File name:

SPF9139.Setup.exe

Full analysis: https://app.any.run/tasks/ec85bc07-a0d0-4328-8334-d1c5cb9ea1ce
Verdict: Malicious activity
Threats:

Metamorfo is a trojan malware family that has been active since 2018. It remains a top threat, focusing on stealing victims’ financial information, including banking credentials and other data. The malware is known for targeting users in Brazil.

Analysis date: December 10, 2023, 21:07:35
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
metamorfo
Indicators:
MIME: application/x-dosexec
File info: MS-DOS executable PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows, MZ for MS-DOS
MD5:

E677DC63238171BDA2405227822FB028

SHA1:

C6581FF53E065E471770F126E3F3D8803415061D

SHA256:

C4CCAF2A7D3521DEACB2EB71A77267575461831E575D50393303E842E8247369

SSDEEP:

98304:XklVm12/cPhVRpC5Icve9x9H4AHZszuW02NMdXdVeXsrdM6WWi2FSB24KOndVy8f:BDEd5/DnkH18

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • METAMORFO has been detected (YARA)

      • SPF9139.Setup.exe (PID: 604)
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    • Checks supported languages

      • SPF9139.Setup.exe (PID: 604)
    • Reads the computer name

      • SPF9139.Setup.exe (PID: 604)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable (generic) (52.9)
.exe | Generic Win/DOS Executable (23.5)
.exe | DOS Executable Generic (23.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2022:04:13 10:44:20+02:00
ImageFileCharacteristics: Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, No debug, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 6152704
InitializedDataSize: 9817600
UninitializedDataSize: -
EntryPoint: 0xebf432
OSVersion: 5
ImageVersion: -
SubsystemVersion: 5
Subsystem: Windows GUI
FileVersionNumber: 3.3.2201.1914
ProductVersionNumber: 3.3.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
FileVersion: 3.3.2201.1914
ProductVersion: 3.3
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
40
Monitored processes
2
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start #METAMORFO spf9139.setup.exe spf9139.setup.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
604"C:\Users\admin\AppData\Local\Temp\SPF9139.Setup.exe" C:\Users\admin\AppData\Local\Temp\SPF9139.Setup.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Version:
3.3.2201.1914
Modules
Images
c:\users\admin\appdata\local\temp\spf9139.setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\winmm.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3048"C:\Users\admin\AppData\Local\Temp\SPF9139.Setup.exe" C:\Users\admin\AppData\Local\Temp\SPF9139.Setup.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Version:
3.3.2201.1914
Modules
Images
c:\users\admin\appdata\local\temp\spf9139.setup.exe
c:\windows\system32\ntdll.dll
Total events
29
Read events
28
Write events
1
Delete events
0

Modification events

(PID) Process:(604) SPF9139.Setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Direct3D\MostRecentApplication
Operation:writeName:Name
Value:
Explorer.EXE
Executable files
0
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

No data
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
2588
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown

DNS requests

No data

Threats

No threats detected
Process
Message
SPF9139.Setup.exe
INSTALL AntivirusList Start
SPF9139.Setup.exe
INSTALL AntivirusList End