File name:

setup_EMDB.exe

Full analysis: https://app.any.run/tasks/9a6f81b3-c290-4138-b3b3-46a239bc80ad
Verdict: Malicious activity
Analysis date: January 20, 2024, 21:52:01
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

A68D30AEA481A9EAD901AB051755C55D

SHA1:

FE58467EEB152691E539799DCB2EA0344DCD7107

SHA256:

D136877082BBE526F0461744F0BA68BD9E14AA1F61F24E11EE50AE17721D27C4

SSDEEP:

98304:YbetXz4KzZiqrNqFyCzcdNeSiQECkcK9f7j8CZ1oLlSoQlQbVpEzQbUq2R1krQHz:uamhcFqboM

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • setup_EMDB.exe (PID: 120)
      • setup_EMDB.exe (PID: 2420)
      • setup_EMDB.tmp (PID: 2024)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • setup_EMDB.exe (PID: 120)
      • setup_EMDB.exe (PID: 2420)
      • setup_EMDB.tmp (PID: 2024)
    • Reads the Windows owner or organization settings

      • setup_EMDB.tmp (PID: 2024)
    • Process drops legitimate windows executable

      • setup_EMDB.tmp (PID: 2024)
    • Reads the Internet Settings

      • AutoUpdater2.exe (PID: 1748)
      • EMDB.exe (PID: 1216)
    • Process requests binary or script from the Internet

      • AutoUpdater2.exe (PID: 1748)
      • EMDB.exe (PID: 1216)
  • INFO

    • Checks supported languages

      • setup_EMDB.exe (PID: 120)
      • setup_EMDB.tmp (PID: 128)
      • setup_EMDB.exe (PID: 2420)
      • setup_EMDB.tmp (PID: 2024)
      • wmpnscfg.exe (PID: 480)
      • AutoUpdater2.exe (PID: 1748)
      • EMDB.exe (PID: 1216)
    • Create files in a temporary directory

      • setup_EMDB.exe (PID: 120)
      • setup_EMDB.exe (PID: 2420)
      • setup_EMDB.tmp (PID: 2024)
    • Reads the computer name

      • setup_EMDB.tmp (PID: 128)
      • setup_EMDB.tmp (PID: 2024)
      • wmpnscfg.exe (PID: 480)
      • EMDB.exe (PID: 1216)
      • AutoUpdater2.exe (PID: 1748)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 480)
    • Creates files in the program directory

      • setup_EMDB.tmp (PID: 2024)
      • AutoUpdater2.exe (PID: 1748)
    • Creates files or folders in the user directory

      • setup_EMDB.tmp (PID: 2024)
      • EMDB.exe (PID: 1216)
    • Checks proxy server information

      • EMDB.exe (PID: 1216)
      • AutoUpdater2.exe (PID: 1748)
    • Reads the machine GUID from the registry

      • EMDB.exe (PID: 1216)
      • AutoUpdater2.exe (PID: 1748)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (71.1)
.exe | Win32 Executable Delphi generic (9.1)
.scr | Windows screen saver (8.4)
.dll | Win32 Dynamic Link Library (generic) (4.2)
.exe | Win32 Executable (generic) (2.9)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 1992:06:20 00:22:17+02:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 40448
InitializedDataSize: 17920
UninitializedDataSize: -
EntryPoint: 0xa5f8
OSVersion: 1
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 0.0.0.0
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: Wicked & Wild Inc.
FileDescription: EMDB Setup
FileVersion:
LegalCopyright:
ProductName: EMDB
ProductVersion:
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
47
Monitored processes
7
Malicious processes
5
Suspicious processes
1

Behavior graph

Click at the process to see the details
start setup_emdb.exe setup_emdb.tmp no specs setup_emdb.exe setup_emdb.tmp wmpnscfg.exe no specs emdb.exe autoupdater2.exe

Process information

PID
CMD
Path
Indicators
Parent process
120"C:\Users\admin\AppData\Local\Temp\setup_EMDB.exe" C:\Users\admin\AppData\Local\Temp\setup_EMDB.exe
explorer.exe
User:
admin
Company:
Wicked & Wild Inc.
Integrity Level:
MEDIUM
Description:
EMDB Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\appdata\local\temp\setup_emdb.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
128"C:\Users\admin\AppData\Local\Temp\is-I5B5K.tmp\setup_EMDB.tmp" /SL5="$301AA,3082765,56832,C:\Users\admin\AppData\Local\Temp\setup_EMDB.exe" C:\Users\admin\AppData\Local\Temp\is-I5B5K.tmp\setup_EMDB.tmpsetup_EMDB.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.52.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-i5b5k.tmp\setup_emdb.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
480"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1216"C:\Program Files\EMDB\EMDB.exe"C:\Program Files\EMDB\EMDB.exe
setup_EMDB.tmp
User:
admin
Company:
Wicked & Wild Inc.
Integrity Level:
MEDIUM
Description:
EMDB - Eric's Movie DataBase
Exit code:
0
Version:
3.0.9.0
Modules
Images
c:\program files\emdb\emdb.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msimg32.dll
1748"C:\Program Files\EMDB\AutoUpdater2.exe" /download-media-infoC:\Program Files\EMDB\AutoUpdater2.exe
EMDB.exe
User:
admin
Company:
Wicked & Wild Inc.
Integrity Level:
HIGH
Description:
EMDB AutoUpdater
Exit code:
0
Version:
1.0.11.0
Modules
Images
c:\program files\emdb\autoupdater2.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msimg32.dll
2024"C:\Users\admin\AppData\Local\Temp\is-2D8HQ.tmp\setup_EMDB.tmp" /SL5="$601B2,3082765,56832,C:\Users\admin\AppData\Local\Temp\setup_EMDB.exe" /SPAWNWND=$401AE /NOTIFYWND=$301AA C:\Users\admin\AppData\Local\Temp\is-2D8HQ.tmp\setup_EMDB.tmp
setup_EMDB.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.52.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-2d8hq.tmp\setup_emdb.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
2420"C:\Users\admin\AppData\Local\Temp\setup_EMDB.exe" /SPAWNWND=$401AE /NOTIFYWND=$301AA C:\Users\admin\AppData\Local\Temp\setup_EMDB.exe
setup_EMDB.tmp
User:
admin
Company:
Wicked & Wild Inc.
Integrity Level:
HIGH
Description:
EMDB Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\appdata\local\temp\setup_emdb.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
Total events
1 791
Read events
1 728
Write events
57
Delete events
6

Modification events

(PID) Process:(2024) setup_EMDB.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:RegFilesHash
Value:
5895010AFE3D9BFBF335C951A56068921FF2AEF4C7DC309C3A1C21D1A92B2ADD
(PID) Process:(2024) setup_EMDB.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:RegFiles0000
Value:
C:\Program Files\EMDB\EMDB.exe
(PID) Process:(2024) setup_EMDB.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:Sequence
Value:
1
(PID) Process:(2024) setup_EMDB.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:SessionHash
Value:
4072C5F550FFF4123975107097883E9D6CD7F2EF597B0F2CF806573A7EED98B0
(PID) Process:(2024) setup_EMDB.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:Owner
Value:
E8070000DC74CEEBEA4BDA01
(PID) Process:(2024) setup_EMDB.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete keyName:(default)
Value:
(PID) Process:(1216) EMDB.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(1216) EMDB.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
460000005B010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(1216) EMDB.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(1216) EMDB.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
Executable files
13
Suspicious files
10
Text files
146
Unknown types
0

Dropped files

PID
Process
Filename
Type
2024setup_EMDB.tmpC:\Program Files\EMDB\EMDB.exeexecutable
MD5:63480D4E403370D057641307FC6A6FCB
SHA256:5A826A817297F575F8D5131822A229107A73277FFC3713FC6AF255B17E5A3093
2024setup_EMDB.tmpC:\Program Files\EMDB\languages\Arabic.lngtext
MD5:441B21D6E8698DA3049FDFA586FCADC9
SHA256:E7059774D964A9078C4F7C3A896C64038D30DDAD51CC207BCE3A931A6ABAE029
2024setup_EMDB.tmpC:\Program Files\EMDB\AutoUpdater2.exeexecutable
MD5:1C8C7DC4E680AA82B01B9FA4FC39F88D
SHA256:68690148DA9064A6165B90F5CF552F8ECD334704F38E9A3ACB6E9BBBA2DFDF84
2420setup_EMDB.exeC:\Users\admin\AppData\Local\Temp\is-2D8HQ.tmp\setup_EMDB.tmpexecutable
MD5:9303156631EE2436DB23827E27337BE4
SHA256:BAE22F27C12BCE1FAEB64B6EB733302AFF5867BAA8EED832397A7CE284A86FF4
2024setup_EMDB.tmpC:\Users\admin\AppData\Local\Temp\is-0POPE.tmp\_isetup\_shfoldr.dllexecutable
MD5:92DC6EF532FBB4A5C3201469A5B5EB63
SHA256:9884E9D1B4F8A873CCBD81F8AD0AE257776D2348D027D811A56475E028360D87
2024setup_EMDB.tmpC:\Program Files\EMDB\unins000.exeexecutable
MD5:60C7FCF18D2F3B62692D15B2B0ECD6F8
SHA256:1C71F02C2AB6BB8309781C3A7658BC4CEF10CCD519F2DF4EADFD62C5990A1391
2024setup_EMDB.tmpC:\Program Files\EMDB\is-0V8G2.tmpexecutable
MD5:1C8C7DC4E680AA82B01B9FA4FC39F88D
SHA256:68690148DA9064A6165B90F5CF552F8ECD334704F38E9A3ACB6E9BBBA2DFDF84
2024setup_EMDB.tmpC:\Program Files\EMDB\is-GS2I2.tmpexecutable
MD5:63480D4E403370D057641307FC6A6FCB
SHA256:5A826A817297F575F8D5131822A229107A73277FFC3713FC6AF255B17E5A3093
2024setup_EMDB.tmpC:\Program Files\EMDB\languages\is-G4GO8.tmptext
MD5:7057FC512E6A79B162221D8255D5AE5F
SHA256:5FEF34242AEC96BD34184EA9D377C2438764D8852C2107AC8868D07E83E7BB15
2024setup_EMDB.tmpC:\Program Files\EMDB\languages\is-0AFPT.tmptext
MD5:C52131E80582C829998D505AC17DC121
SHA256:EE1E2B5D5ECFA0F48C256343A9E265A6E8812A2A8B7840690F4D1C979AF1CDEA
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
8
DNS requests
1
Threats
3

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1216
EMDB.exe
GET
200
81.169.145.156:80
http://www.emdb.eu/autoupdate/autoupdate.script
unknown
text
8.17 Kb
unknown
GET
200
81.169.145.156:80
http://www.emdb.eu/
unknown
html
9.81 Kb
unknown
1748
AutoUpdater2.exe
GET
81.169.145.156:80
http://www.emdb.eu/autoupdate/autoupdate.script
unknown
unknown
1216
EMDB.exe
GET
200
81.169.145.156:80
http://www.emdb.eu/autoupdate/autoupdate.script
unknown
text
8.17 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
1216
EMDB.exe
81.169.145.156:80
www.emdb.eu
Strato AG
DE
unknown
1748
AutoUpdater2.exe
81.169.145.156:80
www.emdb.eu
Strato AG
DE
unknown

DNS requests

Domain
IP
Reputation
www.emdb.eu
  • 81.169.145.156
unknown

Threats

PID
Process
Class
Message
1216
EMDB.exe
A Network Trojan was detected
ET HUNTING Suspicious UA (^IE[ds])
1748
AutoUpdater2.exe
A Network Trojan was detected
ET HUNTING Suspicious UA (^IE[ds])
1216
EMDB.exe
A Network Trojan was detected
ET HUNTING Suspicious UA (^IE[ds])
No debug info