File name:

snare-agent-for-windows-intersect-alliance-pty-ltd.exe

Full analysis: https://app.any.run/tasks/fd7e2057-1211-4c1b-8c2e-26d35a67fe57
Verdict: Malicious activity
Analysis date: May 22, 2025, 01:32:21
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
inno
installer
delphi
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 8 sections
MD5:

269593C33614F56C32289450E6B32343

SHA1:

20B44F64F9E1B2DD14059FAC3B822052F360CB4E

SHA256:

31AA32B8163998807A241B7D0E8024C2D340F801920AD17F02511CAD1453ED50

SSDEEP:

49152:XRnwapWAwZOTAV9SlbMz/Ivjdsi2wA42tZ/5eRLdHiVDBcMsUW4zm9Ianle69G8o:hns7Vs9Mzgvjdsi2btFShiX9sb5nle60

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • snare-agent-for-windows-intersect-alliance-pty-ltd.exe (PID: 7540)
      • is-EE65H.tmp (PID: 7564)
    • Reads the Windows owner or organization settings

      • is-EE65H.tmp (PID: 7564)
    • Process drops legitimate windows executable

      • is-EE65H.tmp (PID: 7564)
    • Executes as Windows Service

      • SnareCore.exe (PID: 7516)
  • INFO

    • Create files in a temporary directory

      • snare-agent-for-windows-intersect-alliance-pty-ltd.exe (PID: 7540)
      • is-EE65H.tmp (PID: 7564)
    • Checks supported languages

      • snare-agent-for-windows-intersect-alliance-pty-ltd.exe (PID: 7540)
      • is-EE65H.tmp (PID: 7564)
      • SnareCore.exe (PID: 7516)
    • The sample compiled with english language support

      • snare-agent-for-windows-intersect-alliance-pty-ltd.exe (PID: 7540)
      • is-EE65H.tmp (PID: 7564)
    • Reads the computer name

      • is-EE65H.tmp (PID: 7564)
      • SnareCore.exe (PID: 7516)
    • Detects InnoSetup installer (YARA)

      • snare-agent-for-windows-intersect-alliance-pty-ltd.exe (PID: 7540)
      • is-EE65H.tmp (PID: 7564)
    • Compiled with Borland Delphi (YARA)

      • is-EE65H.tmp (PID: 7564)
    • Creates files in the program directory

      • is-EE65H.tmp (PID: 7564)
    • Creates files or folders in the user directory

      • is-EE65H.tmp (PID: 7564)
    • Creates a software uninstall entry

      • is-EE65H.tmp (PID: 7564)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable PowerBASIC/Win 9.x (51.2)
.exe | Inno Setup installer (37.9)
.exe | Win32 Executable Delphi generic (4.9)
.dll | Win32 Dynamic Link Library (generic) (2.2)
.exe | Win32 Executable (generic) (1.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 1992:06:19 22:22:17+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 36864
InitializedDataSize: 16896
UninitializedDataSize: -
EntryPoint: 0x98d8
OSVersion: 1
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 0.0.0.0
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
Comments: This installation was built with Inno Setup: http://www.innosetup.com
CompanyName: InterSect Alliance Pty Ltd
FileDescription: Snare Setup
FileVersion:
LegalCopyright: Copyright © 1999-2012 InterSect Alliance Pty Ltd.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
141
Monitored processes
6
Malicious processes
1
Suspicious processes
1

Behavior graph

Click at the process to see the details
start snare-agent-for-windows-intersect-alliance-pty-ltd.exe is-ee65h.tmp sppextcomobj.exe no specs slui.exe no specs snarecore.exe snare-agent-for-windows-intersect-alliance-pty-ltd.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
7468"C:\Users\admin\AppData\Local\Temp\snare-agent-for-windows-intersect-alliance-pty-ltd.exe" C:\Users\admin\AppData\Local\Temp\snare-agent-for-windows-intersect-alliance-pty-ltd.exeexplorer.exe
User:
admin
Company:
InterSect Alliance Pty Ltd
Integrity Level:
MEDIUM
Description:
Snare Setup
Exit code:
3221226540
Version:
Modules
Images
c:\users\admin\appdata\local\temp\snare-agent-for-windows-intersect-alliance-pty-ltd.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
7516"C:\Program Files\Snare\SnareCore.exe"C:\Program Files\Snare\SnareCore.exe
services.exe
User:
SYSTEM
Company:
InterSect Alliance Pty Ltd
Integrity Level:
SYSTEM
Description:
SNARE Service
Version:
4, 0, 1, 1
Modules
Images
c:\program files\snare\snarecore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
7540"C:\Users\admin\AppData\Local\Temp\snare-agent-for-windows-intersect-alliance-pty-ltd.exe" C:\Users\admin\AppData\Local\Temp\snare-agent-for-windows-intersect-alliance-pty-ltd.exe
explorer.exe
User:
admin
Company:
InterSect Alliance Pty Ltd
Integrity Level:
HIGH
Description:
Snare Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\appdata\local\temp\snare-agent-for-windows-intersect-alliance-pty-ltd.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
7564"C:\Users\admin\AppData\Local\Temp\is-PHJJL.tmp\is-EE65H.tmp" /SL4 $40272 "C:\Users\admin\AppData\Local\Temp\snare-agent-for-windows-intersect-alliance-pty-ltd.exe" 867800 52224 C:\Users\admin\AppData\Local\Temp\is-PHJJL.tmp\is-EE65H.tmp
snare-agent-for-windows-intersect-alliance-pty-ltd.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.44.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-phjjl.tmp\is-ee65h.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
7624C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
7656"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exeSppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
Total events
896
Read events
756
Write events
140
Delete events
0

Modification events

(PID) Process:(7564) is-EE65H.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\InterSect Alliance\AuditService\Config
Operation:writeName:Audit
Value:
1
(PID) Process:(7564) is-EE65H.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\InterSect Alliance\AuditService\Config
Operation:writeName:Checksum
Value:
0
(PID) Process:(7564) is-EE65H.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\InterSect Alliance\AuditService\Config
Operation:writeName:Clientname
Value:
(PID) Process:(7564) is-EE65H.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\InterSect Alliance\AuditService\Config
Operation:writeName:CritAudit
Value:
0
(PID) Process:(7564) is-EE65H.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\InterSect Alliance\AuditService\Config
Operation:writeName:Delimiter
Value:
(PID) Process:(7564) is-EE65H.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\InterSect Alliance\AuditService\Config
Operation:writeName:EnableUSB
Value:
0
(PID) Process:(7564) is-EE65H.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\InterSect Alliance\AuditService\Config
Operation:writeName:FileAudit
Value:
0
(PID) Process:(7564) is-EE65H.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\InterSect Alliance\AuditService\Config
Operation:writeName:FileExport
Value:
0
(PID) Process:(7564) is-EE65H.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\InterSect Alliance\AuditService\Config
Operation:writeName:ClearTabs
Value:
0
(PID) Process:(7564) is-EE65H.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\InterSect Alliance\AuditService\Config
Operation:writeName:LeaveRetention
Value:
0
Executable files
11
Suspicious files
4
Text files
8
Unknown types
0

Dropped files

PID
Process
Filename
Type
7564is-EE65H.tmpC:\Users\admin\AppData\Local\Temp\is-5CJUL.tmp\_isetup\_shfoldr.dllexecutable
MD5:92DC6EF532FBB4A5C3201469A5B5EB63
SHA256:9884E9D1B4F8A873CCBD81F8AD0AE257776D2348D027D811A56475E028360D87
7564is-EE65H.tmpC:\Users\admin\AppData\Local\Temp\is-5CJUL.tmp\SnareWindowsInstallSupport.dllexecutable
MD5:7DAFD83D25FCA057ED3B59D410164B44
SHA256:6F60FE313EDE82E9E0312D178EE8E6B0BBD12B2B6C0DC5B7FCF1E531292B8BD0
7564is-EE65H.tmpC:\Users\admin\AppData\Local\Temp\is-5CJUL.tmp\_isetup\_RegDLL.tmpexecutable
MD5:C594B792B9C556EA62A30DE541D2FB03
SHA256:5DCC1E0A197922907BCA2C4369F778BD07EE4B1BBBDF633E987A028A314D548E
7564is-EE65H.tmpC:\Program Files\Snare\is-RV1I8.tmpexecutable
MD5:F666A582BDAF34BF9CED31E690A95C96
SHA256:7D56C88818B354CD9880F847F40A6BB5C8BE740247EA2CF260D141146C29AB76
7564is-EE65H.tmpC:\Users\admin\AppData\Local\Temp\is-5CJUL.tmp\_isetup\_setup64.tmpexecutable
MD5:AA879BAA50DCCA58AD6CD14A92814695
SHA256:7C4BCD92059137479EC4863A202D8E6EEA878EF1E45AC6C9E503498EA4977B8A
7564is-EE65H.tmpC:\Program Files\Snare\is-U4IDE.tmptext
MD5:EF2B18C03EB3CB39DD7E85700309844E
SHA256:C8B6454742BFE5455850021E1BD2B39A371B9BB7A9060CAEE28131AEAD4A6495
7564is-EE65H.tmpC:\Program Files\Snare\Readme.txttext
MD5:A45990AE48EBC38D3AB3E06F94734274
SHA256:D56107AC5F3723E0775AEEC818DA94C7D7F75CB155BD896D724C7C5B9FB7900A
7564is-EE65H.tmpC:\Program Files\Snare\openweb.battext
MD5:816D8F2A2122E1D6F2C6D1EA4D3591EB
SHA256:A4CB2CD1152AEA5588100083E479474F1623E5CCD6C936F88057EE1AA286057F
7564is-EE65H.tmpC:\Program Files\Snare\is-EDF4U.tmptext
MD5:816D8F2A2122E1D6F2C6D1EA4D3591EB
SHA256:A4CB2CD1152AEA5588100083E479474F1623E5CCD6C936F88057EE1AA286057F
7564is-EE65H.tmpC:\Program Files\Snare\stopweb.battext
MD5:EF2B18C03EB3CB39DD7E85700309844E
SHA256:C8B6454742BFE5455850021E1BD2B39A371B9BB7A9060CAEE28131AEAD4A6495
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
19
DNS requests
12
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
23.53.40.176:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
2420
SIHClient.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
2420
SIHClient.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
172.211.123.249:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6544
svchost.exe
20.190.159.130:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
23.53.40.176:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
2.23.246.101:80
www.microsoft.com
Ooredoo Q.S.C.
QA
whitelisted
4996
RUXIMICS.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2104
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5496
MoUsoCoreWorker.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
client.wns.windows.com
  • 172.211.123.249
whitelisted
google.com
  • 142.250.186.46
whitelisted
settings-win.data.microsoft.com
  • 51.104.136.2
  • 20.73.194.208
whitelisted
login.live.com
  • 20.190.159.130
  • 40.126.31.2
  • 20.190.159.71
  • 20.190.159.73
  • 40.126.31.73
  • 20.190.159.131
  • 40.126.31.131
  • 20.190.159.128
whitelisted
crl.microsoft.com
  • 23.53.40.176
  • 23.53.41.90
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
www.microsoft.com
  • 2.23.246.101
whitelisted
slscr.update.microsoft.com
  • 4.175.87.197
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 52.165.164.15
whitelisted

Threats

No threats detected
Process
Message
SnareCore.exe
[SNARE 4.0.1.1](7512 - 22/05/2025 01:32:49): no args
SnareCore.exe
[SNARE 4.0.1.1](7512 - 22/05/2025 01:32:49): [StartService] SNARE Debug: 0
SnareCore.exe
[SNARE 4.0.1.1](7536 - 22/05/2025 01:32:49): SNAREDEBUG: 0
SnareCore.exe
[SNARE 4.0.1.1](7512 - 22/05/2025 01:32:49): Args grabbed