File name:

NavaShield.zip

Full analysis: https://app.any.run/tasks/9acc0fe2-e3a6-400a-8fb8-526cad0769f9
Verdict: Malicious activity
Analysis date: February 02, 2024, 17:26:50
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

B05E1B131299F3D57323BDCA54B00570

SHA1:

82EBEB46687E7B285F588C056E52CCAAB87E464D

SHA256:

3ADB8147E461A11ADD25101D78205B61B54B6993022C8014B9A55B3197CA39C9

SSDEEP:

98304:t2OC4V3d1R3N6Dh9i+uxdqlli0YXZqYo50n54qktOPWL+nD+NBf1GhN2gXKotMiL:tBZJcbnV0LbeMOYH

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

  • SUSPICIOUS

    • Executable content was dropped or overwritten

    • Reads the Internet Settings

      • [email protected] (PID: 3096)
      • NavaShield.exe (PID: 3020)
      • control.exe (PID: 3624)
      • rundll32.exe (PID: 3608)
    • Starts itself from another location

      • NavaShield.exe (PID: 3020)
    • Uses RUNDLL32.EXE to load library

      • control.exe (PID: 3624)
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 268)
    • Reads the computer name

      • [email protected] (PID: 3096)
      • NavaShield.exe (PID: 3020)
      • NavaBridge.exe (PID: 3752)
      • wmpnscfg.exe (PID: 2576)
    • Manual execution by a user

    • Checks supported languages

      • [email protected] (PID: 3096)
      • NavaShield.exe (PID: 3020)
      • NavaBridge.exe (PID: 3752)
      • NavaDebugger.exe (PID: 2612)
      • wmpnscfg.exe (PID: 2576)
    • Create files in a temporary directory

      • [email protected] (PID: 3096)
      • NavaShield.exe (PID: 3020)
      • NavaBridge.exe (PID: 3752)
      • NavaDebugger.exe (PID: 2612)
    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 268)
    • Creates files or folders in the user directory

    • Reads CPU info

      • NavaShield.exe (PID: 3020)
    • Application launched itself

      • msedge.exe (PID: 3520)
      • msedge.exe (PID: 2916)
      • msedge.exe (PID: 2852)
      • msedge.exe (PID: 3704)
    • Reads the time zone

      • rundll32.exe (PID: 3608)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: 0x0001
ZipCompression: Deflated
ZipModifyDate: 2016:04:23 15:58:12
ZipCRC: 0x04ecc40d
ZipCompressedSize: 9761508
ZipUncompressedSize: 10148025
ZipFileName: [email protected]
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
92
Monitored processes
53
Malicious processes
2
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe [email protected] no specs [email protected] navashield.exe no specs navabridge.exe navadebugger.exe no specs control.exe no specs rundll32.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs sndvol.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs wmpnscfg.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
268"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\NavaShield.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
568"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=10 --mojo-platform-channel-handle=1484 --field-trial-handle=1300,i,8077193847377268645,8538694318401093011,131072 /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
696"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=7 --mojo-platform-channel-handle=2904 --field-trial-handle=1300,i,8077193847377268645,8538694318401093011,131072 /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
796"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1528 --field-trial-handle=1296,i,1259961750181503764,4081121125614934878,131072 /prefetch:3C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1028"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=entity_extraction_service.mojom.PageScreenshotProcessor --lang=en-US --service-sandbox-type=entity_extraction --mojo-platform-channel-handle=3660 --field-trial-handle=1344,i,6731337648325840458,12864709174954602403,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1056"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=asset_store.mojom.AssetStoreService --lang=en-US --service-sandbox-type=asset_store_service --mojo-platform-channel-handle=3852 --field-trial-handle=1300,i,8077193847377268645,8538694318401093011,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1216"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=2416 --field-trial-handle=1300,i,8077193847377268645,8538694318401093011,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1556"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3524 --field-trial-handle=1344,i,6731337648325840458,12864709174954602403,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1636"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=4184 --field-trial-handle=1300,i,8077193847377268645,8538694318401093011,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1692"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=2268 --field-trial-handle=1300,i,8077193847377268645,8538694318401093011,131072 /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
Total events
10 482
Read events
10 362
Write events
119
Delete events
1

Modification events

(PID) Process:(268) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(268) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(268) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(268) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(268) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(268) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(268) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(268) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(268) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3096) [email protected]Key:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
Executable files
14
Suspicious files
130
Text files
69
Unknown types
0

Dropped files

PID
Process
Filename
Type
3096[email protected]C:\Users\admin\AppData\Local\Temp\$inst\temp_0.tmp
MD5:
SHA256:
3096[email protected]C:\Users\admin\AppData\Local\Temp\$inst\5.tmpimage
MD5:110B42B9AA84606C7FF6177535D9ED77
SHA256:DDCD070A764F83C367631A205C833C4901293FE0A64C59916C82393F9AEE99AD
3096[email protected]C:\Nava Labs\Nava Shield\bridge.datbinary
MD5:E66F1107F995D52BCD90421B3CDC0DDE
SHA256:45FA6EACEA58E682C2EF2BB9E888CB6BF396C37B957FD144CA73C95699AD3C74
268WinRAR.exeC:\Users\admin\AppData\Local\Temp\NavaShield\[email protected]executable
MD5:1F13396FA59D38EBE76CCC587CCB11BB
SHA256:83ECB875F87150A88F4C3D496EB3CB5388CD8BAFDFF4879884ECECDBD1896E1D
3096[email protected]C:\Nava Labs\Nava Shield\install.logtext
MD5:33836EF8621FC8D2E5F3302FD3BFBC8C
SHA256:FE219EB5CC7DA3F928E816D65DCEC5FD8A727F34B026F681810DFCC2B9F395DA
3096[email protected]C:\Nava Labs\Nava Shield\NavaBridge Libs\MD5.dllexecutable
MD5:831295342C47B770BF7CC591A6916FA7
SHA256:8341ECC0938CA6D90B7E0F02AF2D7E6B571C948A03A99D54AF61C4557C78D656
3096[email protected]C:\Nava Labs\Nava Shield\NavaShield.exeexecutable
MD5:9D299E41BAE269641AF28A6C02B80EF6
SHA256:FCE1BC05FBE2DE83EE535E5CE0CEEE94F2B4F917CDCBE1F1F649F44BE25D4EC8
3096[email protected]C:\Nava Labs\Nava Shield\freeset.dattext
MD5:2C66614915A2EDAC8BD5489C957A2879
SHA256:FD242B6EAED612C71FF90B17D10D129FF9B4B4969291303458EE817FE2FB3F06
3096[email protected]C:\Nava Labs\Nava Shield\NavaShield Libs\MD5.dllexecutable
MD5:831295342C47B770BF7CC591A6916FA7
SHA256:8341ECC0938CA6D90B7E0F02AF2D7E6B571C948A03A99D54AF61C4557C78D656
3096[email protected]C:\Nava Labs\Nava Shield\NavaBridge Libs\Internet Encodings.dllexecutable
MD5:DE5EEFA1B686E3D32E3AE265392492BD
SHA256:A50E56DFB68410A7927ECD50F55044756B54868E920E462671162D1961BFE744
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
42
DNS requests
59
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3384
msedge.exe
GET
200
64.190.63.111:80
http://navashield.com/order/purchase?package=1&a=TNEQ7W7U4W&reid=NEUATK2000&license=hcR138jkUkCddqL0q9bCeg==
unknown
compressed
7.12 Kb
GET
64.190.63.111:80
http://navashield.com/nava/offers?a=TNEQ7W7U4W&v=1&b=/AAp7yGoXwlj3THRnE9G5A==
unknown
3384
msedge.exe
GET
200
64.190.63.111:80
http://navashield.com/search/tsc.php?200=MjE4MTQ2ODUz&21=MjE2LjI0LjIxNi4xODg=&681=MTcwNjg5NTA0MzRlZjc3MWZhYmQ3ZmE3N2VlN2RiZDNhOGMyMGFiMmJl&crc=d1491ca3d8b72525622e871ace97bf1530767728&cv=1
unknown
compressed
7.12 Kb
3384
msedge.exe
GET
200
205.234.175.175:80
http://img.sedoparking.com/templates/logos/sedo_logo.png
unknown
image
14.7 Kb
3384
msedge.exe
GET
200
205.234.175.175:80
http://img.sedoparking.com/templates/bg/arrows.png
unknown
image
12.3 Kb
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
unknown
4
System
192.168.100.255:137
unknown
1080
svchost.exe
224.0.0.252:5355
unknown
3752
NavaBridge.exe
64.190.63.111:80
navashield.com
SEDO GmbH
DE
unknown
3704
msedge.exe
239.255.255.250:1900
unknown
3300
msedge.exe
13.107.42.16:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
3300
msedge.exe
23.32.186.57:443
go.microsoft.com
AKAMAI-AS
BR
unknown
3300
msedge.exe
204.79.197.239:443
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
3300
msedge.exe
88.221.169.152:443
www.microsoft.com
AKAMAI-AS
DE
unknown
3300
msedge.exe
69.192.160.112:443
support.microsoft.com
AKAMAI-AS
DE
unknown

DNS requests

Domain
IP
Reputation
navashield.com
  • 64.190.63.111
unknown
config.edge.skype.com
  • 13.107.42.16
unknown
go.microsoft.com
  • 23.32.186.57
unknown
edge.microsoft.com
  • 204.79.197.239
  • 13.107.21.239
unknown
www.microsoft.com
  • 88.221.169.152
unknown
support.microsoft.com
  • 69.192.160.112
unknown
docs.microsoft.com
  • 2.23.66.17
unknown
learn.microsoft.com
  • 88.221.170.101
unknown
wcpstatic.microsoft.com
  • 13.107.246.62
  • 13.107.213.62
unknown
js.monitor.azure.com
  • 13.107.213.45
  • 13.107.246.45
unknown

Threats

PID
Process
Class
Message
Not Suspicious Traffic
INFO [ANY.RUN] Azure Front Door domain observed in TLS SNI ( .azurefd .net)
No debug info