|
Analyzing...
|
File Name:   setup-installer
SHA1:   4d5c5c1ba6772ad21961df8753cdb0f4ff4af270
MD5:   ca4f3b96b0c56db749d1845c2d40d2b9
First Seen Date:  2017-06-23 05:30:13.926016 ( )
Number of Clients Seen:   8
Last Analysis Date:  2017-06-23 05:30:13.926016 ( )
Human Expert Analysis Result:   No human expert analysis verdict given to this sample yet.
Analysis Summary
| Analysis Type | Date | Verdict | |
|---|---|---|---|
| Signature Based Detection | 2017-06-23 05:30:13.926016 | Clean | |
| Static Analysis Overall Verdict | 2017-06-23 05:30:13.926016 | No Threat Found | help |
| Dynamic Analysis Overall Verdict | 2017-06-23 05:30:13.926016 | No Threat Found | help |
| Precise Detectors Overall Verdict | 2017-06-23 05:30:13.926016 | No Match | help |
Static Analysis
| Static Analysis Overall Verdict | Result |
|---|---|
| No Threat Found | help |
| Detector | Result | |
|---|---|---|
| Optional Header LoaderFlags field is valued illegal | Clean | |
| Non-ascii or empty section names detected | Clean | |
| Illegal size of optional Header | Clean | |
| Packer detection on signature database | Unknown | help |
| Based on the sections entropy check! file is possibly packed | Clean | |
| Timestamp value suspicious | Clean | |
| Header Checksum is zero! | Clean | |
| Enrty point is outside the 1st(.code) section! Binary is possibly packed | Clean | |
| Optional Header NumberOfRvaAndSizes field is valued illegal | Clean | |
| Anti-vm present | Clean | |
| The Size Of Raw data is valued illegal! Binary might crash your disassembler/debugger | Suspicious | |
| TLS callback functions array detected | Clean | |
Dynamic Analysis
| Dynamic Analysis Overall Verdict | Result |
|---|---|
| No Threat Found | help |
| Suspicious Behaviors | |
|---|---|
| Opens a file in a system directory | |
| Uses a function clandestinely | |
Behavioral Information
C:\setup-installer
C:\Windows\system32\RichEd20.dll
C:\Windows\syswow64\MSCTF.dll
C:\Windows\syswow64\USER32.dll
{"lDistanceToMove": "17c0f", "dwMoveMethod": "0", "lpDistanceToMoveHigh": "0", "hFile": "190"}
{"lDistanceToMove": "1525c", "dwMoveMethod": "0", "lpDistanceToMoveHigh": "0", "hFile": "190"}
{"lDistanceToMove": "0", "dwMoveMethod": "1", "lpDistanceToMoveHigh": "0", "hFile": "190"}
{"lDistanceToMove": "f432", "dwMoveMethod": "0", "lpDistanceToMoveHigh": "0", "hFile": "190"}
{"lDistanceToMove": "c21c", "dwMoveMethod": "0", "lpDistanceToMoveHigh": "0", "hFile": "190"}
{"lDistanceToMove": "ca67", "dwMoveMethod": "0", "lpDistanceToMoveHigh": "0", "hFile": "190"}
{"lDistanceToMove": "e27a", "dwMoveMethod": "0", "lpDistanceToMoveHigh": "0", "hFile": "190"}
1ec
198
1c4
2e4
23c
244
1bc
274
240
2dc
264
248
220
C:\Windows\system32\UXTHEME.dll
C:\Windows\system32\USERENV.dll
C:\Windows\system32\SETUPAPI.dll
API-MS-Win-Core-LocalRegistry-L1-1-0.dll
advapi32.dll
C:\Windows\system32\APPHELP.dll
C:\Windows\system32\PROPSYS.dll
ADVAPI32.dll
propsys.dll
C:\Windows\system32\DWMAPI.dll
C:\Windows\system32\CRYPTBASE.dll
C:\Windows\system32\OLEACC.dll
OLEACCRC.DLL
C:\Windows\system32\CLBCATQ.dll
C:\Windows\system32\SHFOLDER.dll
ole32.dll
comctl32.dll
SHELL32.dll
ntmarta.dll
C:\Windows\system32\RichEd20.dll
UxTheme.dll
C:\Windows\system32\ole32.dll
C:\Windows\syswow64\MSCTF.dll
C:\Users\win7\AppData\Local\Temp\nsf3602.tmp\System.dll
C:\Users\win7\AppData\Local\Temp\nsf3602.tmp\nsDialogs.dll
OLEAUT32.DLL
IMM32.dll
C:\Users\win7\AppData\Local\Temp\nsf3602.tmp\inetc.dll
Secur32.dll
api-ms-win-downlevel-advapi32-l2-1-0.dll
api-ms-win-downlevel-ole32-l1-1-0.dll
WS2_32.dll
winhttp.dll
wininet.dll
IPHLPAPI.DLL
CRYPT32.dll
USERENV.dll
api-ms-win-downlevel-shlwapi-l2-1-0.dll
DNSAPI.dll
dhcpcsvc.DLL
API-MS-Win-Security-LSALookup-L1-1-0.dll
CRYPTBASE.dll
OLEAUT32.dll
DnsCacheEntries
DisableKeepAlive
CacheMode
ProxyHttp1.1
DisableBasicOverClearChannel
DisableBranchCache
ScavengeCacheLowerBound
CertCacheNoValidate
IdnEnabled
LeashLegacyCookies
Plane16
MaxConnectionsPer1_0Server
Plane14
Plane15
Plane12
Plane13
Plane10
Plane11
MaxConnectionsPerProxy
DnsCacheTimeout
UseFirstAvailable
FrameMerging
SendTimeOut
DefaultConnectionSettings
WpadSearchAllDomains
ProxyOverride
Plane4
Plane5
Plane6
Plane7
BadProxyExpiresTime
Plane2
Plane3
HttpDefaultExpiryTimeSecs
FromCacheTimeout
Plane8
Plane9
ProxyEnable
SendExtraCRLF
DisableNTLMPreAuth
ShareCredsWithWinHttp
SocketSendBufferLength
ReceiveTimeOut
WarnOnPost
EnforceP3PValidity
ServerInfoTimeout
ConnectTimeOut
AlwaysDrainOnRedirect
WarnOnZoneCrossing
DontUseDNSLoadBalancing
EnableSpdyDebugAsserts
SecureProtocols
WarnAlwaysOnPost
AutoConfigURL
WpadOverride
PreConnectLimit
SavedLegacySettings
MaxConnectionsPerServer
TcpAutotuning
TabProcGrowth
EnableNegotiate
WarnOnBadCertRecving
EnableHttp1_1
SocketReceiveBufferLength
ClientAuthBuiltInUI
FtpDefaultExpiryTimeSecs
ScavengeCacheFileLimit
SyncMode5
CombineFalseStartData
Plane1
DnsCacheEnabled
DisableReadRange
DisableFalseStartBlocklist
ConnectRetries
SqmHttpStreamRandomUploadPoolSize
WarnOnPostRedirect
Disable
FrameTabWindow
MaxHttpRedirects
DataFilePath
AutoDetect
SystemSetupInProgress
AutoProxyDetectType
SessionMerging
ScavengeCacheFileLifeTime
FEATURE_CLIENTAUTHCERTFILTER
KeepAliveTimeout
WarnOnHTTPSToHTTPRedirect
PreResolveLimit
ProgramFilesDir
ProxyServer
DuoProtocols
AdminTabProcs
{"Reserved": "0", "hKey": "2dc", "lpData": "5bb718", "dwType": "3", "lpValueName": "SavedLegacySettings", "cbData": "b8"}
{"Reserved": "0", "hKey": "2e4", "lpData": "32ef330", "dwType": "4", "lpValueName": "ProxyEnable", "cbData": "4"}
{"h_key": "80000001", "samDesired": "1", "Reserved": "0", "lpSecurityAttributes": "0", "lpdwDisposition": "0", "dwOptions": "0", "lpClass": "", "phkResult": "32ef334", "lpSubKey": "Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Connections"}
{"h_key": "80000001", "samDesired": "1", "Reserved": "0", "lpSecurityAttributes": "0", "lpdwDisposition": "0", "dwOptions": "0", "lpClass": "", "phkResult": "32ef294", "lpSubKey": "Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Connections"}
{"h_key": "80000001", "samDesired": "1", "Reserved": "0", "lpSecurityAttributes": "0", "lpdwDisposition": "0", "dwOptions": "0", "lpClass": "", "phkResult": "32ef318", "lpSubKey": "Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Connections"}
{"h_key": "80000001", "samDesired": "2", "Reserved": "0", "lpSecurityAttributes": "0", "lpdwDisposition": "0", "dwOptions": "0", "lpClass": "", "phkResult": "32ef2d4", "lpSubKey": "Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Connections"}
{"h_key": "80000001", "samDesired": "2001f", "Reserved": "0", "lpSecurityAttributes": "0", "lpdwDisposition": "0", "dwOptions": "0", "lpClass": "<NULL>", "phkResult": "26afc08", "lpSubKey": "Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad"}
{"h_key": "80000001", "samDesired": "1", "Reserved": "0", "lpSecurityAttributes": "0", "lpdwDisposition": "0", "dwOptions": "0", "lpClass": "", "phkResult": "32ef214", "lpSubKey": "Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Connections"}
{"h_key": "80000001", "samDesired": "2001f", "Reserved": "0", "lpSecurityAttributes": "0", "lpdwDisposition": "32ef580", "dwOptions": "0", "lpClass": "<NULL>", "phkResult": "32ef584", "lpSubKey": "SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Internet Settings"}
{"h_key": "80000001", "samDesired": "20006", "Reserved": "0", "lpSecurityAttributes": "0", "lpdwDisposition": "0", "dwOptions": "0", "lpClass": "", "phkResult": "32ef334", "lpSubKey": "Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings"}
{"dwCreationDisposition": "3", "path": "C:\\Windows\\system32\\rsaenh.dll", "dwDesiredAccess": "80000000", "dwShareMode": "1"}
{"dwCreationDisposition": "3", "path": "C:\\Users\\win7\\AppData\\Local\\Microsoft\\Windows\\Caches\\cversions.1.db", "dwDesiredAccess": "80000000", "dwShareMode": "3"}
{"dwCreationDisposition": "2", "path": "C:\\Users\\win7\\AppData\\Local\\Temp\\nsf3602.tmp\\TopLogo1.bmp", "dwDesiredAccess": "40000000", "dwShareMode": "1"}
{"dwCreationDisposition": "1", "path": "C:\\Users\\win7\\AppData\\Local\\Temp\\nsf3602.tmp\\System.dll", "dwDesiredAccess": "40000000", "dwShareMode": "1"}
{"dwCreationDisposition": "1", "path": "C:\\Users\\win7\\AppData\\Local\\Temp\\nsf3602.tmp\\inetc.dll", "dwDesiredAccess": "40000000", "dwShareMode": "1"}
{"dwCreationDisposition": "3", "path": "C:\\Windows", "dwDesiredAccess": "100081", "dwShareMode": "7"}
{"dwCreationDisposition": "3", "path": "C:\\Users\\win7\\AppData\\Local\\Temp\\nsf3602.tmp\\TopLogo1.bmp", "dwDesiredAccess": "80000000", "dwShareMode": "1"}
{"dwCreationDisposition": "4", "path": "C:\\Users\\win7\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\counters.dat", "dwDesiredAccess": "c0000000", "dwShareMode": "3"}
{"dwCreationDisposition": "3", "path": "\\\\.\\Nsi", "dwDesiredAccess": "0", "dwShareMode": "3"}
{"dwCreationDisposition": "1", "path": "C:\\Users\\win7\\AppData\\Local\\Temp\\nsf3602.tmp\\nsDialogs.dll", "dwDesiredAccess": "40000000", "dwShareMode": "1"}
{"dwCreationDisposition": "3", "path": "C:\\", "dwDesiredAccess": "100081", "dwShareMode": "7"}
{"dwCreationDisposition": "3", "path": "C:\\setup-installer", "dwDesiredAccess": "80000000", "dwShareMode": "1"}
{"dwCreationDisposition": "3", "path": "C:\\Users\\win7\\AppData\\Local\\Microsoft\\Windows\\Caches\\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000008.db", "dwDesiredAccess": "80000000", "dwShareMode": "1"}
{"dwCreationDisposition": "3", "path": "C:\\Windows\\Fonts\\staticcache.dat", "dwDesiredAccess": "80000000", "dwShareMode": "5"}
{"hKey": "21c", "phkResult": "0", "lpSubKey": "FEATURE_SKIP_POST_RETRY_ON_INTERNETWRITEFILE_KB895954"}
{"hKey": "80000001", "phkResult": "0", "lpSubKey": "Software"}
{"hKey": "80000002", "phkResult": "0", "lpSubKey": "SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\5.0\\Cache"}
{"hKey": "21c", "phkResult": "0", "lpSubKey": "FEATURE_ENABLE_PROXY_CACHE_REFRESH_KB2983228"}
{"hKey": "21c", "phkResult": "0", "lpSubKey": "FEATURE_DISALLOW_NULL_IN_RESPONSE_HEADERS"}
{"hKey": "80000002", "phkResult": "0", "lpSubKey": "SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Internet Settings"}
{"hKey": "80000002", "phkResult": "0", "lpSubKey": "Software\\Policies\\Microsoft\\Internet Explorer\\Main\\FeatureControl"}
{"hKey": "80000002", "phkResult": "0", "lpSubKey": "Software\\Microsoft\\Internet Explorer\\Main"}
{"hKey": "80000002", "phkResult": "0", "lpSubKey": "SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\DataStore_V1.0"}
{"hKey": "80000001", "phkResult": "0", "lpSubKey": "Software\\Policies\\Microsoft\\Internet Explorer\\Main"}
{"hKey": "21c", "phkResult": "0", "lpSubKey": "FEATURE_DIGEST_NO_EXTRAS_IN_URI"}
{"hKey": "80000002", "phkResult": "0", "lpSubKey": "Software\\Policies\\Microsoft\\Internet Explorer\\Main"}
{"hKey": "21c", "phkResult": "0", "lpSubKey": "RETRY_HEADERONLYPOST_ONCONNECTIONRESET"}
{"hKey": "21c", "phkResult": "0", "lpSubKey": "FEATURE_HTTP_USERNAME_PASSWORD_DISABLE"}
{"hKey": "80000001", "phkResult": "0", "lpSubKey": "SOFTWARE\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\5.0\\Cache"}
{"hKey": "80000001", "phkResult": "0", "lpSubKey": "Software\\Microsoft\\Internet Explorer\\Main"}
{"hKey": "80000001", "phkResult": "0", "lpSubKey": "Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings"}
{"hKey": "80000002", "phkResult": "0", "lpSubKey": "Software"}
{"hKey": "80000001", "phkResult": "0", "lpSubKey": "Software\\Policies"}
{"hKey": "80000001", "phkResult": "0", "lpSubKey": "SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\5.0\\Cache"}
{"hKey": "21c", "phkResult": "0", "lpSubKey": "FEATURE_IGNORE_MAPPINGS_FOR_CREDPOLICY"}
{"hKey": "21c", "phkResult": "0", "lpSubKey": "FEATURE_USE_CNAME_FOR_SPN_KB911149"}
{"hKey": "80000001", "phkResult": "0", "lpSubKey": "Software\\Policies\\Microsoft\\Internet Explorer\\Main\\FeatureControl"}
{"hKey": "80000002", "phkResult": "0", "lpSubKey": "Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings"}
{"hKey": "21c", "phkResult": "0", "lpSubKey": "FEATURE_USE_UTF8_FOR_BASIC_AUTH_KB967545"}
{"hKey": "21c", "phkResult": "0", "lpSubKey": "FEATURE_RETURN_FAILED_CONNECT_CONTENT_KB942615"}
{"hKey": "80000001", "phkResult": "0", "lpSubKey": "Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings"}
{"hKey": "21c", "phkResult": "0", "lpSubKey": "FEATURE_COMPAT_USE_CONNECTION_BASED_NEGOTIATE_AUTH_KB2151543"}
{"hKey": "21c", "phkResult": "0", "lpSubKey": "FEATURE_BUFFERBREAKING_818408"}
{"hKey": "80000002", "phkResult": "0", "lpSubKey": "Software\\Policies\\Microsoft\\Internet Explorer"}
{"hKey": "354", "phkResult": "0", "lpSubKey": "{35B2A6E5-E669-426E-AFB6-1C7A607735EF}"}
{"hKey": "80000002", "phkResult": "0", "lpSubKey": "SOFTWARE\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\5.0\\Cache"}
{"hKey": "80000002", "phkResult": "0", "lpSubKey": "Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl"}
{"hKey": "21c", "phkResult": "0", "lpSubKey": "FEATURE_MIME_HANDLING"}
{"hKey": "80000002", "phkResult": "0", "lpSubKey": "System\\Setup"}
{"hKey": "80000002", "phkResult": "0", "lpSubKey": "Software\\Microsoft\\Windows\\CurrentVersion"}
{"hKey": "21c", "phkResult": "0", "lpSubKey": "FEATURE_BYPASS_CACHE_FOR_CREDPOLICY_KB936611"}
{"hKey": "80000002", "phkResult": "0", "lpSubKey": "SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\SurrogateFallback"}
{"hKey": "80000002", "phkResult": "0", "lpSubKey": "Software\\Policies"}
{"hKey": "21c", "phkResult": "0", "lpSubKey": "FEATURE_PRESERVE_SPACES_IN_FILENAMES_KB952730"}
{"hKey": "80000001", "phkResult": "0", "lpSubKey": "Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad"}
{"hKey": "21c", "phkResult": "0", "lpSubKey": "FEATURE_FIX_CHUNKED_PROXY_SCRIPT_DOWNLOAD_KB843289"}
{"hKey": "21c", "phkResult": "0", "lpSubKey": "FEATURE_SCH_SEND_AUX_RECORD_KB_2618444"}
{"hKey": "80000001", "phkResult": "0", "lpSubKey": "Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl"}
{"hKey": "80000002", "phkResult": "0", "lpSubKey": "Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\5.0\\Cache"}
{"hKey": "80000002", "phkResult": "0", "lpSubKey": "Software\\Policies\\Microsoft\\PeerDist\\Service"}
{"hKey": "21c", "phkResult": "0", "lpSubKey": "FEATURE_DISABLE_NOTIFY_UNVERIFIED_SPN_KB2385266"}
{"hKey": "80000002", "phkResult": "0", "lpSubKey": "Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings"}
{"hKey": "21c", "phkResult": "0", "lpSubKey": "FEATURE_PERMIT_CACHE_FOR_AUTHENTICATED_FTP_KB910274"}
{"hKey": "1c4", "phkResult": "0", "lpSubKey": "MS Shell Dlg 2"}
{"hKey": "80000002", "phkResult": "0", "lpSubKey": "SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\FontLink\\SystemLink"}
{"hKey": "80000002", "phkResult": "0", "lpSubKey": "Software\\Microsoft\\Windows NT\\CurrentVersion\\PeerDist\\Service"}
{"hKey": "21c", "phkResult": "0", "lpSubKey": "FEATURE_ENABLE_PASSPORT_SESSION_STORE_KB948608"}
{"hKey": "21c", "phkResult": "0", "lpSubKey": "FEATURE_DISABLE_UNICODE_HANDLE_CLOSING_CALLBACK"}
{"hKey": "21c", "phkResult": "0", "lpSubKey": "FEATURE_INCLUDE_PORT_IN_SPN_KB908209"}
{"hKey": "21c", "phkResult": "0", "lpSubKey": "FEATURE_EXCLUDE_INVALID_CLIENT_CERT_KB929477"}
<NULL>
Local\MSCTF.Asm.MutexDefault1
{"nNumberOfBytesToWrite": "5200", "lpOverlapped": "0", "lpBuffer": "418c48", "lpNumberOfBytesWritten": "282fd94", "hFile": "164"}
{"nNumberOfBytesToWrite": "8000", "lpOverlapped": "0", "lpBuffer": "418c48", "lpNumberOfBytesWritten": "18fbd8", "hFile": "1c"}
{"nNumberOfBytesToWrite": "2a00", "lpOverlapped": "0", "lpBuffer": "418c48", "lpNumberOfBytesWritten": "18f8d4", "hFile": "1ac"}
{"nNumberOfBytesToWrite": "2600", "lpOverlapped": "0", "lpBuffer": "418c48", "lpNumberOfBytesWritten": "18f8d4", "hFile": "1a4"}
{"nNumberOfBytesToWrite": "4291", "lpOverlapped": "0", "lpBuffer": "418c48", "lpNumberOfBytesWritten": "18fbd8", "hFile": "1c"}
{"nNumberOfBytesToWrite": "fad", "lpOverlapped": "0", "lpBuffer": "418c48", "lpNumberOfBytesWritten": "18fbd8", "hFile": "1c"}
C:\Users\win7\AppData\Local\Temp\nsp35F1.tmp
C:\Users\win7\AppData\Local\Temp\nsf3602.tmp
Precise Detectors Analysis Results
| Detector Name | Date | Verdict | Reason | |
|---|---|---|---|---|
| Uninstaller FP Detector | 2017-06-23 05:29:48.532358 | No Match | help | No match. |
| Yara Rule Static Malware Detector | 2017-06-23 05:29:48.545901 | No Match | help | No match. |
| Static Precise PUA Detector 1 | 2017-06-23 05:29:48.564286 | No Match | help | NotDetected |
| Static Precise Virus Detector | 2017-06-23 05:29:48.559441 | No Match | help | NotDetected |
| Static Precise Trojan Detector | 2017-06-23 05:29:48.546462 | No Match | help | NotDetected |
| Static Precise PUA Detector 2 | 2017-06-23 05:29:48.564700 | No Match | help | No match. |
| Static Precise PUA Detector 3 | 2017-06-23 05:29:48.564849 | No Match | help | No match. |
| Static Precise Virus Detector 2 | 2017-06-23 05:29:48.564439 | No Match | help | No match. |
| Static Precise Trojan Detector 2 | 2017-06-23 05:29:48.568786 | No Match | help | No match. |
| Static Precise Trojan Detector 3 | 2017-06-23 05:29:48.567432 | No Match | help | No match. |
| Malicious Url Detector | 2017-06-23 05:30:13.853528 | No Match | help | No match. |
Advance Heuristics
No Advanced Heuristic Analysis Result Received
Additional File Information
| Property | Value |
|---|
| Name | Virtual Address | Virtual Size | Raw Size | Entropy | MD5 |
|---|