File name:

sae.exe

Full analysis: https://app.any.run/tasks/dd705682-18e6-4f31-bd90-daedf15888a0
Verdict: Malicious activity
Analysis date: April 07, 2024, 01:38:48
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (console) Intel 80386, for MS Windows
MD5:

07307F0B92BC10764A345A87D6027F71

SHA1:

D30C96FF5F7CAA14B6E2882A9FD7C1811F5C4DE2

SHA256:

E8132224C4D6328F5BF951C5E118837CB6A44577D8DB1CB765DE7FCE54AD1BC3

SSDEEP:

6144:SuNiNxEURcnLmFlAhFwDNOeNcyKGObiJndfGDHRjxN:NNYxEURSmF2rw8eNc7G4iRwTN

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • sae.exe (PID: 4008)
    • Actions looks like stealing of personal data

      • sae.exe (PID: 4008)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • sae.exe (PID: 4008)
    • Starts a Microsoft application from unusual location

      • aspnet_regiis.exe (PID: 3488)
      • aspnet_state.exe (PID: 2756)
      • aspnet_regiis.exe (PID: 2772)
      • ilasm.exe (PID: 1636)
      • aspnet_state.exe (PID: 1368)
      • diagtrackrunner.exe (PID: 2408)
      • diagtrackrunner.exe (PID: 1308)
      • diagtrackrunner.exe (PID: 3752)
      • aspnet_wp.exe (PID: 3572)
      • ilasm.exe (PID: 3784)
      • TsWpfWrp.exe (PID: 3836)
      • pwahelper.exe (PID: 3708)
      • identity_helper.exe (PID: 2820)
      • csc.exe (PID: 4028)
      • diagtrackrunner.exe (PID: 1196)
      • Setup.exe (PID: 4040)
      • ilasm.exe (PID: 3960)
      • diagtrackrunner.exe (PID: 1976)
      • identity_helper.exe (PID: 1888)
      • diagtrackrunner.exe (PID: 2564)
      • ilasm.exe (PID: 240)
      • csc.exe (PID: 2576)
      • diagtrackrunner.exe (PID: 980)
      • diagtrackrunner.exe (PID: 2888)
      • notification_helper.exe (PID: 1404)
      • TsWpfWrp.exe (PID: 2436)
      • aspnet_wp.exe (PID: 1336)
    • Reads the Internet Settings

      • AdobeCollabSync.exe (PID: 1864)
    • Checks for Java to be installed

      • javaws.exe (PID: 292)
  • INFO

    • Checks supported languages

      • sae.exe (PID: 4008)
      • AcroBroker.exe (PID: 1584)
      • TsWpfWrp.exe (PID: 2436)
      • vlc-cache-gen.exe (PID: 1340)
      • CCleanerReactivator.exe (PID: 3924)
      • updater.exe (PID: 2092)
      • aspnet_state.exe (PID: 2756)
      • vlc.exe (PID: 3372)
      • TsWpfWrp.exe (PID: 3836)
      • CCleanerPerformanceOptimizerService.exe (PID: 3056)
      • ilasm.exe (PID: 1636)
      • acrobroker.exe (PID: 3224)
      • aspnet_regiis.exe (PID: 2772)
      • aspnet_regiis.exe (PID: 3488)
      • aspnet_wp.exe (PID: 1336)
      • AdobeCollabSync.exe (PID: 1864)
      • diagtrackrunner.exe (PID: 1196)
      • CCleanerReactivator.exe (PID: 2892)
      • notepad++.exe (PID: 3560)
      • GUP.exe (PID: 3364)
      • javaws.exe (PID: 292)
      • GUP.exe (PID: 2364)
      • diagtrackrunner.exe (PID: 1308)
      • diagtrackrunner.exe (PID: 3752)
      • ilasm.exe (PID: 3784)
      • aspnet_wp.exe (PID: 3572)
      • diagtrackrunner.exe (PID: 2408)
      • aspnet_state.exe (PID: 1368)
      • ilasm.exe (PID: 240)
      • diagtrackrunner.exe (PID: 2564)
      • diagtrackrunner.exe (PID: 980)
      • diagtrackrunner.exe (PID: 1976)
      • csc.exe (PID: 2576)
      • csc.exe (PID: 4028)
      • ilasm.exe (PID: 3960)
      • diagtrackrunner.exe (PID: 2888)
      • RdrCEF.exe (PID: 448)
      • notification_helper.exe (PID: 1404)
      • AcroBroker.exe (PID: 3904)
    • Creates files or folders in the user directory

      • sae.exe (PID: 4008)
    • Reads the machine GUID from the registry

      • sae.exe (PID: 4008)
      • acrobroker.exe (PID: 3224)
      • notepad++.exe (PID: 3560)
    • Checks proxy server information

      • AdobeCollabSync.exe (PID: 1864)
    • Reads the computer name

      • CCleanerPerformanceOptimizerService.exe (PID: 3056)
      • acrobroker.exe (PID: 3224)
      • AdobeCollabSync.exe (PID: 1864)
    • Create files in a temporary directory

      • sae.exe (PID: 4008)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (64.6)
.dll | Win32 Dynamic Link Library (generic) (15.4)
.exe | Win32 Executable (generic) (10.5)
.exe | Generic Win/DOS Executable (4.6)
.exe | DOS Executable Generic (4.6)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:03:18 13:38:01+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14.36
CodeSize: 211968
InitializedDataSize: 83968
UninitializedDataSize: -
EntryPoint: 0x14067
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows command line
No data.
screenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
108
Monitored processes
47
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start sae.exe acrobroker.exe no specs acrobroker.exe no specs tswpfwrp.exe no specs aspnet_state.exe no specs aspnet_regiis.exe no specs aspnet_wp.exe no specs vlc-cache-gen.exe no specs adobecollabsync.exe no specs aspnet_regiis.exe no specs acrobroker.exe no specs ilasm.exe no specs updater.exe no specs maintenanceservice.exe no specs aspnet_state.exe no specs diagtrackrunner.exe no specs diagtrackrunner.exe no specs diagtrackrunner.exe no specs ccleanerperformanceoptimizerservice.exe no specs aspnet_wp.exe no specs vlc.exe no specs adelrcp.exe no specs notepad++.exe tswpfwrp.exe no specs ccleanerreactivator.exe no specs pwahelper.exe no specs ilasm.exe no specs diagtrackrunner.exe no specs steamservice.exe no specs identity_helper.exe no specs gup.exe no specs csc.exe no specs javaws.exe steamservicetmp.exe no specs setup.exe no specs ccleanerreactivator.exe no specs ilasm.exe no specs gup.exe no specs diagtrackrunner.exe no specs identity_helper.exe no specs ilasm.exe no specs diagtrackrunner.exe no specs diagtrackrunner.exe no specs diagtrackrunner.exe no specs csc.exe no specs rdrcef.exe no specs notification_helper.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
240C:\Users\admin\AppData\Local\Temp\qgwynqp9fo\ilasm.exeC:\Users\admin\AppData\Local\Temp\qgwynqp9fo\ilasm.exesae.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft .NET Framework IL assembler
Exit code:
572662306
Version:
2.0.50727.5483 (Win7SP1GDR.050727-5400)
Modules
Images
c:\users\admin\appdata\local\temp\qgwynqp9fo\ilasm.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mscoree.dll
c:\windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc\msvcr80.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
292C:\Users\admin\AppData\Local\Temp\2pbobc9ase\javaws.exeC:\Users\admin\AppData\Local\Temp\2pbobc9ase\javaws.exe
sae.exe
User:
admin
Company:
Oracle Corporation
Integrity Level:
MEDIUM
Description:
Java(TM) Web Start Launcher
Exit code:
0
Version:
11.271.2.09
Modules
Images
c:\users\admin\appdata\local\temp\2pbobc9ase\javaws.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
448C:\Users\admin\AppData\Local\Temp\kwje3oui_2\RdrCEF.exeC:\Users\admin\AppData\Local\Temp\kwje3oui_2\RdrCEF.exesae.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
MEDIUM
Description:
Adobe RdrCEF
Exit code:
572662306
Version:
20.13.20064.405839
Modules
Images
c:\users\admin\appdata\local\temp\kwje3oui_2\rdrcef.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
980C:\Users\admin\AppData\Local\Temp\bc95ru0hdj\diagtrackrunner.exeC:\Users\admin\AppData\Local\Temp\bc95ru0hdj\diagtrackrunner.exesae.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Windows Diagnostics Tracking Runner
Exit code:
572662306
Version:
10.0.10586.8 (th2_release.151109-1754)
Modules
Images
c:\users\admin\appdata\local\temp\bc95ru0hdj\diagtrackrunner.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
1196C:\Users\admin\AppData\Local\Temp\rpvqea9b_i\diagtrackrunner.exeC:\Users\admin\AppData\Local\Temp\rpvqea9b_i\diagtrackrunner.exesae.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Windows Diagnostics Tracking Runner
Exit code:
572662306
Version:
10.0.10586.8 (th2_release.151109-1754)
Modules
Images
c:\users\admin\appdata\local\temp\rpvqea9b_i\diagtrackrunner.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
1308C:\Users\admin\AppData\Local\Temp\bc95ru0hdj\diagtrackrunner.exeC:\Users\admin\AppData\Local\Temp\bc95ru0hdj\diagtrackrunner.exesae.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Windows Diagnostics Tracking Runner
Exit code:
572662306
Version:
10.0.10586.8 (th2_release.151109-1754)
Modules
Images
c:\users\admin\appdata\local\temp\bc95ru0hdj\diagtrackrunner.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
1336C:\Users\admin\AppData\Local\Temp\zdf0xom9ac\aspnet_wp.exeC:\Users\admin\AppData\Local\Temp\zdf0xom9ac\aspnet_wp.exesae.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
aspnet_wp.exe
Exit code:
572662306
Version:
2.0.50727.8762 (QFE.050727-8700)
Modules
Images
c:\users\admin\appdata\local\temp\zdf0xom9ac\aspnet_wp.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc\msvcr80.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\users\admin\appdata\local\temp\zdf0xom9ac\webengine.dll
1340C:\Users\admin\AppData\Local\Temp\lt6f6g1vah\vlc-cache-gen.exeC:\Users\admin\AppData\Local\Temp\lt6f6g1vah\vlc-cache-gen.exesae.exe
User:
admin
Company:
VideoLAN
Integrity Level:
MEDIUM
Description:
VLC media player
Exit code:
572662306
Version:
3.0.11
Modules
Images
c:\users\admin\appdata\local\temp\lt6f6g1vah\vlc-cache-gen.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\temp\lt6f6g1vah\libvlc.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1368C:\Users\admin\AppData\Local\Temp\ln4oyhyq_0\aspnet_state.exeC:\Users\admin\AppData\Local\Temp\ln4oyhyq_0\aspnet_state.exesae.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft ASP.NET State Server
Exit code:
572662306
Version:
2.0.50727.5483 (Win7SP1GDR.050727-5400)
Modules
Images
c:\users\admin\appdata\local\temp\ln4oyhyq_0\aspnet_state.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc\msvcr80.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\mswsock.dll
1404C:\Users\admin\AppData\Local\Temp\28tmt24e3_\notification_helper.exeC:\Users\admin\AppData\Local\Temp\28tmt24e3_\notification_helper.exesae.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\users\admin\appdata\local\temp\28tmt24e3_\notification_helper.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\powershell\7\api-ms-win-core-winrt-error-l1-1-0.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
Total events
1 458
Read events
1 430
Write events
28
Delete events
0

Modification events

(PID) Process:(4008) sae.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3560) notepad++.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
Executable files
66
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
4008sae.exeC:\Users\admin\AppData\Local\Temp\06dfmek3r2\AcroBroker.exeexecutable
MD5:
SHA256:
4008sae.exeC:\Users\admin\AppData\Local\Temp\bhyd67sb7o\notepad++.exeexecutable
MD5:
SHA256:
4008sae.exeC:\Users\admin\AppData\Local\Temp\06dfmek3r2\sqlite.dllexecutable
MD5:
SHA256:
4008sae.exeC:\Users\admin\AppData\Local\Temp\iqxoq_0eix\diagtrackrunner.exeexecutable
MD5:
SHA256:
4008sae.exeC:\Users\admin\AppData\Local\Temp\iip_wt0l49\CCleanerPerformanceOptimizerService.exeexecutable
MD5:
SHA256:
4008sae.exeC:\Users\admin\AppData\Local\Temp\k_c0f_1uxv\TsWpfWrp.exeexecutable
MD5:
SHA256:
4008sae.exeC:\Users\admin\AppData\Local\Temp\2p7sngu2su\aspnet_state.exeexecutable
MD5:
SHA256:
4008sae.exeC:\Users\admin\AppData\Local\Temp\o3q5iii6ox\aspnet_wp.exeexecutable
MD5:
SHA256:
4008sae.exeC:\Users\admin\AppData\Local\Temp\zdf0xom9ac\aspnet_wp.exeexecutable
MD5:
SHA256:
4008sae.exeC:\Users\admin\AppData\Local\Temp\etx2srwddw\GUP.exeexecutable
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
3
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
unknown

DNS requests

No data

Threats

No threats detected
Process
Message
notepad++.exe
VerifyLibrary: certificate revocation checking is disabled
notepad++.exe
VerifyLibrary: C:\Users\admin\AppData\Local\Temp\bhyd67sb7o\SciLexer.dll
notepad++.exe
ED255D9151912E40DF048A56288E969A8D0DAFA3