File name:

openvpn-install.exe

Full analysis: https://app.any.run/tasks/622bf494-bb6a-4771-9e31-b6cba964fbe9
Verdict: Malicious activity
Analysis date: April 05, 2024, 18:24:14
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows, Nullsoft Installer self-extracting archive
MD5:

0BD5F20A35F8E75D21BF57B2CC4C9FA6

SHA1:

9AD5427268381A0D750E1A2B0D54043CBD6FF5D7

SHA256:

4F95A674C3FFAFD85062DF995A182CFB57CA56D96084472A48A65C546C815F0C

SSDEEP:

98304:c3M5ZXtUGS1MMVbZxU5Qy2EwP0EyOeqAbacwWY6FVN40FA:cS7/UbzUQt33yOeqAbMWYSVN7A

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • tap-windows.exe (PID: 2152)
      • openvpn-install.exe (PID: 2208)
      • tapinstall.exe (PID: 1572)
      • drvinst.exe (PID: 1112)
      • drvinst.exe (PID: 1232)
    • Creates a writable file in the system directory

      • drvinst.exe (PID: 1112)
      • drvinst.exe (PID: 1232)
    • Changes the autorun value in the registry

      • openvpn-install.exe (PID: 2208)
      • drvinst.exe (PID: 1232)
  • SUSPICIOUS

    • Malware-specific behavior (creating "System.dll" in Temp)

      • openvpn-install.exe (PID: 2208)
      • tap-windows.exe (PID: 2152)
    • The process creates files with name similar to system file names

      • openvpn-install.exe (PID: 2208)
      • tap-windows.exe (PID: 2152)
    • Starts application with an unusual extension

      • openvpn-install.exe (PID: 2208)
      • tap-windows.exe (PID: 2152)
    • Creates files in the driver directory

      • drvinst.exe (PID: 1112)
      • drvinst.exe (PID: 1232)
    • Executes as Windows Service

      • VSSVC.exe (PID: 2728)
      • openvpnserv.exe (PID: 2376)
    • Reads settings of System Certificates

      • tapinstall.exe (PID: 1572)
    • Reads security settings of Internet Explorer

      • tapinstall.exe (PID: 1572)
    • Checks Windows Trust Settings

      • tapinstall.exe (PID: 1572)
      • drvinst.exe (PID: 1232)
      • drvinst.exe (PID: 1112)
    • Creates a software uninstall entry

      • tap-windows.exe (PID: 2152)
      • openvpn-install.exe (PID: 2208)
    • Start notepad (likely ransomware note)

      • openvpn-install.exe (PID: 2208)
  • INFO

    • Checks supported languages

      • openvpn-install.exe (PID: 2208)
      • ns5A24.tmp (PID: 796)
      • tap-windows.exe (PID: 2152)
      • ns5BBB.tmp (PID: 240)
      • tapinstall.exe (PID: 1572)
      • ns5B3D.tmp (PID: 2156)
      • tapinstall.exe (PID: 3776)
      • drvinst.exe (PID: 1112)
      • drvinst.exe (PID: 1232)
      • openvpnserv.exe (PID: 2376)
    • Reads the computer name

      • openvpn-install.exe (PID: 2208)
      • tapinstall.exe (PID: 1572)
      • tap-windows.exe (PID: 2152)
      • tapinstall.exe (PID: 3776)
      • drvinst.exe (PID: 1112)
      • drvinst.exe (PID: 1232)
      • openvpnserv.exe (PID: 2376)
    • Create files in a temporary directory

      • openvpn-install.exe (PID: 2208)
      • tap-windows.exe (PID: 2152)
      • tapinstall.exe (PID: 1572)
    • Reads the machine GUID from the registry

      • tapinstall.exe (PID: 1572)
      • drvinst.exe (PID: 1112)
      • drvinst.exe (PID: 1232)
    • Creates files in the program directory

      • openvpn-install.exe (PID: 2208)
      • tap-windows.exe (PID: 2152)
    • Reads the software policy settings

      • drvinst.exe (PID: 1112)
      • tapinstall.exe (PID: 1572)
      • drvinst.exe (PID: 1232)
    • Reads Environment values

      • drvinst.exe (PID: 1232)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2016:04:27 01:27:47+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit, No debug
PEType: PE32
LinkerVersion: 2.26
CodeSize: 35840
InitializedDataSize: 38912
UninitializedDataSize: 110080
EntryPoint: 0x4375
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.0
ProductVersionNumber: 1.0.0.0
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Windows, Latin1
Comments: -
CompanyName: OpenVPN Inc.
FileDescription: OpenVPN-Installer
FileVersion: 1.0.0
LegalCopyright: OpenVPN Inc.
LegalTrademarks: OpenVPN Inc.
ProductName: OpenVPN-Installer
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
57
Monitored processes
14
Malicious processes
7
Suspicious processes
0

Behavior graph

Click at the process to see the details
start openvpn-install.exe ns5a24.tmp no specs tap-windows.exe no specs ns5b3d.tmp no specs tapinstall.exe no specs ns5bbb.tmp no specs tapinstall.exe no specs drvinst.exe no specs rundll32.exe no specs vssvc.exe no specs drvinst.exe openvpnserv.exe no specs notepad.exe no specs openvpn-install.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
240"C:\Users\admin\AppData\Local\Temp\nsa5AA0.tmp\ns5BBB.tmp" "C:\Program Files\TAP-Windows\bin\tapinstall.exe" install "C:\Program Files\TAP-Windows\driver\OemVista.inf" tap0901C:\Users\admin\AppData\Local\Temp\nsa5AA0.tmp\ns5BBB.tmptap-windows.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\nsa5aa0.tmp\ns5bbb.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
796"C:\Users\admin\AppData\Local\Temp\nsp2577.tmp\ns5A24.tmp" "C:\Users\admin\AppData\Local\Temp\tap-windows.exe" /S /SELECT_UTILITIES=1C:\Users\admin\AppData\Local\Temp\nsp2577.tmp\ns5A24.tmpopenvpn-install.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\nsp2577.tmp\ns5a24.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1112DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{437d5b5d-8ab5-376b-69f7-a07fea2bd001}\oemvista.inf" "0" "6d14a44ff" "00000558" "WinSta0\Default" "000003F8" "208" "c:\program files\tap-windows\driver"C:\Windows\System32\drvinst.exesvchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1232DrvInst.exe "2" "211" "ROOT\NET\0000" "C:\Windows\INF\oem2.inf" "oemvista.inf:tap0901.NTx86:tap0901.ndi:9.24.2.601:tap0901" "6d14a44ff" "00000558" "000005EC" "000005F0"C:\Windows\System32\drvinst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1572"C:\Program Files\TAP-Windows\bin\tapinstall.exe" install "C:\Program Files\TAP-Windows\driver\OemVista.inf" tap0901C:\Program Files\TAP-Windows\bin\tapinstall.exens5BBB.tmp
User:
admin
Company:
Windows (R) Win 7 DDK provider
Integrity Level:
HIGH
Description:
Windows Setup API
Exit code:
0
Version:
10.0.10011.16384
Modules
Images
c:\program files\tap-windows\bin\tapinstall.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2152"C:\Users\admin\AppData\Local\Temp\tap-windows.exe" /S /SELECT_UTILITIES=1C:\Users\admin\AppData\Local\Temp\tap-windows.exens5A24.tmp
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\tap-windows.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
2156"C:\Users\admin\AppData\Local\Temp\nsa5AA0.tmp\ns5B3D.tmp" "C:\Program Files\TAP-Windows\bin\tapinstall.exe" hwids tap0901C:\Users\admin\AppData\Local\Temp\nsa5AA0.tmp\ns5B3D.tmptap-windows.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\nsa5aa0.tmp\ns5b3d.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2208"C:\Users\admin\Desktop\openvpn-install.exe" C:\Users\admin\Desktop\openvpn-install.exe
explorer.exe
User:
admin
Company:
OpenVPN Inc.
Integrity Level:
HIGH
Description:
OpenVPN-Installer
Exit code:
0
Version:
1.0.0
Modules
Images
c:\users\admin\desktop\openvpn-install.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\gdi32.dll
2376"C:\Program Files\OpenVPN\bin\openvpnserv.exe"C:\Program Files\OpenVPN\bin\openvpnserv.exeservices.exe
User:
SYSTEM
Company:
The OpenVPN Project
Integrity Level:
SYSTEM
Description:
OpenVPN Service
Version:
2.4.9.0
Modules
Images
c:\program files\openvpn\bin\openvpnserv.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\iphlpapi.dll
2728C:\Windows\system32\vssvc.exeC:\Windows\System32\VSSVC.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Volume Shadow Copy Service
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\vssvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
15 723
Read events
15 129
Write events
538
Delete events
56

Modification events

(PID) Process:(2208) openvpn-install.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\OpenVPN
Operation:writeName:config_dir
Value:
C:\Program Files\OpenVPN\config
(PID) Process:(2208) openvpn-install.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\OpenVPN
Operation:writeName:config_ext
Value:
ovpn
(PID) Process:(2208) openvpn-install.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\OpenVPN
Operation:writeName:exe_path
Value:
C:\Program Files\OpenVPN\bin\openvpn.exe
(PID) Process:(2208) openvpn-install.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\OpenVPN
Operation:writeName:log_dir
Value:
C:\Program Files\OpenVPN\log
(PID) Process:(2208) openvpn-install.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\OpenVPN
Operation:writeName:priority
Value:
NORMAL_PRIORITY_CLASS
(PID) Process:(2208) openvpn-install.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\OpenVPN
Operation:writeName:log_append
Value:
0
(PID) Process:(2208) openvpn-install.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\OpenVPN
Operation:writeName:ovpn_admin_group
Value:
OpenVPN Administrators
(PID) Process:(2208) openvpn-install.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\OpenVPN
Operation:writeName:disable_save_passwords
Value:
0
(PID) Process:(1572) tapinstall.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\Setup\SetupapiLogStatus
Operation:writeName:setupapi.dev.log
Value:
4096
(PID) Process:(1572) tapinstall.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
Executable files
36
Suspicious files
19
Text files
20
Unknown types
16

Dropped files

PID
Process
Filename
Type
2208openvpn-install.exeC:\Users\admin\AppData\Local\Temp\nsp2577.tmp\System.dllexecutable
MD5:
SHA256:
2208openvpn-install.exeC:\Users\admin\AppData\Local\Temp\nsp2577.tmp\UserInfo.dllexecutable
MD5:
SHA256:
2208openvpn-install.exeC:\Users\admin\AppData\Local\Temp\nsp2577.tmp\modern-header.bmpimage
MD5:
SHA256:
2208openvpn-install.exeC:\Users\admin\AppData\Local\Temp\nsp2577.tmp\modern-wizard.bmpimage
MD5:
SHA256:
2208openvpn-install.exeC:\Users\admin\AppData\Local\Temp\nsp2577.tmp\nsDialogs.dllexecutable
MD5:
SHA256:
2208openvpn-install.exeC:\Users\admin\AppData\Local\Temp\nsp2577.tmp\SimpleSC.dllexecutable
MD5:
SHA256:
2208openvpn-install.exeC:\Users\admin\AppData\Local\Temp\nsp2577.tmp\nsProcess.dllexecutable
MD5:
SHA256:
2208openvpn-install.exeC:\Program Files\OpenVPN\bin\openvpn.exeexecutable
MD5:
SHA256:
2208openvpn-install.exeC:\Program Files\OpenVPN\doc\INSTALL-win32.txttext
MD5:
SHA256:
2208openvpn-install.exeC:\Program Files\OpenVPN\doc\openvpn.8.htmlhtml
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
12
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
224.0.0.252:5355
unknown
1080
svchost.exe
224.0.0.252:5355
unknown

DNS requests

No data

Threats

No threats detected
No debug info