File name:

sbsetup.exe

Full analysis: https://app.any.run/tasks/894d7825-05c7-4c1c-bb58-8d76ffd51fa2
Verdict: Malicious activity
Analysis date: November 23, 2023, 09:07:03
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
MD5:

D45E24DA6083F3CBF75EBFC39BE1A076

SHA1:

8F3C6F68A619744D95856B49CD48E38763E4E065

SHA256:

DF7D2B607FFEDFA8D8D139ECC9AFC54C4181D82E42D7496BF7DE668764EA74D5

SSDEEP:

98304:ncoZ0BoGmPNK7UKNNR8FkTRAUT7sU422zMEOEuhSnb+Yck1Xh+4VWa/a1ZOUjoUX:8Qh2spI

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • sbsetup.exe (PID: 3472)
  • SUSPICIOUS

    • Application launched itself

      • sbrowser.exe (PID: 3880)
    • Reads the Internet Settings

      • sbrowser.exe (PID: 3880)
    • Reads Microsoft Outlook installation path

      • sbrowser.exe (PID: 3880)
    • Checks Windows Trust Settings

      • sbrowser.exe (PID: 3880)
    • Detected use of alternative data streams (AltDS)

      • sbrowser.exe (PID: 3880)
    • Reads settings of System Certificates

      • sbrowser.exe (PID: 3880)
    • Reads Internet Explorer settings

      • sbrowser.exe (PID: 3880)
    • Reads security settings of Internet Explorer

      • sbrowser.exe (PID: 3880)
  • INFO

    • Checks supported languages

      • sbsetup.exe (PID: 3472)
      • sbrowser.exe (PID: 3596)
      • sbrowser.exe (PID: 3880)
      • sbrowser.exe (PID: 3724)
      • wmpnscfg.exe (PID: 4068)
    • Create files in a temporary directory

      • sbsetup.exe (PID: 3472)
      • sbrowser.exe (PID: 3880)
    • Reads the computer name

      • sbsetup.exe (PID: 3472)
      • sbrowser.exe (PID: 3596)
      • sbrowser.exe (PID: 3880)
      • sbrowser.exe (PID: 3724)
      • wmpnscfg.exe (PID: 4068)
    • Reads the machine GUID from the registry

      • sbsetup.exe (PID: 3472)
      • sbrowser.exe (PID: 3596)
      • sbrowser.exe (PID: 3880)
      • sbrowser.exe (PID: 3724)
      • wmpnscfg.exe (PID: 4068)
    • Creates files in the program directory

      • sbsetup.exe (PID: 3472)
    • Creates files or folders in the user directory

      • sbsetup.exe (PID: 3472)
      • sbrowser.exe (PID: 3596)
      • sbrowser.exe (PID: 3880)
    • Reads Environment values

      • sbsetup.exe (PID: 3472)
    • Manual execution by a user

      • sbrowser.exe (PID: 3880)
      • wmpnscfg.exe (PID: 4068)
      • WINWORD.EXE (PID: 300)
    • Checks proxy server information

      • sbrowser.exe (PID: 3880)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | NSIS - Nullsoft Scriptable Install System (94.8)
.exe | Win32 Executable MS Visual C++ (generic) (3.4)
.dll | Win32 Dynamic Link Library (generic) (0.7)
.exe | Win32 Executable (generic) (0.5)
.exe | Generic Win/DOS Executable (0.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2007:06:08 23:48:42+02:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 23552
InitializedDataSize: 164864
UninitializedDataSize: 1024
EntryPoint: 0x3190
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
50
Monitored processes
7
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start sbsetup.exe sbrowser.exe no specs sbrowser.exe sbrowser.exe wmpnscfg.exe no specs winword.exe no specs sbsetup.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
300"C:\Program Files\Microsoft Office\Office14\WINWORD.EXE" C:\Program Files\Microsoft Office\Office14\WINWORD.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Word
Exit code:
0
Version:
14.0.6024.1000
Modules
Images
c:\program files\microsoft office\office14\winword.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc\comctl32.dll
3212"C:\Users\admin\AppData\Local\Temp\sbsetup.exe" C:\Users\admin\AppData\Local\Temp\sbsetup.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\appdata\local\temp\sbsetup.exe
c:\windows\system32\ntdll.dll
3472"C:\Users\admin\AppData\Local\Temp\sbsetup.exe" C:\Users\admin\AppData\Local\Temp\sbsetup.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\sbsetup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
3596"C:\Program Files\SlimBrowser\sbrowser.exe"C:\Program Files\SlimBrowser\sbrowser.exesbsetup.exe
User:
admin
Company:
FlashPeak, Inc.
Integrity Level:
HIGH
Description:
FlashPeak SlimBrowser
Exit code:
0
Version:
4.12
Modules
Images
c:\program files\slimbrowser\sbrowser.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
3724"C:\Program Files\SlimBrowser\sbrowser.exe" -sdC:\Program Files\SlimBrowser\sbrowser.exe
sbrowser.exe
User:
admin
Company:
FlashPeak, Inc.
Integrity Level:
HIGH
Description:
FlashPeak SlimBrowser
Exit code:
1
Version:
4.12
Modules
Images
c:\program files\slimbrowser\sbrowser.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
3880"C:\Program Files\SlimBrowser\sbrowser.exe" C:\Program Files\SlimBrowser\sbrowser.exe
explorer.exe
User:
admin
Company:
FlashPeak, Inc.
Integrity Level:
MEDIUM
Description:
FlashPeak SlimBrowser
Exit code:
0
Version:
4.12
Modules
Images
c:\program files\slimbrowser\sbrowser.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
4068"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\ole32.dll
Total events
15 651
Read events
15 119
Write events
353
Delete events
179

Modification events

(PID) Process:(3472) sbsetup.exeKey:HKEY_CURRENT_USER\Software\FlashPeak\SlimBrowser\Settings
Operation:writeName:ProgramGroup
Value:
0
(PID) Process:(3472) sbsetup.exeKey:HKEY_CURRENT_USER\Software\FlashPeak\SlimBrowser\Settings
Operation:writeName:DesktopSC
Value:
0
(PID) Process:(3472) sbsetup.exeKey:HKEY_CURRENT_USER\Software\FlashPeak\SlimBrowser\Settings
Operation:writeName:QuickLaunchSC
Value:
0
(PID) Process:(3596) sbrowser.exeKey:HKEY_CURRENT_USER\Software\FlashPeak\SlimBrowser\Settings
Operation:writeName:FirstRun
Value:
1
(PID) Process:(3596) sbrowser.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
Operation:writeName:GlobalAssocChangedCounter
Value:
115
(PID) Process:(3880) sbrowser.exeKey:HKEY_CURRENT_USER\Software\FlashPeak\SlimBrowser\Settings
Operation:writeName:FirstRun
Value:
0
(PID) Process:(3880) sbrowser.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3880) sbrowser.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(3880) sbrowser.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(3880) sbrowser.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
Executable files
5
Suspicious files
79
Text files
274
Unknown types
0

Dropped files

PID
Process
Filename
Type
3472sbsetup.exeC:\Users\admin\AppData\Local\Temp\nst741C.tmp\UserInfo.dllexecutable
MD5:8092119FA7038477602715FBB9A749B8
SHA256:6C43AF5362C855C59C4472225FBDAEBE26444C711BE22E0E5AB80FDCB32E9AF7
3472sbsetup.exeC:\Program Files\SlimBrowser\sbrowser.chmbinary
MD5:003BD10F08E2A0A0298F215F8843405F
SHA256:625A97B8D20D53F648C7207200606D78006AC4CBFE444F40B8ACBDD6C4DB85AD
3472sbsetup.exeC:\Users\admin\AppData\Local\Temp\nst741C.tmp\ioSpecial.initext
MD5:E2D5070BC28DB1AC745613689FF86067
SHA256:D95AED234F932A1C48A2B1B0D98C60CA31F962310C03158E2884AB4DDD3EA1E0
3472sbsetup.exeC:\Program Files\SlimBrowser\images\Donation_Off.gifimage
MD5:C60DCAC56264A8062B7BD25FFAE57D4C
SHA256:CA6ECE065E0038C46D6356D1F2F3525EE7293C63943E307EFA663A4013433F6E
3472sbsetup.exeC:\Program Files\SlimBrowser\images\nav_first.gifimage
MD5:09D5519250D4BCEFD09153A8EB94D1D7
SHA256:FC169C1AA8486B7D2DB4EA938F81C4A4A8BBA5E2C0E6E0595917383FB0304047
3472sbsetup.exeC:\Program Files\SlimBrowser\images\Donation_On.gifimage
MD5:6D08EE0179AAEDDDE80F2D4FECC7E267
SHA256:62D73A90561C504FB084BAE43CA8AA2687F88C3AC21051FC50093D81E788C67C
3472sbsetup.exeC:\Program Files\SlimBrowser\images\blocked.gifimage
MD5:ED280A0EA3CC38F3CBBC747ACFBEF47D
SHA256:8F69E10876805B747A3AD08A818D46AC7E731B1AF417EA6E259D9B6B7DEB65C5
3472sbsetup.exeC:\Program Files\SlimBrowser\donatedlg.htmhtml
MD5:EA7950711AEF1C17046C9E5FE7CF5489
SHA256:2AE909C7BCBE0F39DC9E2A774B143E4AF0245AFDADE70D1C7633360782B250A2
3472sbsetup.exeC:\Program Files\SlimBrowser\sbrowser.exeexecutable
MD5:43CDBB4D8829D86BC2F842F8B8CDF94E
SHA256:9B3A0391199EC6E7DD75515D4877BAA48405F3C8C69CBBC18374E9F42124CEF3
3472sbsetup.exeC:\Program Files\SlimBrowser\syntax\Defaults\HTML.BCPtext
MD5:74F36F51171544ECA8DF64F39250D9F5
SHA256:AB80FFBA18736E92AA392A727E1425E2B07B628E3F51FDB733225AD623105822
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
26
TCP/UDP connections
69
DNS requests
42
Threats
10

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3880
sbrowser.exe
GET
200
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?5266e337ba798056
unknown
compressed
4.66 Kb
unknown
3880
sbrowser.exe
GET
302
34.205.242.146:80
http://www.slimb.com/sbrowser/version.txt
unknown
unknown
3880
sbrowser.exe
GET
301
2.18.237.101:80
http://ynet.co.il/
unknown
unknown
3880
sbrowser.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEAo3h2ReX7SMIk79G%2B0UDDw%3D
unknown
binary
1.47 Kb
unknown
3880
sbrowser.exe
GET
200
142.250.185.163:80
http://ocsp.pki.goog/gsr1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCEHe9DWzbNvka6iEPxPBY0w0%3D
unknown
binary
1.41 Kb
unknown
3880
sbrowser.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAbY2QTVWENG9oovp1QifsQ%3D
unknown
binary
471 b
unknown
3880
sbrowser.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAz1vQYrVgL0erhQLCPM8GY%3D
unknown
binary
471 b
unknown
GET
200
142.250.185.163:80
http://ocsp.pki.goog/gts1c3/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBTHLnmK3f9hNLO67UdCuLvGwCQHYwQUinR%2Fr4XN7pXNPZzQ4kYU83E1HScCEQDmzKJl66ZMrRKtZxoAGQQd
unknown
binary
472 b
unknown
3880
sbrowser.exe
GET
200
142.250.185.163:80
http://ocsp.pki.goog/gtsr1/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBQwkcLWD4LqGJ7bE7B1XZsEbmfwUAQU5K8rJnEaK0gnhS9SZizv8IkTcT4CDQIDvFNZazTHGPUBUGY%3D
unknown
binary
724 b
unknown
3880
sbrowser.exe
GET
200
108.138.34.92:80
http://o.ss2.us//MEowSDBGMEQwQjAJBgUrDgMCGgUABBSLwZ6EW5gdYc9UaSEaaLjjETNtkAQUv1%2B30c7dH4b0W1Ws3NcQwg6piOcCCQCnDkpMNIK3fw%3D%3D
unknown
binary
2.02 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2588
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
whitelisted
3880
sbrowser.exe
34.205.242.146:80
www.slimb.com
AMAZON-AES
US
unknown
3880
sbrowser.exe
104.26.7.37:443
www.hugedomains.com
CLOUDFLARENET
US
shared
3880
sbrowser.exe
93.184.221.240:80
ctldl.windowsupdate.com
EDGECAST
GB
whitelisted
3880
sbrowser.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
3880
sbrowser.exe
2.18.237.101:80
ynet.co.il
AKAMAI-AS
CL
unknown
3880
sbrowser.exe
184.30.21.140:443
www.ynet.co.il
AKAMAI-AS
DE
unknown

DNS requests

Domain
IP
Reputation
www.slimb.com
  • 34.205.242.146
  • 54.161.222.85
unknown
www.hugedomains.com
  • 104.26.7.37
  • 104.26.6.37
  • 172.67.70.191
whitelisted
ctldl.windowsupdate.com
  • 93.184.221.240
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
ynet.co.il
  • 2.18.237.101
unknown
www.ynet.co.il
  • 184.30.21.140
whitelisted
ynet-pic1.yit.co.il
  • 172.64.152.93
  • 104.18.35.163
unknown
securepubads.g.doubleclick.net
  • 142.250.186.98
whitelisted
totalmedia2.ynet.co.il
  • 184.30.21.140
whitelisted
cdn.taboola.com
  • 151.101.1.44
  • 151.101.65.44
  • 151.101.129.44
  • 151.101.193.44
whitelisted

Threats

PID
Process
Class
Message
3880
sbrowser.exe
Not Suspicious Traffic
INFO [ANY.RUN] FireBase Web App CDN (TLS SNI)
9 ETPRO signatures available at the full report
No debug info