File name: | jre-8u421-windows-x64.exe |
Full analysis: | https://app.any.run/tasks/9f5378ba-dc52-44b1-bfbc-ece8e124a7a9 |
Verdict: | Malicious activity |
Analysis date: | August 12, 2024, 09:31:09 |
OS: | Windows 10 Professional (build: 19045, 64 bit) |
Indicators: | |
MIME: | application/x-dosexec |
File info: | PE32+ executable (GUI) x86-64, for MS Windows |
MD5: | 44212E8E9E46A94AB90D0EF4405FCE7B |
SHA1: | A123299A54411EC6C479C2701A53452EDE431138 |
SHA256: | 53898FDDD0B8D2C1B60DB92B0810F4861B614C4EDE149718266A129E29AAB779 |
SSDEEP: | 786432:ppAMmf6eNbhRa3hL0KmXgnOH6J3mihBY70ekSP:fAMm/NFRa90Km/6J3mihBY70e9P |
.exe | | | Win32 EXE PECompact compressed (generic) (83) |
---|---|---|
.exe | | | Win32 Executable (generic) (9) |
.exe | | | Generic Win/DOS Executable (3.9) |
.exe | | | DOS Executable Generic (3.9) |
MachineType: | AMD AMD64 |
---|---|
TimeStamp: | 2024:06:05 13:44:53+00:00 |
ImageFileCharacteristics: | Executable, Large address aware |
PEType: | PE32+ |
LinkerVersion: | 14.36 |
CodeSize: | 262656 |
InitializedDataSize: | 68777984 |
UninitializedDataSize: | - |
EntryPoint: | 0x19564 |
OSVersion: | 6 |
ImageVersion: | - |
SubsystemVersion: | 6 |
Subsystem: | Windows GUI |
FileVersionNumber: | 8.0.4210.9 |
ProductVersionNumber: | 8.0.4210.9 |
FileFlagsMask: | 0x003f |
FileFlags: | (none) |
FileOS: | Windows NT 32-bit |
ObjectFileType: | Executable application |
FileSubtype: | - |
LanguageCode: | English (U.S.) |
CharacterSet: | Unicode |
CompanyName: | Oracle Corporation |
FileDescription: | Java Platform SE binary |
FileVersion: | 8.0.4210.9 |
FullVersion: | 1.8.0_421-b09 |
InternalName: | Setup Launcher |
LegalCopyright: | Copyright © 2024 |
OriginalFileName: | wrapper_jre_offline.exe |
ProductName: | Java Platform SE 8 U421 |
ProductVersion: | 8.0.4210.9 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
420 | "C:\Program Files\Java\jre1.8.0_421\bin\javaws.exe" -wait -fix -shortcut -silent | C:\Program Files\Java\jre1.8.0_421\bin\javaws.exe | installer.exe | ||||||||||||
User: SYSTEM Company: Oracle Corporation Integrity Level: SYSTEM Description: Java(TM) Web Start Launcher Exit code: 0 Version: 11.421.2.09 Modules
| |||||||||||||||
460 | "C:\Windows\SysWOW64\msiexec.exe" /x {4A03706F-666A-4037-7777-5F2748764D10} /qn | C:\Windows\SysWOW64\msiexec.exe | — | jaureg.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows® installer Exit code: 0 Version: 5.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
1168 | "C:\Program Files (x86)\Common Files\Java\Java Update\jaureg.exe" -u auto-update | C:\Program Files (x86)\Common Files\Java\Java Update\jaureg.exe | MSIEBA1.tmp | ||||||||||||
User: SYSTEM Company: Oracle Corporation Integrity Level: SYSTEM Description: Java Update Registration Exit code: 0 Version: 2.8.271.9 Modules
| |||||||||||||||
1664 | -Djdk.disableLastUsageTracking -cp "C:\Program Files\Java\jre1.8.0_421\bin\..\lib\deploy.jar" com.sun.deploy.panel.ControlPanel -getUserWebJavaStatus | C:\Program Files\Java\jre1.8.0_421\bin\javaw.exe | — | jre-8u421-windows-x64.exe | |||||||||||
User: admin Company: Oracle Corporation Integrity Level: MEDIUM Description: Java(TM) Platform SE binary Exit code: 1 Version: 8.0.4210.9 Modules
| |||||||||||||||
1700 | C:\Windows\syswow64\MsiExec.exe -Embedding 61E75B6C9B8DFE875D92E5300707CA1E E Global\MSI0000 | C:\Windows\SysWOW64\msiexec.exe | — | msiexec.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows® installer Exit code: 0 Version: 5.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
1748 | C:\Windows\syswow64\MsiExec.exe -Embedding 0004BA7CF6F5AD9A2E148FB92A0C5107 | C:\Windows\SysWOW64\msiexec.exe | — | msiexec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows® installer Exit code: 0 Version: 5.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
2064 | "C:\Program Files\Java\jre1.8.0_421\installer.exe" /s INSTALLDIR="C:\Program Files\Java\jre1.8.0_421\\" INSTALL_SILENT=1 AUTO_UPDATE=0 SPONSORS=0 REPAIRMODE=0 ProductCode={77924AE4-039E-4CA4-87B4-2F64180421F0} | C:\Program Files\Java\jre1.8.0_421\installer.exe | msiexec.exe | ||||||||||||
User: admin Company: Oracle Corporation Integrity Level: HIGH Description: Java Platform SE binary Exit code: 0 Version: 8.0.4210.9 Modules
| |||||||||||||||
2272 | "C:\Program Files\Java\jre1.8.0_421\bin\jp2launcher.exe" -secure -javaws -jre "C:\Program Files\Java\jre1.8.0_421" -vma LWNsYXNzcGF0aABDOlxQcm9ncmFtIEZpbGVzXEphdmFcanJlMS44LjBfNDIxXGxpYlxkZXBsb3kuamFyAC1EamF2YS5zZWN1cml0eS5wb2xpY3k9ZmlsZTpDOlxQcm9ncmFtIEZpbGVzXEphdmFcanJlMS44LjBfNDIxXGxpYlxzZWN1cml0eVxqYXZhd3MucG9saWN5AC1EdHJ1c3RQcm94eT10cnVlAC1YdmVyaWZ5OnJlbW90ZQAtRGpubHB4LmhvbWU9QzpcUHJvZ3JhbSBGaWxlc1xKYXZhXGpyZTEuOC4wXzQyMVxiaW4ALURqYXZhLnNlY3VyaXR5Lm1hbmFnZXIALURzdW4uYXd0Lndhcm11cD10cnVlAC1YYm9vdGNsYXNzcGF0aC9hOkM6XFByb2dyYW0gRmlsZXNcSmF2YVxqcmUxLjguMF80MjFcbGliXGphdmF3cy5qYXI7QzpcUHJvZ3JhbSBGaWxlc1xKYXZhXGpyZTEuOC4wXzQyMVxsaWJcZGVwbG95LmphcjtDOlxQcm9ncmFtIEZpbGVzXEphdmFcanJlMS44LjBfNDIxXGxpYlxwbHVnaW4uamFyAC1EamF2YS5hd3QuaGVhZGxlc3M9dHJ1ZQAtRGpubHB4Lmp2bT1DOlxQcm9ncmFtIEZpbGVzXEphdmFcanJlMS44LjBfNDIxXGJpblxqYXZhdy5leGU= -ma LXdhaXQALWZpeAAtcGVybWlzc2lvbnMALXNpbGVudAAtbm90V2ViSmF2YQ== | C:\Program Files\Java\jre1.8.0_421\bin\jp2launcher.exe | — | javaws.exe | |||||||||||
User: SYSTEM Company: Oracle Corporation Integrity Level: SYSTEM Description: Java(TM) Web Launcher Exit code: 0 Version: 11.421.2.09 Modules
| |||||||||||||||
4364 | C:\Windows\System32\MsiExec.exe -Embedding C92AB0EA5AEA4BFC542F0DB290EC19A6 | C:\Windows\System32\msiexec.exe | — | msiexec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows® installer Exit code: 0 Version: 5.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
5144 | C:\Windows\syswow64\MsiExec.exe -Embedding 5F2DD8F2685C3255D11940D0F80B47F6 E Global\MSI0000 | C:\Windows\SysWOW64\msiexec.exe | — | msiexec.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows® installer Exit code: 0 Version: 5.0.19041.3636 (WinBuild.160101.0800) Modules
|
(PID) Process: | (7000) jre-8u421-windows-x64.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\JavaSoft |
Operation: | delete value | Name: | InstallStatus |
Value: | |||
(PID) Process: | (7000) jre-8u421-windows-x64.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content |
Operation: | write | Name: | CachePrefix |
Value: | |||
(PID) Process: | (7000) jre-8u421-windows-x64.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
(PID) Process: | (7000) jre-8u421-windows-x64.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
(PID) Process: | (7000) jre-8u421-windows-x64.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
(PID) Process: | (7000) jre-8u421-windows-x64.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | IntranetName |
Value: 1 | |||
(PID) Process: | (7000) jre-8u421-windows-x64.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
(PID) Process: | (7000) jre-8u421-windows-x64.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | AutoDetect |
Value: 0 | |||
(PID) Process: | (7000) jre-8u421-windows-x64.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\JavaSoft\Java Update\Policy |
Operation: | write | Name: | Country |
Value: IQ | |||
(PID) Process: | (7000) jre-8u421-windows-x64.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\LowRegistry |
Operation: | delete value | Name: | AddToFavoritesInitialSelection |
Value: |
PID | Process | Filename | Type | |
---|---|---|---|---|
6972 | jre-8u421-windows-x64.exe | C:\Users\admin\AppData\Local\Temp\jds960906.tmp\jds960906.tmp | — | |
MD5:— | SHA256:— | |||
6972 | jre-8u421-windows-x64.exe | C:\Users\admin\AppData\Local\Temp\jds960906.tmp\jre-8u421-windows-x64.exe | — | |
MD5:— | SHA256:— | |||
7000 | jre-8u421-windows-x64.exe | C:\Users\admin\AppData\LocalLow\Oracle\Java\jre1.8.0_421_x64\jre1.8.0_42164.msi | — | |
MD5:— | SHA256:— | |||
6308 | msiexec.exe | C:\Windows\Installer\edb58.msi | — | |
MD5:— | SHA256:— | |||
6308 | msiexec.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\698460A0B6E60F2F602361424D832905_8BB23D43DE574E82F2BEE0DF0EC47EEB | binary | |
MD5:D327B84D5A84AB18BEDED6B56565C123 | SHA256:B6CACCEDA8F6C9C99041AFF4C80BAE2B44B2B20D52FC62F334A86BE24FA6940C | |||
6308 | msiexec.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\698460A0B6E60F2F602361424D832905_8BB23D43DE574E82F2BEE0DF0EC47EEB | binary | |
MD5:85C31DA12F9D90932C66614F91256788 | SHA256:4382A8075AADEC1C123E7D40417CA6359FE7FA869C0B2272691FDC36FC27F6F9 | |||
6972 | jre-8u421-windows-x64.exe | C:\Users\admin\AppData\Local\Temp\jusched.log | text | |
MD5:0A105F52E9A008AEEACC4C34FBC17FFD | SHA256:7EBAFB653DC3C144B545A379F2D1FE9A471F7699BB5BF77373760294857541D8 | |||
7000 | jre-8u421-windows-x64.exe | C:\Users\admin\AppData\LocalLow\Oracle\Java\jre1.8.0_421_x64\Java3BillDevices.png | image | |
MD5:8E52EFC6798ED074072F527309A1BA25 | SHA256:12491EBC4EB99BF014D3BC44F770114BDE013E84CBEC2633303559A8C6E5F991 | |||
6308 | msiexec.exe | C:\Windows\Installer\MSIE4C2.tmp | executable | |
MD5:180193EB80971C7868B3AFC922885C8E | SHA256:682AFD3BFD6333A8A009EF41F55A919548096522FC3ECB0C8664D4BFA9B9E07B | |||
6308 | msiexec.exe | C:\Windows\Installer\MSIE454.tmp | executable | |
MD5:180193EB80971C7868B3AFC922885C8E | SHA256:682AFD3BFD6333A8A009EF41F55A919548096522FC3ECB0C8664D4BFA9B9E07B |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
— | — | HEAD | 200 | 23.56.205.197:443 | https://rps-svcs.oracle.com/services/countrylookup | unknown | — | — | — |
6308 | msiexec.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT3xL4LQLXDRDM9P665TW442vrsUQQUReuir%2FSSy4IxLVGLp6chnfNtyA8CEA6bGI750C3n79tQ4ghAGFo%3D | unknown | — | — | whitelisted |
6308 | msiexec.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfIs%2BLjDtGwQ09XEB1Yeq%2BtX%2BBgQQU7NfjgtJxXWRM3y5nP%2Be6mK4cD08CEAitQLJg0pxMn17Nqb2Trtk%3D | unknown | — | — | whitelisted |
6308 | msiexec.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSRXerF0eFeSWRripTgTkcJWMm7iQQUaDfg67Y7%2BF8Rhvv%2BYXsIiGX0TkICEAYOL4%2BeG4vlGNX%2BK2nPzLE%3D | unknown | — | — | whitelisted |
— | — | GET | 200 | 23.56.205.197:443 | https://javadl-esd-secure.oracle.com/update/1.8.0/d8aa705069af427f9b83e66b34f5e380/1.8.0_421-b09.xml | unknown | xml | 647 b | — |
— | — | POST | 204 | 184.86.251.4:443 | https://www.bing.com/threshold/xls.aspx | unknown | — | — | — |
— | — | GET | 200 | null:443 | https://www.java.com/applet/javaLatestVersion.xml | unknown | xml | 3.03 Kb | — |
— | — | POST | 200 | 63.140.62.222:443 | https://sjremetrics.java.com/b/ss//6 | unknown | xml | 64 b | — |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
— | — | 192.168.100.255:138 | — | — | — | whitelisted |
— | — | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
3888 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
— | — | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
7000 | jre-8u421-windows-x64.exe | 2.23.68.183:443 | javadl-esd-secure.oracle.com | AKAMAI-AS | DE | unknown |
7000 | jre-8u421-windows-x64.exe | 23.192.251.112:443 | rps-svcs.oracle.com | AKAMAI-AS | US | unknown |
6308 | msiexec.exe | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
3140 | svchost.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
7000 | jre-8u421-windows-x64.exe | 184.86.251.7:443 | www.java.com | Akamai International B.V. | DE | unknown |
5336 | SearchApp.exe | 184.86.251.9:443 | www.bing.com | Akamai International B.V. | DE | unknown |
Domain | IP | Reputation |
---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
javadl-esd-secure.oracle.com |
| whitelisted |
rps-svcs.oracle.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
www.java.com |
| whitelisted |
www.bing.com |
| whitelisted |
sjremetrics.java.com |
| whitelisted |