File name:

SabyAdminInstaller_win32.exe

Full analysis: https://app.any.run/tasks/e38f0090-a43a-47cf-b693-ff136cb59725
Verdict: Malicious activity
Analysis date: June 26, 2024, 05:40:11
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
upx
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed
MD5:

762E5D223024C0075A8E750837DBE39E

SHA1:

54EB12C6A3EC3B3471D918762C2BF8F2DF0122F9

SHA256:

94285730E8B8A58DBE4F6E795CC66267EB27AE0F8B3DA2AF7659B7133C1ED509

SSDEEP:

98304:ovHY7NGO9bl3KYCd5OOAjSqsYtG13Uah0NYFpAbWFXgordY3iBv3OVAwf93Q65jS:ydDoNdZckyu7uZEeWSH

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • SabyAdminInstaller_win32.exe (PID: 3568)
  • SUSPICIOUS

    • Application launched itself

      • SabyAdminInstaller_win32.exe (PID: 3568)
      • SabyAdminInstaller_win32.exe (PID: 3192)
      • SabyAdminInstaller_win32.exe (PID: 2580)
      • SabyAdminInstaller_win32.exe (PID: 996)
    • Reads security settings of Internet Explorer

      • SabyAdminInstaller_win32.exe (PID: 3192)
    • Reads the Internet Settings

      • SabyAdminInstaller_win32.exe (PID: 3192)
    • Executes as Windows Service

      • SabyAdminInstaller_win32.exe (PID: 2580)
  • INFO

    • Checks supported languages

      • SabyAdminInstaller_win32.exe (PID: 3568)
      • SabyAdminInstaller_win32.exe (PID: 3192)
      • SabyAdminInstaller_win32.exe (PID: 980)
      • SabyAdminInstaller_win32.exe (PID: 2580)
      • SabyAdminInstaller_win32.exe (PID: 996)
      • SabyAdminInstaller_win32.exe (PID: 936)
    • Reads the computer name

      • SabyAdminInstaller_win32.exe (PID: 3568)
      • SabyAdminInstaller_win32.exe (PID: 3192)
      • SabyAdminInstaller_win32.exe (PID: 980)
      • SabyAdminInstaller_win32.exe (PID: 2580)
      • SabyAdminInstaller_win32.exe (PID: 936)
      • SabyAdminInstaller_win32.exe (PID: 996)
    • Reads the machine GUID from the registry

      • SabyAdminInstaller_win32.exe (PID: 3568)
      • SabyAdminInstaller_win32.exe (PID: 3192)
      • SabyAdminInstaller_win32.exe (PID: 980)
      • SabyAdminInstaller_win32.exe (PID: 2580)
      • SabyAdminInstaller_win32.exe (PID: 996)
      • SabyAdminInstaller_win32.exe (PID: 936)
    • Creates files in the program directory

      • SabyAdminInstaller_win32.exe (PID: 3568)
      • SabyAdminInstaller_win32.exe (PID: 996)
      • SabyAdminInstaller_win32.exe (PID: 936)
    • Reads CPU info

      • SabyAdminInstaller_win32.exe (PID: 3568)
      • SabyAdminInstaller_win32.exe (PID: 936)
      • SabyAdminInstaller_win32.exe (PID: 996)
    • UPX packer has been detected

      • SabyAdminInstaller_win32.exe (PID: 996)
      • SabyAdminInstaller_win32.exe (PID: 936)
    • Create files in a temporary directory

      • SabyAdminInstaller_win32.exe (PID: 936)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic Win/DOS Executable (50)
.exe | DOS Executable Generic (49.9)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2018:01:19 23:31:31+00:00
ImageFileCharacteristics: Executable, Large address aware, 32-bit
PEType: PE32
LinkerVersion: 14
CodeSize: 12062720
InitializedDataSize: 352256
UninitializedDataSize: 46710784
EntryPoint: 0x380cee0
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 24.2155.88.0
ProductVersionNumber: 24.2155.88.0
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Unknown (0)
ObjectFileType: Unknown
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Tensor
FileDescription: SabyAdminInstaller
FileVersion: 24.2155.88.0
InternalName: SabyAdminInstaller.exe
LegalCopyright: TENSOR (c). All rights reserved.
OriginalFileName: SabyAdminInstaller.exe
ProductName: SabyAdminInstaller
ProductVersion: 24.2155.88.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
46
Monitored processes
7
Malicious processes
0
Suspicious processes
3

Behavior graph

Click at the process to see the details
start sabyadmininstaller_win32.exe sabyadmininstaller_win32.exe no specs sabyadmininstaller_win32.exe sabyadmininstaller_win32.exe no specs THREAT sabyadmininstaller_win32.exe THREAT sabyadmininstaller_win32.exe wmpnscfg.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
936C:\Users\admin\AppData\Local\Temp\SabyAdminInstaller_win32.exe --mode 1 --installer_mode_version 3 --sess_id 1 --just_run --log_file_path C:\ProgramData\SabyAdmin --language ru --raw_arguments AQAAAD8AAABDOlxVc2Vyc1xhZG1pblxBcHBEYXRhXExvY2FsXFRlbXBcU2FieUFkbWluSW5zdGFsbGVyX3dpbjMyLmV4ZQA= --multi_start --force_set_double_start --privilege_elevation_state 3 --force_use_uac_privilegeC:\Users\admin\AppData\Local\Temp\SabyAdminInstaller_win32.exe
SabyAdminInstaller_win32.exe
User:
SYSTEM
Company:
Tensor
Integrity Level:
SYSTEM
Description:
SabyAdminInstaller
Version:
24.2155.88.0
Modules
Images
c:\users\admin\appdata\local\temp\sabyadmininstaller_win32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\activeds.dll
c:\windows\system32\adsldpc.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\atl.dll
c:\windows\system32\user32.dll
980"C:\Users\admin\AppData\Local\Temp\SabyAdminInstaller_win32.exe" --app_version "24.2155.88.0" --force_set_double_start --force_use_uac_privilege --installer_mode_version 3 --language "en" --log_file "06-40-20_SabyAdminInstaller" --log_file_path "C:\ProgramData\SabyAdmin" --mode 10 --multi_start --privilege_elevation_state 1 --raw_arguments "AQAAAD8AAABDOlxVc2Vyc1xhZG1pblxBcHBEYXRhXExvY2FsXFRlbXBcU2FieUFkbWluSW5zdGFsbGVyX3dpbjMyLmV4ZQA=" --no-silentC:\Users\admin\AppData\Local\Temp\SabyAdminInstaller_win32.exe
SabyAdminInstaller_win32.exe
User:
admin
Company:
Tensor
Integrity Level:
HIGH
Description:
SabyAdminInstaller
Exit code:
0
Version:
24.2155.88.0
Modules
Images
c:\users\admin\appdata\local\temp\sabyadmininstaller_win32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\activeds.dll
c:\windows\system32\adsldpc.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\atl.dll
c:\windows\system32\user32.dll
996"C:\Users\admin\AppData\Local\Temp\SabyAdminInstaller_win32.exe" --app_version "24.2155.88.0" --force_set_double_start --force_use_uac_privilege --installer_mode_version 3 --language "en" --log_file "06-40-20_SabyAdminInstaller" --log_file_path "C:\ProgramData\SabyAdmin" --mode 10 --multi_start --privilege_elevation_state 3 --raw_arguments "AQAAAD8AAABDOlxVc2Vyc1xhZG1pblxBcHBEYXRhXExvY2FsXFRlbXBcU2FieUFkbWluSW5zdGFsbGVyX3dpbjMyLmV4ZQA=" --sess_id 1 --no-silent --just_runC:\Users\admin\AppData\Local\Temp\SabyAdminInstaller_win32.exe
SabyAdminInstaller_win32.exe
User:
SYSTEM
Company:
Tensor
Integrity Level:
SYSTEM
Description:
SabyAdminInstaller
Exit code:
0
Version:
24.2155.88.0
Modules
Images
c:\users\admin\appdata\local\temp\sabyadmininstaller_win32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\activeds.dll
c:\windows\system32\adsldpc.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\atl.dll
c:\windows\system32\user32.dll
2580"C:\Users\admin\AppData\Local\Temp\SabyAdminInstaller_win32.exe" --sess_id 1 --app_version "24.2155.88.0" --force_set_double_start --force_use_uac_privilege --installer_mode_version 3 --language "en" --log_file "06-40-20_SabyAdminInstaller" --log_file_path "C:\ProgramData\SabyAdmin" --mode 10 --multi_start --privilege_elevation_state 2 --raw_arguments "AQAAAD8AAABDOlxVc2Vyc1xhZG1pblxBcHBEYXRhXExvY2FsXFRlbXBcU2FieUFkbWluSW5zdGFsbGVyX3dpbjMyLmV4ZQA=" --no-silentC:\Users\admin\AppData\Local\Temp\SabyAdminInstaller_win32.exeservices.exe
User:
SYSTEM
Company:
Tensor
Integrity Level:
SYSTEM
Description:
SabyAdminInstaller
Exit code:
0
Version:
24.2155.88.0
Modules
Images
c:\users\admin\appdata\local\temp\sabyadmininstaller_win32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\activeds.dll
c:\windows\system32\adsldpc.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\atl.dll
c:\windows\system32\user32.dll
3192C:\Users\admin\AppData\Local\Temp\SabyAdminInstaller_win32.exe --log_file 06-40-20_SabyAdminInstaller --mode 10 --app_version 24.2155.88.0 --installer_mode_version 3 --no-silent --log_file_path C:\ProgramData\SabyAdmin --language en --raw_arguments AQAAAD8AAABDOlxVc2Vyc1xhZG1pblxBcHBEYXRhXExvY2FsXFRlbXBcU2FieUFkbWluSW5zdGFsbGVyX3dpbjMyLmV4ZQA=C:\Users\admin\AppData\Local\Temp\SabyAdminInstaller_win32.exeSabyAdminInstaller_win32.exe
User:
admin
Company:
Tensor
Integrity Level:
MEDIUM
Description:
SabyAdminInstaller
Exit code:
0
Version:
24.2155.88.0
Modules
Images
c:\users\admin\appdata\local\temp\sabyadmininstaller_win32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\activeds.dll
c:\windows\system32\adsldpc.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\atl.dll
c:\windows\system32\user32.dll
3392"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
3568"C:\Users\admin\AppData\Local\Temp\SabyAdminInstaller_win32.exe" C:\Users\admin\AppData\Local\Temp\SabyAdminInstaller_win32.exe
explorer.exe
User:
admin
Company:
Tensor
Integrity Level:
MEDIUM
Description:
SabyAdminInstaller
Exit code:
0
Version:
24.2155.88.0
Modules
Images
c:\users\admin\appdata\local\temp\sabyadmininstaller_win32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\activeds.dll
c:\windows\system32\adsldpc.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\atl.dll
c:\windows\system32\user32.dll
Total events
8 569
Read events
8 546
Write events
23
Delete events
0

Modification events

(PID) Process:(3192) SabyAdminInstaller_win32.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3192) SabyAdminInstaller_win32.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(3192) SabyAdminInstaller_win32.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(3192) SabyAdminInstaller_win32.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(980) SabyAdminInstaller_win32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\LocalDumps\SabyAdminInstaller_win32.exe
Operation:writeName:DumpFolder
Value:
C:\ProgramData\SabyAdmin\dumps
(PID) Process:(980) SabyAdminInstaller_win32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\LocalDumps\SabyAdminInstaller_win32.exe
Operation:writeName:DumpCount
Value:
10
(PID) Process:(980) SabyAdminInstaller_win32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\LocalDumps\SabyAdminInstaller_win32.exe
Operation:writeName:DumpType
Value:
2
(PID) Process:(980) SabyAdminInstaller_win32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System
Operation:writeName:SoftwareSASGeneration
Value:
3
(PID) Process:(980) SabyAdminInstaller_win32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\UIPI\Clipboard\ExceptionFormats
Operation:writeName:CF_HDROP
Value:
15
(PID) Process:(980) SabyAdminInstaller_win32.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\LanmanServer\Parameters
Operation:writeName:DisableStrictNameChecking
Value:
1
Executable files
0
Suspicious files
1
Text files
5
Unknown types
0

Dropped files

PID
Process
Filename
Type
996SabyAdminInstaller_win32.exeC:\ProgramData\Tensor\device.idtext
MD5:5C4964E8403AB256F006557B47243808
SHA256:072FC2B12F00956381B6432F620D194A53A36674A57AC6A3CA0A81C90C6BD5FD
3568SabyAdminInstaller_win32.exeC:\ProgramData\SabyAdmin\logs\20240626\2024-06-26_06-40-20_SabyAdminInstaller-events.logtext
MD5:38AAD733D467E8A90848D56F1CAA5B88
SHA256:C52164BCE500B3445103238ACB3BB7EB9FB1F541922DCDD0D216FC602EB95599
3568SabyAdminInstaller_win32.exeC:\ProgramData\SabyAdmin\logs\20240626\2024-06-26_06-40-20_SabyAdminInstaller-errors.logtext
MD5:10CE3162D447639F484FC585EC7A9570
SHA256:B29D6A91E56137141FDE32529845A6A3F4F9375EFACB917E3F42BEEFDF9E58F9
936SabyAdminInstaller_win32.exeC:\ProgramData\SabyAdmin\logs\20240626\2024-06-26_06-40-44_SabyAdminInstaller-errors.logtext
MD5:61E3683D4E45B6CDDCE46EDF65698945
SHA256:BD790A372117DA72767227203712E660A0BD4B531BE43F2FC364BEFB9C8D7D1A
996SabyAdminInstaller_win32.exeC:\ProgramData\SabyAdmin\_settingscompressed
MD5:7CF4328E1BAF021CA4CD54C736EA6944
SHA256:D34AE7293E1D942D8830A1BE7C6D4253D42E19557B4FC61CF165EE6A5398AC69
936SabyAdminInstaller_win32.exeC:\ProgramData\SabyAdmin\logs\20240626\2024-06-26_06-40-44_SabyAdminInstaller-events.logtext
MD5:3511ABCF89411DD76C68BACC750509B7
SHA256:EBE4683648DF3F217D789AD9EA02D4F3092DB0F91BA7477ADFEDB0ADB3ED70C6
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
15
DNS requests
7
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1372
svchost.exe
GET
304
23.32.238.169:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?33775f6043c93e33
unknown
unknown
1372
svchost.exe
GET
200
23.216.77.6:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
unknown
1372
svchost.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
unknown
1060
svchost.exe
GET
304
23.32.238.219:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?11acddbe1ebd82b3
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1372
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
3568
SabyAdminInstaller_win32.exe
91.232.93.69:443
rhm.sbis.ru
Company Tensor LLC
RU
unknown
1060
svchost.exe
224.0.0.252:5355
unknown
2564
svchost.exe
239.255.255.250:3702
whitelisted
996
SabyAdminInstaller_win32.exe
91.232.93.69:443
rhm.sbis.ru
Company Tensor LLC
RU
unknown
1372
svchost.exe
23.32.238.169:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown
1372
svchost.exe
23.216.77.6:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
1372
svchost.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
unknown

DNS requests

Domain
IP
Reputation
rhm.sbis.ru
  • 91.232.93.69
unknown
settings-win.data.microsoft.com
  • 51.124.78.146
whitelisted
ctldl.windowsupdate.com
  • 23.32.238.169
  • 23.32.238.201
  • 23.32.238.211
  • 23.32.238.232
  • 23.32.238.178
  • 23.32.238.219
whitelisted
crl.microsoft.com
  • 23.216.77.6
  • 23.216.77.28
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
update.sbis.ru
  • 91.232.93.95
unknown

Threats

No threats detected
No debug info