File name:

OCS-Windows-Agent-Setup-x86.exe

Full analysis: https://app.any.run/tasks/7214c2b5-1061-4444-805f-a0efb2de623c
Verdict: Malicious activity
Analysis date: November 10, 2023, 19:09:04
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
MD5:

9834F1FCA0C0D66CBCB92C32F1D280A7

SHA1:

86E2BB1F217D8853FA16F8088A5186E22BA1EC70

SHA256:

342759597B310ACF42DF6EDE24CE07D754C1EDA23086BEF1CFBC6093465E7C01

SSDEEP:

98304:sJHAoEnj2f5o26pg1b//5lXqK+st7vrJ1+5abo39tcnwMvFTsgvS1Mjp6:sqomjGo0/+2+5con4xN4Z1Mw

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Create files in the Startup directory

      • OCS-Windows-Agent-Setup-x86.exe (PID: 3468)
    • Drops the executable file immediately after the start

      • OCS-Windows-Agent-Setup-x86.exe (PID: 3468)
  • SUSPICIOUS

    • Malware-specific behavior (creating "System.dll" in Temp)

      • OCS-Windows-Agent-Setup-x86.exe (PID: 3468)
    • The process creates files with name similar to system file names

      • OCS-Windows-Agent-Setup-x86.exe (PID: 3468)
    • Starts application with an unusual extension

      • OCS-Windows-Agent-Setup-x86.exe (PID: 3468)
    • Process drops legitimate windows executable

      • OCS-Windows-Agent-Setup-x86.exe (PID: 3468)
    • The process drops C-runtime libraries

      • OCS-Windows-Agent-Setup-x86.exe (PID: 3468)
    • Executes as Windows Service

      • OcsService.exe (PID: 3948)
    • Starts CMD.EXE for commands execution

      • OcsService.exe (PID: 3948)
  • INFO

    • Reads the computer name

      • OCS-Windows-Agent-Setup-x86.exe (PID: 3468)
      • ocsinventory.exe (PID: 3884)
      • OcsService.exe (PID: 3944)
      • OcsService.exe (PID: 3948)
      • ocsinventory.exe (PID: 4016)
      • OcsSystray.exe (PID: 3956)
      • ocsinventory.exe (PID: 3028)
      • ocsinventory.exe (PID: 3616)
    • Checks supported languages

      • OCS-Windows-Agent-Setup-x86.exe (PID: 3468)
      • nsD2A9.tmp (PID: 3584)
      • nsD327.tmp (PID: 3556)
      • ns1F25.tmp (PID: 3644)
      • ocsinventory.exe (PID: 3884)
      • ns2476.tmp (PID: 3828)
      • OcsService.exe (PID: 3944)
      • OcsService.exe (PID: 3948)
      • ocsinventory.exe (PID: 4016)
      • OcsSystray.exe (PID: 3956)
      • ocsinventory.exe (PID: 3028)
      • ocsinventory.exe (PID: 3616)
    • Create files in a temporary directory

      • OCS-Windows-Agent-Setup-x86.exe (PID: 3468)
    • Creates files in the program directory

      • OCS-Windows-Agent-Setup-x86.exe (PID: 3468)
      • ocsinventory.exe (PID: 3884)
      • OcsService.exe (PID: 3948)
      • ocsinventory.exe (PID: 4016)
      • ocsinventory.exe (PID: 3028)
      • ocsinventory.exe (PID: 3616)
    • Reads the machine GUID from the registry

      • OcsService.exe (PID: 3948)
      • ocsinventory.exe (PID: 3616)
      • ocsinventory.exe (PID: 4016)
      • ocsinventory.exe (PID: 3028)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2017:07:24 08:35:22+02:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 25088
InitializedDataSize: 118784
UninitializedDataSize: 1024
EntryPoint: 0x330d
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 2.10.1.0
ProductVersionNumber: 2.10.1.0
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
Comments: Setup OCS Inventory NG Agent
CompanyName: OCS Inventory NG Team
FileDescription: OCS Inventory NG Agent
FileVersion: 2.10.1.0
LegalCopyright: Distributed under GNU GPL Version 2 Licence
LegalTrademarks: http://www.ocsinventory-ng.org
ProductName: OCS Inventory NG Agent
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
60
Monitored processes
16
Malicious processes
1
Suspicious processes
1

Behavior graph

Click at the process to see the details
start ocs-windows-agent-setup-x86.exe nsd2a9.tmp no specs nsd327.tmp no specs ns1f25.tmp no specs ocsinventory.exe no specs ns2476.tmp no specs ocsservice.exe no specs ocsservice.exe no specs cmd.exe no specs ocsinventory.exe no specs ocssystray.exe no specs cmd.exe no specs ocsinventory.exe no specs cmd.exe no specs ocsinventory.exe no specs ocs-windows-agent-setup-x86.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
3028"C:\Program Files\OCS Inventory Agent\ocsinventory.exe"C:\Program Files\OCS Inventory Agent\ocsinventory.execmd.exe
User:
SYSTEM
Company:
OCS Inventory
Integrity Level:
SYSTEM
Description:
OCS Inventory Agent
Exit code:
4
Version:
2.10.1.0
Modules
Images
c:\program files\ocs inventory agent\ocsinventory.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\program files\ocs inventory agent\ocsinventory front.dll
3156"C:\Users\admin\AppData\Local\Temp\OCS-Windows-Agent-Setup-x86.exe" C:\Users\admin\AppData\Local\Temp\OCS-Windows-Agent-Setup-x86.exeexplorer.exe
User:
admin
Company:
OCS Inventory NG Team
Integrity Level:
MEDIUM
Description:
OCS Inventory NG Agent
Exit code:
3221226540
Version:
2.10.1.0
Modules
Images
c:\users\admin\appdata\local\temp\ocs-windows-agent-setup-x86.exe
c:\windows\system32\ntdll.dll
3468"C:\Users\admin\AppData\Local\Temp\OCS-Windows-Agent-Setup-x86.exe" C:\Users\admin\AppData\Local\Temp\OCS-Windows-Agent-Setup-x86.exe
explorer.exe
User:
admin
Company:
OCS Inventory NG Team
Integrity Level:
HIGH
Description:
OCS Inventory NG Agent
Exit code:
0
Version:
2.10.1.0
Modules
Images
c:\users\admin\appdata\local\temp\ocs-windows-agent-setup-x86.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
3532"C:\Windows\system32\cmd.exe" /c "C:\Program Files\OCS Inventory Agent\ocsinventory.exe"C:\Windows\System32\cmd.exeOcsService.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Command Processor
Exit code:
4
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3556"C:\Users\admin\AppData\Local\Temp\nsh7083.tmp\nsD327.tmp" C:\Users\admin\AppData\Local\Temp\nsh7083.tmp\SetACL.exe -on "C:\ProgramData\OCS Inventory NG\Agent\Download" -ot file -actn setprot -op "dacl:np;sacl:np" -actn clear -clr "dacl,sacl" -actn rstchldrn -rst "dacl,sacl"C:\Users\admin\AppData\Local\Temp\nsh7083.tmp\nsD327.tmpOCS-Windows-Agent-Setup-x86.exe
User:
admin
Integrity Level:
HIGH
Exit code:
3221225501
Modules
Images
c:\users\admin\appdata\local\temp\nsh7083.tmp\nsd327.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
3584"C:\Users\admin\AppData\Local\Temp\nsh7083.tmp\nsD2A9.tmp" C:\Users\admin\AppData\Local\Temp\nsh7083.tmp\SetACL.exe -on "C:\ProgramData\OCS Inventory NG\Agent" -ot file -actn ace -ace "n:S-1-5-18;p:full;s:y;m:set" -ace "n:S-1-5-32-544;p:full;s:y;m:set" -ace "n:S-1-5-32-547;p:read_ex,change;s:y;m:set" -actn setprot -op "dacl:p_nc;sacl:p_nc" -actn clear -clr "dacl,sacl" -actn rstchldrn -rst "dacl,sacl"C:\Users\admin\AppData\Local\Temp\nsh7083.tmp\nsD2A9.tmpOCS-Windows-Agent-Setup-x86.exe
User:
admin
Integrity Level:
HIGH
Exit code:
3221225501
Modules
Images
c:\users\admin\appdata\local\temp\nsh7083.tmp\nsd2a9.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
3616"C:\Program Files\OCS Inventory Agent\ocsinventory.exe"C:\Program Files\OCS Inventory Agent\ocsinventory.execmd.exe
User:
SYSTEM
Company:
OCS Inventory
Integrity Level:
SYSTEM
Description:
OCS Inventory Agent
Exit code:
4
Version:
2.10.1.0
Modules
Images
c:\program files\ocs inventory agent\ocsinventory.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\program files\ocs inventory agent\ocsinventory front.dll
3644"C:\Users\admin\AppData\Local\Temp\nsh7083.tmp\ns1F25.tmp" "C:\Program Files\OCS Inventory Agent\ocsinventory.exe" /SAVE_CONF /SERVER=http://ocsinventory-ng/ocsinventory /USER= /PWD= /SSL=1 /CA="cacert.pem" /PROXY_TYPE=0 /PROXY= /PROXY_PORT= /PROXY_USER= /PROXY_PWD= /DEBUG=0 /TAG="" /WMI_FLAG_MODE="COMPLETE" /DEFAULT_USER_DOMAIN=""C:\Users\admin\AppData\Local\Temp\nsh7083.tmp\ns1F25.tmpOCS-Windows-Agent-Setup-x86.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\nsh7083.tmp\ns1f25.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
3704"C:\Windows\system32\cmd.exe" /c "C:\Program Files\OCS Inventory Agent\ocsinventory.exe"C:\Windows\System32\cmd.exeOcsService.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Command Processor
Exit code:
4
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3732"C:\Windows\system32\cmd.exe" /c "C:\Program Files\OCS Inventory Agent\ocsinventory.exe"C:\Windows\System32\cmd.exeOcsService.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Command Processor
Exit code:
4
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
Total events
1 451
Read events
1 451
Write events
0
Delete events
0

Modification events

No data
Executable files
40
Suspicious files
13
Text files
9
Unknown types
0

Dropped files

PID
Process
Filename
Type
3468OCS-Windows-Agent-Setup-x86.exeC:\Users\admin\AppData\Local\Temp\OCS-Windows-Agent-Setup-x86.logtext
MD5:85CB0A7C85F412D906A259BF9492EE74
SHA256:432203B41A8E419BCD746E5922A2EB43C3502C6799302F117D59DC58D1E662FC
3468OCS-Windows-Agent-Setup-x86.exeC:\Users\admin\AppData\Local\Temp\nsh7083.tmp\proxy.inibinary
MD5:B3D3D4F96EC5BF5A4F3ED48AE5CB8C9A
SHA256:B675CDB796457651293C86F6D6C265D30DBE0790CCCD08361F73AE54993BBB3A
3468OCS-Windows-Agent-Setup-x86.exeC:\Users\admin\AppData\Local\Temp\nsh7083.tmp\agent2.inibinary
MD5:6CCA25E3DC218F69DFB668BA5C757369
SHA256:D6C1C37EA33ED35D46C0DDE6C1F5A555CB8494BBB7CC77B0D581B4DF3DED033B
3468OCS-Windows-Agent-Setup-x86.exeC:\Users\admin\AppData\Local\Temp\nsh7083.tmp\agent.inibinary
MD5:59BE2F6EC53ADF79AB58416441EA3FD2
SHA256:0008836D0D5A633322E95EE19332B648FAC60999FD585BCC0FF04CC58FDDFDFE
3468OCS-Windows-Agent-Setup-x86.exeC:\Users\admin\AppData\Local\Temp\nsh7083.tmp\System.dllexecutable
MD5:C9473CB90D79A374B2BA6040CA16E45C
SHA256:B80A5CBA69D1853ED5979B0CA0352437BF368A5CFB86CB4528EDADD410E11352
3468OCS-Windows-Agent-Setup-x86.exeC:\Users\admin\AppData\Local\Temp\nsh7083.tmp\advsplash.dllexecutable
MD5:88C3BA1802AEF228541820767453E058
SHA256:2722555EC1F72523774B64D25FD4C2B460000BFE82140876D6100DC4FB1F62B1
3468OCS-Windows-Agent-Setup-x86.exeC:\Users\admin\AppData\Local\Temp\nsh7083.tmp\splash.bmpimage
MD5:DA0E7BCC28506AA8C754F228BCC37C24
SHA256:308FF588C323A37A657C114A46B37844CF65D61D075CFB89DDD95E4A348688DD
3468OCS-Windows-Agent-Setup-x86.exeC:\Users\admin\AppData\Local\Temp\nsh7083.tmp\modern-wizard.bmpimage
MD5:CBE40FD2B1EC96DAEDC65DA172D90022
SHA256:3AD2DC318056D0A2024AF1804EA741146CFC18CC404649A44610CBF8B2056CF2
3468OCS-Windows-Agent-Setup-x86.exeC:\Users\admin\AppData\Local\Temp\nsh7083.tmp\SetACL.exeexecutable
MD5:1FB64FF73938F4A04E97E5E7BF3D618C
SHA256:4EFC87B7E585FCBE4EAED656D3DBADAEC88BECA7F92CA7F0089583B428A6B221
3468OCS-Windows-Agent-Setup-x86.exeC:\Users\admin\AppData\Local\Temp\nsh7083.tmp\local.inibinary
MD5:06F67F6875C9F578509F1C65457875DF
SHA256:4EB25F2DF800FAAF060AFAC330B19EDE713D7218F79148428FB825652652604A
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
10
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2588
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown

DNS requests

No data

Threats

No threats detected
No debug info