URL:

soft32.com

Full analysis: https://app.any.run/tasks/6bc89e48-3d41-464e-9d9a-beae0089a0a9
Verdict: Malicious activity
Analysis date: December 17, 2023, 02:46:18
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

CDD5D92AD2ADF4EC248A89D6C894FCD6

SHA1:

92383D65AE103BCC6200374D9680BA9010AF2372

SHA256:

E03A8FC78E93A1ACB205B094B77A894B18398AD612E879576960BAA6757F9544

SSDEEP:

3:30I:3x

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • Dell XPS One 2710 Intel Wireless Display Application_3.0.12.0.exe (PID: 2436)
    • Actions looks like stealing of personal data

      • Dell XPS One 2710 Intel Wireless Display Application_3.0.12.0.exe (PID: 2436)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • Dell XPS One 2710 Intel Wireless Display Application_3.0.12.0.exe (PID: 2436)
    • The process drops C-runtime libraries

      • Dell XPS One 2710 Intel Wireless Display Application_3.0.12.0.exe (PID: 2436)
    • Reads the Internet Settings

      • Dell XPS One 2710 Intel Wireless Display Application_3.0.12.0.exe (PID: 2436)
      • saBSI.exe (PID: 3092)
    • The process creates files with name similar to system file names

      • Dell XPS One 2710 Intel Wireless Display Application_3.0.12.0.exe (PID: 2436)
    • Reads the Windows owner or organization settings

      • Dell XPS One 2710 Intel Wireless Display Application_3.0.12.0.exe (PID: 2436)
    • Checks Windows Trust Settings

      • Dell XPS One 2710 Intel Wireless Display Application_3.0.12.0.exe (PID: 2436)
      • saBSI.exe (PID: 3092)
    • Reads security settings of Internet Explorer

      • Dell XPS One 2710 Intel Wireless Display Application_3.0.12.0.exe (PID: 2436)
      • saBSI.exe (PID: 3092)
    • Reads settings of System Certificates

      • Dell XPS One 2710 Intel Wireless Display Application_3.0.12.0.exe (PID: 2436)
      • saBSI.exe (PID: 3092)
    • Adds/modifies Windows certificates

      • Dell XPS One 2710 Intel Wireless Display Application_3.0.12.0.exe (PID: 2436)
    • Searches for installed software

      • Dell XPS One 2710 Intel Wireless Display Application_3.0.12.0.exe (PID: 2436)
  • INFO

    • Drops the executable file immediately after the start

      • iexplore.exe (PID: 2088)
    • Checks supported languages

      • Dell XPS One 2710 Intel Wireless Display Application_3.0.12.0.exe (PID: 2436)
      • saBSI.exe (PID: 3092)
    • The process uses the downloaded file

      • iexplore.exe (PID: 1776)
      • Dell XPS One 2710 Intel Wireless Display Application_3.0.12.0.exe (PID: 2436)
    • Application launched itself

      • iexplore.exe (PID: 1776)
    • Reads the computer name

      • Dell XPS One 2710 Intel Wireless Display Application_3.0.12.0.exe (PID: 2436)
      • saBSI.exe (PID: 3092)
    • Create files in a temporary directory

      • Dell XPS One 2710 Intel Wireless Display Application_3.0.12.0.exe (PID: 2436)
    • Reads the machine GUID from the registry

      • Dell XPS One 2710 Intel Wireless Display Application_3.0.12.0.exe (PID: 2436)
      • saBSI.exe (PID: 3092)
    • Reads Environment values

      • Dell XPS One 2710 Intel Wireless Display Application_3.0.12.0.exe (PID: 2436)
    • Reads product name

      • Dell XPS One 2710 Intel Wireless Display Application_3.0.12.0.exe (PID: 2436)
    • Creates files or folders in the user directory

      • Dell XPS One 2710 Intel Wireless Display Application_3.0.12.0.exe (PID: 2436)
    • Creates files in the program directory

      • saBSI.exe (PID: 3092)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
44
Monitored processes
5
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe dell xps one 2710 intel wireless display application_3.0.12.0.exe no specs dell xps one 2710 intel wireless display application_3.0.12.0.exe sabsi.exe

Process information

PID
CMD
Path
Indicators
Parent process
1776"C:\Program Files\Internet Explorer\iexplore.exe" "soft32.com"C:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
2088"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:1776 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
2320"C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\Dell XPS One 2710 Intel Wireless Display Application_3.0.12.0.exe" C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\Dell XPS One 2710 Intel Wireless Display Application_3.0.12.0.exeiexplore.exe
User:
admin
Company:
Intel
Integrity Level:
MEDIUM
Description:
Software Installation
Exit code:
3221226540
Version:
1.1.2.6582
Modules
Images
c:\users\admin\appdata\local\microsoft\windows\temporary internet files\content.ie5\b6qgx7lp\dell xps one 2710 intel wireless display application_3.0.12.0.exe
c:\windows\system32\ntdll.dll
2436"C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\Dell XPS One 2710 Intel Wireless Display Application_3.0.12.0.exe" C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\Dell XPS One 2710 Intel Wireless Display Application_3.0.12.0.exe
iexplore.exe
User:
admin
Company:
Intel
Integrity Level:
HIGH
Description:
Software Installation
Exit code:
0
Version:
1.1.2.6582
Modules
Images
c:\users\admin\appdata\local\microsoft\windows\temporary internet files\content.ie5\b6qgx7lp\dell xps one 2710 intel wireless display application_3.0.12.0.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3092"saBSI.exe" /affid 91212 PaidDistribution=true InstallID=d8bee079-4299-414f-8d00-1936cc9f2a98 subID=TETC:\Users\admin\AppData\Local\Temp\3354215998cc498efdf76f123473fe62\saBSI.exe
Dell XPS One 2710 Intel Wireless Display Application_3.0.12.0.exe
User:
admin
Company:
McAfee, LLC
Integrity Level:
HIGH
Description:
McAfee WebAdvisor(bootstrap installer)
Exit code:
4294967295
Version:
4,1,1,663
Modules
Images
c:\users\admin\appdata\local\temp\3354215998cc498efdf76f123473fe62\sabsi.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
Total events
42 545
Read events
42 306
Write events
235
Delete events
4

Modification events

(PID) Process:(1776) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPDaysSinceLastAutoMigration
Value:
0
(PID) Process:(1776) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchHighDateTime
Value:
30847387
(PID) Process:(1776) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
30847437
(PID) Process:(1776) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(1776) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(1776) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(1776) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(1776) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(1776) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(1776) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
Executable files
23
Suspicious files
113
Text files
490
Unknown types
0

Dropped files

PID
Process
Filename
Type
2088iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\57C8EDB95DF3F0AD4EE2DC2B8CFD4157compressed
MD5:1BFE591A4FE3D91B03CDF26EAACD8F89
SHA256:9CF94355051BF0F4A45724CA20D1CC02F76371B963AB7D1E38BD8997737B13D8
2088iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B66240B0F6C84BD4857ABA60CF5CE4A0_5043E0F5DF723415C9EECC201C838A62der
MD5:E45A0A12A596CA47CBDE7349DBE54B33
SHA256:82783F445F6C66F6F632DF5E8F417C1E75E491F6C98C3BA9463A2EA907274717
2088iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:BA23EE4B0935EF665882DC2201670EDD
SHA256:0CB7D1873DBCD7300AAB6E5614B4D642FBF1274FD60D28E0B9D549381F9EC49C
2088iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\CO2ZQRAV.htmhtml
MD5:CD2E0E43980A00FB6A2742D3AFD803B8
SHA256:BD9DF047D51943ACC4BC6CF55D88EDB5B6785A53337EE2A0F74DD521AEDDE87D
2088iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\BAD725C80F9E10846F35D039A996E4A8_88B6AE015495C1ECC395D19C1DD02894binary
MD5:7B94E902FD73C964884860EF79186AA9
SHA256:941ED1BB0264BB35845FC749B4640FA7FED1F2469D30FD9A8E4E07CA85304851
2088iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\HSW3ANKI.htmhtml
MD5:CD2E0E43980A00FB6A2742D3AFD803B8
SHA256:BD9DF047D51943ACC4BC6CF55D88EDB5B6785A53337EE2A0F74DD521AEDDE87D
2088iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\75CA58072B9926F763A91F0CC2798706_B5D3A17E5BEDD2EDA793611A0A74E1E8der
MD5:2B7B17AA0F07E8062ED54EFD2BABEB9C
SHA256:570620CFC948A4A36ACDA4F2EAE7A485B3DE4D7D097988139D13F16E267C4E64
2088iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5IWPIAR9\icon[1].pngimage
MD5:B63405D98435490DDF2D2238A20CFAC3
SHA256:9C9571CD1BA97A746E3EE04DCED341332890162F256870F43153A1D2C05104F1
2088iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\BAD725C80F9E10846F35D039A996E4A8_88B6AE015495C1ECC395D19C1DD02894binary
MD5:81B415617A049EDE2BD3A29120019DFC
SHA256:44973AD98B84C076ECCFE3BECD822E3643C5AB16E019A453631D22E3740CAC1A
2088iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YTOWV792\9OQDAGXC.htmhtml
MD5:D33908205B09A4D7DC909EEEAFFC2680
SHA256:8535BA03A4F45035F0A42558A89E70064770726D241602EBFD5437612C9AB4B6
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
45
TCP/UDP connections
209
DNS requests
88
Threats
10

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2088
iexplore.exe
GET
301
18.66.122.13:80
http://soft32.com/
unknown
html
178 b
unknown
2088
iexplore.exe
GET
301
18.66.122.79:80
http://www.soft32.com/
unknown
html
178 b
unknown
2088
iexplore.exe
GET
200
23.53.40.35:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?129d20c84d8c4223
unknown
compressed
4.66 Kb
unknown
2088
iexplore.exe
GET
200
108.138.2.173:80
http://o.ss2.us//MEowSDBGMEQwQjAJBgUrDgMCGgUABBSLwZ6EW5gdYc9UaSEaaLjjETNtkAQUv1%2B30c7dH4b0W1Ws3NcQwg6piOcCCQCnDkpMNIK3fw%3D%3D
unknown
binary
2.02 Kb
unknown
2088
iexplore.exe
GET
200
18.66.142.79:80
http://ocsp.rootg2.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBSIfaREXmfqfJR3TkMYnD7O5MhzEgQUnF8A36oB1zArOIiiuG1KnPIRkYMCEwZ%2FlEoqJ83z%2BsKuKwH5CO65xMY%3D
unknown
binary
1.51 Kb
unknown
2088
iexplore.exe
GET
200
18.66.142.79:80
http://ocsp.rootca1.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBRPWaOUU8%2B5VZ5%2Fa9jFTaU9pkK3FAQUhBjMhTTsvAyUlC4IWZzHshBOCggCEwdzEjgLnWaIozse2b%2BczaaODg8%3D
unknown
binary
1.39 Kb
unknown
2088
iexplore.exe
GET
200
142.250.185.163:80
http://ocsp.pki.goog/gts1c3/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTHLnmK3f9hNLO67UdCuLvGwCQHYwQUinR%2Fr4XN7pXNPZzQ4kYU83E1HScCEGupzMnM%2BqGaCjIQPyd58u0%3D
unknown
binary
471 b
unknown
2088
iexplore.exe
GET
200
142.250.185.163:80
http://ocsp.pki.goog/gts1c3/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBTHLnmK3f9hNLO67UdCuLvGwCQHYwQUinR%2Fr4XN7pXNPZzQ4kYU83E1HScCEQCZXmpIP%2Bo%2BHhJmodADfw%2Fc
unknown
binary
472 b
unknown
1776
iexplore.exe
GET
304
23.53.40.35:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?a85e8d0c2f0a71a5
unknown
unknown
2088
iexplore.exe
GET
200
142.250.185.163:80
http://ocsp.pki.goog/gts1c3/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTHLnmK3f9hNLO67UdCuLvGwCQHYwQUinR%2Fr4XN7pXNPZzQ4kYU83E1HScCEGpYRvzN3kAuEMlMWsqSFLc%3D
unknown
binary
471 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
2088
iexplore.exe
18.66.122.13:80
soft32.com
AMAZON-02
US
unknown
4
System
192.168.100.255:138
whitelisted
2088
iexplore.exe
18.66.122.79:80
soft32.com
AMAZON-02
US
unknown
2088
iexplore.exe
18.66.122.79:443
soft32.com
AMAZON-02
US
unknown
2088
iexplore.exe
23.53.40.35:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown
2088
iexplore.exe
108.138.2.173:80
o.ss2.us
AMAZON-02
US
unknown
2088
iexplore.exe
18.66.142.79:80
ocsp.rootg2.amazontrust.com
AMAZON-02
US
unknown
2088
iexplore.exe
142.250.184.226:443
pagead2.googlesyndication.com
GOOGLE
US
whitelisted
2088
iexplore.exe
142.250.186.174:443
www.google-analytics.com
GOOGLE
US
whitelisted

DNS requests

Domain
IP
Reputation
soft32.com
  • 18.66.122.13
  • 18.66.122.88
  • 18.66.122.54
  • 18.66.122.79
shared
www.soft32.com
  • 18.66.122.79
  • 18.66.122.13
  • 18.66.122.88
  • 18.66.122.54
shared
ctldl.windowsupdate.com
  • 23.53.40.35
  • 23.53.40.49
whitelisted
o.ss2.us
  • 108.138.2.173
  • 108.138.2.195
  • 108.138.2.107
  • 108.138.2.10
whitelisted
ocsp.rootg2.amazontrust.com
  • 18.66.142.79
whitelisted
ocsp.rootca1.amazontrust.com
  • 18.66.142.79
shared
d3gx3uz4yj2hnq.cloudfront.net
  • 99.86.1.53
  • 99.86.1.208
  • 99.86.1.71
  • 99.86.1.27
whitelisted
pagead2.googlesyndication.com
  • 142.250.184.226
whitelisted
d3fnqfpn2r2a3x.cloudfront.net
  • 18.245.62.229
  • 18.245.62.149
  • 18.245.62.172
  • 18.245.62.32
whitelisted
ocsp.pki.goog
  • 142.250.185.163
whitelisted

Threats

Found threats are available for the paid subscriptions
10 ETPRO signatures available at the full report
Process
Message
Dell XPS One 2710 Intel Wireless Display Application_3.0.12.0.exe
Error: File not found - sciterwrapper:console.tis
Dell XPS One 2710 Intel Wireless Display Application_3.0.12.0.exe
at sciter:init-script.tis
Dell XPS One 2710 Intel Wireless Display Application_3.0.12.0.exe
file:resources/tis/TranslateOfferTemplate.tis(82) : warning :'async' does not contain any 'await'
Dell XPS One 2710 Intel Wireless Display Application_3.0.12.0.exe
Dell XPS One 2710 Intel Wireless Display Application_3.0.12.0.exe
Dell XPS One 2710 Intel Wireless Display Application_3.0.12.0.exe
Dell XPS One 2710 Intel Wireless Display Application_3.0.12.0.exe
Dell XPS One 2710 Intel Wireless Display Application_3.0.12.0.exe
Error: File not found - sciterwrapper:console.tis
Dell XPS One 2710 Intel Wireless Display Application_3.0.12.0.exe
at sciter:init-script.tis
Dell XPS One 2710 Intel Wireless Display Application_3.0.12.0.exe
file:resources/tis/TranslateOfferTemplate.tis(82) : warning :'async' does not contain any 'await'