File name:

BDESetup.exe

Full analysis: https://app.any.run/tasks/591afdfe-1eae-4bd8-aec7-045a85152af5
Verdict: Malicious activity
Analysis date: February 16, 2024, 17:20:07
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

30C7F9B39C6149E1A6411DDB14973CDD

SHA1:

AB1BECF0B2204E28897B0082FE93347BE58BD82E

SHA256:

EE3291F5989D1D6C80A7D42DA441CD26FB0502BD3CA6ED99CBBD8FD076A6C5C5

SSDEEP:

98304:A/7CybdW/XXkGVQl9p5WDvto3KNWQYoOScSwNbtXwyIHNvdmnDjnsllzK8eQHaG3:0205lapCaty7/9o

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • BDESetup.exe (PID: 3216)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • BDESetup.exe (PID: 3216)
  • INFO

    • Checks supported languages

      • BDESetup.exe (PID: 3216)
    • Create files in a temporary directory

      • BDESetup.exe (PID: 3216)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Wise Installer executable (86.4)
.exe | Win32 Executable MS Visual C++ (generic) (5.7)
.exe | Win64 Executable (generic) (5)
.dll | Win32 Dynamic Link Library (generic) (1.2)
.exe | Win32 Executable (generic) (0.8)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2001:10:25 19:47:11+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit, Removable run from swap
PEType: PE32
LinkerVersion: 6
CodeSize: 8704
InitializedDataSize: 5632
UninitializedDataSize: -
EntryPoint: 0x21af
OSVersion: 4
ImageVersion: 4
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.2
ProductVersionNumber: 1.0.0.2
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows 16-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
CompanyName: BDE Information Utility
FileDescription: BDE Information Utility Setup
FileVersion: 1.0.0.2
LegalCopyright: This program is freeware.
No data.
screenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
40
Monitored processes
2
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start bdesetup.exe bdesetup.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
3216"C:\Users\admin\AppData\Local\Temp\BDESetup.exe" C:\Users\admin\AppData\Local\Temp\BDESetup.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\bdesetup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
3668"C:\Users\admin\AppData\Local\Temp\BDESetup.exe" C:\Users\admin\AppData\Local\Temp\BDESetup.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\appdata\local\temp\bdesetup.exe
c:\windows\system32\ntdll.dll
Total events
65
Read events
65
Write events
0
Delete events
0

Modification events

No data
Executable files
5
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
3216BDESetup.exeC:\Users\admin\AppData\Local\Temp\GLCF898.tmpexecutable
MD5:263E81631FB67194DC968DC3F4BDB4E7
SHA256:9200949AB6F777DF957FC524D4733E2CB47B89A209C07D2BE57B4C63CECBF766
3216BDESetup.exeC:\Users\admin\AppData\Local\Temp\GLF474.tmpexecutable
MD5:3B2E23D259394C701050486E642D14FA
SHA256:166D7156142F3EE09FA69EB617DD22E4FD248AA80A1AC08767DB6AD99A2705C1
3216BDESetup.exeC:\Users\admin\AppData\Local\Temp\~GLH0001.TMPexecutable
MD5:3B2E23D259394C701050486E642D14FA
SHA256:166D7156142F3EE09FA69EB617DD22E4FD248AA80A1AC08767DB6AD99A2705C1
3216BDESetup.exeC:\Users\admin\AppData\Local\Temp\GLF473.tmpexecutable
MD5:5084B505816DD0060AFCBF41EA6AE946
SHA256:02BB5AC5A52BBED328A384E0C31BBFBCD374A5FCF1CE24283B0D931EEDFAA4D4
3216BDESetup.exeC:\Users\admin\AppData\Local\Temp\~GLH0000.TMPexecutable
MD5:5084B505816DD0060AFCBF41EA6AE946
SHA256:02BB5AC5A52BBED328A384E0C31BBFBCD374A5FCF1CE24283B0D931EEDFAA4D4
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown

DNS requests

No data

Threats

No threats detected
No debug info