analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
URL:

https://cdn.discordapp.com/attachments/915358573230448741/935331898278952960/Installer_GenNitro.exe

Full analysis: https://app.any.run/tasks/3d95c01b-f5d9-43dd-a2a3-136d5e60110e
Verdict: Malicious activity
Analysis date: January 25, 2022, 01:58:32
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

A02F5C396777B40937FF9A30888CAE27

SHA1:

65A5BF32030569841BF26AC64C44B2B117316051

SHA256:

068D94C067C0B3ED60262DF6680632BFC2AC6D68A13AA41057079339EB1E40F7

SSDEEP:

3:N8cCWdy6//lc2SREUKc+MQmKqWTXJUn:2cry6Xlc2SWUKlRmKFXJUn

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Installer_GenNitro.exe (PID: 2640)
      • Installer_GenNitro.exe (PID: 468)
      • Installer_GenNitro.exe (PID: 1516)
      • Installer_GenNitro.exe (PID: 3108)
      • Installer_GenNitro.exe (PID: 1340)
      • Installer_GenNitro.exe (PID: 2464)
      • Installer_GenNitro.exe (PID: 1728)
      • Installer_GenNitro.exe (PID: 2600)
      • Installer_GenNitro.exe (PID: 2576)
      • Installer_GenNitro.exe (PID: 2056)
      • Installer_GenNitro.exe (PID: 3388)
      • Installer_GenNitro.exe (PID: 3452)
      • Installer_GenNitro.exe (PID: 4052)
      • Installer_GenNitro.exe (PID: 3016)
      • Installer_GenNitro.exe (PID: 924)
      • Installer_GenNitro.exe (PID: 2752)
      • Installer_GenNitro.exe (PID: 2176)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • iexplore.exe (PID: 3792)
      • iexplore.exe (PID: 1044)
    • Reads Microsoft Outlook installation path

      • iexplore.exe (PID: 3792)
    • Checks supported languages

      • Installer_GenNitro.exe (PID: 468)
      • Installer_GenNitro.exe (PID: 3108)
      • cmd.exe (PID: 2312)
      • cmd.exe (PID: 3840)
      • Installer_GenNitro.exe (PID: 1340)
      • Installer_GenNitro.exe (PID: 2600)
      • cmd.exe (PID: 2544)
      • cmd.exe (PID: 560)
      • cmd.exe (PID: 2908)
      • Installer_GenNitro.exe (PID: 2056)
      • Installer_GenNitro.exe (PID: 3388)
      • cmd.exe (PID: 2712)
      • Installer_GenNitro.exe (PID: 3016)
      • cmd.exe (PID: 2900)
      • Installer_GenNitro.exe (PID: 2752)
      • cmd.exe (PID: 2056)
      • Installer_GenNitro.exe (PID: 924)
      • cmd.exe (PID: 840)
    • Starts CMD.EXE for commands execution

      • Installer_GenNitro.exe (PID: 468)
      • Installer_GenNitro.exe (PID: 3108)
      • Installer_GenNitro.exe (PID: 2600)
      • Installer_GenNitro.exe (PID: 1340)
      • Installer_GenNitro.exe (PID: 3388)
      • Installer_GenNitro.exe (PID: 2056)
      • Installer_GenNitro.exe (PID: 3016)
      • Installer_GenNitro.exe (PID: 924)
      • Installer_GenNitro.exe (PID: 2752)
  • INFO

    • Checks supported languages

      • iexplore.exe (PID: 1044)
      • iexplore.exe (PID: 3792)
      • explorer.exe (PID: 2780)
    • Reads the computer name

      • iexplore.exe (PID: 1044)
      • iexplore.exe (PID: 3792)
      • explorer.exe (PID: 2780)
    • Application launched itself

      • iexplore.exe (PID: 1044)
    • Changes internet zones settings

      • iexplore.exe (PID: 1044)
    • Reads settings of System Certificates

      • iexplore.exe (PID: 3792)
      • iexplore.exe (PID: 1044)
    • Checks Windows Trust Settings

      • iexplore.exe (PID: 3792)
      • iexplore.exe (PID: 1044)
    • Modifies the phishing filter of IE

      • iexplore.exe (PID: 1044)
    • Reads the date of Windows installation

      • iexplore.exe (PID: 1044)
    • Creates files in the user directory

      • iexplore.exe (PID: 1044)
    • Adds / modifies Windows certificates

      • iexplore.exe (PID: 1044)
    • Manual execution by user

      • Installer_GenNitro.exe (PID: 3016)
      • Installer_GenNitro.exe (PID: 4052)
      • explorer.exe (PID: 2780)
      • Installer_GenNitro.exe (PID: 2752)
    • Changes settings of System certificates

      • iexplore.exe (PID: 1044)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
96
Monitored processes
29
Malicious processes
6
Suspicious processes
0

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe installer_gennitro.exe no specs installer_gennitro.exe cmd.exe no specs installer_gennitro.exe no specs installer_gennitro.exe cmd.exe no specs installer_gennitro.exe no specs installer_gennitro.exe cmd.exe no specs installer_gennitro.exe no specs installer_gennitro.exe cmd.exe no specs installer_gennitro.exe no specs installer_gennitro.exe cmd.exe no specs installer_gennitro.exe no specs installer_gennitro.exe cmd.exe no specs explorer.exe no specs installer_gennitro.exe no specs installer_gennitro.exe cmd.exe no specs installer_gennitro.exe cmd.exe no specs installer_gennitro.exe no specs installer_gennitro.exe cmd.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1044"C:\Program Files\Internet Explorer\iexplore.exe" "https://cdn.discordapp.com/attachments/915358573230448741/935331898278952960/Installer_GenNitro.exe"C:\Program Files\Internet Explorer\iexplore.exe
Explorer.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
1
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
3792"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:1044 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2640"C:\Users\admin\Downloads\Installer_GenNitro.exe" C:\Users\admin\Downloads\Installer_GenNitro.exeiexplore.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\downloads\installer_gennitro.exe
c:\windows\system32\ntdll.dll
468"C:\Users\admin\Downloads\Installer_GenNitro.exe" C:\Users\admin\Downloads\Installer_GenNitro.exe
iexplore.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\downloads\installer_gennitro.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
2312"C:\Windows\system32\cmd" /c "C:\Users\admin\AppData\Local\Temp\5ADF.tmp\5AE0.tmp\5AE1.bat C:\Users\admin\Downloads\Installer_GenNitro.exe"C:\Windows\system32\cmd.exeInstaller_GenNitro.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1516"C:\Users\admin\Downloads\Installer_GenNitro.exe" C:\Users\admin\Downloads\Installer_GenNitro.exeiexplore.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\downloads\installer_gennitro.exe
c:\windows\system32\ntdll.dll
3108"C:\Users\admin\Downloads\Installer_GenNitro.exe" C:\Users\admin\Downloads\Installer_GenNitro.exe
iexplore.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\windows\system32\ntdll.dll
c:\users\admin\downloads\installer_gennitro.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
3840"C:\Windows\system32\cmd" /c "C:\Users\admin\AppData\Local\Temp\7A2E.tmp\7A2F.tmp\7A30.bat C:\Users\admin\Downloads\Installer_GenNitro.exe"C:\Windows\system32\cmd.exeInstaller_GenNitro.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2464"C:\Users\admin\Downloads\Installer_GenNitro.exe" C:\Users\admin\Downloads\Installer_GenNitro.exeiexplore.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\downloads\installer_gennitro.exe
c:\windows\system32\ntdll.dll
1340"C:\Users\admin\Downloads\Installer_GenNitro.exe" C:\Users\admin\Downloads\Installer_GenNitro.exe
iexplore.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\downloads\installer_gennitro.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\gdi32.dll
Total events
13 838
Read events
13 720
Write events
0
Delete events
0

Modification events

No data
Executable files
3
Suspicious files
9
Text files
24
Unknown types
5

Dropped files

PID
Process
Filename
Type
1044iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\{4D986145-7D82-11EC-A45D-12A9866C77DE}.datbinary
MD5:606EF00ABB50CC1F5763163DB00B7FB7
SHA256:5696D4CF5DFEAA93F8E5FF6F5DEF9C63D82F53195B85910A65137F6B506C2F75
3792iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:001DC1E25B87A8E14B6391CEC334244A
SHA256:80BEB515DE5B1F9DAFD3DD7B5EBBD9FD2A7C6889173805695270AAE50423C559
3792iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\Installer_GenNitro[1].exeexecutable
MD5:6F3F0E51AAB17F809A598D167364E65C
SHA256:B30E56D6AB063D543E104189234EF17E5CFB1DF3F67B4BDFF42777F4582276D4
1044iexplore.exeC:\Users\admin\AppData\Local\Temp\~DF8BD9465AFD4C0394.TMPgmc
MD5:AC230717F68C224BB0584FF95A4FD672
SHA256:8C1BE7F503A640973E001F32F82E440E5D9997046399B905C50C959AA783FA2F
3792iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\6BADA8974A10C4BD62CC921D13E43B18_28DEA62A0AE77228DD387E155AD0BA27der
MD5:8CD7E90C9F52DCC22A188DB1D82D4356
SHA256:F3F9DC32585CEBC0A478458DF911980CF546F8DAB032649EC676B7D243A4F46F
3792iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\6BADA8974A10C4BD62CC921D13E43B18_28DEA62A0AE77228DD387E155AD0BA27binary
MD5:DB7B2C761496DC5FA4E12891AF5960CB
SHA256:927E12574ED2F65C6310F1F1AF029BCE88A10108F1D27A6737AF409A9B368931
1044iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\7423F88C7F265F0DEFC08EA88C3BDE45_AA1E8580D4EBC816148CE81268683776binary
MD5:C95BE199B3223442F2EB7236E0BC368A
SHA256:0C477840A568CD43CCBE823B330B0955E71E3368D4C1B46B1B1EAAFD37F53B01
1044iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\7423F88C7F265F0DEFC08EA88C3BDE45_AA1E8580D4EBC816148CE81268683776der
MD5:111DCDB55A88510DB3C1E141A0EA1538
SHA256:022A2CD07C65A61F3419427C0D278028CC8FD3C40D593279C2035D881013973B
1044iexplore.exeC:\Users\admin\Downloads\Installer_GenNitro.exeexecutable
MD5:D0A91DA24204B537BBBA7219DDAD012F
SHA256:7264929871B952C0EB00F973480744F8974CF56BE3F01A599BCD502001A71944
3792iexplore.exeC:\Users\admin\Downloads\Installer_GenNitro.exe.kfgvmvn.partialexecutable
MD5:D0A91DA24204B537BBBA7219DDAD012F
SHA256:7264929871B952C0EB00F973480744F8974CF56BE3F01A599BCD502001A71944
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
20
DNS requests
16
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1044
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEA8Ull8gIGmZT9XHrHiJQeI%3D
US
der
1.47 Kb
whitelisted
1044
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
US
der
471 b
whitelisted
3792
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEAo3h2ReX7SMIk79G%2B0UDDw%3D
US
der
1.47 Kb
whitelisted
1044
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEA177el9ggmWelJjG4vdGL0%3D
US
der
471 b
whitelisted
3792
iexplore.exe
GET
200
8.248.1.254:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?edd9ce1cc687364b
US
compressed
4.70 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1044
iexplore.exe
93.184.220.29:80
ocsp.digicert.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
3792
iexplore.exe
93.184.220.29:80
ocsp.digicert.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
3792
iexplore.exe
162.159.135.233:443
cdn.discordapp.com
Cloudflare Inc
shared
1044
iexplore.exe
152.199.19.161:443
iecvlist.microsoft.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
3792
iexplore.exe
162.159.133.233:443
cdn.discordapp.com
Cloudflare Inc
shared
3792
iexplore.exe
8.248.1.254:80
ctldl.windowsupdate.com
Level 3 Communications, Inc.
US
suspicious
1044
iexplore.exe
204.79.197.203:443
www.msn.com
Microsoft Corporation
US
whitelisted
1044
iexplore.exe
204.79.197.200:443
www.bing.com
Microsoft Corporation
US
whitelisted
1044
iexplore.exe
104.111.242.51:443
go.microsoft.com
Akamai International B.V.
NL
unknown
1044
iexplore.exe
40.83.186.94:443
query.prod.cms.msn.com
Microsoft Corporation
US
whitelisted

DNS requests

Domain
IP
Reputation
cdn.discordapp.com
  • 162.159.133.233
  • 162.159.135.233
  • 162.159.129.233
  • 162.159.130.233
  • 162.159.134.233
shared
ctldl.windowsupdate.com
  • 8.248.1.254
  • 8.238.20.126
  • 8.247.211.254
  • 8.248.7.254
  • 8.238.24.126
  • 67.26.105.254
  • 8.253.208.121
  • 8.238.23.254
  • 8.238.20.254
whitelisted
ocsp.digicert.com
  • 93.184.220.29
whitelisted
api.bing.com
  • 13.107.5.80
whitelisted
www.bing.com
  • 204.79.197.200
  • 13.107.21.200
whitelisted
iecvlist.microsoft.com
  • 152.199.19.161
whitelisted
r20swj13mr.microsoft.com
  • 152.199.19.161
whitelisted
ieonline.microsoft.com
  • 204.79.197.200
whitelisted
go.microsoft.com
  • 104.111.242.51
whitelisted
www.msn.com
  • 204.79.197.203
whitelisted

Threats

No threats detected
No debug info