| File name: | cade-simu-4.0-installer_EY-UN51.exe |
| Full analysis: | https://app.any.run/tasks/5211a1a3-2b05-45a4-9716-25ad3f755d5e |
| Verdict: | Malicious activity |
| Analysis date: | May 28, 2025, 16:17:58 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, 5 sections |
| MD5: | 519323C0BA82598E4304211EE225D998 |
| SHA1: | 34488CDA57D1A98ED2B8FB6B65307AD285F16ED4 |
| SHA256: | 4BC69ACDBC93F0CFA42B28DBCD51BBA4F2E4347EC84054AB5B3178788BB3C60A |
| SSDEEP: | 98304:7PIRMu5DUrszskSGjKuV3XNr/g4T6Gq+flu+ehce/Unba+O+CB3jD9hlS:k |
| .exe | | | Win64 Executable (generic) (17.3) |
|---|---|---|
| .dll | | | Win32 Dynamic Link Library (generic) (4.1) |
| .exe | | | Win32 Executable (generic) (2.8) |
| .exe | | | Generic Win/DOS Executable (1.2) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2024:10:31 15:22:05+00:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 14.42 |
| CodeSize: | 2143744 |
| InitializedDataSize: | 2316288 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x1c118b |
| OSVersion: | 6 |
| ImageVersion: | - |
| SubsystemVersion: | 6 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 3.0.11.0 |
| ProductVersionNumber: | 3.0.11.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Windows NT 32-bit |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| CompanyName: | Softonic |
| FileDescription: | Softonic |
| FileVersion: | 3.0.11.0.0 |
| LegalCopyright: | (c) Softonic |
| ProductName: | Softonic |
| ProductVersion: | 3.0.11.0.0 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 496 | "C:\Program Files\McAfee\WebAdvisor\ServiceHost.exe" | C:\Program Files\McAfee\WebAdvisor\servicehost.exe | services.exe | ||||||||||||
User: SYSTEM Company: McAfee, LLC Integrity Level: SYSTEM Description: McAfee WebAdvisor(service) Version: 4,1,1,1026 Modules
| |||||||||||||||
| 780 | "C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEvent | C:\Windows\System32\slui.exe | — | SppExtComObj.Exe | |||||||||||
User: NETWORK SERVICE Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows Activation Client Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1812 | C:\WINDOWS\system32\SppExtComObj.exe -Embedding | C:\Windows\System32\SppExtComObj.Exe | — | svchost.exe | |||||||||||
User: NETWORK SERVICE Company: Microsoft Corporation Integrity Level: SYSTEM Description: KMS Connection Broker Version: 10.0.19041.3996 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 4152 | "C:\ProgramData\McAfee\WebAdvisor\saBSI\saBSI.exe" /install /affid 91082 PaidDistribution=true saBsiVersion=4.1.1.865 CountryCode=DE /no_self_update | C:\ProgramData\McAfee\WebAdvisor\saBSI\saBSI.exe | saBSI.exe | ||||||||||||
User: admin Company: McAfee, LLC Integrity Level: HIGH Description: McAfee WebAdvisor(bootstrap installer) Exit code: 0 Version: 4,1,1,1006 Modules
| |||||||||||||||
| 5972 | "C:\Program Files\McAfee\WebAdvisor\UIHost.exe" | C:\Program Files\McAfee\WebAdvisor\uihost.exe | — | servicehost.exe | |||||||||||
User: admin Company: McAfee, LLC Integrity Level: MEDIUM Description: McAfee WebAdvisor(user level process) Version: 4,1,1,1026 Modules
| |||||||||||||||
| 6708 | "C:\ProgramData\McAfee\WebAdvisor\saBSI\\installer.exe" /setOem:Affid=91082 /s /thirdparty /upgrade | C:\ProgramData\McAfee\WebAdvisor\saBSI\installer.exe | saBSI.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 6876 | "C:\Users\admin\AppData\Local\Temp\cade-simu-4.0-installer_EY-UN51.exe" | C:\Users\admin\AppData\Local\Temp\cade-simu-4.0-installer_EY-UN51.exe | — | explorer.exe | |||||||||||
User: admin Company: Softonic Integrity Level: MEDIUM Description: Softonic Exit code: 3221226540 Version: 3.0.11.0.0 Modules
| |||||||||||||||
| 6980 | "C:\Users\admin\AppData\Local\Temp\cade-simu-4.0-installer_EY-UN51.exe" | C:\Users\admin\AppData\Local\Temp\cade-simu-4.0-installer_EY-UN51.exe | explorer.exe | ||||||||||||
User: admin Company: Softonic Integrity Level: HIGH Description: Softonic Exit code: 0 Version: 3.0.11.0.0 Modules
| |||||||||||||||
| 7144 | "C:\Program Files\McAfee\Temp2714115429\installer.exe" /setOem:Affid=91082 /s /thirdparty /upgrade | C:\Program Files\McAfee\Temp2714115429\installer.exe | installer.exe | ||||||||||||
User: admin Company: McAfee, LLC Integrity Level: HIGH Description: McAfee WebAdvisor(installer) Exit code: 0 Version: 4,1,1,1026 Modules
| |||||||||||||||
| 7332 | "C:\Users\admin\AppData\Local\Temp\ISVD07C.tmp\saBSI\saBSI.exe" /affid 91082 PaidDistribution=true CountryCode=DE | C:\Users\admin\AppData\Local\Temp\ISVD07C.tmp\saBSI\saBSI.exe | cade-simu-4.0-installer_EY-UN51.exe | ||||||||||||
User: admin Company: McAfee, LLC Integrity Level: HIGH Description: McAfee WebAdvisor(bootstrap installer) Exit code: 0 Version: 4,1,1,865 Modules
| |||||||||||||||
| (PID) Process: | (6980) cade-simu-4.0-installer_EY-UN51.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
| (PID) Process: | (6980) cade-simu-4.0-installer_EY-UN51.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (6980) cade-simu-4.0-installer_EY-UN51.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (6980) cade-simu-4.0-installer_EY-UN51.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\Component Categories\{56FFCC30-D398-11D0-B2AE-00A0C908FA49}\Enum |
| Operation: | write | Name: | Implementing |
Value: 1C00000001000000E907050003001C001000120016007D02010000001E768127E028094199FEB9D127C57AFE | |||
| (PID) Process: | (6980) cade-simu-4.0-installer_EY-UN51.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\Component Categories\{56FFCC30-D398-11D0-B2AE-00A0C908FA49}\Enum |
| Operation: | write | Name: | Implementing |
Value: 1C00000001000000E907050003001C001000120016008D02010000001E768127E028094199FEB9D127C57AFE | |||
| (PID) Process: | (6980) cade-simu-4.0-installer_EY-UN51.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached |
| Operation: | write | Name: | {2781761E-28E0-4109-99FE-B9D127C57AFE} {56FFCC30-D398-11D0-B2AE-00A0C908FA49} 0xFFFF |
Value: 01000000000000009687F521ECCFDB01 | |||
| (PID) Process: | (7332) saBSI.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\WebAdvisor |
| Operation: | write | Name: | UUID |
Value: {56B0BD32-4632-4B4B-97ED-5FB05B864A9E} | |||
| (PID) Process: | (7332) saBSI.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\WebAdvisor |
| Operation: | write | Name: | InstallerFlags |
Value: 1 | |||
| (PID) Process: | (7332) saBSI.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates |
| Operation: | delete value | Name: | 4EFC31460C619ECAE59C1BCE2C008036D94C84B8 |
Value: | |||
| (PID) Process: | (7332) saBSI.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\4EFC31460C619ECAE59C1BCE2C008036D94C84B8 |
| Operation: | write | Name: | Blob |
Value: 040000000100000010000000E94FB54871208C00DF70F708AC47085B0F0000000100000030000000C130BBA37B8B350E89FD5ED76B4F78777FEEE220D3B9E729042BEF6AF46E8E4C1B252E32B3080C681BC9A8A1AFDD0A3C0300000001000000140000004EFC31460C619ECAE59C1BCE2C008036D94C84B809000000010000000C000000300A06082B060105050703031D00000001000000100000005467B0ADDE8D858E30EE517B1A19ECD91400000001000000140000001F00BF46800AFC7839B7A5B443D95650BBCE963B53000000010000001F000000301D301B060567810C010330123010060A2B0601040182373C0101030200C06200000001000000200000007B9D553E1C92CB6E8803E137F4F287D4363757F5D44B37D52F9FCA22FB97DF860B000000010000004200000047006C006F00620061006C005300690067006E00200043006F006400650020005300690067006E0069006E006700200052006F006F007400200052003400350000001900000001000000100000005D1B8FF2C30F63F5B536EDD400F7F9B4200000000100000076050000308205723082035AA00302010202107653FEAC75464893F5E5D74A483A4EF8300D06092A864886F70D01010C05003053310B300906035504061302424531193017060355040A1310476C6F62616C5369676E206E762D73613129302706035504031320476C6F62616C5369676E20436F6465205369676E696E6720526F6F7420523435301E170D3230303331383030303030305A170D3435303331383030303030305A3053310B300906035504061302424531193017060355040A1310476C6F62616C5369676E206E762D73613129302706035504031320476C6F62616C5369676E20436F6465205369676E696E6720526F6F742052343530820222300D06092A864886F70D01010105000382020F003082020A0282020100B62DC530DD7AE8AB903D0372B03A4B991661B2E5FFA5671D371CE57EEC9383AA84F5A3439B98458AB863575D9B00880425E9F868924B82D84BC94A03F3A87F6A8F8A6127BDA144D0FDF53F22C2A34F918DB305B22882915DFB5988050B9706C298F82CA73324EE503A41CCF0A0B07B1D4DD2A8583896E9DFF91B91BB8B102CD2C7431DA20974A180AF7BE6330A0C596B8EBCF4AB5A977B7FAE55FB84F080FE844CD7E2BABDC475A16FBD61107444B29807E274ABFF68DC6C263EE91FE5E00487AD30D30C8D037C55B816705C24782025EB676788ABBA4E34986B7011DE38CAD4BEA1C09CE1DF1E0201D83BE1674384B6CFFC74B72F84A3BFBA09373D676CB1455C1961AB4183F5AC1DEB770D464773CEBFBD9595ED9D2B8810FEFA58E8A757E1B3CFA85AE907259B12C49E80723D93DC8C94DF3B44E62680FCD2C303F08C0CD245D62EE78F989EE604EE426E677E42167162E704F960C664A1B69C81214E2BC66D689486C699747367317A91F2D48C796E7CA6BB7E466F4DC585122BCF9A224408A88537CE07615706171224C0C43173A1983557477E103A45D92DA4519098A9A00737C4651AAA1C6B1677F7A797EC3F1930996F31FBEA40B2E7D2C4FAC9D0F050767459FA8D6D1732BEF8E97E03F4E787759AD44A912C850313022B4280F2896A36CFC84CA0CE9EF8CB8DAD16A7D3DED59B18A7C6923AF18263F12E0E2464DF0203010001A3423040300E0603551D0F0101FF040403020186300F0603551D130101FF040530030101FF301D0603551D0E041604141F00BF46800AFC7839B7A5B443D95650BBCE963B300D06092A864886F70D01010C050003820201005E2BBA749734445F764828408493EE016EE9A1B3D68025E67BE4BC09913D0FFC76ADD7D43020BB8F60D091D61CF29CEF781A2B943202C12496525202D0F3D1FCF29B396E99E11F8E43417D9A1E5BC95D9A84FC26E687F3747226ADA41BD93D3B6A52A03C091E2F1E7BB333B445C7F7ACB1AF9360AD76AEB8B21578EB836AEBFFDB46AB24E5EE02FA901F59C02F5DD6B75DA45C10B77253F8414ECCFA781A254ACAFE85624361C3B437AA81D2F4D63A0FBD8D597E3047DE2B6BE72150335FD4679BD4B8679F3C279903FF85438E7312CA20CDE861D5B166DC17D6396D0FDBCF2337A182894E1C6B3FD6A0CDAA079D3E4226AAD70CEEFA47BF1A527ED17581D3C98A62176D4F88A021A0263EAF6DD962301FE99828AE6E8DD58E4C726693808D2AE355C760679042565C22510FB3DC4E39EE4DDDD91D7810543B6ED0976F03B51EB22373C612B29A64D0FC958524A8FFDFA1B0DC9140AEDF0933ABB9DD92B7F1CC91743B69EB67971B90BFE7C7A06F71BB57BFB78F5AED7A406A16CD80842D2FE102D4249443B315FC0C2B1BFD716FFCCBBC75173A5E83D2C9B32F1BD59C8D7F54FE7E7EE456A387A79DE1595294418F6D5BBE86959AFF1A76DD40D2514A70B41F336323773FEC271E59E40887ED34824A0F3FFEA01DC1F56773458678F4AA29E92787C619DBC61314C33949874DA097E06513F59D7756E9DAB358C73AF2C0CD82 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6708 | installer.exe | C:\Program Files\McAfee\Temp2714115429\browserplugin.cab | — | |
MD5:— | SHA256:— | |||
| 6980 | cade-simu-4.0-installer_EY-UN51.exe | C:\Users\admin\AppData\Local\Temp\ISVD07C.tmp\saBSI.zip | compressed | |
MD5:F68008B70822BD28C82D13A289DEB418 | SHA256:CC6F4FAF4E8A9F4D2269D1D69A69EA326F789620FB98078CC98597F3CB998589 | |||
| 6980 | cade-simu-4.0-installer_EY-UN51.exe | C:\Users\admin\AppData\Local\Temp\ISVD07C.tmp\saBSI\saBSI.exe | executable | |
MD5:143255618462A577DE27286A272584E1 | SHA256:F5AA950381FBCEA7D730AA794974CA9E3310384A95D6CF4D015FBDBD9797B3E4 | |||
| 4152 | saBSI.exe | C:\Users\admin\AppData\Local\Temp\mwa16EB.tmp | executable | |
MD5:32528F494643E0E05625D5A5B8E61263 | SHA256:926061FC6A92079AA227CC2E426BD5B2130501422A95E6A8984F15F05DEE2E70 | |||
| 7332 | saBSI.exe | C:\ProgramData\McAfee\WebAdvisor\saBSI\saBSI.exe | executable | |
MD5:7A1B6316D5D64A740B847D8261EA3E83 | SHA256:5EC42B168F2541DBB413D6F87AA5569470A2B0C6C574C3E655242461A4524763 | |||
| 6708 | installer.exe | C:\Program Files\McAfee\Temp2714115429\logicmodule.cab | compressed | |
MD5:E302174DFA9892A1993D5A87DCF25E96 | SHA256:90F8DD2705B5C65128BDAF5092E83F26FEC6D822F601490F69EC5532A302C256 | |||
| 6980 | cade-simu-4.0-installer_EY-UN51.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\103621DE9CD5414CC2538780B4B75751 | binary | |
MD5:B0975609DE1C11B4D051C51963131F78 | SHA256:40E4558A3E73CADA1B5CBB912C92A4FE2BEB8708E82FED10AEB0B1007462002D | |||
| 6708 | installer.exe | C:\Program Files\McAfee\Temp2714115429\l10n.cab | compressed | |
MD5:485C6EE57565ECA064A92914859B192A | SHA256:FD1BC0582ED13353749AF3C41C2D082516B3DCE58B24E1B1453BDFDFF2CF020E | |||
| 6980 | cade-simu-4.0-installer_EY-UN51.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\103621DE9CD5414CC2538780B4B75751 | der | |
MD5:E192462F281446B5D1500D474FBACC4B | SHA256:F1BA9F1B63C447682EBF9DE956D0DA2A027B1B779ABEF9522D347D3479139A60 | |||
| 6708 | installer.exe | C:\Program Files\McAfee\Temp2714115429\logicscripts.cab | compressed | |
MD5:67F8FE1BAAD39510A168DC08EB6982F1 | SHA256:491A103DB92DD9CFDDF7A3356C0A8843EBD5CE840BB0F3E675217C778FF075FD | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
5496 | MoUsoCoreWorker.exe | GET | 200 | 23.48.23.143:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
6980 | cade-simu-4.0-installer_EY-UN51.exe | GET | 200 | 2.16.252.233:80 | http://x1.c.lencr.org/ | unknown | — | — | whitelisted |
5496 | MoUsoCoreWorker.exe | GET | 200 | 2.23.181.156:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
7304 | SIHClient.exe | GET | 200 | 2.23.246.101:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
7304 | SIHClient.exe | GET | 200 | 2.23.246.101:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 40.127.240.158:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
7804 | RUXIMICS.exe | 40.127.240.158:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
5496 | MoUsoCoreWorker.exe | 23.48.23.143:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
5496 | MoUsoCoreWorker.exe | 2.23.181.156:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
1276 | svchost.exe | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
6980 | cade-simu-4.0-installer_EY-UN51.exe | 18.245.78.145:443 | di7e1j5f1plfo.cloudfront.net | — | US | whitelisted |
6980 | cade-simu-4.0-installer_EY-UN51.exe | 151.101.65.91:443 | images.sftcdn.net | FASTLY | US | whitelisted |
3216 | svchost.exe | 172.211.123.250:443 | client.wns.windows.com | MICROSOFT-CORP-MSN-AS-BLOCK | FR | whitelisted |
6980 | cade-simu-4.0-installer_EY-UN51.exe | 2.16.252.233:80 | x1.c.lencr.org | Akamai International B.V. | NL | whitelisted |
Domain | IP | Reputation |
|---|---|---|
google.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
settings-win.data.microsoft.com |
| whitelisted |
di7e1j5f1plfo.cloudfront.net |
| whitelisted |
images.sftcdn.net |
| whitelisted |
client.wns.windows.com |
| whitelisted |
gsf-fl.softonic.com |
| whitelisted |
cade-simu.softonic.com |
| whitelisted |
x1.c.lencr.org |
| whitelisted |