| File name: | sai-eng-pack-1.1.0-f1.exe |
| Full analysis: | https://app.any.run/tasks/48a45595-5f9b-4f96-8260-b3aa2b469066 |
| Verdict: | Malicious activity |
| Analysis date: | November 09, 2023, 22:09:16 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive |
| MD5: | 58021F97C35478B4422BB9BBE1D1E41A |
| SHA1: | 5B5618E840BAED63172ECB1FD1B972B16657B394 |
| SHA256: | A69EE2EA00FC26C99D5C4FC69134D926F216FC31DDDEC75A8C2454E39E8F53F0 |
| SSDEEP: | 98304:ZXanXUy3kBDdkhEA1ULARxMR/Zou6e1cJ0yamRq0lBWb4M4Rd9veaT27lecGsCkG:yz |
| .exe | | | NSIS - Nullsoft Scriptable Install System (94.8) |
|---|---|---|
| .exe | | | Win32 Executable MS Visual C++ (generic) (3.4) |
| .dll | | | Win32 Dynamic Link Library (generic) (0.7) |
| .exe | | | Win32 Executable (generic) (0.5) |
| .exe | | | Generic Win/DOS Executable (0.2) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2009:12:05 23:50:52+01:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 24064 |
| InitializedDataSize: | 164864 |
| UninitializedDataSize: | 1024 |
| EntryPoint: | 0x30fa |
| OSVersion: | 4 |
| ImageVersion: | 6 |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 3384 | "C:\Program Files\Windows Media Player\wmpnscfg.exe" | C:\Program Files\Windows Media Player\wmpnscfg.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Network Sharing Service Configuration Application Exit code: 0 Version: 12.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3484 | "C:\Users\admin\AppData\Local\Temp\sai-eng-pack-1.1.0-f1.exe" | C:\Users\admin\AppData\Local\Temp\sai-eng-pack-1.1.0-f1.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 3512 | "sai.exe" | C:\Users\admin\AppData\Local\Zame\PaintTool SAI English Pack\sai.exe | — | start-sai.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 3564 | "C:\Users\admin\AppData\Local\Zame\PaintTool SAI English Pack\start-sai.exe" | C:\Users\admin\AppData\Local\Zame\PaintTool SAI English Pack\start-sai.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 1 Modules
| |||||||||||||||
| 3928 | "sai.exe" | C:\Users\admin\AppData\Local\Zame\PaintTool SAI English Pack\sai.exe | — | start-sai.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 3932 | "C:\Users\admin\AppData\Local\Zame\PaintTool SAI English Pack\start-sai.exe" | C:\Users\admin\AppData\Local\Zame\PaintTool SAI English Pack\start-sai.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 1 Modules
| |||||||||||||||
| (PID) Process: | (3384) wmpnscfg.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{A0846696-F2EF-45EA-8FF7-08F391F5C737}\{857FCC3A-0778-40AB-8F81-FDA324CC6E41} |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (3384) wmpnscfg.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{A0846696-F2EF-45EA-8FF7-08F391F5C737} |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (3384) wmpnscfg.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Health\{622543A4-75A1-49AC-B1EB-13369586EEDA} |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (3928) sai.exe | Key: | HKEY_CURRENT_USER\Software\SYSTEMAX Software Development\Sai\Tool\marquee@sai |
| Operation: | write | Name: | ShortcutKey |
Value: 0 | |||
| (PID) Process: | (3928) sai.exe | Key: | HKEY_CURRENT_USER\Software\SYSTEMAX Software Development\Sai\Tool\marquee@sai |
| Operation: | write | Name: | HQPreview |
Value: 0 | |||
| (PID) Process: | (3928) sai.exe | Key: | HKEY_CURRENT_USER\Software\SYSTEMAX Software Development\Sai\Tool\marquee@sai |
| Operation: | write | Name: | Perspective |
Value: 0 | |||
| (PID) Process: | (3928) sai.exe | Key: | HKEY_CURRENT_USER\Software\SYSTEMAX Software Development\Sai\Tool\lasso@sai |
| Operation: | write | Name: | ShortcutKey |
Value: 0 | |||
| (PID) Process: | (3928) sai.exe | Key: | HKEY_CURRENT_USER\Software\SYSTEMAX Software Development\Sai\Tool\lasso@sai |
| Operation: | write | Name: | Antialias |
Value: 1 | |||
| (PID) Process: | (3928) sai.exe | Key: | HKEY_CURRENT_USER\Software\SYSTEMAX Software Development\Sai\Tool\magicwand@sai |
| Operation: | write | Name: | ShortcutKey |
Value: 0 | |||
| (PID) Process: | (3928) sai.exe | Key: | HKEY_CURRENT_USER\Software\SYSTEMAX Software Development\Sai\Tool\magicwand@sai |
| Operation: | write | Name: | FillMode |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3484 | sai-eng-pack-1.1.0-f1.exe | C:\Users\admin\AppData\Local\Zame\PaintTool SAI English Pack\misc.ini | binary | |
MD5:8AFF15CB6484CAC7C3E1EDE83D59F192 | SHA256:49B9FC44815E7112A354A5D6138825ED63ED7A956B84782C08891987489C0699 | |||
| 3484 | sai-eng-pack-1.1.0-f1.exe | C:\Users\admin\AppData\Local\Zame\PaintTool SAI English Pack\blotmap\Noise.bmp | image | |
MD5:7E313E2D7A64656EF7101D180EFC2DA8 | SHA256:75B412BC911F85B71AB0F74648FCA9D8A7B0F88BD2EB65CD9F941CC1CA87FA42 | |||
| 3484 | sai-eng-pack-1.1.0-f1.exe | C:\Users\admin\AppData\Local\Zame\PaintTool SAI English Pack\sai.exe | executable | |
MD5:155192CE86F1B5417F651F59C7B06729 | SHA256:8B2779E90DAC0C057C9D9E6D5F0EBDA5331494DE5887BD0ED58F82B7BB4333F1 | |||
| 3484 | sai-eng-pack-1.1.0-f1.exe | C:\Users\admin\AppData\Local\Zame\PaintTool SAI English Pack\blotmap\Fuzystatic.bmp | image | |
MD5:3C66321A69262FB03FE41F8E1D85CFA9 | SHA256:69D721EC8BF39A5EE8A375C21655A4FF5447415216C711FE3045B81BA011B62A | |||
| 3484 | sai-eng-pack-1.1.0-f1.exe | C:\Users\admin\AppData\Local\Zame\PaintTool SAI English Pack\language.conf | text | |
MD5:E92D5E445498C960ED1389904704F5B4 | SHA256:666D7F0B271B9C590911DADC55024E0A4B5D594A8114F3EBEC72677DD512DE41 | |||
| 3484 | sai-eng-pack-1.1.0-f1.exe | C:\Users\admin\AppData\Local\Zame\PaintTool SAI English Pack\do-it-yourself\TODO.txt | text | |
MD5:F6E78C820A563B065BBF45817C0456D0 | SHA256:65FEE1A8DAD533AD8AB770F9A05CD54A455CDD1BF665F0CB66DAB6FE6301D266 | |||
| 3484 | sai-eng-pack-1.1.0-f1.exe | C:\Users\admin\AppData\Local\Zame\PaintTool SAI English Pack\blotmap\Spread.bmp | image | |
MD5:B953210F80206D395F79BDFC480B08BA | SHA256:3A50C1123D38839112E6EFDBA622098138F895EECA65A13923EAA00EF5903FB1 | |||
| 3484 | sai-eng-pack-1.1.0-f1.exe | C:\Users\admin\AppData\Local\Zame\PaintTool SAI English Pack\brushtex\Canvas.bmp | image | |
MD5:77ABF38CEB44FF0D9F32F1A28106CF40 | SHA256:56FD2208AC9082C2500B155F5DFD312B3289C53B2E5AE259D6B30E50982A5D76 | |||
| 3484 | sai-eng-pack-1.1.0-f1.exe | C:\Users\admin\AppData\Local\Zame\PaintTool SAI English Pack\history.txt | text | |
MD5:19EFC35F746C5A8566A034B8C4FE47C2 | SHA256:F631C269852D8C631DA40BBB404A6EECC6BAFA0571B6D1BAE0AF8EDE71A9F958 | |||
| 3484 | sai-eng-pack-1.1.0-f1.exe | C:\Users\admin\AppData\Local\Zame\PaintTool SAI English Pack\help.chm | binary | |
MD5:6B07AD12686295D20F9989B6D7C1999A | SHA256:23B70C51992D895FB0A103C963D3920E546DAF26C8A1FA64E5A7771E969F3AA9 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
2588 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |