| File name: | CCSetup.exe |
| Full analysis: | https://app.any.run/tasks/49a54401-f763-43da-9f94-b47258dd8b91 |
| Verdict: | Malicious activity |
| Analysis date: | November 20, 2023, 14:47:29 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | B56A43DE95057FEFDCD9294F028022BE |
| SHA1: | B152B1AE2891A518941DA1F99D56456249BAFF4A |
| SHA256: | F4EF5BB5A9F9EC95087F69BE76914C829FC6A6EE5B01C0EF06BD46D5E323738D |
| SSDEEP: | 98304:e9t0taQEx5Tf+S+PI6zxZmDFuN9fLlcYk4LwkYcMiNJ7kx9I5isSaf9TYcNfI+4v:6euB7 |
| .exe | | | Win64 Executable (generic) (64.6) |
|---|---|---|
| .dll | | | Win32 Dynamic Link Library (generic) (15.4) |
| .exe | | | Win32 Executable (generic) (10.5) |
| .exe | | | Generic Win/DOS Executable (4.6) |
| .exe | | | DOS Executable Generic (4.6) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2021:06:20 21:44:34+02:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 11 |
| CodeSize: | 622080 |
| InitializedDataSize: | 780288 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x59e5a |
| OSVersion: | 5.1 |
| ImageVersion: | - |
| SubsystemVersion: | 5.1 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.0.59.0 |
| ProductVersionNumber: | 1.0.59.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Dynamic link library |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| CompanyName: | RCS LT |
| FileDescription: | Combo Cleaner |
| FileVersion: | 1.0.59.0 |
| InternalName: | Setup |
| LegalCopyright: | Copyright (c) 2021 RCS LT, UAB. All Rights Reserved. |
| OriginalFileName: | CCSetup.exe |
| ProductName: | Combo Cleaner |
| ProductVersion: | 1.0.59.0 |
| InternalBuildNumber: | 202227 |
| ISInternalVersion: | 26.0.720 |
| ISInternalDescription: | Setup Launcher Unicode |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 280 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3620 --field-trial-handle=1312,i,11109790888405918695,5485028252693538536,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 300 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --instant-process --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=2292 --field-trial-handle=1312,i,11109790888405918695,5485028252693538536,131072 /prefetch:1 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 368 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=28 --mojo-platform-channel-handle=5168 --field-trial-handle=1312,i,11109790888405918695,5485028252693538536,131072 /prefetch:1 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 968 | SetupUtility.exe /aupause | C:\1999dcf6b371d6fd43e4\SetupUtility.exe | — | Setup.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft .NET Framework 4.5 Setup Exit code: 0 Version: 14.7.3081.0 built by: NET472REL1 Modules
| |||||||||||||||
| 1064 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=entity_extraction_service.mojom.Extractor --lang=en-US --service-sandbox-type=entity_extraction --onnx-enabled-for-ee --mojo-platform-channel-handle=1268 --field-trial-handle=1312,i,11109790888405918695,5485028252693538536,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1576 | C:\1999dcf6b371d6fd43e4\\Setup.exe /q /norestart /x86 /x64 /redist | C:\1999dcf6b371d6fd43e4\Setup.exe | ndp472-kb4054530-x86-x64-allos-enu.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Setup Installer Exit code: 0 Version: 14.7.3081.0 built by: NET472REL1 Modules
| |||||||||||||||
| 1824 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=8 --mojo-platform-channel-handle=3756 --field-trial-handle=1312,i,11109790888405918695,5485028252693538536,131072 /prefetch:1 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1836 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=4240 --field-trial-handle=1312,i,11109790888405918695,5485028252693538536,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1864 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=20 --mojo-platform-channel-handle=3572 --field-trial-handle=1312,i,11109790888405918695,5485028252693538536,131072 /prefetch:1 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1924 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --use-gl=angle --use-angle=swiftshader-webgl --mojo-platform-channel-handle=1576 --field-trial-handle=1312,i,11109790888405918695,5485028252693538536,131072 /prefetch:2 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| (PID) Process: | (3524) CCSetup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | write | Name: | ProxyEnable |
Value: 0 | |||
| (PID) Process: | (3524) CCSetup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections |
| Operation: | write | Name: | SavedLegacySettings |
Value: 4600000059010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3524) CCSetup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (3524) CCSetup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (3524) CCSetup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (3524) CCSetup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (3524) CCSetup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (3524) CCSetup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (3524) CCSetup.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\17A\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3876) wmpnscfg.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{6C86B798-E2D3-4EB1-A431-64569648B915}\{F3B0F564-FD34-438F-ADED-D1486CD96820} |
| Operation: | delete key | Name: | (default) |
Value: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3504 | CCSetup.exe | C:\Users\admin\AppData\Local\Temp\~73BE.tmp | text | |
MD5:C8C14AE5FB013DA397AD84646E33AC83 | SHA256:296D51F6D6CF3B7904AB73B5272D60E116FEA0CED103015FD2379E0513ADE223 | |||
| 3504 | CCSetup.exe | C:\Users\admin\AppData\Local\Temp\{DA0F55E3-0CDD-4A4F-8CD0-71F9DB74E066}\_ISMSIDEL.INI | text | |
MD5:09BAA35A458DA1A18CD15D3F8975D9CD | SHA256:7222F6DEAD4BAE3FFAA6B9D1A609CBC44B6AE12E26C68B332A2227B28393815F | |||
| 3504 | CCSetup.exe | C:\Users\admin\AppData\Local\Temp\{DA0F55E3-0CDD-4A4F-8CD0-71F9DB74E066}\CCSetup.exe | executable | |
MD5:B56A43DE95057FEFDCD9294F028022BE | SHA256:F4EF5BB5A9F9EC95087F69BE76914C829FC6A6EE5B01C0EF06BD46D5E323738D | |||
| 3524 | CCSetup.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\7423F88C7F265F0DEFC08EA88C3BDE45_AA1E8580D4EBC816148CE81268683776 | binary | |
MD5:EF059695552DB202EA425D04B7B14C02 | SHA256:A97209B39043D80EB4FE3E5B44417C8F0744D80F38831DFC60DE2E63F315814A | |||
| 3524 | CCSetup.exe | C:\Users\admin\AppData\Local\Temp\~77A5.tmp | text | |
MD5:C8C14AE5FB013DA397AD84646E33AC83 | SHA256:296D51F6D6CF3B7904AB73B5272D60E116FEA0CED103015FD2379E0513ADE223 | |||
| 3524 | CCSetup.exe | C:\Users\admin\AppData\Local\Temp\{DA0F55E3-0CDD-4A4F-8CD0-71F9DB74E066}\Setup.INI | text | |
MD5:C8C14AE5FB013DA397AD84646E33AC83 | SHA256:296D51F6D6CF3B7904AB73B5272D60E116FEA0CED103015FD2379E0513ADE223 | |||
| 3504 | CCSetup.exe | C:\Users\admin\AppData\Local\Temp\~73AE.tmp | text | |
MD5:C8C14AE5FB013DA397AD84646E33AC83 | SHA256:296D51F6D6CF3B7904AB73B5272D60E116FEA0CED103015FD2379E0513ADE223 | |||
| 3524 | CCSetup.exe | C:\Users\admin\AppData\Local\Temp\~77A6.tmp | text | |
MD5:C8C14AE5FB013DA397AD84646E33AC83 | SHA256:296D51F6D6CF3B7904AB73B5272D60E116FEA0CED103015FD2379E0513ADE223 | |||
| 3524 | CCSetup.exe | C:\Users\admin\AppData\Local\Temp\{DA0F55E3-0CDD-4A4F-8CD0-71F9DB74E066}\0x0409.ini | text | |
MD5:A108F0030A2CDA00405281014F897241 | SHA256:8B76DF0FFC9A226B532B60936765B852B89780C6E475C152F7C320E085E43948 | |||
| 3524 | CCSetup.exe | C:\Users\admin\AppData\Local\Temp\{DA0F55E3-0CDD-4A4F-8CD0-71F9DB74E066}\Microsoft .NET Framework 4.7.2 Full.prq | xml | |
MD5:742F35470542E0F3B871918C6A10ABB2 | SHA256:880DF4512FFA3353A9658C8FCF0927F9E285B2E41905864EA0A04661C0649BBA | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
4036 | msedge.exe | GET | 204 | 13.107.6.158:80 | http://edge-http.microsoft.com/captiveportal/generate_204 | unknown | — | — | unknown |
1576 | Setup.exe | GET | 200 | 2.16.164.49:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | binary | 1.11 Kb | unknown |
4036 | msedge.exe | GET | 301 | 192.0.66.233:80 | http://malwarebytes.com/download | unknown | html | 162 b | unknown |
3524 | CCSetup.exe | GET | 200 | 64.14.29.56:80 | http://saturn.installshield.com/is/prerequisites/Microsoft%20.NET%20Framework%204.7.2%20Full.prq | unknown | xml | 1.64 Kb | unknown |
3524 | CCSetup.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | binary | 471 b | unknown |
1576 | Setup.exe | GET | 200 | 2.16.164.49:80 | http://crl.microsoft.com/pki/crl/products/MicrosoftTimeStampPCA.crl | unknown | binary | 519 b | unknown |
1576 | Setup.exe | GET | 200 | 2.16.164.49:80 | http://crl.microsoft.com/pki/crl/products/microsoftrootcert.crl | unknown | binary | 767 b | unknown |
3524 | CCSetup.exe | GET | 200 | 8.253.95.120:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?d19af1718ae57980 | unknown | compressed | 4.66 Kb | unknown |
1576 | Setup.exe | GET | 200 | 95.101.149.131:80 | http://www.microsoft.com/pkiops/crl/MicCodSigPCA2011_2011-07-08.crl | unknown | binary | 1.05 Kb | unknown |
3524 | CCSetup.exe | GET | 200 | 64.14.29.56:80 | http://saturn.installshield.com/is/prerequisites/Microsoft%20.NET%20Framework%204.7.2%20Full.prq | unknown | xml | 1.64 Kb | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
2588 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
3524 | CCSetup.exe | 64.14.29.56:80 | saturn.installshield.com | FLEXERA-SC4 | US | unknown |
3524 | CCSetup.exe | 68.232.34.200:443 | download.visualstudio.microsoft.com | EDGECAST | US | whitelisted |
3524 | CCSetup.exe | 8.253.95.120:80 | ctldl.windowsupdate.com | LEVEL3 | US | unknown |
3524 | CCSetup.exe | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
3912 | msedge.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
4036 | msedge.exe | 204.79.197.203:443 | ntp.msn.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
saturn.installshield.com |
| unknown |
download.visualstudio.microsoft.com |
| whitelisted |
ctldl.windowsupdate.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
ntp.msn.com |
| whitelisted |
config.edge.skype.com |
| whitelisted |
edge.microsoft.com |
| whitelisted |
assets.msn.com |
| whitelisted |
img-s-msn-com.akamaized.net |
| whitelisted |
sb.scorecardresearch.com |
| shared |
PID | Process | Class | Message |
|---|---|---|---|
3524 | CCSetup.exe | Misc activity | ET INFO Installshield One Click Install User-Agent Toys File |
3524 | CCSetup.exe | Misc activity | ET INFO Installshield One Click Install User-Agent Toys File |