File name:

setup.exe

Full analysis: https://app.any.run/tasks/c23dba30-919f-4709-a4fe-7958ecdf4874
Verdict: Malicious activity
Analysis date: November 23, 2023, 17:00:05
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

EA58C12B25C48FEA01EEE390ED06C84A

SHA1:

DF28A8077121C74EFE33A0617F8CC030C654F3C6

SHA256:

FA757528FDF828A3C372A2C12A4BACA687CED0D1F7E4C5F7A69183ADDC575A46

SSDEEP:

98304:QJyEM7ncqFIG7xn8Oy2uyCNxIHCrrHk+4kq65I+G6fs8IN1DGfma5E7vVpKYFNMV:VYv3eg

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • setup.exe (PID: 3508)
      • setup.tmp (PID: 3524)
      • _iu14D2N.tmp (PID: 3632)
      • unins000.exe (PID: 3624)
  • SUSPICIOUS

    • Reads the Windows owner or organization settings

      • setup.tmp (PID: 3524)
      • _iu14D2N.tmp (PID: 3632)
    • Process drops legitimate windows executable

      • setup.tmp (PID: 3524)
      • _iu14D2N.tmp (PID: 3632)
    • Starts application with an unusual extension

      • unins000.exe (PID: 3624)
    • Starts itself from another location

      • unins000.exe (PID: 3624)
  • INFO

    • Checks supported languages

      • setup.exe (PID: 3508)
      • setup.tmp (PID: 3524)
      • unins000.exe (PID: 3624)
      • _iu14D2N.tmp (PID: 3632)
    • Reads the computer name

      • setup.tmp (PID: 3524)
    • Create files in a temporary directory

      • setup.exe (PID: 3508)
      • setup.tmp (PID: 3524)
      • unins000.exe (PID: 3624)
      • _iu14D2N.tmp (PID: 3632)
    • Creates files in the program directory

      • setup.tmp (PID: 3524)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (81.5)
.exe | Win32 Executable Delphi generic (10.5)
.exe | Win32 Executable (generic) (3.3)
.exe | Win16/32 Executable Delphi generic (1.5)
.exe | Generic Win/DOS Executable (1.4)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2012:10:02 07:04:04+02:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 86016
InitializedDataSize: 158208
UninitializedDataSize: -
EntryPoint: 0x16478
OSVersion: 5
ImageVersion: 6
SubsystemVersion: 5
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.5
ProductVersionNumber: 1.0.0.5
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: torrent-igruha.org
FileDescription: Half-Life 2 Complete Edition Setup
FileVersion: 1.0.0.5
LegalCopyright: © Mail
ProductName: Half-Life 2 Complete Edition
ProductVersion: 1.0.0.5
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
42
Monitored processes
5
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
start setup.exe setup.tmp no specs unins000.exe no specs _iu14d2n.tmp no specs setup.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
3128"C:\Users\admin\AppData\Local\Temp\setup.exe" C:\Users\admin\AppData\Local\Temp\setup.exeexplorer.exe
User:
admin
Company:
torrent-igruha.org
Integrity Level:
MEDIUM
Description:
Half-Life 2 Complete Edition Setup
Exit code:
3221226540
Version:
1.0.0.5
Modules
Images
c:\users\admin\appdata\local\temp\setup.exe
c:\windows\system32\ntdll.dll
3508"C:\Users\admin\AppData\Local\Temp\setup.exe" C:\Users\admin\AppData\Local\Temp\setup.exe
explorer.exe
User:
admin
Company:
torrent-igruha.org
Integrity Level:
HIGH
Description:
Half-Life 2 Complete Edition Setup
Exit code:
0
Version:
1.0.0.5
Modules
Images
c:\users\admin\appdata\local\temp\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
3524"C:\Users\admin\AppData\Local\Temp\is-D6JCC.tmp\setup.tmp" /SL5="$70134,1698870,245248,C:\Users\admin\AppData\Local\Temp\setup.exe" C:\Users\admin\AppData\Local\Temp\is-D6JCC.tmp\setup.tmpsetup.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-d6jcc.tmp\setup.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
3624"C:\Program Files\Half-Life 2 Complete Edition\unins000.exe" /VERYSILENTC:\Program Files\Half-Life 2 Complete Edition\unins000.exesetup.tmp
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\program files\half-life 2 complete edition\unins000.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
3632"C:\Users\admin\AppData\Local\Temp\_iu14D2N.tmp" /SECONDPHASE="C:\Program Files\Half-Life 2 Complete Edition\unins000.exe" /FIRSTPHASEWND=$501A0 /VERYSILENTC:\Users\admin\AppData\Local\Temp\_iu14D2N.tmpunins000.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\_iu14d2n.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
Total events
771
Read events
764
Write events
0
Delete events
7

Modification events

(PID) Process:(3632) _iu14D2N.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Half-Life 2 Complete Edition_is1
Operation:delete keyName:(default)
Value:
(PID) Process:(3632) _iu14D2N.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers
Operation:delete valueName:C:\Program Files\Half-Life 2 Complete Edition\Half-Life 2 Episode Two.exe
Value:
RUNASADMIN
(PID) Process:(3632) _iu14D2N.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers
Operation:delete valueName:C:\Program Files\Half-Life 2 Complete Edition\Half-Life 2 Episode One.exe
Value:
RUNASADMIN
(PID) Process:(3632) _iu14D2N.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers
Operation:delete valueName:C:\Program Files\Half-Life 2 Complete Edition\Half-Life 2 Lost Coast.exe
Value:
RUNASADMIN
(PID) Process:(3632) _iu14D2N.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers
Operation:delete valueName:C:\Program Files\Half-Life 2 Complete Edition\Half-Life Source.exe
Value:
RUNASADMIN
(PID) Process:(3632) _iu14D2N.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers
Operation:delete valueName:C:\Program Files\Half-Life 2 Complete Edition\hl2.exe
Value:
RUNASADMIN
(PID) Process:(3632) _iu14D2N.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers
Operation:delete keyName:(default)
Value:
Executable files
16
Suspicious files
2
Text files
7
Unknown types
0

Dropped files

PID
Process
Filename
Type
3524setup.tmpC:\Users\admin\AppData\Local\Temp\is-NLBOJ.tmp\cls.ini
MD5:
SHA256:
3524setup.tmpC:\Users\admin\AppData\Local\Temp\is-NLBOJ.tmp\_isetup\_shfoldr.dllexecutable
MD5:92DC6EF532FBB4A5C3201469A5B5EB63
SHA256:9884E9D1B4F8A873CCBD81F8AD0AE257776D2348D027D811A56475E028360D87
3524setup.tmpC:\Users\admin\AppData\Local\Temp\is-NLBOJ.tmp\CLS-srep.dllexecutable
MD5:E68C32297A0B144D13C0B5870CA8C8D8
SHA256:6954112104BA041D18760DE5EB7E6825CC14CEC98FF49939A587CC6B27908BD2
3524setup.tmpC:\Users\admin\AppData\Local\Temp\is-NLBOJ.tmp\ISDone.dllexecutable
MD5:4FEAFA8B5E8CDB349125C8AF0AC43974
SHA256:BB8A0245DCC5C10A1C7181BAD509B65959855009A8105863EF14F2BB5B38AC71
3524setup.tmpC:\Users\admin\AppData\Local\Temp\is-NLBOJ.tmp\unarc.dllexecutable
MD5:C8600EE0BAD1CB2A899B792CB6C1869B
SHA256:B670F7E828AEFF88BBE6351BF3B0775AF39ADC1BFAC3B84AF4061A4C78ED174A
3524setup.tmpC:\Users\admin\AppData\Local\Temp\is-NLBOJ.tmp\Russian.initext
MD5:C2F6F1038DE8369B2E31067EA4D48536
SHA256:1CFA41921DCE01991640DB414D4955B1A6DC6D6FA4F4333CA7552E2E8B81391E
3524setup.tmpC:\Users\admin\AppData\Local\Temp\is-NLBOJ.tmp\botva2.dllexecutable
MD5:67965A5957A61867D661F05AE1F4773E
SHA256:450B9B0BA25BF068AFBC2B23D252585A19E282939BF38326384EA9112DFD0105
3524setup.tmpC:\Users\admin\AppData\Local\Temp\is-NLBOJ.tmp\b2p.dllexecutable
MD5:AB35386487B343E3E82DBD2671FF9DAB
SHA256:C3729545522FCFF70DB61046C0EFD962DF047D40E3B5CCD2272866540FC872B2
3524setup.tmpC:\Users\admin\AppData\Local\Temp\is-NLBOJ.tmp\CallbackCtrl.dllexecutable
MD5:F07E819BA2E46A897CFABF816D7557B2
SHA256:68F42A7823ED7EE88A5C59020AC52D4BBCADF1036611E96E470D986C8FAA172D
3524setup.tmpC:\Users\admin\Documents\TI\icon.icoimage
MD5:516B46D8BA74C15AF629E09E05E02CDD
SHA256:EB495744A32B3D773CDC6AAD2C1570C991923CD4EB4C8A21DB8F722F37F96156
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:137
whitelisted
2588
svchost.exe
239.255.255.250:1900
whitelisted

DNS requests

No data

Threats

No threats detected
No debug info