| File name: | sublime_text_build_4180_x64_setup.exe |
| Full analysis: | https://app.any.run/tasks/260eeaaf-0a3b-4283-b277-8117285e6732 |
| Verdict: | Malicious activity |
| Analysis date: | November 21, 2024, 08:40:39 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, 8 sections |
| MD5: | AAF9512B5751E651B6A5888196CDC1C8 |
| SHA1: | 39C1A9790110E4DBCF17954C01E82E413C388AAB |
| SHA256: | 99650270AA32E8997AEC2BDE30EBE0F2D79A6A83E629293CE4537C74975DD924 |
| SSDEEP: | 98304:pgkz9zTGvY7lIQQ9hbZwvu33GmHSIaYRqwSrhS2IMC0p8L0w5FN8BysIaCx5gbuj:JQ1ka0sjpREnmHS3l81fvkVndUzt |
| .exe | | | InstallShield setup (57.8) |
|---|---|---|
| .exe | | | Win32 Executable Delphi generic (19) |
| .dll | | | Win32 Dynamic Link Library (generic) (8.8) |
| .exe | | | Win32 Executable (generic) (6) |
| .exe | | | Win16/32 Executable Delphi generic (2.7) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2016:04:06 14:39:04+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi |
| PEType: | PE32 |
| LinkerVersion: | 2.25 |
| CodeSize: | 66560 |
| InitializedDataSize: | 53760 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x117dc |
| OSVersion: | 5 |
| ImageVersion: | 6 |
| SubsystemVersion: | 5 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 0.0.0.0 |
| ProductVersionNumber: | 0.0.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| Comments: | This installation was built with Inno Setup. |
| CompanyName: | Sublime HQ Pty Ltd |
| FileDescription: | Sublime Text Setup |
| FileVersion: | |
| LegalCopyright: | |
| ProductName: | Sublime Text |
| ProductVersion: |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 3620 | "C:\Users\admin\AppData\Local\Temp\sublime_text_build_4180_x64_setup.exe" /SPAWNWND=$501DE /NOTIFYWND=$501F8 | C:\Users\admin\AppData\Local\Temp\sublime_text_build_4180_x64_setup.exe | sublime_text_build_4180_x64_setup.tmp | ||||||||||||
User: admin Company: Sublime HQ Pty Ltd Integrity Level: HIGH Description: Sublime Text Setup Exit code: 0 Version: Modules
| |||||||||||||||
| 3812 | "C:\Users\admin\AppData\Local\Temp\is-1Q440.tmp\sublime_text_build_4180_x64_setup.tmp" /SL5="$190022,15643013,121344,C:\Users\admin\AppData\Local\Temp\sublime_text_build_4180_x64_setup.exe" /SPAWNWND=$501DE /NOTIFYWND=$501F8 | C:\Users\admin\AppData\Local\Temp\is-1Q440.tmp\sublime_text_build_4180_x64_setup.tmp | sublime_text_build_4180_x64_setup.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 Modules
| |||||||||||||||
| 5880 | "C:\Users\admin\AppData\Local\Temp\is-1UPSJ.tmp\sublime_text_build_4180_x64_setup.tmp" /SL5="$501F8,15643013,121344,C:\Users\admin\AppData\Local\Temp\sublime_text_build_4180_x64_setup.exe" | C:\Users\admin\AppData\Local\Temp\is-1UPSJ.tmp\sublime_text_build_4180_x64_setup.tmp | — | sublime_text_build_4180_x64_setup.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 Modules
| |||||||||||||||
| 6060 | "C:\Users\admin\AppData\Local\Temp\sublime_text_build_4180_x64_setup.exe" | C:\Users\admin\AppData\Local\Temp\sublime_text_build_4180_x64_setup.exe | explorer.exe | ||||||||||||
User: admin Company: Sublime HQ Pty Ltd Integrity Level: MEDIUM Description: Sublime Text Setup Exit code: 0 Version: Modules
| |||||||||||||||
| 6216 | "C:\WINDOWS\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\TextInputHost.exe" -ServerName:InputApp.AppXjd5de1g66v206tj52m9d0dtpppx4cgpn.mca | C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\TextInputHost.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Version: 123.26505.0.0 Modules
| |||||||||||||||
| 6820 | "C:\WINDOWS\system32\mspaint.exe" "C:\Users\admin\Desktop\systemplease.png" | C:\Windows\System32\mspaint.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Paint Exit code: 0 Version: 10.0.19041.3758 (WinBuild.160101.0800) Modules
| |||||||||||||||
| (PID) Process: | (3812) sublime_text_build_4180_x64_setup.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.sublime-build\OpenWithProgids |
| Operation: | write | Name: | com.sublimehq.sublimetext.build-system |
Value: | |||
| (PID) Process: | (3812) sublime_text_build_4180_x64_setup.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Applications\sublime_text.exe\SupportedTypes |
| Operation: | write | Name: | .sublime-build |
Value: | |||
| (PID) Process: | (3812) sublime_text_build_4180_x64_setup.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.sublime-color-scheme\OpenWithProgids |
| Operation: | write | Name: | com.sublimehq.sublimetext.color-scheme |
Value: | |||
| (PID) Process: | (3812) sublime_text_build_4180_x64_setup.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Applications\sublime_text.exe\SupportedTypes |
| Operation: | write | Name: | .sublime-color-scheme |
Value: | |||
| (PID) Process: | (3812) sublime_text_build_4180_x64_setup.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.sublime-commands\OpenWithProgids |
| Operation: | write | Name: | com.sublimehq.sublimetext.commands |
Value: | |||
| (PID) Process: | (3812) sublime_text_build_4180_x64_setup.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Applications\sublime_text.exe\SupportedTypes |
| Operation: | write | Name: | .sublime-commands |
Value: | |||
| (PID) Process: | (3812) sublime_text_build_4180_x64_setup.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.sublime-completions\OpenWithProgids |
| Operation: | write | Name: | com.sublimehq.sublimetext.completions |
Value: | |||
| (PID) Process: | (3812) sublime_text_build_4180_x64_setup.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Applications\sublime_text.exe\SupportedTypes |
| Operation: | write | Name: | .sublime-completions |
Value: | |||
| (PID) Process: | (3812) sublime_text_build_4180_x64_setup.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.sublime-keymap\OpenWithProgids |
| Operation: | write | Name: | com.sublimehq.sublimetext.keymap |
Value: | |||
| (PID) Process: | (3812) sublime_text_build_4180_x64_setup.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Applications\sublime_text.exe\SupportedTypes |
| Operation: | write | Name: | .sublime-keymap |
Value: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3812 | sublime_text_build_4180_x64_setup.tmp | C:\Users\admin\AppData\Local\Temp\is-85NBI.tmp\_isetup\_setup64.tmp | executable | |
MD5:E4211D6D009757C078A9FAC7FF4F03D4 | SHA256:388A796580234EFC95F3B1C70AD4CB44BFDDC7BA0F9203BF4902B9929B136F95 | |||
| 6060 | sublime_text_build_4180_x64_setup.exe | C:\Users\admin\AppData\Local\Temp\is-1UPSJ.tmp\sublime_text_build_4180_x64_setup.tmp | executable | |
MD5:6E3790D6371E3B91685CF12150698545 | SHA256:A5AC7EE2ADD434AF74FB3E1AB6CE51B54859E34BBF169826B05813F1E96AB0C6 | |||
| 3812 | sublime_text_build_4180_x64_setup.tmp | C:\Program Files\Sublime Text\sublime_text.exe | executable | |
MD5:ED18178DC554270EA339606FBBC703ED | SHA256:559ABBCE0D9083D2A19EE98CA7AA1E4A1CA04715B6E30A8C0D34A7DC4B8C0BA0 | |||
| 3812 | sublime_text_build_4180_x64_setup.tmp | C:\Program Files\Sublime Text\subl.exe | executable | |
MD5:078CD87747852248523C88A427456355 | SHA256:ABD2F1ED5F5E283641F0472C0217F12267CED3264B69478AE15E861DA737BA2F | |||
| 3812 | sublime_text_build_4180_x64_setup.tmp | C:\Program Files\Sublime Text\update_installer.exe | executable | |
MD5:9155C9ED10429307CB87EC505CD37ADE | SHA256:3DF7C995328BA1C1B47AD25F22EC22245105BEFF850B8E9AE97D70AF8D7B1CEE | |||
| 3812 | sublime_text_build_4180_x64_setup.tmp | C:\Program Files\Sublime Text\unins000.exe | executable | |
MD5:6E3790D6371E3B91685CF12150698545 | SHA256:A5AC7EE2ADD434AF74FB3E1AB6CE51B54859E34BBF169826B05813F1E96AB0C6 | |||
| 3812 | sublime_text_build_4180_x64_setup.tmp | C:\Program Files\Sublime Text\plugin_host-3.8.exe | executable | |
MD5:427A998C61DE637690A2E925119A841C | SHA256:F22CB4C40C1F92760A1C1436BD80A760F5C939C65A497D60618FBB76967FCC66 | |||
| 3812 | sublime_text_build_4180_x64_setup.tmp | C:\Program Files\Sublime Text\is-131DI.tmp | executable | |
MD5:ED18178DC554270EA339606FBBC703ED | SHA256:559ABBCE0D9083D2A19EE98CA7AA1E4A1CA04715B6E30A8C0D34A7DC4B8C0BA0 | |||
| 3812 | sublime_text_build_4180_x64_setup.tmp | C:\Program Files\Sublime Text\crash_handler.exe | executable | |
MD5:8971185B1EC37121B7A4343758DDE077 | SHA256:610A60FBB42E360C850C8F8C1AC3A46EE11CDC7AA0BCEA1F586E641CE9D72AE1 | |||
| 3812 | sublime_text_build_4180_x64_setup.tmp | C:\Program Files\Sublime Text\is-TJKKV.tmp | executable | |
MD5:9155C9ED10429307CB87EC505CD37ADE | SHA256:3DF7C995328BA1C1B47AD25F22EC22245105BEFF850B8E9AE97D70AF8D7B1CEE | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
4712 | MoUsoCoreWorker.exe | GET | 200 | 2.16.241.12:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
5064 | SearchApp.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D | unknown | — | — | whitelisted |
1176 | svchost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
4712 | MoUsoCoreWorker.exe | GET | 200 | 95.101.149.131:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
6548 | SIHClient.exe | GET | 200 | 23.35.229.160:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
6120 | backgroundTaskHost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D | unknown | — | — | whitelisted |
6548 | SIHClient.exe | GET | 200 | 23.35.229.160:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 51.104.136.2:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4712 | MoUsoCoreWorker.exe | 2.16.241.12:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
4712 | MoUsoCoreWorker.exe | 95.101.149.131:80 | www.microsoft.com | Akamai International B.V. | NL | whitelisted |
4932 | svchost.exe | 51.104.136.2:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
544 | RUXIMICS.exe | 51.104.136.2:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4932 | svchost.exe | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
5064 | SearchApp.exe | 92.123.104.31:443 | www.bing.com | Akamai International B.V. | DE | whitelisted |
1176 | svchost.exe | 40.126.32.136:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
Domain | IP | Reputation |
|---|---|---|
google.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
settings-win.data.microsoft.com |
| whitelisted |
www.bing.com |
| whitelisted |
login.live.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
go.microsoft.com |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |
fe3cr.delivery.mp.microsoft.com |
| whitelisted |