| File name: | AE-Setup.exe |
| Full analysis: | https://app.any.run/tasks/55df6e89-80e2-484e-b6c6-9e7f241eed7c |
| Verdict: | Malicious activity |
| Analysis date: | February 24, 2024, 17:08:20 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | D97283061514C75F1D9A5B55A1C52DBD |
| SHA1: | 834A52B63B15C4D13CF47C9C672D2991E9562610 |
| SHA256: | D633D10734D4C4D80BEFE4D7F03CB6542F551C4D3D13672729D700A38B169086 |
| SSDEEP: | 98304:HSRted+iJjL5PX8yhvwt6ikAxUkbJfZFiahUcKRKwgN+HkRAkyqCT6AWL6I1QCYM:QWBoYBF0Nd |
| .exe | | | Win32 Executable Microsoft Visual Basic 6 (84.4) |
|---|---|---|
| .dll | | | Win32 Dynamic Link Library (generic) (6.7) |
| .exe | | | Win32 Executable (generic) (4.6) |
| .exe | | | Generic Win/DOS Executable (2) |
| .exe | | | DOS Executable Generic (2) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2017:08:16 04:42:04+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 802816 |
| InitializedDataSize: | 7258112 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x1aa4 |
| OSVersion: | 4 |
| ImageVersion: | 2.1 |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 2.1.0.0 |
| ProductVersionNumber: | 2.1.0.0 |
| FileFlagsMask: | 0x0000 |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| CompanyName: | Anti Explorator ApS |
| FileDescription: | Anti Explorator |
| LegalCopyright: | © Anti Explorator ApS |
| ProductName: | Anti Explorator |
| FileVersion: | 2.01 |
| ProductVersion: | 2.01 |
| InternalName: | SETUP |
| OriginalFileName: | SETUP.EXE |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 316 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3248 --field-trial-handle=1276,i,2981395471495451762,11096657823434267235,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 480 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1208 --field-trial-handle=1332,i,2583112756625278965,2653380697239822276,131072 /prefetch:3 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 572 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=2240 --field-trial-handle=1276,i,2981395471495451762,11096657823434267235,131072 /prefetch:1 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 764 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" "--metrics-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=109.0.5414.149 "--annotation=exe=C:\Program Files\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win32 "--annotation=prod=Microsoft Edge" --annotation=ver=109.0.1518.115 --initial-client-data=0xc8,0xcc,0xd0,0x9c,0xdc,0x69edf598,0x69edf5a8,0x69edf5b4 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 796 | "C:\Program Files\Anti Explorator\BgProcess.exe" -Embedding | C:\Program Files\Anti Explorator\BgProcess.exe | — | AntiExplorator.exe | |||||||||||
User: admin Company: Anti Explorator ApS Integrity Level: HIGH Description: BgProcess Exit code: 0 Version: 2.01 Modules
| |||||||||||||||
| 1232 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1296 --field-trial-handle=1332,i,2583112756625278965,2653380697239822276,131072 /prefetch:2 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1380 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --first-renderer-process --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --mojo-platform-channel-handle=2220 --field-trial-handle=1276,i,2981395471495451762,11096657823434267235,131072 /prefetch:1 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1692 | schtasks /create /sc onlogon /tn "AVEXTONENGX" /rl highest /tr "'C:\Program Files\Anti Explorator\BgProcess.exe' -Embedding" /ru Users /f | C:\Windows\System32\schtasks.exe | — | AE-Setup.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Manages scheduled tasks Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1824 | "C:\Program Files\Anti Explorator\AntiExplorator.exe" | C:\Program Files\Anti Explorator\AntiExplorator.exe | — | AE-Setup.exe | |||||||||||
User: admin Company: Anti Explorator ApS Integrity Level: HIGH Description: Anti Explorator Exit code: 0 Version: 2.01 Modules
| |||||||||||||||
| 1836 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=3548 --field-trial-handle=1276,i,2981395471495451762,11096657823434267235,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| (PID) Process: | (2964) AE-Setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1E2015E9-9DC8-4066-988A-43B7476CE125}\TypeLib |
| Operation: | write | Name: | Version |
Value: 1.2 | |||
| (PID) Process: | (2964) AE-Setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{CFA593F6-CA48-4A95-98A7-86DF81BCAB56}\TypeLib |
| Operation: | write | Name: | Version |
Value: 1.2 | |||
| (PID) Process: | (2964) AE-Setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9BC8C4AB-7C85-4D1C-A2DD-7EA13928A942}\TypeLib |
| Operation: | write | Name: | Version |
Value: 1.2 | |||
| (PID) Process: | (2964) AE-Setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{52B7AE94-83FC-45E6-9A54-E23CE0086DE1}\TypeLib |
| Operation: | write | Name: | Version |
Value: 1.2 | |||
| (PID) Process: | (2964) AE-Setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FE04D833-A5D3-4D70-B341-98620DD6F2AC}\TypeLib |
| Operation: | write | Name: | Version |
Value: 1.2 | |||
| (PID) Process: | (2964) AE-Setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{3AA45B2D-7725-4D86-AD7D-34D057C781F0}\TypeLib |
| Operation: | write | Name: | Version |
Value: 1.2 | |||
| (PID) Process: | (2964) AE-Setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6FED11D8-EA11-4F5E-BD6D-4F6F65B08412}\TypeLib |
| Operation: | write | Name: | Version |
Value: 1.2 | |||
| (PID) Process: | (2964) AE-Setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E6207BFB-6934-47E0-80FB-472012A5CD19}\TypeLib |
| Operation: | write | Name: | Version |
Value: 1.2 | |||
| (PID) Process: | (2964) AE-Setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{349DF6A8-3B1B-48DE-BAE6-55F330F4BA0A}\TypeLib |
| Operation: | write | Name: | Version |
Value: 1.2 | |||
| (PID) Process: | (2964) AE-Setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6FB1F0AD-B2DD-41FF-9FD9-EEDE1C851AAE}\TypeLib |
| Operation: | write | Name: | Version |
Value: 1.2 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2964 | AE-Setup.exe | C:\Program Files\Anti Explorator\Help\da-DK\activate.html | html | |
MD5:FF3AC88DF395BF2B1BA40FFA0CEEF49A | SHA256:034A8402C8A47794C687E1701C56D3E56597F6C5DFDB7C4DE4D057C17F4CC596 | |||
| 2964 | AE-Setup.exe | C:\Windows\Temp\inst_soft_package.tmp | compressed | |
MD5:412804613EB2312AC5298AAB6E7C7559 | SHA256:DAFB069A61133C64A181DA614D8C1B81A81D5EE870F9DD9F4153950FB041E277 | |||
| 2964 | AE-Setup.exe | C:\Program Files\Anti Explorator\AntiExplorator.exe | executable | |
MD5:23740954C0892A8E7C989E40B8F66A07 | SHA256:1B41B48DC2A5E807D4EF2A542572B52F0E49E3B808912D2A21123D37912134B2 | |||
| 2964 | AE-Setup.exe | C:\Program Files\Anti Explorator\Help\da-DK\pushmsgs.html | html | |
MD5:604ADAE033787BB8A8F4445F69C8EB58 | SHA256:1A251EAFD97CC2E7FE3A3F9A33BD1D167019F5E0859B6D1D004DB5A11CE1C1B4 | |||
| 2964 | AE-Setup.exe | C:\Program Files\Anti Explorator\Help\da-DK\improve.html | html | |
MD5:96E107AB7344DA3C689D8496172F44B1 | SHA256:E1EAD5B5EF7974EAF2B6744BA1777BBD0A2F4095B3312098D25E70B02F177016 | |||
| 2964 | AE-Setup.exe | C:\Windows\System32\winarchextrcmod.dll | executable | |
MD5:C97F49F22861FF826883EF84A020EDE5 | SHA256:43CED30A4E5A98EBD8C79FA87529B519A04887A886A743488571A819721D5660 | |||
| 2964 | AE-Setup.exe | C:\Program Files\Anti Explorator\Help\da-DK\scandone.html | html | |
MD5:FB3009CE7ED4E90639DDA97201D94867 | SHA256:BB5A68204BE354E6EDE9ED3A8539F3E22C006B0634EB8DD4052B5CCF7B097AB0 | |||
| 2964 | AE-Setup.exe | C:\Program Files\Anti Explorator\Help\da-DK\setup.html | html | |
MD5:51AA9AF160E38E1BB3AA73D9C96DDB4A | SHA256:F690B07C769B0ADD91CB08B65E7BEA0A9246F1D1DB2D794DB6CA8E54F11B0B28 | |||
| 2964 | AE-Setup.exe | C:\Program Files\Anti Explorator\Help\da-DK\scantypes.html | html | |
MD5:E3261D8FBBF75DFAFB5A50A17EF5DFA1 | SHA256:4BFBD5C06AF39CE85B80ADF1339EC198125429A1A19C34A2EC2886106B5EDFFF | |||
| 2964 | AE-Setup.exe | C:\Program Files\Anti Explorator\Help\da-DK\update.html | html | |
MD5:9E2126024667EEEE0C73F27215A29C40 | SHA256:E0936D36C24D7E1A9398AD3FE5668537E190335B5B6FB033D1FF2331947D6C3A | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2596 | Update.exe | GET | 200 | 104.108.145.136:80 | http://x1.c.lencr.org/ | unknown | binary | 717 b | unknown |
2596 | Update.exe | GET | 304 | 93.184.221.240:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?f662c1db8f54f176 | unknown | — | — | unknown |
2596 | Update.exe | GET | 200 | 23.217.106.17:80 | http://r3.o.lencr.org/MFMwUTBPME0wSzAJBgUrDgMCGgUABBRI2smg%2ByvTLU%2Fw3mjS9We3NfmzxAQUFC6zF7dYVsuuUAlA5h%2BvnYsUwsYCEgPdqN5Uw6nzYJEOVjWdZCO%2FpA%3D%3D | unknown | binary | 503 b | unknown |
2596 | Update.exe | GET | 200 | 93.184.221.240:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?afa14730405214d1 | unknown | compressed | 65.2 Kb | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
2596 | Update.exe | 18.184.117.135:443 | anti-explorator.com | AMAZON-02 | DE | unknown |
2620 | msedge.exe | 239.255.255.250:1900 | — | — | — | unknown |
2596 | Update.exe | 93.184.221.240:80 | ctldl.windowsupdate.com | EDGECAST | GB | whitelisted |
2984 | msedge.exe | 18.184.117.135:443 | anti-explorator.com | AMAZON-02 | DE | unknown |
2984 | msedge.exe | 204.79.197.239:443 | edge.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | unknown |
2984 | msedge.exe | 13.107.42.16:443 | config.edge.skype.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
2596 | Update.exe | 104.108.145.136:80 | x1.c.lencr.org | AKAMAI-AS | DE | unknown |
Domain | IP | Reputation |
|---|---|---|
anti-explorator.com |
| unknown |
ctldl.windowsupdate.com |
| whitelisted |
www.anti-explorator.com |
| unknown |
edge.microsoft.com |
| whitelisted |
config.edge.skype.com |
| whitelisted |
x1.c.lencr.org |
| whitelisted |
r3.o.lencr.org |
| shared |
www.bing.com |
| whitelisted |
ajax.googleapis.com |
| whitelisted |
fonts.googleapis.com |
| whitelisted |