File name:

OmegaLog161.exe

Full analysis: https://app.any.run/tasks/53d712bb-46d1-4750-9565-f9eb9ce087d2
Verdict: Malicious activity
Analysis date: May 13, 2024, 15:49:08
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

5CBECB586DD46F1D189DA0B9A0784D24

SHA1:

78E9998B9354AFC3755406DFEED85BC16E6607D1

SHA256:

DDFCF49A171EE272DAAD1DC401D4913A1D16E711EA23F502853CE5F622B5B510

SSDEEP:

98304:iJeSfxnHQ4aZlPSs9mZAv9h+9UrML7RJffsC0fBsUkDBtap/jC052JWNXnyCiffZ:rS6EzQHkMJe0tPDlMlTPfnYsjT

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • OmegaLog161.exe (PID: 4076)
      • irsetup.exe (PID: 1020)
      • USBDataLogInstaller_x86.exe (PID: 1876)
      • drvinst.exe (PID: 2136)
      • msiexec.exe (PID: 1652)
      • vcredist_x86.exe (PID: 304)
    • Actions looks like stealing of personal data

      • irsetup.exe (PID: 1020)
    • Creates a writable file in the system directory

      • drvinst.exe (PID: 2136)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • irsetup.exe (PID: 1020)
      • USBDataLogInstaller_x86.exe (PID: 1876)
      • vcredist_x86.exe (PID: 304)
      • msiexec.exe (PID: 1652)
    • Creates/Modifies COM task schedule object

      • irsetup.exe (PID: 1020)
    • Reads security settings of Internet Explorer

      • OmegaLog161.exe (PID: 4076)
    • Executable content was dropped or overwritten

      • OmegaLog161.exe (PID: 4076)
      • irsetup.exe (PID: 1020)
      • USBDataLogInstaller_x86.exe (PID: 1876)
      • drvinst.exe (PID: 2136)
      • vcredist_x86.exe (PID: 304)
    • Drops a system driver (possible attempt to evade defenses)

      • irsetup.exe (PID: 1020)
      • USBDataLogInstaller_x86.exe (PID: 1876)
      • drvinst.exe (PID: 2136)
    • Reads the Internet Settings

      • OmegaLog161.exe (PID: 4076)
    • Creates a software uninstall entry

      • irsetup.exe (PID: 1020)
      • USBDataLogInstaller_x86.exe (PID: 1876)
    • Reads the Windows owner or organization settings

      • irsetup.exe (PID: 1020)
      • msiexec.exe (PID: 1652)
    • Creates files in the driver directory

      • drvinst.exe (PID: 2136)
    • Checks Windows Trust Settings

      • drvinst.exe (PID: 2136)
      • msiexec.exe (PID: 1652)
    • Starts a Microsoft application from unusual location

      • vcredist_x86.exe (PID: 304)
    • The process drops C-runtime libraries

      • msiexec.exe (PID: 1652)
  • INFO

    • Checks supported languages

      • irsetup.exe (PID: 1020)
      • OmegaLog161.exe (PID: 4076)
      • USBDataLogInstaller_x86.exe (PID: 1876)
      • drvinst.exe (PID: 2136)
      • install.exe (PID: 316)
      • msiexec.exe (PID: 1652)
      • vcredist_x86.exe (PID: 304)
    • Reads the computer name

      • OmegaLog161.exe (PID: 4076)
      • irsetup.exe (PID: 1020)
      • USBDataLogInstaller_x86.exe (PID: 1876)
      • drvinst.exe (PID: 2136)
      • msiexec.exe (PID: 1652)
      • vcredist_x86.exe (PID: 304)
      • install.exe (PID: 316)
    • Create files in a temporary directory

      • OmegaLog161.exe (PID: 4076)
      • irsetup.exe (PID: 1020)
      • USBDataLogInstaller_x86.exe (PID: 1876)
      • install.exe (PID: 316)
      • msiexec.exe (PID: 1652)
    • Creates files in the program directory

      • irsetup.exe (PID: 1020)
    • Reads the machine GUID from the registry

      • USBDataLogInstaller_x86.exe (PID: 1876)
      • drvinst.exe (PID: 2136)
      • vcredist_x86.exe (PID: 304)
      • install.exe (PID: 316)
      • msiexec.exe (PID: 1652)
    • Reads the software policy settings

      • drvinst.exe (PID: 2136)
      • msiexec.exe (PID: 1652)
    • Reads Environment values

      • vcredist_x86.exe (PID: 304)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 1652)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 1652)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.8)
.exe | Win32 EXE Yoda's Crypter (36.4)
.dll | Win32 Dynamic Link Library (generic) (9)
.exe | Win32 Executable (generic) (6.1)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2019:01:03 19:13:08+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 10
CodeSize: 23552
InitializedDataSize: 48640
UninitializedDataSize: -
EntryPoint: 0x2ce1
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 9.5.3.0
ProductVersionNumber: 9.5.3.0
FileFlagsMask: 0x003f
FileFlags: Private build
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
Comments: Created with Setup Factory
FileDescription: Setup Application
FileVersion: 9.5.3.0
InternalName: suf_launch
LegalCopyright: Setup Engine Copyright © 2004-2019 Indigo Rose Corporation
LegalTrademarks: Setup Factory is a trademark of Indigo Rose Corporation.
OriginalFileName: suf_launch.exe
ProductName: Setup Factory Runtime
ProductVersion: 9.5.3.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
46
Monitored processes
8
Malicious processes
6
Suspicious processes
0

Behavior graph

Click at the process to see the details
start omegalog161.exe irsetup.exe usbdataloginstaller_x86.exe drvinst.exe vcredist_x86.exe install.exe no specs msiexec.exe omegalog161.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
304"C:\Users\admin\AppData\Local\Temp\_ir_sf_temp_0\vcredist_x86.exe" /qC:\Users\admin\AppData\Local\Temp\_ir_sf_temp_0\vcredist_x86.exe
irsetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Visual C++ 2008 Redistributable Setup
Exit code:
0
Version:
9.0.21022.218
Modules
Images
c:\users\admin\appdata\local\temp\_ir_sf_temp_0\vcredist_x86.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
316c:\887d6db72e20fd7649\.\install.exe /qC:\887d6db72e20fd7649\install.exevcredist_x86.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
External Installer
Exit code:
0
Version:
9.0.21022.218 built by: QFEN-1
Modules
Images
c:\887d6db72e20fd7649\install.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
1020"C:\Users\admin\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe" __IRAOFF:1797666 "__IRAFN:C:\Users\admin\AppData\Local\Temp\OmegaLog161.exe" "__IRCT:0" "__IRTSS:0" "__IRSID:S-1-5-21-1302019708-1500728564-335382590-1000"C:\Users\admin\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe
OmegaLog161.exe
User:
admin
Company:
Indigo Rose Corporation
Integrity Level:
HIGH
Description:
Setup Application
Exit code:
0
Version:
9.5.3.0
Modules
Images
c:\users\admin\appdata\local\temp\_ir_sf_temp_0\irsetup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\gdi32.dll
1652C:\Windows\system32\msiexec.exe /VC:\Windows\System32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1876"C:\Program Files\OmegaLog\USBDriverV6.7.6\USBDataLogInstaller_x86.exe"C:\Program Files\OmegaLog\USBDriverV6.7.6\USBDataLogInstaller_x86.exe
irsetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Driver Package Installer
Exit code:
256
Version:
2.1
Modules
Images
c:\program files\omegalog\usbdriverv6.7.6\usbdataloginstaller_x86.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2136DrvInst.exe "4" "8" "C:\Users\admin\AppData\Local\Temp\{0e5b1b00-1061-7ed1-711a-b832c552f63f}\slabvcp.inf" "0" "64f3afc8f" "000002BC" "WinSta0\Default" "00000330" "208" "c:\program files\omegalog\usbdriverv6.7.6"C:\Windows\System32\drvinst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
3972"C:\Users\admin\AppData\Local\Temp\OmegaLog161.exe" C:\Users\admin\AppData\Local\Temp\OmegaLog161.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup Application
Exit code:
3221226540
Version:
9.5.3.0
Modules
Images
c:\users\admin\appdata\local\temp\omegalog161.exe
c:\windows\system32\ntdll.dll
4076"C:\Users\admin\AppData\Local\Temp\OmegaLog161.exe" C:\Users\admin\AppData\Local\Temp\OmegaLog161.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup Application
Exit code:
0
Version:
9.5.3.0
Modules
Images
c:\users\admin\appdata\local\temp\omegalog161.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
Total events
12 563
Read events
12 293
Write events
255
Delete events
15

Modification events

(PID) Process:(4076) OmegaLog161.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(4076) OmegaLog161.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(4076) OmegaLog161.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(4076) OmegaLog161.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(1020) irsetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{399CB6C4-7312-11D2-B4D9-00105A0422DF}\InprocServer32
Operation:writeName:ThreadingModel
Value:
Apartment
(PID) Process:(1020) irsetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{959F94FD-DD1E-11D2-B559-00105A0422DF}\InprocServer32
Operation:writeName:ThreadingModel
Value:
Apartment
(PID) Process:(1020) irsetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{399CB6C3-7312-11D2-B4D9-00105A0422DF}\TypeLib
Operation:writeName:Version
Value:
1.0
(PID) Process:(1020) irsetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OmegaLog_Supco_Software
Operation:writeName:DisplayName
Value:
OmegaLog
(PID) Process:(1020) irsetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OmegaLog_Supco_Software
Operation:writeName:NoModify
Value:
1
(PID) Process:(1020) irsetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OmegaLog_Supco_Software
Operation:writeName:NoRepair
Value:
1
Executable files
56
Suspicious files
46
Text files
34
Unknown types
3

Dropped files

PID
Process
Filename
Type
1020irsetup.exeC:\Program Files\OmegaLog\OmegaLog.pdf
MD5:
SHA256:
1020irsetup.exeC:\Users\admin\AppData\Local\Temp\_ir_sf_temp_0\IRIMG2.JPGimage
MD5:0068EFA951114B30CBBF44CA6255917A
SHA256:4CDA756B8C77368451D116F39CF9918B54E741F84F3FC5B769A8096955C83003
1020irsetup.exeC:\Program Files\OmegaLog\Uninstall\uniC49A.tmpbinary
MD5:12B9AC4341CB74FFFAAB0E0F217E7D31
SHA256:9D4D239B3D66ACF885BE68220BB118B793F99F4C3135891EA0398D13A0E3BF9A
1020irsetup.exeC:\Windows\OmegaLog\uninstall.exeexecutable
MD5:68AC216F38A5F7C823712C216CA4B060
SHA256:748D48D246526E2A79EDCDE87255FFA5387E3BCC94F6CA5E59589E07E683CD80
1020irsetup.exeC:\Program Files\OmegaLog\Uninstall\uninstall.xmlxml
MD5:1BAB44EB8AE6EB54C1BFEF5BB45F7E12
SHA256:C888A27BF23C7B5D1DEF18094594B63E03001242367995B9720E83C1C5AFF782
1020irsetup.exeC:\Program Files\OmegaLog\HHActiveX.dllexecutable
MD5:87C6C4BA98D1173760109F88CFBB1DD1
SHA256:5FE9A435CCA3F1C10FDC81B5569A787FA7021D3139D815044C6316D408158658
4076OmegaLog161.exeC:\Users\admin\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exeexecutable
MD5:68AC216F38A5F7C823712C216CA4B060
SHA256:748D48D246526E2A79EDCDE87255FFA5387E3BCC94F6CA5E59589E07E683CD80
4076OmegaLog161.exeC:\Users\admin\AppData\Local\Temp\_ir_sf_temp_0\lua5.1.dllexecutable
MD5:80D93D38BADECDD2B134FE4699721223
SHA256:C572A6103AF1526F97E708A229A532FD02100A52B949F721052107F1F55E0C59
1020irsetup.exeC:\Users\admin\AppData\Local\Temp\_ir_sf_temp_0\vcredist_x86.exeexecutable
MD5:13FE5682123396101F48215F92B7AE20
SHA256:A78A49BEAC7C78BDA45AC197B8F53C7EEFA970126759FE3D2D94569B1D5FC6AA
1020irsetup.exeC:\Program Files\OmegaLog\ROBOEX32.DLLexecutable
MD5:A24D86086CF890079E82F22F09C368AC
SHA256:601728814E3F6B8D9B4E804FAF28D6972BDF60CA2891B0F428545F5DFE030A19
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
2
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted

DNS requests

No data

Threats

No threats detected
No debug info