File name:

CADLink-Viewer.EXE

Full analysis: https://app.any.run/tasks/07ace8b0-5b42-41dd-9ea1-21ca96ce1bba
Verdict: Malicious activity
Analysis date: June 29, 2025, 20:34:20
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 4 sections
MD5:

EEA7B8FC3213F22DCD30A145818798B8

SHA1:

1FC601BD156ADE8356F7583ACCC18C325940E1A9

SHA256:

CB9ECF0260027A2F0E31AFD6CF3FD4DAC4E8E98B471F4A40BFDA30A29FBEAB49

SSDEEP:

49152:xiejsRxasgQAEoF3Prp6E003jkNLbpZ0AJNoSfQ1NFRhxJ2ltmBgJJdrtLSLmBsy:ZYAsgQ3opp6E00Tkpbp9Rf2RnAltmSdd

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • CADLink-Viewer.EXE.exe (PID: 1732)
    • Process drops legitimate windows executable

      • CADLink-Viewer.EXE.exe (PID: 1732)
    • Searches for installed software

      • CADLink-Viewer.EXE.exe (PID: 1732)
    • There is functionality for taking screenshot (YARA)

      • CADLink-Viewer.EXE.exe (PID: 1732)
    • Creates a software uninstall entry

      • CADLink-Viewer.EXE.exe (PID: 1732)
    • Starts application with an unusual extension

      • CADLink-Viewer.EXE.exe (PID: 1732)
    • Creates/Modifies COM task schedule object

      • GLJ4BFE.tmp (PID: 5240)
      • GLJ4BFE.tmp (PID: 4864)
      • GLJ4BFE.tmp (PID: 3956)
    • Reads Microsoft Outlook installation path

      • Browser.exe (PID: 6876)
    • Reads security settings of Internet Explorer

      • Browser.exe (PID: 6876)
    • Reads Internet Explorer settings

      • Browser.exe (PID: 6876)
  • INFO

    • Create files in a temporary directory

      • CADLink-Viewer.EXE.exe (PID: 1732)
      • I-View.exe (PID: 4888)
      • Browser.exe (PID: 6876)
    • The sample compiled with english language support

      • CADLink-Viewer.EXE.exe (PID: 1732)
    • Reads the computer name

      • CADLink-Viewer.EXE.exe (PID: 1732)
      • GLJ4BFE.tmp (PID: 5240)
      • GLJ4BFE.tmp (PID: 6764)
      • GLJ4BFE.tmp (PID: 5372)
      • GLJ4BFE.tmp (PID: 4864)
      • I-View.exe (PID: 4888)
      • GLJ4BFE.tmp (PID: 3956)
      • Browser.exe (PID: 6876)
    • Checks supported languages

      • CADLink-Viewer.EXE.exe (PID: 1732)
      • GLJ4BFE.tmp (PID: 5240)
      • GLJ4BFE.tmp (PID: 6764)
      • GLJ4BFE.tmp (PID: 5372)
      • GLJ4BFE.tmp (PID: 4864)
      • GLJ4BFE.tmp (PID: 3956)
      • I-View.exe (PID: 4888)
      • Browser.exe (PID: 6876)
    • Creates files or folders in the user directory

      • CADLink-Viewer.EXE.exe (PID: 1732)
      • Browser.exe (PID: 6876)
    • Manual execution by a user

      • Browser.exe (PID: 6876)
      • I-View.exe (PID: 4888)
    • Checks proxy server information

      • Browser.exe (PID: 6876)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Wise Installer executable (96.9)
.dll | Win32 Dynamic Link Library (generic) (1.3)
.exe | Win32 Executable (generic) (0.9)
.exe | Generic Win/DOS Executable (0.4)
.exe | DOS Executable Generic (0.4)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2000:04:25 14:37:12+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit, Removable run from swap
PEType: PE32
LinkerVersion: 6
CodeSize: 8704
InitializedDataSize: 5632
UninitializedDataSize: -
EntryPoint: 0x21af
OSVersion: 4
ImageVersion: 4
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 1.3.0.2009
ProductVersionNumber: 1.3.0.2009
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows 16-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
CompanyName: CADLink UK Limited
FileDescription: CADLink Viewer
FileVersion: 1.3.0.2009
LegalCopyright: P J Paterson, 1997 - 2008
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
150
Monitored processes
11
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start cadlink-viewer.exe.exe glj4bfe.tmp no specs glj4bfe.tmp no specs glj4bfe.tmp no specs glj4bfe.tmp no specs glj4bfe.tmp no specs rundll32.exe no specs i-view.exe no specs browser.exe slui.exe no specs cadlink-viewer.exe.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1332"C:\Users\admin\Desktop\CADLink-Viewer.EXE.exe" C:\Users\admin\Desktop\CADLink-Viewer.EXE.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\desktop\cadlink-viewer.exe.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
1732"C:\Users\admin\Desktop\CADLink-Viewer.EXE.exe" C:\Users\admin\Desktop\CADLink-Viewer.EXE.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\desktop\cadlink-viewer.exe.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acgenral.dll
2848C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
3956"C:\Users\admin\AppData\Local\Temp\GLJ4BFE.tmp" C:\Windows\System32\COMDLG32.OCXC:\Users\admin\AppData\Local\Temp\GLJ4BFE.tmpCADLink-Viewer.EXE.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\glj4bfe.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acgenral.dll
4864"C:\Users\admin\AppData\Local\Temp\GLJ4BFE.tmp" C:\Windows\System32\COMCTL32.OCXC:\Users\admin\AppData\Local\Temp\GLJ4BFE.tmpCADLink-Viewer.EXE.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\glj4bfe.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acgenral.dll
4888"C:\CADLink V5\I-View.exe" C:\CADLink V5\I-View.exeexplorer.exe
User:
admin
Company:
CADLink UK
Integrity Level:
MEDIUM
Description:
This program is free to anyone using CADLink generated drawings!
Exit code:
0
Version:
5.301.2021
Modules
Images
c:\cadlink v5\i-view.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvbvm60.dll
5240"C:\Users\admin\AppData\Local\Temp\GLJ4BFE.tmp" C:\Windows\System32\msvbvm60.dllC:\Users\admin\AppData\Local\Temp\GLJ4BFE.tmpCADLink-Viewer.EXE.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\glj4bfe.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acgenral.dll
5372"C:\Users\admin\AppData\Local\Temp\GLJ4BFE.tmp" C:\Windows\System32\THREED32.OCXC:\Users\admin\AppData\Local\Temp\GLJ4BFE.tmpCADLink-Viewer.EXE.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\glj4bfe.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acgenral.dll
6164C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -EmbeddingC:\Windows\System32\rundll32.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shcore.dll
c:\windows\system32\imagehlp.dll
6764"C:\Users\admin\AppData\Local\Temp\GLJ4BFE.tmp" C:\Windows\System32\Spin32.ocxC:\Users\admin\AppData\Local\Temp\GLJ4BFE.tmpCADLink-Viewer.EXE.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\glj4bfe.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acgenral.dll
Total events
2 418
Read events
1 962
Write events
360
Delete events
96

Modification events

(PID) Process:(1732) CADLink-Viewer.EXE.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\CADLink\CADLinkUK
Operation:writeName:INIFile
Value:
C:\CADLink V5
(PID) Process:(1732) CADLink-Viewer.EXE.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\SharedDlls
Operation:writeName:C:\Windows\System32\msvbvm60.dll
Value:
2
(PID) Process:(1732) CADLink-Viewer.EXE.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\SharedDlls
Operation:writeName:C:\Windows\System32\COMCTL32.OCX
Value:
1
(PID) Process:(1732) CADLink-Viewer.EXE.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\SharedDlls
Operation:writeName:C:\Windows\System32\COMDLG32.OCX
Value:
1
(PID) Process:(1732) CADLink-Viewer.EXE.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\SharedDlls
Operation:writeName:C:\Windows\System32\Spin32.ocx
Value:
1
(PID) Process:(1732) CADLink-Viewer.EXE.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\SharedDlls
Operation:writeName:C:\Windows\System32\THREED32.OCX
Value:
1
(PID) Process:(1732) CADLink-Viewer.EXE.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\CADLink Viewer
Operation:writeName:DisplayName
Value:
CADLink Viewer
(PID) Process:(1732) CADLink-Viewer.EXE.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\CADLink Viewer
Operation:writeName:UninstallString
Value:
C:\CADLink V5\UNWISE.EXE C:\CADLink V5\INSTALL.LOG
(PID) Process:(5240) GLJ4BFE.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{D5DE8D20-5BB8-11D1-A1E3-00A0C90F2731}\InProcServer32
Operation:writeName:ThreadingModel
Value:
Apartment
(PID) Process:(6764) GLJ4BFE.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{B16553C1-06DB-101B-85B2-0000C009BE81}\TypeLib
Operation:writeName:Version
Value:
1.0
Executable files
20
Suspicious files
5
Text files
18
Unknown types
0

Dropped files

PID
Process
Filename
Type
1732CADLink-Viewer.EXE.exeC:\Users\admin\AppData\Local\Temp\GLF57E8.tmpexecutable
MD5:B9B41E50D612E00BF3A49A6405B89D74
SHA256:50E7A30E1825FAB93B94B698C2C6D2CC1787B094C6CEE53EEED5C497F77443C9
1732CADLink-Viewer.EXE.exeC:\Users\admin\AppData\Local\Temp\GLC4BED.tmpexecutable
MD5:625214A1C57538359244DAB9FAC4636F
SHA256:810BBA54C92479BB47574BC214911BF310F0E98800BC33CDEFF35A5E13C82AC9
1732CADLink-Viewer.EXE.exeC:\Users\admin\AppData\Local\Temp\~GLH0000.TMPexecutable
MD5:B9B41E50D612E00BF3A49A6405B89D74
SHA256:50E7A30E1825FAB93B94B698C2C6D2CC1787B094C6CEE53EEED5C497F77443C9
1732CADLink-Viewer.EXE.exeC:\CADLink V5\I-View.exeexecutable
MD5:6EB95DBC5B59E965D57F697B2679D4EE
SHA256:15598FFFC449CD911D9AE76CDF94CE70C898B458317CD68338986859E0574CAB
1732CADLink-Viewer.EXE.exeC:\Users\admin\AppData\Local\Temp\GLJ4BFE.tmpexecutable
MD5:6F608D264503796BEBD7CD66B687BE92
SHA256:49833D2820AFB1D7409DFBD916480F2CDF5787D2E2D94166725BEB9064922D5D
1732CADLink-Viewer.EXE.exeC:\CADLink V5\~GLH0008.TMPexecutable
MD5:8818947909C867C779198CEF1645991A
SHA256:DE6F1F9BCF08E9CA1E20A7B3C758FD40B9A5DC6D7B16A111D81DC9F3D5C8D461
1732CADLink-Viewer.EXE.exeC:\CADLink V5\~GLH0007.TMPtext
MD5:D459967D5EE9E0BFE4BE400B94D4994F
SHA256:2D230107B776E5857EFB35D8E91096F7017A0EFC9AB63C0FD0971A564E02E271
1732CADLink-Viewer.EXE.exeC:\CADLink V5\~GLH0005.TMPtext
MD5:08E19C53F6B6773A4708B5401D7D4266
SHA256:88484BF7FEBDD7C8E3CEB409DCACBD7A1C9311D03CBF7D3255A7F304EDE90882
1732CADLink-Viewer.EXE.exeC:\CADLink V5\~GLH0004.TMPtext
MD5:04C402028B58D0E6E904540442FB8413
SHA256:361AD5365B861FC3E29E487F8B2487BAE410DBA7E80BDE5E8B0E6637D3A49280
1732CADLink-Viewer.EXE.exeC:\CADLink V5\CADLink Draft.initext
MD5:2F51E6C6CE36C19358791A6EA0B7B209
SHA256:B8832A643EDEA9191708FFBAF1EBD5675BEB7D374564DF2642468166B6ACA7BE
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
23
DNS requests
18
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2072
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
4680
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
1268
svchost.exe
GET
200
23.48.23.174:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
1268
svchost.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6876
Browser.exe
GET
200
176.32.230.9:80
http://www.cadlinkuk.com/Registration.htm
unknown
unknown
4680
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
6876
Browser.exe
GET
200
176.32.230.9:80
http://www.cadlinkuk.com/background.gif
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
5944
MoUsoCoreWorker.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3964
RUXIMICS.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1268
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
1268
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1268
svchost.exe
23.48.23.174:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
1268
svchost.exe
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
1268
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2072
svchost.exe
20.190.159.2:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
  • 4.231.128.59
  • 51.124.78.146
whitelisted
google.com
  • 142.250.186.110
whitelisted
crl.microsoft.com
  • 23.48.23.174
  • 23.48.23.183
  • 23.48.23.181
  • 23.48.23.177
  • 23.48.23.169
  • 23.48.23.194
  • 23.48.23.170
  • 23.48.23.173
  • 23.48.23.175
whitelisted
www.microsoft.com
  • 23.35.229.160
whitelisted
login.live.com
  • 20.190.159.2
  • 40.126.31.69
  • 40.126.31.3
  • 40.126.31.1
  • 20.190.159.129
  • 20.190.159.23
  • 20.190.159.4
  • 40.126.31.67
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
client.wns.windows.com
  • 172.211.123.248
whitelisted
nexusrules.officeapps.live.com
  • 52.111.229.43
whitelisted
slscr.update.microsoft.com
  • 4.245.163.56
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 13.95.31.18
whitelisted

Threats

PID
Process
Class
Message
Unknown Traffic
ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW)
No debug info