File name:

sai-eng-pack-1.1.0-f1.exe

Full analysis: https://app.any.run/tasks/48a45595-5f9b-4f96-8260-b3aa2b469066
Verdict: Malicious activity
Analysis date: November 09, 2023, 22:09:16
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
MD5:

58021F97C35478B4422BB9BBE1D1E41A

SHA1:

5B5618E840BAED63172ECB1FD1B972B16657B394

SHA256:

A69EE2EA00FC26C99D5C4FC69134D926F216FC31DDDEC75A8C2454E39E8F53F0

SSDEEP:

98304:ZXanXUy3kBDdkhEA1ULARxMR/Zou6e1cJ0yamRq0lBWb4M4Rd9veaT27lecGsCkG:yz

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • sai-eng-pack-1.1.0-f1.exe (PID: 3484)
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    • Checks supported languages

      • sai-eng-pack-1.1.0-f1.exe (PID: 3484)
      • wmpnscfg.exe (PID: 3384)
      • start-sai.exe (PID: 3564)
      • sai.exe (PID: 3512)
      • start-sai.exe (PID: 3932)
      • sai.exe (PID: 3928)
    • Reads the computer name

      • wmpnscfg.exe (PID: 3384)
      • sai-eng-pack-1.1.0-f1.exe (PID: 3484)
      • sai.exe (PID: 3512)
      • sai.exe (PID: 3928)
    • Creates files or folders in the user directory

      • sai-eng-pack-1.1.0-f1.exe (PID: 3484)
      • start-sai.exe (PID: 3564)
      • sai.exe (PID: 3512)
      • start-sai.exe (PID: 3932)
      • sai.exe (PID: 3928)
    • Creates files in the program directory

      • sai.exe (PID: 3512)
      • sai.exe (PID: 3928)
    • Reads CPU info

      • sai.exe (PID: 3512)
      • sai.exe (PID: 3928)
    • Reads the machine GUID from the registry

      • wmpnscfg.exe (PID: 3384)
      • sai.exe (PID: 3512)
      • sai.exe (PID: 3928)
    • Manual execution by a user

      • start-sai.exe (PID: 3564)
      • start-sai.exe (PID: 3932)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | NSIS - Nullsoft Scriptable Install System (94.8)
.exe | Win32 Executable MS Visual C++ (generic) (3.4)
.dll | Win32 Dynamic Link Library (generic) (0.7)
.exe | Win32 Executable (generic) (0.5)
.exe | Generic Win/DOS Executable (0.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2009:12:05 23:50:52+01:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 24064
InitializedDataSize: 164864
UninitializedDataSize: 1024
EntryPoint: 0x30fa
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
44
Monitored processes
6
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start sai-eng-pack-1.1.0-f1.exe no specs start-sai.exe no specs sai.exe no specs start-sai.exe sai.exe no specs wmpnscfg.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
3384"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\ole32.dll
3484"C:\Users\admin\AppData\Local\Temp\sai-eng-pack-1.1.0-f1.exe" C:\Users\admin\AppData\Local\Temp\sai-eng-pack-1.1.0-f1.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\sai-eng-pack-1.1.0-f1.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
3512"sai.exe"C:\Users\admin\AppData\Local\Zame\PaintTool SAI English Pack\sai.exestart-sai.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\zame\painttool sai english pack\sai.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3564"C:\Users\admin\AppData\Local\Zame\PaintTool SAI English Pack\start-sai.exe" C:\Users\admin\AppData\Local\Zame\PaintTool SAI English Pack\start-sai.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
1
Modules
Images
c:\users\admin\appdata\local\zame\painttool sai english pack\start-sai.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imm32.dll
3928"sai.exe"C:\Users\admin\AppData\Local\Zame\PaintTool SAI English Pack\sai.exestart-sai.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\zame\painttool sai english pack\sai.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3932"C:\Users\admin\AppData\Local\Zame\PaintTool SAI English Pack\start-sai.exe" C:\Users\admin\AppData\Local\Zame\PaintTool SAI English Pack\start-sai.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
1
Modules
Images
c:\users\admin\appdata\local\zame\painttool sai english pack\start-sai.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imm32.dll
Total events
2 230
Read events
2 209
Write events
18
Delete events
3

Modification events

(PID) Process:(3384) wmpnscfg.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{A0846696-F2EF-45EA-8FF7-08F391F5C737}\{857FCC3A-0778-40AB-8F81-FDA324CC6E41}
Operation:delete keyName:(default)
Value:
(PID) Process:(3384) wmpnscfg.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{A0846696-F2EF-45EA-8FF7-08F391F5C737}
Operation:delete keyName:(default)
Value:
(PID) Process:(3384) wmpnscfg.exeKey:HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Health\{622543A4-75A1-49AC-B1EB-13369586EEDA}
Operation:delete keyName:(default)
Value:
(PID) Process:(3928) sai.exeKey:HKEY_CURRENT_USER\Software\SYSTEMAX Software Development\Sai\Tool\marquee@sai
Operation:writeName:ShortcutKey
Value:
0
(PID) Process:(3928) sai.exeKey:HKEY_CURRENT_USER\Software\SYSTEMAX Software Development\Sai\Tool\marquee@sai
Operation:writeName:HQPreview
Value:
0
(PID) Process:(3928) sai.exeKey:HKEY_CURRENT_USER\Software\SYSTEMAX Software Development\Sai\Tool\marquee@sai
Operation:writeName:Perspective
Value:
0
(PID) Process:(3928) sai.exeKey:HKEY_CURRENT_USER\Software\SYSTEMAX Software Development\Sai\Tool\lasso@sai
Operation:writeName:ShortcutKey
Value:
0
(PID) Process:(3928) sai.exeKey:HKEY_CURRENT_USER\Software\SYSTEMAX Software Development\Sai\Tool\lasso@sai
Operation:writeName:Antialias
Value:
1
(PID) Process:(3928) sai.exeKey:HKEY_CURRENT_USER\Software\SYSTEMAX Software Development\Sai\Tool\magicwand@sai
Operation:writeName:ShortcutKey
Value:
0
(PID) Process:(3928) sai.exeKey:HKEY_CURRENT_USER\Software\SYSTEMAX Software Development\Sai\Tool\magicwand@sai
Operation:writeName:FillMode
Value:
0
Executable files
8
Suspicious files
21
Text files
63
Unknown types
0

Dropped files

PID
Process
Filename
Type
3484sai-eng-pack-1.1.0-f1.exeC:\Users\admin\AppData\Local\Zame\PaintTool SAI English Pack\sai.exeexecutable
MD5:155192CE86F1B5417F651F59C7B06729
SHA256:8B2779E90DAC0C057C9D9E6D5F0EBDA5331494DE5887BD0ED58F82B7BB4333F1
3484sai-eng-pack-1.1.0-f1.exeC:\Users\admin\AppData\Local\Zame\PaintTool SAI English Pack\history.txttext
MD5:19EFC35F746C5A8566A034B8C4FE47C2
SHA256:F631C269852D8C631DA40BBB404A6EECC6BAFA0571B6D1BAE0AF8EDE71A9F958
3484sai-eng-pack-1.1.0-f1.exeC:\Users\admin\AppData\Local\Zame\PaintTool SAI English Pack\presetcvsize.conftext
MD5:8B89CE7A6E8FA6F52CBD9446614D04F7
SHA256:A1FF6E27F1A18EE4081C3D66DB2725005FFD241868E341D131991402DFB89E00
3484sai-eng-pack-1.1.0-f1.exeC:\Users\admin\AppData\Local\Zame\PaintTool SAI English Pack\sfl.dllexecutable
MD5:3156C1DDAE3728DCA1D103A5E92ABBD7
SHA256:20E7CF5B16F1898844D1AA38C247E0D84482763616F6D17998C6D9CE63E4D927
3484sai-eng-pack-1.1.0-f1.exeC:\Users\admin\AppData\Local\Zame\PaintTool SAI English Pack\blotmap\Spread.bmpimage
MD5:B953210F80206D395F79BDFC480B08BA
SHA256:3A50C1123D38839112E6EFDBA622098138F895EECA65A13923EAA00EF5903FB1
3484sai-eng-pack-1.1.0-f1.exeC:\Users\admin\AppData\Local\Zame\PaintTool SAI English Pack\do-it-yourself\elemap-empty.psdbinary
MD5:65BFE651D6BB215E926ACD5B8A7B59C3
SHA256:E19E18F7C0C50AC5ED9FA25DB34D997E8A499EC394C9010F376BD3C0BCE1846D
3484sai-eng-pack-1.1.0-f1.exeC:\Users\admin\AppData\Local\Zame\PaintTool SAI English Pack\do-it-yourself\TODO.txttext
MD5:F6E78C820A563B065BBF45817C0456D0
SHA256:65FEE1A8DAD533AD8AB770F9A05CD54A455CDD1BF665F0CB66DAB6FE6301D266
3484sai-eng-pack-1.1.0-f1.exeC:\Users\admin\AppData\Local\Zame\PaintTool SAI English Pack\misc.inibinary
MD5:8AFF15CB6484CAC7C3E1EDE83D59F192
SHA256:49B9FC44815E7112A354A5D6138825ED63ED7A956B84782C08891987489C0699
3484sai-eng-pack-1.1.0-f1.exeC:\Users\admin\AppData\Local\Zame\PaintTool SAI English Pack\language.conftext
MD5:E92D5E445498C960ED1389904704F5B4
SHA256:666D7F0B271B9C590911DADC55024E0A4B5D594A8114F3EBEC72677DD512DE41
3484sai-eng-pack-1.1.0-f1.exeC:\Users\admin\AppData\Local\Zame\PaintTool SAI English Pack\blotmap\Noise.bmpimage
MD5:7E313E2D7A64656EF7101D180EFC2DA8
SHA256:75B412BC911F85B71AB0F74648FCA9D8A7B0F88BD2EB65CD9F941CC1CA87FA42
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
2588
svchost.exe
239.255.255.250:1900
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown

DNS requests

No data

Threats

No threats detected
No debug info