)
    • Creates files in the program directory

      • Setup-3.2.exe (PID: 6696)
    • Reads the machine GUID from the registry

      • Setup-3.2.exe (PID: 6696)
    • Reads the computer name

      • Setup-3.2.exe (PID: 6696)
    • Create files in a temporary directory

      • Setup-3.2.exe (PID: 6696)
    • Manages system restore points

      • SrTasks.exe (PID: 6812)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (35.8)
.exe | Win64 Executable (generic) (31.7)
.scr | Windows screen saver (15)
.dll | Win32 Dynamic Link Library (generic) (7.5)
.exe | Win32 Executable (generic) (5.1)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2004:04:19 04:44:28+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 66048
InitializedDataSize: 47616
UninitializedDataSize: -
EntryPoint: 0xc7f8
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 10.0.0.159
ProductVersionNumber: 10.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: InstallShield Software Corporation
FileDescription: Setup.exe
FileVersion: 10.0.159
InternalName: Setup
OriginalFileName: Setup.exe
LegalCopyright: Copyright (C) 2004 InstallShield Software Corp.
ProductName: InstallShield (R)
ProductVersion: 10
OLESelfRegister: -
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
147
Monitored processes
17
Malicious processes
2
Suspicious processes
1

Behavior graph

Click at the process to see the details
start setup-3.2.exe setup-3.2.exe SPPSurrogate no specs vssvc.exe no specs srtasks.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs reg.exe no specs agent.exe no specs agent.exe no specs isuspm.exe no specs agent.exe no specs issch.exe no specs issch.exe no specs SPPSurrogate no specs setup-3.2.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
236C:\WINDOWS\system32\DllHost.exe /Processid:{F32D97DF-E3E5-4CB9-9E3E-0EB5B4E49801}C:\Windows\System32\dllhost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
COM Surrogate
Exit code:
1073807364
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\dllhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\msvcrt.dll
2076REG ADD HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System /v EnableLUA /t REG_DWORD /d 0 /fC:\Windows\SysWOW64\reg.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Registry Console Tool
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\reg.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
2212"C:\Program Files (x86)\Common Files\InstallShield\UpdateService\agent.exe" /l{37365259-9D37-4FBE-9204-08B4034623B6} /1033C:\Program Files (x86)\Common Files\InstallShield\UpdateService\agent.exeSetup-3.2.exe
User:
admin
Company:
InstallShield Software Corporation
Integrity Level:
HIGH
Description:
InstallShield Update Service Agent
Exit code:
0
Version:
3, 00, 100, 1165
Modules
Images
c:\program files (x86)\common files\installshield\updateservice\agent.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acspecfc.dll
3416"C:\Program Files (x86)\Common Files\InstallShield\UpdateService\agent.exe" /ssi{37365259-9D37-4FBE-9204-08B4034623B6},30:CEDBD7DF79AC27FF2EAC809FDE9C978FB9FBF78F49EBA788CE1B5788DE8BA7589E2C575FF9ACC:\Program Files (x86)\Common Files\InstallShield\UpdateService\agent.exeSetup-3.2.exe
User:
admin
Company:
InstallShield Software Corporation
Integrity Level:
HIGH
Description:
InstallShield Update Service Agent
Exit code:
0
Version:
3, 00, 100, 1165
Modules
Images
c:\program files (x86)\common files\installshield\updateservice\agent.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acspecfc.dll
3664"C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe" -set "C:\Program Files (x86)\Common Files\InstallShield\UpdateService\isuspm.exe /scheduler" -wk 1C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exeISUSPM.exe
User:
admin
Company:
InstallShield Software Corporation
Integrity Level:
HIGH
Description:
InstallShield Update Service Scheduler
Exit code:
0
Version:
3, 00, 100, 1161
Modules
Images
c:\program files (x86)\common files\installshield\updateservice\issch.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acspecfc.dll
4984"C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe" -startC:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exeissch.exe
User:
admin
Company:
InstallShield Software Corporation
Integrity Level:
HIGH
Description:
InstallShield Update Service Scheduler
Exit code:
1073807364
Version:
3, 00, 100, 1161
Modules
Images
c:\program files (x86)\common files\installshield\updateservice\issch.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acspecfc.dll
6244C:\WINDOWS\system32\vssvc.exeC:\Windows\System32\VSSVC.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Volume Shadow Copy Service
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\vssvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
6492"C:\Users\admin\AppData\Local\Temp\Setup-3.2.exe" C:\Users\admin\AppData\Local\Temp\Setup-3.2.exeexplorer.exe
User:
admin
Company:
InstallShield Software Corporation
Integrity Level:
MEDIUM
Description:
Setup.exe
Exit code:
3221226540
Version:
10.0.159
Modules
Images
c:\users\admin\appdata\local\temp\setup-3.2.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
6676"C:\Users\admin\AppData\Local\Temp\Setup-3.2.exe" C:\Users\admin\AppData\Local\Temp\Setup-3.2.exe
explorer.exe
User:
admin
Company:
InstallShield Software Corporation
Integrity Level:
HIGH
Description:
Setup.exe
Exit code:
1073807364
Version:
10.0.159
Modules
Images
c:\users\admin\appdata\local\temp\setup-3.2.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acspecfc.dll
6696 -deleter C:\Users\admin\AppData\Local\Temp\Setup-3.2.exe
Setup-3.2.exe
User:
admin
Company:
InstallShield Software Corporation
Integrity Level:
HIGH
Description:
Setup.exe
Exit code:
1073807364
Version:
10.0.159
Modules
Images
c:\users\admin\appdata\local\temp\setup-3.2.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acspecfc.dll
Total events
4 260
Read events
3 553
Write events
683
Delete events
24

Modification events

(PID) Process:(6696) Setup-3.2.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{F4817E4B-04B6-11D3-8862-00C04F72F303}\InProcServer32
Operation:writeName:ThreadingModel
Value:
Both
(PID) Process:(6696) Setup-3.2.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{AA7E2068-CB55-11D2-8094-00104B1F9838}\TypeLib
Operation:writeName:Version
Value:
1.0
(PID) Process:(6696) Setup-3.2.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{AA7E2068-CB55-11D2-8094-00104B1F9838}\TypeLib
Operation:writeName:Version
Value:
1.0
(PID) Process:(6696) Setup-3.2.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{AA7E2066-CB55-11D2-8094-00104B1F9838}\TypeLib
Operation:writeName:Version
Value:
1.0
(PID) Process:(6696) Setup-3.2.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{AA7E2066-CB55-11D2-8094-00104B1F9838}\TypeLib
Operation:writeName:Version
Value:
1.0
(PID) Process:(6696) Setup-3.2.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{CC096170-E2CB-11D2-80C8-00104B1F6CEA}\TypeLib
Operation:writeName:Version
Value:
1.0
(PID) Process:(6696) Setup-3.2.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{CC096170-E2CB-11D2-80C8-00104B1F6CEA}\TypeLib
Operation:writeName:Version
Value:
1.0
(PID) Process:(6696) Setup-3.2.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{8C3C1B11-E59D-11D2-B40B-00A024B9DDDD}\TypeLib
Operation:writeName:Version
Value:
1.0
(PID) Process:(6696) Setup-3.2.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8C3C1B11-E59D-11D2-B40B-00A024B9DDDD}\TypeLib
Operation:writeName:Version
Value:
1.0
(PID) Process:(6696) Setup-3.2.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{8C3C1B13-E59D-11D2-B40B-00A024B9DDDD}\TypeLib
Operation:writeName:Version
Value:
1.0
Executable files
139
Suspicious files
41
Text files
463
Unknown types
0

Dropped files

PID
Process
Filename
Type
6696Setup-3.2.exeC:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\10\00\Intel32\set5C6E.tmpex_
MD5:0FA6C08B935872DBDA9DE3C5866931EA
SHA256:628E00BCC0621FAE1F9E94D6275B438275782D5ACEEC5B9FF4970E08051BEB82
6696Setup-3.2.exeC:\Users\admin\AppData\Local\Temp\bye5B23.tmp\Disk1\setup.isnbinary
MD5:13B4A6BEB33353B63DE31E771072CB6B
SHA256:37441528C8BA2D1EB1EF5821689D689D6F95DEC5FEBEB3D59D77689610E624E0
6696Setup-3.2.exeC:\Users\admin\AppData\Local\Temp\bye5B23.tmp\Disk1\setup.exeexecutable
MD5:DD11E8FED01AC201C24C7DF5F786ADF5
SHA256:41F2795146EC6AC1EDD4B3B95174622BC27F5AFAC7E932160C5CEFCE9F63F449
6696Setup-3.2.exeC:\Users\admin\AppData\Local\Temp\bye5B23.tmp\Disk1\data1.cabcompressed
MD5:7B4E7EEBDC86F9E9A39BD0B13A8AFDB4
SHA256:47E6403282592DDD3336AF531DF64B598FC79402C3B806A0EF94DE7B001578FC
6696Setup-3.2.exeC:\Users\admin\AppData\Local\Temp\bye5B23.tmp\Disk1\setup.inxbinary
MD5:EDF75D8F254A6DED33F95EF123F4C677
SHA256:3EEE5B829CC8FE07A8FA9363DD024A226CD76DC1D24264E7AE6E2ACE21985B42
6696Setup-3.2.exeC:\Users\admin\AppData\Local\Temp\iss5BD0.tmp\setup.initext
MD5:867510F2A2D1D7BD5C70BED25FD41BEB
SHA256:6895D742CB29109B4D1EEDB9D176603E1DDF3340560642EF01AE457CF0CD08E7
6696Setup-3.2.exeC:\Users\admin\AppData\Local\Temp\bye5B23.tmp\Disk1\setup.ibtbinary
MD5:A6E2436F0A1194E22D5B0DEFAA171200
SHA256:91486F7C6811E2CD42DD2B38C4971A7B8F26E9F192C4DC1A5D6C43DBCE69AC13
6696Setup-3.2.exeC:\Users\admin\AppData\Local\Temp\bye5B23.tmp\Disk1\data1.hdrbinary
MD5:FC7EB81027B3145FF59C8E6795063994
SHA256:442DCF29DFB976B0145ECF9A42A2E3071B9455CCB854FB7AD6B42AE11B76B5B0
6696Setup-3.2.exeC:\Users\admin\AppData\Local\Temp\bye5B23.tmp\Disk1\layout.binbinary
MD5:56EA5F777AD60921AC5796BA11128669
SHA256:A1A86C69A5CE403DD0E1B8387CA81060B92BE253A7F0A5A785638224B640DD1E
6696Setup-3.2.exeC:\Users\admin\AppData\Local\Temp\bye5B23.tmp\Disk1\setup.initext
MD5:867510F2A2D1D7BD5C70BED25FD41BEB
SHA256:6895D742CB29109B4D1EEDB9D176603E1DDF3340560642EF01AE457CF0CD08E7
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
33
DNS requests
19
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5064
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
GET
200
2.16.241.12:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6372
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
1804
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
1804
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4712
MoUsoCoreWorker.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
2148
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5064
SearchApp.exe
2.23.209.189:443
www.bing.com
Akamai International B.V.
GB
whitelisted
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5064
SearchApp.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
2.16.241.12:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
1176
svchost.exe
40.126.32.134:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
  • 20.73.194.208
  • 4.231.128.59
whitelisted
www.bing.com
  • 2.23.209.189
  • 2.23.209.187
  • 2.23.209.140
  • 2.23.209.133
  • 2.23.209.135
  • 2.23.209.130
  • 2.23.209.185
  • 2.23.209.131
  • 2.23.209.193
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
crl.microsoft.com
  • 2.16.241.12
  • 2.16.241.19
whitelisted
google.com
  • 216.58.212.174
whitelisted
www.microsoft.com
  • 95.101.149.131
whitelisted
login.live.com
  • 40.126.32.134
  • 40.126.32.140
  • 40.126.32.138
  • 40.126.32.72
  • 40.126.32.76
  • 40.126.32.133
  • 20.190.160.17
  • 40.126.32.68
whitelisted
go.microsoft.com
  • 23.32.186.57
whitelisted
arc.msn.com
  • 20.223.35.26
whitelisted
fd.api.iris.microsoft.com
  • 20.103.156.88
whitelisted

Threats

No threats detected
No debug info