File name:

NVIDIA Profile Inspector 3.5.0.0.zip

Full analysis: https://app.any.run/tasks/e24887ca-50da-4b5e-bdca-f9b7bf340d4f
Verdict: Malicious activity
Threats:

Remcos is a commercially distributed remote administration and surveillance tool that has been widely observed in unauthorized deployments, where threat actors use it to perform remote actions on compromised machines. It is actively maintained by its vendor, with new versions and feature updates released on a frequent, near-monthly basis.

Analysis date: May 01, 2024, 12:17:48
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
remcos
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=deflate
MD5:

62D0B897F3D76117DF9656E6B6F57374

SHA1:

B1B81328F3CBBC052B2E43EEE6C760DE67062BB3

SHA256:

54DF6D48C377D97458D837BA65682B7CB42002204F552AEA2F5A146182C0160B

SSDEEP:

98304:kkN7jOq7NsK/n4JGKtfuE8ak2YsBX/e8dT/A1BFJS4poBUkM34PsWv/bdynl5Vvm:0cV+Kix

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 3980)
      • NVIDIA Profile Inspector 3.5.0.0.exe (PID: 1764)
      • NVIDIA Profile Inspector 3.5.0.0.exe (PID: 312)
    • REMCOS has been detected (YARA)

      • cmd.exe (PID: 2512)
  • SUSPICIOUS

    • Reads the Windows owner or organization settings

      • NVIDIA Profile Inspector 3.5.0.0.exe (PID: 1764)
      • NVIDIA Profile Inspector 3.5.0.0.exe (PID: 312)
    • Application launched itself

      • NVIDIA Profile Inspector 3.5.0.0.exe (PID: 1136)
      • NVIDIA Profile Inspector 3.5.0.0.exe (PID: 1764)
    • Executable content was dropped or overwritten

      • NVIDIA Profile Inspector 3.5.0.0.exe (PID: 1764)
      • NVIDIA Profile Inspector 3.5.0.0.exe (PID: 312)
    • Reads the Internet Settings

      • NVIDIA Profile Inspector 3.5.0.0.exe (PID: 1764)
      • ipconfig.exe (PID: 1816)
    • Reads security settings of Internet Explorer

      • NVIDIA Profile Inspector 3.5.0.0.exe (PID: 1764)
    • Process uses IPCONFIG to get network configuration information

      • Nvidia Security Update.exe (PID: 1840)
    • Reads settings of System Certificates

      • ipconfig.exe (PID: 1816)
    • Adds/modifies Windows certificates

      • ipconfig.exe (PID: 1816)
    • Starts CMD.EXE for commands execution

      • ipconfig.exe (PID: 1816)
  • INFO

    • Manual execution by a user

      • NVIDIA Profile Inspector 3.5.0.0.exe (PID: 1136)
      • wmpnscfg.exe (PID: 2556)
    • Checks supported languages

      • NVIDIA Profile Inspector 3.5.0.0.exe (PID: 1136)
      • NVIDIA Profile Inspector 3.5.0.0.exe (PID: 1764)
      • NVIDIA Profile Inspector 3.5.0.0.exe (PID: 312)
      • NVidiaProfileInspectorDmW.exe (PID: 1652)
      • Nvidia Security Update.exe (PID: 1840)
      • wmpnscfg.exe (PID: 2556)
    • Reads the computer name

      • NVIDIA Profile Inspector 3.5.0.0.exe (PID: 1136)
      • NVIDIA Profile Inspector 3.5.0.0.exe (PID: 1764)
      • NVIDIA Profile Inspector 3.5.0.0.exe (PID: 312)
      • NVidiaProfileInspectorDmW.exe (PID: 1652)
      • Nvidia Security Update.exe (PID: 1840)
      • wmpnscfg.exe (PID: 2556)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3980)
    • Create files in a temporary directory

      • NVIDIA Profile Inspector 3.5.0.0.exe (PID: 1764)
      • NVIDIA Profile Inspector 3.5.0.0.exe (PID: 312)
    • Creates files in the program directory

      • NVIDIA Profile Inspector 3.5.0.0.exe (PID: 312)
    • Creates files or folders in the user directory

      • ipconfig.exe (PID: 1816)
    • Reads the machine GUID from the registry

      • NVidiaProfileInspectorDmW.exe (PID: 1652)
    • Reads the software policy settings

      • ipconfig.exe (PID: 1816)
    • Checks proxy server information

      • ipconfig.exe (PID: 1816)
    • Reads security settings of Internet Explorer

      • ipconfig.exe (PID: 1816)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Remcos

(PID) Process(2512) cmd.exe
C2 (1)45.147.230.213:5885
Botnet5885
Options
Connect_interval1
Install_flagFalse
Install_HKCU\RunTrue
Setup_path%APPDATA%
Copy_fileremcos.exe
Startup_valueremcos
Hide_fileFalse
Mutex_nameRemcos-FF8L7S
Keylog_flag1
Keylog_path%TEMP%
Keylog_filehipster.bin
Keylog_cryptTrue
Hide_keylogFalse
Screenshot_flagFalse
Screenshot_time5
Take_ScreenshotFalse
Screenshot_namewikipedia;solitaire;
Screenshot_path%APPDATA%
Screenshot_fileScreenshots
Screenshot_cryptFalse
Mouse_optionFalse
Delete_fileFalse
Audio_record_time5
Audio_path%APPDATA%
Audio_dirMicRecords
Connect_delay0
Copy_dirremcos
Keylog_dirsvchost
Max_keylog_file10000
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2019:03:26 02:35:12
ZipCRC: 0x33420732
ZipCompressedSize: 3660
ZipUncompressedSize: 8704
ZipFileName: NVIDIA Profile Inspector 3.5.0.0/AutoClosingMessageBox.dll
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
50
Monitored processes
9
Malicious processes
6
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe nvidia profile inspector 3.5.0.0.exe no specs nvidia profile inspector 3.5.0.0.exe nvidia profile inspector 3.5.0.0.exe nvidiaprofileinspectordmw.exe nvidia security update.exe no specs ipconfig.exe #REMCOS cmd.exe no specs wmpnscfg.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
312"C:\Users\admin\Desktop\NVIDIA Profile Inspector 3.5.0.0\NVIDIA Profile Inspector 3.5.0.0.exe" /VERYSILENTC:\Users\admin\Desktop\NVIDIA Profile Inspector 3.5.0.0\NVIDIA Profile Inspector 3.5.0.0.exe
NVIDIA Profile Inspector 3.5.0.0.exe
User:
admin
Company:
Modified by DeadManWalking (DeadManWalkingTO-Github)
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\desktop\nvidia profile inspector 3.5.0.0\nvidia profile inspector 3.5.0.0.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1136"C:\Users\admin\Desktop\NVIDIA Profile Inspector 3.5.0.0\NVIDIA Profile Inspector 3.5.0.0.exe" C:\Users\admin\Desktop\NVIDIA Profile Inspector 3.5.0.0\NVIDIA Profile Inspector 3.5.0.0.exeexplorer.exe
User:
admin
Company:
Modified by DeadManWalking (DeadManWalkingTO-Github)
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
1
Version:
51.1052.0.0
Modules
Images
c:\users\admin\desktop\nvidia profile inspector 3.5.0.0\nvidia profile inspector 3.5.0.0.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1652"C:\Users\admin\AppData\Local\Temp\NVidiaProfileInspectorDmW.exe"C:\Users\admin\AppData\Local\Temp\NVidiaProfileInspectorDmW.exe
NVIDIA Profile Inspector 3.5.0.0.exe
User:
admin
Company:
Modified by DeadManWalking (DeadManWalkingTO-Github)
Integrity Level:
HIGH
Description:
NVidiaProfileInspectorDmW
Version:
3.5.0.0
Modules
Images
c:\users\admin\appdata\local\temp\nvidiaprofileinspectordmw.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1764"C:\Users\admin\Desktop\NVIDIA Profile Inspector 3.5.0.0\NVIDIA Profile Inspector 3.5.0.0.exe" /SPAWNWND=$101B4 /NOTIFYWND=$101B4 C:\Users\admin\Desktop\NVIDIA Profile Inspector 3.5.0.0\NVIDIA Profile Inspector 3.5.0.0.exe
NVIDIA Profile Inspector 3.5.0.0.exe
User:
admin
Company:
Modified by DeadManWalking (DeadManWalkingTO-Github)
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
1
Version:
51.1052.0.0
Modules
Images
c:\users\admin\desktop\nvidia profile inspector 3.5.0.0\nvidia profile inspector 3.5.0.0.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1816"C:\Windows\system32\ipconfig.exe"C:\Windows\System32\ipconfig.exe
Nvidia Security Update.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
IP Configuration Utility
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ipconfig.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\ws2_32.dll
1840"C:\Users\admin\AppData\Local\Temp\Nvidia Security Update.exe"C:\Users\admin\AppData\Local\Temp\Nvidia Security Update.exeNVIDIA Profile Inspector 3.5.0.0.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\nvidia security update.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\winspool.drv
2512"C:\Windows\system32\cmd.exe"C:\Windows\System32\cmd.exe
ipconfig.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
Remcos
(PID) Process(2512) cmd.exe
C2 (1)45.147.230.213:5885
Botnet5885
Options
Connect_interval1
Install_flagFalse
Install_HKCU\RunTrue
Setup_path%APPDATA%
Copy_fileremcos.exe
Startup_valueremcos
Hide_fileFalse
Mutex_nameRemcos-FF8L7S
Keylog_flag1
Keylog_path%TEMP%
Keylog_filehipster.bin
Keylog_cryptTrue
Hide_keylogFalse
Screenshot_flagFalse
Screenshot_time5
Take_ScreenshotFalse
Screenshot_namewikipedia;solitaire;
Screenshot_path%APPDATA%
Screenshot_fileScreenshots
Screenshot_cryptFalse
Mouse_optionFalse
Delete_fileFalse
Audio_record_time5
Audio_path%APPDATA%
Audio_dirMicRecords
Connect_delay0
Copy_dirremcos
Keylog_dirsvchost
Max_keylog_file10000
2556"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
3980"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\NVIDIA Profile Inspector 3.5.0.0.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
Total events
130 257
Read events
130 155
Write events
79
Delete events
23

Modification events

(PID) Process:(3980) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3980) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3980) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3980) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(3980) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(3980) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(3980) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\NVIDIA Profile Inspector 3.5.0.0.zip
(PID) Process:(3980) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3980) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3980) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
Executable files
7
Suspicious files
8
Text files
6
Unknown types
1

Dropped files

PID
Process
Filename
Type
3980WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3980.19143\NVIDIA Profile Inspector 3.5.0.0\Nvidia Profile test.txt
MD5:
SHA256:
312NVIDIA Profile Inspector 3.5.0.0.exeC:\Users\admin\AppData\Local\Temp\NVidiaProfileInspectorDmW.exe
MD5:
SHA256:
3980WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3980.19143\NVIDIA Profile Inspector 3.5.0.0\Performance profile.nipxml
MD5:DFA4855C121D2C558DAB457A42951EA4
SHA256:D1422C72CEBD6311B985E01022184C7706C26A779F5B1F1E9C06C03AA4194542
3980WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3980.19143\NVIDIA Profile Inspector 3.5.0.0\Ultimate performance plan.txttext
MD5:E4DB047350C96CC595626F94EDB2D539
SHA256:9012E156B5D2EA4513C1F921CF204D8CFB65A20E65E85353F66E11CB09EA6F88
3980WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3980.19143\NVIDIA Profile Inspector 3.5.0.0\NVIDIA Profile Inspector 3.5.0.0.exeexecutable
MD5:35E9FB365044AEDE6CFE1099E2CB9F8B
SHA256:03C7BC92859DCA2EDFEA1903131FE7897DF7A41E4FB65C660511CD22DC789E19
2512cmd.exeC:\Users\admin\AppData\Local\Temp\2f205cd2.lnk
MD5:
SHA256:
3980WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3980.19143\NVIDIA Profile Inspector 3.5.0.0\NVIDIA Profile Inspector 3.5.0.0-1.binbinary
MD5:CA57B8B613422FC930793891093BD39F
SHA256:604C70BA3207BF3B81B46B7387D53E9E60204DFB59D2BDF7E84CFD94C561EF1F
1816ipconfig.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:ED8A4D9A6901268638CCC89E919F9733
SHA256:FE2A7D4956E4E9BC87B46B458E959553CEDE74818E1498B7BD3F0FA6A76AE54D
312NVIDIA Profile Inspector 3.5.0.0.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows NT\NVidiaProfileInspectorDmW.lnklnk
MD5:7F08F149B0421E876C241B7E32EB31C6
SHA256:25DEAC6A0ECABDC026C3C3BCEE0061975E53F6829DF3A8B066D8156661E210DB
1816ipconfig.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B2FAF7692FD9FFBD64EDE317E42334BA_D7393C8F62BDE4D4CB606228BC7A711Ebinary
MD5:D74C3342B546AE0B00789666C46E6FE3
SHA256:474CB468EC0CA975A696248F814CA3050F9D6951AA73B05839890192FA883F23
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
3
TCP/UDP connections
10
DNS requests
4
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
304
23.45.119.165:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?f4dd37beaa18db38
unknown
unknown
1816
ipconfig.exe
GET
200
172.64.149.23:80
http://ocsp.usertrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTNMNJMNDqCqx8FcBWK16EHdimS6QQUU3m%2FWqorSs9UgOHYm8Cd8rIDZssCEH1bUSa0droR23QWC7xTDac%3D
unknown
unknown
1816
ipconfig.exe
GET
200
104.18.38.233:80
http://ocsp.comodoca.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRTtU9uFqgVGHhJwXZyWCNXmVR5ngQUoBEKIz6W8Qfs4q8p74Klf9AwpLQCEDlyRDr5IrdR19NsEN0xNZU%3D
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1088
svchost.exe
224.0.0.252:5355
unknown
1640
svchost.exe
239.255.255.250:1900
unknown
1816
ipconfig.exe
146.75.120.193:443
i.imgur.com
FASTLY
US
unknown
1816
ipconfig.exe
23.45.119.165:80
ctldl.windowsupdate.com
Akamai International B.V.
US
unknown
1816
ipconfig.exe
104.18.38.233:80
ocsp.comodoca.com
CLOUDFLARENET
shared
1816
ipconfig.exe
172.64.149.23:80
ocsp.comodoca.com
CLOUDFLARENET
US
unknown

DNS requests

Domain
IP
Reputation
i.imgur.com
  • 146.75.120.193
shared
ctldl.windowsupdate.com
  • 23.45.119.165
  • 23.45.119.174
whitelisted
ocsp.comodoca.com
  • 104.18.38.233
  • 172.64.149.23
whitelisted
ocsp.usertrust.com
  • 172.64.149.23
  • 104.18.38.233
whitelisted

Threats

No threats detected
No debug info