File name:

navegante-1.1.1-win64-installer.exe

Full analysis: https://app.any.run/tasks/21e7eff6-46d9-45a7-adc8-3a7d0fb32110
Verdict: Malicious activity
Analysis date: January 29, 2025, 10:23:55
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
arch-doc
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 10 sections
MD5:

8F676C3D419F72E11F3DE116D4E20767

SHA1:

52ACB53E8C6153F68E2DC5BD846D9C816282D500

SHA256:

4002FE0FBE5C39072D63F7961A06846F694504255B0137C9A8D238BB2E5819F4

SSDEEP:

98304:k+cD4dnzFDmlFblXJghUyJY95uSvH9U6iRylXuer20TIBs63yjF151XI0RrgMEpY:8UUUbfbLNuJy2JuxzJHc

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • navegante-1.1.1-win64-installer.exe (PID: 6220)
    • Create files in the Startup directory

      • navegante-1.1.1-win64-installer.tmp (PID: 6240)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • navegante-1.1.1-win64-installer.exe (PID: 6220)
      • navegante-1.1.1-win64-installer.tmp (PID: 6240)
    • Checks for Java to be installed

      • navegante.exe (PID: 6932)
  • INFO

    • Creates files or folders in the user directory

      • navegante-1.1.1-win64-installer.tmp (PID: 6240)
      • javaw.exe (PID: 6952)
    • Create files in a temporary directory

      • navegante-1.1.1-win64-installer.exe (PID: 6220)
      • javaw.exe (PID: 6952)
    • Checks supported languages

      • navegante-1.1.1-win64-installer.exe (PID: 6220)
      • navegante.exe (PID: 6932)
      • javaw.exe (PID: 6952)
    • Creates a software uninstall entry

      • navegante-1.1.1-win64-installer.tmp (PID: 6240)
    • Creates files in the program directory

      • javaw.exe (PID: 6952)
    • Reads the computer name

      • javaw.exe (PID: 6952)
    • Reads the machine GUID from the registry

      • javaw.exe (PID: 6952)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (65.1)
.exe | Win32 EXE PECompact compressed (generic) (24.6)
.dll | Win32 Dynamic Link Library (generic) (3.9)
.exe | Win32 Executable (generic) (2.6)
.exe | Win16/32 Executable Delphi generic (1.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2022:04:14 16:10:23+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 741888
InitializedDataSize: 66560
UninitializedDataSize: -
EntryPoint: 0xb5eec
OSVersion: 6.1
ImageVersion: 6
SubsystemVersion: 6.1
Subsystem: Windows GUI
FileVersionNumber: 0.0.0.0
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: TML
FileDescription: navegante Setup
FileVersion:
LegalCopyright:
OriginalFileName:
ProductName: navegante
ProductVersion: 1.1.1
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
132
Monitored processes
6
Malicious processes
1
Suspicious processes
1

Behavior graph

Click at the process to see the details
start navegante-1.1.1-win64-installer.exe navegante-1.1.1-win64-installer.tmp navegante.exe no specs javaw.exe icacls.exe no specs conhost.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
6220"C:\Users\admin\AppData\Local\Temp\navegante-1.1.1-win64-installer.exe" C:\Users\admin\AppData\Local\Temp\navegante-1.1.1-win64-installer.exe
explorer.exe
User:
admin
Company:
TML
Integrity Level:
MEDIUM
Description:
navegante Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\appdata\local\temp\navegante-1.1.1-win64-installer.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
6240"C:\Users\admin\AppData\Local\Temp\is-KHCSG.tmp\navegante-1.1.1-win64-installer.tmp" /SL5="$70298,8619565,809472,C:\Users\admin\AppData\Local\Temp\navegante-1.1.1-win64-installer.exe" C:\Users\admin\AppData\Local\Temp\is-KHCSG.tmp\navegante-1.1.1-win64-installer.tmp
navegante-1.1.1-win64-installer.exe
User:
admin
Company:
TML
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\windows\syswow64\sspicli.dll
c:\windows\syswow64\explorerframe.dll
c:\windows\syswow64\sfc.dll
c:\windows\syswow64\sfc_os.dll
c:\windows\syswow64\setupapi.dll
c:\windows\syswow64\cfgmgr32.dll
c:\windows\syswow64\propsys.dll
c:\windows\syswow64\linkinfo.dll
c:\windows\syswow64\ntshrui.dll
c:\windows\syswow64\srvcli.dll
6932"C:\Users\admin\AppData\Local\Navegante\navegante.exe"C:\Users\admin\AppData\Local\Navegante\navegante.exenavegante-1.1.1-win64-installer.tmp
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\navegante\navegante.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
6952"C:\Program Files\Java\jre1.8.0_271\bin\javaw.exe" -Djava.library.path=C:\Windows\System32;bin/ -jar "C:\Users\admin\AppData\Local\Navegante\navegante.exe"C:\Program Files\Java\jre1.8.0_271\bin\javaw.exe
navegante.exe
User:
admin
Company:
Oracle Corporation
Integrity Level:
MEDIUM
Description:
Java(TM) Platform SE binary
Version:
8.0.2710.9
Modules
Images
c:\program files\java\jre1.8.0_271\bin\javaw.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
7048C:\WINDOWS\system32\icacls.exe C:\ProgramData\Oracle\Java\.oracle_jre_usage /grant "everyone":(OI)(CI)MC:\Windows\System32\icacls.exejavaw.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\icacls.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
7056\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeicacls.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
867
Read events
843
Write events
24
Delete events
0

Modification events

(PID) Process:(6240) navegante-1.1.1-win64-installer.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\E5B11362-8B69-459F-A02D-E4998968A631_is1
Operation:writeName:Inno Setup: Setup Version
Value:
6.2.1
(PID) Process:(6240) navegante-1.1.1-win64-installer.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\E5B11362-8B69-459F-A02D-E4998968A631_is1
Operation:writeName:Inno Setup: App Path
Value:
C:\Users\admin\AppData\Local\Navegante
(PID) Process:(6240) navegante-1.1.1-win64-installer.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\E5B11362-8B69-459F-A02D-E4998968A631_is1
Operation:writeName:InstallLocation
Value:
C:\Users\admin\AppData\Local\Navegante\
(PID) Process:(6240) navegante-1.1.1-win64-installer.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\E5B11362-8B69-459F-A02D-E4998968A631_is1
Operation:writeName:Inno Setup: Icon Group
Value:
(Default)
(PID) Process:(6240) navegante-1.1.1-win64-installer.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\E5B11362-8B69-459F-A02D-E4998968A631_is1
Operation:writeName:Inno Setup: User
Value:
admin
(PID) Process:(6240) navegante-1.1.1-win64-installer.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\E5B11362-8B69-459F-A02D-E4998968A631_is1
Operation:writeName:Inno Setup: Selected Tasks
Value:
desktopicon,autostarticon
(PID) Process:(6240) navegante-1.1.1-win64-installer.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\E5B11362-8B69-459F-A02D-E4998968A631_is1
Operation:writeName:Inno Setup: Deselected Tasks
Value:
(PID) Process:(6240) navegante-1.1.1-win64-installer.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\E5B11362-8B69-459F-A02D-E4998968A631_is1
Operation:writeName:Inno Setup: Language
Value:
english
(PID) Process:(6240) navegante-1.1.1-win64-installer.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\E5B11362-8B69-459F-A02D-E4998968A631_is1
Operation:writeName:DisplayName
Value:
navegante 1.1.1
(PID) Process:(6240) navegante-1.1.1-win64-installer.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\E5B11362-8B69-459F-A02D-E4998968A631_is1
Operation:writeName:UninstallString
Value:
"C:\Users\admin\AppData\Local\Navegante\unins000.exe"
Executable files
30
Suspicious files
27
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
6240navegante-1.1.1-win64-installer.tmpC:\Users\admin\AppData\Local\Temp\is-04O0V.tmp\_isetup\_setup64.tmpexecutable
MD5:E4211D6D009757C078A9FAC7FF4F03D4
SHA256:388A796580234EFC95F3B1C70AD4CB44BFDDC7BA0F9203BF4902B9929B136F95
6240navegante-1.1.1-win64-installer.tmpC:\Users\admin\AppData\Local\Navegante\lib\citizencard-module-1.4.jarcompressed
MD5:6A282926CF6D5B39A0243050B1DB8ABD
SHA256:278A5BCCDD806EFEC3B552AE37E8ABAE097B2BEE265D9230F01C8C0DE98B929F
6240navegante-1.1.1-win64-installer.tmpC:\Users\admin\AppData\Local\Navegante\is-GNO6N.tmpexecutable
MD5:65A5CC7AF6B57E084C1CE9F7285B7C59
SHA256:53CD256C4282F70B3D97871F699E0A941453C68F1FAA86C801D74C76D8050365
6240navegante-1.1.1-win64-installer.tmpC:\Users\admin\AppData\Local\Navegante\bin\is-OLNON.tmpexecutable
MD5:4A99F69F30572F42ADA03A794E0BF7B0
SHA256:5135DAF3C9D03BF9436AAD2172A7719CD7A4B198B38033BEF649413AC68DFD30
6240navegante-1.1.1-win64-installer.tmpC:\Users\admin\AppData\Local\Navegante\navegante.execompressed
MD5:C344C61A396664470C76ACB9DF5BFCB7
SHA256:A56A4BA235D800919495E109BBA94275C5D5B0ADA76AB388E4058A8F79384F0E
6240navegante-1.1.1-win64-installer.tmpC:\Users\admin\AppData\Local\Navegante\unins000.exeexecutable
MD5:65A5CC7AF6B57E084C1CE9F7285B7C59
SHA256:53CD256C4282F70B3D97871F699E0A941453C68F1FAA86C801D74C76D8050365
6240navegante-1.1.1-win64-installer.tmpC:\Users\admin\AppData\Local\Navegante\is-6OTJO.tmpcompressed
MD5:C344C61A396664470C76ACB9DF5BFCB7
SHA256:A56A4BA235D800919495E109BBA94275C5D5B0ADA76AB388E4058A8F79384F0E
6240navegante-1.1.1-win64-installer.tmpC:\Users\admin\AppData\Local\Navegante\bin\api_os.dllexecutable
MD5:2ACD45C039F374695FC7ED7DCC2627D3
SHA256:9ABB918A4C9FA0BAFC065F2CFDA52AEA0EA7D0D63AE76E89E738F3372556D912
6240navegante-1.1.1-win64-installer.tmpC:\Users\admin\AppData\Local\Navegante\bin\is-T1N67.tmpexecutable
MD5:2ACD45C039F374695FC7ED7DCC2627D3
SHA256:9ABB918A4C9FA0BAFC065F2CFDA52AEA0EA7D0D63AE76E89E738F3372556D912
6240navegante-1.1.1-win64-installer.tmpC:\Users\admin\AppData\Local\Navegante\bin\vrc.dllexecutable
MD5:4A99F69F30572F42ADA03A794E0BF7B0
SHA256:5135DAF3C9D03BF9436AAD2172A7719CD7A4B198B38033BEF649413AC68DFD30
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
28
DNS requests
13
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4712
MoUsoCoreWorker.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
7148
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
7148
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
1668
backgroundTaskHost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4712
MoUsoCoreWorker.exe
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
51.104.136.2:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
23.213.166.81:443
go.microsoft.com
AKAMAI-AS
DE
whitelisted
20.190.159.68:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
1176
svchost.exe
20.190.159.68:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1684
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted

DNS requests

Domain
IP
Reputation
www.microsoft.com
  • 23.35.229.160
whitelisted
go.microsoft.com
  • 23.213.166.81
whitelisted
login.live.com
  • 20.190.159.68
  • 20.190.159.0
  • 20.190.159.4
  • 20.190.159.23
  • 40.126.31.71
  • 40.126.31.73
  • 40.126.31.67
  • 20.190.159.71
whitelisted
settings-win.data.microsoft.com
  • 20.73.194.208
whitelisted
www.portalviva.pt
  • 62.28.82.51
unknown
slscr.update.microsoft.com
  • 4.175.87.197
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 52.165.164.15
whitelisted
arc.msn.com
  • 20.223.35.26
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
fd.api.iris.microsoft.com
  • 20.199.58.43
whitelisted

Threats

No threats detected
No debug info