download:

okta.swa.ie-5.35.0.exe

Full analysis: https://app.any.run/tasks/93e81fe9-5664-445d-8406-34530bdda2c7
Verdict: Malicious activity
Analysis date: December 25, 2019, 02:28:17
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

67394CE49E6238BB678094E571F75A01

SHA1:

8070AE5435F0024DA9592F4359E893AB07DC9979

SHA256:

109C362D4EE3571B3871B8B49620AC707E700FBFB51EF824801C22C70A25DE99

SSDEEP:

49152:Wcc8yUuQbSwIUTJPPN7H0oy4TO/eyOx5dTQRYvQkhrHBjlpNtPCISffl:wuumjIcJP9HE4ZfQS4UljTof

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • okta.swa.ie-5.35.0.exe (PID: 3820)
      • regsvr32.exe (PID: 3956)
      • regsvr32.exe (PID: 1536)
      • IEXPLORE.EXE (PID: 2336)
      • IEXPLORE.EXE (PID: 1524)
      • iexplore.exe (PID: 1072)
      • svchost.exe (PID: 864)
    • Application was dropped or rewritten from another process

      • regsvr32.exe (PID: 1536)
      • regsvr32.exe (PID: 3956)
  • SUSPICIOUS

    • Creates COM task schedule object

      • regsvr32.exe (PID: 1536)
      • regsvr32.exe (PID: 3956)
    • Creates files in the program directory

      • okta.swa.ie-5.35.0.exe (PID: 3820)
    • Starts Internet Explorer

      • okta.swa.ie-5.35.0.exe (PID: 3820)
    • Executable content was dropped or overwritten

      • okta.swa.ie-5.35.0.exe (PID: 3820)
    • Uses TASKKILL.EXE to kill process

      • okta.swa.ie-5.35.0.exe (PID: 3820)
    • Creates a software uninstall entry

      • okta.swa.ie-5.35.0.exe (PID: 3820)
  • INFO

    • Changes internet zones settings

      • IEXPLORE.EXE (PID: 1524)
      • iexplore.exe (PID: 2120)
    • Creates files in the user directory

      • IEXPLORE.EXE (PID: 2336)
      • IEXPLORE.EXE (PID: 1524)
    • Reads internet explorer settings

      • IEXPLORE.EXE (PID: 2336)
      • iexplore.exe (PID: 1072)
    • Dropped object may contain Bitcoin addresses

      • IEXPLORE.EXE (PID: 2336)
      • okta.swa.ie-5.35.0.exe (PID: 3820)
    • Reads Internet Cache Settings

      • iexplore.exe (PID: 1072)
    • Manual execution by user

      • iexplore.exe (PID: 2120)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2016:05:11 16:58:52+02:00
PEType: PE32
LinkerVersion: 8
CodeSize: 8192
InitializedDataSize: 2738176
UninitializedDataSize: -
EntryPoint: 0x1592
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 2019.12.3.2128
ProductVersionNumber: 5.35.0.0
FileFlagsMask: 0x003f
FileFlags: Special build
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
ProductName: Okta IE plugin
ProductVersion: 5.35.0
CompanyName: Okta
LegalCopyright: Okta (c) 2019. All rights reserved.
Email: pluginsupport@okta.com
WebSite: http://www.okta.com
FileDescription: Installer for Okta IE plugin
FileVersion: 2019.12.3.2128
OriginalFileName: Okta Secure Web Authentication Plugin-Setup.exe
InternalName: TSULoader
Comments: WinNT (x86) Unicode Lib Rel
ProductCode: {951D73C6-B2B4-4319-A4E0-0E393B3D20F3}
PackageCode: {9C690506-28EA-485E-1228-3D8AC278264A}
Arguments: -
SpecialBuild: -
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
48
Monitored processes
10
Malicious processes
5
Suspicious processes
1

Behavior graph

Click at the process to see the details
drop and start drop and start start okta.swa.ie-5.35.0.exe taskkill.exe no specs regsvr32.exe no specs regsvr32.exe no specs iexplore.exe iexplore.exe svchost.exe iexplore.exe no specs iexplore.exe no specs okta.swa.ie-5.35.0.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
864C:\Windows\system32\svchost.exe -k netsvcsC:\Windows\System32\svchost.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Host Process for Windows Services
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
940"C:\Users\admin\AppData\Local\Temp\okta.swa.ie-5.35.0.exe" C:\Users\admin\AppData\Local\Temp\okta.swa.ie-5.35.0.exeexplorer.exe
User:
admin
Company:
Okta
Integrity Level:
MEDIUM
Description:
Installer for Okta IE plugin
Exit code:
3221226540
Version:
2019.12.3.2128
Modules
Images
c:\users\admin\appdata\local\temp\okta.swa.ie-5.35.0.exe
c:\systemroot\system32\ntdll.dll
1072"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2120 CREDAT:71937C:\Program Files\Internet Explorer\iexplore.exeiexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1524"C:\Program Files\Internet Explorer\IEXPLORE.EXE" "https://system.okta.com/plugin/verification/ie"C:\Program Files\Internet Explorer\IEXPLORE.EXE
okta.swa.ie-5.35.0.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Internet Explorer
Exit code:
1
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1536"C:\ProgramData\InstallMate\{951D73C6-B2B4-4319-A4E0-0E393B3D20F3}\x86\regsvr32.exe" "C:\Program Files\Okta IE plugin\x86\toolbar\OktaIEBand.dll" /i:`` /rC:\ProgramData\InstallMate\{951D73C6-B2B4-4319-A4E0-0E393B3D20F3}\x86\regsvr32.exeokta.swa.ie-5.35.0.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Out-of-process DLL registration helper
Exit code:
0
Version:
2016.05.11.1557U
Modules
Images
c:\programdata\installmate\{951d73c6-b2b4-4319-a4e0-0e393b3d20f3}\x86\regsvr32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
1880"C:\Windows\system32\taskkill.exe" /im OktaIeHelper.exe /fC:\Windows\system32\taskkill.exeokta.swa.ie-5.35.0.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Terminates Processes
Exit code:
128
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskkill.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\gdi32.dll
2120"C:\Program Files\Internet Explorer\iexplore.exe" C:\Program Files\Internet Explorer\iexplore.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
0
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2336"C:\Program Files\Internet Explorer\IEXPLORE.EXE" SCODEF:1524 CREDAT:79873C:\Program Files\Internet Explorer\IEXPLORE.EXE
IEXPLORE.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Internet Explorer
Exit code:
0
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3820"C:\Users\admin\AppData\Local\Temp\okta.swa.ie-5.35.0.exe" C:\Users\admin\AppData\Local\Temp\okta.swa.ie-5.35.0.exe
explorer.exe
User:
admin
Company:
Okta
Integrity Level:
HIGH
Description:
Installer for Okta IE plugin
Exit code:
0
Version:
2019.12.3.2128
Modules
Images
c:\users\admin\appdata\local\temp\okta.swa.ie-5.35.0.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imm32.dll
3956"C:\ProgramData\InstallMate\{951D73C6-B2B4-4319-A4E0-0E393B3D20F3}\x86\regsvr32.exe" "C:\Program Files\Okta IE plugin\x86\OktaBHO.dll" /i:`` /rC:\ProgramData\InstallMate\{951D73C6-B2B4-4319-A4E0-0E393B3D20F3}\x86\regsvr32.exeokta.swa.ie-5.35.0.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Out-of-process DLL registration helper
Exit code:
0
Version:
2016.05.11.1557U
Modules
Images
c:\programdata\installmate\{951d73c6-b2b4-4319-a4e0-0e393b3d20f3}\x86\regsvr32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
Total events
1 199
Read events
862
Write events
292
Delete events
45

Modification events

(PID) Process:(3820) okta.swa.ie-5.35.0.exeKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
EC0E0000AC3A6803CBBAD501
(PID) Process:(3820) okta.swa.ie-5.35.0.exeKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:SessionHash
Value:
0E311D4198810AF5733A9366AC316FCE479A02D1C57601D60435D42B0F51C74D
(PID) Process:(3820) okta.swa.ie-5.35.0.exeKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Sequence
Value:
1
(PID) Process:(3956) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E411779C-5CFE-413F-A57B-18C55A4EFADA}
Operation:writeName:
Value:
OktaBHO Class
(PID) Process:(3956) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E411779C-5CFE-413F-A57B-18C55A4EFADA}\InprocServer32
Operation:writeName:
Value:
C:\Program Files\Okta IE plugin\x86\OktaBHO.dll
(PID) Process:(3956) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E411779C-5CFE-413F-A57B-18C55A4EFADA}\InprocServer32
Operation:writeName:ThreadingModel
Value:
Apartment
(PID) Process:(3956) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E411779C-5CFE-413F-A57B-18C55A4EFADA}
Operation:writeName:AppID
Value:
{CA21169E-15AD-4932-A161-D544E66145CC}
(PID) Process:(3956) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E411779C-5CFE-413F-A57B-18C55A4EFADA}\TypeLib
Operation:writeName:
Value:
{CC8FCBD1-6B44-4A92-BAC4-2096A7A1C666}
(PID) Process:(3956) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E411779C-5CFE-413F-A57B-18C55A4EFADA}\Version
Operation:writeName:
Value:
1.0
(PID) Process:(3956) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E411779C-5CFE-413F-A57B-18C55A4EFADA}
Operation:writeName:
Value:
OktaBHO
Executable files
12
Suspicious files
7
Text files
34
Unknown types
13

Dropped files

PID
Process
Filename
Type
3820okta.swa.ie-5.35.0.exeC:\Users\admin\AppData\Local\Temp\2FFF6685.dat
MD5:
SHA256:
3820okta.swa.ie-5.35.0.exeC:\Program Files\Okta IE plugin\x86\OktaBHO.dll._tm
MD5:
SHA256:
3820okta.swa.ie-5.35.0.exeC:\Program Files\Okta IE plugin\x86\toolbar\OktaIEBand.dll._tm
MD5:
SHA256:
2336IEXPLORE.EXEC:\Users\admin\AppData\LocalLow\Okta\IE Plugin\persistent_storage_1.dat
MD5:
SHA256:
1524IEXPLORE.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LH043OAM\favicon[1].ico
MD5:
SHA256:
1524IEXPLORE.EXEC:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.ico
MD5:
SHA256:
1880taskkill.exeC:\Users\admin\AppData\Local\Temp\RunProgram7.txttext
MD5:
SHA256:
2336IEXPLORE.EXEC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@system.okta[2].txt
MD5:
SHA256:
3820okta.swa.ie-5.35.0.exeC:\Users\admin\AppData\Local\Temp\2FFF6685\_Setupx.dllexecutable
MD5:
SHA256:
2336IEXPLORE.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LH043OAM\ie[1].txt
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
8
DNS requests
3
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1524
IEXPLORE.EXE
GET
200
204.79.197.200:80
http://www.bing.com/favicon.ico
US
image
237 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2336
IEXPLORE.EXE
52.14.242.20:443
system.okta.com
Amazon.com, Inc.
US
unknown
2336
IEXPLORE.EXE
143.204.214.63:443
ok6static.oktacdn.com
US
suspicious
1524
IEXPLORE.EXE
204.79.197.200:80
www.bing.com
Microsoft Corporation
US
whitelisted

DNS requests

Domain
IP
Reputation
system.okta.com
  • 52.14.242.20
  • 52.14.242.18
  • 52.14.242.19
unknown
www.bing.com
  • 204.79.197.200
  • 13.107.21.200
whitelisted
ok6static.oktacdn.com
  • 143.204.214.63
  • 143.204.214.127
  • 143.204.214.46
  • 143.204.214.101
shared

Threats

No threats detected
No debug info