| File name: | rcsetup153.exe |
| Full analysis: | https://app.any.run/tasks/e2de6591-4f9b-4cad-aba1-49bcbaff3068 |
| Verdict: | Malicious activity |
| Analysis date: | December 14, 2023, 22:40:28 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive |
| MD5: | A8B8AB47CB3124FB373D526E0992EDBC |
| SHA1: | 6309FF089057DF60264689DC8B201A0E2DCE967C |
| SHA256: | F5463E767123F678C2B8DC71738696A24C6F8E5286D8BB98B9A0D81E4375EEA7 |
| SSDEEP: | 393216:gbTkXmQB3tw5Xctkv7Kog1taovYKbjNiyPUgluL:gbwGquXg1AaNmglu |
| .exe | | | Win32 Executable MS Visual C++ (generic) (67.4) |
|---|---|---|
| .dll | | | Win32 Dynamic Link Library (generic) (14.2) |
| .exe | | | Win32 Executable (generic) (9.7) |
| .exe | | | Generic Win/DOS Executable (4.3) |
| .exe | | | DOS Executable Generic (4.3) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2021:09:26 00:04:50+02:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 26624 |
| InitializedDataSize: | 428544 |
| UninitializedDataSize: | 16384 |
| EntryPoint: | 0x3640 |
| OSVersion: | 4 |
| ImageVersion: | 6 |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.53.0.2095 |
| ProductVersionNumber: | 1.53.0.2095 |
| FileFlagsMask: | 0x0000 |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| CompanyName: | Piriform Software Ltd |
| FileDescription: | Recuva Installer |
| FileVersion: | 1.53.0.2095 |
| LegalCopyright: | Copyright © 2006-2023 Piriform Software Ltd |
| ProductName: | Recuva |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 580 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1216 --field-trial-handle=1400,i,17690580881604505044,9365652112854275344,131072 /prefetch:2 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 608 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1544 --field-trial-handle=1400,i,17690580881604505044,9365652112854275344,131072 /prefetch:3 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | msedge.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 644 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --first-renderer-process --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --mojo-platform-channel-handle=2344 --field-trial-handle=1400,i,17690580881604505044,9365652112854275344,131072 /prefetch:1 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 904 | C:\Windows\system32\vssvc.exe | C:\Windows\System32\VSSVC.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft® Volume Shadow Copy Service Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1032 | regsvr32.exe /I "C:\Program Files\Recuva\RecuvaShell.dll" /s | C:\Windows\System32\regsvr32.exe | — | rcsetup153.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft(C) Register Server Exit code: 4 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1152 | "C:\Users\admin\Desktop\rcsetup153.exe" | C:\Users\admin\Desktop\rcsetup153.exe | explorer.exe | ||||||||||||
User: admin Company: Piriform Software Ltd Integrity Level: HIGH Description: Recuva Installer Exit code: 0 Version: 1.53.0.2095 Modules
| |||||||||||||||
| 1576 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=1632 --field-trial-handle=1400,i,17690580881604505044,9365652112854275344,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1864 | "C:\Users\admin\Desktop\rcsetup153.exe" | C:\Users\admin\Desktop\rcsetup153.exe | — | explorer.exe | |||||||||||
User: admin Company: Piriform Software Ltd Integrity Level: MEDIUM Description: Recuva Installer Exit code: 3221226540 Version: 1.53.0.2095 Modules
| |||||||||||||||
| 2080 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1420 --field-trial-handle=1380,i,2988972612266788009,4472433726871695013,131072 /prefetch:3 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 2084 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" "--metrics-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=109.0.5414.149 "--annotation=exe=C:\Program Files\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win32 "--annotation=prod=Microsoft Edge" --annotation=ver=109.0.1518.115 --initial-client-data=0xc8,0xcc,0xd0,0x9c,0xd8,0x6913f598,0x6913f5a8,0x6913f5b4 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| (PID) Process: | (1152) rcsetup153.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | RegFiles0000 |
Value: C:\Users\admin\AppData\Local\Microsoft\Windows\WebCache\WebCacheV01.dat | |||
| (PID) Process: | (1152) rcsetup153.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | RegFilesHash |
Value: 5AFF46735A9F8FAF53F4367D7555C5B33351AD1E069F5C470C116E5DAF7EC4D8 | |||
| (PID) Process: | (1152) rcsetup153.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | delete value | Name: | RegFilesHash |
Value: BF45A1178E3AB885805E02C77A5F1D7CD46AB27A653C6D91D7FBDD3C40898B70 | |||
| (PID) Process: | (1152) rcsetup153.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | delete value | Name: | RegFiles0000 |
Value: C:\Users\admin\AppData\Local\Microsoft\Windows\WebCache\WebCacheV01.dat | |||
| (PID) Process: | (1152) rcsetup153.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | delete value | Name: | Sequence |
Value: 1 | |||
| (PID) Process: | (1152) rcsetup153.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | delete value | Name: | SessionHash |
Value: 8A4B6D41AB1B478E9809E87065EE15FBA7A64E58F004BD08EC4890FA7EDBF2A5 | |||
| (PID) Process: | (1152) rcsetup153.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | delete value | Name: | Owner |
Value: 80040000B06B1D92DE2EDA01 | |||
| (PID) Process: | (1152) rcsetup153.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (1152) rcsetup153.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | write | Name: | ProxyEnable |
Value: 0 | |||
| (PID) Process: | (1152) rcsetup153.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections |
| Operation: | write | Name: | SavedLegacySettings |
Value: 460000005A010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1152 | rcsetup153.exe | C:\Users\admin\AppData\Local\Temp\nso418.tmp\System.dll | executable | |
MD5:CFF85C549D536F651D4FB8387F1976F2 | SHA256:8DC562CDA7217A3A52DB898243DE3E2ED68B80E62DDCB8619545ED0B4E7F65A8 | |||
| 1152 | rcsetup153.exe | C:\Users\admin\AppData\Local\Temp\nso418.tmp\UserInfo.dll | executable | |
MD5:2F69AFA9D17A5245EC9B5BB03D56F63C | SHA256:E54989D2B83E7282D0BEC56B098635146AAB5D5A283F1F89486816851EF885A0 | |||
| 1152 | rcsetup153.exe | C:\Users\admin\AppData\Local\Temp\nso418.tmp\ui\pfUI.dll | executable | |
MD5:F7222368C66E02EE333E6FCA4FDCCB66 | SHA256:B09F1359C68947C7D13123DDA3AB56360B982BEFB43C134BE815934ED4879215 | |||
| 1152 | rcsetup153.exe | C:\Users\admin\AppData\Local\Temp\nso418.tmp\ui\res\PF_logo.png | image | |
MD5:079CCA30760CCA3C01863B6B96E87848 | SHA256:8DD37D3721E25C32C5BF878B6DBA9E61D04B7CE8AEC45BDF703A41BC41802DFA | |||
| 1152 | rcsetup153.exe | C:\Users\admin\AppData\Local\Temp\nso418.tmp\ui\res\lang-1053.dll | executable | |
MD5:1181929E3ECDADED7B5526C2084CF7EC | SHA256:B1B96DABB98F5C3C0238CCC964F03E9B03885AE551146AA90E547958A2E4F14E | |||
| 1152 | rcsetup153.exe | C:\Users\admin\AppData\Local\Temp\nso418.tmp\ui\res\Recuva_Logo_72px.png | image | |
MD5:6A2E01749E591A1CE8216DAED41B8721 | SHA256:F72782600989EFF0AA13FF7C63875538C9042C32B77862475C899514F61C9290 | |||
| 1152 | rcsetup153.exe | C:\Users\admin\AppData\Local\Temp\nso418.tmp\ui\res\Montserrat-Regular.otf | binary | |
MD5:27E50FFD6A14CBC8221C9DBD3B5208DC | SHA256:40FC1142200A5C1C18F80B6915257083C528C7F7FD2B00A552AEEBC42898D428 | |||
| 1152 | rcsetup153.exe | C:\Users\admin\AppData\Local\Temp\nso418.tmp\ui\res\lang-1040.dll | executable | |
MD5:1B76D1E1721505BB78E244CA9F4B4592 | SHA256:7000A53F92557E349FD06A7D8C243D15EB934F07E85FB384B331EEBB429296C2 | |||
| 1152 | rcsetup153.exe | C:\Users\admin\AppData\Local\Temp\nso418.tmp\g\gcapi_dll.dll | executable | |
MD5:2973AF8515EFFD0A3BFC7A43B03B3FCC | SHA256:D0E4581210A22135CE5DEB47D9DF4D636A94B3813E0649AAB84822C9F08AF2A0 | |||
| 1152 | rcsetup153.exe | C:\Users\admin\AppData\Local\Temp\nso418.tmp\ui\res\RC_Computer.png | image | |
MD5:67F13E50FA75087EF8C2074A52CC8BB1 | SHA256:044EC2D36E9F573D762FC8A43EB09F7B24EB30094A4E61B5D606FD96F72D391F | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
608 | msedge.exe | GET | 404 | 49.13.77.253:80 | http://www.ccleaner.com/go/app_releasenotes?p=2&v=1.53.2095&l=1033&b=1&a=0 | unknown | xml | 341 b | unknown |
608 | msedge.exe | GET | 404 | 49.13.77.253:80 | http://www.ccleaner.com/favicon.ico | unknown | xml | 341 b | unknown |
1080 | svchost.exe | GET | 404 | 49.13.77.253:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?e0032a321da2bdc4 | unknown | xml | 341 b | unknown |
484 | lsass.exe | GET | 404 | 49.13.77.253:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?153435dafcbdd709 | unknown | xml | 341 b | unknown |
484 | lsass.exe | GET | 404 | 49.13.77.253:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?c06f5c0780293fe1 | unknown | xml | 341 b | unknown |
1080 | svchost.exe | GET | 404 | 49.13.77.253:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?86cdc092d7002690 | unknown | xml | 341 b | unknown |
1080 | svchost.exe | GET | 404 | 49.13.77.253:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?d3beddd762d67162 | unknown | xml | 341 b | unknown |
484 | lsass.exe | GET | 404 | 49.13.77.253:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?440741f4bd306e5a | unknown | xml | 341 b | unknown |
1080 | svchost.exe | GET | 404 | 49.13.77.253:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?abdc0569852e700a | unknown | xml | 341 b | unknown |
608 | msedge.exe | GET | 404 | 49.13.77.253:443 | https://49.13.77.253/extensionwebstorebase/v1/logextensionreliability?success=false&cv=&errorString=MANIFEST_FETCH_FAILED&crxId=jmjflgjpcpepeafmmgdpfkogkghcpiha&os=win&arch=x86&os_arch=x86&nacl_arch=x86-32&prod=edgecrx&prodchannel=&prodversion=109.0.1518.115&lang=en-US&acceptformat=crx3 | unknown | xml | 341 b | — |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2588 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
1152 | rcsetup153.exe | 49.13.77.253:443 | analytics.ff.avast.com | Hetzner Online GmbH | DE | unknown |
484 | lsass.exe | 49.13.77.253:80 | analytics.ff.avast.com | Hetzner Online GmbH | DE | unknown |
1152 | rcsetup153.exe | 49.13.77.253:80 | analytics.ff.avast.com | Hetzner Online GmbH | DE | unknown |
3956 | recuva.exe | 49.13.77.253:443 | analytics.ff.avast.com | Hetzner Online GmbH | DE | unknown |
3956 | recuva.exe | 49.13.77.253:80 | analytics.ff.avast.com | Hetzner Online GmbH | DE | unknown |
2096 | msedge.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
Domain | IP | Reputation |
|---|---|---|
analytics.ff.avast.com |
| whitelisted |
ctldl.windowsupdate.com |
| whitelisted |
service.piriform.com |
| whitelisted |
www.ccleaner.com |
| whitelisted |
config.edge.skype.com |
| whitelisted |
edge.microsoft.com |
| whitelisted |
www.bing.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
3956 | recuva.exe | Misc activity | ET POLICY Recuva File Recovery Software - Observed User-Agent |