File name:

GWSetup.exe

Full analysis: https://app.any.run/tasks/531aac56-305c-40cd-b6d8-f0b5dbc706ec
Verdict: Malicious activity
Analysis date: July 29, 2024, 03:34:31
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, InstallShield self-extracting archive
MD5:

D8E1DEF4D2B55210DCFAE3AD784CA7B9

SHA1:

398902BC050EBAAB539C37429C887714A60AE76F

SHA256:

EAB58C18FA7A36D77CB0D62C73B0D5AD674F1A37A1073D5BA50D7E12EE7EFCEE

SSDEEP:

98304:lgrrdQE3heOgiLJC44Cjn+rCPpzj0HyWvwGgrjEplb/eJh3J43+DxHJWAnayBSlc:+NQlBbgmvaJYcTE72yUAMZ

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • GWSetup.exe (PID: 5284)
    • Registers / Runs the DLL via REGSVR32.EXE

      • GWSetup.exe (PID: 5284)
  • SUSPICIOUS

    • Checks Windows Trust Settings

      • GWSetup.exe (PID: 5284)
    • Executable content was dropped or overwritten

      • GWSetup.exe (PID: 5284)
    • Reads security settings of Internet Explorer

      • GWSetup.exe (PID: 5284)
    • Drops a system driver (possible attempt to evade defenses)

      • GWSetup.exe (PID: 5284)
    • Adds/modifies Windows certificates

      • GWSetup.exe (PID: 5284)
    • Creates/Modifies COM task schedule object

      • GWSetup.exe (PID: 5284)
      • regsvr32.exe (PID: 4388)
    • Executes as Windows Service

      • gwupdater.exe (PID: 5448)
      • gwservice.exe (PID: 5528)
    • Creates a software uninstall entry

      • GWSetup.exe (PID: 5284)
    • Creates or modifies Windows services

      • GWSetup.exe (PID: 5284)
  • INFO

    • Checks supported languages

      • GWSetup.exe (PID: 5284)
      • gwupdater.exe (PID: 5448)
      • gwservice.exe (PID: 5528)
      • devcon.exe (PID: 3848)
    • Create files in a temporary directory

      • GWSetup.exe (PID: 5284)
    • Creates files in the program directory

      • GWSetup.exe (PID: 5284)
      • gwupdater.exe (PID: 5448)
      • gwservice.exe (PID: 5528)
    • Reads the computer name

      • GWSetup.exe (PID: 5284)
      • gwupdater.exe (PID: 5448)
      • gwservice.exe (PID: 5528)
    • Reads the machine GUID from the registry

      • GWSetup.exe (PID: 5284)
      • gwservice.exe (PID: 5528)
      • gwupdater.exe (PID: 5448)
    • Reads the software policy settings

      • GWSetup.exe (PID: 5284)
      • gwupdater.exe (PID: 5448)
      • gwservice.exe (PID: 5528)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2022:10:10 03:22:54+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 31232
InitializedDataSize: 34304
UninitializedDataSize: -
EntryPoint: 0x8810
OSVersion: 4
ImageVersion: -
SubsystemVersion: 5
Subsystem: Windows GUI
FileVersionNumber: 0.0.1.3
ProductVersionNumber: 1.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Chinese (Simplified)
CharacterSet: Unicode
Comments: -
CompanyName: -
FileDescription: GWSetup
FileVersion: 0, 0, 1, 3
InternalName: GWSetup
LegalCopyright: Copyright 2020
LegalTrademarks: -
OriginalFileName: SetupStub.exe
PrivateBuild: -
ProductName: -
ProductVersion: 1, 0, 0, 0
SpecialBuild: -
No data.
screenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
147
Monitored processes
8
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start gwsetup.exe regsvr32.exe no specs gwupdater.exe gwservice.exe devcon.exe no specs conhost.exe no specs slui.exe no specs gwsetup.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1028\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exedevcon.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3848"C:\WINDOWS\system32\drivers\devcon.exe" enable gwvnicC:\Windows\System32\drivers\devcon.exeGWSetup.exe
User:
admin
Company:
Windows (R) Codename Longhorn DDK provider
Integrity Level:
HIGH
Description:
Windows Setup API
Exit code:
0
Version:
6.0.6001.18000 built by: WinDDK
Modules
Images
c:\windows\system32\drivers\devcon.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
3940C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
4388"C:\WINDOWS\system32\regsvr32.exe" "C:\Program Files\Gateway\SSLVPN\gwieplugin_1d3222a3c1.dll" /sC:\Windows\System32\regsvr32.exeGWSetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
4808"C:\Users\admin\AppData\Local\Temp\GWSetup.exe" C:\Users\admin\AppData\Local\Temp\GWSetup.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
GWSetup
Exit code:
3221226540
Version:
0, 0, 1, 3
Modules
Images
c:\users\admin\appdata\local\temp\gwsetup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
5284"C:\Users\admin\AppData\Local\Temp\GWSetup.exe" C:\Users\admin\AppData\Local\Temp\GWSetup.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Description:
GWSetup
Exit code:
0
Version:
0, 0, 1, 3
Modules
Images
c:\users\admin\appdata\local\temp\gwsetup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acgenral.dll
5448"C:\WINDOWS\SysWOW64\gwupdater.exe"C:\Windows\SysWOW64\gwupdater.exe
services.exe
User:
SYSTEM
Integrity Level:
SYSTEM
Description:
gwservice
Version:
0, 0, 1, 54
Modules
Images
c:\windows\syswow64\gwupdater.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acgenral.dll
5528"C:\WINDOWS\SysWOW64\gwservice.exe"C:\Windows\SysWOW64\gwservice.exe
services.exe
User:
SYSTEM
Integrity Level:
SYSTEM
Description:
gwservice
Version:
0, 0, 1, 54
Modules
Images
c:\windows\syswow64\gwservice.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
Total events
11 870
Read events
11 680
Write events
172
Delete events
18

Modification events

(PID) Process:(5284) GWSetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\GWClient\Install
Operation:writeName:UpdaterFlag
Value:
0
(PID) Process:(5284) GWSetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\GWClient\Install
Operation:writeName:UIOption
Value:
0
(PID) Process:(5284) GWSetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\GWClient\Install
Operation:writeName:InstallPath
Value:
C:\Program Files (x86)\Gateway\SSLVPN
(PID) Process:(5284) GWSetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\GWClient\Install
Operation:writeName:InstallPath64
Value:
C:\Program Files\Gateway\SSLVPN
(PID) Process:(5284) GWSetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\GWClient\Install
Operation:writeName:InstallPath64
Value:
(PID) Process:(5284) GWSetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{100C2765-1362-4CCF-AB02-56D916BB8732}\InprocServer32
Operation:delete keyName:(default)
Value:
(PID) Process:(5284) GWSetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{100C2765-1362-4CCF-AB02-56D916BB8732}
Operation:delete keyName:(default)
Value:
(PID) Process:(5284) GWSetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{4A2B7DF6-7E36-4A71-8169-D790C00DFCD3}\InprocServer32
Operation:delete keyName:(default)
Value:
(PID) Process:(5284) GWSetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{4A2B7DF6-7E36-4A71-8169-D790C00DFCD3}
Operation:delete keyName:(default)
Value:
(PID) Process:(5284) GWSetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\GWClient\Install\Shortcut
Operation:delete keyName:(default)
Value:
Executable files
90
Suspicious files
74
Text files
18
Unknown types
9

Dropped files

PID
Process
Filename
Type
5284GWSetup.exeC:\Users\admin\AppData\Local\Temp\gwtemp\gwuninstall.exe.cabcompressed
MD5:F99914BE0A2031359173FF3064B22384
SHA256:01DD490A987B7C2C0058E0B795515BD39004A78A88588D8ABDCF8D40917881F9
5284GWSetup.exeC:\Users\admin\AppData\Local\Temp\gwtemp\signcrack.exeexecutable
MD5:BB03938C9127612DD30A96B4A421FFC2
SHA256:E079F07A37BCEE95738FFB162AF75D487D95E7D67359459A1A0B2193F48DCF36
5284GWSetup.exeC:\Users\admin\AppData\Local\Temp\gwtemp\gwuninstall.exeexecutable
MD5:CB0107B47A77FE4FC7C158F4F7AE4591
SHA256:8F62AD14C3946D53A790672915513595454547BE9729FCC425037A3B663FCFC7
5284GWSetup.exeC:\Users\admin\AppData\Local\Temp\gwtemp\gwupdater.dll.cabcompressed
MD5:7D1808986C2EA6271063EC7CFE360D7B
SHA256:FEA0A2358F04183BBACB5CAB5A9F3C666C3776D3D91A21285371914A51631D8C
5284GWSetup.exeC:\Users\admin\AppData\Local\Temp\gwtemp\gwclient.exeexecutable
MD5:90C1778D45FD9ACA9E21D708BEA36D9D
SHA256:2C7DA6690BE26BD6B5CEEA90B233FDD26589D7A72B2A62468903ABA887E7AD6A
5284GWSetup.exeC:\Users\admin\AppData\Local\Temp\gwtemp\gwclient.exe.cabcompressed
MD5:996CB58EA64015C4C63BEC7234B2C8A6
SHA256:928DB5AADAD4D3D3FDE92C63D760FEE2A91D7D6EFE6675A98153A7C27C8651A0
5284GWSetup.exeC:\Users\admin\AppData\Local\Temp\gwtemp\GWVPNDoctor.exe.cabcompressed
MD5:61E12AF3F5FD2EEC4F5EA72BA819AFC8
SHA256:0A45778BF05CF539FE43DB2A40AD20B2EB31DDF173E75254B1BB130C47168793
5284GWSetup.exeC:\Users\admin\AppData\Local\Temp\gwtemp\gwtrayclient.exe.cabcompressed
MD5:817713E095C18E60DC53A295DFD38A0D
SHA256:ADFD1EAE028A2A889BBE86AD66F514D16E84D0E385A5A0B3849BC79C4D132BBE
5284GWSetup.exeC:\Users\admin\AppData\Local\Temp\gwtemp\gwsdk.dll.cabcompressed
MD5:2B53FEC738E8A4BC56616FDC956063AE
SHA256:3F2414EF59CB4F0BE1C7A2CF15A7319B888DD9715F452679188F86C4696D472A
5284GWSetup.exeC:\Users\admin\AppData\Local\Temp\gwtemp\GWVPNDoctor.exeexecutable
MD5:19F0EB0B269FA8BD647B52954706A45B
SHA256:85BDD14F616073CB28D29C1704112E3595FB5515B2E41DA00E7FA8C5019E825C
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
41
DNS requests
23
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4424
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
5368
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
3676
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
5368
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEApDqVCbATUviZV57HIIulA%3D
unknown
whitelisted
4132
OfficeClickToRun.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
5532
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
131.253.33.254:443
a-ring-fallback.msedge.net
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
104.126.37.145:443
www.bing.com
Akamai International B.V.
DE
unknown
2348
RUXIMICS.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6012
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4792
slui.exe
20.83.72.98:443
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
1620
slui.exe
20.83.72.98:443
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
3952
svchost.exe
239.255.255.250:1900
whitelisted
4092
slui.exe
20.83.72.98:443
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
t-ring-fdv2.msedge.net
  • 13.107.237.254
unknown
a-ring-fallback.msedge.net
  • 131.253.33.254
unknown
settings-win.data.microsoft.com
  • 4.231.128.59
  • 20.73.194.208
  • 51.104.136.2
whitelisted
www.bing.com
  • 104.126.37.145
  • 104.126.37.123
  • 104.126.37.128
  • 104.126.37.176
  • 104.126.37.136
  • 104.126.37.185
  • 104.126.37.131
  • 104.126.37.178
  • 104.126.37.139
  • 104.126.37.153
  • 104.126.37.130
whitelisted
google.com
  • 172.217.16.206
whitelisted
fp-afd-nocache-ccp.azureedge.net
  • 13.107.246.60
whitelisted
login.live.com
  • 40.126.32.140
  • 40.126.32.138
  • 20.190.160.14
  • 40.126.32.72
  • 40.126.32.136
  • 20.190.160.20
  • 20.190.160.22
  • 40.126.32.133
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
fd.api.iris.microsoft.com
  • 20.31.169.57
whitelisted
client.wns.windows.com
  • 40.113.103.199
whitelisted

Threats

No threats detected
Process
Message
GWSetup.exe
[07-29 03:34:42][INF][GWUPDLL]DLL_PROCESS_ATTACH
GWSetup.exe
[07-29 03:34:42][INF][GWUPDLL]Load SSPI library(C:\WINDOWS\syswow64\Secur32.dll).
GWSetup.exe
[07-29 03:34:42][WAR][GWUPDLL]Name:GWVNIC, Mask:xp|vista|win7|win8, CurrentOS:win10,Filter Out!
GWSetup.exe
[07-29 03:34:42][WAR][GWUPDLL]Name:VNICCAT, Mask:xp|vista|win7|win8, CurrentOS:win10,Filter Out!
GWSetup.exe
[07-29 03:34:42][WAR][GWUPDLL]Name:VNICINF, Mask:xp|vista|win7|win8, CurrentOS:win10,Filter Out!
GWSetup.exe
[07-29 03:34:42][DBG][GWUPDLL]check ver conf path:C:\Program Files (x86)\Gateway\SSLVPN\package.conf.bak
GWSetup.exe
[07-29 03:34:42][WAR][GWUPDLL]file[C:\Program Files (x86)\Gateway\SSLVPN\package.conf.bak] md5:
GWSetup.exe
[07-29 03:34:42][DBG][GWUPDLL]conf.bak check failed
GWSetup.exe
get sign config is not xp
GWSetup.exe
get sign config is not xp