File name:

SQL2022-SSEI-Dev.exe

Full analysis: https://app.any.run/tasks/11461e66-f33f-4fe7-b796-da7203bb60a2
Verdict: Malicious activity
Analysis date: March 25, 2024, 20:00:08
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
MD5:

9CF37E0194C8A1211B3581A4D553C52E

SHA1:

E3D3B5EE51C15FEAEC2AB3144C2D3085604D57AC

SHA256:

5D9D277DCCEF80F2395F915664BD8E63FE7496B7B9C005C2F0C78A3C70D03813

SSDEEP:

49152:oYliwMwWVdDjoxzCm5BOjP7EGyZbY4qtOtdGAhTuD2/Y+gXO:IoQX0

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • SQL2022-SSEI-Dev.exe (PID: 2756)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • SQL2022-SSEI-Dev.exe (PID: 2756)
    • Starts a Microsoft application from unusual location

      • SQL2022-SSEI-Dev.exe (PID: 1696)
      • SQL2022-SSEI-Dev.exe (PID: 2756)
    • Reads settings of System Certificates

      • SQL2022-SSEI-Dev.exe (PID: 2756)
    • Reads the Internet Settings

      • SQL2022-SSEI-Dev.exe (PID: 2756)
  • INFO

    • Checks supported languages

      • SQL2022-SSEI-Dev.exe (PID: 2756)
      • wmpnscfg.exe (PID: 2904)
    • Reads the computer name

      • SQL2022-SSEI-Dev.exe (PID: 2756)
      • wmpnscfg.exe (PID: 2904)
    • Reads the software policy settings

      • SQL2022-SSEI-Dev.exe (PID: 2756)
    • Reads Environment values

      • SQL2022-SSEI-Dev.exe (PID: 2756)
    • Reads the machine GUID from the registry

      • SQL2022-SSEI-Dev.exe (PID: 2756)
    • Creates files in the program directory

      • SQL2022-SSEI-Dev.exe (PID: 2756)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 2904)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (49.4)
.scr | Windows screen saver (23.4)
.dll | Win32 Dynamic Link Library (generic) (11.7)
.exe | Win32 Executable (generic) (8)
.exe | Generic Win/DOS Executable (3.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2086:03:07 01:36:02+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32
LinkerVersion: 48
CodeSize: 4265984
InitializedDataSize: 14336
UninitializedDataSize: -
EntryPoint: 0x41373e
OSVersion: 4
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 16.2211.5693.3
ProductVersionNumber: 16.2211.5693.3
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
CompanyName: Microsoft Corporation
FileDescription: SQL Server Installer for Developer Edition
FileVersion: 16.2211.5693.3
InternalName: SQL2022-SSEI-Dev.exe
LegalCopyright: Copyright (c) Microsoft Corporation. All rights reserved.
LegalTrademarks: Microsoft and Windows are either registered trademarks or trademarks of Microsoft Corporation in the U.S. and/or other countries.
OriginalFileName: SQL2022-SSEI-Dev.exe
ProductName: Microsoft Sql Server Installer
ProductVersion: 16.2211.5693.3
AssemblyVersion: 16.2211.0.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
42
Monitored processes
3
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start sql2022-ssei-dev.exe wmpnscfg.exe no specs sql2022-ssei-dev.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1696"C:\Users\admin\AppData\Local\Temp\SQL2022-SSEI-Dev.exe" C:\Users\admin\AppData\Local\Temp\SQL2022-SSEI-Dev.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
SQL Server Installer for Developer Edition
Exit code:
3221226540
Version:
16.2211.5693.3
Modules
Images
c:\users\admin\appdata\local\temp\sql2022-ssei-dev.exe
c:\windows\system32\ntdll.dll
2756"C:\Users\admin\AppData\Local\Temp\SQL2022-SSEI-Dev.exe" C:\Users\admin\AppData\Local\Temp\SQL2022-SSEI-Dev.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
SQL Server Installer for Developer Edition
Version:
16.2211.5693.3
Modules
Images
c:\users\admin\appdata\local\temp\sql2022-ssei-dev.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2904"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
Total events
5 410
Read events
5 376
Write events
31
Delete events
3

Modification events

(PID) Process:(2756) SQL2022-SSEI-Dev.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Direct3D\MostRecentApplication
Operation:writeName:Name
Value:
SQL2022-SSEI-Dev.exe
(PID) Process:(2756) SQL2022-SSEI-Dev.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\SQL2022-SSEI-Dev_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(2756) SQL2022-SSEI-Dev.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\SQL2022-SSEI-Dev_RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(2756) SQL2022-SSEI-Dev.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\SQL2022-SSEI-Dev_RASAPI32
Operation:writeName:FileTracingMask
Value:
(PID) Process:(2756) SQL2022-SSEI-Dev.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\SQL2022-SSEI-Dev_RASAPI32
Operation:writeName:ConsoleTracingMask
Value:
(PID) Process:(2756) SQL2022-SSEI-Dev.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\SQL2022-SSEI-Dev_RASAPI32
Operation:writeName:MaxFileSize
Value:
1048576
(PID) Process:(2756) SQL2022-SSEI-Dev.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\SQL2022-SSEI-Dev_RASAPI32
Operation:writeName:FileDirectory
Value:
%windir%\tracing
(PID) Process:(2756) SQL2022-SSEI-Dev.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\SQL2022-SSEI-Dev_RASMANCS
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(2756) SQL2022-SSEI-Dev.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\SQL2022-SSEI-Dev_RASMANCS
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(2756) SQL2022-SSEI-Dev.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\SQL2022-SSEI-Dev_RASMANCS
Operation:writeName:FileTracingMask
Value:
Executable files
0
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

No data
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
8
DNS requests
4
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
2756
SQL2022-SSEI-Dev.exe
23.218.210.69:443
go.microsoft.com
AKAMAI-AS
DE
unknown
2756
SQL2022-SSEI-Dev.exe
23.32.101.194:443
download.microsoft.com
AKAMAI-AS
SE
unknown
2756
SQL2022-SSEI-Dev.exe
104.208.16.90:443
vortex.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown

DNS requests

Domain
IP
Reputation
go.microsoft.com
  • 23.218.210.69
whitelisted
download.microsoft.com
  • 23.32.101.194
whitelisted
vortex.data.microsoft.com
  • 104.208.16.90
whitelisted

Threats

No threats detected
Process
Message
SQL2022-SSEI-Dev.exe
(01) 2024-03-25 20:00:17 CorrelationId: d0353b7c-bd53-449f-9f06-0caba92901bc
SQL2022-SSEI-Dev.exe
(01) 2024-03-25 20:00:17 SSEI v16.2211.5693.3
SQL2022-SSEI-Dev.exe
(01) 2024-03-25 20:00:17 CurrentUICulture.Name='en-US'.LCID='1033'.Parent.Name='en'
SQL2022-SSEI-Dev.exe
(01) 2024-03-25 20:00:17 supported culture detected ='en-US'.
SQL2022-SSEI-Dev.exe
(01) 2024-03-25 20:00:17 CurrentCulture.Name='en-US'.LCID='1033'.Parent.Name='en'
SQL2022-SSEI-Dev.exe
(01) 2024-03-25 20:00:17 resolvedCulture: en-US
SQL2022-SSEI-Dev.exe
(01) 2024-03-25 20:00:17 osSupported: False, osVersion: 6.1.7601.65536, osPlatform: x86
SQL2022-SSEI-Dev.exe
(10) 2024-03-25 20:00:17 .NET Framework Version: 4.5
SQL2022-SSEI-Dev.exe
(10) 2024-03-25 20:00:17 StartupBootstrapActivity:SSEIActivityStart:Message: Starting Activity StartupBootstrapActivity
SQL2022-SSEI-Dev.exe
(10) 2024-03-25 20:00:17 StartupBootstrapActivity:SSEIProgressReport:ProgressPercent: 1