File name:

NavaShield.zip

Full analysis: https://app.any.run/tasks/b323de93-7498-4adc-80b9-145311e8adef
Verdict: Malicious activity
Analysis date: July 10, 2020, 13:35:51
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

B05E1B131299F3D57323BDCA54B00570

SHA1:

82EBEB46687E7B285F588C056E52CCAAB87E464D

SHA256:

3ADB8147E461A11ADD25101D78205B61B54B6993022C8014B9A55B3197CA39C9

SSDEEP:

196608:RIqrrCcUdFJp1YNYbsVNCpsF98DOV9Qz7FFEClC6j2LzfFXkoZc1kXa:FCcUdFX5gNL8oQz7FFECl3j2ffF0L1Ua

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Endermanch@NavaShield.exe (PID: 2304)
      • NavaDebugger.exe (PID: 3124)
      • Endermanch@NavaShield.exe (PID: 1384)
      • NavaShield.exe (PID: 2596)
      • NavaBridge.exe (PID: 2604)
    • Loads dropped or rewritten executable

      • NavaDebugger.exe (PID: 3124)
      • NavaShield.exe (PID: 2596)
      • NavaBridge.exe (PID: 2604)
    • Changes the autorun value in the registry

      • Endermanch@NavaShield.exe (PID: 2304)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 124)
      • Endermanch@NavaShield.exe (PID: 2304)
    • Creates a software uninstall entry

      • Endermanch@NavaShield.exe (PID: 2304)
    • Creates files in the user directory

      • Endermanch@NavaShield.exe (PID: 2304)
    • Starts itself from another location

      • NavaShield.exe (PID: 2596)
  • INFO

    • Creates files in the user directory

      • WINWORD.EXE (PID: 4024)
    • Reads Microsoft Office registry keys

      • WINWORD.EXE (PID: 4024)
    • Manual execution by user

      • WINWORD.EXE (PID: 4024)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: 0x0001
ZipCompression: Deflated
ZipModifyDate: 2016:04:23 15:58:06
ZipCRC: 0x04ecc40d
ZipCompressedSize: 9761508
ZipUncompressedSize: 10148025
ZipFileName: Endermanch@NavaShield.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
45
Monitored processes
7
Malicious processes
4
Suspicious processes
1

Behavior graph

Click at the process to see the details
drop and start drop and start start drop and start winrar.exe endermanch@navashield.exe no specs endermanch@navashield.exe navashield.exe no specs navabridge.exe no specs navadebugger.exe no specs winword.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
124"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\NavaShield.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
1384"C:\Users\admin\AppData\Local\Temp\Rar$EXb124.964\Endermanch@NavaShield.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXb124.964\Endermanch@NavaShield.exeWinRAR.exe
User:
admin
Company:
Nava Labs
Integrity Level:
MEDIUM
Description:
Nava Shield 4.1 Installation
Exit code:
3221226540
Version:
4.1
Modules
Images
c:\users\admin\appdata\local\temp\rar$exb124.964\endermanch@navashield.exe
c:\systemroot\system32\ntdll.dll
2304"C:\Users\admin\AppData\Local\Temp\Rar$EXb124.964\Endermanch@NavaShield.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXb124.964\Endermanch@NavaShield.exe
WinRAR.exe
User:
admin
Company:
Nava Labs
Integrity Level:
HIGH
Description:
Nava Shield 4.1 Installation
Exit code:
0
Version:
4.1
Modules
Images
c:\users\admin\appdata\local\temp\rar$exb124.964\endermanch@navashield.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2596"C:\Nava Labs\Nava Shield\NavaShield.exe" C:\Nava Labs\Nava Shield\NavaShield.exeEndermanch@NavaShield.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\nava labs\nava shield\navashield.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2604"C:\Nava Labs\Nava Shield\NavaBridge.exe" C:\Nava Labs\Nava Shield\NavaBridge.exeNavaShield.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\nava labs\nava shield\navabridge.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
3124"C:\Nava Labs\Nava Shield\NavaDebugger.exe" C:\Nava Labs\Nava Shield\NavaDebugger.exeNavaShield.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\nava labs\nava shield\navadebugger.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
4024"C:\Program Files\Microsoft Office\Office14\WINWORD.EXE" /n "C:\Users\admin\Desktop\effectso.rtf"C:\Program Files\Microsoft Office\Office14\WINWORD.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Word
Exit code:
0
Version:
14.0.6024.1000
Modules
Images
c:\program files\microsoft office\office14\winword.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
Total events
1 685
Read events
1 333
Write events
212
Delete events
140

Modification events

(PID) Process:(124) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(124) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(124) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(124) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12F\52C64B7E
Operation:writeName:@C:\Windows\system32\NetworkExplorer.dll,-1
Value:
Network
(PID) Process:(124) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\NavaShield.zip
(PID) Process:(124) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(124) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(124) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(124) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(124) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface
Operation:writeName:ShowPassword
Value:
0
Executable files
13
Suspicious files
9
Text files
8
Unknown types
9

Dropped files

PID
Process
Filename
Type
2304Endermanch@NavaShield.exeC:\Users\admin\AppData\Local\Temp\$inst\temp_0.tmp
MD5:
SHA256:
2304Endermanch@NavaShield.exeC:\Users\admin\AppData\Local\Temp\$inst\0001.tmp
MD5:
SHA256:
2304Endermanch@NavaShield.exeC:\Nava Labs\Nava Shield\config.datbinary
MD5:389BF6E15AE0A7250F454DA52AA7CED5
SHA256:5993325ACFE309946C176737A019AA16E22B921FA6387B766BF8BC8A504E220D
2304Endermanch@NavaShield.exeC:\Users\admin\AppData\Local\Temp\$inst\2.tmpcompressed
MD5:37A639FC899D0C312AF607BE808B5E4D
SHA256:8ECAD2A44EBB53CEF96FDF4D6A695B729FC2027408421A194F290A31E28B9790
124WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb124.964\Endermanch@NavaShield.exeexecutable
MD5:1F13396FA59D38EBE76CCC587CCB11BB
SHA256:83ECB875F87150A88F4C3D496EB3CB5388CD8BAFDFF4879884ECECDBD1896E1D
2304Endermanch@NavaShield.exeC:\Nava Labs\Nava Shield\install.logtext
MD5:33836EF8621FC8D2E5F3302FD3BFBC8C
SHA256:FE219EB5CC7DA3F928E816D65DCEC5FD8A727F34B026F681810DFCC2B9F395DA
2304Endermanch@NavaShield.exeC:\Nava Labs\Nava Shield\NavaBridge Libs\Browser Plugin.dllexecutable
MD5:912924F628E277BE9CC28A5F2A990CB9
SHA256:BD474C5AAFCAA12F20DA5ECB29E17555B953ECA46B4F56588A72672A36D4A8EB
2304Endermanch@NavaShield.exeC:\Nava Labs\Nava Shield\NavaMod.dllexecutable
MD5:3D7F80FB0534D24F95EE377C40B72FB3
SHA256:ABD84867D63A5449101B7171B1CC3907C44D7D327EA97D45B22A1015CC3AF4DC
2304Endermanch@NavaShield.exeC:\Nava Labs\Nava Shield\NavaDebugger Libs\MD5.dllexecutable
MD5:831295342C47B770BF7CC591A6916FA7
SHA256:8341ECC0938CA6D90B7E0F02AF2D7E6B571C948A03A99D54AF61C4557C78D656
2304Endermanch@NavaShield.exeC:\Nava Labs\Nava Shield\NavaShield Libs\MD5.dllexecutable
MD5:831295342C47B770BF7CC591A6916FA7
SHA256:8341ECC0938CA6D90B7E0F02AF2D7E6B571C948A03A99D54AF61C4557C78D656
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info