| File name: | OpenShellSetup_4_4_195.exe |
| Full analysis: | https://app.any.run/tasks/1aed91f1-e102-4cbd-b78e-c67eafc203ca |
| Verdict: | Malicious activity |
| Analysis date: | February 13, 2025, 00:40:50 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, 6 sections |
| MD5: | FEB30D464607626F3EB3FAF91CAD2D82 |
| SHA1: | 93FC9FABFF60AF8F357AB2E7EE58562E02A5DF45 |
| SHA256: | DC79E3ABEBD128D7F44FA8F03A4E660B5F60B011F7BCF374B35C18A741F5818A |
| SSDEEP: | 98304:dyu3a7BC7fGnWqboMC68WsaI33Bjxug50/FK2PtIxVIuRLNV+QOUiZPG48ZRKHWa:7U+aNBFZMlJkE |
| .exe | | | Win64 Executable (generic) (76.4) |
|---|---|---|
| .exe | | | Win32 Executable (generic) (12.4) |
| .exe | | | Generic Win/DOS Executable (5.5) |
| .exe | | | DOS Executable Generic (5.5) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2025:01:04 15:35:42+00:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 14.42 |
| CodeSize: | 79872 |
| InitializedDataSize: | 7543808 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x2627 |
| OSVersion: | 6 |
| ImageVersion: | - |
| SubsystemVersion: | 6 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 4.4.195.0 |
| ProductVersionNumber: | 4.4.195.0 |
| FileFlagsMask: | 0x0017 |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| CompanyName: | Open-Shell |
| FileDescription: | Adds classic shell features to Windows 7 and Windows 8 |
| FileVersion: | 4.4.195 |
| InternalName: | OpenShellSetup |
| LegalCopyright: | Copyright (C) 2017-2018, The Open-Shell Team |
| OriginalFileName: | OpenShellSetup.exe |
| ProductName: | Open-Shell |
| ProductVersion: | 4.4.195 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1480 | "C:\Windows\System32\MsiExec.exe" /Y "C:\Program Files\Open-Shell\ClassicExplorer64.dll" | C:\Windows\System32\msiexec.exe | — | msiexec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Exit code: 0 Version: 5.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 3848 | "C:\Windows\syswow64\MsiExec.exe" /Y "C:\WINDOWS\SysWOW64\StartMenuHelper32.dll" | C:\Windows\SysWOW64\msiexec.exe | — | msiexec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Exit code: 0 Version: 5.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 3876 | "C:\Program Files\Open-Shell\StartMenu.exe" | C:\Program Files\Open-Shell\StartMenu.exe | — | msiexec.exe | |||||||||||
User: admin Company: Open-Shell Integrity Level: MEDIUM Description: Open-Shell Menu Version: 4.4.195 Modules
| |||||||||||||||
| 4120 | C:\WINDOWS\SysWOW64\DllHost.exe /Processid:{06622D85-6856-4460-8DE1-A81921B41C4B} | C:\Windows\SysWOW64\dllhost.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: COM Surrogate Exit code: 0 Version: 10.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 4132 | "C:\Windows\syswow64\MsiExec.exe" /Y "C:\Program Files\Open-Shell\ClassicExplorer32.dll" | C:\Windows\SysWOW64\msiexec.exe | — | msiexec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Exit code: 0 Version: 5.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 4488 | C:\WINDOWS\Explorer.EXE | C:\Windows\explorer.exe | — | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Explorer Version: 10.0.19041.3758 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6084 | "C:\Windows\System32\MsiExec.exe" /Y "C:\WINDOWS\system32\StartMenuHelper64.dll" | C:\Windows\System32\msiexec.exe | — | msiexec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Exit code: 0 Version: 5.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6240 | "C:\Users\admin\AppData\Local\Temp\OpenShellSetup_4_4_195.exe" | C:\Users\admin\AppData\Local\Temp\OpenShellSetup_4_4_195.exe | explorer.exe | ||||||||||||
User: admin Company: Open-Shell Integrity Level: MEDIUM Description: Adds classic shell features to Windows 7 and Windows 8 Exit code: 0 Version: 4.4.195 Modules
| |||||||||||||||
| 6260 | msiexec.exe /i "C:\ProgramData\OpenShellSetup64_4_4_195.msi" | C:\Windows\SysWOW64\msiexec.exe | — | OpenShellSetup_4_4_195.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Exit code: 0 Version: 5.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6300 | C:\WINDOWS\system32\msiexec.exe /V | C:\Windows\System32\msiexec.exe | services.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows® installer Version: 5.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| (PID) Process: | (4488) explorer.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:0000000000080306 |
| Operation: | write | Name: | VirtualDesktop |
Value: 1000000030304456A48A294F7A40804AB924005FF030B61F | |||
| (PID) Process: | (4488) explorer.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:00000000000502AA |
| Operation: | write | Name: | VirtualDesktop |
Value: 1000000030304456A48A294F7A40804AB924005FF030B61F | |||
| (PID) Process: | (4488) explorer.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:00000000001002D2 |
| Operation: | write | Name: | VirtualDesktop |
Value: 1000000030304456A48A294F7A40804AB924005FF030B61F | |||
| (PID) Process: | (4488) explorer.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:00000000000502AA |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (4488) explorer.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:000000000009007E |
| Operation: | write | Name: | VirtualDesktop |
Value: 1000000030304456A48A294F7A40804AB924005FF030B61F | |||
| (PID) Process: | (4488) explorer.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:00000000001002D2 |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (4488) explorer.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:00000000000702AA |
| Operation: | write | Name: | VirtualDesktop |
Value: 1000000030304456A48A294F7A40804AB924005FF030B61F | |||
| (PID) Process: | (4488) explorer.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:000000000009007E |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (4488) explorer.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:00000000000702AA |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (4488) explorer.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:00000000000A007E |
| Operation: | write | Name: | VirtualDesktop |
Value: 1000000030304456A48A294F7A40804AB924005FF030B61F | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6240 | OpenShellSetup_4_4_195.exe | C:\ProgramData\OpenShellSetup64_4_4_195.msi | — | |
MD5:— | SHA256:— | |||
| 6300 | msiexec.exe | C:\System Volume Information\SPP\metadata-2 | — | |
MD5:— | SHA256:— | |||
| 6300 | msiexec.exe | C:\Windows\Installer\13c1fb.msi | — | |
MD5:— | SHA256:— | |||
| 6300 | msiexec.exe | C:\Program Files\Open-Shell\Skins\Classic Skin.skin7 | executable | |
MD5:FAA7CA24C9006EF763C6F457B1DC0DFA | SHA256:7BF49E5A5D9E6E47F89BCFE6381C2E7FF3BAFB004866B8BB9F0DF1A436250742 | |||
| 6300 | msiexec.exe | C:\Program Files\Open-Shell\ClassicExplorer32.dll | executable | |
MD5:558609ADB9FE385662C6CD8C7D869829 | SHA256:A4E4E14B4C8B652D6793D0AADA0EF9C3274685BE392A6651C08D4FAE39D8A369 | |||
| 6300 | msiexec.exe | C:\Windows\Temp\~DFB5F8398BD27A6EAC.TMP | binary | |
MD5:938554626AAD6005E11C02BF74728FAF | SHA256:8838EA5D1C006DB7FC34B3D94B9D740206356666ECD58B7F43F53EBDF3BEEC77 | |||
| 6300 | msiexec.exe | C:\Program Files\Open-Shell\Skins\Immersive.skin | executable | |
MD5:46FE65CFACF3F046272FEE22EB387F1B | SHA256:62C5330A3C746FEBF3B0D1019EE2AD860A6287C3855D93120E7161DCF327187D | |||
| 6300 | msiexec.exe | C:\System Volume Information\SPP\snapshot-2 | binary | |
MD5:4350FF04B072A0586986EAD35B104A5F | SHA256:AB16CB2D26C839DD04630403911AAC0091599091048A5179367B4FFEBAE30DBF | |||
| 6300 | msiexec.exe | C:\Windows\Temp\~DFB1B5AFEDA1C1F353.TMP | binary | |
MD5:BF619EAC0CDF3F68D496EA9344137E8B | SHA256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560 | |||
| 6300 | msiexec.exe | C:\Program Files\Open-Shell\ClassicExplorerSettings.exe | executable | |
MD5:63BD2D008A91E7FB95FF1C529A6E59F4 | SHA256:992FD6C95C730709B47AF4F8D39F9F5558139603DD0030F7290122EF0DC4D89D | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | GET | 200 | 184.30.131.245:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D | unknown | — | — | whitelisted |
2736 | svchost.exe | GET | 200 | 2.21.245.180:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
4712 | MoUsoCoreWorker.exe | GET | 200 | 2.21.245.180:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
— | — | GET | 200 | 2.21.245.180:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
4712 | MoUsoCoreWorker.exe | GET | 200 | 23.58.102.107:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
— | — | GET | 200 | 23.58.102.107:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
2736 | svchost.exe | GET | 200 | 23.58.102.107:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
4488 | explorer.exe | GET | 200 | 172.64.149.23:80 | http://ocsp.comodoca.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRTtU9uFqgVGHhJwXZyWCNXmVR5ngQUoBEKIz6W8Qfs4q8p74Klf9AwpLQCEFZnHQTqT5lMbxCBR1nSdZQ%3D | unknown | — | — | whitelisted |
— | — | GET | 200 | 172.64.149.23:80 | http://ocsp.usertrust.com/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBSr83eyJy3njhjVpn5bEpfc6MXawQQUOuEJhtTPGcKWdnRJdtzgNcZjY5oCEQDzZE5rbgBQI34JRr174fUd | unknown | — | — | whitelisted |
4488 | explorer.exe | GET | 200 | 104.18.38.233:80 | http://ocsp.sectigo.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTPlNxcMEqnlIVyH5VuZ4lawhZX3QQU9oUKOxGG4QR9DqoLLNLuzGR7e64CECoW9cIBGAf3CpJj3Tw5qfI%3D | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
— | — | 192.168.100.255:137 | — | — | — | whitelisted |
5064 | SearchApp.exe | 95.100.248.219:443 | www.bing.com | Akamai International B.V. | NL | whitelisted |
— | — | 184.30.131.245:80 | ocsp.digicert.com | AKAMAI-AS | US | whitelisted |
2736 | svchost.exe | 2.21.245.180:80 | crl.microsoft.com | Akamai International B.V. | NL | whitelisted |
4712 | MoUsoCoreWorker.exe | 2.21.245.180:80 | crl.microsoft.com | Akamai International B.V. | NL | whitelisted |
— | — | 2.21.245.180:80 | crl.microsoft.com | Akamai International B.V. | NL | whitelisted |
4712 | MoUsoCoreWorker.exe | 23.58.102.107:80 | www.microsoft.com | AKAMAI-AS | IN | whitelisted |
2736 | svchost.exe | 23.58.102.107:80 | www.microsoft.com | AKAMAI-AS | IN | whitelisted |
— | — | 23.58.102.107:80 | www.microsoft.com | AKAMAI-AS | IN | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
www.bing.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
api.github.com |
| whitelisted |
ocsp.comodoca.com |
| whitelisted |
ocsp.usertrust.com |
| whitelisted |
ocsp.sectigo.com |
| whitelisted |