File name:

Clear-ManualsLibrary.b3003.SK041.ch.exe

Full analysis: https://app.any.run/tasks/050d51d0-2c6d-446e-ac2a-13de17ef1a03
Verdict: Malicious activity
Analysis date: April 29, 2024, 16:42:10
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

A196BF8E7BDADAC7A17007AD2F75BA2D

SHA1:

E7418C4025C3097BF7B05CC8B330E3A85A38186A

SHA256:

E161A46FE428D16D2D006C0C2415B36710278C7E273FE409E51010A2BC6404C9

SSDEEP:

98304:OkLC3YEPb56O965T3jP6g48WXyePqx/HB8K10vAUl+d6lfos53Uo8J:JCtb56O9CT3TF43yhh8iUk6l5xlQ

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • Clear-ManualsLibrary.b3003.SK041.ch.exe (PID: 3984)
      • Clear-ManualsLibrary.b3003.SK041.ch.tmp (PID: 4000)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • Clear-ManualsLibrary.b3003.SK041.ch.exe (PID: 3984)
      • Clear-ManualsLibrary.b3003.SK041.ch.tmp (PID: 4000)
    • Reads the Windows owner or organization settings

      • Clear-ManualsLibrary.b3003.SK041.ch.tmp (PID: 4000)
  • INFO

    • Checks supported languages

      • Clear-ManualsLibrary.b3003.SK041.ch.exe (PID: 3984)
      • Clear-ManualsLibrary.b3003.SK041.ch.tmp (PID: 4000)
    • Reads the computer name

      • Clear-ManualsLibrary.b3003.SK041.ch.tmp (PID: 4000)
    • Create files in a temporary directory

      • Clear-ManualsLibrary.b3003.SK041.ch.exe (PID: 3984)
      • Clear-ManualsLibrary.b3003.SK041.ch.tmp (PID: 4000)
    • Reads Environment values

      • Clear-ManualsLibrary.b3003.SK041.ch.tmp (PID: 4000)
    • Reads the machine GUID from the registry

      • Clear-ManualsLibrary.b3003.SK041.ch.tmp (PID: 4000)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (65.1)
.exe | Win32 EXE PECompact compressed (generic) (24.6)
.dll | Win32 Dynamic Link Library (generic) (3.9)
.exe | Win32 Executable (generic) (2.6)
.exe | Win16/32 Executable Delphi generic (1.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2022:04:14 16:10:23+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 741888
InitializedDataSize: 63488
UninitializedDataSize: -
EntryPoint: 0xb5eec
OSVersion: 6.1
ImageVersion: 6
SubsystemVersion: 6.1
Subsystem: Windows GUI
FileVersionNumber: 1.1.1.0
ProductVersionNumber: 1.1.1.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: Clear.App
FileDescription: Clear Setup
FileVersion: 1.1.1.0
LegalCopyright: Clear.App
OriginalFileName:
ProductName: Clear
ProductVersion: 1.1.1.0/Stub::1.1.1.0/46f04b2/2023-06-15T12:42:58+
No data.
screenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
35
Monitored processes
2
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start clear-manualslibrary.b3003.sk041.ch.exe clear-manualslibrary.b3003.sk041.ch.tmp

Process information

PID
CMD
Path
Indicators
Parent process
3984"C:\Users\admin\AppData\Local\Temp\Clear-ManualsLibrary.b3003.SK041.ch.exe" C:\Users\admin\AppData\Local\Temp\Clear-ManualsLibrary.b3003.SK041.ch.exe
explorer.exe
User:
admin
Company:
Clear.App
Integrity Level:
MEDIUM
Description:
Clear Setup
Exit code:
3762504530
Version:
1.1.1.0
Modules
Images
c:\users\admin\appdata\local\temp\clear-manualslibrary.b3003.sk041.ch.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
4000"C:\Users\admin\AppData\Local\Temp\is-8DIIK.tmp\Clear-ManualsLibrary.b3003.SK041.ch.tmp" /SL5="$20138,4024375,806400,C:\Users\admin\AppData\Local\Temp\Clear-ManualsLibrary.b3003.SK041.ch.exe" C:\Users\admin\AppData\Local\Temp\is-8DIIK.tmp\Clear-ManualsLibrary.b3003.SK041.ch.tmp
Clear-ManualsLibrary.b3003.SK041.ch.exe
User:
admin
Company:
Clear.App
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
3762504530
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-8diik.tmp\clear-manualslibrary.b3003.sk041.ch.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
Total events
418
Read events
415
Write events
3
Delete events
0

Modification events

(PID) Process:(4000) Clear-ManualsLibrary.b3003.SK041.ch.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
A00F0000DCFBB434549ADA01
(PID) Process:(4000) Clear-ManualsLibrary.b3003.SK041.ch.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:SessionHash
Value:
1E5BBDB56174F2184FECA27B3B4EC16ECA346134E29A188E9FFBC3FE4ED35F5F
(PID) Process:(4000) Clear-ManualsLibrary.b3003.SK041.ch.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Sequence
Value:
1
Executable files
3
Suspicious files
1
Text files
17
Unknown types
0

Dropped files

PID
Process
Filename
Type
4000Clear-ManualsLibrary.b3003.SK041.ch.tmpC:\Users\admin\AppData\Local\Temp\is-CPLSQ.tmp\html\css\baselinenew.csstext
MD5:4D9E4F45F1F8500EB7FE29AC4A34818D
SHA256:03ED977D9D2B9AEEE7912886185B69BABB7496DC9B45042190097F81153762DC
4000Clear-ManualsLibrary.b3003.SK041.ch.tmpC:\Users\admin\AppData\Local\Temp\is-CPLSQ.tmp\html\js\installer.jsbinary
MD5:C0122689D0F116B0C79D58C9962F7F75
SHA256:25565351691900A9DBBFB5D1911132B27CC36A1965FB336E6CD9BA960E37408C
4000Clear-ManualsLibrary.b3003.SK041.ch.tmpC:\Users\admin\AppData\Local\Temp\is-CPLSQ.tmp\Networking.dllexecutable
MD5:93EB3FB394F660B7DA2350BBF86F71C0
SHA256:5B92B1E84560B4567D2CE26267AE09CBBC80A72515724AD3C74518E8315EF2D8
3984Clear-ManualsLibrary.b3003.SK041.ch.exeC:\Users\admin\AppData\Local\Temp\is-8DIIK.tmp\Clear-ManualsLibrary.b3003.SK041.ch.tmpexecutable
MD5:D250BC4F53D1D78AAC084AAD5B3EEC04
SHA256:229F1ECFCE581B66AFB249FF19EDFBECAF9FF893A5DAB8E6E022DA958F056A8E
4000Clear-ManualsLibrary.b3003.SK041.ch.tmpC:\Users\admin\AppData\Local\Temp\is-CPLSQ.tmp\Profiles\profile_map.txttext
MD5:6444764B2CF9F2B2C274787263A78CCB
SHA256:1AF45A6C76B8BAA3CC167690EB748D8C367D1B5E98FE3581B6D8975632FF07F7
4000Clear-ManualsLibrary.b3003.SK041.ch.tmpC:\Users\admin\AppData\Local\Temp\is-CPLSQ.tmp\html\css\baseline.csstext
MD5:4C862C415540662AAB18410305790F9A
SHA256:085862D788D0DFE742617007AB076333D5C583AF4D179E73825F7718F2B8846D
4000Clear-ManualsLibrary.b3003.SK041.ch.tmpC:\Users\admin\AppData\Local\Temp\is-CPLSQ.tmp\Profiles\manualssearch_clearbar.jsontext
MD5:E6AD4AB2E714C62C49C4A426A0AB73E3
SHA256:1DDF86BA170A4F05F3D6B7B22B634935B6CA4F21EB0FD74486D295F6C1F8E437
4000Clear-ManualsLibrary.b3003.SK041.ch.tmpC:\Users\admin\AppData\Local\Temp\is-CPLSQ.tmp\html\css\baseline-compliant.csstext
MD5:78D40BDAB40ED79853222569B9AC5BD9
SHA256:E9B2E3C37C6463706FBE22925EB0B084AA785E78D49F65136608D9C15CA6C960
4000Clear-ManualsLibrary.b3003.SK041.ch.tmpC:\Users\admin\AppData\Local\Temp\is-CPLSQ.tmp\html\assets\common\browse_icon.pngimage
MD5:9C26F5DD459C12F2F8A28CAFB7447520
SHA256:3156AD4638AB7AE34E17E07A4BFC0E2509690B886506035DC92EF0EA8ADB0847
4000Clear-ManualsLibrary.b3003.SK041.ch.tmpC:\Users\admin\AppData\Local\Temp\is-CPLSQ.tmp\html\assets\common\greenprogress.gifimage
MD5:CB84E51D64C4D8F5C25D1563BC83C49A
SHA256:D916A57D1601286604BF570FA5F88E5A257026EDE1A41F5D305AF24B6315CE05
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
3
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
unknown
4
System
192.168.100.255:137
whitelisted
224.0.0.252:5355
unknown

DNS requests

No data

Threats

No threats detected
No debug info