| File name: | Ninite 7Zip Chrome Notepad VLC Installer.exe |
| Full analysis: | https://app.any.run/tasks/f731cf8b-62e0-4628-a057-5f7938160cfe |
| Verdict: | Malicious activity |
| Threats: | A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection. |
| Analysis date: | December 20, 2024, 11:14:39 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, 6 sections |
| MD5: | 1C0C860A028FC2A0E44597153EE8A8BB |
| SHA1: | 747A23342212B5AF8F0CA3908897771B0A57C06C |
| SHA256: | 544361A60577915BEAA392C42E716E1AF3800A8BBEAA6AC3E01C2DC0F310455E |
| SSDEEP: | 12288:2LVP603RQX2pyf+cnci2N9pKKfyeo+pW1KKRyzEK:oVP60BM2pMUN9keo+c+zEK |
| .exe | | | Win64 Executable (generic) (76.4) |
|---|---|---|
| .exe | | | Win32 Executable (generic) (12.4) |
| .exe | | | Generic Win/DOS Executable (5.5) |
| .exe | | | DOS Executable Generic (5.5) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2017:04:12 00:19:47+00:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 14 |
| CodeSize: | 233472 |
| InitializedDataSize: | 182272 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x1a53a |
| OSVersion: | 5.1 |
| ImageVersion: | - |
| SubsystemVersion: | 5.1 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 0.1.1.1183 |
| ProductVersionNumber: | 0.1.1.1183 |
| FileFlagsMask: | 0x0017 |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| CompanyName: | Secure By Design Inc. |
| FileDescription: | Ninite |
| FileVersion: | 0,1,1,1183 |
| InternalName: | Ninite |
| LegalCopyright: | Copyright (C) 2009 Secure By Design Inc |
| OriginalFileName: | - |
| ProductName: | Ninite |
| ProductVersion: | 0,1,1,1183 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1228 | C:\Windows\syswow64\MsiExec.exe -Embedding AF187C1FFBC2F7952F97F1076A58CC2E | C:\Windows\SysWOW64\msiexec.exe | — | msiexec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows® installer Version: 5.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1760 | C:\WINDOWS\SystemTemp\Google5112_1930860682\bin\Offline\{0087ee13-0e71-4542-8fdc-84b7cc418a06}\{8a69d345-d564-463c-aff1-a69d9e530f96}\CR_667E8.tmp\setup.exe --type=crashpad-handler /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler --database=C:\WINDOWS\SystemTemp\Crashpad --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win64 --annotation=prod=Chrome --annotation=ver=131.0.6778.205 --initial-client-data=0x29c,0x2a0,0x2a4,0x278,0x2a8,0x7ff6a978fd28,0x7ff6a978fd34,0x7ff6a978fd40 | C:\Windows\SystemTemp\Google5112_1930860682\bin\Offline\{0087ee13-0e71-4542-8fdc-84b7cc418a06}\{8A69D345-D564-463c-AFF1-A69D9E530F96}\CR_667E8.tmp\setup.exe | — | setup.exe | |||||||||||
User: SYSTEM Company: Google LLC Integrity Level: SYSTEM Description: Google Chrome Installer Version: 131.0.6778.205 Modules
| |||||||||||||||
| 2076 | msiexec.exe /i "C:\Users\admin\AppData\Local\Temp\9F2D95~1\GoogleChromeStandaloneEnterprise64.msi" /qn /norestart REBOOT=ReallySuppress ALLUSERS=1 NOGOOGLEUPDATEPING=1 /Le "C:\Users\admin\AppData\Local\Temp\9F2D95~1\msi_log.txt" | C:\Windows\SysWOW64\msiexec.exe | — | Ninite.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows® installer Version: 5.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2220 | "C:\Program Files (x86)\Google\GoogleUpdater\131.0.6776.0\updater.exe" --system --windows-service --service=update-internal | C:\Program Files (x86)\Google\GoogleUpdater\131.0.6776.0\updater.exe | services.exe | ||||||||||||
User: SYSTEM Company: Google LLC Integrity Level: SYSTEM Description: Google Updater Version: 131.0.6776.0 Modules
| |||||||||||||||
| 2456 | "C:\Program Files (x86)\Google\GoogleUpdater\131.0.6776.0\updater.exe" --crash-handler --system "--database=C:\Program Files (x86)\Google\GoogleUpdater\131.0.6776.0\Crashpad" --url=https://clients2.google.com/cr/report --annotation=prod=Update4 --annotation=ver=131.0.6776.0 "--attachment=C:\Program Files (x86)\Google\GoogleUpdater\updater.log" --initial-client-data=0x2a0,0x2a4,0x2a8,0x27c,0x2ac,0x4f6290,0x4f629c,0x4f62a8 | C:\Program Files (x86)\Google\GoogleUpdater\131.0.6776.0\updater.exe | — | updater.exe | |||||||||||
User: SYSTEM Company: Google LLC Integrity Level: SYSTEM Description: Google Updater Version: 131.0.6776.0 Modules
| |||||||||||||||
| 5076 | "C:\WINDOWS\SystemTemp\Google5112_1930860682\bin\Offline\{0087ee13-0e71-4542-8fdc-84b7cc418a06}\{8a69d345-d564-463c-aff1-a69d9e530f96}\CR_667E8.tmp\setup.exe" --install-archive="C:\WINDOWS\SystemTemp\Google5112_1930860682\bin\Offline\{0087ee13-0e71-4542-8fdc-84b7cc418a06}\{8a69d345-d564-463c-aff1-a69d9e530f96}\CR_667E8.tmp\CHROME.PACKED.7Z" --do-not-launch-chrome --installerdata="C:\Windows\SystemTemp\scoped_dir7024_529988692\52951a68-567a-4303-b8c3-c7ee2d770383.tmp" | C:\Windows\SystemTemp\Google5112_1930860682\bin\Offline\{0087ee13-0e71-4542-8fdc-84b7cc418a06}\{8A69D345-D564-463c-AFF1-A69D9E530F96}\CR_667E8.tmp\setup.exe | — | 131.0.6778.205_chrome_installer.exe | |||||||||||
User: SYSTEM Company: Google LLC Integrity Level: SYSTEM Description: Google Chrome Installer Version: 131.0.6778.205 Modules
| |||||||||||||||
| 5112 | "C:\WINDOWS\Installer\MSIF0FE.tmp" --silent --install="appguid={8A69D345-D564-463C-AFF1-A69D9E530F96}&iid={04890063-2FDC-8C69-AA75-7BE52EF733F1}&lang=en&browser=4&usagestats=0&appname=Google%20Chrome&needsadmin=true&ap=x64-stable-statsdef_0&brand=GCEA" --installsource=enterprisemsi --enterprise --appargs="appguid={8A69D345-D564-463c-AFF1-A69D9E530F96}&installerdata=%7B%22distribution%22%3A%7B%22msi%22%3Atrue%2C%22system_level%22%3Atrue%2C%22verbose_logging%22%3Atrue%2C%22msi_product_id%22%3A%22629D2D6F-24EC-3737-8C9E-061E2A0E2F66%22%2C%22allow_downgrade%22%3Afalse%7D%7D" | C:\Windows\Installer\MSIF0FE.tmp | — | msiexec.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: HIGH Description: Google Installer Version: 131.0.6776.0 Modules
| |||||||||||||||
| 5872 | "C:\WINDOWS\SystemTemp\Google5112_1930860682\bin\Offline\{0087ee13-0e71-4542-8fdc-84b7cc418a06}\{8a69d345-d564-463c-aff1-a69d9e530f96}\131.0.6778.205_chrome_installer.exe" --do-not-launch-chrome --installerdata="C:\Windows\SystemTemp\scoped_dir7024_529988692\52951a68-567a-4303-b8c3-c7ee2d770383.tmp" | C:\Windows\SystemTemp\Google5112_1930860682\bin\Offline\{0087ee13-0e71-4542-8fdc-84b7cc418a06}\{8A69D345-D564-463c-AFF1-A69D9E530F96}\131.0.6778.205_chrome_installer.exe | updater.exe | ||||||||||||
User: SYSTEM Company: Google LLC Integrity Level: SYSTEM Description: Google Chrome Installer Version: 131.0.6778.205 Modules
| |||||||||||||||
| 6244 | "C:\Users\admin\AppData\Local\Temp\Ninite 7Zip Chrome Notepad VLC Installer.exe" | C:\Users\admin\AppData\Local\Temp\Ninite 7Zip Chrome Notepad VLC Installer.exe | explorer.exe | ||||||||||||
User: admin Company: Secure By Design Inc. Integrity Level: MEDIUM Description: Ninite Version: 0,1,1,1183 Modules
| |||||||||||||||
| 6324 | Ninite.exe "90a9fcde5f9309e91ba2bcca626ad0c9812b487f" /fullpath "C:\Users\admin\AppData\Local\Temp\Ninite 7Zip Chrome Notepad VLC Installer.exe" | C:\Users\admin\AppData\Local\Temp\9ce41f82-bec3-11ef-b4ea-18f7786f96ee\Ninite.exe | — | Ninite 7Zip Chrome Notepad VLC Installer.exe | |||||||||||
User: admin Company: Secure By Design Inc. Integrity Level: MEDIUM Description: Ninite Version: 0,1,1,1481 Modules
| |||||||||||||||
| (PID) Process: | (7028) control.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
| (PID) Process: | (7028) control.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (7028) control.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (7028) control.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer |
| Operation: | write | Name: | SlowContextMenuEntries |
Value: 6024B221EA3A6910A2DC08002B30309D0A010000BD0E0C47735D584D9CEDE91E22E23282770100000114020000000000C0000000000000468D0000006078A409B011A54DAFA526D86198A780390100009AD298B2EDA6DE11BA8CA68E55D895936E000000 | |||
| (PID) Process: | (6648) msiexec.exe | Key: | HKEY_USERS\S-1-5-21-1693682860-607145093-2874071422-1001\SOFTWARE\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | Owner |
Value: F819000046920E73D052DB01 | |||
| (PID) Process: | (6648) msiexec.exe | Key: | HKEY_USERS\S-1-5-21-1693682860-607145093-2874071422-1001\SOFTWARE\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | SessionHash |
Value: 22D049C826C9E2AA947C9CE3BA79DDFB639BE886387698C375A38198B7CC4B59 | |||
| (PID) Process: | (6648) msiexec.exe | Key: | HKEY_USERS\S-1-5-21-1693682860-607145093-2874071422-1001\SOFTWARE\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | Sequence |
Value: 1 | |||
| (PID) Process: | (6648) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders |
| Operation: | write | Name: | C:\Config.Msi\ |
Value: | |||
| (PID) Process: | (6648) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\CC25D338FFEA3FD3EA8273C2B51C0588\SourceList |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (6648) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\CC25D338FFEA3FD3EA8273C2B51C0588 |
| Operation: | delete key | Name: | (default) |
Value: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6496 | Ninite.exe | C:\Users\admin\AppData\Local\Temp\9f2d95ad-bec3-11ef-b4ea-18f7786f96ee\GoogleChromeStandaloneEnterprise64.msi_9f2d95af-bec3-11ef-b4ea-18f7786f96ee | — | |
MD5:— | SHA256:— | |||
| 6496 | Ninite.exe | C:\Users\admin\AppData\Local\Temp\9f2d95ad-bec3-11ef-b4ea-18f7786f96ee\GoogleChromeStandaloneEnterprise64.msi | — | |
MD5:— | SHA256:— | |||
| 6244 | Ninite 7Zip Chrome Notepad VLC Installer.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\75CA58072B9926F763A91F0CC2798706_645BC4A49DCDC40FE5917FA45C6D4517 | binary | |
MD5:5B9B0FB6F98F7805A586A55F742E4F20 | SHA256:9BFE4042839503B85C1BA5001F71477B22234BEF410BDC159E4759992343C85C | |||
| 6244 | Ninite 7Zip Chrome Notepad VLC Installer.exe | C:\Users\admin\AppData\Local\Temp\9ce41f82-bec3-11ef-b4ea-18f7786f96ee\Ninite.exe | executable | |
MD5:AECEA03AB75EA848DC8BB0511A3DFD83 | SHA256:168C0280421EC2CEA8ADCF34A22056839F32DF0AC3575B08F98001A10AD587C9 | |||
| 6244 | Ninite 7Zip Chrome Notepad VLC Installer.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\75CA58072B9926F763A91F0CC2798706_645BC4A49DCDC40FE5917FA45C6D4517 | der | |
MD5:7E164878DD7587A223B05A5F9FEA2CE7 | SHA256:C04840B67C8264899F7F46475936A7FA3B8DD8C4AF80DFC27EB6BDD94AF1DF31 | |||
| 6244 | Ninite 7Zip Chrome Notepad VLC Installer.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\A1D627669EFC8CD4F21BCF387D97F9B5_BCCFCBC66B448214318C9391CA0E275F | binary | |
MD5:30989A1CB54F09342AA432AEC730CE8F | SHA256:85BF16B833F3786546EE35339AB75E17896FE892E6F6E8B0A2A81EF069526B7A | |||
| 6244 | Ninite 7Zip Chrome Notepad VLC Installer.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B039FEA45CB4CC4BBACFC013C7C55604_50385F8EB1F713E33924A830D7A2A41C | binary | |
MD5:F124BD7566A3138B56E6AE12CD99390F | SHA256:76BF98A6DA50D71B0553FDCA6297B9A6E6B0809B2296B946142C730D6810386A | |||
| 6244 | Ninite 7Zip Chrome Notepad VLC Installer.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B039FEA45CB4CC4BBACFC013C7C55604_50385F8EB1F713E33924A830D7A2A41C | der | |
MD5:8DA14606CF094A95231261506641727E | SHA256:E8CAA91F8BFD7ADFCF0E793568E570AF590D1360D18C4927D563DC71AD4AFC4A | |||
| 6496 | Ninite.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\05DDC6AA91765AACACDB0A5F96DF8199 | binary | |
MD5:5A7AB7E7C2CB52224DAAC75728F161EB | SHA256:79D399270E10116924C5984BEC98D42B992D32481CFCF9CB15FA2FB3A65F9221 | |||
| 6648 | msiexec.exe | C:\Windows\Installer\13dca7.msi | — | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | GET | 200 | 23.48.23.143:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
— | — | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
— | — | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D | unknown | — | — | whitelisted |
6244 | Ninite 7Zip Chrome Notepad VLC Installer.exe | GET | 200 | 18.245.38.41:80 | http://ocsp.rootca1.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBRPWaOUU8%2B5VZ5%2Fa9jFTaU9pkK3FAQUhBjMhTTsvAyUlC4IWZzHshBOCggCEwdzEkzUBtJnwJkc3SmanzgxeYU%3D | unknown | — | — | unknown |
6244 | Ninite 7Zip Chrome Notepad VLC Installer.exe | GET | 200 | 104.18.21.226:80 | http://ocsp.globalsign.com/codesigningrootr45/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBQVFZP5vqhCrtRN5SWf40Rn6NM1IAQUHwC%2FRoAK%2FHg5t6W0Q9lWULvOljsCEQCBTkIXoSl%2F7VrM1Bf4ka11 | unknown | — | — | whitelisted |
6244 | Ninite 7Zip Chrome Notepad VLC Installer.exe | GET | 200 | 104.18.21.226:80 | http://ocsp.globalsign.com/gsgccr45codesignca2020/ME0wSzBJMEcwRTAJBgUrDgMCGgUABBTLuA3ygnKW%2F7xuSx%2F09F%2BhHVuEUQQU2rONwCSQo2t30wygWd0hZ2R2C3gCDGPUxoqhhiZifL455A%3D%3D | unknown | — | — | whitelisted |
— | — | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
6244 | Ninite 7Zip Chrome Notepad VLC Installer.exe | GET | 200 | 104.18.21.226:80 | http://ocsp.globalsign.com/rootr3/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT1nGh%2FJBjWKnkPdZIzB1bqhelHBwQUj%2FBLf6guRSSuTVD6Y5qL3uLdG7wCEHgDGEJFcIpBz28BuO60qVQ%3D | unknown | — | — | whitelisted |
6496 | Ninite.exe | GET | 200 | 142.250.185.67:80 | http://ocsp.pki.goog/gsr1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCEHe9DWzbNvka6iEPxPBY0w0%3D | unknown | — | — | whitelisted |
— | — | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4712 | MoUsoCoreWorker.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
5156 | svchost.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
— | — | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
— | — | 23.48.23.143:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
— | — | 184.30.21.171:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
5064 | SearchApp.exe | 104.126.37.161:443 | www.bing.com | Akamai International B.V. | DE | whitelisted |
— | — | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
1176 | svchost.exe | 40.126.32.140:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
www.bing.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
login.live.com |
| whitelisted |
ninite.com |
| whitelisted |
ocsp.rootca1.amazontrust.com |
| shared |
ocsp.globalsign.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
6496 | Ninite.exe | Potential Corporate Privacy Violation | ET POLICY PE EXE or DLL Windows file download HTTP |
6496 | Ninite.exe | Potential Corporate Privacy Violation | ET POLICY PE EXE or DLL Windows file download HTTP |