File name:

NavaShield.zip

Full analysis: https://app.any.run/tasks/b323de93-7498-4adc-80b9-145311e8adef
Verdict: Malicious activity
Analysis date: July 10, 2020, 13:35:51
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

B05E1B131299F3D57323BDCA54B00570

SHA1:

82EBEB46687E7B285F588C056E52CCAAB87E464D

SHA256:

3ADB8147E461A11ADD25101D78205B61B54B6993022C8014B9A55B3197CA39C9

SSDEEP:

196608:RIqrrCcUdFJp1YNYbsVNCpsF98DOV9Qz7FFEClC6j2LzfFXkoZc1kXa:FCcUdFX5gNL8oQz7FFECl3j2ffF0L1Ua

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Endermanch@NavaShield.exe (PID: 2304)
      • Endermanch@NavaShield.exe (PID: 1384)
      • NavaShield.exe (PID: 2596)
      • NavaDebugger.exe (PID: 3124)
      • NavaBridge.exe (PID: 2604)
    • Changes the autorun value in the registry

      • Endermanch@NavaShield.exe (PID: 2304)
    • Loads dropped or rewritten executable

      • NavaShield.exe (PID: 2596)
      • NavaBridge.exe (PID: 2604)
      • NavaDebugger.exe (PID: 3124)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 124)
      • Endermanch@NavaShield.exe (PID: 2304)
    • Creates files in the user directory

      • Endermanch@NavaShield.exe (PID: 2304)
    • Creates a software uninstall entry

      • Endermanch@NavaShield.exe (PID: 2304)
    • Starts itself from another location

      • NavaShield.exe (PID: 2596)
  • INFO

    • Manual execution by user

      • WINWORD.EXE (PID: 4024)
    • Creates files in the user directory

      • WINWORD.EXE (PID: 4024)
    • Reads Microsoft Office registry keys

      • WINWORD.EXE (PID: 4024)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: 0x0001
ZipCompression: Deflated
ZipModifyDate: 2016:04:23 15:58:06
ZipCRC: 0x04ecc40d
ZipCompressedSize: 9761508
ZipUncompressedSize: 10148025
ZipFileName: Endermanch@NavaShield.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
45
Monitored processes
7
Malicious processes
4
Suspicious processes
1

Behavior graph

Click at the process to see the details
drop and start drop and start start drop and start winrar.exe endermanch@navashield.exe no specs endermanch@navashield.exe navashield.exe no specs navabridge.exe no specs navadebugger.exe no specs winword.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
124"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\NavaShield.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
1384"C:\Users\admin\AppData\Local\Temp\Rar$EXb124.964\Endermanch@NavaShield.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXb124.964\Endermanch@NavaShield.exeWinRAR.exe
User:
admin
Company:
Nava Labs
Integrity Level:
MEDIUM
Description:
Nava Shield 4.1 Installation
Exit code:
3221226540
Version:
4.1
Modules
Images
c:\users\admin\appdata\local\temp\rar$exb124.964\endermanch@navashield.exe
c:\systemroot\system32\ntdll.dll
2304"C:\Users\admin\AppData\Local\Temp\Rar$EXb124.964\Endermanch@NavaShield.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXb124.964\Endermanch@NavaShield.exe
WinRAR.exe
User:
admin
Company:
Nava Labs
Integrity Level:
HIGH
Description:
Nava Shield 4.1 Installation
Exit code:
0
Version:
4.1
Modules
Images
c:\users\admin\appdata\local\temp\rar$exb124.964\endermanch@navashield.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2596"C:\Nava Labs\Nava Shield\NavaShield.exe" C:\Nava Labs\Nava Shield\NavaShield.exeEndermanch@NavaShield.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\nava labs\nava shield\navashield.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2604"C:\Nava Labs\Nava Shield\NavaBridge.exe" C:\Nava Labs\Nava Shield\NavaBridge.exeNavaShield.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\nava labs\nava shield\navabridge.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
3124"C:\Nava Labs\Nava Shield\NavaDebugger.exe" C:\Nava Labs\Nava Shield\NavaDebugger.exeNavaShield.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\nava labs\nava shield\navadebugger.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
4024"C:\Program Files\Microsoft Office\Office14\WINWORD.EXE" /n "C:\Users\admin\Desktop\effectso.rtf"C:\Program Files\Microsoft Office\Office14\WINWORD.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Word
Exit code:
0
Version:
14.0.6024.1000
Modules
Images
c:\program files\microsoft office\office14\winword.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
Total events
1 685
Read events
1 333
Write events
212
Delete events
140

Modification events

(PID) Process:(124) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(124) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(124) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(124) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12F\52C64B7E
Operation:writeName:@C:\Windows\system32\NetworkExplorer.dll,-1
Value:
Network
(PID) Process:(124) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\NavaShield.zip
(PID) Process:(124) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(124) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(124) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(124) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(124) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface
Operation:writeName:ShowPassword
Value:
0
Executable files
13
Suspicious files
9
Text files
8
Unknown types
9

Dropped files

PID
Process
Filename
Type
2304Endermanch@NavaShield.exeC:\Users\admin\AppData\Local\Temp\$inst\temp_0.tmp
MD5:
SHA256:
2304Endermanch@NavaShield.exeC:\Users\admin\AppData\Local\Temp\$inst\0001.tmp
MD5:
SHA256:
124WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb124.964\Endermanch@NavaShield.exeexecutable
MD5:1F13396FA59D38EBE76CCC587CCB11BB
SHA256:83ECB875F87150A88F4C3D496EB3CB5388CD8BAFDFF4879884ECECDBD1896E1D
2304Endermanch@NavaShield.exeC:\Users\admin\AppData\Local\Temp\$inst\5.tmpimage
MD5:110B42B9AA84606C7FF6177535D9ED77
SHA256:DDCD070A764F83C367631A205C833C4901293FE0A64C59916C82393F9AEE99AD
2304Endermanch@NavaShield.exeC:\Nava Labs\Nava Shield\bridge.datbinary
MD5:E66F1107F995D52BCD90421B3CDC0DDE
SHA256:45FA6EACEA58E682C2EF2BB9E888CB6BF396C37B957FD144CA73C95699AD3C74
2304Endermanch@NavaShield.exeC:\Users\admin\AppData\Local\Temp\$inst\4.tmpimage
MD5:5252FE76395E49A85C435D3431EE3927
SHA256:5CA7C69BA0AA28276A718706CAE4E61520CB45FB34F32DE9FAC019B0574B2C1C
2304Endermanch@NavaShield.exeC:\Nava Labs\Nava Shield\NavaMod.dllexecutable
MD5:3D7F80FB0534D24F95EE377C40B72FB3
SHA256:ABD84867D63A5449101B7171B1CC3907C44D7D327EA97D45B22A1015CC3AF4DC
2304Endermanch@NavaShield.exeC:\Nava Labs\Nava Shield\NavaBridge.exeexecutable
MD5:6F89DF4CDE193C0636C3D497CF1A17BF
SHA256:E7F05380E90DFB15B91B8BBC2AE48A04BA84D573B3C9F7D81BCC12F814215929
2304Endermanch@NavaShield.exeC:\Nava Labs\Nava Shield\NavaShield Libs\Appearance Pak.dllexecutable
MD5:FCF3AC25F11BA7E8B31C4BAF1910F7A6
SHA256:E5B3249FBEEA8395FD56C20511BFCFDB2B2632D3C8D517B943466A4E47F97B5C
2304Endermanch@NavaShield.exeC:\Nava Labs\Nava Shield\NavaDebugger Libs\MD5.dllexecutable
MD5:831295342C47B770BF7CC591A6916FA7
SHA256:8341ECC0938CA6D90B7E0F02AF2D7E6B571C948A03A99D54AF61C4557C78D656
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info