File name:

NordVPNSetup.exe

Full analysis: https://app.any.run/tasks/111ebb6a-f34e-42c7-a214-cebc5767e9fb
Verdict: Malicious activity
Analysis date: June 17, 2024, 04:31:17
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

5D6F0577264346D7C28F1853871D89B7

SHA1:

A606FA6E79ED5CA473EED30CC8483901CA67FAE1

SHA256:

391B613C8DB8F21FE6545D6448ADB188DD2B54749F31E7CD7ABEFB6E61F388D2

SSDEEP:

49152:O7HecD4dnbibBlf8+XVUQ+c31Bfw2Jt+Cf1ZLwr9+QC2JiLA1KYPAQEb0bJAl5Hb:W+cD4dncBU482vor9+OE9bQfylxrlHC0

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • NordVPNSetup.exe (PID: 3972)
      • NordVPNSetup.exe (PID: 1120)
      • NordVPNSetup.tmp (PID: 820)
      • NordVPNSetup.exe (PID: 312)
      • NordVPNSetup.tmp (PID: 660)
      • NordUpdaterSetup.exe (PID: 2236)
      • NordUpdaterSetup.tmp (PID: 2272)
      • msiexec.exe (PID: 1408)
      • tapinstall.exe (PID: 2916)
      • drvinst.exe (PID: 2924)
      • NordVPNTapSetup.exe (PID: 2468)
    • Creates a writable file in the system directory

      • NordUpdateService.exe (PID: 2620)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • NordVPNSetup.exe (PID: 3972)
      • NordVPNSetup.tmp (PID: 820)
      • NordVPNSetup.exe (PID: 1120)
      • NordVPNSetup.exe (PID: 312)
      • NordVPNSetup.tmp (PID: 660)
      • NordUpdaterSetup.exe (PID: 2236)
      • NordUpdaterSetup.tmp (PID: 2272)
      • NordVPNTapSetup.exe (PID: 2468)
      • rundll32.exe (PID: 2780)
      • tapinstall.exe (PID: 2916)
      • drvinst.exe (PID: 2924)
    • Reads the Windows owner or organization settings

      • NordVPNSetup.tmp (PID: 820)
      • NordUpdaterSetup.tmp (PID: 2272)
      • NordVPNSetup.tmp (PID: 660)
      • NordVPNTapSetup.exe (PID: 2468)
      • msiexec.exe (PID: 1408)
    • Checks Windows Trust Settings

      • NordVPNSetup.tmp (PID: 820)
      • NordVPNSetup.tmp (PID: 660)
      • NordUpdateService.exe (PID: 2620)
      • NordVPNTapSetup.exe (PID: 2468)
      • msiexec.exe (PID: 1408)
      • tapinstall.exe (PID: 2916)
    • Reads security settings of Internet Explorer

      • NordVPNSetup.tmp (PID: 820)
      • NordVPNSetup.tmp (PID: 660)
      • NordVPNTapSetup.exe (PID: 2468)
      • tapinstall.exe (PID: 2916)
    • Adds/modifies Windows certificates

      • NordVPNSetup.tmp (PID: 820)
    • Reads the Internet Settings

      • NordVPNSetup.tmp (PID: 820)
      • NordVPNSetup.tmp (PID: 660)
    • Reads settings of System Certificates

      • NordVPNSetup.tmp (PID: 820)
      • NordVPNSetup.tmp (PID: 660)
      • NordVPNTapSetup.exe (PID: 2468)
      • tapinstall.exe (PID: 2916)
    • Searches for installed software

      • NordVPNSetup.tmp (PID: 660)
    • Uses TASKKILL.EXE to kill process

      • NordVPNSetup.tmp (PID: 660)
    • Process drops legitimate windows executable

      • NordUpdaterSetup.tmp (PID: 2272)
    • Uses ICACLS.EXE to modify access control lists

      • NordUpdaterSetup.tmp (PID: 2272)
    • Executes as Windows Service

      • NordUpdateService.exe (PID: 2620)
    • Drops a system driver (possible attempt to evade defenses)

      • rundll32.exe (PID: 2780)
      • msiexec.exe (PID: 1408)
      • tapinstall.exe (PID: 2916)
      • drvinst.exe (PID: 2924)
    • Uses RUNDLL32.EXE to load library

      • msiexec.exe (PID: 2420)
  • INFO

    • Create files in a temporary directory

      • NordVPNSetup.exe (PID: 3972)
      • NordVPNSetup.exe (PID: 1120)
      • NordVPNSetup.tmp (PID: 820)
      • NordVPNSetup.exe (PID: 312)
      • NordVPNSetup.tmp (PID: 660)
      • NordUpdaterSetup.exe (PID: 2236)
      • NordUpdaterSetup.tmp (PID: 2272)
      • NordVPNTapSetup.exe (PID: 2468)
      • msiexec.exe (PID: 2680)
      • msiexec.exe (PID: 1408)
    • Checks supported languages

      • NordVPNSetup.exe (PID: 1120)
      • NordVPNSetup.exe (PID: 3972)
      • NordVPNSetup.tmp (PID: 820)
      • wmpnscfg.exe (PID: 116)
      • NordVPNSetup.exe (PID: 312)
      • NordVPNSetup.tmp (PID: 660)
      • NordUpdaterSetup.exe (PID: 2236)
      • NordUpdaterSetup.tmp (PID: 2272)
      • NordUpdateService.exe (PID: 2620)
      • NordVPNTapSetup.exe (PID: 2468)
      • msiexec.exe (PID: 1408)
      • msiexec.exe (PID: 2504)
      • NordVPNSetup.tmp (PID: 3988)
      • msiexec.exe (PID: 2420)
      • tapinstall.exe (PID: 2696)
      • tapinstall.exe (PID: 2916)
    • Reads the computer name

      • NordVPNSetup.tmp (PID: 820)
      • NordVPNSetup.tmp (PID: 3988)
      • wmpnscfg.exe (PID: 116)
      • NordVPNSetup.tmp (PID: 660)
      • NordUpdaterSetup.tmp (PID: 2272)
      • NordUpdateService.exe (PID: 2620)
      • NordVPNTapSetup.exe (PID: 2468)
      • msiexec.exe (PID: 1408)
      • msiexec.exe (PID: 2504)
      • msiexec.exe (PID: 2420)
      • tapinstall.exe (PID: 2696)
      • tapinstall.exe (PID: 2916)
    • Reads the machine GUID from the registry

      • NordVPNSetup.tmp (PID: 820)
      • NordVPNSetup.tmp (PID: 660)
      • NordUpdateService.exe (PID: 2620)
      • NordVPNTapSetup.exe (PID: 2468)
      • msiexec.exe (PID: 1408)
      • msiexec.exe (PID: 2504)
      • msiexec.exe (PID: 2420)
      • tapinstall.exe (PID: 2916)
    • Reads the software policy settings

      • NordVPNSetup.tmp (PID: 820)
      • NordVPNSetup.tmp (PID: 660)
      • NordUpdateService.exe (PID: 2620)
      • NordVPNTapSetup.exe (PID: 2468)
      • msiexec.exe (PID: 1408)
    • Disables trace logs

      • NordVPNSetup.tmp (PID: 820)
      • NordVPNSetup.tmp (PID: 660)
    • Creates files or folders in the user directory

      • NordVPNSetup.tmp (PID: 820)
    • Reads Environment values

      • NordVPNSetup.tmp (PID: 820)
      • NordVPNSetup.tmp (PID: 660)
      • NordVPNTapSetup.exe (PID: 2468)
      • NordUpdateService.exe (PID: 2620)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 116)
    • Creates files in the program directory

      • NordUpdaterSetup.tmp (PID: 2272)
      • NordUpdateService.exe (PID: 2620)
    • Creates a software uninstall entry

      • NordUpdaterSetup.tmp (PID: 2272)
      • msiexec.exe (PID: 1408)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 1408)
    • Application launched itself

      • msiexec.exe (PID: 1408)
    • Drops the executable file immediately after the start

      • rundll32.exe (PID: 2780)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (67.7)
.exe | Win32 EXE PECompact compressed (generic) (25.6)
.exe | Win32 Executable (generic) (2.7)
.exe | Win16/32 Executable Delphi generic (1.2)
.exe | Generic Win/DOS Executable (1.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:02:15 14:54:16+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 741888
InitializedDataSize: 123392
UninitializedDataSize: -
EntryPoint: 0xb5eec
OSVersion: 6.1
ImageVersion: 6
SubsystemVersion: 6.1
Subsystem: Windows GUI
FileVersionNumber: 0.0.11.0
ProductVersionNumber: 0.0.11.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: NordVPN
FileDescription: NordVPN Web Installer
FileVersion: 0.0.11.0
LegalCopyright:
OriginalFileName:
ProductName: NordVPN
ProductVersion: 0.0.11.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
71
Monitored processes
25
Malicious processes
13
Suspicious processes
2

Behavior graph

Click at the process to see the details
start nordvpnsetup.exe nordvpnsetup.tmp no specs nordvpnsetup.exe nordvpnsetup.tmp wmpnscfg.exe no specs nordvpnsetup.exe nordvpnsetup.tmp taskkill.exe no specs nordupdatersetup.exe nordupdatersetup.tmp icacls.exe no specs icacls.exe no specs icacls.exe no specs icacls.exe no specs nordupdateservice.exe nordvpntapsetup.exe msiexec.exe msiexec.exe no specs msiexec.exe no specs msiexec.exe no specs rundll32.exe tapinstall.exe no specs tapinstall.exe drvinst.exe rundll32.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
116"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
188"C:\Windows\system32\icacls.exe" "C:\Program Files\NordUpdater" /grant *S-1-5-32-544:(OI)(CI)(F)C:\Windows\System32\icacls.exeNordUpdaterSetup.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\icacls.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
312"C:\Users\admin\AppData\Local\Temp\is-1N9MU.tmp\NordVPNSetup.exe" /webinstaller=true /DIR="C:\Program Files\NordVPN" /guid=dc5639ff-05e0-41f0-9f59-14c894734399C:\Users\admin\AppData\Local\Temp\is-1N9MU.tmp\NordVPNSetup.exe
NordVPNSetup.tmp
User:
admin
Company:
TEFINCOM S.A.
Integrity Level:
HIGH
Description:
NordVPN Installer
Version:
6.45.10.3
Modules
Images
c:\users\admin\appdata\local\temp\is-1n9mu.tmp\nordvpnsetup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\comctl32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
660"C:\Users\admin\AppData\Local\Temp\is-OFBMB.tmp\NordVPNSetup.tmp" /SL5="$101AE,36994529,893952,C:\Users\admin\AppData\Local\Temp\is-1N9MU.tmp\NordVPNSetup.exe" /webinstaller=true /DIR="C:\Program Files\NordVPN" /guid=dc5639ff-05e0-41f0-9f59-14c894734399C:\Users\admin\AppData\Local\Temp\is-OFBMB.tmp\NordVPNSetup.tmp
NordVPNSetup.exe
User:
admin
Company:
TEFINCOM S.A.
Integrity Level:
HIGH
Description:
Setup/Uninstall
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-ofbmb.tmp\nordvpnsetup.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
820"C:\Users\admin\AppData\Local\Temp\is-15I96.tmp\NordVPNSetup.tmp" /SL5="$3013A,890444,866304,C:\Users\admin\AppData\Local\Temp\NordVPNSetup.exe" /SPAWNWND=$20130 /NOTIFYWND=$20138 C:\Users\admin\AppData\Local\Temp\is-15I96.tmp\NordVPNSetup.tmp
NordVPNSetup.exe
User:
admin
Company:
NordVPN
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-15i96.tmp\nordvpnsetup.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1120"C:\Users\admin\AppData\Local\Temp\NordVPNSetup.exe" /SPAWNWND=$20130 /NOTIFYWND=$20138 C:\Users\admin\AppData\Local\Temp\NordVPNSetup.exe
NordVPNSetup.tmp
User:
admin
Company:
NordVPN
Integrity Level:
HIGH
Description:
NordVPN Web Installer
Exit code:
0
Version:
0.0.11.0
Modules
Images
c:\users\admin\appdata\local\temp\nordvpnsetup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\comctl32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
1408C:\Windows\system32\msiexec.exe /VC:\Windows\System32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1884"C:\Windows\system32\icacls.exe" "C:\Program Files\NordUpdater" /inheritance:rC:\Windows\System32\icacls.exeNordUpdaterSetup.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\icacls.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
1932"C:\Windows\system32\taskkill.exe" /f /im NordVPN.exeC:\Windows\System32\taskkill.exeNordVPNSetup.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Terminates Processes
Exit code:
128
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
2172"C:\Windows\system32\icacls.exe" "C:\Program Files\NordUpdater" /grant *S-1-5-32-545:(OI)(CI)(RX)C:\Windows\System32\icacls.exeNordUpdaterSetup.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\icacls.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
Total events
46 378
Read events
46 075
Write events
269
Delete events
34

Modification events

(PID) Process:(820) NordVPNSetup.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
34030000482A14366FC0DA01
(PID) Process:(820) NordVPNSetup.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:SessionHash
Value:
C5440C1621F30FB2E813AEF8C2A6E2180E52C1F1358555C31EAB639CDDC9FE7A
(PID) Process:(820) NordVPNSetup.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Sequence
Value:
1
(PID) Process:(820) NordVPNSetup.tmpKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(820) NordVPNSetup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Root\Certificates
Operation:delete valueName:9F6134C5FA75E4FDDE631B232BE961D6D4B97DB6
Value:
(PID) Process:(820) NordVPNSetup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Root\Certificates\9F6134C5FA75E4FDDE631B232BE961D6D4B97DB6
Operation:writeName:Blob
Value:
0F00000001000000200000009065F32AFC2CFEA7F452D2D6BE94D20C877EFC1C05433D9935696193FDCC05D80300000001000000140000009F6134C5FA75E4FDDE631B232BE961D6D4B97DB6200000000100000047030000308203433082022BA00302010202147327B7C17D5AE708EF73F1F45A79D78B4E99A29F300D06092A864886F70D01010B05003031310B3009060355040613025553310F300D06035504080C06426F73746F6E3111300F060355040A0C084469676943657274301E170D3233303932393130353030335A170D3339303530383130353030335A3031310B3009060355040613025553310F300D06035504080C06426F73746F6E3111300F060355040A0C08446967694365727430820122300D06092A864886F70D01010105000382010F003082010A0282010100D91B7A55548F44F3E97C493153B75B055695736B184640D7335A2E6218083B5A1BEE2695209350E57A3EB76FBC604CB3B250DF3D9D0C560D1FBDFE30108D233A3C555100BE1A3F8E543C0B253E06E91B6D5F9CB3A093009BC8B4D3A0EB19DB59E56DA7E3D637847970D6C2AEB4A1FCF3896A7C080FE68759BAA62E6AAA8B7C7CBDA176DDC72F8D259A16D3469E31F19D2959904611D730D7D26FCFED789A0C49698FDFABF3F6727D08C61A073BB11E85C96486D49B0E0D38364C008A5EB964F8813C5DF004F9E76D2F8DB90702D800032674959BF0DF823785419101CEA928A10ACBAE7E48FE19202F3CB7BCF416476D17CB64C5570FCED443BD75D9F2C632FF0203010001A3533051301D0603551D0E041604145D6CA352CEFC713CBBC5E21F663C3639FD19D4D7301F0603551D230418301680145D6CA352CEFC713CBBC5E21F663C3639FD19D4D7300F0603551D130101FF040530030101FF300D06092A864886F70D01010B05000382010100AF2218E4CA18144728FCC76EA14958061522FD4A018BED1A4BFCC5CCE70BC6AE9DF7D3795C9A010D53628E2B6E7C10D6B07E53546235A5EE480E5A434E312154BF1E39AAC27D2C18D4F41CBBECFE4538CEF93EF62C17D187A7F720F4A9478410D09620C9F8B293B5786A5440BC0743B7B7753CF66FBA498B7E083BC267597238DC031B9BB131F997D9B8164AAED0D6E328420E53E1969DA6CD035078179677A7177BB2BF9C87CF592910CD380E8501B92040A39469C782BA383BEAE498C060FCC7C429BC10B7B6B7A0659C9BE03DC13DB46C638CF5E3B22A303726906DC8DD91C64501EBFC282A3A497EC430CACC066EE4BF9C5C8F2F2A05D0C1921A9E3E85E3
(PID) Process:(820) NordVPNSetup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Root\Certificates\9F6134C5FA75E4FDDE631B232BE961D6D4B97DB6
Operation:writeName:Blob
Value:
1400000001000000140000005D6CA352CEFC713CBBC5E21F663C3639FD19D4D70300000001000000140000009F6134C5FA75E4FDDE631B232BE961D6D4B97DB60F00000001000000200000009065F32AFC2CFEA7F452D2D6BE94D20C877EFC1C05433D9935696193FDCC05D8200000000100000047030000308203433082022BA00302010202147327B7C17D5AE708EF73F1F45A79D78B4E99A29F300D06092A864886F70D01010B05003031310B3009060355040613025553310F300D06035504080C06426F73746F6E3111300F060355040A0C084469676943657274301E170D3233303932393130353030335A170D3339303530383130353030335A3031310B3009060355040613025553310F300D06035504080C06426F73746F6E3111300F060355040A0C08446967694365727430820122300D06092A864886F70D01010105000382010F003082010A0282010100D91B7A55548F44F3E97C493153B75B055695736B184640D7335A2E6218083B5A1BEE2695209350E57A3EB76FBC604CB3B250DF3D9D0C560D1FBDFE30108D233A3C555100BE1A3F8E543C0B253E06E91B6D5F9CB3A093009BC8B4D3A0EB19DB59E56DA7E3D637847970D6C2AEB4A1FCF3896A7C080FE68759BAA62E6AAA8B7C7CBDA176DDC72F8D259A16D3469E31F19D2959904611D730D7D26FCFED789A0C49698FDFABF3F6727D08C61A073BB11E85C96486D49B0E0D38364C008A5EB964F8813C5DF004F9E76D2F8DB90702D800032674959BF0DF823785419101CEA928A10ACBAE7E48FE19202F3CB7BCF416476D17CB64C5570FCED443BD75D9F2C632FF0203010001A3533051301D0603551D0E041604145D6CA352CEFC713CBBC5E21F663C3639FD19D4D7301F0603551D230418301680145D6CA352CEFC713CBBC5E21F663C3639FD19D4D7300F0603551D130101FF040530030101FF300D06092A864886F70D01010B05000382010100AF2218E4CA18144728FCC76EA14958061522FD4A018BED1A4BFCC5CCE70BC6AE9DF7D3795C9A010D53628E2B6E7C10D6B07E53546235A5EE480E5A434E312154BF1E39AAC27D2C18D4F41CBBECFE4538CEF93EF62C17D187A7F720F4A9478410D09620C9F8B293B5786A5440BC0743B7B7753CF66FBA498B7E083BC267597238DC031B9BB131F997D9B8164AAED0D6E328420E53E1969DA6CD035078179677A7177BB2BF9C87CF592910CD380E8501B92040A39469C782BA383BEAE498C060FCC7C429BC10B7B6B7A0659C9BE03DC13DB46C638CF5E3B22A303726906DC8DD91C64501EBFC282A3A497EC430CACC066EE4BF9C5C8F2F2A05D0C1921A9E3E85E3
(PID) Process:(820) NordVPNSetup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates
Operation:delete valueName:8094640EB5A7A1CA119C1FDDD59F810263A7FBD1
Value:
(PID) Process:(820) NordVPNSetup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\8094640EB5A7A1CA119C1FDDD59F810263A7FBD1
Operation:writeName:Blob
Value:
0400000001000000100000004FDD07E4D42264391E0C3742EAD1C6AE090000000100000056000000305406082B0601050507030206082B06010505070303060A2B0601040182370A030C060A2B0601040182370A030406082B0601050507030406082B0601050507030906082B0601050507030106082B060105050703080F0000000100000030000000EA09C51D4C3A334CE4ACD2BC08C6A9BE352E334F45C4FCCFCAB63EDB9F82DC87D4BD2ED2FADAE11163FB954809984FF10300000001000000140000008094640EB5A7A1CA119C1FDDD59F810263A7FBD17E00000001000000080000000000042BEB77D5017F000000010000000C000000300A06082B060105050703091D0000000100000010000000521F5C98970D19A8E515EF6EEB6D48EF140000000100000014000000AE6C05A39313E2A2E7E2D71CD6C7F07FC86753A06200000001000000200000002CABEAFE37D06CA22ABA7391C0033D25982952C453647349763A3AB5AD6CCF690B000000010000003000000047006C006F00620061006C005300690067006E00200052006F006F00740020004300410020002D00200052003600000053000000010000007E000000307C301F06092B06010401A032010130123010060A2B0601040182373C0101030200C0301F06092B06010401A032010230123010060A2B0601040182373C0101030200C0301B060567810C010130123010060A2B0601040182373C0101030200C0301B060567810C010330123010060A2B0601040182373C0101030200C0190000000100000010000000CB9DD0FCEAAA492F75CE292C21BBFBDD7A000000010000000C000000300A06082B06010505070309200000000100000087050000308205833082036BA003020102020E45E6BB038333C3856548E6FF4551300D06092A864886F70D01010C0500304C3120301E060355040B1317476C6F62616C5369676E20526F6F74204341202D20523631133011060355040A130A476C6F62616C5369676E311330110603550403130A476C6F62616C5369676E301E170D3134313231303030303030305A170D3334313231303030303030305A304C3120301E060355040B1317476C6F62616C5369676E20526F6F74204341202D20523631133011060355040A130A476C6F62616C5369676E311330110603550403130A476C6F62616C5369676E30820222300D06092A864886F70D01010105000382020F003082020A02820201009507E873CA66F9EC14CA7B3CF70D08F1B4450B2C82B448C6EB5B3CAE83B841923314A46F7FE92ACCC6B0886BC5B689D1C6B2FF14CE511421EC4ADD1B5AC6D687EE4D3A1506ED64660B9280CA44DE73944EF3A7897F4F786308C812506D42662F4DB979284D521A8A1A80B719810E7EC48ABC644C211C4368D73D3C8AC5B266D5909AB73106C5BEE26D3206A61EF9B9EBAAA3B8BFBE826350D0F01889DFE40F79F5EAA21F2AD2702E7BE7BC93BB6D53E2487C8C100738FF66B277617EE0EA8C3CAAB4A4F6F3954A12076DFD8CB289CFD0A06177C85874B0D4233AF75D3ACAA2DB9D09DE5D442D90F181CD5792FA7EBC50046334DF6B9318BE6B36B239E4AC2436B7F0EFB61C135793B6DEB2F8E285B773A2B835AA45F2E09D36A16F548AF172566E2E88C55142441594EEA3C538969B4E4E5A0B47F30636497730BC7137E5A6EC210875FCE661163F77D5D99197840A6CD4024D74C014EDFD39FB83F25E14A104B00BE9FEEE8FE16E0BB208B36166096AB1063A659659C0F035FDC9DA288D1A118770810AA89A751D9E3A8605009EDB80D625F9DC059E27594C76395BEAF9A5A1D8830FD1FFDF3011F985CF3348F5CA6D64142C7A584FD34B0849C595641A630E793DF5B38CCA58AD9C4245796E0E87195C54B165B6BF8C9BDC13E90D6FB82EDC676EC98B11B584148A0019708379919791D41A27BF371E3207D814633C284CAF0203010001A3633061300E0603551D0F0101FF040403020106300F0603551D130101FF040530030101FF301D0603551D0E04160414AE6C05A39313E2A2E7E2D71CD6C7F07FC86753A0301F0603551D23041830168014AE6C05A39313E2A2E7E2D71CD6C7F07FC86753A0300D06092A864886F70D01010C050003820201008325EDE8D1FD9552CD9EC004A09169E65CD084DEDCADA24FE84778D66598A95BA83C877C028AD16EB71673E65FC05498D574BEC1CDE21191AD23183DDDE1724496B4955EC07B8E99781643135657B3A2B33BB577DC4072ACA3EB9B353EB10821A1E7C443377932BEB5E79C2C4CBC4329998E30D3AC21E0E31DFAD80733765400222AB94D202E7068DAE553FC835CD39DF2FF440C4466F2D2E3BD46001A6D02BA255D8DA13151DD54461C4DDB9996EF1A1C045CA615EF78E079FE5DDB3EAA4C55FD9A15A96FE1A6FBDF7030E9C3EE4246EDC2930589FA7D637B3FD071817C00E898AE0E7834C325FBAF0A9F206BDD3B138F128CE2411A487A73A07769C7B65C7F82C81EFE581B282BA86CAD5E6DC005D27BB7EB80FE2537FE029B68AC425DC3EEF5CCDCF05075D236699CE67B04DF6E0669B6DE0A09485987EB7B14607A64AA6943EF91C74CEC18DD6CEF532D8C99E15EF2723ECF54C8BD67ECA40F4C45FFD3B93023074C8F10BF8696D9995AB499571CA4CCBB158953BA2C050FE4C49E19B11834D54C9DBAEDF71FAF24950478A803BBEE81E5DA5F7C8B4AA1907425A7B33E4BC82C56BDC7C8EF38E25C92F079F79C84BA742D6101207E7ED1F24F07595F8B2D4352EB460C94E1F566477977D5545B1FAD2437CB455A4EA04448C8D8B099C5158409F6D64949C065B8E61A716EA0A8F182E8453E6CD602D70A6783055AC9A410
(PID) Process:(820) NordVPNSetup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\8094640EB5A7A1CA119C1FDDD59F810263A7FBD1
Operation:writeName:Blob
Value:
5C0000000100000004000000001000007A000000010000000C000000300A06082B06010505070309190000000100000010000000CB9DD0FCEAAA492F75CE292C21BBFBDD53000000010000007E000000307C301F06092B06010401A032010130123010060A2B0601040182373C0101030200C0301F06092B06010401A032010230123010060A2B0601040182373C0101030200C0301B060567810C010130123010060A2B0601040182373C0101030200C0301B060567810C010330123010060A2B0601040182373C0101030200C00B000000010000003000000047006C006F00620061006C005300690067006E00200052006F006F00740020004300410020002D0020005200360000006200000001000000200000002CABEAFE37D06CA22ABA7391C0033D25982952C453647349763A3AB5AD6CCF69140000000100000014000000AE6C05A39313E2A2E7E2D71CD6C7F07FC86753A01D0000000100000010000000521F5C98970D19A8E515EF6EEB6D48EF7F000000010000000C000000300A06082B060105050703097E00000001000000080000000000042BEB77D5010300000001000000140000008094640EB5A7A1CA119C1FDDD59F810263A7FBD10F0000000100000030000000EA09C51D4C3A334CE4ACD2BC08C6A9BE352E334F45C4FCCFCAB63EDB9F82DC87D4BD2ED2FADAE11163FB954809984FF1090000000100000056000000305406082B0601050507030206082B06010505070303060A2B0601040182370A030C060A2B0601040182370A030406082B0601050507030406082B0601050507030906082B0601050507030106082B060105050703080400000001000000100000004FDD07E4D42264391E0C3742EAD1C6AE200000000100000087050000308205833082036BA003020102020E45E6BB038333C3856548E6FF4551300D06092A864886F70D01010C0500304C3120301E060355040B1317476C6F62616C5369676E20526F6F74204341202D20523631133011060355040A130A476C6F62616C5369676E311330110603550403130A476C6F62616C5369676E301E170D3134313231303030303030305A170D3334313231303030303030305A304C3120301E060355040B1317476C6F62616C5369676E20526F6F74204341202D20523631133011060355040A130A476C6F62616C5369676E311330110603550403130A476C6F62616C5369676E30820222300D06092A864886F70D01010105000382020F003082020A02820201009507E873CA66F9EC14CA7B3CF70D08F1B4450B2C82B448C6EB5B3CAE83B841923314A46F7FE92ACCC6B0886BC5B689D1C6B2FF14CE511421EC4ADD1B5AC6D687EE4D3A1506ED64660B9280CA44DE73944EF3A7897F4F786308C812506D42662F4DB979284D521A8A1A80B719810E7EC48ABC644C211C4368D73D3C8AC5B266D5909AB73106C5BEE26D3206A61EF9B9EBAAA3B8BFBE826350D0F01889DFE40F79F5EAA21F2AD2702E7BE7BC93BB6D53E2487C8C100738FF66B277617EE0EA8C3CAAB4A4F6F3954A12076DFD8CB289CFD0A06177C85874B0D4233AF75D3ACAA2DB9D09DE5D442D90F181CD5792FA7EBC50046334DF6B9318BE6B36B239E4AC2436B7F0EFB61C135793B6DEB2F8E285B773A2B835AA45F2E09D36A16F548AF172566E2E88C55142441594EEA3C538969B4E4E5A0B47F30636497730BC7137E5A6EC210875FCE661163F77D5D99197840A6CD4024D74C014EDFD39FB83F25E14A104B00BE9FEEE8FE16E0BB208B36166096AB1063A659659C0F035FDC9DA288D1A118770810AA89A751D9E3A8605009EDB80D625F9DC059E27594C76395BEAF9A5A1D8830FD1FFDF3011F985CF3348F5CA6D64142C7A584FD34B0849C595641A630E793DF5B38CCA58AD9C4245796E0E87195C54B165B6BF8C9BDC13E90D6FB82EDC676EC98B11B584148A0019708379919791D41A27BF371E3207D814633C284CAF0203010001A3633061300E0603551D0F0101FF040403020106300F0603551D130101FF040530030101FF301D0603551D0E04160414AE6C05A39313E2A2E7E2D71CD6C7F07FC86753A0301F0603551D23041830168014AE6C05A39313E2A2E7E2D71CD6C7F07FC86753A0300D06092A864886F70D01010C050003820201008325EDE8D1FD9552CD9EC004A09169E65CD084DEDCADA24FE84778D66598A95BA83C877C028AD16EB71673E65FC05498D574BEC1CDE21191AD23183DDDE1724496B4955EC07B8E99781643135657B3A2B33BB577DC4072ACA3EB9B353EB10821A1E7C443377932BEB5E79C2C4CBC4329998E30D3AC21E0E31DFAD80733765400222AB94D202E7068DAE553FC835CD39DF2FF440C4466F2D2E3BD46001A6D02BA255D8DA13151DD54461C4DDB9996EF1A1C045CA615EF78E079FE5DDB3EAA4C55FD9A15A96FE1A6FBDF7030E9C3EE4246EDC2930589FA7D637B3FD071817C00E898AE0E7834C325FBAF0A9F206BDD3B138F128CE2411A487A73A07769C7B65C7F82C81EFE581B282BA86CAD5E6DC005D27BB7EB80FE2537FE029B68AC425DC3EEF5CCDCF05075D236699CE67B04DF6E0669B6DE0A09485987EB7B14607A64AA6943EF91C74CEC18DD6CEF532D8C99E15EF2723ECF54C8BD67ECA40F4C45FFD3B93023074C8F10BF8696D9995AB499571CA4CCBB158953BA2C050FE4C49E19B11834D54C9DBAEDF71FAF24950478A803BBEE81E5DA5F7C8B4AA1907425A7B33E4BC82C56BDC7C8EF38E25C92F079F79C84BA742D6101207E7ED1F24F07595F8B2D4352EB460C94E1F566477977D5545B1FAD2437CB455A4EA04448C8D8B099C5158409F6D64949C065B8E61A716EA0A8F182E8453E6CD602D70A6783055AC9A410
Executable files
87
Suspicious files
64
Text files
19
Unknown types
5

Dropped files

PID
Process
Filename
Type
820NordVPNSetup.tmpC:\Users\admin\AppData\Local\Temp\is-1N9MU.tmp\is-STB3R.tmp
MD5:
SHA256:
820NordVPNSetup.tmpC:\Users\admin\AppData\Local\Temp\is-1N9MU.tmp\NordVPNSetup.exe
MD5:
SHA256:
3972NordVPNSetup.exeC:\Users\admin\AppData\Local\Temp\is-BSEDC.tmp\NordVPNSetup.tmpexecutable
MD5:6693DDACA0479CDEEA33386155E9CACF
SHA256:384DAB757AF95F6D6D4A80351507F6F455C0FCE58F2AA32FF1C1E8CEEB3ADE82
820NordVPNSetup.tmpC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506compressed
MD5:49AEBF8CBD62D92AC215B2923FB1B9F5
SHA256:B33EFCB95235B98B48508E019AFA4B7655E80CF071DEFABD8B2123FC8B29307F
820NordVPNSetup.tmpC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\C5C8CC0A7FE31816B4641D0465402560binary
MD5:D60C83F1E96A07B8DA25E59636616132
SHA256:B49A3CBA31AEC9ADA8454D6F42EE20179D9DE6CD45FB67AA77282AEEA236AE6D
820NordVPNSetup.tmpC:\Users\admin\AppData\Local\Temp\is-1N9MU.tmp\Nord.Setup.dllexecutable
MD5:D9D4E2634AF0B4E81D473E5A76DF357F
SHA256:E897C29355A0E81E55FD9F8C74B52810A065E9E8C37A4C2ED813EFB846C9E89F
820NordVPNSetup.tmpC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506binary
MD5:777B78534EFEFD4FB3ED0EDA91239E3E
SHA256:EE58368295687D870F3CDD7415CC895D17C0B5015670C6F9A99C983235C99A29
820NordVPNSetup.tmpC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\357F04AD41BCF5FE18FCB69F60C6680F_59F1658D90E38DA89AB56C23C0E7D055binary
MD5:566E5D7727D545F095D98B9E4A5ECFFA
SHA256:6A775B3A5A9025FBDA3DCFD392EB68F57988AD77EA02FB81AE05EFC2EF326FA9
820NordVPNSetup.tmpC:\Users\admin\AppData\Local\Temp\Cab3143.tmpcompressed
MD5:49AEBF8CBD62D92AC215B2923FB1B9F5
SHA256:B33EFCB95235B98B48508E019AFA4B7655E80CF071DEFABD8B2123FC8B29307F
820NordVPNSetup.tmpC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:79C0CD0BA395585BA243CE7AAE11B69D
SHA256:B65F29C664BF338262A55BFC3AA7C70F2066DA4349EFBBA5CA4B6E020F84144B
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
22
TCP/UDP connections
17
DNS requests
9
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
820
NordVPNSetup.tmp
GET
200
104.18.21.226:80
http://ocsp2.globalsign.com/gsextendcodesignsha2g3/ME0wSzBJMEcwRTAJBgUrDgMCGgUABBQ3DAV9N6WelMGCzSTdNIqjdmfHiAQU3CxYLCpvNS2feZWoSF3EbT5Tv7kCDHsPcEljS9j9f3elgA%3D%3D
unknown
binary
5 b
unknown
820
NordVPNSetup.tmp
GET
200
104.18.21.226:80
http://ocsp2.globalsign.com/gsextendcodesignsha2g3/ME0wSzBJMEcwRTAJBgUrDgMCGgUABBQ3DAV9N6WelMGCzSTdNIqjdmfHiAQU3CxYLCpvNS2feZWoSF3EbT5Tv7kCDHsPcEljS9j9f3elgA%3D%3D
unknown
binary
5 b
unknown
820
NordVPNSetup.tmp
GET
200
104.18.21.226:80
http://secure.globalsign.com/cacert/codesigningrootr45.crt
unknown
binary
1.37 Kb
unknown
GET
200
104.18.21.226:80
http://crl.globalsign.com/gsextendcodesignsha2g3.crl
unknown
binary
4.49 Kb
unknown
820
NordVPNSetup.tmp
GET
200
23.50.131.200:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?081d980c52711b09
DE
compressed
70.2 Kb
unknown
820
NordVPNSetup.tmp
GET
304
23.50.131.200:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?c4534354707b2a5c
DE
compressed
70.2 Kb
unknown
820
NordVPNSetup.tmp
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfIs%2BLjDtGwQ09XEB1Yeq%2BtX%2BBgQQU7NfjgtJxXWRM3y5nP%2Be6mK4cD08CEAc2N7ckVHzYR6z9KGYqXls%3D
US
binary
727 b
unknown
820
NordVPNSetup.tmp
GET
200
104.18.20.226:80
http://ocsp.globalsign.com/codesigningrootr45/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQVFZP5vqhCrtRN5SWf40Rn6NM1IAQUHwC%2FRoAK%2FHg5t6W0Q9lWULvOljsCEHe9DgW3WQu2HUdhUx4%2Fde0%3D
unknown
binary
1.67 Kb
unknown
820
NordVPNSetup.tmp
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT3xL4LQLXDRDM9P665TW442vrsUQQUReuir%2FSSy4IxLVGLp6chnfNtyA8CEA6bGI750C3n79tQ4ghAGFo%3D
US
binary
471 b
unknown
820
NordVPNSetup.tmp
GET
200
104.18.20.226:80
http://ocsp.globalsign.com/gsgccr45evcodesignca2020/ME0wSzBJMEcwRTAJBgUrDgMCGgUABBQaCbVYh07WONuW4e63Ydlu4AlbDAQUJZ3Q%2FFkJhmPF7POxEztXHAOSNhECDF2zq5W4nUrgkGCLSg%3D%3D
unknown
binary
1.65 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1088
svchost.exe
224.0.0.252:5355
unknown
820
NordVPNSetup.tmp
104.18.21.226:80
secure.globalsign.com
CLOUDFLARENET
shared
820
NordVPNSetup.tmp
23.50.131.200:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown
820
NordVPNSetup.tmp
104.19.159.190:443
api.nordvpn.com
CLOUDFLARENET
unknown
820
NordVPNSetup.tmp
104.16.167.111:443
applytics.zwyr157wwiu6eior.com
CLOUDFLARENET
unknown
820
NordVPNSetup.tmp
104.16.155.111:443
downloads.nordcdn.com
CLOUDFLARENET
unknown
820
NordVPNSetup.tmp
104.18.20.226:80
secure.globalsign.com
CLOUDFLARENET
shared
820
NordVPNSetup.tmp
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted

DNS requests

Domain
IP
Reputation
secure.globalsign.com
  • 104.18.21.226
  • 104.18.20.226
whitelisted
ctldl.windowsupdate.com
  • 23.50.131.200
  • 23.50.131.216
whitelisted
api.nordvpn.com
  • 104.19.159.190
  • 104.16.208.203
unknown
applytics.zwyr157wwiu6eior.com
  • 104.16.167.111
  • 104.16.168.111
unknown
downloads.nordcdn.com
  • 104.16.155.111
  • 104.16.156.111
unknown
ocsp.globalsign.com
  • 104.18.20.226
  • 104.18.21.226
whitelisted
ocsp2.globalsign.com
  • 104.18.21.226
  • 104.18.20.226
whitelisted
crl.globalsign.com
  • 104.18.21.226
  • 104.18.20.226
unknown
ocsp.digicert.com
  • 192.229.221.95
whitelisted

Threats

No threats detected
No debug info