| File name: | NVIDIA Profile Inspector 3.5.0.0.zip |
| Full analysis: | https://app.any.run/tasks/e24887ca-50da-4b5e-bdca-f9b7bf340d4f |
| Verdict: | Malicious activity |
| Threats: | Remcos is a commercially distributed remote administration and surveillance tool that has been widely observed in unauthorized deployments, where threat actors use it to perform remote actions on compromised machines. It is actively maintained by its vendor, with new versions and feature updates released on a frequent, near-monthly basis. |
| Analysis date: | May 01, 2024, 12:17:48 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract, compression method=deflate |
| MD5: | 62D0B897F3D76117DF9656E6B6F57374 |
| SHA1: | B1B81328F3CBBC052B2E43EEE6C760DE67062BB3 |
| SHA256: | 54DF6D48C377D97458D837BA65682B7CB42002204F552AEA2F5A146182C0160B |
| SSDEEP: | 98304:kkN7jOq7NsK/n4JGKtfuE8ak2YsBX/e8dT/A1BFJS4poBUkM34PsWv/bdynl5Vvm:0cV+Kix |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 20 |
|---|---|
| ZipBitFlag: | - |
| ZipCompression: | Deflated |
| ZipModifyDate: | 2019:03:26 02:35:12 |
| ZipCRC: | 0x33420732 |
| ZipCompressedSize: | 3660 |
| ZipUncompressedSize: | 8704 |
| ZipFileName: | NVIDIA Profile Inspector 3.5.0.0/AutoClosingMessageBox.dll |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 312 | "C:\Users\admin\Desktop\NVIDIA Profile Inspector 3.5.0.0\NVIDIA Profile Inspector 3.5.0.0.exe" /VERYSILENT | C:\Users\admin\Desktop\NVIDIA Profile Inspector 3.5.0.0\NVIDIA Profile Inspector 3.5.0.0.exe | NVIDIA Profile Inspector 3.5.0.0.exe | ||||||||||||
User: admin Company: Modified by DeadManWalking (DeadManWalkingTO-Github) Integrity Level: HIGH Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 Modules
| |||||||||||||||
| 1136 | "C:\Users\admin\Desktop\NVIDIA Profile Inspector 3.5.0.0\NVIDIA Profile Inspector 3.5.0.0.exe" | C:\Users\admin\Desktop\NVIDIA Profile Inspector 3.5.0.0\NVIDIA Profile Inspector 3.5.0.0.exe | — | explorer.exe | |||||||||||
User: admin Company: Modified by DeadManWalking (DeadManWalkingTO-Github) Integrity Level: MEDIUM Description: Setup/Uninstall Exit code: 1 Version: 51.1052.0.0 Modules
| |||||||||||||||
| 1652 | "C:\Users\admin\AppData\Local\Temp\NVidiaProfileInspectorDmW.exe" | C:\Users\admin\AppData\Local\Temp\NVidiaProfileInspectorDmW.exe | NVIDIA Profile Inspector 3.5.0.0.exe | ||||||||||||
User: admin Company: Modified by DeadManWalking (DeadManWalkingTO-Github) Integrity Level: HIGH Description: NVidiaProfileInspectorDmW Version: 3.5.0.0 Modules
| |||||||||||||||
| 1764 | "C:\Users\admin\Desktop\NVIDIA Profile Inspector 3.5.0.0\NVIDIA Profile Inspector 3.5.0.0.exe" /SPAWNWND=$101B4 /NOTIFYWND=$101B4 | C:\Users\admin\Desktop\NVIDIA Profile Inspector 3.5.0.0\NVIDIA Profile Inspector 3.5.0.0.exe | NVIDIA Profile Inspector 3.5.0.0.exe | ||||||||||||
User: admin Company: Modified by DeadManWalking (DeadManWalkingTO-Github) Integrity Level: HIGH Description: Setup/Uninstall Exit code: 1 Version: 51.1052.0.0 Modules
| |||||||||||||||
| 1816 | "C:\Windows\system32\ipconfig.exe" | C:\Windows\System32\ipconfig.exe | Nvidia Security Update.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: IP Configuration Utility Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1840 | "C:\Users\admin\AppData\Local\Temp\Nvidia Security Update.exe" | C:\Users\admin\AppData\Local\Temp\Nvidia Security Update.exe | — | NVIDIA Profile Inspector 3.5.0.0.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 2512 | "C:\Windows\system32\cmd.exe" | C:\Windows\System32\cmd.exe | ipconfig.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
Remcos(PID) Process(2512) cmd.exe C2 (1)45.147.230.213:5885 Botnet5885 Options Connect_interval1 Install_flagFalse Install_HKCU\RunTrue Setup_path%APPDATA% Copy_fileremcos.exe Startup_valueremcos Hide_fileFalse Mutex_nameRemcos-FF8L7S Keylog_flag1 Keylog_path%TEMP% Keylog_filehipster.bin Keylog_cryptTrue Hide_keylogFalse Screenshot_flagFalse Screenshot_time5 Take_ScreenshotFalse Screenshot_namewikipedia;solitaire; Screenshot_path%APPDATA% Screenshot_fileScreenshots Screenshot_cryptFalse Mouse_optionFalse Delete_fileFalse Audio_record_time5 Audio_path%APPDATA% Audio_dirMicRecords Connect_delay0 Copy_dirremcos Keylog_dirsvchost Max_keylog_file10000 | |||||||||||||||
| 2556 | "C:\Program Files\Windows Media Player\wmpnscfg.exe" | C:\Program Files\Windows Media Player\wmpnscfg.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Network Sharing Service Configuration Application Exit code: 0 Version: 12.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3980 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\NVIDIA Profile Inspector 3.5.0.0.zip" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| (PID) Process: | (3980) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (3980) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (3980) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3980) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\phacker.zip | |||
| (PID) Process: | (3980) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (3980) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip | |||
| (PID) Process: | (3980) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\NVIDIA Profile Inspector 3.5.0.0.zip | |||
| (PID) Process: | (3980) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (3980) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (3980) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3980 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3980.19143\NVIDIA Profile Inspector 3.5.0.0\Nvidia Profile test.txt | — | |
MD5:— | SHA256:— | |||
| 312 | NVIDIA Profile Inspector 3.5.0.0.exe | C:\Users\admin\AppData\Local\Temp\NVidiaProfileInspectorDmW.exe | — | |
MD5:— | SHA256:— | |||
| 3980 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3980.19143\NVIDIA Profile Inspector 3.5.0.0\AutoClosingMessageBox.dll | executable | |
MD5:22784F6F6D9714D920D6FC11EE3699EE | SHA256:8F94F24B6C089C86ACFB94C592820731B6F303A694D8AA98407135252F4D1E20 | |||
| 3980 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3980.19143\NVIDIA Profile Inspector 3.5.0.0\Performance profile.7z | compressed | |
MD5:A4ADCCBB6B3731959248888D123B47A8 | SHA256:D2676BFFE13E45DCB76A958F4DFCB3637DD03341D642BBD78B9E80A2F553F240 | |||
| 3980 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3980.19143\NVIDIA Profile Inspector 3.5.0.0\Performance profile.nip | xml | |
MD5:DFA4855C121D2C558DAB457A42951EA4 | SHA256:D1422C72CEBD6311B985E01022184C7706C26A779F5B1F1E9C06C03AA4194542 | |||
| 2512 | cmd.exe | C:\Users\admin\AppData\Local\Temp\2f205cd2.lnk | — | |
MD5:— | SHA256:— | |||
| 3980 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3980.19143\NVIDIA Profile Inspector 3.5.0.0\NVIDIA Profile Inspector 3.5.0.0.exe | executable | |
MD5:35E9FB365044AEDE6CFE1099E2CB9F8B | SHA256:03C7BC92859DCA2EDFEA1903131FE7897DF7A41E4FB65C660511CD22DC789E19 | |||
| 3980 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3980.19143\NVIDIA Profile Inspector 3.5.0.0\NVIDIA Profile Inspector 3.5.0.0-0.bin | binary | |
MD5:CEE33BC514D9763032E087B5677C552C | SHA256:7B3925BEEDE2CD7A21B3FBF56D41950E8C706AA28F168CCF98CFCFCC8551B0B2 | |||
| 3980 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3980.19143\NVIDIA Profile Inspector 3.5.0.0\NVIDIA Profile Inspector 3.5.0.0-1.bin | binary | |
MD5:CA57B8B613422FC930793891093BD39F | SHA256:604C70BA3207BF3B81B46B7387D53E9E60204DFB59D2BDF7E84CFD94C561EF1F | |||
| 3980 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3980.19143\NVIDIA Profile Inspector 3.5.0.0\NVidiaProfileInspectorDmW.exe.config | xml | |
MD5:10AC8BFC8E450B2AAC4A9F1B90892C57 | SHA256:F3F4847275F08DB429019EE65F0DD8E3D2384A35035322DE949EB43009FD1A57 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | GET | 304 | 23.45.119.165:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?f4dd37beaa18db38 | unknown | — | — | unknown |
1816 | ipconfig.exe | GET | 200 | 104.18.38.233:80 | http://ocsp.comodoca.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRTtU9uFqgVGHhJwXZyWCNXmVR5ngQUoBEKIz6W8Qfs4q8p74Klf9AwpLQCEDlyRDr5IrdR19NsEN0xNZU%3D | unknown | — | — | unknown |
1816 | ipconfig.exe | GET | 200 | 172.64.149.23:80 | http://ocsp.usertrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTNMNJMNDqCqx8FcBWK16EHdimS6QQUU3m%2FWqorSs9UgOHYm8Cd8rIDZssCEH1bUSa0droR23QWC7xTDac%3D | unknown | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1088 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
1640 | svchost.exe | 239.255.255.250:1900 | — | — | — | unknown |
1816 | ipconfig.exe | 146.75.120.193:443 | i.imgur.com | FASTLY | US | unknown |
1816 | ipconfig.exe | 23.45.119.165:80 | ctldl.windowsupdate.com | Akamai International B.V. | US | unknown |
1816 | ipconfig.exe | 104.18.38.233:80 | ocsp.comodoca.com | CLOUDFLARENET | — | shared |
1816 | ipconfig.exe | 172.64.149.23:80 | ocsp.comodoca.com | CLOUDFLARENET | US | unknown |
Domain | IP | Reputation |
|---|---|---|
i.imgur.com |
| shared |
ctldl.windowsupdate.com |
| whitelisted |
ocsp.comodoca.com |
| whitelisted |
ocsp.usertrust.com |
| whitelisted |