| File name: | NordVPN Cracked.exe |
| Full analysis: | https://app.any.run/tasks/d118c68d-09da-4ebf-85e7-fdeb8507085d |
| Verdict: | Malicious activity |
| Analysis date: | October 31, 2018, 12:50:14 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 2EC1AEA2DB8183BF39257B4C0AC2D22E |
| SHA1: | 9A139BE4C3AD8AF6CCD9ED9AA113AAFF3B3A90DD |
| SHA256: | 091B14D5ED6BCAE150026410ADDA8BE0E29872CBCE4C72944C54500F0DB2B9FC |
| SSDEEP: | 12288:dh1Lk70TnvjcocpAQ31EjjqjKjjDjMjRjhj+joj+jojnj6jkajjXjWHibUyic3pj:Zk70TrcKQ31EjjqjKjjDjMjRjhj+joj0 |
| .exe | | | Win32 Executable MS Visual C++ (generic) (42.2) |
|---|---|---|
| .exe | | | Win64 Executable (generic) (37.3) |
| .dll | | | Win32 Dynamic Link Library (generic) (8.8) |
| .exe | | | Win32 Executable (generic) (6) |
| .exe | | | Generic Win/DOS Executable (2.7) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2012:07:14 00:47:16+02:00 |
| PEType: | PE32 |
| LinkerVersion: | 9 |
| CodeSize: | 104448 |
| InitializedDataSize: | 551424 |
| UninitializedDataSize: | - |
| EntryPoint: | 0xcd2f |
| OSVersion: | 5 |
| ImageVersion: | - |
| SubsystemVersion: | 5 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 6.5.0.0 |
| ProductVersionNumber: | 6.5.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| Comments: | NordVPN Crack |
| FileDescription: | NordVPN |
| FileVersion: | 6.5.0.0 |
| InternalName: | .exe |
| LegalCopyright: | Copyright 2018 |
| OriginalFileName: | .exe |
| ProductVersion: | 6.5.0.0 |
| AssemblyVersion: | 6.5.0.0 |
| Architecture: | IMAGE_FILE_MACHINE_I386 |
|---|---|
| Subsystem: | IMAGE_SUBSYSTEM_WINDOWS_GUI |
| Compilation Date: | 13-Jul-2012 22:47:16 |
| Debug artifacts: | |
| Comments: | NordVPN Crack |
| FileDescription: | NordVPN |
| FileVersion: | 6.5.0.0 |
| InternalName: | .exe |
| LegalCopyright: | Copyright 2018 |
| OriginalFilename: | .exe |
| ProductVersion: | 6.5.0.0 |
| Assembly Version: | 6.5.0.0 |
| Magic number: | MZ |
|---|---|
| Bytes on last page of file: | 0x0090 |
| Pages in file: | 0x0003 |
| Relocations: | 0x0000 |
| Size of header: | 0x0004 |
| Min extra paragraphs: | 0x0000 |
| Max extra paragraphs: | 0xFFFF |
| Initial SS value: | 0x0000 |
| Initial SP value: | 0x00B8 |
| Checksum: | 0x0000 |
| Initial IP value: | 0x0000 |
| Initial CS value: | 0x0000 |
| Overlay number: | 0x0000 |
| OEM identifier: | 0x0000 |
| OEM information: | 0x0000 |
| Address of NE header: | 0x000000E0 |
| Signature: | PE |
|---|---|
| Machine: | IMAGE_FILE_MACHINE_I386 |
| Number of sections: | 4 |
| Time date stamp: | 13-Jul-2012 22:47:16 |
| Pointer to Symbol Table: | 0x00000000 |
| Number of symbols: | 0 |
| Size of Optional Header: | 0x00E0 |
| Characteristics: |
|
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
|---|---|---|---|---|---|
.text | 0x00001000 | 0x00019718 | 0x00019800 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.74857 |
.rdata | 0x0001B000 | 0x00006DB4 | 0x00006E00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 6.44296 |
.data | 0x00022000 | 0x000030C0 | 0x00001600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 3.26259 |
.rsrc | 0x00026000 | 0x0007E44C | 0x0007E600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.60741 |
Title | Entropy | Size | Codepage | Language | Type |
|---|---|---|---|---|---|
1 | 5.00112 | 490 | Latin 1 / Western European | UNKNOWN | RT_MANIFEST |
2 | 4.81392 | 4264 | Latin 1 / Western European | UNKNOWN | RT_ICON |
3 | 4.87955 | 9640 | Latin 1 / Western European | UNKNOWN | RT_ICON |
4 | 4.47541 | 16936 | Latin 1 / Western European | UNKNOWN | RT_ICON |
5 | 4.24612 | 67624 | Latin 1 / Western European | UNKNOWN | RT_ICON |
6 | 4.1246 | 270376 | Latin 1 / Western European | UNKNOWN | RT_ICON |
7 | 4.81392 | 4264 | Latin 1 / Western European | UNKNOWN | RT_ICON |
8 | 4.87955 | 9640 | Latin 1 / Western European | UNKNOWN | RT_ICON |
32512 | 2.55805 | 34 | Latin 1 / Western European | UNKNOWN | RT_GROUP_ICON |
__ | 7.99867 | 131202 | Latin 1 / Western European | UNKNOWN | RT_RCDATA |
KERNEL32.dll |
OLEAUT32.dll |
ole32.dll |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 116 | "C:\Users\admin\AppData\Local\Temp\NordVPN.exe" | C:\Users\admin\AppData\Local\Temp\NordVPN.exe | NordVPN Cracked.exe | ||||||||||||
User: admin Company: NordVPN Integrity Level: HIGH Description: NordVPN Installer Exit code: 0 Version: 6.18.5 Modules
| |||||||||||||||
| 476 | C:\Windows\system32\MsiExec.exe -Embedding 43FCAAA418D0A5C9D946D086293C3206 C | C:\Windows\system32\MsiExec.exe | — | msiexec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1000 | "C:\Program Files\NordVPN network TAP\bin\i386\tapinstall.exe" hwids tapnordvpn | C:\Program Files\NordVPN network TAP\bin\i386\tapinstall.exe | — | rundll32.exe | |||||||||||
User: admin Company: Windows (R) Win 7 DDK provider Integrity Level: HIGH Description: Windows Setup API Exit code: 0 Version: 6.1.7600.16385 built by: WinDDK Modules
| |||||||||||||||
| 1192 | "C:\Users\admin\AppData\Roaming\NordVPN\NordVPN\prerequisites\NordVPNTapSetup.exe" | C:\Users\admin\AppData\Roaming\NordVPN\NordVPN\prerequisites\NordVPNTapSetup.exe | NordVPN.exe | ||||||||||||
User: admin Company: NordVPN Integrity Level: HIGH Description: NordVPN network TAP Installer Exit code: 0 Version: 1.0.1 Modules
| |||||||||||||||
| 1228 | wmic qfe where "HotFixID = 'KB3033929'" | C:\Windows\System32\Wbem\WMIC.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: WMI Commandline Utility Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1476 | C:\Windows\system32\vssvc.exe | C:\Windows\system32\vssvc.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft® Volume Shadow Copy Service Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1576 | DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{39bdc750-c9f0-0ccc-8c3d-336cdfaef238}\oemvista.inf" "0" "6166dbbc3" "000005C8" "WinSta0\Default" "000005BC" "208" "c:\program files\nordvpn network tap\default\i386" | C:\Windows\system32\DrvInst.exe | svchost.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Driver Installation Module Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2112 | "C:\Users\admin\AppData\Local\Temp\NordVPN Setup.exe" | C:\Users\admin\AppData\Local\Temp\NordVPN Setup.exe | NordVPN Cracked.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 3735929054 Modules
| |||||||||||||||
| 2180 | "C:\Users\admin\AppData\Local\Temp\NordVPN.exe" | C:\Users\admin\AppData\Local\Temp\NordVPN.exe | — | NordVPN Cracked.exe | |||||||||||
User: admin Company: NordVPN Integrity Level: MEDIUM Description: NordVPN Installer Exit code: 3221226540 Version: 6.18.5 Modules
| |||||||||||||||
| 2268 | rundll32.exe C:\Windows\system32\pnpui.dll,InstallSecurityPromptRunDllW 10 Global\{2b5b4184-7c58-6f5e-c4eb-9b1927ac7412} Global\{31fe8d6d-fe20-2936-448e-ef47117c9557} C:\Windows\System32\DriverStore\Temp\{3a8d452d-0e12-7c1a-e312-113143a70a7b}\oemvista.inf C:\Windows\System32\DriverStore\Temp\{3a8d452d-0e12-7c1a-e312-113143a70a7b}\tapnordvpn.cat | C:\Windows\system32\rundll32.exe | — | DrvInst.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows host process (Rundll32) Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (2288) NordVPN Cracked.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\NordVPN Cracked_RASAPI32 |
| Operation: | write | Name: | EnableFileTracing |
Value: 0 | |||
| (PID) Process: | (2288) NordVPN Cracked.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\NordVPN Cracked_RASAPI32 |
| Operation: | write | Name: | EnableConsoleTracing |
Value: 0 | |||
| (PID) Process: | (2288) NordVPN Cracked.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\NordVPN Cracked_RASAPI32 |
| Operation: | write | Name: | FileTracingMask |
Value: 4294901760 | |||
| (PID) Process: | (2288) NordVPN Cracked.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\NordVPN Cracked_RASAPI32 |
| Operation: | write | Name: | ConsoleTracingMask |
Value: 4294901760 | |||
| (PID) Process: | (2288) NordVPN Cracked.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\NordVPN Cracked_RASAPI32 |
| Operation: | write | Name: | MaxFileSize |
Value: 1048576 | |||
| (PID) Process: | (2288) NordVPN Cracked.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\NordVPN Cracked_RASAPI32 |
| Operation: | write | Name: | FileDirectory |
Value: %windir%\tracing | |||
| (PID) Process: | (2288) NordVPN Cracked.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\NordVPN Cracked_RASMANCS |
| Operation: | write | Name: | EnableFileTracing |
Value: 0 | |||
| (PID) Process: | (2288) NordVPN Cracked.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\NordVPN Cracked_RASMANCS |
| Operation: | write | Name: | EnableConsoleTracing |
Value: 0 | |||
| (PID) Process: | (2288) NordVPN Cracked.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\NordVPN Cracked_RASMANCS |
| Operation: | write | Name: | FileTracingMask |
Value: 4294901760 | |||
| (PID) Process: | (2288) NordVPN Cracked.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\NordVPN Cracked_RASMANCS |
| Operation: | write | Name: | ConsoleTracingMask |
Value: 4294901760 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 116 | NordVPN.exe | C:\Users\admin\AppData\Roaming\NordVPN\NordVPN 6.18.5\install\holder0.aiph | — | |
MD5:— | SHA256:— | |||
| 3220 | MsiExec.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@google[1].txt | — | |
MD5:— | SHA256:— | |||
| 3220 | MsiExec.exe | C:\Users\admin\AppData\Local\Temp\tinAAC7.tmp.part | — | |
MD5:— | SHA256:— | |||
| 3220 | MsiExec.exe | C:\Users\admin\AppData\Local\Temp\tinAAC7.tmp | — | |
MD5:— | SHA256:— | |||
| 116 | NordVPN.exe | C:\Users\admin\AppData\Roaming\NordVPN\NordVPN 6.18.5\install\040A8E6\NordVPN Setup.msi | executable | |
MD5:— | SHA256:— | |||
| 3220 | MsiExec.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@google[2].txt | text | |
MD5:— | SHA256:— | |||
| 2288 | NordVPN Cracked.exe | C:\Users\admin\AppData\Local\Temp\NordVPN Setup.exe | executable | |
MD5:— | SHA256:— | |||
| 2288 | NordVPN Cracked.exe | C:\Users\admin\AppData\Local\Temp\NordVPN.exe | executable | |
MD5:— | SHA256:— | |||
| 116 | NordVPN.exe | C:\Users\admin\AppData\Local\Temp\MSIA8C5.tmp | executable | |
MD5:AAAB8D3F7E9E8F143A17A0D15A1D1715 | SHA256:FD3D6C50C3524063F7C28F815838E0FB06FD4EBFF094E7B88902334ABD463889 | |||
| 116 | NordVPN.exe | C:\Users\admin\AppData\Local\Temp\MSIA953.tmp | executable | |
MD5:DF4115323D835EE32473BAAB7EF00237 | SHA256:442D30FEBF08C0214BAD64111B9B6CC4D03BFC0EE7E4A84542EB5AEDA7982964 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3220 | MsiExec.exe | GET | 200 | 216.58.205.68:80 | http://www.google.com/ | US | html | 12.5 Kb | malicious |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2288 | NordVPN Cracked.exe | 88.99.66.31:443 | 2no.co | Hetzner Online GmbH | DE | malicious |
2288 | NordVPN Cracked.exe | 159.65.182.87:443 | idontknow.moe | — | US | suspicious |
2288 | NordVPN Cracked.exe | 104.18.111.14:443 | downloads.nordcdn.com | Cloudflare Inc | US | shared |
3220 | MsiExec.exe | 216.58.205.68:80 | www.google.com | Google Inc. | US | whitelisted |
116 | NordVPN.exe | 23.54.115.197:443 | download.microsoft.com | Akamai International B.V. | NL | whitelisted |
Domain | IP | Reputation |
|---|---|---|
2no.co |
| whitelisted |
idontknow.moe |
| unknown |
downloads.nordcdn.com |
| unknown |
www.google.com |
| malicious |
download.microsoft.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
1056 | svchost.exe | Potentially Bad Traffic | SUSPICIOUS [PTsecurity] DNS bad file hosting service idontknow.moe |