analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

mt4setup.exe

Full analysis: https://app.any.run/tasks/56717594-add1-4653-8d4e-004a6627389f
Verdict: Malicious activity
Analysis date: December 06, 2018, 03:36:42
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed
MD5:

7B8932B4736E937CD8D54FDCB53951CF

SHA1:

274C6DDEBD32264DAAF04557C777B863343D0E23

SHA256:

D9D6914DE366AFF54F569D4F66A89E9880CBCA636FB6BD556AE5260E4D87A2AA

SSDEEP:

24576:hGSLzjDbuQzky9B310b6a9/ZhbyPQkbEpjwTda6KPUdYlCrF8JN:hFLjyQzkyN0bZFZhuPipjwhaEY8h6N

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes settings of System certificates

      • mt4setup.exe (PID: 2124)
      • terminal.exe (PID: 3100)
  • SUSPICIOUS

    • Application launched itself

      • mt4setup.exe (PID: 3492)
    • Low-level read access rights to disk partition

      • terminal.exe (PID: 3100)
      • mt4setup.exe (PID: 2124)
    • Creates files in the user directory

      • mt4setup.exe (PID: 2124)
      • terminal.exe (PID: 3100)
      • metaeditor.exe (PID: 3608)
      • terminal.exe (PID: 3784)
    • Executable content was dropped or overwritten

      • mt4setup.exe (PID: 2124)
    • Reads internet explorer settings

      • mt4setup.exe (PID: 2124)
    • Creates a software uninstall entry

      • mt4setup.exe (PID: 2124)
    • Adds / modifies Windows certificates

      • mt4setup.exe (PID: 2124)
      • terminal.exe (PID: 3100)
    • Starts Internet Explorer

      • mt4setup.exe (PID: 2124)
    • Modifies the open verb of a shell class

      • terminal.exe (PID: 3100)
    • Changes IE settings (feature browser emulation)

      • terminal.exe (PID: 3100)
    • Connects to unusual port

      • terminal.exe (PID: 3784)
    • Creates files in the program directory

      • mt4setup.exe (PID: 2124)
  • INFO

    • Application launched itself

      • iexplore.exe (PID: 3468)
    • Changes internet zones settings

      • iexplore.exe (PID: 3468)
    • Reads internet explorer settings

      • iexplore.exe (PID: 2540)
    • Creates files in the user directory

      • iexplore.exe (PID: 2540)
    • Reads Internet Cache Settings

      • iexplore.exe (PID: 2540)
    • Dropped object may contain Bitcoin addresses

      • terminal.exe (PID: 3784)
    • Reads settings of System Certificates

      • terminal.exe (PID: 3784)
      • mt4setup.exe (PID: 2124)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable (generic) (52.9)
.exe | Generic Win/DOS Executable (23.5)
.exe | DOS Executable Generic (23.5)

EXIF

EXE

ProductVersion: 5.0.0.1882
ProductName: Setup
OriginalFileName: Setup
LegalTrademarks: MetaTrader
LegalCopyright: © 2000-2018, MetaQuotes Software Corp.
InternalName: Setup
FileVersion: 5.0.0.1882
FileDescription: Setup
CompanyName: MetaQuotes Software Corp.
Comments: https://www.metaquotes.net
CharacterSet: Unicode
LanguageCode: Neutral
FileSubtype: -
ObjectFileType: Dynamic link library
FileOS: Win32
FileFlags: (none)
FileFlagsMask: 0x003f
ProductVersionNumber: 5.0.0.1882
FileVersionNumber: 5.0.0.1882
Subsystem: Windows GUI
SubsystemVersion: 5.1
ImageVersion: -
OSVersion: 5.1
EntryPoint: 0x30e980
UninitializedDataSize: 2215936
InitializedDataSize: 159744
CodeSize: 987136
LinkerVersion: 14.14
PEType: PE32
TimeStamp: 1970:01:14 07:43:12+01:00
MachineType: Intel 386 or later, and compatibles
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
43
Monitored processes
9
Malicious processes
5
Suspicious processes
0

Behavior graph

Click at the process to see the details
start mt4setup.exe no specs mt4setup.exe terminal.exe iexplore.exe iexplore.exe explorer.exe no specs explorer.exe no specs terminal.exe metaeditor.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
3492"C:\Users\admin\AppData\Local\Temp\mt4setup.exe" C:\Users\admin\AppData\Local\Temp\mt4setup.exeexplorer.exe
User:
admin
Company:
MetaQuotes Software Corp.
Integrity Level:
MEDIUM
Description:
Setup
Exit code:
0
Version:
5.0.0.1882
2124"C:\Users\admin\AppData\Local\Temp\mt4setup.exe" C:\Users\admin\AppData\Local\Temp\mt4setup.exe
mt4setup.exe
User:
admin
Company:
MetaQuotes Software Corp.
Integrity Level:
HIGH
Description:
Setup
Exit code:
1
Version:
5.0.0.1882
3100"C:\Program Files\MetaTrader\terminal.exe" /installC:\Program Files\MetaTrader\terminal.exe
mt4setup.exe
User:
admin
Company:
MetaQuotes Software Corp.
Integrity Level:
HIGH
Description:
MetaTrader 5 Client Terminal
Exit code:
0
Version:
5.0.0.1940
3468"C:\Program Files\Internet Explorer\iexplore.exe" -nohomeC:\Program Files\Internet Explorer\iexplore.exe
mt4setup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Internet Explorer
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
2540"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3468 CREDAT:79873C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Internet Explorer
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
3868"C:\Windows\explorer.exe" "C:\Program Files\MetaTrader\terminal.exe"C:\Windows\explorer.exemt4setup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Explorer
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
3404C:\Windows\explorer.exe /factory,{75dff2b7-6936-4c06-a8bb-676a7b00b24b} -EmbeddingC:\Windows\explorer.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
3784"C:\Program Files\MetaTrader\terminal.exe" C:\Program Files\MetaTrader\terminal.exe
explorer.exe
User:
admin
Company:
MetaQuotes Software Corp.
Integrity Level:
MEDIUM
Description:
MetaTrader 5 Client Terminal
Version:
5.0.0.1940
3608"C:\Program Files\MetaTrader\metaeditor.exe" /compile:"C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\MQL5" /inc:"C:\Users\admin\AppData\Roaming\MetaQuotes\Terminal\F762D69EEEA9B4430D7F17C82167C844\MQL5" /time:0 /flg:0 /stop:se3560_1313921C:\Program Files\MetaTrader\metaeditor.exeterminal.exe
User:
admin
Company:
MetaQuotes Software Corp.
Integrity Level:
MEDIUM
Description:
MetaEditor
Version:
5.0.0.1940
Total events
1 422
Read events
1 232
Write events
0
Delete events
0

Modification events

No data
Executable files
2
Suspicious files
71
Text files
781
Unknown types
24

Dropped files

PID
Process
Filename
Type
2124mt4setup.exeC:\Users\admin\AppData\Local\Temp\CabAE73.tmp
MD5:
SHA256:
2124mt4setup.exeC:\Users\admin\AppData\Local\Temp\TarAE74.tmp
MD5:
SHA256:
2124mt4setup.exeC:\Users\admin\AppData\Local\Temp\CabAF31.tmp
MD5:
SHA256:
2124mt4setup.exeC:\Users\admin\AppData\Local\Temp\TarAF32.tmp
MD5:
SHA256:
2124mt4setup.exeC:\Program Files\MetaTrader\metaeditor.exe
MD5:
SHA256:
2124mt4setup.exeC:\Program Files\MetaTrader\Bases\Default\History\USDJPY\2018.hccbinary
MD5:97EBCF46EA7BB7760C5E8F455C77BF12
SHA256:CC361DA9E6479DE6FB9FB7BD94B7A2B44E8AA1462437E5F2185ED6301C8A29BB
2124mt4setup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015binary
MD5:FC89F0E1C493C102544FF24302EDD473
SHA256:42A6E0136914E9993F62EE9B3C134B567AFB3A58F67E521D2F1BD23658E9C140
2124mt4setup.exeC:\Users\admin\AppData\Roaming\MetaQuotes\WebInstall\mt5clw.pngcompressed
MD5:88B91937D29A0BC666A694784E12C448
SHA256:73C95A3D2DA09B3F6B49C8858C1815D69877D1662551EC34BE2DA8AD7EF75A4C
2124mt4setup.exeC:\Program Files\MetaTrader\Bases\Default\History\GBPUSD\2018.hccbinary
MD5:0F3100FDAC01537F86A7EA1C7AA0E188
SHA256:1CA08AD74CC9A20FCCB966BE6D002C50EE45DCFD55C2E2614159B208899E7021
2124mt4setup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\94308059B57B3142E455B38A6EB92015compressed
MD5:A902CF373E02F7DC34F456ED7449279C
SHA256:EA0C12AEDEA644678014991A96534145E85AA12CD8955396DFDC98A4FC96F0D5
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
3
TCP/UDP connections
95
DNS requests
14
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2124
mt4setup.exe
GET
200
205.185.216.42:80
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab
US
compressed
55.2 Kb
whitelisted
2124
mt4setup.exe
GET
200
205.185.216.42:80
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/47BEABC922EAE80E78783462A79F45C254FDE68B.crt
US
der
969 b
whitelisted
3468
iexplore.exe
GET
200
204.79.197.200:80
http://www.bing.com/favicon.ico
US
image
237 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2124
mt4setup.exe
47.74.14.49:443
Alibaba (China) Technology Co., Ltd.
JP
unknown
2124
mt4setup.exe
47.95.9.170:443
Hangzhou Alibaba Advertising Co.,Ltd.
CN
unknown
2124
mt4setup.exe
88.212.244.84:443
Servers.com, Inc.
RU
unknown
2124
mt4setup.exe
104.41.54.220:443
Microsoft Corporation
BR
whitelisted
2124
mt4setup.exe
119.235.249.82:443
PT. Raja Sepadan Abadi
ID
unknown
2124
mt4setup.exe
47.52.161.165:443
Alibaba (China) Technology Co., Ltd.
HK
unknown
2124
mt4setup.exe
47.100.195.238:443
Hangzhou Alibaba Advertising Co.,Ltd.
CN
unknown
2124
mt4setup.exe
78.140.180.86:443
content.mql5.com
Webzilla B.V.
NL
suspicious
2124
mt4setup.exe
138.201.201.91:443
c.mql5.com
Hetzner Online GmbH
DE
unknown
2124
mt4setup.exe
120.79.203.118:443
Hangzhou Alibaba Advertising Co.,Ltd.
CN
unknown

DNS requests

Domain
IP
Reputation
content.mql5.com
  • 78.140.180.86
suspicious
www.download.windowsupdate.com
  • 205.185.216.42
  • 205.185.216.10
  • 205.185.216.10
  • 205.185.216.10
whitelisted
www.mql5.com
  • 78.140.180.100
suspicious
www.bing.com
  • 204.79.197.200
  • 13.107.21.200
whitelisted
c.mql5.com
  • 138.201.201.91
  • 78.140.180.43
suspicious
connect.facebook.net
  • 31.13.75.12
whitelisted
msg1.mql5.com
  • 78.140.180.45
unknown
api1.mql5.com
  • 78.140.180.43
suspicious
msg2.mql5.com
  • 66.242.4.32
unknown
access.metatrader5.com
  • 78.140.180.198
unknown

Threats

PID
Process
Class
Message
3784
terminal.exe
unknown
SURICATA TCPv4 invalid checksum
No debug info