File name:

navegante-1.1.1-win64-installer.exe

Full analysis: https://app.any.run/tasks/21e7eff6-46d9-45a7-adc8-3a7d0fb32110
Verdict: Malicious activity
Analysis date: January 29, 2025, 10:23:55
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
arch-doc
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 10 sections
MD5:

8F676C3D419F72E11F3DE116D4E20767

SHA1:

52ACB53E8C6153F68E2DC5BD846D9C816282D500

SHA256:

4002FE0FBE5C39072D63F7961A06846F694504255B0137C9A8D238BB2E5819F4

SSDEEP:

98304:k+cD4dnzFDmlFblXJghUyJY95uSvH9U6iRylXuer20TIBs63yjF151XI0RrgMEpY:8UUUbfbLNuJy2JuxzJHc

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • navegante-1.1.1-win64-installer.exe (PID: 6220)
    • Create files in the Startup directory

      • navegante-1.1.1-win64-installer.tmp (PID: 6240)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • navegante-1.1.1-win64-installer.tmp (PID: 6240)
      • navegante-1.1.1-win64-installer.exe (PID: 6220)
    • Checks for Java to be installed

      • navegante.exe (PID: 6932)
  • INFO

    • Checks supported languages

      • navegante-1.1.1-win64-installer.exe (PID: 6220)
      • navegante.exe (PID: 6932)
      • javaw.exe (PID: 6952)
    • Create files in a temporary directory

      • navegante-1.1.1-win64-installer.exe (PID: 6220)
      • javaw.exe (PID: 6952)
    • Creates files or folders in the user directory

      • navegante-1.1.1-win64-installer.tmp (PID: 6240)
      • javaw.exe (PID: 6952)
    • Creates a software uninstall entry

      • navegante-1.1.1-win64-installer.tmp (PID: 6240)
    • Creates files in the program directory

      • javaw.exe (PID: 6952)
    • Reads the computer name

      • javaw.exe (PID: 6952)
    • Reads the machine GUID from the registry

      • javaw.exe (PID: 6952)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (65.1)
.exe | Win32 EXE PECompact compressed (generic) (24.6)
.dll | Win32 Dynamic Link Library (generic) (3.9)
.exe | Win32 Executable (generic) (2.6)
.exe | Win16/32 Executable Delphi generic (1.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2022:04:14 16:10:23+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 741888
InitializedDataSize: 66560
UninitializedDataSize: -
EntryPoint: 0xb5eec
OSVersion: 6.1
ImageVersion: 6
SubsystemVersion: 6.1
Subsystem: Windows GUI
FileVersionNumber: 0.0.0.0
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: TML
FileDescription: navegante Setup
FileVersion:
LegalCopyright:
OriginalFileName:
ProductName: navegante
ProductVersion: 1.1.1
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
132
Monitored processes
6
Malicious processes
1
Suspicious processes
1

Behavior graph

Click at the process to see the details
start navegante-1.1.1-win64-installer.exe navegante-1.1.1-win64-installer.tmp navegante.exe no specs javaw.exe icacls.exe no specs conhost.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
6220"C:\Users\admin\AppData\Local\Temp\navegante-1.1.1-win64-installer.exe" C:\Users\admin\AppData\Local\Temp\navegante-1.1.1-win64-installer.exe
explorer.exe
User:
admin
Company:
TML
Integrity Level:
MEDIUM
Description:
navegante Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\appdata\local\temp\navegante-1.1.1-win64-installer.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
6240"C:\Users\admin\AppData\Local\Temp\is-KHCSG.tmp\navegante-1.1.1-win64-installer.tmp" /SL5="$70298,8619565,809472,C:\Users\admin\AppData\Local\Temp\navegante-1.1.1-win64-installer.exe" C:\Users\admin\AppData\Local\Temp\is-KHCSG.tmp\navegante-1.1.1-win64-installer.tmp
navegante-1.1.1-win64-installer.exe
User:
admin
Company:
TML
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\windows\syswow64\sspicli.dll
c:\windows\syswow64\explorerframe.dll
c:\windows\syswow64\sfc.dll
c:\windows\syswow64\sfc_os.dll
c:\windows\syswow64\setupapi.dll
c:\windows\syswow64\cfgmgr32.dll
c:\windows\syswow64\propsys.dll
c:\windows\syswow64\linkinfo.dll
c:\windows\syswow64\ntshrui.dll
c:\windows\syswow64\srvcli.dll
6932"C:\Users\admin\AppData\Local\Navegante\navegante.exe"C:\Users\admin\AppData\Local\Navegante\navegante.exenavegante-1.1.1-win64-installer.tmp
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\navegante\navegante.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
6952"C:\Program Files\Java\jre1.8.0_271\bin\javaw.exe" -Djava.library.path=C:\Windows\System32;bin/ -jar "C:\Users\admin\AppData\Local\Navegante\navegante.exe"C:\Program Files\Java\jre1.8.0_271\bin\javaw.exe
navegante.exe
User:
admin
Company:
Oracle Corporation
Integrity Level:
MEDIUM
Description:
Java(TM) Platform SE binary
Version:
8.0.2710.9
Modules
Images
c:\program files\java\jre1.8.0_271\bin\javaw.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
7048C:\WINDOWS\system32\icacls.exe C:\ProgramData\Oracle\Java\.oracle_jre_usage /grant "everyone":(OI)(CI)MC:\Windows\System32\icacls.exejavaw.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\icacls.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
7056\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeicacls.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
867
Read events
843
Write events
24
Delete events
0

Modification events

(PID) Process:(6240) navegante-1.1.1-win64-installer.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\E5B11362-8B69-459F-A02D-E4998968A631_is1
Operation:writeName:Inno Setup: Setup Version
Value:
6.2.1
(PID) Process:(6240) navegante-1.1.1-win64-installer.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\E5B11362-8B69-459F-A02D-E4998968A631_is1
Operation:writeName:Inno Setup: App Path
Value:
C:\Users\admin\AppData\Local\Navegante
(PID) Process:(6240) navegante-1.1.1-win64-installer.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\E5B11362-8B69-459F-A02D-E4998968A631_is1
Operation:writeName:InstallLocation
Value:
C:\Users\admin\AppData\Local\Navegante\
(PID) Process:(6240) navegante-1.1.1-win64-installer.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\E5B11362-8B69-459F-A02D-E4998968A631_is1
Operation:writeName:Inno Setup: Icon Group
Value:
(Default)
(PID) Process:(6240) navegante-1.1.1-win64-installer.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\E5B11362-8B69-459F-A02D-E4998968A631_is1
Operation:writeName:Inno Setup: User
Value:
admin
(PID) Process:(6240) navegante-1.1.1-win64-installer.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\E5B11362-8B69-459F-A02D-E4998968A631_is1
Operation:writeName:Inno Setup: Selected Tasks
Value:
desktopicon,autostarticon
(PID) Process:(6240) navegante-1.1.1-win64-installer.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\E5B11362-8B69-459F-A02D-E4998968A631_is1
Operation:writeName:Inno Setup: Deselected Tasks
Value:
(PID) Process:(6240) navegante-1.1.1-win64-installer.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\E5B11362-8B69-459F-A02D-E4998968A631_is1
Operation:writeName:Inno Setup: Language
Value:
english
(PID) Process:(6240) navegante-1.1.1-win64-installer.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\E5B11362-8B69-459F-A02D-E4998968A631_is1
Operation:writeName:DisplayName
Value:
navegante 1.1.1
(PID) Process:(6240) navegante-1.1.1-win64-installer.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\E5B11362-8B69-459F-A02D-E4998968A631_is1
Operation:writeName:UninstallString
Value:
"C:\Users\admin\AppData\Local\Navegante\unins000.exe"
Executable files
30
Suspicious files
27
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
6240navegante-1.1.1-win64-installer.tmpC:\Users\admin\AppData\Local\Navegante\bin\is-T1N67.tmpexecutable
MD5:2ACD45C039F374695FC7ED7DCC2627D3
SHA256:9ABB918A4C9FA0BAFC065F2CFDA52AEA0EA7D0D63AE76E89E738F3372556D912
6240navegante-1.1.1-win64-installer.tmpC:\Users\admin\AppData\Local\Navegante\unins000.exeexecutable
MD5:65A5CC7AF6B57E084C1CE9F7285B7C59
SHA256:53CD256C4282F70B3D97871F699E0A941453C68F1FAA86C801D74C76D8050365
6240navegante-1.1.1-win64-installer.tmpC:\Users\admin\AppData\Local\Navegante\bin\is-OLNON.tmpexecutable
MD5:4A99F69F30572F42ADA03A794E0BF7B0
SHA256:5135DAF3C9D03BF9436AAD2172A7719CD7A4B198B38033BEF649413AC68DFD30
6240navegante-1.1.1-win64-installer.tmpC:\Users\admin\AppData\Local\Navegante\bin\api_os.dllexecutable
MD5:2ACD45C039F374695FC7ED7DCC2627D3
SHA256:9ABB918A4C9FA0BAFC065F2CFDA52AEA0EA7D0D63AE76E89E738F3372556D912
6240navegante-1.1.1-win64-installer.tmpC:\Users\admin\AppData\Local\Navegante\bin\vrc.dllexecutable
MD5:4A99F69F30572F42ADA03A794E0BF7B0
SHA256:5135DAF3C9D03BF9436AAD2172A7719CD7A4B198B38033BEF649413AC68DFD30
6220navegante-1.1.1-win64-installer.exeC:\Users\admin\AppData\Local\Temp\is-KHCSG.tmp\navegante-1.1.1-win64-installer.tmpexecutable
MD5:BBEAD3C79D2E43B129D645E40401ED10
SHA256:E08F11D6B7474143E30682A94E559B911DD2AE4F2EF2803EB834C4D28FA99920
6240navegante-1.1.1-win64-installer.tmpC:\Users\admin\AppData\Local\Navegante\is-GNO6N.tmpexecutable
MD5:65A5CC7AF6B57E084C1CE9F7285B7C59
SHA256:53CD256C4282F70B3D97871F699E0A941453C68F1FAA86C801D74C76D8050365
6240navegante-1.1.1-win64-installer.tmpC:\Users\admin\AppData\Local\Navegante\lib\is-EBFBM.tmpjava
MD5:303BAF002CE6D382198090AEDD9D79A2
SHA256:B3E9F6D63A790109BF0D056611FBED1CF69055826DEFEB9894A71369D246ED63
6240navegante-1.1.1-win64-installer.tmpC:\Users\admin\AppData\Local\Navegante\lib\jackson-core-2.12.6.jarjava
MD5:3976126E023F2969B4267963FE841F43
SHA256:0026CFF293BDBA389FBBBC67A20FDD5F73E091554AB46671EFA654C25C807EE6
6240navegante-1.1.1-win64-installer.tmpC:\Users\admin\AppData\Local\Navegante\lib\is-KN7NK.tmpjava
MD5:88088E2E9BBC93ADB021AE8BF436E544
SHA256:EB60E494BA8C23E653DA4DB8E29AF0342927FC7E1C60501BF99E93145738C696
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
28
DNS requests
13
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4712
MoUsoCoreWorker.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
7148
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
7148
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
1668
backgroundTaskHost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4712
MoUsoCoreWorker.exe
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
51.104.136.2:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
23.213.166.81:443
go.microsoft.com
AKAMAI-AS
DE
whitelisted
20.190.159.68:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
1176
svchost.exe
20.190.159.68:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1684
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted

DNS requests

Domain
IP
Reputation
www.microsoft.com
  • 23.35.229.160
whitelisted
go.microsoft.com
  • 23.213.166.81
whitelisted
login.live.com
  • 20.190.159.68
  • 20.190.159.0
  • 20.190.159.4
  • 20.190.159.23
  • 40.126.31.71
  • 40.126.31.73
  • 40.126.31.67
  • 20.190.159.71
whitelisted
settings-win.data.microsoft.com
  • 20.73.194.208
whitelisted
www.portalviva.pt
  • 62.28.82.51
unknown
slscr.update.microsoft.com
  • 4.175.87.197
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 52.165.164.15
whitelisted
arc.msn.com
  • 20.223.35.26
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
fd.api.iris.microsoft.com
  • 20.199.58.43
whitelisted

Threats

No threats detected
No debug info