File name:

bookingDesktopAppUpdateSetup.exe

Full analysis: https://app.any.run/tasks/a0b2e618-cf04-4734-aa0a-805553ed7905
Verdict: Malicious activity
Analysis date: December 19, 2023, 10:39:32
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

21A9E727AD3CDD6CCB03EB28D78417FA

SHA1:

E090ADB14D6C4B561DDD435C8A147732867C682C

SHA256:

EEE241F737ED25A8A7643994303654F9466D82D6F1270BB08DFA08C5AD9B055D

SSDEEP:

49152:bSECqYFOYthVfzBpBl7CpBI1ioIXmvyUqMInpIXvFSOv7Wr+OrKEZX9CR3atxY17:bSvqijthVfzBnsfIkw/XvFvT2+Ojt9ig

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • bookingDesktopAppUpdateSetup.exe (PID: 128)
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    • Checks supported languages

      • bookingDesktopAppUpdateSetup.exe (PID: 128)
    • Create files in a temporary directory

      • bookingDesktopAppUpdateSetup.exe (PID: 128)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (76.4)
.exe | Win32 Executable (generic) (12.4)
.exe | Generic Win/DOS Executable (5.5)
.exe | DOS Executable Generic (5.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2019:07:19 22:50:26+02:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14
CodeSize: 87552
InitializedDataSize: 826880
UninitializedDataSize: -
EntryPoint: 0x4e6a
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 1.3.99.0
ProductVersionNumber: 1.3.99.0
FileFlagsMask: 0x003f
FileFlags: Private build
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: bookingDesktopApp.
FileDescription: bookingDesktopApp Update Setup
FileVersion: 1.3.99.0
InternalName: bookingDesktopApp Update Setup
LegalCopyright: Copyright 2007-2010 Google Inc.
OriginalFileName: bookingDesktopAppUpdateSetup.exe
ProductName: bookingDesktopApp Update
ProductVersion: 1.3.99.0
LanguageId: en
PrivateBuild: -
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
33
Monitored processes
1
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start bookingdesktopappupdatesetup.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
128"C:\bookingDesktopAppUpdateSetup.exe" C:\bookingDesktopAppUpdateSetup.exeexplorer.exe
User:
admin
Company:
bookingDesktopApp.
Integrity Level:
MEDIUM
Description:
bookingDesktopApp Update Setup
Exit code:
0
Version:
1.3.99.0
Modules
Images
c:\bookingdesktopappupdatesetup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
Total events
13
Read events
13
Write events
0
Delete events
0

Modification events

No data
Executable files
17
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
128bookingDesktopAppUpdateSetup.exeC:\Users\admin\AppData\Local\Temp\GUMF6D4.tmp\bookingDesktopAppUpdateOnDemand.exeexecutable
MD5:02473EB08DBBE4184AF4555C36F66C2B
SHA256:7FCE45E9A625DBCA17FFC077B4C565B4842BB7CA90FE342F1BCE41B6A93B2232
128bookingDesktopAppUpdateSetup.exeC:\Users\admin\AppData\Local\Temp\GUMF6D4.tmp\bookingDesktopAppUpdateWebPlugin.exeexecutable
MD5:13BF5E223634E178A15DD4DB3DFCCA4F
SHA256:BA340C19C7754CC71D2CB867717C6EED91E8B30C1383F4D42E801C5EDC197E48
128bookingDesktopAppUpdateSetup.exeC:\Users\admin\AppData\Local\Temp\GUMF6D4.tmp\psmachine.dllexecutable
MD5:887AE6FE0B57B6039CDE85B27C277C7D
SHA256:7753B5F3250457E3744A092A5DA712D2ED0A0534D1628BCDEA401CB05A52672D
128bookingDesktopAppUpdateSetup.exeC:\Users\admin\AppData\Local\Temp\GUMF6D4.tmp\psmachine_64.dllexecutable
MD5:3EF75A781120E519E1D68E526CA5161A
SHA256:12562A58EEE3FAC602C555FB5EF20CE0FA8A00FE7E22E7DF2AE997DDAA84F539
128bookingDesktopAppUpdateSetup.exeC:\Users\admin\AppData\Local\Temp\GUMF6D4.tmp\bookingDesktopAppUpdateHelper.msiexecutable
MD5:7E9B4B560EA62CB2CA4DD9F498672C49
SHA256:30B6D42CDB0A71B40084888184EB53F7788BA2B01133E097C46EB3E5305348C7
128bookingDesktopAppUpdateSetup.exeC:\Users\admin\AppData\Local\Temp\GUMF6D4.tmp\bookingDesktopAppCrashHandler.exeexecutable
MD5:710FD71FDEC506F8A9498B4B5CC85FDE
SHA256:8186AB35CBC87FB3B02DE883D6BA478CAB0245940D77C2B9A08ED567D5690D8A
128bookingDesktopAppUpdateSetup.exeC:\Users\admin\AppData\Local\Temp\GUMF6D4.tmp\psuser.dllexecutable
MD5:F2909CE754E016DF0261507D66BF4168
SHA256:78D31956BEDF30FD3AC730CDA58F026442B0AE93A3E8A432877F1E9380461AB7
128bookingDesktopAppUpdateSetup.exeC:\Users\admin\AppData\Local\Temp\GUMF6D4.tmp\bookingDesktopAppUpdateSetup.exeexecutable
MD5:21A9E727AD3CDD6CCB03EB28D78417FA
SHA256:EEE241F737ED25A8A7643994303654F9466D82D6F1270BB08DFA08C5AD9B055D
128bookingDesktopAppUpdateSetup.exeC:\Users\admin\AppData\Local\Temp\GUMF6D4.tmp\npbookingDesktopAppUpdate3.dllexecutable
MD5:EC95A5860D0EF5E36EBE32190E1175C8
SHA256:F8DACA9E904C05AFCCE37EE1BC860712A7F58D57619D14BC4B05FE9B2BA84DF2
128bookingDesktopAppUpdateSetup.exeC:\Users\admin\AppData\Local\Temp\GUMF6D4.tmp\bookingDesktopAppUpdateCore.exeexecutable
MD5:B0F2EA54887D16568D425A508E0C4485
SHA256:B0217FB641D72C871D2986B1B5672990CCE88EAF9178A0B2FAD24BE539800C2E
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown

DNS requests

No data

Threats

No threats detected
No debug info