| File name: | NSFOCUS-Agent-Windows-1.0.4 (4).zip |
| Full analysis: | https://app.any.run/tasks/e8bd72c9-080f-493b-880e-0d2d14ff8e20 |
| Verdict: | Malicious activity |
| Analysis date: | July 22, 2021, 02:39:27 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract |
| MD5: | B3DA64C1838B935E2F59B9B3F535714A |
| SHA1: | 782C6107B23F5249915BE9CB3AB59430DDF9C756 |
| SHA256: | 3DAFBC408AD71EB023C7A45390AAE1C760E61348507E1618A88DD490CB5A6B6C |
| SSDEEP: | 6144:+ffyWrWgorgLuUN4/BRjYnZOtGd/H8qU1n/CCF7IL6AYf85:mvrWtrgyp/EnZOtiK3F7IeAYA |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipFileName: | setup.dat |
|---|---|
| ZipUncompressedSize: | 379047 |
| ZipCompressedSize: | 379047 |
| ZipCRC: | 0x5742e0cc |
| ZipModifyDate: | 2021:07:21 15:23:15 |
| ZipCompression: | None |
| ZipBitFlag: | - |
| ZipRequiredVersion: | 20 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 756 | "C:\Users\admin\Desktop\setup.exe" | C:\Users\admin\Desktop\setup.exe | — | Explorer.EXE | |||||||||||
User: admin Company: NSFOCUS Integrity Level: MEDIUM Description: NSFOCUS installation launcher Exit code: 3221226540 Version: 1.0.0.1 Modules
| |||||||||||||||
| 936 | "C:\Program Files\TAP-Windows\bin\devcon.exe" hwids tap0901 | C:\Program Files\TAP-Windows\bin\devcon.exe | — | ns1D04.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Setup API Exit code: 0 Version: 6.1.7600.16385 (win7_wdk.100208-1538) Modules
| |||||||||||||||
| 1032 | C:\Windows\System32\svchost.exe -k nsfagent | C:\Windows\System32\svchost.exe | services.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Host Process for Windows Services Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2248 | "C:\Users\admin\AppData\Local\Temp\nsj6110.tmp\ns1D04.tmp" "C:\Program Files\TAP-Windows\bin\devcon.exe" hwids tap0901 | C:\Users\admin\AppData\Local\Temp\nsj6110.tmp\ns1D04.tmp | — | tap-windows-9.9.2_3.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 2524 | DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{1a5ab17a-0eba-73ad-ab5a-741879f5b911}\oemwin2k.inf" "0" "6d14a44ff" "00000584" "WinSta0\Default" "000005BC" "208" "c:\program files\tap-windows\driver" | C:\Windows\system32\DrvInst.exe | svchost.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Driver Installation Module Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2572 | rundll32.exe C:\Windows\system32\pnpui.dll,InstallSecurityPromptRunDllW 20 Global\{04b53b29-5436-7bf2-37eb-a5196445654d} Global\{5ebf33b0-2e13-128e-bb14-675506aa5a0b} C:\Windows\System32\DriverStore\Temp\{44efe033-33cc-5771-4fe5-8011c064af6b}\oemwin2k.inf C:\Windows\System32\DriverStore\Temp\{44efe033-33cc-5771-4fe5-8011c064af6b}\tap0901.cat | C:\Windows\system32\rundll32.exe | — | DrvInst.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows host process (Rundll32) Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2668 | "C:\Users\admin\AppData\Local\Temp\nsj6110.tmp\ns1D82.tmp" "C:\Program Files\TAP-Windows\bin\devcon.exe" install "C:\Program Files\TAP-Windows\driver\OemWin2k.inf" tap0901 | C:\Users\admin\AppData\Local\Temp\nsj6110.tmp\ns1D82.tmp | — | tap-windows-9.9.2_3.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 3052 | "C:\Users\admin\Desktop\setup.exe" | C:\Users\admin\Desktop\setup.exe | — | Explorer.EXE | |||||||||||
User: admin Company: NSFOCUS Integrity Level: MEDIUM Description: NSFOCUS installation launcher Exit code: 3221226540 Version: 1.0.0.1 Modules
| |||||||||||||||
| 3176 | DrvInst.exe "2" "211" "ROOT\NET\0000" "C:\Windows\INF\oem5.inf" "oemwin2k.inf:tap0901:tap0901.ndi:9.0.0.9:tap0901" "6d14a44ff" "00000584" "000005DC" "000005E0" | C:\Windows\system32\DrvInst.exe | svchost.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Driver Installation Module Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3368 | "C:\Users\admin\Desktop\setup.exe" | C:\Users\admin\Desktop\setup.exe | Explorer.EXE | ||||||||||||
User: admin Company: NSFOCUS Integrity Level: HIGH Description: NSFOCUS installation launcher Exit code: 0 Version: 1.0.0.1 Modules
| |||||||||||||||
| (PID) Process: | (3968) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (3968) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (3968) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3968) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip | |||
| (PID) Process: | (3968) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\NSFOCUS-Agent-Windows-1.0.4 (4).zip | |||
| (PID) Process: | (3968) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (3968) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (3968) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (3968) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (3976) setup.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\nsfagent\nsfagent |
| Operation: | write | Name: | ServiceDll |
Value: %SystemRoot%\system32\nsfagent.dll | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3976 | setup.exe | C:\Windows\system32\nsfagenu.dll | executable | |
MD5:— | SHA256:— | |||
| 3968 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3968.42010\setup.exe | executable | |
MD5:— | SHA256:— | |||
| 3976 | setup.exe | C:\Windows\system32\nsfagent.dll | executable | |
MD5:— | SHA256:— | |||
| 3968 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3968.42010\setup.dat | binary | |
MD5:— | SHA256:— | |||
| 3976 | setup.exe | C:\Users\admin\AppData\Local\Temp\tap-windows-9.9.2_3.exe | executable | |
MD5:AC9B2624EF366742C9AD32B86225A251 | SHA256:02E1013EE8D548EDC3FBAFAB672977EA8C677CF1F0B57018652FCF2A2411CBFB | |||
| 3872 | tap-windows-9.9.2_3.exe | C:\Users\admin\AppData\Local\Temp\nsj6110.tmp\ioSpecial.ini | text | |
MD5:E2D5070BC28DB1AC745613689FF86067 | SHA256:D95AED234F932A1C48A2B1B0D98C60CA31F962310C03158E2884AB4DDD3EA1E0 | |||
| 3616 | devcon.exe | C:\Windows\INF\setupapi.dev.log | text | |
MD5:— | SHA256:— | |||
| 3616 | devcon.exe | C:\Windows\INF\setupapi.app.log | ini | |
MD5:— | SHA256:— | |||
| 3872 | tap-windows-9.9.2_3.exe | C:\Program Files\TAP-Windows\driver\tap0901.sys | executable | |
MD5:432D9D823C4C26B6070C41BAD4404CE4 | SHA256:741B41F7467D312AF4CC733EA31F647FBCD06985CBB6A14117E8A87A6F7B06F5 | |||
| 3872 | tap-windows-9.9.2_3.exe | C:\Program Files\TAP-Windows\license.txt | text | |
MD5:E313073B8D6B53042307B371EB609D37 | SHA256:7423B37197A8FDB1450C0AB34634B505D51B6FE7E6C99EEBE6252637097BB615 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
1032 | svchost.exe | 103.213.96.209:17047 | — | — | CN | unknown |
— | — | 103.213.96.209:17047 | — | — | CN | unknown |
— | — | 142.250.181.238:443 | clients2.google.com | Google Inc. | US | whitelisted |
— | — | 142.250.184.237:443 | accounts.google.com | Google Inc. | US | suspicious |
— | — | 142.250.185.132:443 | www.google.com | Google Inc. | US | whitelisted |
— | — | 142.250.184.202:443 | fonts.googleapis.com | Google Inc. | US | whitelisted |
— | — | 142.250.186.99:443 | www.gstatic.com | Google Inc. | US | whitelisted |
— | — | 142.250.186.46:443 | apis.google.com | Google Inc. | US | whitelisted |
— | — | 142.250.185.238:443 | ogs.google.com | Google Inc. | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
clients2.google.com |
| whitelisted |
accounts.google.com |
| shared |
www.google.com |
| malicious |
fonts.googleapis.com |
| whitelisted |
www.gstatic.com |
| whitelisted |
fonts.gstatic.com |
| whitelisted |
apis.google.com |
| whitelisted |
ogs.google.com |
| whitelisted |
clientservices.googleapis.com |
| whitelisted |
Process | Message |
|---|---|
setup.exe | �� [TID: 2136 ] [Install ] [Line: 2896 ] | -------- start to parse msi config --------
|
setup.exe | �� [TID: 2136 ] [Install ] [Line: 2965 ] | get config username is NULL
|
setup.exe | �� [TID: 2136 ] [Install ] [Line: 2969 ] | config service=nsfagent,group=nsfagent,type=1
|
setup.exe | �� [TID: 2136 ] [Install ] [Line: 2974 ] | -------- start to INSTALL --------
|
setup.exe | �� [TID: 2136 ] [Install ] [Line: 963 ] | RegQueryValueExA 1 nsfagent error 2
|
setup.exe | �� [TID: 2136 ] [Install ] [Line: 2477 ] | -------- start to install service=nsfagent,group=nsfagent --------
|
setup.exe | �� [TID: 2136 ] [Install ] [Line: 2502 ] | -------- start to set service reg --------
|
setup.exe | �� [TID: 2136 ] [Install ] [Line: 2511 ] | -------- start to descompress dll --------
|
setup.exe | �� [TID: 2136 ] [Install ] [Line: 2520 ] | -------- start to start service --------
|