File name:

sagethumbs_2.0.0.23_setup.exe

Full analysis: https://app.any.run/tasks/2d6f419b-3506-436d-aacd-52857fa576ce
Verdict: Malicious activity
Analysis date: November 05, 2024, 10:10:36
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive, 5 sections
MD5:

2AF65ABF462C9B3170C6E80428F90888

SHA1:

DD798C6DDC1FE523B0919C0D70C36B7932A67BE5

SHA256:

705D743E28B487E34A4A7245A0DBC303A10E45BA0FD9E4DA4101C8CDF506839A

SSDEEP:

98304:bhMGV3jIjAXbgsgxZHBcsp/X1mIBFagQM1UYKzlke2vPxA/9A3Kjnry2OKH+pPth:lZM1Uw

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Registers / Runs the DLL via REGSVR32.EXE

      • sagethumbs_2.0.0.23_setup.exe (PID: 6440)
  • SUSPICIOUS

    • Malware-specific behavior (creating "System.dll" in Temp)

      • sagethumbs_2.0.0.23_setup.exe (PID: 6440)
    • The process creates files with name similar to system file names

      • sagethumbs_2.0.0.23_setup.exe (PID: 6440)
    • Executable content was dropped or overwritten

      • sagethumbs_2.0.0.23_setup.exe (PID: 6440)
  • INFO

    • Checks supported languages

      • sagethumbs_2.0.0.23_setup.exe (PID: 6440)
    • Reads the computer name

      • sagethumbs_2.0.0.23_setup.exe (PID: 6440)
    • Create files in a temporary directory

      • sagethumbs_2.0.0.23_setup.exe (PID: 6440)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | NSIS - Nullsoft Scriptable Install System (91.9)
.exe | Win32 Executable MS Visual C++ (generic) (3.3)
.exe | Win64 Executable (generic) (3)
.dll | Win32 Dynamic Link Library (generic) (0.7)
.exe | Win32 Executable (generic) (0.4)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2014:10:07 04:40:17+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 23552
InitializedDataSize: 117760
UninitializedDataSize: 1024
EntryPoint: 0x3217
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 2.0.0.23
ProductVersionNumber: 2.0.0.23
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Turkish
CharacterSet: Windows, Turkish
Comments: http://sagethumbs.sourceforge.net/
CompanyName: Cherubic Software
FileDescription: SageThumbs
FileVersion: 2.0.0.23
LegalCopyright: Copyright © 2004-2017 Nikolay Raspopov
OriginalFileName: ..\..\redist\sagethumbs_2.0.0.23_setup.exe
ProductName: SageThumbs
ProductVersion: 2.0.0.23
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
144
Monitored processes
8
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start sagethumbs_2.0.0.23_setup.exe sppextcomobj.exe no specs slui.exe regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs slui.exe sagethumbs_2.0.0.23_setup.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1452"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exe
SppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
4556C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
5892"C:\Users\admin\AppData\Local\Temp\sagethumbs_2.0.0.23_setup.exe" C:\Users\admin\AppData\Local\Temp\sagethumbs_2.0.0.23_setup.exeexplorer.exe
User:
admin
Company:
Cherubic Software
Integrity Level:
MEDIUM
Description:
SageThumbs
Exit code:
3221226540
Version:
2.0.0.23
Modules
Images
c:\users\admin\appdata\local\temp\sagethumbs_2.0.0.23_setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
6132 /s "C:\Program Files (x86)\SageThumbs\64\SageThumbs.dll"C:\Windows\System32\regsvr32.exeregsvr32.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
6180C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
6256"C:\WINDOWS\system32\regsvr32.exe" /s "C:\Program Files (x86)\SageThumbs\32\SageThumbs.dll"C:\Windows\SysWOW64\regsvr32.exesagethumbs_2.0.0.23_setup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
6440"C:\Users\admin\AppData\Local\Temp\sagethumbs_2.0.0.23_setup.exe" C:\Users\admin\AppData\Local\Temp\sagethumbs_2.0.0.23_setup.exe
explorer.exe
User:
admin
Company:
Cherubic Software
Integrity Level:
HIGH
Description:
SageThumbs
Exit code:
0
Version:
2.0.0.23
Modules
Images
c:\users\admin\appdata\local\temp\sagethumbs_2.0.0.23_setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
6956"C:\WINDOWS\system32\regsvr32.exe" /s "C:\Program Files (x86)\SageThumbs\64\SageThumbs.dll"C:\Windows\SysWOW64\regsvr32.exesagethumbs_2.0.0.23_setup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
Total events
21 171
Read events
17 439
Write events
3 595
Delete events
137

Modification events

(PID) Process:(6440) sagethumbs_2.0.0.23_setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\SageThumbs
Operation:writeName:Install
Value:
C:\Program Files (x86)\SageThumbs
(PID) Process:(6440) sagethumbs_2.0.0.23_setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SageThumbs
Operation:writeName:DisplayName
Value:
SageThumbs 2.0.0.23
(PID) Process:(6440) sagethumbs_2.0.0.23_setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SageThumbs
Operation:writeName:ModifyPath
Value:
C:\Program Files (x86)\SageThumbs\Repair.exe
(PID) Process:(6440) sagethumbs_2.0.0.23_setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SageThumbs
Operation:writeName:UninstallString
Value:
C:\Program Files (x86)\SageThumbs\Uninst.exe
(PID) Process:(6440) sagethumbs_2.0.0.23_setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SageThumbs
Operation:writeName:InstallLocation
Value:
C:\Program Files (x86)\SageThumbs
(PID) Process:(6440) sagethumbs_2.0.0.23_setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SageThumbs
Operation:writeName:DisplayIcon
Value:
C:\Program Files (x86)\SageThumbs\32\SageThumbs.dll
(PID) Process:(6440) sagethumbs_2.0.0.23_setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SageThumbs
Operation:writeName:DisplayVersion
Value:
2.0.0.23
(PID) Process:(6440) sagethumbs_2.0.0.23_setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SageThumbs
Operation:writeName:Publisher
Value:
Cherubic Software
(PID) Process:(6440) sagethumbs_2.0.0.23_setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SageThumbs
Operation:writeName:URLInfoAbout
Value:
http://sagethumbs.sourceforge.net/
(PID) Process:(6440) sagethumbs_2.0.0.23_setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SageThumbs
Operation:writeName:NoModify
Value:
0
Executable files
22
Suspicious files
6
Text files
5
Unknown types
1

Dropped files

PID
Process
Filename
Type
6440sagethumbs_2.0.0.23_setup.exeC:\Users\admin\AppData\Local\Temp\nszB8DB.tmp\nsDialogs.dllexecutable
MD5:36BDF3E282EE81EA2F9A400604A55FF6
SHA256:C5BF321A3A2AACE7B42014CF78A3D0FB3EEC03B2C8FF00AD72445F56657377AF
6440sagethumbs_2.0.0.23_setup.exeC:\Users\admin\AppData\Local\Temp\nszB8DB.tmp\System.dllexecutable
MD5:883EFF06AC96966270731E4E22817E11
SHA256:44E5DFD551B38E886214BD6B9C8EE913C4C4D1F085A6575D97C3E892B925DA82
6440sagethumbs_2.0.0.23_setup.exeC:\Users\admin\AppData\Local\Temp\nszB8DB.tmp\modern-wizard.bmpimage
MD5:CBE40FD2B1EC96DAEDC65DA172D90022
SHA256:3AD2DC318056D0A2024AF1804EA741146CFC18CC404649A44610CBF8B2056CF2
6440sagethumbs_2.0.0.23_setup.exeC:\Program Files (x86)\SageThumbs\32\SageThumbs.dll.tmpexecutable
MD5:B3A7DE1EE3B0EE68989BD68D8A2ECCC4
SHA256:366D169DDB3897C77D632466CE969BEBD8DEF4E8F111AE21598CB5BE5FC71DB4
6440sagethumbs_2.0.0.23_setup.exeC:\Users\admin\AppData\Local\Temp\nszB8DB.tmp\modern-header.bmpimage
MD5:EADF80C79F88337C58CA0FB5032CB579
SHA256:8E58B3E6E3896A4BAE05FA2F6ADC238D391AA80BC51C138F851F373C6C23E518
6440sagethumbs_2.0.0.23_setup.exeC:\Program Files (x86)\SageThumbs\32\libgfle340.dll.tmpexecutable
MD5:1D3C7D9388FA818FFC7F5BDF0479C05D
SHA256:58F19E055060193ED63A4D33F5ED334217D61EA4ECAE6BFA25E02EAB9696C504
6440sagethumbs_2.0.0.23_setup.exeC:\Program Files (x86)\SageThumbs\32\SageThumbs.dllexecutable
MD5:B3A7DE1EE3B0EE68989BD68D8A2ECCC4
SHA256:366D169DDB3897C77D632466CE969BEBD8DEF4E8F111AE21598CB5BE5FC71DB4
6440sagethumbs_2.0.0.23_setup.exeC:\Users\admin\AppData\Local\Temp\nszB8DB.tmp\LangDLL.dllexecutable
MD5:FEEDCA220D8A53786FA10DACADB75619
SHA256:5795C00A067C4D3A9F04BD34108C5541189C3F8D8D8EE75A3FAEF337F27CF909
6440sagethumbs_2.0.0.23_setup.exeC:\Program Files (x86)\SageThumbs\64\sqlite3.dll.tmpexecutable
MD5:5951B2BF50C903730FAFDEA5D267FE09
SHA256:A1751B4A4A40F82EECEE217B22048D04248AEADE9CE946B240E439CBD2BD79D4
6440sagethumbs_2.0.0.23_setup.exeC:\Program Files (x86)\SageThumbs\32\sqlite3.dll.tmpexecutable
MD5:654888380D8EB02CB752E18918CA8283
SHA256:0EEEF7A93F51584EE88420A2F12BC8073697C68443226411803611530D00B0F6
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
43
DNS requests
22
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
23.216.77.18:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
7028
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
4360
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
6824
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
4232
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
4232
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
6944
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
5488
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
23.216.77.18:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
4360
SearchApp.exe
104.126.37.168:443
www.bing.com
Akamai International B.V.
DE
whitelisted
4360
SearchApp.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
7028
svchost.exe
40.126.32.136:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 51.104.136.2
  • 51.124.78.146
whitelisted
crl.microsoft.com
  • 23.216.77.18
  • 23.216.77.23
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
google.com
  • 142.250.185.78
whitelisted
www.bing.com
  • 104.126.37.168
  • 104.126.37.155
  • 104.126.37.169
  • 104.126.37.163
  • 104.126.37.170
  • 104.126.37.160
  • 104.126.37.152
  • 104.126.37.161
  • 104.126.37.153
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
login.live.com
  • 40.126.32.136
  • 40.126.32.134
  • 20.190.160.20
  • 40.126.32.76
  • 40.126.32.68
  • 40.126.32.138
  • 20.190.160.14
  • 40.126.32.74
whitelisted
th.bing.com
  • 104.126.37.169
  • 104.126.37.155
  • 104.126.37.178
  • 104.126.37.171
  • 104.126.37.161
  • 104.126.37.163
  • 104.126.37.168
  • 104.126.37.160
  • 104.126.37.170
whitelisted
go.microsoft.com
  • 23.35.238.131
whitelisted
client.wns.windows.com
  • 40.113.110.67
whitelisted

Threats

No threats detected
No debug info