File name:

e5afe9e958150dc4be1fe2d521a44a20.exe

Full analysis: https://app.any.run/tasks/6c7ef6c2-2c0e-4e2a-b46a-6e6bd323f278
Verdict: Malicious activity
Threats:

Stealers are a group of malicious software that are intended for gaining unauthorized access to users’ information and transferring it to the attacker. The stealer malware category includes various types of programs that focus on their particular kind of data, including files, passwords, and cryptocurrency. Stealers are capable of spying on their targets by recording their keystrokes and taking screenshots. This type of malware is primarily distributed as part of phishing campaigns.

Analysis date: September 03, 2025, 17:58:17
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
upx
susp-powershell
stealer
salatstealer
golang
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed, 4 sections
MD5:

E5AFE9E958150DC4BE1FE2D521A44A20

SHA1:

AEC6EAA8E38F80092CBA3AFD807336CA05EA93FA

SHA256:

B86B984ADDD013ED5D0CD5653529549B80A0DFAE2552244D537B7030F915B475

SSDEEP:

98304:cFzatZTMZfc48En7pDm4lDvD8ac7dTV3IIVwKrqoGqFjFdReXWQgUQAEh2E5Geai:gF0tYm2OdRP

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • SALATSTEALER has been detected (YARA)

      • e5afe9e958150dc4be1fe2d521a44a20.exe (PID: 3572)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • e5afe9e958150dc4be1fe2d521a44a20.exe (PID: 2964)
    • Application launched itself

      • e5afe9e958150dc4be1fe2d521a44a20.exe (PID: 2964)
    • There is functionality for taking screenshot (YARA)

      • e5afe9e958150dc4be1fe2d521a44a20.exe (PID: 3572)
    • Multiple wallet extension IDs have been found

      • e5afe9e958150dc4be1fe2d521a44a20.exe (PID: 3572)
  • INFO

    • Checks supported languages

      • e5afe9e958150dc4be1fe2d521a44a20.exe (PID: 2964)
      • e5afe9e958150dc4be1fe2d521a44a20.exe (PID: 3572)
    • Reads the computer name

      • e5afe9e958150dc4be1fe2d521a44a20.exe (PID: 2964)
      • e5afe9e958150dc4be1fe2d521a44a20.exe (PID: 3572)
    • Reads the machine GUID from the registry

      • e5afe9e958150dc4be1fe2d521a44a20.exe (PID: 2964)
      • e5afe9e958150dc4be1fe2d521a44a20.exe (PID: 3572)
    • Process checks computer location settings

      • e5afe9e958150dc4be1fe2d521a44a20.exe (PID: 2964)
    • Found Base64 encoded access to Windows Defender via PowerShell (YARA)

      • e5afe9e958150dc4be1fe2d521a44a20.exe (PID: 3572)
    • Detects GO elliptic curve encryption (YARA)

      • e5afe9e958150dc4be1fe2d521a44a20.exe (PID: 3572)
    • Application based on Golang

      • e5afe9e958150dc4be1fe2d521a44a20.exe (PID: 3572)
    • Found Base64 encoded file access via PowerShell (YARA)

      • e5afe9e958150dc4be1fe2d521a44a20.exe (PID: 3572)
    • Found Base64 encoded access to environment variables via PowerShell (YARA)

      • e5afe9e958150dc4be1fe2d521a44a20.exe (PID: 3572)
    • UPX packer has been detected

      • e5afe9e958150dc4be1fe2d521a44a20.exe (PID: 3572)
    • Reads the software policy settings

      • slui.exe (PID: 6860)
    • Checks proxy server information

      • slui.exe (PID: 6860)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | UPX compressed Win32 Executable (61.1)
.dll | Win32 Dynamic Link Library (generic) (14.8)
.exe | Win32 Executable (generic) (10.1)
.exe | Win16/32 Executable Delphi generic (4.6)
.exe | Generic Win/DOS Executable (4.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 0000:00:00 00:00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 3
CodeSize: 3289088
InitializedDataSize: 9868800
UninitializedDataSize: 8798208
EntryPoint: 0xb870e0
OSVersion: 6.1
ImageVersion: 1
SubsystemVersion: 6.1
Subsystem: Windows GUI
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
140
Monitored processes
3
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details

Process information

PID
CMD
Path
Indicators
Parent process
2964"C:\Users\admin\AppData\Local\Temp\e5afe9e958150dc4be1fe2d521a44a20.exe" C:\Users\admin\AppData\Local\Temp\e5afe9e958150dc4be1fe2d521a44a20.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
2
Modules
Images
c:\users\admin\appdata\local\temp\e5afe9e958150dc4be1fe2d521a44a20.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\bcryptprimitives.dll
3572"C:\Users\admin\AppData\Local\Temp\e5afe9e958150dc4be1fe2d521a44a20.exe" C:\Users\admin\AppData\Local\Temp\e5afe9e958150dc4be1fe2d521a44a20.exe
e5afe9e958150dc4be1fe2d521a44a20.exe
User:
admin
Integrity Level:
HIGH
Modules
Images
c:\users\admin\appdata\local\temp\e5afe9e958150dc4be1fe2d521a44a20.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\bcryptprimitives.dll
6860C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
Total events
1 288
Read events
1 288
Write events
0
Delete events
0

Modification events

No data
Executable files
0
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

No data
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
67
DNS requests
20
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3396
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
DE
binary
471 b
whitelisted
1268
svchost.exe
GET
200
23.216.77.6:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
DE
binary
825 b
whitelisted
1268
svchost.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
DE
binary
814 b
whitelisted
2940
svchost.exe
GET
200
69.192.161.44:80
http://x1.c.lencr.org/
DE
binary
734 b
whitelisted
6812
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
DE
binary
407 b
whitelisted
6812
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
DE
binary
419 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
5944
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1268
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5432
RUXIMICS.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3572
e5afe9e958150dc4be1fe2d521a44a20.exe
8.8.4.4:443
dns.google
whitelisted
3572
e5afe9e958150dc4be1fe2d521a44a20.exe
8.8.8.8:443
dns.google
whitelisted
3572
e5afe9e958150dc4be1fe2d521a44a20.exe
104.21.112.1:443
unknown
4
System
192.168.100.255:138
whitelisted
3572
e5afe9e958150dc4be1fe2d521a44a20.exe
1.1.1.1:443
whitelisted
3396
svchost.exe
20.190.160.64:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 4.231.128.59
  • 20.73.194.208
whitelisted
google.com
  • 172.217.18.14
whitelisted
dns.google
  • 8.8.8.8
  • 8.8.4.4
whitelisted
login.live.com
  • 20.190.160.64
  • 20.190.160.132
  • 20.190.160.5
  • 40.126.32.74
  • 40.126.32.136
  • 40.126.32.133
  • 20.190.160.2
  • 20.190.160.66
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
crl.microsoft.com
  • 23.216.77.6
  • 23.216.77.20
  • 23.216.77.42
whitelisted
www.microsoft.com
  • 23.35.229.160
whitelisted
client.wns.windows.com
  • 172.211.123.249
whitelisted
slscr.update.microsoft.com
  • 74.178.76.128
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 13.95.31.18
whitelisted

Threats

PID
Process
Class
Message
3572
e5afe9e958150dc4be1fe2d521a44a20.exe
Misc activity
ET INFO Observed Cloudflare DNS over HTTPS Domain (cloudflare-dns .com in TLS SNI)
3572
e5afe9e958150dc4be1fe2d521a44a20.exe
Misc activity
ET INFO Observed Google DNS over HTTPS Domain (dns .google in TLS SNI)
No debug info