File name:

Core-Temp-setup-v1.18.1.0.exe

Full analysis: https://app.any.run/tasks/f8d2e273-39a8-4e0c-878f-a9497a3cefce
Verdict: Malicious activity
Analysis date: October 05, 2023, 20:06:34
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

176642114EE7A82E0486BF5FAC5777C0

SHA1:

F4329A1AFC37F143BA1D39D9670CA4B1ACD61C23

SHA256:

CA7D1365E934B3BD122AB8B0DBD24EF5E0C52471CFCA15921555FC6B244E9AB6

SSDEEP:

49152:TwE0bqq2LkelPNf4qz2ZBQq9RuNkDtz7OU4SD3e9yDZocZIOtAcAmWoz4IY3WO+y:z0bBWTJ4VBL9RBtzBO9yGgMu40X9SFuu

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • Core-Temp-setup-v1.18.1.0.exe (PID: 3820)
      • Core-Temp-setup-v1.18.1.0.exe (PID: 3812)
      • Core-Temp-setup-v1.18.1.0.tmp (PID: 1940)
      • Core Temp.exe (PID: 1896)
    • Application was dropped or rewritten from another process

      • Core Temp.exe (PID: 1896)
  • SUSPICIOUS

    • Reads the Windows owner or organization settings

      • Core-Temp-setup-v1.18.1.0.tmp (PID: 1940)
    • Start notepad (likely ransomware note)

      • Core-Temp-setup-v1.18.1.0.tmp (PID: 3604)
    • Drops a system driver (possible attempt to evade defenses)

      • Core Temp.exe (PID: 1896)
  • INFO

    • Create files in a temporary directory

      • Core-Temp-setup-v1.18.1.0.exe (PID: 3820)
      • Core-Temp-setup-v1.18.1.0.exe (PID: 3812)
      • Core Temp.exe (PID: 1896)
    • Checks supported languages

      • Core-Temp-setup-v1.18.1.0.exe (PID: 3820)
      • Core-Temp-setup-v1.18.1.0.exe (PID: 3812)
      • Core-Temp-setup-v1.18.1.0.tmp (PID: 3604)
      • Core-Temp-setup-v1.18.1.0.tmp (PID: 1940)
      • Core Temp.exe (PID: 1896)
    • Reads the computer name

      • Core-Temp-setup-v1.18.1.0.tmp (PID: 3604)
      • Core-Temp-setup-v1.18.1.0.tmp (PID: 1940)
      • Core Temp.exe (PID: 1896)
    • Application was dropped or rewritten from another process

      • Core-Temp-setup-v1.18.1.0.tmp (PID: 1940)
      • Core-Temp-setup-v1.18.1.0.tmp (PID: 3604)
    • Creates files in the program directory

      • Core-Temp-setup-v1.18.1.0.tmp (PID: 1940)
      • Core Temp.exe (PID: 1896)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable Delphi generic (45.2)
.dll | Win32 Dynamic Link Library (generic) (20.9)
.exe | Win32 Executable (generic) (14.3)
.exe | Win16/32 Executable Delphi generic (6.6)
.exe | Generic Win/DOS Executable (6.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2018:06:14 15:27:46+02:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 66560
InitializedDataSize: 53760
UninitializedDataSize: -
EntryPoint: 0x1181c
OSVersion: 5
ImageVersion: 6
SubsystemVersion: 5
Subsystem: Windows GUI
FileVersionNumber: 1.18.1.0
ProductVersionNumber: 1.18.1.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: ALCPU
FileDescription: Core Temp Setup
FileVersion: 1.18.1.0
LegalCopyright:
ProductName: Core Temp
ProductVersion: 1.18.1
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
43
Monitored processes
6
Malicious processes
5
Suspicious processes
0

Behavior graph

Click at the process to see the details
drop and start start drop and start drop and start core-temp-setup-v1.18.1.0.exe no specs core-temp-setup-v1.18.1.0.tmp no specs core-temp-setup-v1.18.1.0.exe core-temp-setup-v1.18.1.0.tmp no specs notepad.exe no specs core temp.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1896"C:\Program Files\Core Temp\Core Temp.exe"C:\Program Files\Core Temp\Core Temp.exeCore-Temp-setup-v1.18.1.0.tmp
User:
admin
Company:
ALCPU
Integrity Level:
HIGH
Description:
CPU temperature and system information utility
Exit code:
0
Version:
1.18.1.0
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\program files\core temp\core temp.exe
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1940"C:\Users\admin\AppData\Local\Temp\is-KHCP4.tmp\Core-Temp-setup-v1.18.1.0.tmp" /SL5="$90194,868100,121344,C:\Users\admin\AppData\Local\Temp\Core-Temp-setup-v1.18.1.0.exe" /SPAWNWND=$90216 /NOTIFYWND=$F00FA C:\Users\admin\AppData\Local\Temp\is-KHCP4.tmp\Core-Temp-setup-v1.18.1.0.tmpCore-Temp-setup-v1.18.1.0.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-khcp4.tmp\core-temp-setup-v1.18.1.0.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2544"C:\Windows\system32\NOTEPAD.EXE" C:\Program Files\Core Temp\Readme.txtC:\Windows\System32\notepad.exeCore-Temp-setup-v1.18.1.0.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\notepad.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3604"C:\Users\admin\AppData\Local\Temp\is-7ESFP.tmp\Core-Temp-setup-v1.18.1.0.tmp" /SL5="$F00FA,868100,121344,C:\Users\admin\AppData\Local\Temp\Core-Temp-setup-v1.18.1.0.exe" C:\Users\admin\AppData\Local\Temp\is-7ESFP.tmp\Core-Temp-setup-v1.18.1.0.tmpCore-Temp-setup-v1.18.1.0.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-7esfp.tmp\core-temp-setup-v1.18.1.0.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
3812"C:\Users\admin\AppData\Local\Temp\Core-Temp-setup-v1.18.1.0.exe" /SPAWNWND=$90216 /NOTIFYWND=$F00FA C:\Users\admin\AppData\Local\Temp\Core-Temp-setup-v1.18.1.0.exe
Core-Temp-setup-v1.18.1.0.tmp
User:
admin
Company:
ALCPU
Integrity Level:
HIGH
Description:
Core Temp Setup
Exit code:
0
Version:
1.18.1.0
Modules
Images
c:\users\admin\appdata\local\temp\core-temp-setup-v1.18.1.0.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3820"C:\Users\admin\AppData\Local\Temp\Core-Temp-setup-v1.18.1.0.exe" C:\Users\admin\AppData\Local\Temp\Core-Temp-setup-v1.18.1.0.exeexplorer.exe
User:
admin
Company:
ALCPU
Integrity Level:
MEDIUM
Description:
Core Temp Setup
Exit code:
0
Version:
1.18.1.0
Modules
Images
c:\users\admin\appdata\local\temp\core-temp-setup-v1.18.1.0.exe
c:\windows\system32\rpcrt4.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
Total events
1 333
Read events
1 327
Write events
0
Delete events
6

Modification events

(PID) Process:(1940) Core-Temp-setup-v1.18.1.0.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:RegFilesHash
Value:
7D5FB9399836C51DAEC5893F82119E6749E79039BC8800CFE735D499DB2EA13C
(PID) Process:(1940) Core-Temp-setup-v1.18.1.0.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:RegFiles0000
Value:
C:\Program Files\Core Temp\Core Temp.exe
(PID) Process:(1940) Core-Temp-setup-v1.18.1.0.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:Sequence
Value:
1
(PID) Process:(1940) Core-Temp-setup-v1.18.1.0.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:SessionHash
Value:
803932B911DE8B14497C325394EFCB491CAFE7F5019789AEBAE7CCDCA78CF055
(PID) Process:(1940) Core-Temp-setup-v1.18.1.0.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:Owner
Value:
94070000D66D6976C7F7D901
(PID) Process:(1940) Core-Temp-setup-v1.18.1.0.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete keyName:(default)
Value:
Executable files
7
Suspicious files
4
Text files
7
Unknown types
0

Dropped files

PID
Process
Filename
Type
1940Core-Temp-setup-v1.18.1.0.tmpC:\Program Files\Core Temp\unins000.exeexecutable
MD5:E535020EB53AF0A8CC69FD8180F7275E
SHA256:F515206B2C2FD3A59CF6F003143EFCA98456E2BDC4B7A8F622BEB98F735CF667
1940Core-Temp-setup-v1.18.1.0.tmpC:\Program Files\Core Temp\is-5OHBB.tmpexecutable
MD5:E535020EB53AF0A8CC69FD8180F7275E
SHA256:F515206B2C2FD3A59CF6F003143EFCA98456E2BDC4B7A8F622BEB98F735CF667
1940Core-Temp-setup-v1.18.1.0.tmpC:\Program Files\Core Temp\Changes.txttext
MD5:0FF2E6869879C98DC6144F3384DB16A0
SHA256:87E330164B239690BA6E3B99F16768CEE7C457225C2971C7C3E52C0E21F95332
1940Core-Temp-setup-v1.18.1.0.tmpC:\Program Files\Core Temp\is-MTRIN.tmptext
MD5:0FF2E6869879C98DC6144F3384DB16A0
SHA256:87E330164B239690BA6E3B99F16768CEE7C457225C2971C7C3E52C0E21F95332
3820Core-Temp-setup-v1.18.1.0.exeC:\Users\admin\AppData\Local\Temp\is-7ESFP.tmp\Core-Temp-setup-v1.18.1.0.tmpexecutable
MD5:34ACC2BDB45A9C436181426828C4CB49
SHA256:9C81817ACD4982632D8C7F1DF3898FCA1477577738184265D735F49FC5480F07
1940Core-Temp-setup-v1.18.1.0.tmpC:\Program Files\Core Temp\is-1TIRO.tmptext
MD5:932B5FB4B60BBA2DBF7D178518C69670
SHA256:37C7CC1DEE0A655060E37333B4D99E697DAD5C197FFDB30BF136E1412C5D70D8
1940Core-Temp-setup-v1.18.1.0.tmpC:\Program Files\Core Temp\unins000.datbinary
MD5:3BD137C363C7782C9B05DE68B7FE5101
SHA256:3AA376B47AD391BC8ABA5EE783F937D68872E3AFA0B166F62C7A31F586ECA7DD
1940Core-Temp-setup-v1.18.1.0.tmpC:\Program Files\Core Temp\License.txttext
MD5:932B5FB4B60BBA2DBF7D178518C69670
SHA256:37C7CC1DEE0A655060E37333B4D99E697DAD5C197FFDB30BF136E1412C5D70D8
1940Core-Temp-setup-v1.18.1.0.tmpC:\Users\admin\Desktop\Core Temp.lnkbinary
MD5:70BBCB3A171A74AA2534CFA8BC093D74
SHA256:D7825EDBDC9DD2924D76E94220832DA602EF78A7FEE45E96BADCB047780F1386
1940Core-Temp-setup-v1.18.1.0.tmpC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Core Temp\Core Temp.lnkbinary
MD5:683F2F11721E9A0676CC3B5BC5505A1C
SHA256:C922CB87B72C62CD4BDFEFCF45FADC73B486672D1CBA23CF96B97E8B41AAD52E
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
3
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
2656
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:138
whitelisted

DNS requests

No data

Threats

No threats detected
No debug info