| download: | /Sbis3Plugin/master/win32/sbisplugin-setup-web.exe |
| Full analysis: | https://app.any.run/tasks/eabb6b78-48e0-45f7-92c5-c5b29eeb99a5 |
| Verdict: | Malicious activity |
| Analysis date: | May 27, 2024, 14:18:21 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | E55205B41B09A33F517486B63BA8931A |
| SHA1: | 735AF77D665342572D8A503D7B74F173AB36D841 |
| SHA256: | 34A5E76F07ECAC90D94CF5D5360EB4769B7C26883B4EE273FE9F3BC40985F8FB |
| SSDEEP: | 98304:M+RhDZUicnNttUioSnXQtTWew01U1OCg55fovmQzGmYaLmPRMYrnoHGyscV41Rj4:VYg55foA350X |
| .exe | | | Generic Win/DOS Executable (50) |
|---|---|---|
| .exe | | | DOS Executable Generic (49.9) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 1970:06:12 19:26:45+00:00 |
| ImageFileCharacteristics: | Executable, Large address aware, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 14 |
| CodeSize: | 3750400 |
| InitializedDataSize: | 3793920 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x358607 |
| OSVersion: | 6 |
| ImageVersion: | - |
| SubsystemVersion: | 6 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 24.2148.6.0 |
| ProductVersionNumber: | 24.2148.6.0 |
| FileFlagsMask: | 0x0000 |
| FileFlags: | (none) |
| FileOS: | Unknown (0) |
| ObjectFileType: | Unknown |
| FileSubtype: | - |
| LanguageCode: | English (British) |
| CharacterSet: | Windows, Latin1 |
| CompanyName: | Tensor |
| FileDescription: | Saby Plugin Installer |
| FileVersion: | 24.2148.6.0 |
| InternalName: | setup-web.exe |
| LegalCopyright: | Copyright © Tensor |
| OriginalFileName: | setup-web.exe |
| ProductName: | Saby Plugin Installer |
| ProductVersion: | 24.2148.6.0 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 768 | "C:\Users\admin\Desktop\sbisplugin-setup-web.exe" | C:\Users\admin\Desktop\sbisplugin-setup-web.exe | — | explorer.exe | |||||||||||
User: admin Company: Tensor Integrity Level: MEDIUM Description: Saby Plugin Installer Exit code: 3221226540 Version: 24.2148.6.0 Modules
| |||||||||||||||
| 1020 | "C:\Users\admin\Desktop\sbisplugin-setup-web.exe" | C:\Users\admin\Desktop\sbisplugin-setup-web.exe | explorer.exe | ||||||||||||
User: admin Company: Tensor Integrity Level: HIGH Description: Saby Plugin Installer Exit code: 0 Version: 24.2148.6.0 Modules
| |||||||||||||||
| 1640 | "C:\Users\admin\Desktop\sbisplugin-setup-web.exe" | C:\Users\admin\Desktop\sbisplugin-setup-web.exe | explorer.exe | ||||||||||||
User: admin Company: Tensor Integrity Level: HIGH Description: Saby Plugin Installer Exit code: 0 Version: 24.2148.6.0 Modules
| |||||||||||||||
| 2032 | "C:\Program Files\Windows Media Player\wmpnscfg.exe" | C:\Program Files\Windows Media Player\wmpnscfg.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Network Sharing Service Configuration Application Exit code: 0 Version: 12.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3964 | "C:\Users\admin\Desktop\sbisplugin-setup-web.exe" | C:\Users\admin\Desktop\sbisplugin-setup-web.exe | — | explorer.exe | |||||||||||
User: admin Company: Tensor Integrity Level: MEDIUM Description: Saby Plugin Installer Exit code: 3221226540 Version: 24.2148.6.0 Modules
| |||||||||||||||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1020 | sbisplugin-setup-web.exe | C:\Users\admin\AppData\Local\Temp\SbisPlugin.Installer\Sbis3Plugin.json | binary | |
MD5:2000333A2191D0CBBE8A08E33ADB02E5 | SHA256:28AADE20624DE14BB39D9A1B33CA5C33C261FBD8E43A53DA631835C185C6915C | |||
| 1020 | sbisplugin-setup-web.exe | C:\Users\admin\AppData\Local\Temp\SbisPlugin.Installer\file_info.txt | text | |
MD5:340A39045C40D50DDA207BCFDECE883A | SHA256:D8A1082B68A287D591A958486DC8E132B2EF7673A21EC940917A6BA13FAB69DA | |||
| 1020 | sbisplugin-setup-web.exe | C:\Users\admin\AppData\Local\Temp\SbisPlugin.Installer\https...update.sbis.ru.rules.Sbis3Plugin.json | binary | |
MD5:2000333A2191D0CBBE8A08E33ADB02E5 | SHA256:28AADE20624DE14BB39D9A1B33CA5C33C261FBD8E43A53DA631835C185C6915C | |||
| 1020 | sbisplugin-setup-web.exe | C:\Users\admin\AppData\Local\Temp\SbisPlugin.Installer\windows.i686.extensions.txt | binary | |
MD5:133B34C4DCD45B9071426D640E1EA677 | SHA256:E3BBC31087640072E45E55ECA90ACA677636AC7FB25435EA137F71969BD266D4 | |||
| 1020 | sbisplugin-setup-web.exe | C:\Users\admin\AppData\Local\Temp\SbisPlugin.Installer\sabyapps_install_gui.log | text | |
MD5:A6FDFF6D97C489272C51D210502B89A6 | SHA256:EF03406D150BD218E4EA6BAF79ECE6F2DCD3716D23E9CA92CAEC12C758EFA9E9 | |||
| 1020 | sbisplugin-setup-web.exe | C:\Users\admin\Desktop\sabyapps_install_gui.log | csv | |
MD5:8CBCC411A7232C84F352A9029DFDEE17 | SHA256:7340F73C8EE4056946AE2A08A8667108A507CEEDECA977685859431AFCECE50A | |||
| 1020 | sbisplugin-setup-web.exe | C:\ProgramData\Sbis3Plugin\update-cancellation.txt | text | |
MD5:91C544760F7DDD58739427B499F6A132 | SHA256:610C5E2F6CA536B4956A8228079E92B40642F9888FBB34A30363ECCA4851F29D | |||
| 1020 | sbisplugin-setup-web.exe | C:\Users\admin\AppData\Local\Temp\SbisPlugin.Installer\version.txt | text | |
MD5:1D1130B428539BAE878D1186D36A554C | SHA256:527AA688093F1EA6393A1AB43DB7A55901202B3ABF68B62995F7BB6BF6F5254E | |||
| 1020 | sbisplugin-setup-web.exe | C:\Users\admin\Desktop\web_setup_logs_27_05_2024_15-20-44.zip | compressed | |
MD5:31837EBB4DFB1E86EBA600E1B17E4829 | SHA256:DD6EC5EE4EEAA773331E89F095DE8F3DD60998FCD7483A18FE2B3E1A814C23B5 | |||
| 1020 | sbisplugin-setup-web.exe | C:\ProgramData\Sbis3Plugin\logs\web_installer_history\270524_15-18-34 | binary | |
MD5:F9F9BBD588E1457B0E703BB9C33B605C | SHA256:BB1FDEA95DD0F3495F66C97209A106069B9CBB918D54EFCF6B31409291717887 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:138 | — | — | — | unknown |
1020 | sbisplugin-setup-web.exe | 91.232.93.95:443 | update.sbis.ru | Company Tensor LLC | RU | unknown |
1020 | sbisplugin-setup-web.exe | 139.45.228.9:443 | update-msk2.sbis.ru | JSC RetnNet | RU | unknown |
1020 | sbisplugin-setup-web.exe | 185.167.120.80:443 | update-spb1.sbis.ru | Maloe Innovacionnoe Predpriyatie Bonch IT LLC | RU | unknown |
1020 | sbisplugin-setup-web.exe | 91.194.3.193:443 | update-msk1.sbis.ru | RealHost Ltd. | RU | unknown |
1020 | sbisplugin-setup-web.exe | 212.232.32.6:443 | update-yar1.sbis.ru | Yarnet Ltd | RU | unknown |
1640 | sbisplugin-setup-web.exe | 91.232.93.95:443 | update.sbis.ru | Company Tensor LLC | RU | unknown |
1640 | sbisplugin-setup-web.exe | 139.45.228.9:443 | update-msk2.sbis.ru | JSC RetnNet | RU | unknown |
Domain | IP | Reputation |
|---|---|---|
update.sbis.ru |
| unknown |
update-msk2.sbis.ru |
| unknown |
update-spb1.sbis.ru |
| unknown |
update-msk1.sbis.ru |
| unknown |
update-yar1.sbis.ru |
| unknown |