URL:

soft32.com

Full analysis: https://app.any.run/tasks/6bc89e48-3d41-464e-9d9a-beae0089a0a9
Verdict: Malicious activity
Analysis date: December 17, 2023, 02:46:18
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

CDD5D92AD2ADF4EC248A89D6C894FCD6

SHA1:

92383D65AE103BCC6200374D9680BA9010AF2372

SHA256:

E03A8FC78E93A1ACB205B094B77A894B18398AD612E879576960BAA6757F9544

SSDEEP:

3:30I:3x

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • Dell XPS One 2710 Intel Wireless Display Application_3.0.12.0.exe (PID: 2436)
    • Actions looks like stealing of personal data

      • Dell XPS One 2710 Intel Wireless Display Application_3.0.12.0.exe (PID: 2436)
  • SUSPICIOUS

    • The process drops C-runtime libraries

      • Dell XPS One 2710 Intel Wireless Display Application_3.0.12.0.exe (PID: 2436)
    • The process creates files with name similar to system file names

      • Dell XPS One 2710 Intel Wireless Display Application_3.0.12.0.exe (PID: 2436)
    • Reads the Internet Settings

      • Dell XPS One 2710 Intel Wireless Display Application_3.0.12.0.exe (PID: 2436)
      • saBSI.exe (PID: 3092)
    • Reads the Windows owner or organization settings

      • Dell XPS One 2710 Intel Wireless Display Application_3.0.12.0.exe (PID: 2436)
    • Process drops legitimate windows executable

      • Dell XPS One 2710 Intel Wireless Display Application_3.0.12.0.exe (PID: 2436)
    • Checks Windows Trust Settings

      • Dell XPS One 2710 Intel Wireless Display Application_3.0.12.0.exe (PID: 2436)
      • saBSI.exe (PID: 3092)
    • Reads security settings of Internet Explorer

      • Dell XPS One 2710 Intel Wireless Display Application_3.0.12.0.exe (PID: 2436)
      • saBSI.exe (PID: 3092)
    • Reads settings of System Certificates

      • Dell XPS One 2710 Intel Wireless Display Application_3.0.12.0.exe (PID: 2436)
      • saBSI.exe (PID: 3092)
    • Adds/modifies Windows certificates

      • Dell XPS One 2710 Intel Wireless Display Application_3.0.12.0.exe (PID: 2436)
    • Searches for installed software

      • Dell XPS One 2710 Intel Wireless Display Application_3.0.12.0.exe (PID: 2436)
  • INFO

    • Application launched itself

      • iexplore.exe (PID: 1776)
    • Drops the executable file immediately after the start

      • iexplore.exe (PID: 2088)
    • Create files in a temporary directory

      • Dell XPS One 2710 Intel Wireless Display Application_3.0.12.0.exe (PID: 2436)
    • Checks supported languages

      • Dell XPS One 2710 Intel Wireless Display Application_3.0.12.0.exe (PID: 2436)
      • saBSI.exe (PID: 3092)
    • The process uses the downloaded file

      • iexplore.exe (PID: 1776)
      • Dell XPS One 2710 Intel Wireless Display Application_3.0.12.0.exe (PID: 2436)
    • Reads the computer name

      • Dell XPS One 2710 Intel Wireless Display Application_3.0.12.0.exe (PID: 2436)
      • saBSI.exe (PID: 3092)
    • Reads Environment values

      • Dell XPS One 2710 Intel Wireless Display Application_3.0.12.0.exe (PID: 2436)
    • Reads the machine GUID from the registry

      • Dell XPS One 2710 Intel Wireless Display Application_3.0.12.0.exe (PID: 2436)
      • saBSI.exe (PID: 3092)
    • Reads product name

      • Dell XPS One 2710 Intel Wireless Display Application_3.0.12.0.exe (PID: 2436)
    • Creates files or folders in the user directory

      • Dell XPS One 2710 Intel Wireless Display Application_3.0.12.0.exe (PID: 2436)
    • Creates files in the program directory

      • saBSI.exe (PID: 3092)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
44
Monitored processes
5
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe dell xps one 2710 intel wireless display application_3.0.12.0.exe no specs dell xps one 2710 intel wireless display application_3.0.12.0.exe sabsi.exe

Process information

PID
CMD
Path
Indicators
Parent process
1776"C:\Program Files\Internet Explorer\iexplore.exe" "soft32.com"C:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
2088"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:1776 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
2320"C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\Dell XPS One 2710 Intel Wireless Display Application_3.0.12.0.exe" C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\Dell XPS One 2710 Intel Wireless Display Application_3.0.12.0.exeiexplore.exe
User:
admin
Company:
Intel
Integrity Level:
MEDIUM
Description:
Software Installation
Exit code:
3221226540
Version:
1.1.2.6582
Modules
Images
c:\users\admin\appdata\local\microsoft\windows\temporary internet files\content.ie5\b6qgx7lp\dell xps one 2710 intel wireless display application_3.0.12.0.exe
c:\windows\system32\ntdll.dll
2436"C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\Dell XPS One 2710 Intel Wireless Display Application_3.0.12.0.exe" C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\Dell XPS One 2710 Intel Wireless Display Application_3.0.12.0.exe
iexplore.exe
User:
admin
Company:
Intel
Integrity Level:
HIGH
Description:
Software Installation
Exit code:
0
Version:
1.1.2.6582
Modules
Images
c:\users\admin\appdata\local\microsoft\windows\temporary internet files\content.ie5\b6qgx7lp\dell xps one 2710 intel wireless display application_3.0.12.0.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3092"saBSI.exe" /affid 91212 PaidDistribution=true InstallID=d8bee079-4299-414f-8d00-1936cc9f2a98 subID=TETC:\Users\admin\AppData\Local\Temp\3354215998cc498efdf76f123473fe62\saBSI.exe
Dell XPS One 2710 Intel Wireless Display Application_3.0.12.0.exe
User:
admin
Company:
McAfee, LLC
Integrity Level:
HIGH
Description:
McAfee WebAdvisor(bootstrap installer)
Exit code:
4294967295
Version:
4,1,1,663
Modules
Images
c:\users\admin\appdata\local\temp\3354215998cc498efdf76f123473fe62\sabsi.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
Total events
42 545
Read events
42 306
Write events
235
Delete events
4

Modification events

(PID) Process:(1776) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPDaysSinceLastAutoMigration
Value:
0
(PID) Process:(1776) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchHighDateTime
Value:
30847387
(PID) Process:(1776) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
30847437
(PID) Process:(1776) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(1776) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(1776) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(1776) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(1776) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(1776) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(1776) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
Executable files
23
Suspicious files
113
Text files
490
Unknown types
0

Dropped files

PID
Process
Filename
Type
2088iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\CO2ZQRAV.htmhtml
MD5:CD2E0E43980A00FB6A2742D3AFD803B8
SHA256:BD9DF047D51943ACC4BC6CF55D88EDB5B6785A53337EE2A0F74DD521AEDDE87D
2088iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B66240B0F6C84BD4857ABA60CF5CE4A0_5043E0F5DF723415C9EECC201C838A62binary
MD5:B53794E21746DA0880DDE85C8C8019BB
SHA256:CBB772EC05AE4A0B30AB023AF35330E3CB48CE99029B3B5516262587AEEE07AC
2088iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\75CA58072B9926F763A91F0CC2798706_B5D3A17E5BEDD2EDA793611A0A74E1E8binary
MD5:0BC7B7B1DAE145F74EA9882067003DCE
SHA256:77AB6DCFC07E8EF9801611E1B94EE62DE66601DD198E4F8129E879C36378E91D
2088iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\BAD725C80F9E10846F35D039A996E4A8_88B6AE015495C1ECC395D19C1DD02894binary
MD5:7B94E902FD73C964884860EF79186AA9
SHA256:941ED1BB0264BB35845FC749B4640FA7FED1F2469D30FD9A8E4E07CA85304851
2088iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YTOWV792\9OQDAGXC.htmhtml
MD5:D33908205B09A4D7DC909EEEAFFC2680
SHA256:8535BA03A4F45035F0A42558A89E70064770726D241602EBFD5437612C9AB4B6
2088iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\icon[1].pngimage
MD5:D13C4AE0907F4B79C398AC653DDD31C3
SHA256:755498CEC7AE9EB38AC48DF2196F4003693FCFA15D7B4926CD6DD1123EC2BB63
2088iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:BA23EE4B0935EF665882DC2201670EDD
SHA256:0CB7D1873DBCD7300AAB6E5614B4D642FBF1274FD60D28E0B9D549381F9EC49C
2088iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\icon[2].pngimage
MD5:B0F88A75D7E894412DB6C919CE50AECF
SHA256:109AEABCB39C215CBD00DB1A27EB92ABBD0A457417F3A1E4152E8E4B2E3AF351
2088iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\BAD725C80F9E10846F35D039A996E4A8_88B6AE015495C1ECC395D19C1DD02894binary
MD5:81B415617A049EDE2BD3A29120019DFC
SHA256:44973AD98B84C076ECCFE3BECD822E3643C5AB16E019A453631D22E3740CAC1A
2088iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\icon[5].pngimage
MD5:D26D42B00FDF212EC35CB6D9187DC7EA
SHA256:A29A6DE78F21C1E7B6EE59F11574AB47D5C3C049A5A9DBFE540774502CFFC799
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
45
TCP/UDP connections
209
DNS requests
88
Threats
10

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2088
iexplore.exe
GET
301
18.66.122.13:80
http://soft32.com/
unknown
html
178 b
unknown
2088
iexplore.exe
GET
200
108.138.2.173:80
http://o.ss2.us//MEowSDBGMEQwQjAJBgUrDgMCGgUABBSLwZ6EW5gdYc9UaSEaaLjjETNtkAQUv1%2B30c7dH4b0W1Ws3NcQwg6piOcCCQCnDkpMNIK3fw%3D%3D
unknown
binary
2.02 Kb
unknown
2088
iexplore.exe
GET
301
18.66.122.79:80
http://www.soft32.com/
unknown
html
178 b
unknown
2088
iexplore.exe
GET
200
23.53.40.35:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?129d20c84d8c4223
unknown
compressed
4.66 Kb
unknown
2088
iexplore.exe
GET
200
18.66.142.79:80
http://ocsp.rootg2.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBSIfaREXmfqfJR3TkMYnD7O5MhzEgQUnF8A36oB1zArOIiiuG1KnPIRkYMCEwZ%2FlEoqJ83z%2BsKuKwH5CO65xMY%3D
unknown
binary
1.51 Kb
unknown
2088
iexplore.exe
GET
200
142.250.185.163:80
http://ocsp.pki.goog/gts1c3/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTHLnmK3f9hNLO67UdCuLvGwCQHYwQUinR%2Fr4XN7pXNPZzQ4kYU83E1HScCEGupzMnM%2BqGaCjIQPyd58u0%3D
unknown
binary
471 b
unknown
1776
iexplore.exe
GET
304
23.53.40.35:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?ed92cde4cb766a79
unknown
unknown
2088
iexplore.exe
GET
200
142.250.185.163:80
http://ocsp.pki.goog/gts1c3/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTHLnmK3f9hNLO67UdCuLvGwCQHYwQUinR%2Fr4XN7pXNPZzQ4kYU83E1HScCEGpYRvzN3kAuEMlMWsqSFLc%3D
unknown
binary
471 b
unknown
1776
iexplore.exe
GET
304
23.53.40.35:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?914f352674d8023c
unknown
unknown
1776
iexplore.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAzlnDD9eoNTLi0BRrMy%2BWU%3D
unknown
binary
313 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
2088
iexplore.exe
18.66.122.13:80
soft32.com
AMAZON-02
US
unknown
4
System
192.168.100.255:138
whitelisted
2088
iexplore.exe
18.66.122.79:80
soft32.com
AMAZON-02
US
unknown
2088
iexplore.exe
18.66.122.79:443
soft32.com
AMAZON-02
US
unknown
2088
iexplore.exe
23.53.40.35:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown
2088
iexplore.exe
108.138.2.173:80
o.ss2.us
AMAZON-02
US
unknown
2088
iexplore.exe
18.66.142.79:80
ocsp.rootg2.amazontrust.com
AMAZON-02
US
unknown
2088
iexplore.exe
142.250.184.226:443
pagead2.googlesyndication.com
GOOGLE
US
whitelisted
2088
iexplore.exe
142.250.186.174:443
www.google-analytics.com
GOOGLE
US
whitelisted

DNS requests

Domain
IP
Reputation
soft32.com
  • 18.66.122.13
  • 18.66.122.88
  • 18.66.122.54
  • 18.66.122.79
shared
www.soft32.com
  • 18.66.122.79
  • 18.66.122.13
  • 18.66.122.88
  • 18.66.122.54
shared
ctldl.windowsupdate.com
  • 23.53.40.35
  • 23.53.40.49
whitelisted
o.ss2.us
  • 108.138.2.173
  • 108.138.2.195
  • 108.138.2.107
  • 108.138.2.10
whitelisted
ocsp.rootg2.amazontrust.com
  • 18.66.142.79
whitelisted
ocsp.rootca1.amazontrust.com
  • 18.66.142.79
shared
d3gx3uz4yj2hnq.cloudfront.net
  • 99.86.1.53
  • 99.86.1.208
  • 99.86.1.71
  • 99.86.1.27
whitelisted
pagead2.googlesyndication.com
  • 142.250.184.226
whitelisted
d3fnqfpn2r2a3x.cloudfront.net
  • 18.245.62.229
  • 18.245.62.149
  • 18.245.62.172
  • 18.245.62.32
whitelisted
ocsp.pki.goog
  • 142.250.185.163
whitelisted

Threats

Found threats are available for the paid subscriptions
10 ETPRO signatures available at the full report
Process
Message
Dell XPS One 2710 Intel Wireless Display Application_3.0.12.0.exe
Error: File not found - sciterwrapper:console.tis
Dell XPS One 2710 Intel Wireless Display Application_3.0.12.0.exe
at sciter:init-script.tis
Dell XPS One 2710 Intel Wireless Display Application_3.0.12.0.exe
file:resources/tis/TranslateOfferTemplate.tis(82) : warning :'async' does not contain any 'await'
Dell XPS One 2710 Intel Wireless Display Application_3.0.12.0.exe
Dell XPS One 2710 Intel Wireless Display Application_3.0.12.0.exe
Dell XPS One 2710 Intel Wireless Display Application_3.0.12.0.exe
Dell XPS One 2710 Intel Wireless Display Application_3.0.12.0.exe
Dell XPS One 2710 Intel Wireless Display Application_3.0.12.0.exe
Error: File not found - sciterwrapper:console.tis
Dell XPS One 2710 Intel Wireless Display Application_3.0.12.0.exe
at sciter:init-script.tis
Dell XPS One 2710 Intel Wireless Display Application_3.0.12.0.exe
file:resources/tis/TranslateOfferTemplate.tis(82) : warning :'async' does not contain any 'await'